第十二課 NAT、Telnet和單臂路由的配置案例
實(shí)驗(yàn)?zāi)康模?/strong>
1、掌握NAT的配置方法
2、了解靜態(tài)路由的配置方法
3、掌握Telnet的配置方法
4、掌握單臂路由的配置方法
實(shí)驗(yàn)內(nèi)容:
本實(shí)驗(yàn)?zāi)M企業(yè)網(wǎng)絡(luò)場(chǎng)景。公司市場(chǎng)部客戶(hù)端Client1和網(wǎng)絡(luò)部PC2分別屬于VLAN 10和VLAN20,IP地址分別規(guī)劃見(jiàn)網(wǎng)絡(luò)拓?fù)鋱D,電信運(yùn)營(yíng)商分配給公司的公網(wǎng)IP為202.1.1.2,現(xiàn)需經(jīng)NAT轉(zhuǎn)換上互聯(lián)網(wǎng),網(wǎng)絡(luò)管理員可在家中訪(fǎng)問(wèn)公司內(nèi)部路由器R1。
網(wǎng)絡(luò)拓?fù)洌?/strong>
實(shí)驗(yàn)配置步驟:
市場(chǎng)部客戶(hù)端Client1的配置如下:
IP地址:192.168.10.1
子網(wǎng)掩碼:255.255.255.0
網(wǎng)關(guān):192.168.10.254
網(wǎng)絡(luò)部PC2的配置如下:
IP地址:192.168.20.1
子網(wǎng)掩碼:255.255.255.0
網(wǎng)關(guān):192.168.20.254
交換機(jī)SW2的配置如下:
sysname SW2
vlan batch 10 20
interface Ethernet0/0/1
port link-type access
port default vlan 10
interface Ethernet0/0/2
port link-type access
port default vlan 20
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 10 20 100
交換機(jī)SW1的配置如下:
sysname SW1
vlan batch 10 20 100
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 10 20
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 10 20
路由器R1的配置如下:
sysname R1
vlan batch 100
acl number 2000
rule 5 permit source 192.168.0.0 0.0.255.255
aaa
local-user huawei password cipher huawei123
local-user huawei privilege level 15
local-user huawei service-type telnet
interface GigabitEthernet0/0/0
ip address 202.1.1.2 255.255.255.0
nat outbound 2000
interface GigabitEthernet0/0/1.1
dot1q termination vid 10
ip address 192.168.10.254 255.255.255.0
arp broadcast enable
interface GigabitEthernet0/0/1.2
dot1q termination vid 20
ip address 192.168.20.254 255.255.255.0
arp broadcast enable
ip route-static 192.168.30.0 255.255.255.0 202.1.1.1
user-interface vty 0 4
protocol inbound telnet
authentication-mode aaa
路由器R2的配置如下:
sysname R2
interface GigabitEthernet0/0/0
ip address 202.1.1.1 255.255.255.0
interface GigabitEthernet0/0/1
ip address 192.168.30.254 255.255.255.0
ip route-static 192.168.0.0 255.255.0.0 202.1.1.2
路由器R3的配置如下:
sysname R3
interface GigabitEthernet0/0/0
ip address 192.168.30.1 255.255.255.0
ip route-static 202.1.1.0 255.255.255.0 192.168.30.254