1 / 69
网络安全
路由交换实验指南
2 / 69
目 录
Part1:Tarena Certified Network Administrator .............................................................................. 3
案例 01:配置 VLAN 虚拟局域网 ........................................................................................................................ 3
案例 02:VLAN 与 trunk 配置 ............................................................................................................................. 5
案例 03:配置 hybrid 端口 .................................................................................................................................. 6
案例 04:配置静态路由 ......................................................................................................................................... 7
案例 05:配置多路由静态路由 ............................................................................................................................. 9
案例 06:配置默认路由 ....................................................................................................................................... 10
案例 07:路由故障排查 ....................................................................................................................................... 11
案例 08:华为单臂路由配置 ............................................................................................................................... 12
案例 09:三层交换 VLAN 间通信 ...................................................................................................................... 13
案例 10:多交换机 VLAN 间通信 ...................................................................................................................... 15
案例 11:三层交换配置路由 ............................................................................................................................... 16
案例 12:配置 STP 生成树 .................................................................................................................................. 18
案例 13:配置 MSTP 及负载均衡 ...................................................................................................................... 20
案例 14:基于全局的 DHCP 配置 ..................................................................................................................... 25
案例 15:基于接口的 DHCP 配置 ..................................................................................................................... 27
案例 16:配置 DHCP 中继 ................................................................................................................................. 28
案例 17:交换机配置 DHCP 服务器.................................................................................................................. 30
Part2:Tarena Certified Network Engineer ........................................................................................ 33
案例 01:三层链路冗余-单宿主网络 ................................................................................................................. 33
案例 02:三层链路冗余-多宿主网络 ................................................................................................................. 36
案例 03:三层设备冗余-VRRP 虚拟路由 .......................................................................................................... 39
案例 04:3 层设备冗余-多层交换机 .................................................................................................................. 41
案例 05:流量管控-基本 ACL 配置.................................................................................................................... 44
案例 06:流量管控-高级 ACL 配置.................................................................................................................... 46
案例 07:网络边缘-NAT 服务器实现(由内而外) ........................................................................................ 49
案例 08:网络边缘-NAT 服务器实现(由外而内) ........................................................................................ 51
案例 09:大型网络架构-单区域 OSPF 配置 ..................................................................................................... 52
案例 10:大型网络架构-多区域 OSPF 配置 ..................................................................................................... 54
案例 11:大型网络架构-OSPF 之特殊区域 ...................................................................................................... 57
案例 12:Internet 互联基础-BGP 邻居建立 .................................................................................................... 60
案例 13:Internet 巨型环路-IBGP 防环机制 ................................................................................................... 64
3 / 69
Part1:Tarena Certified Network Administrator
案例 01:配置 VLAN 虚拟局域网
实验需求:
1)创建 VLAN10,VLAN20,VLAN30
2)将端口加入 VLAN
3)查看 VLAN 信息
实验拓扑:
实验步骤:
1)创建 VLAN10,VLAN20,VLAN30
[Huawei]vlan 10
[Huawei-vlan10]q
[Huawei]vlan 20
[Huawei-vlan20]q
[Huawei]vlan 30
[Huawei-vlan30]quit
2)将端口加入 VLAN
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type access
[Huawei-GigabitEthernet0/0/1]port default vlan 10
[Huawei-GigabitEthernet0/0/1]q
4 / 69
[Huawei]interface g0/0/2
[Huawei-GigabitEthernet0/0/2]port link-type access
[Huawei-GigabitEthernet0/0/2]port default vlan 20
[Huawei-GigabitEthernet0/0/2]q
[Huawei]int g0/0/3
[Huawei-GigabitEthernet0/0/3]port link-type access
[Huawei-GigabitEthernet0/0/3]port default vlan 30
3)查看 VLAN 信息
[Huawei]display vlan
The total number of vlans is : 4
--------------------------------------------------------------------------------
U: Up; D: Down; TG: Tagged; UT: Untagged;
MP: Vlan-mapping; ST: Vlan-stacking;
#: ProtocolTransparent-vlan; *: Management-vlan;
--------------------------------------------------------------------------------
VID Type Ports
--------------------------------------------------------------------------------
1 common UT:GE0/0/4(D) GE0/0/5(D) GE0/0/6(D) GE0/0/7(D)
GE0/0/8(D) GE0/0/9(D) GE0/0/10(D) GE0/0/11(D)
GE0/0/12(D) GE0/0/13(D) GE0/0/14(D) GE0/0/15(D)
GE0/0/16(D) GE0/0/17(D) GE0/0/18(D) GE0/0/19(D)
GE0/0/20(D) GE0/0/21(D) GE0/0/22(D) GE0/0/23(D)
GE0/0/24(D)
10 common UT:GE0/0/1(U)
20 common UT:GE0/0/2(U)
30 common UT:GE0/0/3(U)
VID Status Property MAC-LRN Statistics Description
--------------------------------------------------------------------------------
1 enable default enable disable VLAN 0001
10 enable default enable disable VLAN 0010
20 enable default enable disable VLAN 0020
30 enable default enable disable VLAN 0030
[Huawei]display port vlan
Port Link Type PVID Trunk VLAN List
-------------------------------------------------------------------------------
GigabitEthernet0/0/1 access 10 -
GigabitEthernet0/0/2 access 20 -
GigabitEthernet0/0/3 access 30 -
GigabitEthernet0/0/4 hybrid 1 -
GigabitEthernet0/0/5 hybrid 1 -
GigabitEthernet0/0/6 hybrid 1 -
GigabitEthernet0/0/7 hybrid 1 -
GigabitEthernet0/0/8 hybrid 1 -
GigabitEthernet0/0/9 hybrid 1 -
GigabitEthernet0/0/10 hybrid 1 -
GigabitEthernet0/0/11 hybrid 1 -
GigabitEthernet0/0/12 hybrid 1 -
GigabitEthernet0/0/13 hybrid 1 -
GigabitEthernet0/0/14 hybrid 1 -
GigabitEthernet0/0/15 hybrid 1 -
GigabitEthernet0/0/16 hybrid 1 -
GigabitEthernet0/0/17 hybrid 1 -
GigabitEthernet0/0/18 hybrid 1 -
GigabitEthernet0/0/19 hybrid 1 -
5 / 69
GigabitEthernet0/0/20 hybrid 1 -
GigabitEthernet0/0/21 hybrid 1 -
GigabitEthernet0/0/22 hybrid 1 -
GigabitEthernet0/0/23 hybrid 1 -
GigabitEthernet0/0/24 hybrid 1 -
案例 02:VLAN 与 trunk 配置
实验需求:
实现跨交换机的相同 VLAN 通信。
实验拓扑:
实验步骤:
1)配置 PC 相关地址信息
2)配置 SW1、SW2 的 VLAN10,VLAN20
[sw1]vlan 10
[sw1-vlan10]q
[sw1]vlan 20
[sw1-vlan20]quit
[sw2]vlan 10
[sw2-vlan10]qu
[sw2]vlan 20
[sw2-vlan20]qu
3)配置 SW1,SW2 与 PC 相连的接口类型为 access,并将接口加入对应 VLAN
[sw1]int g0/0/1
[sw1-GigabitEthernet0/0/1]port link-type access
[sw1-GigabitEthernet0/0/1]port default vlan 10
[sw1-GigabitEthernet0/0/1]q