實驗過程中用到的設備
兩臺銳捷S3550三層交換機,兩臺銳捷S2126G二層交換機,兩臺銳捷2600路由器。
對網絡地址規劃,如表1,表2,表3所示
表1 各設備的ip地址規劃
設備 |
接口 |
IP地址 |
S |
VLAN 1 |
192.168.1.2/24 |
S2126B |
VLAN 1 |
192.168.1.3/24 |
S |
F0/24 |
192.168.100.1/24 |
VLAN 1 |
192.168.1.1/24 | |
S3550B |
F0/24 |
192.168.200.1/24 |
R |
F1/0 |
192.168.100.2/24 |
F1/1 |
192.168.200.2/24 | |
S1/2 |
| |
R2600B |
S1/2 |
|
Loopback0 |
|
表2在覈心層S3550A , S3550B 上配置的地址
VLAN ID |
S |
S |
S3550B 虛擬IP |
S3550B真實IP |
VLAN 2 |
192.168.2.254 |
192.168.2.1 |
192.168.2.254 |
192.168.2.2 |
VLAN 3 |
192.168.3.254 |
192.168.3.1 |
192.168.3.254 |
192.168.3.2 |
VLAN 4 |
192.168.4.254 |
192.168.4.1 |
192.168.4.254 |
192.168.4.2 |
VLAN 5 |
192.168.5.254 |
192.168.5.1 |
192.168.5.254 |
192.168.5.2 |
表3在
VLAN2 , VLAN3, VLAN4, VLAN5 中PC的地址及網關
VLAN ID |
PC機地址範圍 |
子網掩碼 |
網關 |
VLAN 2 |
192.168.2.10—192.168.2.250 |
255.255.255.0 |
192.168.2.254 |
VLAN 3 |
192.168.3.10—192.168.3.250 |
255.255.255.0 |
192.168.3.254 |
VLAN 4 |
192.168.4.10—192.168.4.250 |
255.255.255.0 |
192.168.4.254 |
VLAN 5 |
192.168.5.10—192.168.5.250 |
255.255.255.0 |
192.168.5.254 |
具體配置和方法
3.1 S3550A 的配置
S3550B的配置跟S3550A 類似
S3550A (config)#vlan 2
S3550A (config-vlan)#exit
S3550A (config)#interface Vlan 1
S3550A (config-if)#ip address 192.168.1.1 255.255.255.0
S3550A (config)#spanning-tree mode mstp
S3550A (config)#spanning-tree mst configuration
S3550A (config-mst)#instance 1 vlan 1,2,3
S3550A (config-mst)#instance 2 vlan 4,5
S3550A (config-mst)#name hzu 配置MST域的名字爲hzu
S3550A (config-mst)#revision 1
S3550A (config-mst)#exit
S3550A (config)#spanning-tree mst 1 priority 0 設置交換機指定實例的優先級,優先級值小的優先級高,
S3550A (config)#spanning-tree mst 2 priority 4096
S3550A (config)#interface Vlan 2
S3550A (config-if)#ip address 192.168.2.1 255.255.255.0
S3550A (config-if)#standby 1 ip 192.168.2.254
S3550A (config-if)#standby 1 priority 120
S3550A (config-if)#standby 1 preempt
3.2 S2126A 的配置
S2126B配置跟S2126A 類似
S2126A (config)#interface range fastEthernet 0/1-8
S2126A (config-if-range)# switchport access vlan 2
S2126A (config-if-range)# spanning-tree bpdufilter enabled
S2126A (config-if-range)# spanning-tree bpduguard enabled
S2126A (config-if-range)# switchport port-security
S2126A (config-if-range)# switchport port-security violation restrict
S2126A (config-if-range)# switchport port-security maximum 1
3.3 R2600A 的配置
R2600A (config)#access-list 1 permit 192.168.0.0 0.0.255.255
R2600A (config)#ip nat pool jin 10.1.1 .1 10.1.1.1 netmask 255.255.255.0
R2600A (config)#ip nat inside source list 1 pool jin overload
R2600A (config)#interface FastEthernet 1/0
R2600A (config-if)# ip nat inside
R2600A (config)#interface serial 1/2
R2600A (config-if)# ip nat outside
R2600A (config)#router ospf
R2600A (config-router)# default-information originate always
R2600A (config-router)# network 192.168.100.2 0.0.0 .255 area 0
R2600A (config-router)# network 192.168.200.2 0.0.0 .255 area 0