NAT 網絡地址轉換 eigrp ospf 路由重分佈 DHCP

網絡互連要求:

  1. 規劃和設計各路由接口的IP地址
  2. 除了路由器R4的G0/1、G0/2兩個接口外,在其它路由器的所有接口上使用EIGRP動態路由協議進行子網互連,自治系統編號AS爲2332;
  3. 在路由器R4的G0/1、G0/2兩個接口,及三層交換機的所有網段上啓用OSPF動態路由協議,且都指定爲區域0,進程號都指定爲100;
  4. 在S1 、S1的接口F0/2F0/3上,設置交換機端口聚合,聚合後的接口PO1設置爲TRUNK模式;
  5. 在S1 、S1上創建VLAN 4和VLAN 5,並在S1上設置這兩個VLAN的地址分別爲192.168.4.254/24、192.168.5.254/24; 在S2上設置這兩個VLAN的地址分別爲192.168.4.253/24、192.168.5.253/24;
  6. 在S1上爲VLAN 4和VLAN 5的計算機創建DHCP服務,實現IP地址自動分配服務;
  7. 在路由器R4上使用地址轉換技術,使內網VLAN 4和VLAN 5的地址可以訪問外網的任何IP和服務;
  8. 外網只能訪問服務器192.168.3.1 上的WWW服務(http協議);
  9. 外網上的地址202.16.13.1對應內網的計算機PC1(設地址爲192.168.4.1);

網絡拓撲圖:

代碼:

R1:
En
Conf t
Host r1
No ip domain-lookup
Int g0/0
Ip address 202.16.2.1 255.255.255.0
No shut
Int g0/1
Ip address 202.16.1.254 255.255.255.0
No shut
Int g0/2
Ip address 202.16.13.13 255.255.255.0
No shut
Int loopback 0
Ip address 1.1.1.1 255.255.255.255
No shut
Exit
Router eigrp 2332
Network 202.16.2.0 0.0.0.255
Network 202.16.1.0 0.0.0.255
Network 202.16.13.0 0.0.0.255
No auto-summary
 
R2:
En
Conf t
Host r2
No ip domain-lookup
Int g0/0
Ip address 202.16.2.2 255.255.255.0
No shut
Int s0/3/0
Clock rate 2000000
Ip address 202.16.3.5 255.255.255.0
No shut
Int loopback 0
Ip address 2.2.2.2 255.255.255.255
No shut
Exit
Router eigrp 2332
Network 202.16.2.0 0.0.0.255
Network 202.16.3.0 0.0.0.255
No auto-summary

R3:
En
Conf t
Host r3
No ip domain-lookup
Int s0/3/0
Ip address 202.16.3.6 255.255.255.0
No shut
Int s0/3/1
Ip address 62.16.3.10 255.255.255.0
No shut
Int loopback 0
Ip address 3.3.3.3 255.255.255.255
No shut
Exit
Router eigrp 2332
Network 202.16.3.0 0.0.0.255
Network 62.16.3.0 0.0.0.255
No auto-summary

R4:
En
Conf t
Host r4
No ip domain-lookup
Int g0/0
Ip address 202.16.13.14 255.255.255.0
No shut
Int g0/1
Ip address 192.168.1.1 255.255.255.252
No shut
Int g0/2
Ip address 192.168.2.1 255.255.255.252
No shut
Int s0/3/0
Ip address 62.16.3.9 255.255.255.0
No shut
Int loopback 0
Ip address 4.4.4.4 255.255.255.255
No shut
Exit
Router eigrp 2332
Network 202.16.13.0 0.0.0.255
Network 62.16.3.0 0.0.0.255
No auto-summary
Exit
Router ospf 100
Network 192.168.1.0 0.0.0.3 area 0
Network 192.168.2.0 0.0.0.3 area 0
Redistribute eigrp 2332 metric 3 subnets
Exit
!地址轉換
!指定轉換的外口
int g0/0
ip nat outside
int s0/3/0
ip nat outside
!指定轉換的內口
int range g0/1-2
ip nat inside
Exit
!指定地址轉換外部地址池
ip nat pool global 202.16.13.15 202.16.13.18 netmask 255.255.255.0
!指定地址轉換內部地址池
access-list 1 permit 192.168.1.0 0.0.0.3
access-list 1 permit 192.168.2.0 0.0.0.3
access-list 1 permit 192.168.3.0 0.0.0.255
access-list 1 permit 192.168.4.0 0.0.0.255
access-list 1 permit 192.168.5.0 0.0.0.255
!執行NAT指定地址轉換內部地址池
ip nat inside source list 1 pool global overload
!利用NAT實現外網訪問內網服務器上特定的應用;
!允許公網訪問內網特定主機上的WEB應用(WWW服務)(TCP 80端口號)
ip nat inside source static tcp 192.168.3.1 80 202.16.13.19 80
!指定NAT地址轉換外部地址和內部地址的對應關係(靜態地址轉換一對一)
!外網和內網地址的一一綁定
ip nat inside source static 192.168.4.1 202.16.13.1

S1:
En
Conf t
Host s1
No ip domain-lookup
Int range f0/2-3
Channel-group 1 mode desirable
Switchport mode access
Switchport mode trunk
Exit
Vlan 4
Exit
Vlan 5
Exit
Int vlan 4
Ip address 192.168.4.254 255.255.255.0
Int vlan 5
Ip address 192.168.5.254 255.255.255.0
Int f0/1
No switchport
Ip address 192.168.1.2 255.255.255.252
No shut
Int f0/4
Switchport access vlan 4
Int f0/5
Switchport access vlan 5
Exit
Ip routing
Router ospf 100
Network 192.168.1.0 0.0.0.3 area 0
Network 192.168.4.0 0.0.0.255 area 0
Network 192.168.5.0 0.0.0.255 area 0
Exit
service dhcp
!啓動dhcp服務
ip dhcp excluded-address 192.168.4.253 192.168.4.254
!排除不拿來分配的地址192.168.4.253 到192.168.4.254的所有
ip dhcp pool vlan4
!建立一個地址池,名字由字母加數字構成
network 192.168.4.0 255.255.255.0
default-router 192.168.4.254
!指定客戶機的網關地址
dns-server 8.8.8.8
!給定客戶機dns服務器地址,8.8.8.8是google的
exit
ip dhcp excluded-address 192.168.5.253 192.168.5.254
ip dhcp pool vlan5
network 192.168.5.0 255.255.255.0
default-router 192.168.5.254
dns-server 114.114.114.114
! 114.114.114.114這個是中國電信的
exit

S2:
En
Conf t
Host s2
No ip domain-lookup
Int range f0/2-3
Channel-group 1 mode desirable
Switchport mode access
Switchport mode trunk
Exit
Vlan 4
Exit
Vlan 5
Exit
Int vlan 4
Ip address 192.168.4.253 255.255.255.0
Int vlan 5
Ip address 192.168.5.253 255.255.255.0
Int f0/1
No switchport
Ip address 192.168.2.2 255.255.255.252
No shut
Int f0/4
No switchport
Ip address 192.168.3.254 255.255.255.0
No shut
Exit
Ip routing
Router ospf 100
Network 192.168.2.0 0.0.0.3 area 0
Network 192.168.3.0 0.0.0.255 area 0
Network 192.168.4.0 0.0.0.255 area 0
Network 192.168.5.0 0.0.0.255 area 0
Exit

在外網的每一個路由器上配置Debug ip icmp:
en
Debug ip icmp

訪問外網結果:

PC1:

PC2:

PC B:

R2上配置Debug ip icmp:

PC A訪問服務器192.168.3.1上的WWW服務:

路由表:

路由表內網s1:

路由表外網r2:

發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章