企业网实例.docx
- 文档编号:11337916
- 上传时间:2023-02-28
- 格式:DOCX
- 页数:17
- 大小:52.56KB
企业网实例.docx
《企业网实例.docx》由会员分享,可在线阅读,更多相关《企业网实例.docx(17页珍藏版)》请在冰豆网上搜索。
企业网实例
3750不能做NAT吧,你可以参考以下配置,也许对您会有帮助。
IP规划
vlnaIDip网段vlan网关
vlan1172.16.1.0/24172.16.1.7-9
vlan2172.16.2.0/24172.16.2.252-254
vlan3172.16.3.0/24172.16.3.252-254
vlan4172.16.4.0/24172.16.4.252-254
vlan5172.16.5.0/24172.16.5.252-254
vlan6172.16.6.0/24172.16.6.252-254总裁室
vlan7172.16.7.0/24172.16.7.252-254财务部
vlan8172.16.8.0/24172.16.8.252-254服务器群
vlan9172.16.9.0/24172.16.9.252-254
要求只有总裁室可以访问财务部。
路由器配置:
servicepassword-encryption
!
hostnamecisco2621
!
enablesecret654321
enablepassword123456
!
ipsubnet-zero
noipdomain-lookup
ipname-server202.96.134.133
ipname-server202.96.128.68
!
!
!
!
interfaceFastEthernet0/0
ipaddress172.16.9.250255.255.255.0
speedauto
ipnatinside
ipaccess-group101in
noshutdown
!
interfaceSerial0/0
bandwidth2048
ipaddress61.142.221.225255.255.255.240
encapsulationppp
innatoutside
noshutdown
ipnatpoolinternet61.142.221.22661.142.221.227netmask255.255.255.252
ipnatinsidesourcelist1poolinternetoverload
ipnatinsidesourcestatictcp172.16.8.68061.142.221.23180
ipnatinsidesourcestatictcp172.16.8.644361.142.221.231443
ipnatinsidesourcestatictcp172.16.8.72561.142.221.23325
ipnatinsidesourcestatictcp172.16.8.711061.142.221.233110
time-rangedaytime
periodicweekday8:
00to17:
30
arp172.16.7.810005.0298.7385ARPA
arp172.16.7.8500A7.C963.FD8AARPA
access-list1permit172.16.0.00.0.255.255
access-list101permitiphost172.16.7.81any
access-list101permitiphost172.16.7.85any
access-list101denyicmpanyany
access-list101permittcphost172.16.8.2anyeq53
access-list101permitudphost172.16.8.2anyeq53
access-list101permitiphost172.16.5.1any
access-list101permittcp172.16.4.10.0.0.31anyeq80
access-list101permittcp172.16.4.10.0.0.31anyeq443
access-list101permittcp172.16.4.10.0.0.31anyeq21
access-list101permittcp172.16.4.10.0.0.31anyeq25
access-list101permittcp172.16.4.10.0.0.31anyeq110
access-list101permittcp172.16.4.10.0.0.31anyeq53
access-list101permitudp172.16.4.10.0.0.31anyeq53
access-list101permittcp172.16.4.10.0.0.31anyeq1860
access-list101permittcp172.16.4.10.0.0.31anyeq7788
access-list101permitudp172.16.4.10.0.0.31anyeq7788
access-list101permittcp172.16.4.10.0.0.31anyeq8000
access-list101permitudp172.16.4.10.0.0.31anyeq8000
access-list101permittcphost172.16.7.83anyeq80
access-list101permittcphost172.16.7.83anyeq443
access-list101permittcphost172.16.7.83anyeq21
access-list101permittcphost172.16.7.83anyeq25
access-list101permittcphost172.16.7.83anyeq110
access-list101permittcphost172.16.7.83anyeq53
access-list101permitudphost172.16.7.83anyeq53
access-list101permittcphost172.16.7.83anyeq1860
access-list101permittcphost172.16.7.83anyeq7788
access-list101permitudphost172.16.7.83anyeq7788
access-list101permittcphost172.16.7.83anyeq8000
access-list101permitudphost172.16.7.83anyeq8000
access-list101permittcphost172.16.7.89anyeq80
access-list101permittcphost172.16.7.89anyeq443
access-list101permittcphost172.16.7.89anyeq21
access-list101permittcphost172.16.7.89anyeq25
access-list101permittcphost172.16.7.89anyeq110
access-list101permittcphost172.16.7.89anyeq53
access-list101permitudphost172.16.7.89anyeq53
access-list101permittcphost172.16.7.89anyeq1860
access-list101permittcphost172.16.7.89anyeq7788
access-list101permitudphost172.16.7.89anyeq7788
access-list101permittcphost172.16.7.89anyeq8000
access-list101permitudphost172.16.7.89anyeq8000
access-list101permittcphost172.16.4.135ancyeq80time-rangedaytime
access-list101permittcphost172.16.4.135ancyeq443time-rangedaytime
access-list101permittcphost172.16.4.135ancyeq21time-rangedaytime
access-list101permittcp172.16.8.00.0.0.255anyeq80
access-list101permittcp172.16.8.00.0.0.255anyeq443
access-list101permittcp172.16.8.00.0.0.255anyeq25
access-list101permittcp172.16.8.00.0.0.255anyeq110
access-list101permittcp172.16.8.00.0.0.255anyeq21
access-list101denyipanyany
routerrip
version2
network172.16.0.0
ipclassless
iproute172.16.0.0.255.255.0.0172.16.9.254
iproute0.0.0.00.0.0.0Serial0
iphttpserver
!
!
!
linecon0
lineaux0
linevty04
password123456
login
!
end
copyrunning-configstartup-config
交换机配置
一、Catalyst3550-12T1交换机配置:
Enable
Configureterminal
servicepad
servicepassword-encryption
hostnameCatalyst3550-12T1
enablepassword123456.
Enablesecret654321
Ipsubnet-zero
Ipname-server172.16.8.1172.16.8.2
Servicedhcp
Ipdhcprelayinformationoption
iprouting
Exit
Vlandatabase
Vtpmodeserver
Vtpdomaincentervtp
Vlan2namevlan2
Vlan3namevlan3
Vlan4namevlan4
Vlan5namevlan5
Vlan6namevlan6
Vlan7namevlan7
Vlan8namevlan8
Vlan9namevlan9
Exit
Configureterminal
interfacePort-channel1
switchporttrunkencapsulationdot1q
switchportmodetrunk
switchporttrunkallowedvlanall
Interfacegigabitethernet0/1
switchporttrunkencapsulationdotlq
switchportmodetrunk
switchporttrunkallowedvlanall
channel-group1modeon
Interfacegigabitethernet0/2
switchporttrunkencapsulationdotlq
switchportmodetrunk
switchporttrunkallowedvlanall
channel-group1modeon
port-channelload-balancesrc-dst-ip
interfacegigabitethernet0/3
switchporttrunkencapsulationdotlq
switchportmodetrunk
switchporttrunkallowedvlanall
interfacegigabitethernet0/4
switchporttrunkencapsulationdotlq
switchportmodetrunk
switchporttrunkallowedvlanall
interfacegigbitethernet0/5
switchporttrunkencapsulationdotlq
switchportmodetrunk
switchporttrunkallowedvlanall
interfacegigbitethernet0/6
switchporttrunkencapsulationdotlq
switchportmodetrunk
switchprottrunkallowedvlanall
interfacegigbitethernet0/7
Switchportmodeaccess
switchportaccessvlan9
noshutdown
spanning-treevlan6-9cost1000
interfacerangegigabitethernet0/8–10
switchportmodeaccess
switchportaccessvlan8
noshutdown
spanning-treeportfast
interfacegigabitethernet0/11
switchporttrunkencapsulationdotlq
switchportmodetrunk
switchporttrunkallowedvlanall
interfacegigabitethernet0/12
switchporttrunkencapsulationdotlq
switchportmodetrunk
switchporttrunkallowedvlanall
spanning-treevlan1-9rootprimary
spanning-treebackbonefast
interfacevlan1
ipaddress172.16.1.7255.255.255.0
noshutdown
standby1ip172.16.1.9
standby1priority110preempt
interfacevlan2
ipaddress172.16.2.252255.255.255.0
noshutdown
standby2ip172.16.2.254
standby2priority110preempt
ipaccess-group101in
interfacevlan3
ipaddress172.16.3.252255.255.255.0
noshutdown
standby3ip172.16.3.254
standby3priority110preempt
ipaccess-group101in
interfacevlan4
ipaddress172.16.4.252255.255.255.0
noshutdown
standby4ip172.16.4.254
standby4priority110preempt
ipaccess-group101in
interfacevlan5
ipaddress172.16.5.252255.255.255.0
noshutdown
standby5ip172.16.5.254
standby5priority110preempt
ipaccess-group101in
interfacevlan6
ipaddress172.16.6.252255.255.255.0
noshutdown
standby6ip172.16.6.254
standby6priority100preempt
interfacevlan7
ipaddress172.16.7.252255.255.255.0
noshutdown
standby7ip172.16.7.254
standby7priority100preempt
interfacevlan8
ipaddress172.16.8.252255.255.255.0
noshutdown
standby8ip172.16.8.254
standby8priority100preempt
interfacevlan9
ipaddress172.16.9.252255.255.255.0
noshutdown
standby9ip172.16.9.254
standby9priority100preempt
access-list101denyipany172.16.7.00.0.0.255
access-list101permitipanyany
Interfacevlan1
Iphelper-address172.16.8.1
Interfacevlan2
Iphelper-address172.16.8.1
Interfacevlan3
iphelper-address172.16.8.1
interfacevlan4
iphelper-address172.16.8.1
interfacevlan5
iphelper-address172.16.8.1
interfacevlan6
iphelper-address172.16.8.1
interfacevlan7
iphelper-address172.16.8.1
interfacevlan9
iphelper-address172.16.8.1
routerrip
version2
network172.16.0.0
exit
arp172.16.7.810005.0298.7385ARPA
arp172.16.7.8500A7.C963.FD8AARPA
ipclassless
iproute0.0.0.00.0.0.0172.16.9.250
linecon0
lineaux0
linevty015
password12345678
login
end
copyrunning-configstartup-config
二、Catalyst3550-12T2交换机配置:
Enable
Configureterminal
servicepad
servicepassword-encryption
hostnamec3550-12t2
enablepassword123456
enablesecret654321
ipsubnet-zero
ipname-server172.16.8.1.172.16.8.2
servicedhcp
ipdhcprelayinformationoption
iprouting
exit
vlandatabase
vtpmodeserver
vtpdomaincentervtp
vlan2namevlan2
vlan3namevlan3
vlan4namevlan4
vlan5namevlan5
vlan6namevlan6
vlan7namevlan7
vlan8namevlan8
vlan9namevlan9
exit
configureterminal
interfacePort-channel1
switchporttrunkencapsulationdot1q
switchportmodetrunk
switchporttrunkallowedvlanall
interfacegigabitethernet0/1
switchportencapsulationdotlq
switchportmodetrunk
swithchporttrunkallowedvlanall
channel-group1modeon
interfacegigabitethernet0/2
switchportencapsulationdotlq
switchportmodetrunk
swithchporttrunkallowedvlanall
channel-group1modeon
port-channelload-balancesrc-dst-ip
exit
interfacegigabitethernet0/3
switchporttrunkencapsulationdotlq
switchportmodetrunk
swithcporttrunkallowedvlanall
interfacegigabitethernet0/4
s
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- 企业 实例