《实验-CISCO.docx》由会员分享,可在线阅读,更多相关《实验-CISCO.docx(41页珍藏版)》请在得力文库 - 分享文档赚钱的网站上搜索。
1、编号:时间:2021年x月x日书山有路勤为径,学海无涯苦作舟页码:第41页 共41页难度110分1、2、3、4、5难度315分6、6、8、9、10难度515分11、12、13、14、15一、请按要求完成静态、默认路由的相关配置(难度等级1)。根据下图所示(以下的设备均为CISCO设备),完成静态路由的相关配置。实验要求:1、配置路由器R1、R2和R3的网络接口地址,地址分配如下表所示:设备接口IP 地址子网掩码网关备注R1Fa0/0172.16.3.1255.255.255.0不适用R1S1/0172.16.2.1255.255.255.0不适用R2Fa0/0172.16.1.1255.255
2、.255.0不适用R2S1/0172.16.2.2255.255.255.0不适用R2S1/1192.168.1.2255.255.255.0不适用R3Fa0/0192.168.2.1255.255.255.0不适用R3S1/1192.168.1.1255.255.255.0不适用PC1网卡172.16.3.11255.255.255.0172.16.3.1已完成配置PC2网卡172.16.1.11255.255.255.0172.16.1.1已完成配置PC3网卡192.168.2.11255.255.255.0192.168.2.1已完成配置2、配置静态路由及默认路由。3、实现全网互通,并保
3、存配置。得分点:操作内容分数10关键字配置各接口地址3ip add 静态路由配置3ip route 172.16.3.0 255.255.255.0 172.16.2.1ip route 192.168.2.0 255.255.255.0 192.168.1.1默认路由配置3ip route 0.0.0.0 255.255.255.0 192.168.1.2答案:R1配置:RouterenRouterenableRouter#confRouter#configure tRouter#configure terminalRouter(config)#hostRouter(config)#host
4、name R1Router(config)#hostname R1 命名R1(config)#no ip domain-lookup 容错R1(config)#line con 0 进入consolR1(config-line)#logging syn 日志同步R1(config-line)#exec-timeout 0 延时为0R1(config)#interface s1/0 进入串口R1(config-line)#description linkto R2-s1/0 说明路径R1(config-if)#no shutdown 打开端口!interface fa0/0ip address
5、172.16.3.1 255.255.255.0no shutdown!interface s1/0ip address 172.16.2.1 255.255.255.0clock rate 64000 no shutdown!ip route 0.0.0.0 255.255.255.0 172.16.2.2!R2配置:!interface fa0/0ip address 172.16.1.1 255.255.255.0no shutdown!interface s1/0ip address 172.16.2.2 255.255.255.0clock rate 64000no shutdown
6、!interface s1/1ip address 192.168.1.2 255.255.255.0clock rate 64000 no shutdown!ip route 172.16.3.0 255.255.255.0 172.16.2.1ip route 192.168.2.0 255.255.255.0 192.168.1.1!R3配置:!interface fa0/0ip address 192.168.2.1 255.255.255.0no shutdown!interface s1/1ip address 192.168.1.1 255.255.255.0no shutdow
7、n!ip route 0.0.0.0 255.255.255.0 192.168.1.2!二、EthernetChannel基本配置(难度1)根据下图所示(以下所有设备均为CISCO设备),完成EthernetChannel基础配置。要求:1、将两台交换机的F0/2,F0/3绑定一个EthernetChannel,mode为on 状态;2、验证EthernetChannel配置的正确性。操作内容分数10关键字接口配置3switchport mode trunk接口配置3channel-group 1 mode onPort-channel配置4interface port-channel 1s
8、witchport mode trunk答案:SW1的配置:!interface port-channel 1 switchport mode trunk no shutinterface FastEthernet 0/2 channel-group 1 mode on switchport mode trunk no shutint FastEthernet 0/3 channel-group 1 mode on switchport mode trunk no shut!SW2的配置:!interface port-channel 1 switchport mode trunk no sh
9、ut!interface FastEthernet 0/2 channel-group 1 mode on switchport mode trunk no shut!int FastEthernet 0/3 channel-group 1 mode on switchport mode trunk no shut!三、Trunk基本配置(难度1)根据下图所示(以下所有设备均为CISCO设备),完成Trunk基础配置。要求:1、SW1上分别有VLan10、20,SW2上有VLAN10,PC1/PC3属于VLAN10,PC2属于VLAN20;2、SW1、SW2之间配置Trunk,实现不同的VlA
10、N相互通信。操作内容分数10关键字VLAN 配置3vlan 10,vlan 20 ;int vlan ip addressVLAN划分3switchport mode accessswitchport access vlan 10Trunk启用、并保证不同VLAN将的PC互通4interface Fastethernet0/1switchport trunk encapsulation dot1qswitchport mode trunk互ping答案:SW1的配置:!ip routing!vlan 10name jiguan!vlan 20name shengchan!int vlan 10
11、ip address 192.168.10.1 255.255.255.0no shut!nt vlan 20ip address 192.168.20.1 255.255.255.0no shut!interface Fastethernet0/1switchport trunk encapsulation dot1q 启用1q模式封装switchport mode trunk 选择路由为trunk模式no shutswitchport trunk allowed vlan10,20 连通vlan10 20!interface Fastethernet0/2switchport mode a
12、ccess 连接模式switchport access vlan 10no shut!interface Fasetethernet0/3switchport mode accessswitchport mode accessswitchport access vlan 20no shut!SW2配置:!ip routing!vlan 10vlan 20!interface vlan 10ip address 192.168.10.2 255.255.255.0no shut!interface Fastethernet0/1switchport trunk encapsulation dot
13、1qswtichport mode trunkno shut!interface Fastethernet0/2switchport mode accessswitchport access vlan 10no shut!四、CHAP 认证基本配置(难度1)要求:1、使用“username 用户名 password 密码” 命令为对方配置用户名和密码,注意:两方的密码要相同。2、在路由器R1、R2串口上配置PPP封装,并配置 CHAP身份验证。3、验证否配置成功。操作内容分数10关键字接口 配置3ip address 使用用户名密码3username XX password cisco在两台设
14、备启用PPP封装,并配置CHAP身份验证4interface s0/0encapsulation pppppp authentication chap答案:R1的配置!sh run 查看配置interface s1/0ip address 192.168.12.1 255.255.255.252no shut!username R1 password ciscousername cisco password cisco (可不用这句)no ip domain-lookup!interface s1/0 description linkto R2-s1/0ip address 192.168.1
15、2.1 255.255.255.252no shutencapsulation ppp 启用PPP协议ppp authentication chap 验证PPP命令!Line con 0Exec-timeout 0 0 Password ciscoLogin local 本地启用!Line vty 0 4 配置过程登陆Password ciscoLogin local 本地启用R2的配置!interface s0/0ip address 192.168.12.2 255.255.255.252no shut!username R2 password cisco!interface s0/0en
16、capsulation pppppp authentication chap!End路由重启后生效测试命令: debug ppp authentication关闭测试命令: no debug ppp authentication五、EIGRP手工汇总(难度1)要求:1、完成拓扑图上所标识接口地址的配置工作,注意子网掩码的划分。2、路由器R1、R2 和R3 之间运行EIGRP,进程10,关闭自动汇总功能。3、在路由器R3 上将四个回环地址做手工路由汇总,在R1上查看路由学习情况,并实现全网互通。操作内容分数10关键字接口 配置3ip address EIGRP协议的运行3router eigrp
17、 10 network 1.1.1.0 0.0.0.255 network 192.168.12.0 no auto-summary在R3上的Serial0/1上做手工汇总4interface Serial0/1 ip summary-address eigrp 10 3.3.0.0 255.255.252.0 5答案:R1的配置:!interface Loopback0 ip address 1.1.1.1 255.255.255.0!interface Serial0/0 ip address 192.168.12.1 255.255.255.0no shut!router eigrp 1
18、0 network 1.1.1.0 0.0.0.255 network 192.168.12.0 no auto-summary!R2的配置!interface Loopback0 ip address 2.2.2.2 255.255.255.0!interface Serial0/0 ip address 192.168.12.2 255.255.255.0!interface Serial0/1 ip address 192.168.23.2 255.255.255.0 no shut!router eigrp 10 network 192.168.12.0 network 192.168
19、.23.0 network 2.2.2.0 0.0.0.255 no auto-summary!R3的配置:!interface Loopback0 ip address 3.3.0.3 255.255.255.0!interface Loopback1 ip address 3.3.1.3 255.255.255.0!interface Loopback2 ip address 3.3.2.3 255.255.255.0!interface Loopback3 ip address 3.3.3.3 255.255.255.0!interface Serial0/1 ip address 19
20、2.168.23.3 255.255.255.0 ip summary-address eigrp 10 3.3.0.0 255.255.252.0 5 no shut!router eigrp 10 network 192.168.23.0 network 3.3.0.0 0.0.3.255 no auto-summary!六、RIPv2和OSPF的重分布实验,(难度等级3)。根据下图所示(以下的设备均为CISCO设备),请进行路由重发布配置;要求:1、每台路由器接口、环回口配置正确的IP地址,地址分配如下表所示:设备接口IP 地址备注R1F0/0192.168.12.1/24R1Loopb
21、ack01.1.1.1/24R1Loopback11.1.2.1/24R2F0/0192.168.12.2/24R2F0/1192.168.23.2/24R2Loopback02.2.2.2/24R3F0/1192.168.23.3/24R3Loopback03.3.3.3/242、三台路由器,R1运行RIPV2,R2运行RIPV2和OSPF,R3运行OSPF,进程号100,Area 0。3、在R2中重分布RIP协议和OSPF协议,查看各自路由表的状态。4、实现全网互联,并保存配置。操作内容分数15关键字接口配置3ip address 根据图的提示完成RIP路由协议的运行4router rip
22、 version 2 network 1.0.0.0 network 192.168.12.0 no auto-summary根据图的提示完成RIP、OSPF路由协议的运行4router ospf 100 router-id X.X.X.X /路由器Lop0地址 network 2.2.2.0 0.0.0.255 area 0 network 192.168.23.0 0.0.0.255 area 0在R2上的上做路由重分布4router ospf 100redistribute rip subnets router rip redistribute ospf 100 metric 3答案:R
23、1配置:!interface Loopback0 ip address 1.1.1.1 255.255.255.0!interface Loopback1 ip address 1.1.2.1 255.255.255.0!interface FastEthernet0/0 ip address 192.168.12.1 255.255.255.0 no shut!router rip version 2 network 1.0.0.0 network 192.168.12.0 no auto-summary!R2配置:!interface Loopback0 ip address 2.2.2.
24、2 255.255.255.0!interface FastEthernet0/0 ip address 192.168.12.2 255.255.255.0 no shut!interface FastEthernet0/1 ip address 192.168.23.2 255.255.255.0 no shut!router ospf 100 router-id 2.2.2.2redistribute rip subnets network 2.2.2.0 0.0.0.255 area 0 network 192.168.23.0 0.0.0.255 area 0!router rip
25、version 2 redistribute ospf 100 metric 3 network 192.168.12.0 no auto-summary!R3配置:!interface Loopback0 ip address 3.3.3.3 255.255.255.0!interface FastEthernet0/1 ip address 192.168.23.3 255.255.255.0no shut!router ospf 100router-id 3.3.3.3network 3.3.3.0 0.0.0.255 area 0 network 192.168.23.0 0.0.0.
26、255 area 0!七、PAT配置(难度3)要求:1、路由器R1、R2接口s0/0地址分别配置10.10.10.1/10.10.10.2;R1的F0/0配置192.168.1.254/24。2、把内部地址映射到外部网络的IP 地址的不同端口上,从而可以实现多对一的映射。3、内网地址为192.168.1.0/24,映射为10.10.10.3,使用相关show 命令检查PAT配置的正确性。4、两台路由器之间使用RIPv2协议,关闭路由汇总的命令,实现内网PC能ping通R2上的2.2.2.2地址。操作内容分数15关键字接口配置2ip address 路由协议配置3router rip versi
27、onnetworkno auto-summary配置访问控制列表3access-list 1 permi配置NAT地址池4p nat pool NAT 10.10.10.3 10.10.10.3 netmask 255.255.255.0ip nat inside source list 1 pool NAT overloa配置NAT地址转换3ip nat outsideip nat inside答案:R1的配置 !interface s0/0ip address 10.10.10.1 255.255.255.0ip nat outsideno shut!ip nat pool NAT 10.
28、10.10.3 10.10.10.3 netmask 255.255.255.0ip nat inside source list 1 pool NAT overloadaccess-list 1 permit 192.168.1.0 0.0.0.255!interface f0/0ip address 192.168.1. 254 255.255.255.0ip nat insideinterface s0/0!router rip version 2 network 10.0.0.0 no auto-summary!R2的配置:!interface Loopback0 ip address
29、 2.2.2.2 255.255.255.0!interface s0/0ip address 10.10.10.2 255.255.255.0no shut!router ripversion 2no auto-summarynetwork 10.10.10.0network 2.0.0.0!八、OSPF完全末梢区域(难度3)根据下图所示(以下所有设备均为CISCO设备),完成OSPF完全末梢区域的配置。要求:1、分配为四台路由器配置IP地址、Lop地址,地址分配如下表所示:设备接口IP 地址区域R1S0/0192.168.12.1/24Area 1R1Lop01.1.1.1/24Area
30、1R2S0/0192.168.12.2/24Area 1R2S0/1192.168.23.2/24Area 0R2Lop02.2.2.2/24Area 0R3S0/1192.168.23.3/24Area 0R3S0/0192.168.34.3/24Area 2R3Lop03.3.3.3/24Area 2R4S0/0192.168.34.4/24Area 2R4Lop04.4.4.4Area 22、R1、R2、R3、R4之间运行OSPF协议,进程号100, R1、R2区域Area 1,R2、R位于Area0、R3、R4位于Area 2;3、按图上的标识,末节区域、完全末节区域的配置;4、实现全
31、网互通,并在R1、R4上查看路由学习情况,并保证配置;操作内容分数15关键字接口配置3ip address 路由协议配置4router ospf 100 router-idnetwork末节区域4router ospf 100 area 1 stub完全末节区域4outer ospf 100 area 2 stub答案:R1配置:!interface Loopback0 ip address 1.1.1.1 255.255.255.0!interface Serial0/0 ip address 192.168.12.1 255.255.255.0 no shut!router ospf 10
32、0 router-id 1.1.1.1area 1 stub network 1.1.1.0 0.0.0.255 area 1 network 192.168.12.0 0.0.0.255 area 1!R2配置:!interface Loopback0 ip address 2.2.2.2 255.255.255.0!interface Serial0/0 ip address 192.168.12.2 255.255.255.0 no shut!interface Serial0/1 ip address 192.168.23.2 255.255.255.0no shut!router o
33、spf 100 router-id 2.2.2.2 area 1 stub network 2.2.2.0 0.0.0.255 area 0 network 192.168.23.0 0.0.0.255 area 0 network 192.168.12.0 0.0.0.255 area 1!R3的配置!interface Loopback0 ip address 3.3.3.3 255.255.255.0!interface Serial0/0 ip address 192.168.34.3 255.255.255.0 no shut!interface Serial0/1 ip addre
34、ss 192.168.23.3 255.255.255.0 no shut!router ospf 100 router-id 3.3.3.3area 2 stub no-summary network 3.3.3.0 0.0.0.255 area 0 network 192.168.23.0 0.0.0.255 area 0 network 192.168.34.0 0.0.0.255 area 2!R4配置!interface Loopback0 ip address 4.4.4.4 255.255.255.0!interface Serial0/0 ip address 192.168.
35、34.4 255.255.255.0 no shut!router ospf 100 router-id 4.4.4.4area 2 stub network 4.4.4.0 0.0.0.255 area 2 network 192.168.34.0 0.0.0.255 area 2!九、ERIGP及ACL配置实验(难度3)要求:1、整个网络配置EIGRP,进程10,关闭自动汇总功能。2、拒绝PC2 所在网段禁止访问路由器R2,同时只允许主机PC1 访问路由器R2 的telnet服务,其他功能正常访问。操作内容分数15关键字接口配置3ip address 路由协议配置4router eigrp
36、 10 network禁止PC2访问路由器R24access-list 1 deny access-list 1 permit any interface Serial0/0 ip access-group 1 in允许主机PC1 访问路由器R2 的telnet4access-list 2 permit 10.1.1.0 0.0.0.255line vty 0 4 access-class 2 in答案:R1的配置:!interface FastEthernet0/0 ip address 10.1.1.254 255.255.255.0 no shut!interface FastEther
37、net0/1 ip address 172.16.1.254 255.255.255.0 no shut!interface Serial0/0 ip address 192.168.12.1 255.255.255.252 no shut!router eigrp 10 network 192.168.12.0 0.0.0.3 network 172.16.1.0 0.0.0.255 network 10.1.1.0 0.0.0.255 no auto-summary! R2的配置:!interface Loopback0 ip address 2.2.2.2 255.255.255.0!i
38、nterface Serial0/0 ip address 192.168.12.2 255.255.255.252 no shut ip access-group 1 in!router eigrp 10 network 2.2.2.0 0.0.0.255 network 192.168.12.0 0.0.0.3 no auto-summary!access-list 1 deny 172.16.1.0 0.0.0.255access-list 1 permit anyaccess-list 2 permit 10.1.1.0 0.0.0.255!line vty 0 4 access-cl
39、ass 2 in password cisco login!十、OSPF多区域配置(难度5)要求:1、4个路由器按图上标示的IP地址进行配置,并配置各个环回口地址。2、4个路由器都配置OSPF路由协议,进程号为100;R1、R2之间为Area1,R2、R3之间为Area 0,R3、R4之间为Area 2。3、配置时采用环回接口尽量靠近区域0 的原则。路由器R4 的环回接口不在OSPF 进程中通告,通过重分布的方法进入OSPF 网络。4、完成以上要求,并查看路由学习情况,了解OSPF不同区域之间的路由学习情况。操作内容分数15关键字接口配置3ip address 路由协议配置4router os
40、pf 100区域1配置4network 1.1.1.0 0.0.0.255 area 1区域2配置4network 192.168.34.0 0.0.0.255 area 2答案:R1的配置:!interface Loopback0 ip address 1.1.1.1 255.255.255.0!interface Serial0/0 ip address 192.168.12.1 255.255.255.0 no shut!router ospf 100 router-id 1.1.1.1network 1.1.1.0 0.0.0.255 area 1 network 192.168.12
41、.0 0.0.0.255 area 1!R2的配置:!interface Loopback0 ip address 2.2.2.2 255.255.255.0!interface Serial0/0 ip address 192.168.12.2 255.255.255.0 no shut!interface Serial0/1 ip address 192.168.23.2 255.255.255.0 no shut!router ospf 100 router-id 2.2.2.2network 2.2.2.0 0.0.0.255 area 0 network 192.168.23.0 0
42、.0.0.255 area 0 network 192.168.12.0 0.0.0.255 area 1!R3的配置:!interface Loopback0 ip address 3.3.3.3 255.255.255.0!interface Serial0/0 ip address 192.168.34.3 255.255.255.0 no shut!interface Serial0/1 ip address 192.168.23.3 255.255.255.0 no shut!router ospf 100 router-id 3.3.3.3network 3.3.3.0 0.0.0
43、.255 area 0 network 192.168.23.0 0.0.0.255 area 0 network 192.168.34.0 0.0.0.255 area 2!R4的配置:!interface Loopback0 ip address 4.4.4.4 255.255.255.0!interface Serial0/0 ip address 192.168.34.4 255.255.255.0 no shut!router ospf 100 router-id 4.4.4.4redistribute connected subnets network 192.168.34.0 0.0.0.25