hcie lab2需求與解法所有設(shè)備IP地址如圖為10 Y AB X24例如_第1頁(yè)
hcie lab2需求與解法所有設(shè)備IP地址如圖為10 Y AB X24例如_第2頁(yè)
hcie lab2需求與解法所有設(shè)備IP地址如圖為10 Y AB X24例如_第3頁(yè)
hcie lab2需求與解法所有設(shè)備IP地址如圖為10 Y AB X24例如_第4頁(yè)
hcie lab2需求與解法所有設(shè)備IP地址如圖為10 Y AB X24例如_第5頁(yè)
已閱讀5頁(yè),還剩36頁(yè)未讀, 繼續(xù)免費(fèi)閱讀

下載本文檔

版權(quán)說(shuō)明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)

文檔簡(jiǎn)介

IPinterfaceSerial1/0/erfaceSerial1/0/erfaceSerial2/0/erfaceGigabitEthernet0/0/erfaceSerial1/0/erfaceGigabitEthernet0/0/erfaceGigabitEthernet0/0/erfaceSerial1/0/erfaceGigabitEthernet0/0/erfaceGigabitEthernet0/0/erfaceSerial1/0/erfaceSerial1/0/erfaceGigabitEthernet0/0/erfaceGigabitEthernet0/0/erfaceSerial1/0/erfaceSerial1/0/erfaceGigabitEthernet0/0/erfaceGigabitEthernet0/0/erfaceSerial1/0/erfaceSerial1/0/erfaceipaddress255.255.255.VlanSysnamevlanbatch35 110113135222224255interfaceVlanif erfaceVlani erfaceGigabitEthernet0/0/1portlink-typeaccessportdefaultvlaninterfaceGigabitEthernet0/0/2portlink-typeaccessportdefaultvlan Sysnamevlanbatch35 110113135222224255interfaceVerfaceVerfaceGigabitEthernet0/0/2portlink-typeaccessportdefaultvlaninterfaceGigabitEthernet0/0/3portlink-typeaccessportdefaultvlaninterfaceGigabitEthernet0/0/4portlink-typeaccessportdefaultvlanSysnamevlanbatch35 110113135222224255interfaceVerfaceEthernet0/0/3portlink-typeaccessportdefaultvlan interfaceEthernet0/0/5portlink-typeaccessportdefaultvlan35interfaceEthernet0/0/22portlink-typeaccessportdefaultvlan255Sysnamevlanbatch35 110113135222224255interfaceEthernet0/0/5portlink-typeaccessportdefaultvlanSection1Layer日TrLNAC模LNLNSW1的GE0/0/13SW2的GE0/0/13,GE0/0/16連接SW3的Eth0/0/13,GE0019連接SW4的Eth0013。SW2的GE0016連接SW3的Eth0016,GE0019連接SW4的Eth0016。將上述W1、W2、W2、W4互連的接口修改為T(mén)runk類(lèi)型,允許除了LN1之外的所有LSW1:interfaceg0/0/13(g0/0/16)(g0/0/19)porttrunkpvid255portlink-typetrporttrunkall -passvlanSW2:interfaceg0/0/13(g0/0/16)(g0/0/19)porttrunkpvid255portlink-typetrporttrunkall -passvlanSW3:interface eth0/0/13(eth0/0/16)porttrunkpvid255portlink-typetrporttrunkall -passvlanSW4:interface eth0/0/13(eth0/0/16)porttrunkpvid255portlink-typetrporttrunkall -passvlan日在SW1、SW2、SW3都運(yùn)行MSTPVlan110Vlan135Vlan222Vlan224關(guān)聯(lián)到Instance10,SW1作為PrimaryRoot,SW2為SecondaryRoot。Vlan113Vlan35、Vlan255關(guān)聯(lián)到Instance20。SW2作為PrimaryRoot,SW1為SecondaryRootMstp的regionname 。Revision-l SW3上防止E0/0/24收到攜帶更高優(yōu)先級(jí)的BPDU而的根橋變化的危害SW1,SW2,stpmodemststpregion-configurationregion-namerevision-levelinstance10vlan110135222instance20vlan35113255activeregion-configurationstpinstance10rootprimarstpinstance20rootsecondarstpinstance10rootsecondarystpinstance20rootprimaryinterface eth0/0/24stproot-protectionSMART-日SW4通過(guò)Eth0013接口連接SW1的GE0/019接口,通過(guò)Eth0016接口連接SW2GE0019接口。Eth0013作為Master接口Eth0016作為Slave若SW4的Eth0013接口出現(xiàn)故障,流量自動(dòng)切換到Eth0016接口。Eth0013恢復(fù)正常后,流量在30s內(nèi)自動(dòng)切回。Vlan110作為ControlVerface eth0/0/13stpdisableinterface eth0/0/16stpdisablesmart-linkgroupport eth0/0/13masterport eth0/0/16slavesmart-linkenablerestoreenabltimerwtr ###缺省回切時(shí)間為60flushsendcontr -vlanSW1/interfaceg0/0/19stpdisablesmart-linkflushreceivecontr -vlan建議在SW4上先down掉0/13和0/16接口,完成后再開(kāi)啟該端口,避免出現(xiàn)mac翻動(dòng)FrameR1、R4、R5之間使用Frame-rel 進(jìn)行互連,Hub-Spoke模式R1在Hub端,R4、R5在Spoke端,所有Frame-rel 接口不能使用子接口,并且需要關(guān)閉自InverseARP功interfaceSerial1/0/0erfaceSerial1/0/0erfaceSerial1/0/0link-protocolfrundofrinarpfrmapip401brfrmapip401bripaddress255.255.255.

R1和R2通過(guò)串行鏈路互連,封裝類(lèi)型為PPPR1需要對(duì)R2進(jìn)行CHAP認(rèn)證,R1為認(rèn)證端。R2位被認(rèn)證端。驗(yàn)證的用戶名為chapuser,密碼為CHAP123,且需以密文顯示。2需要對(duì)R1認(rèn)證,21papuser,為123且以顯。interfaces1/0/pppauthenticati -modechapdomainppppaplocal-userpapuserpasswordcipherPAP123authentication-schemechapauthenticati -modeldomainauthenticati -schemelocal-userchapuserpasswordcipherCHAP123local-userchapuserservice -typepppinterfaces1/0/pppauthentication-modepapdomainppppappppchapuserchapuserpppchappasswordcipherCHAP123authentication-schemepapauthentication-modelocaldomainauthenticati -schemelocal-userpapuserpasswordcipherPAP123local-userpapuserservice-typepppBasic

代表你的CK,代表由號(hào),1備號(hào)12設(shè)編為2,1設(shè)編號(hào)為11,2備為2,他此推設(shè)之互網(wǎng)段IP地為4掩,有路由器擁Loopback0接口,I址為10...X,碼為32位4的Loopback1接口I地址為10.Y.40.4/24, (不置23之的連口址)所有設(shè)備接口IP地址Sw1上vlan110接口的ip地址為10Y1101124vlan113接口ip10Y1131124,SW2上vlan222的接口IP地址為10Y2221224VLAN224的接口IP地址為10.Y.224.1224,SW3上VLAN135的接口的IP地址為10Y1351324.R1連接R4使用DLCI104R1連接R5使用DLCI105R4連接R1使用DLCI401R5連接R1使用DLCI501DLCI號(hào)碼。Framerelay接口之間需要能相互ping通。幀中繼網(wǎng)絡(luò)需支持廣播。R1連接BB1的IP地址為157681124,R6連接BB2的IP地址為157682124,連接BB3的IP地址為157683124,設(shè)置路由器的RrouterID為L(zhǎng)oopback0練習(xí)過(guò)程中,所有設(shè)備的端口IP地址自己按照?qǐng)D配置。R1-R6要在全局配置router-id; [R1]routerid[R2]routerid10.1.2.R5和R6運(yùn)行RI versi 路由協(xié)議,且禁用匯總,通告R5與R6之間互聯(lián)網(wǎng)段R1、R2和SW2運(yùn)行RIPversion2路由協(xié)議,且禁用匯總,在RIP中通告R1與R2,R2SW2之間的互聯(lián)網(wǎng)段,R2的loopback0通告進(jìn)RIPripversion2undosummarynetwork10.0.0.ripversion2undosummarynetwork10.0.0.ripversion2undosummarynetwork10.0.0.ripversion2undosummarynetwork10.0.0.ripversion2undosummarynetwork10.0.0.RIP

R6通過(guò)S100接口和BB2互連,BB2運(yùn)行RIPVersion2路由協(xié)議,BB2連接R6接口IP地址為:54,在R6上通告R6與BB2的互連網(wǎng)段。且只發(fā)送單播路由更新信息。R1和SW2不能向非相關(guān)接口發(fā)送和接收RIP更文work157.68.0.silent-interfaceSerial1/0/interfaceGigabitEthernet0/0/1(Serial1/0/0)undoripoutputundoripiinterfaceVlanif224undoripoutputundoripinputR5:interfaceg0/0/1(g0/0/0)(s1/0/0)undoripinputundoripoutRIP路由引R2的GE0/0/0接口不能運(yùn)行RIP協(xié)議,但接口所在網(wǎng)段能被RIP區(qū)域的到ripimport-routedirectroute -policydirectroute-policydirectpermitnode10if-matchinterfaceg0/0/RIPROUTER實(shí)現(xiàn)R6只向BB2發(fā)送一條10.Y.0.0/ 的匯總路由interfaceSerial1/0/ripsummary-address avoid-feedbackrip1filter-policyip-prefix rip-sum-outexports1/0/0ipip-prefixrip-sum-outpermit16BASE

所有路由器OSPF進(jìn)程號(hào)為R1、R4、R5之間通過(guò)Framerelay互連的接口以及他們的Loopback0接口,R1的S200(BackBone接口)都運(yùn)行在OSPFAREA0內(nèi),不能修改接口默認(rèn)的網(wǎng)絡(luò)R1的GE001接口、R5的GE001接口和SW3上的VLAN135接口屬于OSPFAREA135內(nèi),R5的GE000接口、R3的GE001和Loopback0接口屬于OSPFAREA35內(nèi)。R3的GE000接口、S300接口、R4的S101接口和SW1的VLAN113接口屬于OSPFAREA34內(nèi),R4的GE000和SW2的VLAN224接口屬于OSPFAREA224.erfaceSerial1/0/0erfaceSerial1/0/0work20.0.0.OSPFR1和R5之間的FrameRelay連接是主鏈路,正常情況下從AREA35到R1S200所在網(wǎng)段流量都會(huì)經(jīng)過(guò)FrameRelay,但是這條鏈路不穩(wěn)定,在FrameRelay鏈路中斷的情況下,流量需要被切換到R1和R5之間的Ethernet備份鏈,F(xiàn)rame-Relay主鏈路恢復(fù)正常后流量自動(dòng)被切回erfaceGigabitEthernet0/0/1erfaceGigabitEthernet0/0/1ospfcost1570流量?jī)?yōu)Vlan135VLAN113ospf1area0.0.0.vlink-peer10.1.5.ospf1area0.0.0.vlink-peer10.1.3.OSPF 0使用區(qū)域認(rèn)證防護(hù),認(rèn)證方式使用MD5認(rèn)證,口令類(lèi)型為明文,認(rèn)證為ospf1areaauthenticati -modemd51plainospfareaauthenticati -modemd51plainospfareaauthenticati -modemd51plainospfareaauthenticati -modemd51plain

OSPFAREA34不接受任何的OSPF其他AREA引入的外部路由。SW1只把VLAN110所在的IP網(wǎng)段引入到OSPF中。使用默認(rèn)類(lèi)型,TAG值vlanif110OSPFAREA34用stub區(qū)域,如果描述為“區(qū)域34不接收其他區(qū)域的外部路由”則使用route-policydirectpermitnode10if-matchinterfaceVlanif110applytag100ospfimport-routedirectroute -policydirectarea4ospf1area4OSPF和RIP在R5上RIP和OSPF在R1、SW2上分別進(jìn)行RIP和OSPF的相互引入,RIP引入到OSPF的路由類(lèi)型為實(shí)現(xiàn)在OSPF區(qū)域內(nèi)能看到從R5引入來(lái)的所有路由 值為100,TAG值為100,且能學(xué)習(xí)10.Y.56.0/24、10.Y.6.6/32和171.10.X.0/24的匯總路由,請(qǐng)使用最少令,禁ripimportospf1ospf1asbr-summarytag100cost100importrip1route-policyr2oroute-policyr2opermitnode10if-matchip-prefixripapplycost100applytagiip-prefiriipermiiip-prefiriipermiiip-prefiriipermi16great-l-equalR1、SW2要通過(guò)走最優(yōu)路徑外部網(wǎng)絡(luò),配置要求有設(shè)計(jì)的擴(kuò)展性R2優(yōu)選經(jīng)由SW2ospfimport-routerip1route-policyr2opreferenceaserout -policyextripimport-routeospf1route-policyroute-policyo2rdenynode10if-matchtag102route-policyo2rpermitnode20applytag101route-policyr2odenynode10if-matchtag201route-policyr2opermitnode20applytag202route-policyextpermitnode10if-matchtag100applyprefer interfaces1/0/1ripmetricoutospfimport-routerip1route-policyr2opreferenceaserout -policyextripimport-routeospf1route-policyroute-policyr2odenynode10if-matchtag101route-policyr2opermitnode20applytag102route-policyo2rdenynode10if-matchtag202route-policyo2rpermitnode20applytag201route-policyextpermitnode10if-matchtag100applyprefer R2與vl 135之間互訪的流量往返路徑一致,對(duì)于其他外部路由,R2優(yōu)選SW2,有關(guān)于修改RI跳數(shù)的操作 都需要在R2上完成。則ipip-prefixvlan135permit10.1.135. intG0/0/ripmetricini -prefixvl 日R1和SW3屬于AS10,R2和SW2屬于AS20,R3、R4、R5屬于AS345R6屬于ASR1和SW3通過(guò)直連鏈路建立IBGP鄰居,R2和SW2通過(guò)直連鏈路建立IBGP鄰居在 345內(nèi)的路由器建立穩(wěn)定可靠的BGP鄰居關(guān)系,R4和R5不建立BGP的鄰居bgp10peer3as-numberbgppeeras-numberbgp345peeras-numberpeer -interfacebgp345peeras-numberpeer -interfacepeerrefl -clipeeras-numberpeer -interfacepeerrefl -clibgp345peeras-numberpeer -interfacebgp20peer2as-numberbgppeeras-number日EBGP全都使用直連建立鄰居關(guān)系,BB1和BB2處于AS254內(nèi)R1和R2建立EBGP關(guān)系,R5和R6建立EBGP關(guān)系 和R4建立EBGP關(guān)系R1和BB1建立EBGP,BB1地址為:157.68.1. ,BB1認(rèn)為R1在AS100內(nèi)R6和BB2建立EBGP,BB2地址為:157.68.2.bgp10peeras-number as-number fake-asbgp20peeras-numberbgppeeras-numberbgp345peer2as-numberbgp345peeras-numberbgp60peeras-number as-numberEBGP日 munity為1:254的路由匯聚成一條最優(yōu)匯總路由,并繼承明細(xì)路由的Community屬性。bgp60peeradverti -communitipcommunity-filter1permit1:254route-policyoriginpermitnodeif-matchcommunity-filter1route-policyattpermitnode10applycommunityno-exportadditivebgp345aggregateas -setorigin-policyoriginattribute-policyattpeeradverti -communitbgp345peeradverti -communitBGP日R4上接口Loopback1,IP地址為10.Y.40.4/ ,通告到BGP中1需要匯總一條10.Y.0.0/16 的BP路由,明細(xì)路由不通告,2不能看到這條匯聚路由能路濾。bgp345networkbgp10aggregate -setdet -supprBGP日AS10、AS20、AS345、AS60優(yōu)選從BB2來(lái)的路由,若BB2不可達(dá),需要通過(guò)BB1R4的 1接口連接的網(wǎng)段需能被BB1、BB2正常到,只能在R1上配置bgp10peer54route -policyas-pathimportpeerroute -policyfrom_r2importroute-policyas-pathpermitnodeapplyas-path254254254254additiipip-prefixnet40index10permit24route-policyfrom_r2permitnode10if-matchip-prefixnetroute-policyfrom_r2permitnode20applyip-addressnext-hop日R1、R2、R3、R4、R5和SW2相鄰設(shè)備使用PIMSM模式建立鄰居關(guān)multicastrouting interfaceSerial1/0/0piminterfaceSerial1/0/1pimsminterfaceGigabitEthernet0/0/1pimsmmulticastrouting interfaceSerial1/0/1piminterfaceGigabitEthernet0/0/1pimsminterfaceLoopBack0pimsmmulticastrouting interfaceSerial1/0/1piminterfaceGigabitEthernet0/0/1pimsminterfaceLoopBack0pimsmmulticastrouting interfaceSerial1/0/0piminterfaceSerial1/0/1pimsminterfaceGigabitEthernet0/0/0pimsminterfaceLoopBack0pimsmmulticastrouting-enableinterfaceSerial1/0/0piminterfaceGigabitEthernet0/0/0pimsminterfaceGigabitEthernet0/0/1pimsmmulticastrouting-enableinterfacevlanif224piminterfacevlanif222pimsm日R2使用Loopback0地址作為-239.255.255. 組播地址段的C-RP地址R3使用Loopback0地址作為-239.255.255. 組播地址段的C-RP地址R4使用Loopback0地址作為CBSR的地要求所有組播路由器都能學(xué)習(xí)到C-RP的地aclnumberrule10permitsource55pimc-rpLoopBack0group-policyaclnumberrule10permitsource55pimc-rpLoopBack0group-policypimc-bsriprpf-route-static3210.1.145.日5的0/0/0接口靜態(tài)加入組播組 ,5總是使用RP作為組播源。并且在2上能夠看到這個(gè)地址的組播路由。有一組播源在 135網(wǎng)段,R1在這網(wǎng)段負(fù)責(zé)向RP進(jìn)行組播源的interfaceGigabitEthernet0/0/pimhello-optiondr-priorityinterfaceGigabitEthernet0/0/igmpstatic-group0pimspt-switch-thresholdinfinit5.1日R3和R4創(chuàng) -InstanceABC,RD為34:34,RT為34:R2的接口S1/0/0和R3的接口S1/0/0屬于站點(diǎn)ABC,R2與R3172123X ,R4的接口GE0/0/1屬于站點(diǎn)ABC,地址為/R2與R3的互連接口運(yùn)行在OSPF23區(qū)域0中ip -instanceABCipv4-familyroute-distinguisher34:target34:34expor -extcommunittarget34:34import -extcommunityinterfaces1/0/0ipbinding -instanceABCipaddress24ip -instanceABCipv4-familyroute-distinguisher34:target34:34expor -extcommunittarget34:34import -extcommunityinterfaceg0/0/1ipbinding -instanceABCwork0.0.0.ospf23 -instanceABCareanetwork.2MP-日

R3與R4使用接口 0建 v4鄰居實(shí)現(xiàn)站點(diǎn)ABC的互通互訪,不能對(duì)現(xiàn)有IGP和BP路由進(jìn)行修改,需運(yùn)行MLS的路由器的L-ID為L(zhǎng)pack0 bgpipv4-famil peerenablipv4-family -instanceABCimport-routeospf23ospfimport-routebgp345ipv4-famil peerenablipv4-family -instanceABCimport-routedirectmplslsr-idmplsinterfaces1/0/0mplsstatic-lspegress34incoming -interfaceSerial1/0/0in -label32static-lspingress43destination32outgoing -interfaceSerial1/0/0nexthopout-label40mplslsr-idmplsinterfaces1/0/0mplsstatic-lsptransit43incoming -interfaceSerial1/0/0in -label40outgoing-interfaceSerial1/0/0nexthopout-label41static-lsptransit34incoming -interfaceSerial1/0/0in -label31outgoing-interfaceSerial1/0/0nexthopout-label32mplslsr-idmplsinterfaces1/0/0mplsinterfaceg0/0/0mplsstatic-lsptransit43incoming -interfaceSerial1/0/0in -label41outgoing-interfaceGigabitEthernet0/0/0nexthopout-labelstatic-lsptransit34incoming -interfaceGigabitEthernet0/0/0in label30outgoing-interfaceSerial1/0/0nexthopout-labelmplslsr-idmplsinterfaceg0/0/1mplsstatic-lspingress34destination32outgoing -interfaceGigabitEthernet0/0/1nexthopout-label30static-lspegress43incoming -interfaceGigabitEthernet0/0/1in label42QOS流分日路由器 GE0/0/0接口信任接收到的報(bào)文的優(yōu)先級(jí),將接收到的DSCP值為27的報(bào)文DSCP值映射并修改為在SW2GE0/0/10的入接口方向上把目的端為6000的UDP報(bào)文DSCP值修改為10,源I地址為10.Y.224.0/ 的TCP報(bào)文DSCP值修改為interfaceg0/0/trustdscpoverriqosmap-tabledscp-dscpinput27output7aclnumberrule10permitudpdestination -porteq6000aclnumber3001rule10permittcpsource55trafficclassifier10operatorandif-matchacltrafficclassifier20operatorandif-matchacl3001trafficbehavior10remarkdscp10trafficbehavior20remarkdscp20trafficpolicymarclassifier10behavior10classifier20behavior20intg0/0/traffic-policymarki aclnumberrule10permitudpdestination -porteq6000aclnumber3001rule10permittcpsource55intg0/0/10traffic-remarkinboundacl3000dscp10traffic-remarkinboundacl3001dscp日WRD20%30%95%drop-profilewredwreddscpdscpaf11low-limit20high -limit95discard-percentage30t

溫馨提示

  • 1. 本站所有資源如無(wú)特殊說(shuō)明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁(yè)內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒(méi)有圖紙預(yù)覽就沒(méi)有圖紙。
  • 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
  • 5. 人人文庫(kù)網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
  • 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
  • 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。

評(píng)論

0/150

提交評(píng)論