1、RG-S3760-48-1VLAN1192.168.11.1/24F0/1-RG-S2126G1VLAN2192.168.12.1/24F0/2-RG-S2126G2VLAN10192.168.13.1/24F0/10-RG-S3760-48-2 F0/10192.168.13.2/24F0/10-RG-S3760-48-1 F0/10 (续表)RG-S3760-48-2VLAN11192.168.1.11/24F0/11-防火墙eth0VLAN24192.168.24.1/24F0/24-内网服务器R1Fastethernet1/0192.168.1.12/24F1/0-防火墙eth1Ser
2、ial1/2 (DTE)202.202.1.1/24S1/2R2 S1/2R2Serial1/2 (DCE)202.202.1.2/24S1/2R1 S1/2【基本配置】步骤1. S2126G1基本配置。switch(config)#host RG-2126G-1RG-2126G-1(config)# interface range fa 0/1-24 !该步骤可省略RG-2126G-1(config-if-range)#switchport access vlan 1 !步骤2. S2126G2基本配置。switch(config)#host RG-2126G-2RG-2126G-2(con
3、fig)#vlan 2RG-2126G-2(config-vlan)#exitRG-2126G-2(config)#interface range fa 0/1-24RG-2126G-2(config-if-range)#switchport access vlan 2步骤3. RG-3760-48-1基本配置。switch(config)#host RG-3760-48-1RG-3760-48-1(config)# vlan 2RG-3760-48-1(config-vlan)#exitRG-3760-48-1(config)# vlan 10RG-3760-48-1(config)#int
4、erface fa 0/1RG-3760-48-1(config-if)#switch access vlan 1RG-3760-48-1(config-if)#exitRG-3760-48-1(config)#interface fa 0/2RG-3760-48-1(config-if)#switch access vlan 2RG-3760-48-1(config)#interface fa 0/10RG-3760-48-1(config-if)#switch acess vlan 10RG-3760-48-1(config)#interface vlan 1RG-3760-48-1(co
5、nfig-if)#ip address 192.168.11.1 255.255.255.0RG-3760-48-1(config-if)#no shRG-3760-48-1(config)#interface vlan 2RG-3760-48-1(config-if)#ip address 192.168.12.1 255.255.255.0RG-3760-48-1(config)#interface vlan 10RG-3760-48-1(config-if)#ip address 192.168.13.1 255.255.255.0步骤4. RG-3760-48-2基本配置。switch
6、(config)#host RG-3760-48-2RG-3760-48-2(config)# vlan 10RG-3760-48-2(config-vlan)#exitRG-3760-48-2(config)# vlan 11RG-3760-48-2(config)# vlan 24RG-3760-48-2(config)#interface fa 0/10RG-3760-48-2(config-if)#switch access vlan 10RG-3760-48-2(config-if)#exitRG-3760-48-2(config)#interface fa 0/11RG-3760-
7、48-2(config-if)#switch access vlan 11RG-3760-48-2(config)#interface fa 0/24RG-3760-48-2(config-if)#switch access vlan 24RG-3760-48-2(config)#interface vlan 10RG-3760-48-2(config-if)#ip address 192.168.13.2 255.255.255.0RG-3760-48-2(config-if)#no shRG-3760-48-2(config)#interface vlan 11RG-3760-48-2(c
8、onfig-if)#ip address 192.168.1.11 255.255.255.0RG-3760-48-2(config)#interface vlan 24RG-3760-48-2(config-if)#ip address 192.168.24.1 255.255.255.0步骤5. R1基本配置。Red-GiantenRed-Giant#conf tRed-Giant(config)#host R1R1(config)#interface fa 1/0R1(config-if)#ip add 192.168.1.12 255.255.255.0R1(config-if)#no
9、 shR1(config)#interface serial 1/2R1(config-if)#ip add 202.202.1.1 255.255.255.0步骤6. R2基本配置。Red-Giant(config)#host R2R2(config)#int serial 1/2R2(config-if)#ip add 202.202.1.2 255.255.255.0R2(config-if)#clock rate 64000R2(config-if)#no sh步骤7. 测试各个直连接口能够ping通(步骤略)。【路由配置】步骤8. RG-S3760-48-1路由配置。RG-3760-
10、48-1(config)#ip routingRG-3760-48-1(config)# ip route 0.0.0.0 0.0.0.0 192.168.13.2RG-3760-48-1#show ip route!Type: C - connected, S - static, R - RIP, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2Typ
11、e Destination IP Next hop Interface Distance Metric Status-S 0.0.0.0/0 192.168.13.2 VL10 1 0 ActiveC 192.168.11.0/24 0.0.0.0 VL1 0 0 ActiveC 192.168.12.0/24 0.0.0.0 VL2 0 0 ActiveC 192.168.13.0/24 0.0.0.0 VL10 0 0 Active步骤9. RG-S3760-48-2路由配置。RG-3760-48-2(config)# ip routingRG-3760-48-2(config)# ip
12、route 0.0.0.0 0.0.0.0 192.168.1.12RG-3760-48-2(config)# ip route 192.168.11.0 255.255.255.0 192.168.13.1RG-3760-48-2(config)# ip route 192.168.12.0 255.255.255.0 192.168.13.1RG-3760-48-2#show ip route-S 0.0.0.0/0 192.168.1.12 VL11 1 0 ActiveC 192.168.1.0/24 0.0.0.0 VL11 0 0 ActiveS 192.168.11.0/24 1
13、92.168.13.1 VL10 1 0 ActiveS 192.168.12.0/24 192.168.13.1 VL10 1 0 ActiveC 192.168.24.0/24 0.0.0.0 VL24 0 0 Active步骤10. R1路由配置。R1(config)#ip route 192.168.11.0 255.255.255.0 192.168.1.11R1(config)#ip route 192.168.12.0 255.255.255.0 192.168.1.11R1(config)#ip route 0.0.0.0 0.0.0.0 serial 1/2R1# sh ip
14、 routeCodes: C - connected, S - static, R - RIP O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 * - candidate defaultGateway of last resort is 0.0.0.0 to network 0.0.0.0S* 0.0.0.0/0 is directly connected, serial 1/2C 192.168.1.0/24 is directly connected,
15、 FastEthernet 1/0C 192.168.1.12/32 is local host.S 192.168.11.0/24 is directly connected, FastEthernet 1/0S 192.168.12.0/24 is directly connected, FastEthernet 1/0C 202.202.1.0/24 is directly connected, serial 1/2C 202.202.1.1/32 is local host.步骤11. RG-S3760-48-1安全配置。RG-3760-48-1(config)#RG-3760-48-
16、1(config)#ip access-list extended deny_ftpRG-3760-48-1(config-ext-nacl)# deny tcp 192.168.11.0 0.0.0.255 192.168.24.0 0.0.0.255 eq ftp 192.168.24.0 0.0.0.255 eq ftp-dataRG-3760-48-1(config-ext-nacl)#permit ip any anyRG-3760-48-1(config-ext-nacl)#end【R1的NAT配置】R1(config)#access-list 1 permit 192.168.1
17、1.0 0.0.0.255R1(config)#access-list 1 permit 192.168.12.0 0.0.0.255R1(config)#int fa1/0R1(config-if)#ip nat insideR1(config-if)#exitR1(config)#int s1/2R1(config-if)#ip nat outsideR1(config)#ip nat inside source list 1 interface serial 1/2 overload【注意事项】1、安全访问控制列表要添加允许所有的条目,并在交换机相关接口下运用。2、R2作为模拟外网的路由
18、器,在本实验中无需添加路由条目。3、R2的S1/2接口为DCE接口,要设置时钟速率。4、各个接口地址及连线要保证正确。5、路由器接口与防火墙接口相连请用交叉线。【参考配置】RG-3760-48-1#show running-configSystem software version : 1.02 Build Oct 17 2005 ReleaseBuilding configuration.Current configuration : 625 bytesversion 1.0hostname RG-3760-48-1vlan 1vlan 2vlan 10interface FastEther
19、net 0/2 switchport access vlan 2interface FastEthernet 0/10 switchport access vlan 10interface Vlan 1 ip address 192.168.11.1 255.255.255.0interface Vlan 2 ip address 192.168.12.1 255.255.255.0interface Vlan 10 ip address 192.168.13.1 255.255.255.0ip route 0.0.0.0 0.0.0.0 Vlan 10 192.168.13.2 1 enab
20、ledendRG-3760-48-2#show running-config 1.03(1) Build Dec 1 2005 Release 786 byteshostname RG-3760-48-2vlan 11vlan 24interface FastEthernet 0/11 switchport access vlan 11interface FastEthernet 0/24 switchport access vlan 24 ip address 192.168.13.2 255.255.255.0interface Vlan 11 ip address 192.168.1.1
21、1 255.255.255.0interface Vlan 24 ip address 192.168.24.1 255.255.255.0ip route 0.0.0.0 0.0.0.0 Vlan 11 192.168.1.12 1 enabledip route 192.168.11.0 255.255.255.0 Vlan 10 192.168.13.1 1 enabledip route 192.168.12.0 255.255.255.0 Vlan 10 192.168.13.1 1 enabledR1#sh run 849 bytesversion 8.32(building 5)
22、hostname R1access-list 1 permit 192.168.11.0 0.0.0.255access-list 1 permit 192.168.12.0 0.0.0.255interface serial 1/2 ip nat outside ip address 202.202.1.1 255.255.255.0interface serial 1/3interface FastEthernet 1/0 ip nat inside ip address 192.168.1.12 255.255.255.0 duplex auto speed autointerface
23、FastEthernet 1/1interface Null 0ip nat inside source list 1 interface serial 1/2 overloadline con 0line aux 0line vty 0 4login说明:R2路由器配置为基础配置,此处略。防火墙可按图示配置,此处略。RG-2126G-1#sh run 1.61(4) Build Sep 9 2005 Release 2261 byteshostname RG-2126G-1ip access-list extended deny_worms deny tcp any any eq 135 deny tcp any any eq 136 deny tcp any any eq 137 deny tcp any any eq 138 deny tcp any any eq 139 deny tcp any any eq 445 deny udp any any eq 135 deny udp any any eq 136 deny udp any any eq netbios-ns deny udp any a