實驗目的:
1.pc位址都是DHCP擷取IP;
2.C1,C3在vlan10,C2,C4在vlan20,且實作互通;
3.pc都能通路外網;
4.在AR2能夠遠端AR1
所需裝置:
使用ENSP模拟器模拟2台路由器 1台三層交換機2台二層交換機 4台PC機
實驗拓撲圖:

實驗步驟:
1.給二層交換機劃分vlan,并把每個接口加入各自的vlan和建立中繼口。
LSW2:劃分vlan:
[Huawei]vlan 10 劃分vlan 10
[Huawei-vlan10]vlan 20 劃分vlan 20
把接口加入vlan:
[Huawei]int e0/0/2 進接口
[Huawei-Ethernet0/0/2]port link-type access 建立access口
[Huawei-Ethernet0/0/2]port default vlan 10 把接口e0/0/2加入vlan 10
[Huawei]int e0/0/3
[Huawei-Ethernet0/0/3]port link-type access
[Huawei-Ethernet0/0/3]port default vlan 20
[Huawei]int e0/0/1
配置中繼口:
[Huawei-Ethernet0/0/1]port link-type trunk 建立trunk口
[Huawei-Ethernet0/0/1]port trunk allow-pass vlan 10 20建立中繼口
LSW3同LSW2
2.給三層交換機劃分vlan,并且建立中繼口和配置每個vlan的網關位址。
[Huawei]vlan 10
[Huawei-vlan10]vlan 20
配置中繼口:
[Huawei-Vlanif20] int g0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type trunk
[Huawei-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
[Huawei-GigabitEthernet0/0/1] g0/0/2
[Huawei-GigabitEthernet0/0/1]port link-type trunk
[Huawei-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
給VLAN添加IP:
int VLAN 10
ip add 192.168.10.1 24
undo sh
int vlan 20
ip add 192.168.20.1 24
undo sh
DHCP:
[Huawei]dhcp enable 激活DHCP
[Huawei]int vlan 10進入虛拟vlan接口
[Huawei-Vlanif10]dhcp select interface 開啟vlan 10自動擷取IP
[Huawei-Vlanif10]dhcp server dns-list 8.8.8.8 配置DNS
[Huawei-Vlanif10]int vlan 20
[Huawei-Vlanif20]dhcp select interface
[Huawei-Vlanif20]dhcp server dns-list 9.9.9.9
驗證:
3.能夠讓pc通路到AR1。
[Huawei]vlan 100 建立vlan100
[Huawei-vlan100]int g0/0/3
[Huawei-GigabitEthernet0/0/3]port link-type access
[Huawei-GigabitEthernet0/0/3]port default vlan 100
[Huawei-Vlanif100]int vlan 100
[Huawei-Vlanif100]ip add 192.168.1.1 24
[Huawei-Vlanif100]un shutdown
注:三層交換機沒有三層接口是以給SW1g0/0/3和AR1不好配置在一個網段,隻能用虛拟vlan接口來配置IP。
[Huawei]ip route-static 0.0.0.0 0.0.0.0 192.168.1.2 配置三層交換機到AR1交換機的預設路由
給AR1配置IP和靜态路由。
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 192.168.1.2 24
[Huawei-GigabitEthernet0/0/0]un shutdown
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/0]ip add 202.106.1.1 24
[Huawei-GigabitEthernet0/0/0]un shutdown
[Huawei]ip route-static 192.168.10.0 255.255.255.0 192.168.1.1 配置R1到10.0網段的靜态路由
[Huawei]ip route-static 192.168.20.0 255.255.255.0 192.168.1.1 配置R1到20.0網段的靜态路由
[Huawei]ip route-static 172.16.1.0 255.255.255.0 202.106.1.2 配置R1到172.16.1.0網段的靜态路由
4.讓pc使用者能夠通路外網。
配置路由器AR2IP
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 202.106.1.2 24
[Huawei-GigabitEthernet0/0/0]un shutdown
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 172.16.1.1 24
[Huawei-GigabitEthernet0/0/1]un shutdown
[Huawei]ip route-static 192.168.10.0 255.255.255.0 202.106.1.1 配置R2到10.0網段的靜态路由
[Huawei]ip route-static 192.168.20.0 255.255.255.0 202.106.1.1 配置R2到20.0網段的靜态路由
[Huawei]ip route-static 192.168.1.0 255.255.255.0 202.106.1.1 配置R2到1192.168.1.0網段的靜态路由
測試能夠互通就行
給路由器AR1開啟遠端登入
[Huawei]user-interface vty 0 4
[Huawei-ui-vty0-4]authentication-mode password
Please configure the login password (maximum length 16):123.com
[Huawei-ui-vty0-4]q
[Huawei]super password cipher abc123
在AR2上測試遠端登陸AR1,如圖,登陸成功,實驗結束
pc機通路伺服器資源
![](https://img-blog.csdnimg.cn/20210311172823207.png?x-oss-process=image/watermark,type_ZmFuZ3poZW5naGVpdGk,shadow_10,text_aHR0cHM6Ly9ibG9nLmNzZG4ubmV0L3dlaXhpbl80MjIyNDM0Mw==,size_16,color_FFFFFF,t_70