VLAN DHCP ACL RIP 配置
實驗要求:
vlan10網關sw1 vlan20網關R1 vlan30/40網關sw2
vlan50/60網關R2 vlan40與vlan50都可以訪問vlan60
但兩個vlan在2層互相隔離 sw3 為DHCP服務器
實現全網vlan互通
思路與步驟:
實驗 VLAN DHCP ACL RIP 配置
思路與配置:
1.配置SW1:創建vlan10和vlan20
將0端口加入vlan10 2和3端口加入vlan20
vlanif10 ip:192.168.10.254 255.255.255.0
vlanif20 ip:192.168.20.2 255.255.255.0
2.配置SW2:創建vlan30 40 50 60
將5端口加入vlan30 4端口加入vlan40
將1和2端口加入vlan50 1和6端口加入vlan60
vlanif30ip:192.168.30.254 255.255.255.0
vlanif40ip:192.168.40.254 255.255.255.0
vlanif530ip:192.168.50.2 255.255.255.0
vlanif60ip:192.168.60.24 255.255.255.0
3.配置R1: 配置0端口ip:192.168.20.254 255.255.255.0
配置1端口ip:192.168.12.1 255.255.255.0
4.配置R2: 配置0端口ip:192.168.50.254 255.255.255.0
配置1端口ip:192.168.12.2 255.255.255.0
配置2端口ip:192.168.60.254 255.255.255.0
5.配置SW3 創建vlan100
將1端口加入vlan100
vlanif100ip:192.168.100.1 255.255.255.0
6.配置SW1 創建RIP
rip
version 2
network 192.168.10.0
network 192.168.20.0
7.配置R1 創建RIP
rip
version 2
network 192.168.12.0
network 192.168.20.0
network 192.168.100.0
8.配置SW2 創建RIP
rip
version 2
network 192.168.30.0
network 192.168.40.0
network 192.168.50.0
network 192.168.60.0
9.配置R2 創建RIP
rip
version 2
network 192.168.12.0
network 192.168.50.0
network 192.168.60.0
10.配置sw3 創建RIP
rip
version 2
network 192.168.100.0
如果手動配置pc機的ip 此就可以全網互通
11.配置SW3的地址池:系統模式下 dhcp enable
ip pool vlan10
network 192.168.10.0 mask 255.255.255.0
gateway-list 192.168.10.254
dns-list 1.1.1.1
lease day 3
ip pool vlan20
network 192.168.20.0 mask 255.255.255.0
gateway-list 192.168.20.254
dns-list 1.1.1.1
lease day 3
ip pool vlan30
network 192.168.30.0 mask 255.255.255.0
gateway-list 192.168.30.254
dns-list 1.1.1.1
lease day 3
ip pool vlan40
network 192.168.40.0 mask 255.255.255.0
gateway-list 192.168.40.254
dns-list 1.1.1.1
lease day 3
ip pool vlan50
network 192.168.50.0 mask 255.255.255.0
gateway-list 192.168.50.254
dns-list 1.1.1.1
lease day 3
進入vlan100端口 選擇全局模式
interface g0/0/0
dhcp select global
12.配置SW1:開啟中繼 dhcp enable
interface vlanif 10
dhcp select relay
dhcp relay sever-ip 192.168.100.1
13.配置R1:開啟中繼 dhcp enable
interface g0/0/0
dhcp select relay
dhcp relay sever-ip 192.168.100.1
14.配置SW2:開啟中繼 dhcp enable
interface vlanif 30
dhcp select relay
dhcp relay sever-ip 192.168.100.1
interface vlanif 40
dhcp select relay
dhcp relay sever-ip 192.168.100.1
15.配置R2:開啟中繼 dhcp enable
interface g0/0/0
dhcp select relay
dhcp relay sever-ip 192.168.100.1
interface g0/0/2
dhcp select relay
dhcp relay sever-ip 192.168.100.1
16.此時在個pc機上選擇dhcp獲取:通過ipconfig查取ip
pc1:
pc2:
pc3:
pc4:
pc5:
17.配置SW2 配置ACL 讓pc4與pc2隔離
acl name pc4-2 advance
rule 5 deny ip sourse 192.168.40.253 0.0.0.0 destiation 192.168.50.253 0.0.0.0
quit
interface e0/0/4
traffic-fliter inbound acl name pc4-2
18.手動配置sever1的 ip192.168.60.1 255.255.255.0
網關 192.168.60.254
##除了pc4與pc2不通之外 此時全網所有pc機互通
VLAN DHCP ACL RIP 配置