![四、ccna实验工大瑞普手册-lab_第1页](http://file4.renrendoc.com/view/dc7f8c0e10a27428574615905a2e2fa6/dc7f8c0e10a27428574615905a2e2fa61.gif)
![四、ccna实验工大瑞普手册-lab_第2页](http://file4.renrendoc.com/view/dc7f8c0e10a27428574615905a2e2fa6/dc7f8c0e10a27428574615905a2e2fa62.gif)
![四、ccna实验工大瑞普手册-lab_第3页](http://file4.renrendoc.com/view/dc7f8c0e10a27428574615905a2e2fa6/dc7f8c0e10a27428574615905a2e2fa63.gif)
![四、ccna实验工大瑞普手册-lab_第4页](http://file4.renrendoc.com/view/dc7f8c0e10a27428574615905a2e2fa6/dc7f8c0e10a27428574615905a2e2fa64.gif)
![四、ccna实验工大瑞普手册-lab_第5页](http://file4.renrendoc.com/view/dc7f8c0e10a27428574615905a2e2fa6/dc7f8c0e10a27428574615905a2e2fa65.gif)
版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
CISCO3CCIE,100CISCOPIX,3550交换机,7000路由器,两条ISDN线路基带MODEM,交换机,NETSCREEN登录微 本地 Lab1-BasicRouterLab2-AdvancedRouterLab3-Lab4 Lab5-Lab6-Lab7-Lab8-Lab9-Lab10–Catalyst1900SwitchLab11-VLANs&Trunking(CatalystLab12-Catalyst2950SwitchLab13-VLANsandTrunking(CatalystLab13-1RoutinginterLab14-IPAccessLab15-Lab16-PPP&Lab17-ISDNBRI-BRIusingLegacyLab18-ISDNBRI-BRIusingDialerLab19-ISDNPRIusingDialerLab20-FrameLAB1–基本Router>enable//用户模式敲入enable进入到模Router#?//Router# //模式敲入disable退到用户模Router>enable//用户模式敲入enable进入到模Router#configure //模式敲入configureterminal进入配置模 配置路由器名字(主机名)如‘R1’03,则命名为na03r1,如12,则命名na12r1,依次类推).Router(config)#hostname //12号实验台的第一台路由器命名为配置路由器的配置console口R1(config)#lineconsole0R1(config-line)#passwordcisco设置后00:29:42:%SYS-5-CONFIG_I:ConfiguredfromconsolebyconsoleUserAccessVerification //这里要输入console口配置enable//从用户模式到enable模式的Awhenbothencryptedandunencryptedenablepasswordsareconfigured,whichoneisused?R1(config)#enablepassword //显示为明R1(config)#enablesecret 注:用命令showrunning-config可以看到cisco为明文,wisdom显示为乱码,当两个都配置时,只有enablesecret所跟的生效,两个不可以配置一样的.配置vty//登 netR1(config)#linevty04R1(config-line)#passwordcisconet命令的使用 net+IPaddressorhostnameofaremote例如:net配置路由器接口ethernet0的IPR1#configureterminalR1(config)#interfaceethernetR1(config-if)#ipaddressR1(config-if)#noshutdown在Serial0R1(config-if)#intserialR1(config-if)#ipaddressR1(config-if)#noshutdown测试ctrl-zR1(config-if)#ctrl-z任何模式下敲入ctrl-z都会退回到模 模R1#logout回到模R1>password:cisco输入enablesecret的为cisco显示接口的基本概况R1#showipinterface显示详细信息:showinterface接口类型+接口偏号R1#showinterfacesethernet0或是showinterfaceserialR1#showinterfacesethernet0Ethernet0isup,lineprotocolisdownHardwareisLance,addressis0000.0c92.8164(bia0000.0c92.8164)Internetaddressis/24MTU1500bytes,BW10000Kbit,DLY1000usec,rely145/255,loadR1#showrunning-config//显示 Ifnot,whyR1#showstartup-config保存配置R1#copyrunning-configstartup-保存配置:copyrunning-configstartup-config等同于R1#showstartup-使用Show问题A:WhatIOSreleaseisrunning在 查看IOS的版问题B:Whatarethecontentsoftheconfiguration 查看寄存器的R1#showA:whichprotocolsarecurrentlyrunningontheR1#showip进入另一台Router>Router#configureterminal配置主机名,配置Router(config)#hostnameR2R2(config)#enablesecret配置以太网R2(config)#interfaceR2(config-if)#ipaddressR2(config-if)#noshutdownR2(config-if)#ctrl-R2#showipinterfaceR1#showipinterface OK?MethodStatus YESmanualup YES administrativelydown YES administrativelydown配置登陆信息 etoWISDOMLAB-AuthorizedUsersR1(config)#bannermotdetoWISDOMLAB-AuthorizedUsersOnly password:cisco password:ciscoR1R2对应起来(相当于WindowsHosts文件的作用)。R1(config)#iphostR2R1中主机名和IP地址的对应R1#showR1#R2上的AwhatisthenameoftheIOSimageinflashandhowlargeisR2#showR2#showSystemflash1[16384KbytesofprocessorboardSystemflash(ReadONLY)显示R1上曾经敲入令,可以看到前10条,可以通过Ctrl+P或向上箭头调出这R1#showR1#ctrl- (toseepreviouslyenteredR1#showinterfacesserial0R1#configureterminalR1(config)#interfaceserial0R1S0口接的线是DCE即使你配置了IP也没法连通。R1(config-if)#clockrate64000R1(config-if)#ctrl-zR1#showinterfacesserial配置接口的R1(config)#interfaceserialR1(config-if)#descriptionSerialLinktoR2R1(config-if)#exitR1(config)#R1#showinterfacesserial验证两条常用命令的作用(1)会话退Router(config)#lineconsoleRouter(config-line)#exec-timeout0(2)使光标还原到原来的位置,重新显示被覆盖Router(config)#lineconsole0Router(config-line)#loggingsynchronousCCNA实验拓扑图R1、R2、R3R1R2R3confconfconfhosthosthostno -no -no -lineconlineconlineconpasspasspassnoexec-noexec-noexec-logglogglogglinevty0linevty0linevty0passpasspassloggnoexec-noexec-noexec-loggloggenaseenaseenaseintintintipaddipaddipaddnonononointintintipaddipaddipaddnonoclonononointintintipaddipaddipaddclonoclonono检查网络的连通性:在R1用来测试网络的连通R1#TypeescapesequencetoSending5,100-byteICMPEchosto,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=4/4/4msR1#TypeescapesequencetoSending5,100-byteICMPEchosto,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=4/4/4msR1R2,R3OKLAB3CDP(CISCO的发现协议R1#showcdp Informationforspecificneighborentry CDPinterfacestatusandconfiguration CDPneighborentries CDPR1.CDPR1#shcdp显示邻居的详细信息R1#showcdpneighborsdetailR1#showcdpentry*查看那个接口运行R1#showcdpR1,CDP的计时器R1(config)#cdptimer50R1(config)#cdpholdtime170R1(config)#exitR1#shcdp启用和禁用R1(config)#nocdprun!路由器运行CDPR1#showcdpnei !检查看到没有CDP运行R1#configureterminalR1(config-if)#nocdpenable !此接口运行CDPR1#showcdpinterface !看不到Serial0运行CDP启用CDPR1(config)#cdprunR1(config-if)#cdpLAB4 R1#configR1(config)#interfaceserial0R1(config-if)#noshR1(config-if)#clockrateR1(config-if)#ipaddR1(config)#interfaceserail1R1(config-if)#clockrateR1(config-if)#ipaddR1(config-if)#endR2#configR2(config)#interfaceserial0R2(config-if)#noshR2(config-if)#ipaddR3#configR3(config)#interfaceserial0R3(config-if)#noshR3(config-if)#ipadd首先在R2和R3上配置好R3#configtR3(config)#linevty04R3#configtR3(config)#linevty04R1 netR2#showR2CTRL-SHIFT-6X.R2#ctrl-shift-6xR1#shownet netR3>ctrl-shift-6xR1#showR1R1#disconnectR1#disconnect1R1#showsessionsR2R3Showsessionshowuser的区别DisconnectClearline区别Ctrl+shift+6xresumeShowsession查看打开了多少个net的会Showuser 查看有谁通过net来连接我 Clearline (Ctrl+shift+6)xnet介面的切换 再次LAB5-R1上配置:R1#conftR1(config)#inte0R1(config-if)#ipaddressR1#98 !tftpServer的地址是49,测试是否能连通R1#copystartup-configtftp把NVRAM里的配置备份到TFTPServerR1#copytftpstartup- 把TFTPServer里的配置文件COPY到R1#copyflash:tftp:IOSTFTPR1#dirIOSDirectoryof1-<no(IOSbytestotalbytesLAB6-R1#configR1(config)#interfaceserial0R1(config-if)#noshR1(config-if)#clockrateR1(config-if)#ipaddR1(config)#interfaceserail1R1(config-if)#clockrateR1(config-if)#ipaddR1(config-if)#exitR1(config)#interfaceethernet0R1(config-if)#ipR1(config-if)#noshutR1(config-if)#nokeepaliveR2#configR2(config)#interfaceserial0R1(config-if)#clockrateR2(config-if)#noshR2(config-if)#ipaddR2(config-if)#ipaddR2(config-if)#noshutR2(config-if)#nokeepaliveR3#configR3(config)#interfaceserial0R3(config-if)#noshR1(config-if)#clockrateR3(config-if)#ipaddR3(config-if)#ipaddR3(config-if)#noshutR3(config-if)#nokeepaliveR1(config)#routerripR1(config-router)#version2R1(config-router)#noauto-summaryR1(config-router)#networkR1(config-router)#networkR1(config-router)#networkR2(config)#routerripR2(config-router)#version2R2(config-router)#noauto-summaryR2(config-router)#networkR2(config-router)#networkR3(config)#routerripR3(config-router)#version2R3(config-router)#noauto-summaryR3(config-router)#networkR3(config-router)#networkR1shipprotocolsR1#showipR1RIPa.RIP的管理距离是多少 showip在R2,R2#R2#使用cleiproute*清除路由表R2#cleariprouteR1使用Debug命令,30秒更新一次路由R1#debugip使用undebugallR1#showdebuging!DebugR1#undebugall!DebugLAB7–假设所有路由器已经配置好了IP地址(路已经修好了)RIProuterx(config)#norouterriprouterx#showipprotocolsR1,R2,R3,R1(config)#routerigrp100R1(config-router)#networkR1(config-router)#networkR1(config-router)#networkR2(config)#routerigrp100R2(config-router)#networkR2(config-router)#networkR3(config)#routerigrp100R3(config-router)#networkR3(config-router)#network显示动态路由协议A:howfrequentlydoesIGRPsendoutroutingBwhatistheholddownintervalforIGRP?问题C:whatisthedefaulthopcountforIGRP?R1#showipprotocols显示IP路由A:whatistheadministrativedistanceforR1#showip在R2,R2#R2#A:whatisthedifferencebetweenthetwodebugipigrpR1#debugipigrpR1#debugipigrpLAB8–清除刚才配置的IGRProuterx(config)#norouterigrp100R1(config)#routereigrp1R1(config-router)#noauto-summaryR1(config-router)#networkR1(config-router)#networkR1(config-router)#networkR2(config)#routereigrp1R2(config-router)#noauto-summaryR2(config-router)#networkR2(config-router)#networkR3(config)#routereigrp1R3(config-router)#noauto-summaryR3(config-router)#networkR3(config-router)#network查看路由协议问题A:whatistheumrouterhopcountwithrouter4#showipR1上显示EIGRP邻居R1#showipeigrpR1是能够显示EIGRP包的发送和接受数量R1#showipeigrpR1上显示EIGRPtopologyA:whatdoestheEIGRPtopologydatabaseR1#showipeigrpR2A:EIGRP的管理距离多少router4#showip在R2#R2#R1#debugipLAB9-naxxx(config)#noroutereigrpR1的LOOPBACK地址作为ROUTER-interfaceloopbackipadderssR2的LOOPBACK地址作为ROUTER-interfaceloopbackipadderssR3的LOOPBACK地址作为ROUTER-interfaceloopbackipadderssR1(config)#routerospf1R1(config-router)#router-idR1(config-router)#network55areaR1(config-router)#network55areaR1(config-router)#network55areaR2(config)#routerospf1R2(config-router)#router-idR2(config-router)#networkareaR2(config-router)#networkareaR3(config)#routerospf1R3(config-router)#router-id3.3..3.3R3(config-router)#networkareaR3(config-router)#networkarea显示路由协议信息A:HowfrequentlydoesOSPFsendroutingR1#shipR1上检查邻居R1#shipospfR1OSPF的接口A:10MbpsCOST是多少R1#shipospf检查路由表A:OSPF的管理距离多少router4#showip在R2,R2#R2#LAB10CATALYST1900SWITCH配置(不要求#?#>Onswitch1,gointoprivilegedmodeandthenintoglobalconfigurationmode.AssignSwitch1ahostnameof1900sw1.Useexitorctrl-ztogetoutofconfigurationmode. configureterminal(config)#hostname1900sw11900sw1(config)#exitOnswitch1,typeshowrunning-configtoseetheactiveADoyouneedtoissuecopyrunning-configstartup-configontheCatalyst1900tosavetherunningconfiguration?Ifnot,why1900sw1#showrunning-Onswitch1,erasethecurrentconfigurationwiththefollowing1900sw1#deleteOnswitch1,getintoprivilegedmodeandthenintoglobalconfiguration.Reassigntheswitchahostnameof1900sw1andanenablepasswordof‘cisco’.AssigntheswitchanIPaddressof9withasubnetmaskof.Assigntheswitchadefaultgatewayof(router4’sEthernet#configure(config)#hostname1900sw1(config)#enablepasswordlevel15cisco1900sw1(config)#ipaddress91900sw1(config)#ipdefault-gatewayOnswitch1,issuetheshowipcommandtoverifythattheIPaddress,mask,andgatewayare1900sw1#showOnswitch1,issuetheshowinterfacesA:WhatistheSpanningTree802.1D)stateofinterfaceB:Whatistheduplexsettingforinterface1900sw1#showFromtheNetSimtoolbar,selectSwitch2(Catalyst1900).Configureitwithahostnameof1900sw2andanenablepasswordofcisco(theenablepasswordshouldbeencryptedwhendisyingtheconfigurationfile).AssignanIPaddressof00/24andadefault-gatewayof#configure(config)#hostname1900sw21900sw2(config)#enablesecretlevel15cisco1900sw2(config)#ipaddress001900sw2(config)#ipdefault-gatewayOnswitch2,issuetheshowversionA:WhatversionofIOSistheswitchB:WhatisthebaseEthernetaddressof1900sw2#showOnswitch1,issuetheshowspantreeA:whatistheaddressoftherootBwhatistheportcostofE0/1?问题C:whatisthemaxageinterval?问题D:whatistheointerval?1900sw1#showOnswitch1,issuetheshowmac-address-tablecommand.Thisshowswhichdevicesareattachedtowhichswitchports.1900sw1#showmac-address-Onswitch1,permanentlyassignadevicewithMACaddress1111-1111-1111toportE0/5.Issuetheshowmac-address-tablecommandtoverifythedeviceisinthetableasapermanententry.1900sw1(config)#mac-address-tablepermanent1111-1111-1111e0/51900sw1(config)#exit1900sw1#showmac-address-Onswitch1,configureportsecurityforporte0/9.Theswitchwill‘sticky-learn’theMACaddressofthedeviceconnectedtoporte0/9andwillonlyallowthatdevicetoconnecttothisportinthefuture.1900sw1(config)#interfacee0/91900sw1(config-if)#port1900sw1(config-if)#portsecuremax-mac-countLAB11–VLANsand (Catalyst1900Inthislab,youwillsetupVLANsontheCatalyst1900switchesandtestthembyingbetweenrouter4andPC1.Router4isconnectedtoe0/1onswitch1andPC1isconnectedtoe0/1onswitch2.Switch1andswitch2areinterconnectedthroughtheirfa0/26FastEthernetUsingwinipcfgonPC1,configureanIPaddressof/24andadefaultgatewayof(ifnotalreadyconfiguredfromapreviousc:>VerifyyoucanpresentlybetweenPC1androuter4.Ifyoucannotsuccessfully,checkthatrouter4’sEthernet0IPaddressis/24andthattheinterfaceisenabled.Also,usingthewinipcfgutility,checkthatthePChasaconfiguredIPaddressofc:>Onswitch1andswitch2,issuetheshowvlancommand.Youshouldnotethat,bydefault,allswitchportsareinVLAN1.Becauserouter4,PC1,andtheswitch-to-switchlinkareallinVLAN1,shouldbeabletobetweenPC1androuter4. showOnswitch1andswitch2,setupaVTPcalledbig.Verifyithasbeencreatedwiththeshowvtpcommand.A:whatVTPoperatingmodearetheswitches1900swx(config)#vtp 1900swx(config)#exit1900swx#showOnswitch1andswitch2,createVLAN10,callingitccnavlan.Issuetheshowvlancommandtoverifyitwassuccessfullycreated.A:doyouseeanyportsconnectedtoVLAN10.Ifnot,why1900swx(config)#vlan10nameccnavlan1900swx(config)#exit1900swx#showOnswitch1andswitch2,assignthee0/1portstothenewVLANyoucreated.Router4andPC1areattachedtotheseports.IssuetheshowvlancommandonbothswitchestoverifytheseportshavebeenmovedtoVLAN10.Also,issuetheshowvlan-membershipcommand.ThisisanothercommandthatshowsVLANassignmentsbyportonthe1900.1900swx(config)#interfacee0/11900swx(config-if)#vlan-membershipstatic101900swx(config-if)#ctrl-z1900swx#show1900swx#showvlan-Nowthatbothrouter4andPC1areinVLAN10,trytofromthePC1torouter4.Itshouldfail.问题A:ifbothdevicesareinthesameVLAN,whyshouldthesc:>Makethelinkbetweenswitch1andswitch2atrunklinecapableofcarryingtrafficforanyVLAN.Usetheshowtrunkacommandtoverifytrunkingisenabledonportfa0/26onbothswitches(itshouldsay“Trunking:on”)A:whattrunkingprotocoldoesthe1900use–ISLor1900swx(config)#interfacefa0/261900swx(config-if)#trunkon1900swx(config-if)#ctrl-z1900swx#showtrunkaNowbetweenPC1androuter4.ThesshouldsucceedbecausebothdevicesarethesameVLANandtheinter-switchlinkisatrunklinecapableofcarryingtrafficforanyc:>LAB12-2950交换机配Switch>enableSwitch#?Switch#disableSwitch>Switch#configureterminalSwitchconfig)#hostnamesw2950sw2050(config)#exitsw2950#showrunning-sw2950#copyrunning-configstartup-configsw2950#showstartup-config删除配置,sw2950#erasestartup- sw2950#reload配置交换机的IP交换机的IP地址和网关只是为了方便来管理交换机而设置Switch>Switch#configureSwitch(config)#hostnamesw2950sw2950(config)#enablepasswordciscosw2950(config)#interfacevlan1sw2950(config-if)#ipaddress9sw2950(config-if)#noshutdownsw2950(config-if)#sw2950(config)#ipdefault-gateway//sw2950#showinterfacevlan1SW2950(config)#interfacefastEthernetSW2950(config-if)#duplex EnableAUTOduplexconfigurationfullfullduplexoperationhalfhalf-duplexSW2950(config-if)#duplexfullfastEthernet0/1100MOnswitch3issuetheshowinterfacescommand.问题A:interfacefa0/1的生成树状态是什么?问题B:fa0/2的双工模式是什么?sw2950#showinterfacessw2950#showversion使用Showspanning-A:根网桥的网桥ID是多少?问题B:fa0/1的COST是多少?问题C:maxage是多少?问题D:o间隔是多少?sw2950#showspanning-tree//检查生成树状态检查MACsw2950#showmac-address-MACsw2950(config)#mac-address-tablestatic4444-4444-4444vlan1intfa0/5sw2950(config)#exitsw2950#showmac-address-sw2950(config)#interfacefa0/9sw2950(config-if)#switchportport-securitysw2950(config-if)#switchportport- umsw2950(config-if)#switchportport-securitymac-address-tableSW2950(config-if)#switchportport-securityviolationprotect/restrict/ Securityviolationprotectmode Securityviolationrestrictmode SecurityviolationshutdownLAB13–VLANsand1 showISLSw01(config)#interfacefa0/1sw01(config-if)#switchportmodetrunkSw01(conifg-if)#swtichporttrunkencapsulationisl !2950交换机不能敲入此命令缺省为dot1Qsw01(config-if)#ctrl-zsw01#showinterfacefa0/1Sw01(config)#interfacefa0/1sw01(config-if)#switchportmodetrunk !2950sw01(config-if)#ctrl-sw01#showinterfacefa0/1DOT1QSw01(config)#interfacefa0/1sw01(config-if)#switchportmodetrunk !2950sw01(config-if)#ctrl-sw01#showinterfacefa0/1Sw01(config)#interfacefa0/1sw01(config-if)#switchportmodetrunk !2950sw01(config-if)#ctrl-sw01#showinterfacefa0/1VTP(两种方法第一种sw01#vlandatabasesw01(vlan)#vtp sw01(vlan)#vtpserversw01(vlan)#ctrl-zsw01#showvtp第二种 sw01(vlan)#vtpmodeserversw01#showvtpsw02#vlandatabasesw02(vlan)#vtp sw02(vlan)#ctrl-zsw02#showvtpstatussw01#vlandatabasesw01(vlan)#vlan2namevlan2sw01(vlan)#vlan3namevlan3sw01(vlan)#exitsw01#show在sw02Vlan,Vlan2,3Sw02#showvlan在sw01上将f0/4Vlan2,在Sw02f0/6Vlan2,f0/10Sw01(config)#interfaceSw01(config-if)#switchportmodeaccessSw01(config-if)#switchportaccessvlan2Sw02(config)#interfacefa0/6Sw02(config-if)#switchportmodeaccessSw02(config-if)#switchportaccessvlan2Sw02(config)#interfacefa0/10Sw02(config-if)#switchportmodeaccessSw02(config-if)#switchportaccessvlan3Sw02(config-if)#ctrl-z2950swx#showR1、R2和R3的IPR1(config)#interfacee0R1(config-if)#ipaddR2(config)#interfacee0R2(config-if)#ipaddR3(config)#interfacee0R3(config-if)#ipadd在R1上能通,不能通R1#R1#LAB13–1VLAN间路4.1.1Router#configuretRouter#configureterminalRouter(config)#hostnameR2610R2610(config)#interfacee0/0R2610(config-if)#noshutdownR2610(config-if)#noipaddressR2610(config)#interfacee0/0.2R2610(config-subif)#encapsulationdot1QR2610(config-subif)#ipaddR2610(config)#inte0/0.3R2610(config-subif)#encapsulationdot1QR2610(config-subif)#ipaddR2610(config-subif)#encapsulationdot1QR2610(config-subif)#ipaddSwitch#configuretSwitch#configureterminalSwitch(config)#hostsw2950sw2950(config)#intf0/24sw2950(config-if)#switchportmodetrunksw2950(config)#vlan2sw2950(config-vlan)#nameVLAN2sw2950(config)#vlan3sw2950(config-vlan)#nameVLAN3sw2950(config)#vlan4sw2950(config-vlan)#nameVLAN4sw2950(config)#intrangef0/1-6sw2950(config-if-range)#switchportmodeaccesssw2950(config-if-range)#switchportaccessvlan2sw2950(config)#intrangef0/7-12sw2950(config-if-range)#switchportmodeaccesssw2950(config-if-range)#switchportaccessvlan3sw2950(config)#intrangef0/13-18sw2950(config-if-range)#switchportmodeaccesssw2950(config-if-range)#switchportaccessvlan4LAB14–IP列Naxxr3实验一:将R2,R3认为是一台计算机,R1是路由器,配置标准列表,不允许R2做好基本配置,R1#conftR1(config)#ints0R1(config-if)#noshR1(config-if)#ipaddR1(config-if)#clockrR1(config)#ints1R1(config-if)#ipaddR1(config-if)#noshR1(config-if)#clockrR2#conftEnterconfigurationcommands,oneperline. EndwithR2(config)#hostnameR2R2(config-if)#ipaddressR2(config-if)#noshR2(config)#iprouteR2#TypeescapesequencetoSending5,100-byteICMPEchosto,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=4/7/8msRouter#conftEnterconfigurationcommands,oneperline. EndwithCNTL/Z.Router(config)#hostnameR3R3(config)#interfaceserial0R3(config-if)#noshutdownR3(config-if)#ipaddR3(config)#iprouteR3#TypeescapesequencetoSending5,100-byteICMPEchosto,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=4/6/8msR1(config)#access-list1denyR1(config)#access-list1permitanyR1(config)#interfaces1R1(config-if)#ipaccess-group1 !如将列表应用在S0口,怎么配置呢R1#showaccess-list !或者使用showipaccess-listR1#showipinterface在R2上测试R2# !是否能通R2#net !能net到成功马?R1#conft )#noaccess-list1 !删除列表1R1#show !检查列表1,还有列表吗实验二:不允许R2R3,其他的连接可R1#conftR1(config)#ints0R1(config-if)#noshR1(config-if)#ipaddR1(config-if)#clockrR1(config)#ints1R1(config-if)#ipaddR1(config-if)#noshR1(config-if)#clockrR2#conftEnterconfigurationcommands,oneperline. EndwithR2(config)#hostnameR2R2(config)#ints0R2(config-if)#ipaddressR2(config-if)#noshR2(config)#iprouteR2#TypeescapesequencetoSending5,100-byteICMPEchosto,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=4/7/8msRouter#conftEnterconfigurationcommands,oneperline. EndwithCNTL/Z.Router(config)#hostnameR3R3(config)#interfaceserial0R3(config-if)#noshutdownR3(config-if)#ipaddR3(config)#iprouteR3#TypeescapesequencetoSending5,100-byteICMPEchosto,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=4/6/8ms2.配置列表R1(config)#access-list101deny icmphostR1(config)#access-list101permitipanyR1(config)#interfaceR1(config-if)#ipaccess-group101out !如将列表应用在S0口,怎么配置呢?R1#showaccess-list !或者使用showipaccess-listR1#showip在R2上测试R2# !是否能通R2#net !能net到成功马?R1#conft )#noaccess-list101 !删除列表1R1#showrun !检查列表1,还有列表吗?LAB15 Inthislab,youwillconfigureNAT/PATfunctionR1.Youwillconfigurethreeformsoftranslation:staticnetworkaddresstranslation,dynamictranslation,andoverloading(portaddresstranslation).Remembertodisabletheaccesslistsyourconfiguredinthepreviouslabbeforecontinuingthislab.R1,configureNATtostaticallytranslateR2’sEthernetaddresstoR1(config)#ipnatinsidesourcestaticR1(config)#interfaceethernet0R1(config-if)#ipaddressR1(config-if)#ipnatinsideR1(config-if)#interfaceR1(config-if)#ipaddressR1(config-if)#ipnatoutsideR1(config-if)#noTestthestaticNATtranslationbynet’ingfromR2toR3.OnceintoR3,issuetheshowuserscommand.Theoutputofthiscommandshouldshowthat(thetranslatedIPaddress)isthelogged-indevice. netR3#showDisytheNATTranslationtable在R1.TheoutputofthedisyshouldshowthattheinsidelocalIPaddress()istranslatedtotheinsideglobalIPaddress().问题A:doesthe“insideglobalIPaddress”normallyrepresentapublicoraprivateIPR1#showipnatR1,removethepreviousstaticNATcommandsandconfigureNATtotranslateR2’sEthernetaddresstoadynamicallyassignedaddress.Youwillutilizeapoolofpublicaddressesintherangeof0to00.AifthepoolofdynamicallyassignedaddressesonlycontainsoneIPaddressentry,what’sanothertermforthisformofNATtranslation?R1(config)#noipnatinsidesourcestaticR1(config)#ipnatpoolpool1000netmaskR1(config)#ipnatinsidesourcelist1poolpool1R1(config)#access-list1permit55TestthedynamicNATtranslationfunction net’ingfromR2toR3.OnceintoR3,theshowuserscommand.Theoutputofthiscommandshouldshowthatthelogged-indeviceis0(thetranslatedaddress).Also,disytheNATtranslationtable在R1usingtheshowipnattranslationscommand. netR3#showR1#showipnatRemovethepreviousNATcommands.ConfigureNAToverloadingportaddresstranslation)R1totranslateR2’sEthernetaddress(totheserial0interfaceaddress)R1(config)#ipnatinsidesourcelist1interfaceserial0overloadR1(config)#interfaceEthernet0R1(config-if)#ipaddressR1(config-if)#ipnatinsideR1(config-if)#interfaceserialR1(config-if)#ipaddressR1(config-if)#ipnatoutsideR1(config-if)#R1(config)#access-list1permitTesttheoverloading(PAT)functionbynet’ingfromR2toR3.IssuetheshowuserscommandR3.Itshouldshowthatthelogged-indeviceis(thetranslatedIPaddress).Also,issuetheshowipnattranslationscommand在R1todisytheNATtranslationtable. netR3#showR1#showipnatRemoveallNAT/PATconfigurationcommandsfromR1beforecontinuingonwiththeCCNAlabs.LAB16-PPP&R1#conftR1(config)#ints0R1(config-if)#noshR1(config-if)#ipaddR1(config-if)#clockrR1(config)#ints1R1(config-if)#ipaddR1(config-if)#noshR1(config-if)#clockrtR2(config)#hostnameR2R2(config)#ints0R2(config-if)#ipaddressR2(config-if)#noshR1#showinterfacesserialR1和R2上配置PPP封装R1(config)#interfaceserial0R1(config-if)#encapsulationpppR2(config)#interfaceserial0R2(config-if)#encapsulationppprouterx#showinterfacesserial0!PPP了吗?R1#配置R1(config)#usernameR2passwordciscoR1(config)#interfaceserial0R1(config-if)#pppauthenticationchapR2(config)#usernameR1passwordciscoR2(config)#interfaceserial0R2(config-if)#pppauthentication检查接口状态R1#showinterfacesserial0R1#R1(config)#interfaceserial0R1#debugpppR1(config-if)#noPPPLAB17ISDNBRI-BRIDDR配ISDN#--R1(config)#isdnswitch-typebasic-net3R1(config)#dialer-list1protocolippermitR1(config)#usernameR2passwordciscoR1(config)#interfacebri0R1(config-if)#encapR1(config-if)#ipaddressR1(config-if)#dialer-groupR1(config-if)#dialermapipnameR2broadcastR1(config-if)#pppauthenticationchapR1(config-if)#noR2(config)#isdnswitch-typebasic-net3R2(config)#dialer-list1protocolippermitR2(config)#usernameR1passwordciscoR2(config)#interfacebri0/0R2(config-if)#encapR2(config-if)#ipaddressR2(config-if)#dialer-groupR2(config-if)#dialermapipnameR1broadcastR2(config-if)#pppauthenticationchapR2(config-if)#no检查ISDN链路状态Layer1:Layer2:MultipleFrameEstablishedwithspid1routerx#showisdnA:whatstatusaretheBchannels?R1#showinterfaces !显示DR1#showinterfacesbri01 !显示BAwhichconfigurationparameter(s)R1identifiestheinterestingtrafficthatwilltriggeracall?R1#检查ISDNA:whatdoesitshowforthe‘Layer3R1#showisdn检查BA:whatisthestatusofthetwoBR1#showinterfacesbri01LAB18ISDNBRI-BRIusingDialerProfiles(不要求掌握#-i-iISDNInthislab,youwillconfigureISDNBRI在R1andR2usingdialerprofiles.Withdialerprofiles,youareeffectivelymovingsomeofthelogicalISDNparametersfromthephysicalBRI/PRIinterfacetoadialerinterface.AnyIPpacketshouldrepresent‘interestingtraffic’inthislabandeitherroutershouldbeabletoinitiatethecall.PPPencapsulationandCHAPauthenticationshouldbeused.RefertothetableaboveforISDNswitch-type,IPaddresses,subnetmasks,andephonenumbers.R1(config)#isdnswitch-typebasic-net3R1(config)#dialer-list1protocolippermitR1(config)#usernameR2passwordciscoR1(config)#interfacebri0R1(config-if)#encapR1(config-if)#pppauthenticationchapR1(config-if)#isdnspid132122094760100R1(config-if)#dialerpool-member1R1(config-if)#noshutR1(config-if)#interfacedialer1R1(config-if)#noshutR1(config-if)#ipaddressR1(config-if)#encappppR1(config-if)#dialer-group1R1(config-if)#dialerpool1R1(config-if)#dialerremote-nameR2R1(config-if)#dialerstring pppauthenticationchapR2(config)#isdnswitch-typebasic-net3R2(config)#dialer-list1protocolippermitR2(config)#usernameR1passwordciscoR2(config)#interfacebri0/0R2(config-if)#encapR2(config-if)#pppauthenticationchapR2(config-if)#isdnspid132177820020100R2(config-if)#dialerpool-member1R2(config-if)#noshutR2(config-if)#interfacedialer1R2(config-if)#noshutR2(config-if)#ipaddressR2(config-if)#encappppR2(config-if)#dialer-group1R2(config-if)#dialerpool1R2(config-if)#dialerremote-nameR1R2(config-if)#dialerstring pppauthenticationIssuetheshowisdnstatuscommandonbothR1andR2.YoushouldLayer1:Layer2:MultipleFrameEstablishedwithspid1valid.routerx#showisdnstatusIssuetheshowinterfacesbri0command在R1.ThisdisysthesignalingorChannel.Itshouldshow‘UpandUp(spoofing)’ifitisreadytohandleacallrequest. issuethecommandshowinterfacesbri012.Thisshouldshowthestatusofthetwodata,orBR1#showinterfacesbri0R1#showinterfacesbri012FromR1,theISDNinterfaceofR2.ThisshouldcauseanISDNcalltobeinitiatedthesshouldR1#IssuetheshowisdnstatuscommandR1.UndertheLayer3statusintheoutputitshouldshowonecallactive.R1#showisdnIssuetheshowinterfacesbri012commandR1.ThisshowsthestatusoftheBchannels(datachannels).OneoftheBchannelsshouldhaveastatusof‘UPandUP’indicatingasuccessfulcallisinprogress.R1#showinterfacesbri01LAB19–ISDNPRIusingDialer (
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- Cefotaxime-d3-Cefotaxim-d-sub-3-sub-生命科学试剂-MCE-1932
- 二零二五年度生物基因编辑技术研发合作保密协议
- 2025年度药店全职员工聘用合同
- 2025年度银企合作风险控制与业务拓展合同标准
- 2025年度二零二五年度门面房使用权拍卖合同
- 2025年度鱼塘承包合同书:鱼塘承包与渔业市场拓展合作合同
- 2025年度超市租赁合同排他性节假日营销活动策划协议
- 二零二五年度终止合伙合同-海洋资源开发合作终止协议
- 个人机械租赁合同范本
- 上海市电子产品购销合同
- 2025-2030年中国纳米氧化铝行业发展前景与投资战略研究报告新版
- 2025年度正规离婚协议书电子版下载服务
- 2025年贵州蔬菜集团有限公司招聘笔试参考题库含答案解析
- 煤矿安全生产方针及法律法规课件
- 进入答辩环节的高职应用技术推广中心申报书(最终版)
- 2022-2023学年上海市杨浦区上海同济大附属存志学校七年级数学第二学期期中综合测试模拟试题含解析
- 稿件修改说明(模板)
- GB/T 33107-2016工业用碳酸二甲酯
- GB/T 16604-2017涤纶工业长丝
- 劳动合同法经典讲义
- 工时定额编制标准(焊接)
评论
0/150
提交评论