网络系统建设与运维初级 6.4 综合实验_第1页
网络系统建设与运维初级 6.4 综合实验_第2页
网络系统建设与运维初级 6.4 综合实验_第3页
网络系统建设与运维初级 6.4 综合实验_第4页
网络系统建设与运维初级 6.4 综合实验_第5页
已阅读5页,还剩37页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

4.IPv4编址及静态路由配置您是公司的网络管理员,现在公司安排您来组建企业网。通过本项目可以掌握如下知识点和技能点。本项目的主要任务是复习与巩固网络运维相关的知识点和能力。步骤7STelnet远程登步骤10电子标签、配置文件等资步骤1数据准备。型U=untaggedT=tagged4To_staffAccess4Access115To_staffAccess51无无无huaweihuawei@B1webuserhuawei123huaweihuawei@B2huaweihuawei@HQhuawei123步骤1设备名称和接口描述等基础配置,此处列出HQ-R上的配置,其他设备的基础Entersystemview,returnuserviewwi[HQ-R]interfaceGigabi[HQ-R-GigabitEthernet0/0/0]descrip[HQ-R]interfaceGigabi[HQ-R-GigabitEthernet0/0/1]descrip[HQ-R]interfaceGigabit[HQ-R-GigabitEthernet0/0/2]descri[HQ-S-1-Eth-Trunk1]m[HQ-S-1]interfaceGigabi[HQ-S-1-GigabitEthernet0/0/[HQ-S-1]interfaceGigabi[HQ-S-2-Eth-Trunk1]m[HQ-S-2]interfaceGiga[HQ-S-2]interfaceGigabi[HQ-S-1]interfaceGigabi[HQ-S-1-GigabitEthernet0/0/1]port[HQ-S-1-GigabitEthernet0/0/1]porthybridp[HQ-S-1-GigabitEthernet0/0/1]porthybrid[HQ-S-1]interfaceGigabi[HQ-S-1-GigabitEthernet0/0/2]port[HQ-S-1-GigabitEthernet0/0/2]portde[HQ-S-1-GigabitEthe[HQ-S-1]interfaceGigabitE[HQ-S-1-GigabitEthernet0/0/24]porthybrid[HQ-S-1-GigabitEthe[HQ-S-1-Eth-Trunk1]portli[HQ-S-1-Eth-Trunk1]porttrunka[HQ-S-2]interfaceGigabi[HQ-S-2-GigabitEthernet0/0/1]port[HQ-S-2-GigabitEthernet0/0/1]port[HQ-S-2-GigabitEthernet0/0/1]porthybrid[HQ-S-2]interfaceGigabi[HQ-S-2-GigabitEthernet0/0/2]port[HQ-S-2-GigabitEthernet0/0/2]portdefaultv[HQ-S-2-Eth-Trunk1]portli[HQ-S-2-Eth-Trunk1]porttrunka步骤4IPv4编址。按表[B1-R]interfaceGigabi[B1-R]interfaceGigabi[B2-R]interfaceGigabi[B2-R]interfaceGigabi[HQ-R]interfaceGigabi[HQ-R]interfaceGigabi[HQ-R]interfaceGigabi步骤5静态路由配置,假定分公司访问互联网需要经过总部HQ-R上中转。因此对于分公司之间的通信,采用浮动路由配置,主路由为B1R到B2R互联的链路,备份路由为经过HQR再到B2R的链路,具体配置如下。lB2R上的配置。与B1R类似,B2R上配置一条缺省路步骤6Telnet远程登[B1-R]user-interface[B1-R]user-interface[B1-R-ui-vty0-4]authenticaPleaseconfiguretheloginpasswor[B1-R-ui-vty0-4]userprivilegel[B1-R]superpassword[B1-R]superpassword[B2-R-aaa]local-userhuaweipasswor[B2-R-aaa]local-userhuaweiservice-[B2-R-aaa]local-userhuaweiprivile[B2-R-ui-vty0-4]auth[B2-R-ui-vty0-4]userpriv[B2-R]superpassword[HQ-R-aaa]local-userhuaweipasswo[HQ-R-aaa]local-userhuaweiprivilegel[HQ-R-aaa]local-userhuaw[HQR]user-interface[HQR]user-interface[HQR-ui-vty0-4]authentic[HQR-ui-vty0-4]userprivilegele[HQ-R]rsalocal-key-paThekeynamewillb%RSAkeysdefinedforHosConfirmtoreplacethem?(yTherangeofpublickeysizeis(512~2048).NOTES:Ifthekeymodulusisgreaterthan512,Inputthebitsinthemodulus[default=Generatingkeys..............................[HQ-R]sshuserhuaweiauthenticat[HQ-R]sshuserhuaweiauthenticat步骤8配置Web登录相关设置。配“huawei123”,https端[B1-R-aaa]local-userwebuserpasswordc[B1-R-aaa]local-userwebuser[B1-R-aaa]local-userwebuserse[B1-R]httpserverpermitinterfaceGiga注:在使能HTTPS服务时,可能会提示没有配置S[B1-R]sslpolicyde[B1-R-ssl-policy-default][B1-R]httpsecure-serv步骤9FTP服务器搭建。该部分配置实验只要求在HQ-R上完成。要求路由器HQ-R上搭建FTP服务器,FTP用户名为[HQ-R]setdefaultftp-di[HQ-R-aaa]local-userftpuserpasswordciph[HQ-R-aaa]local-userftpuserse[HQ-R-aaa]local-userftpuserftp-d步骤10电子标签、配置文件等备1)路由器HQR上执行如下操作,将电子标签备份到本地,建议文件名为“设备-elabel-日期”。[HQ-R]backupelabel[HQ-R]backupelabel<<HQ-R>saveHQR-cfg-0506.zipAreyousuretosavetheconfigurationtoHQR-cfg-0506.zipItwilltakeseveralminutestosaveconfigurationfConfigurationfilehadbeeNote:Theconfigurationfilewilltakeeffectafter3)维护终端上执行如下操作,将电子标签、配置文件保存到计算机。530PleaseloginwithUSER用户(:(none)):f331Passwordrequiredfor684May0607:09rsa_host_key.efs2263May0604:49statemach.efs223May0604:56private-150OpeningBINARYmodedataconnectionf150OpeningBINARYmodedataconnectionEth-Trunk1'sstateinfHasharithmetic:AccordNumberOfUpPortInTrunk:2ActorPortNameStatusPortTypePortPriPortNoPortKeyPortStateWeight-------------------------------------------------------------------------ActorPortNameSysPriSystemIDPortPriPortNoPortKeyPoEth-Trunk1'sstateinfHasharithmetic:AccoNumberOfUpPortInTrunk:2 ActorPortNameStatusPortTypePortPriPortNoPortKeyPortStateW-------------------------------------------------------------------------ActorPortNamePortPriPortNoPortKeyPort4c1f-ccd7-178614411111111111111111111155111111111111111111111的Ping2的Ping步骤3执行[displayipinterf<B1-R><B1-R>displayipinterfacebriefThenumberofinterfacethatisUPinPhysicalis4ThenumberofinterfacethatisThenumberofinterfacethatisUPinProtocolis4ThenumberofinterfacethatisDOWNinProtocolis1InterfaceIPAddress/MaskGigabitEthernet0/0/0unassignedGigabitEthernet0/0/1/24GigabitEthernet0/0/2/24LoopBack0/24NULL0unassignedupup(s)<B2-R><B2-R>displayipinterfacebriefThenumberofinterfacethatisUPinPhysicalis4ThenumberofinterfacethatisDOWNinPhysicaliThenumberofinterfacethatisUPinProtocolis4ThenumberofinterfacethatisDOWNinProtocolis1ProtocolupupupupNULL0unassignedupupup(s)up(s)<HQ-R>displayipinterfacebriefThenumberofinterfacethatisUPinPhysicalis5ThenumberofinterfacethatisDOWNinPhyThenumberofinterfacethatisUPinProtocolis5ThenumberofinterfacethatisDOWNinProtocolis0Protocolupupupupupupupup(s)NULL0unassignedupup(s)<B1-R>dispiprouting-tableprotocolstaRouteFlags:R-relay,Destination/MaskProtoPreCoNextHop00Destination/MaskProtoPreCNextHopR<B2-R>displayiprouting-tableprotocolstRouteFlags:R-relay,NextHop00Destination/MaskProtoPreCNextHopR<HQ-R>displayiprouting-tableprotocolstaticRouteFlags:R-relay,-----------------------------------------------------------------------NextHop0000总部PC测试到分公司2的连通性并跟踪路由。12123123tracerouteto(),maxhops:30,packetlength:40,pressCTRL_C120ms20ms10msB1-R上关闭接口GE0/0/2(模拟接口故障),此份链路(绕行HQ-R)进行通信。查看路<B1-R>displayiprouting-tableprotocolstatRouteFlags:R-relay,NextHop00PreCostFlaNextHoptracerouteto(),maxhops:30,packetlength:40,pressCTRL_C^Error:UnrecognizedcommandfoundatNowuserprivilegeislevel3,andonlythosecommandsequaltoorlessthanthislPrivilegenote:0-VISIT,1-MOEntersystemview,returnuserviewwit2)B1-R上查看Telnet服务<B1-R>displaytelnetserversUser-IntfDelayTypeNetworkAddressAuthenStatusAuthorcm--------------------------------------------------------------------^Error:Unrecognizedcommandfoundat'^'posiNowuserprivilegeislevel3,andonlythosecommandsequaltoorlessthanthislPrivilegenote:0-VISIT,1-MOEntersystemview,returnuserviewwi2)B2-R上查看Telnet服务User-IntfDelayTypeNetworkAddressAuthenStatusAuthoSSHserverkeygeneConnVerEncryStateAuth-type-------------------------------------------------------------VTY02.0AESrunpassword步骤8查看Web服务器状态,并进行登录管理。:终端上使用URL::8443,进行远程Web登录管理。步骤9终端测试登录HQR的FTP服务器,然后查看FTP服务器相关配置及状态。UsercountTimeoutvalue(inminute)Listeningport21Aclnumberusernamehostportidle<B1-R>displaycurrent-configura##superpasswordlevel3cipher%$%$n=z)5Gcqs:%"<_DrQD#httpsecure-serverssl-policydefahttpsecure-serverenhttpserverpermitinterfaceGigabitEthernet0/0/1##local-userwebuserpasswordcipher%$%$`bv:%2Mi75)G\kG;7local-userwebuserprivilegelevel3local-userwebuserservice-typ#interfaceGigabitEther#interfaceGigabitEther###user-interfacevty04setauthenticationpasswordcipher%$%$Bz1f7*~W3DH`]h8F}K8+,,]VnS`>@\G+`6bw7W!OxI#<B2-R>displaycurrent-configuration[V200R003C00]#sysnameB2-R#superpasswordlevel3cipher%$%$xeW[&$3T"A>hg`Ur$[wV,,uv%$%$#aaaauthentication-schemedefaultauthorization-schemedefaultaccounting-schemedefaultdomaindefaultdomaindefault_adminlocal-useradminpasswordcipher%$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$local-useradminservice-typehttplocal-userhuaweipasswordcipher%$%$>e60(ZMjLKrG-,;1!:=1Q5J@%$%$local-userhuaweiprivilegelevel0local-userhuaweiservice-typetelnet#interfaceGigabitEthernet0/0/0descriptionto-HQ-Ripaddress#interfaceGigabitEthernet0/0/2descriptionto-B1-Ripaddress#interfaceLoopBack0ipaddress#iproute-staticiproute-staticiproute-staticpreference80#user-interfacecon0authentication-modepassworduser-interfacevty04authentication-modeaaauser-interfacevty1620#return[HQ-R]displaycurre##superpasswordlevel3cipher%$%$}*yM's@C3;Mi#lo

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论