【正文】
23SW1(configif)switchport mode trunk%LINEPROTO5UPDOWN: Line protocol on Interface FastEthernet0/23, changed state to down%LINEPROTO5UPDOWN: Line protocol on Interface FastEthernet0/23, changed state to upSW1(configif)int fa0/24SW1(configif)swi mode trunk%LINEPROTO5UPDOWN: Line protocol on Interface FastEthernet0/24, changed state to down%LINEPROTO5UPDOWN: Line protocol on Interface FastEthernet0/24, changed state to up SW2的配置SW2(config)vtp domain caChanging VTP domain name from NULL to caSW2(config)vtp mode clientSetting device to VTP CLIENT mode.SW2(config)int fa0/23SW2(configif)%LINEPROTO5UPDOWN: Line protocol on Interface FastEthernet0/23, changed state to downSW2(configif)swi mode trunkSW2(configif)int fa0/24SW2(configif)swi mode trunk%LINEPROTO5UPDOWN: Line protocol on Interface FastEthernet0/24, changed state to down%LINEPROTO5UPDOWN: Line protocol on Interface FastEthernet0/24, changed state to up因?yàn)樗伎平粨Q機(jī)默認(rèn)是VTPServer,所以SW1是需要配置VTP域名就可以。 VLAN劃分 交換機(jī)VLAN配置在VTP Server交換機(jī)SW1上添加VLAN,并把端口加入到對(duì)應(yīng)的VLAN中。SW1和R1之間的鏈路要配置成主干鏈路,SW1的配置如下:SW1(config)int fa0/1SW1(configif)swi mode trunk%LINEPROTO5UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to down%LINEPROTO5UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to up路由器R1的配置如下:R1(config)int fa0/%LINK5CHANGED: Interface FastEthernet0/, changed state to up%LINEPROTO5UPDOWN: Line protocol on Interface FastEthernet0/, changed state to upR1(configsubif)encapsulation dot1Q 1R1(configsubif)ip add R1(configsubif)int fa0/%LINK5CHANGED: Interface FastEthernet0/, changed state to up%LINEPROTO5UPDOWN: Line protocol on Interface FastEthernet0/, changed state to upR1(configsubif)enca dot 2R1(configsubif)ip add R1(configsubif)int fa0/%LINK5CHANGED: Interface FastEthernet0/, changed state to up%LINEPROTO5UPDOWN: Line protocol on Interface FastEthernet0/, changed state to upR1(configsubif)enca dot 3R1(configsubif)ip add 配置STP協(xié)議配置前線查看STP協(xié)議運(yùn)行情況,SW1上顯示如下:SW1show spanningtreeVLAN0001 Spanning tree enabled protocol ieee Root ID Priority 32769 Address Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32769 (priority 32768 sysidext 1) Address Aging Time 300Interface Role Sts Cost Type Fa0/1 Desg FWD 19 ShrFa0/23 Altn BLK 19 ShrFa0/24 Root FWD 19 ShrVLAN0002 Spanning tree enabled protocol ieee Root ID Priority 32770 Address Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32770 (priority 32768 sysidext 2) Address Aging Time 300Interface Role Sts Cost Type Fa0/1 Desg FWD 19 ShrFa0/2 Desg FWD 19 ShrFa0/23 Altn BLK 19 ShrFa0/24 Root FWD 19 ShrVLAN0003 Spanning tree enabled protocol ieee Root ID Priority 32771 Address Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32771 (priority 32768 sysidext 3) Address Aging Time 300Interface Role Sts Cost Type Fa0/1 Desg FWD 19 ShrFa0/3 Desg FWD 19 ShrFa0/23 Altn BLK 19 ShrFa0/24 Root FWD 19 Shr從上面的輸出可以看到,交換機(jī)上默認(rèn)運(yùn)行的是PVST+,在VLANVLAN和VLAN3中,SW1都不是跟交換機(jī),交換機(jī)上使用了擴(kuò)展的systemID,systemID等于每個(gè)VLAN的編號(hào)。網(wǎng)絡(luò)中只有兩臺(tái)交換機(jī),既然SW1不是根交換機(jī),那么跟交換機(jī)是SW2。 那么接下來(lái)配置ACL訪問(wèn)控制列表。顯示如圖52圖52 測(cè)試Internet部分連通性 NAT的驗(yàn)證在PCPCPCPC4上PingWeb服務(wù)器的IP地址,顯示如圖53:圖53 PC1與Web的連通性在路由器R1上使用“show ipnat translations”命令,查看路由器R1上配置的靜態(tài)和產(chǎn)生的動(dòng)態(tài)轉(zhuǎn)換條目,如圖54所示圖54 NAT顯示從圖中可以看到,最終實(shí)驗(yàn)拓?fù)鋱D如下:總結(jié)本企業(yè)網(wǎng)設(shè)計(jì)中,我們從交換模塊、路由器模塊兩個(gè)部分進(jìn)行設(shè)計(jì)。交換模塊我們根據(jù)各部門(mén)職能不同劃分了2個(gè)VLAN,各部門(mén)VLAN被劃分為多個(gè)廣播域,從而有效地控制廣播風(fēng)暴的發(fā)生,以及使網(wǎng)絡(luò)的拓?fù)浣Y(jié)構(gòu)變得非常靈活的優(yōu)點(diǎn)外,通過(guò)啟動(dòng)三層交換機(jī)路由功能同時(shí)設(shè)置ACL,還可以用于控制網(wǎng)絡(luò)中不同部門(mén)間的互訪。通過(guò)設(shè)置路由器的ACL,限制Internet對(duì)企業(yè)內(nèi)部網(wǎng)的訪問(wèn),增強(qiáng)了網(wǎng)絡(luò)安全性。 Keith W. Ross,陳鳴譯,計(jì)算機(jī)網(wǎng)絡(luò)—自頂向下方法(第4版),北京:機(jī)械工業(yè)出版社,2009。 李立軍,電子工業(yè)出版社,2007。5. 謝希仁,計(jì)算機(jī)網(wǎng)絡(luò)(第5版),北京:電子工業(yè)出版社,2009。7. 銳捷公司路由器、交換機(jī)隨機(jī)手冊(cè)。,王兆文譯,CCNP SWITCH 人民郵電出版社, 2010,復(fù)俊杰譯 CCNP TSHOOT 人民郵電出版社,2010,王兆文譯 CCNP ROUTE 人民郵電出版社,2010致謝在此要感謝我的指導(dǎo)老師郭輝老師對(duì)我悉心的指導(dǎo),感謝老師給我的幫助。在整個(gè)設(shè)計(jì)中我懂得了許多東西,也培養(yǎng)了我獨(dú)立工作的能力,樹(shù)立了對(duì)自己工作能力的信心,相信會(huì)對(duì)今后的學(xué)習(xí)工作生活有非常重要的影響。雖然這個(gè)設(shè)計(jì)做的也不太好,但是在設(shè)計(jì)過(guò)程中所學(xué)到的東西是這次畢業(yè)設(shè)計(jì)的最大收獲和財(cái)富,使我