B1封装帧中继:
Router(config)#hostname B1 B1(config)#int se 0/0/0
B1(config-if)#encapsulation frame-relay B1(config-if)#frame-relay lmi-type q933a B1(config-if)#frame-relay interface-dlci 100
B1(config-if)#ip add 10.255.255.2 255.255.255.252 B1(config-if)#no shutdown
B1配制单臂路由:
B1(config-if)#exit B1(config)#int fa 0/0 B1(config-if)#no sh
B1(config-if)#no shutdown B1(config-if)#int fa 0/0.10
B1(config-subif)#encapsulation dot1Q 10
B1(config-subif)#ip add 10.1.10.1 255.255.255.0 B1(config-subif)#no shutdown B1(config-subif)#exit B1(config)#int fa 0/0.20
B1(config-subif)#encapsulation dot1Q 20
B1(config-subif)#ip add 10.1.20.1 255.255.255.0 B1(config-subif)#exit B1(config)#int fa 0/0.30
B1(config-subif)#encapsulation dot1Q 30
B1(config-subif)#ip add 10.1.30.1 255.255.255.0 B1(config-subif)#exit B1(config)#int fa 0/0.88
B1(config-subif)#encapsulation dot1Q 88
B1(config-subif)#ip add 10.1.88.1 255.255.255.0 B1(config-subif)#exit B1(config)#int fa 0/0.99
B1(config-subif)#encapsulation dot1Q 99 native B1(config-subif)#ip add 10.1.99.1 255.255.255.0 B1(config-subif)#no sh
B1(config-subif)#no shutdown B1(config-subif)#end B1#copy run start
配制dhcp服务
B1#conf t
B1(config)#ip dhcp pool B1_VLAN10
B1(dhcp-config)#network 10.1.10.0 255.255.255.0 B1(dhcp-config)#default-router 10.1.10.1 B1(dhcp-config)#dns-server 10.0.1.4 B1(dhcp-config)#exit
B1(config)#ip dhcp excluded-address 10.1.10.1 10.1.10.10 B1(config)#ip dhcp pool B1_VLAN20
B1(dhcp-config)#network 10.1.20.0 255.255.255.0 B1(dhcp-config)#default-router 10.1.20.1 B1(dhcp-config)#dns-server 10.0.1.4 B1(dhcp-config)#exit
B1(config)#ip dhcp excluded-address 10.1.20.1 10.1.20.10 B1(config)#ip dhcp pool B1_VLAN30
B1(dhcp-config)#network 10.1.30.0 255.255.255.0 B1(dhcp-config)#default-router 10.1.30.1 B1(dhcp-config)#dns-server 10.0.1.4 B1(dhcp-config)#exit
B1(config)#ip dhcp excluded-address 10.1.30.1 10.1.30.10 B1(config)#ip dhcp excluded-address 10.1.88.1 10.1.88.24 B1(config)#exit
配制eigrp和被动接口
B1(config)#router eigrp 100
B1(config-router)#network 10.1.10.0 B1(config-router)#network 10.1.20.0 B1(config-router)#network 10.1.30.0 B1(config-router)#network 10.1.88.0 B1(config-router)#network 10.1.99.0 B1(config-router)#network 10.255.255. 0 B1(config-router)#no auto-summary
B1(config-router)#passive-interface default B1(config-router)#no passive-interface fa 0/0.88 B1(config)#int se 0/0/0
B1(config-if)#ip summary-address eigrp 100 10.1.0.0 255.255.0.0 配制默认路由:
B1(config)#ip route 0.0.0.0 0.0.0.0 10.255.255.1
B1-S1 配置
Switch(config)#hostname B1-S1 B1-S1(config)#vtp mode server B1-S1(config)#vtp domain xyzcorp B1-S1(config)#vtp password xyzvtp B1-S1#vlan database
B1-S1(vlan)# vlan 10 name Admin
//手动汇总
B1-S1(vlan)# vlan 20 name Sales
B1-S1(vlan)# vlan 30 name Production B1-S1(vlan)# vlan 88 name Wireless
B1-S1(vlan)# vlan 99 name Mgmt&Native B1-S1(config)#int range fa 0/1-5
B1-S1(config-if-range)#switchport mode trunk
B1-S1(config-if-range)#switchport trunk native vlan 99 B1-S1(config-if-range)#exit B1-S1(config)#int vlan 99
B1-S1(config-if)#ip add 10.1.99.21 255.255.255.0 B1-S1(config-if)# no shutdown
B1-S1(config)#ip default-gateway 10.1.99.1
B1-S1(config)#spanning-tree vlan 1 priority 4096 B1-S1(config)#spanning-tree vlan 10 priority 4096 B1-S1(config)#spanning-tree vlan 20 priority 4096 B1-S1(config)#spanning-tree vlan 30 priority 4096 B1-S1(config)#spanning-tree vlan 88 priority 4096 B1-S1(config)#spanning-tree vlan 99 priority 4096
B1-S2 配置
Switch(config)#hostname B1-S2 B1-S2(config)#vtp mode client B1-S2(config)#vtp domain xyzcorp B1-S2(config)#vtp password xyzvtp B1-S2(config)#int vlan 99
B1-S2(config-if)#ip add 10.1.99.22 255.255.255.0 B1-S2(config-if)#no shutdown
B1-S2(config)#ip default-gateway 10.1.99.1 B1-S2(config)#int fa 0/6
B1-S2(config-if)#switchport mode access B1-S2(config-if)#switchport access vlan 10 B1-S2(config-if)#exit B1-S2(config)#int fa 0/11
B1-S2(config-if)#switchport mode access B1-S2(config-if)#switchport access vlan 20 B1-S2(config-if)#exit B1-S2(config)#int fa 0/16
B1-S2(config-if)#switchport mode access B1-S2(config-if)#switchport access vlan 30 B1-S2(config-if)#exit
B1-S2(config)#int range fa 0/1-4
B1-S2(config-if-range)#switchport mode trunk
B1-S2(config-if-range)#switchport trunk native vlan 99
B1-S2(config)#int fa 0/6 //配制端口安全 B1-S2(config-if)#switchport port-security
B1-S2(config-if)#switchport port-security maximum 1
B1-S2(config-if)#switchport port-security mac-address sticky B1-S2(config-if)#switchport port-security violation shutdown B1-S2(config-if)#exit
B1-S2(config)#int fa 0/11 //配制端口安全 B1-S2(config-if)#switchport port-security
B1-S2(config-if)#switchport port-security maximum 1
B1-S2(config-if)#switchport port-security mac-address sticky B1-S2(config-if)#switchport port-security violation shutdown B1-S2(config-if)#exit
B1-S2(config)#int fa 0/16 //配制端口安全 B1-S2(config-if)#switchport port-security
B1-S2(config-if)#switchport port-security maximum 1
B1-S2(config-if)#switchport port-security mac-address sticky B1-S2(config-if)#switchport port-security violation shutdown B1-S2(config-if)#exit
B1-S3 配置
Switch(config)#hostname B1-S3 B1-S3(config)#vtp mode client B1-S3(config)#vtp domain xyzcorp B1-S3(config)#vtp password xyzvtp B1-S3(config)#int vlan 99
B1-S3(config-if)#ip add 10.1.99.23 255.255.255.0 B1-S3(config-if)#no shutdown B1-S3(config-if)#exit
B1-S3(config)#ip default-gateway 10.1.99.1 B1-S3(config)#int range fa 0/1-4
B1-S3(config-if-range)#switchport mode trunk
B1-S3(config-if-range)#switchport trunk native vlan 99 B1-S3(config)#int fa 0/7
B1-S3(config-if)#switchport mode access B1-S3(config-if)#switchport access vlan 88
B1-S3(config)#spanning-tree vlan 1 priority 8192 B1-S3(config)#spanning-tree vlan 10 priority 8192 B1-S3(config)#spanning-tree vlan 20 priority 8192 B1-S3(config)#spanning-tree vlan 30 priority 8192 B1-S3(config)#spanning-tree vlan 88 priority 8192 B1-S3(config)#spanning-tree vlan 99 priority 8192
HQ 配置
Router(config)#hostname HQ HQ(config)#int fa 0/0
HQ(config-if)#ip add 10.0.1.1 255.255.255.0 HQ(config-if)#no shutdown
HQ(config)#username NewB password ciscopap HQ(config)#int se 0/0/1
HQ(config-if)#ip add 10.255.255.253 255.255.255.252 HQ(config-if)#clock rate 64000 HQ(config-if)#encapsulation ppp HQ(config-if)#ppp authentication pap
HQ(config-if)#ppp pap sent-username HQ password ciscopap HQ(config-if)#no shutdown
HQ(config)#username ISP password ciscopap HQ(config)#int se 0/1/0
HQ(config-if)#ip add 209.165.201.1 255.255.255.252 HQ(config-if)#encapsulation ppp
HQ(config-if)#ppp authentication chap HQ(config-if)#exit
HQ(config-if)#no shutdown HQ(config)#int se0/0/0
HQ(config-if)#encapsulation frame-relay HQ(config-if)#frame-relay lmi-type q933a HQ(config-if)#no shutdown
HQ(config)#int se 0/0/0.41 point-to-point
HQ(config-subif)#ip add 10.255.255.1 255.255.255.252 HQ(config-subif)#frame-relay interface-dlci 41 HQ(config-subif)#exit
HQ(config)#int se 0/0/0.42 point-to-point
HQ(config-subif)#ip add 10.255.255.5 255.255.255.252 HQ(config-subif)#frame-relay interface-dlci 42 HQ(config-subif)#exit
HQ(config)#int se 0/0/0.43 point-to-point
HQ(config-subif)#ip add 10.255.255.9 255.255.255.252 HQ(config-subif)#frame-relay interface-dlci 43
HQ(config)#ip nat inside source static 10.0.1.2 209.165.200.246 HQ(config)#int fa 0/0
HQ(config-if)#ip nat inside HQ(config-if)#int se 0/1/0 HQ(config-if)#ip nat outside HQ(config-if)#exit
HQ(config)#ip nat pool XYZCORP 209.165.200.241 209.165.200.245 netmask 255.255.255.248 HQ(config)#ip access-list standard NAT_LIST
HQ(config-std-nacl)#permit 10.0.0.0 0.255.255.255 HQ(config-std-nacl)#exit
HQ(config)#ip nat inside source list NAT_LIST pool XYZCORP HQ(config)#int se 0/0/1 HQ(config-if)#ip nat inside
HQ(config)#int se 0/0/0.41 point-to-point HQ(config-if)#ip nat inside
HQ(config)#int se 0/0/0.42 point-to-point HQ(config-if)#ip nat inside
HQ(config)#int se 0/0/0.43 point-to-point HQ(config-if)#ip nat inside
HQ(config)#ip route 0.0.0.0 0.0.0.0 se0/1/0 // 到ISP的默认路由 HQ(config)#ip route 10.4.5.0 255.255.255.0 se 0/0/1 //到NewB的默认路由 HQ(config)#router eigrp 100
HQ(config-router)#network 10.0.0.0 HQ(config-router)#no auto-summary
HQ(config-router)#passive-interface default
HQ(config-router)#no passive-interface se0/0/0.41 HQ(config-router)#no passive-interface se0/0/0.42
HQ(config-router)#no passive-interface se0/0/0.43 或passive-interface se0/1/0 HQ(config-router)#no passive-interface fa 0/1 或passive-interface se0/0/1 HQ(config)#ip access-list extended FIREWALL
HQ(config-ext-nacl)#permit tcp any host 10.0.1.2 eq 80 HQ(config-ext-nacl)#permit tcp 209.165.201.0 0.0.0.3 any HQ(config-ext-nacl)#permit tcp 209.165.201.136 0.0.0.3 any HQ(config-ext-nacl)#permit tcp 209.165.201.132 0.0.0.3 any HQ(config-ext-nacl)#permit tcp 209.165.201.128 0.0.0.3 any HQ(config-ext-nacl)#permit icmp 209.165.201.0 0.0.0.3 any echo HQ(config-ext-nacl)#permit icmp 209.165.201.136 0.0.0.3 any echo HQ(config-ext-nacl)#permit icmp 209.165.201.132 0.0.0.3 any echo HQ(config-ext-nacl)#permit icmp 209.165.201.128 0.0.0.3 any echo HQ(config-ext-nacl)#exit HQ(config)#int se 0/1/0
HQ(config-if)#ip access-group FIREWALL in HQ(config-if)#exit