四、ccna實驗工大瑞普手冊-lab_第1頁
四、ccna實驗工大瑞普手冊-lab_第2頁
四、ccna實驗工大瑞普手冊-lab_第3頁
四、ccna實驗工大瑞普手冊-lab_第4頁
四、ccna實驗工大瑞普手冊-lab_第5頁
免費預(yù)覽已結(jié)束,剩余35頁可下載查看

下載本文檔

版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進(jìn)行舉報或認(rèn)領(lǐng)

文檔簡介

CISCO3CCIE,100CISCOPIX,3550交換機(jī),7000路由器,兩條ISDN線路基帶MODEM,交換機(jī),NETSCREEN登錄微 本地 Lab1-BasicRouterLab2-AdvancedRouterLab3-Lab4 Lab5-Lab6-Lab7-Lab8-Lab9-Lab10–Catalyst1900SwitchLab11-VLANs&Trunking(CatalystLab12-Catalyst2950SwitchLab13-VLANsandTrunking(CatalystLab13-1RoutinginterLab14-IPAccessLab15-Lab16-PPP&Lab17-ISDNBRI-BRIusingLegacyLab18-ISDNBRI-BRIusingDialerLab19-ISDNPRIusingDialerLab20-FrameLAB1–基本Router>enable//用戶模式敲入enable進(jìn)入到模Router#?//Router# //模式敲入disable退到用戶模Router>enable//用戶模式敲入enable進(jìn)入到模Router#configure //模式敲入configureterminal進(jìn)入配置模 配置路由器名字(主機(jī)名)如‘R1’03,則命名為na03r1,如12,則命名na12r1,依次類推).Router(config)#hostname //12號實驗臺的第一臺路由器命名為配置路由器的配置console口R1(config)#lineconsole0R1(config-line)#passwordcisco設(shè)置后00:29:42:%SYS-5-CONFIG_I:ConfiguredfromconsolebyconsoleUserAccessVerification //這里要輸入console口配置enable//從用戶模式到enable模式的Awhenbothencryptedandunencryptedenablepasswordsareconfigured,whichoneisused?R1(config)#enablepassword //顯示為明R1(config)#enablesecret 注:用命令showrunning-config可以看到cisco為明文,wisdom顯示為亂碼,當(dāng)兩個都配置時,只有enablesecret所跟的生效,兩個不可以配置一樣的.配置vty//登 netR1(config)#linevty04R1(config-line)#passwordcisconet命令的使用 net+IPaddressorhostnameofaremote例如:net配置路由器接口ethernet0的IPR1#configureterminalR1(config)#interfaceethernetR1(config-if)#ipaddressR1(config-if)#noshutdown在Serial0R1(config-if)#intserialR1(config-if)#ipaddressR1(config-if)#noshutdown測試ctrl-zR1(config-if)#ctrl-z任何模式下敲入ctrl-z都會退回到模 模R1#logout回到模R1>password:cisco輸入enablesecret的為cisco顯示接口的基本概況R1#showipinterface顯示詳細(xì)信息:showinterface接口類型+接口偏號R1#showinterfacesethernet0或是showinterfaceserialR1#showinterfacesethernet0Ethernet0isup,lineprotocolisdownHardwareisLance,addressis0000.0c92.8164(bia0000.0c92.8164)Internetaddressis/24MTU1500bytes,BW10000Kbit,DLY1000usec,rely145/255,loadR1#showrunning-config//顯示 Ifnot,whyR1#showstartup-config保存配置R1#copyrunning-configstartup-保存配置:copyrunning-configstartup-config等同于R1#showstartup-使用Show問題A:WhatIOSreleaseisrunning在 查看IOS的版問題B:Whatarethecontentsoftheconfiguration 查看寄存器的R1#showA:whichprotocolsarecurrentlyrunningontheR1#showip進(jìn)入另一臺Router>Router#configureterminal配置主機(jī)名,配置Router(config)#hostnameR2R2(config)#enablesecret配置以太網(wǎng)R2(config)#interfaceR2(config-if)#ipaddressR2(config-if)#noshutdownR2(config-if)#ctrl-R2#showipinterfaceR1#showipinterface OK?MethodStatus YESmanualup YES administrativelydown YES administrativelydown配置登陸信息 etoWISDOMLAB-AuthorizedUsersR1(config)#bannermotdetoWISDOMLAB-AuthorizedUsersOnly password:cisco password:ciscoR1R2對應(yīng)起來(相當(dāng)于WindowsHosts文件的作用)。R1(config)#iphostR2R1中主機(jī)名和IP地址的對應(yīng)R1#showR1#R2上的AwhatisthenameoftheIOSimageinflashandhowlargeisR2#showR2#showSystemflash1[16384KbytesofprocessorboardSystemflash(ReadONLY)顯示R1上曾經(jīng)敲入令,可以看到前10條,可以通過Ctrl+P或向上箭頭調(diào)出這R1#showR1#ctrl- (toseepreviouslyenteredR1#showinterfacesserial0R1#configureterminalR1(config)#interfaceserial0R1S0口接的線是DCE即使你配置了IP也沒法連通。R1(config-if)#clockrate64000R1(config-if)#ctrl-zR1#showinterfacesserial配置接口的R1(config)#interfaceserialR1(config-if)#descriptionSerialLinktoR2R1(config-if)#exitR1(config)#R1#showinterfacesserial驗證兩條常用命令的作用(1)會話退Router(config)#lineconsoleRouter(config-line)#exec-timeout0(2)使光標(biāo)還原到原來的位置,重新顯示被覆蓋Router(config)#lineconsole0Router(config-line)#loggingsynchronousCCNA實驗拓?fù)鋱DR1、R2、R3R1R2R3confconfconfhosthosthostno -no -no -lineconlineconlineconpasspasspassnoexec-noexec-noexec-logglogglogglinevty0linevty0linevty0passpasspassloggnoexec-noexec-noexec-loggloggenaseenaseenaseintintintipaddipaddipaddnonononointintintipaddipaddipaddnonoclonononointintintipaddipaddipaddclonoclonono檢查網(wǎng)絡(luò)的連通性:在R1用來測試網(wǎng)絡(luò)的連通R1#TypeescapesequencetoSending5,100-byteICMPEchosto,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=4/4/4msR1#TypeescapesequencetoSending5,100-byteICMPEchosto,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=4/4/4msR1R2,R3OKLAB3CDP(CISCO的發(fā)現(xiàn)協(xié)議R1#showcdp Informationforspecificneighborentry CDPinterfacestatusandconfiguration CDPneighborentries CDPR1.CDPR1#shcdp顯示鄰居的詳細(xì)信息R1#showcdpneighborsdetailR1#showcdpentry*查看那個接口運行R1#showcdpR1,CDP的計時器R1(config)#cdptimer50R1(config)#cdpholdtime170R1(config)#exitR1#shcdp啟用和禁用R1(config)#nocdprun!路由器運行CDPR1#showcdpnei !檢查看到?jīng)]有CDP運行R1#configureterminalR1(config-if)#nocdpenable !此接口運行CDPR1#showcdpinterface !看不到Serial0運行CDP啟用CDPR1(config)#cdprunR1(config-if)#cdpLAB4 R1#configR1(config)#interfaceserial0R1(config-if)#noshR1(config-if)#clockrateR1(config-if)#ipaddR1(config)#interfaceserail1R1(config-if)#clockrateR1(config-if)#ipaddR1(config-if)#endR2#configR2(config)#interfaceserial0R2(config-if)#noshR2(config-if)#ipaddR3#configR3(config)#interfaceserial0R3(config-if)#noshR3(config-if)#ipadd首先在R2和R3上配置好R3#configtR3(config)#linevty04R3#configtR3(config)#linevty04R1 netR2#showR2CTRL-SHIFT-6X.R2#ctrl-shift-6xR1#shownet netR3>ctrl-shift-6xR1#showR1R1#disconnectR1#disconnect1R1#showsessionsR2R3Showsessionshowuser的區(qū)別DisconnectClearline區(qū)別Ctrl+shift+6xresumeShowsession查看打開了多少個net的會Showuser 查看有誰通過net來連接我 Clearline (Ctrl+shift+6)xnet介面的切換 再次LAB5-R1上配置:R1#conftR1(config)#inte0R1(config-if)#ipaddressR1#98 !tftpServer的地址是49,測試是否能連通R1#copystartup-configtftp把NVRAM里的配置備份到TFTPServerR1#copytftpstartup- 把TFTPServer里的配置文件COPY到R1#copyflash:tftp:IOSTFTPR1#dirIOSDirectoryof1-<no(IOSbytestotalbytesLAB6-R1#configR1(config)#interfaceserial0R1(config-if)#noshR1(config-if)#clockrateR1(config-if)#ipaddR1(config)#interfaceserail1R1(config-if)#clockrateR1(config-if)#ipaddR1(config-if)#exitR1(config)#interfaceethernet0R1(config-if)#ipR1(config-if)#noshutR1(config-if)#nokeepaliveR2#configR2(config)#interfaceserial0R1(config-if)#clockrateR2(config-if)#noshR2(config-if)#ipaddR2(config-if)#ipaddR2(config-if)#noshutR2(config-if)#nokeepaliveR3#configR3(config)#interfaceserial0R3(config-if)#noshR1(config-if)#clockrateR3(config-if)#ipaddR3(config-if)#ipaddR3(config-if)#noshutR3(config-if)#nokeepaliveR1(config)#routerripR1(config-router)#version2R1(config-router)#noauto-summaryR1(config-router)#networkR1(config-router)#networkR1(config-router)#networkR2(config)#routerripR2(config-router)#version2R2(config-router)#noauto-summaryR2(config-router)#networkR2(config-router)#networkR3(config)#routerripR3(config-router)#version2R3(config-router)#noauto-summaryR3(config-router)#networkR3(config-router)#networkR1shipprotocolsR1#showipR1RIPa.RIP的管理距離是多少 showip在R2,R2#R2#使用cleiproute*清除路由表R2#cleariprouteR1使用Debug命令,30秒更新一次路由R1#debugip使用undebugallR1#showdebuging!DebugR1#undebugall!DebugLAB7–假設(shè)所有路由器已經(jīng)配置好了IP地址(路已經(jīng)修好了)RIProuterx(config)#norouterriprouterx#showipprotocolsR1,R2,R3,R1(config)#routerigrp100R1(config-router)#networkR1(config-router)#networkR1(config-router)#networkR2(config)#routerigrp100R2(config-router)#networkR2(config-router)#networkR3(config)#routerigrp100R3(config-router)#networkR3(config-router)#network顯示動態(tài)路由協(xié)議A:howfrequentlydoesIGRPsendoutroutingBwhatistheholddownintervalforIGRP?問題C:whatisthedefaulthopcountforIGRP?R1#showipprotocols顯示IP路由A:whatistheadministrativedistanceforR1#showip在R2,R2#R2#A:whatisthedifferencebetweenthetwodebugipigrpR1#debugipigrpR1#debugipigrpLAB8–清除剛才配置的IGRProuterx(config)#norouterigrp100R1(config)#routereigrp1R1(config-router)#noauto-summaryR1(config-router)#networkR1(config-router)#networkR1(config-router)#networkR2(config)#routereigrp1R2(config-router)#noauto-summaryR2(config-router)#networkR2(config-router)#networkR3(config)#routereigrp1R3(config-router)#noauto-summaryR3(config-router)#networkR3(config-router)#network查看路由協(xié)議問題A:whatistheumrouterhopcountwithrouter4#showipR1上顯示EIGRP鄰居R1#showipeigrpR1是能夠顯示EIGRP包的發(fā)送和接受數(shù)量R1#showipeigrpR1上顯示EIGRPtopologyA:whatdoestheEIGRPtopologydatabaseR1#showipeigrpR2A:EIGRP的管理距離多少router4#showip在R2#R2#R1#debugipLAB9-naxxx(config)#noroutereigrpR1的LOOPBACK地址作為ROUTER-interfaceloopbackipadderssR2的LOOPBACK地址作為ROUTER-interfaceloopbackipadderssR3的LOOPBACK地址作為ROUTER-interfaceloopbackipadderssR1(config)#routerospf1R1(config-router)#router-idR1(config-router)#network55areaR1(config-router)#network55areaR1(config-router)#network55areaR2(config)#routerospf1R2(config-router)#router-idR2(config-router)#networkareaR2(config-router)#networkareaR3(config)#routerospf1R3(config-router)#router-id3.3..3.3R3(config-router)#networkareaR3(config-router)#networkarea顯示路由協(xié)議信息A:HowfrequentlydoesOSPFsendroutingR1#shipR1上檢查鄰居R1#shipospfR1OSPF的接口A:10MbpsCOST是多少R1#shipospf檢查路由表A:OSPF的管理距離多少router4#showip在R2,R2#R2#LAB10CATALYST1900SWITCH配置(不要求#?#>Onswitch1,gointoprivilegedmodeandthenintoglobalconfigurationmode.AssignSwitch1ahostnameof1900sw1.Useexitorctrl-ztogetoutofconfigurationmode. configureterminal(config)#hostname1900sw11900sw1(config)#exitOnswitch1,typeshowrunning-configtoseetheactiveADoyouneedtoissuecopyrunning-configstartup-configontheCatalyst1900tosavetherunningconfiguration?Ifnot,why1900sw1#showrunning-Onswitch1,erasethecurrentconfigurationwiththefollowing1900sw1#deleteOnswitch1,getintoprivilegedmodeandthenintoglobalconfiguration.Reassigntheswitchahostnameof1900sw1andanenablepasswordof‘cisco’.AssigntheswitchanIPaddressof9withasubnetmaskof.Assigntheswitchadefaultgatewayof(router4’sEthernet#configure(config)#hostname1900sw1(config)#enablepasswordlevel15cisco1900sw1(config)#ipaddress91900sw1(config)#ipdefault-gatewayOnswitch1,issuetheshowipcommandtoverifythattheIPaddress,mask,andgatewayare1900sw1#showOnswitch1,issuetheshowinterfacesA:WhatistheSpanningTree802.1D)stateofinterfaceB:Whatistheduplexsettingforinterface1900sw1#showFromtheNetSimtoolbar,selectSwitch2(Catalyst1900).Configureitwithahostnameof1900sw2andanenablepasswordofcisco(theenablepasswordshouldbeencryptedwhendisyingtheconfigurationfile).AssignanIPaddressof00/24andadefault-gatewayof#configure(config)#hostname1900sw21900sw2(config)#enablesecretlevel15cisco1900sw2(config)#ipaddress001900sw2(config)#ipdefault-gatewayOnswitch2,issuetheshowversionA:WhatversionofIOSistheswitchB:WhatisthebaseEthernetaddressof1900sw2#showOnswitch1,issuetheshowspantreeA:whatistheaddressoftherootBwhatistheportcostofE0/1?問題C:whatisthemaxageinterval?問題D:whatistheointerval?1900sw1#showOnswitch1,issuetheshowmac-address-tablecommand.Thisshowswhichdevicesareattachedtowhichswitchports.1900sw1#showmac-address-Onswitch1,permanentlyassignadevicewithMACaddress1111-1111-1111toportE0/5.Issuetheshowmac-address-tablecommandtoverifythedeviceisinthetableasapermanententry.1900sw1(config)#mac-address-tablepermanent1111-1111-1111e0/51900sw1(config)#exit1900sw1#showmac-address-Onswitch1,configureportsecurityforporte0/9.Theswitchwill‘sticky-learn’theMACaddressofthedeviceconnectedtoporte0/9andwillonlyallowthatdevicetoconnecttothisportinthefuture.1900sw1(config)#interfacee0/91900sw1(config-if)#port1900sw1(config-if)#portsecuremax-mac-countLAB11–VLANsand (Catalyst1900Inthislab,youwillsetupVLANsontheCatalyst1900switchesandtestthembyingbetweenrouter4andPC1.Router4isconnectedtoe0/1onswitch1andPC1isconnectedtoe0/1onswitch2.Switch1andswitch2areinterconnectedthroughtheirfa0/26FastEthernetUsingwinipcfgonPC1,configureanIPaddressof/24andadefaultgatewayof(ifnotalreadyconfiguredfromapreviousc:>VerifyyoucanpresentlybetweenPC1androuter4.Ifyoucannotsuccessfully,checkthatrouter4’sEthernet0IPaddressis/24andthattheinterfaceisenabled.Also,usingthewinipcfgutility,checkthatthePChasaconfiguredIPaddressofc:>Onswitch1andswitch2,issuetheshowvlancommand.Youshouldnotethat,bydefault,allswitchportsareinVLAN1.Becauserouter4,PC1,andtheswitch-to-switchlinkareallinVLAN1,shouldbeabletobetweenPC1androuter4. showOnswitch1andswitch2,setupaVTPcalledbig.Verifyithasbeencreatedwiththeshowvtpcommand.A:whatVTPoperatingmodearetheswitches1900swx(config)#vtp 1900swx(config)#exit1900swx#showOnswitch1andswitch2,createVLAN10,callingitccnavlan.Issuetheshowvlancommandtoverifyitwassuccessfullycreated.A:doyouseeanyportsconnectedtoVLAN10.Ifnot,why1900swx(config)#vlan10nameccnavlan1900swx(config)#exit1900swx#showOnswitch1andswitch2,assignthee0/1portstothenewVLANyoucreated.Router4andPC1areattachedtotheseports.IssuetheshowvlancommandonbothswitchestoverifytheseportshavebeenmovedtoVLAN10.Also,issuetheshowvlan-membershipcommand.ThisisanothercommandthatshowsVLANassignmentsbyportonthe1900.1900swx(config)#interfacee0/11900swx(config-if)#vlan-membershipstatic101900swx(config-if)#ctrl-z1900swx#show1900swx#showvlan-Nowthatbothrouter4andPC1areinVLAN10,trytofromthePC1torouter4.Itshouldfail.問題A:ifbothdevicesareinthesameVLAN,whyshouldthesc:>Makethelinkbetweenswitch1andswitch2atrunklinecapableofcarryingtrafficforanyVLAN.Usetheshowtrunkacommandtoverifytrunkingisenabledonportfa0/26onbothswitches(itshouldsay“Trunking:on”)A:whattrunkingprotocoldoesthe1900use–ISLor1900swx(config)#interfacefa0/261900swx(config-if)#trunkon1900swx(config-if)#ctrl-z1900swx#showtrunkaNowbetweenPC1androuter4.ThesshouldsucceedbecausebothdevicesarethesameVLANandtheinter-switchlinkisatrunklinecapableofcarryingtrafficforanyc:>LAB12-2950交換機(jī)配Switch>enableSwitch#?Switch#disableSwitch>Switch#configureterminalSwitchconfig)#hostnamesw2950sw2050(config)#exitsw2950#showrunning-sw2950#copyrunning-configstartup-configsw2950#showstartup-config刪除配置,sw2950#erasestartup- sw2950#reload配置交換機(jī)的IP交換機(jī)的IP地址和網(wǎng)關(guān)只是為了方便來管理交換機(jī)而設(shè)置Switch>Switch#configureSwitch(config)#hostnamesw2950sw2950(config)#enablepasswordciscosw2950(config)#interfacevlan1sw2950(config-if)#ipaddress9sw2950(config-if)#noshutdownsw2950(config-if)#sw2950(config)#ipdefault-gateway//sw2950#showinterfacevlan1SW2950(config)#interfacefastEthernetSW2950(config-if)#duplex EnableAUTOduplexconfigurationfullfullduplexoperationhalfhalf-duplexSW2950(config-if)#duplexfullfastEthernet0/1100MOnswitch3issuetheshowinterfacescommand.問題A:interfacefa0/1的生成樹狀態(tài)是什么?問題B:fa0/2的雙工模式是什么?sw2950#showinterfacessw2950#showversion使用Showspanning-A:根網(wǎng)橋的網(wǎng)橋ID是多少?問題B:fa0/1的COST是多少?問題C:maxage是多少?問題D:o間隔是多少?sw2950#showspanning-tree//檢查生成樹狀態(tài)檢查MACsw2950#showmac-address-MACsw2950(config)#mac-address-tablestatic4444-4444-4444vlan1intfa0/5sw2950(config)#exitsw2950#showmac-address-sw2950(config)#interfacefa0/9sw2950(config-if)#switchportport-securitysw2950(config-if)#switchportport- umsw2950(config-if)#switchportport-securitymac-address-tableSW2950(config-if)#switchportport-securityviolationprotect/restrict/ Securityviolationprotectmode Securityviolationrestrictmode SecurityviolationshutdownLAB13–VLANsand1 showISLSw01(config)#interfacefa0/1sw01(config-if)#switchportmodetrunkSw01(conifg-if)#swtichporttrunkencapsulationisl !2950交換機(jī)不能敲入此命令缺省為dot1Qsw01(config-if)#ctrl-zsw01#showinterfacefa0/1Sw01(config)#interfacefa0/1sw01(config-if)#switchportmodetrunk !2950sw01(config-if)#ctrl-sw01#showinterfacefa0/1DOT1QSw01(config)#interfacefa0/1sw01(config-if)#switchportmodetrunk !2950sw01(config-if)#ctrl-sw01#showinterfacefa0/1Sw01(config)#interfacefa0/1sw01(config-if)#switchportmodetrunk !2950sw01(config-if)#ctrl-sw01#showinterfacefa0/1VTP(兩種方法第一種sw01#vlandatabasesw01(vlan)#vtp sw01(vlan)#vtpserversw01(vlan)#ctrl-zsw01#showvtp第二種 sw01(vlan)#vtpmodeserversw01#showvtpsw02#vlandatabasesw02(vlan)#vtp sw02(vlan)#ctrl-zsw02#showvtpstatussw01#vlandatabasesw01(vlan)#vlan2namevlan2sw01(vlan)#vlan3namevlan3sw01(vlan)#exitsw01#show在sw02Vlan,Vlan2,3Sw02#showvlan在sw01上將f0/4Vlan2,在Sw02f0/6Vlan2,f0/10Sw01(config)#interfaceSw01(config-if)#switchportmodeaccessSw01(config-if)#switchportaccessvlan2Sw02(config)#interfacefa0/6Sw02(config-if)#switchportmodeaccessSw02(config-if)#switchportaccessvlan2Sw02(config)#interfacefa0/10Sw02(config-if)#switchportmodeaccessSw02(config-if)#switchportaccessvlan3Sw02(config-if)#ctrl-z2950swx#showR1、R2和R3的IPR1(config)#interfacee0R1(config-if)#ipaddR2(config)#interfacee0R2(config-if)#ipaddR3(config)#interfacee0R3(config-if)#ipadd在R1上能通,不能通R1#R1#LAB13–1VLAN間路4.1.1Router#configuretRouter#configureterminalRouter(config)#hostnameR2610R2610(config)#interfacee0/0R2610(config-if)#noshutdownR2610(config-if)#noipaddressR2610(config)#interfacee0/0.2R2610(config-subif)#encapsulationdot1QR2610(config-subif)#ipaddR2610(config)#inte0/0.3R2610(config-subif)#encapsulationdot1QR2610(config-subif)#ipaddR2610(config-subif)#encapsulationdot1QR2610(config-subif)#ipaddSwitch#configuretSwitch#configureterminalSwitch(config)#hostsw2950sw2950(config)#intf0/24sw2950(config-if)#switchportmodetrunksw2950(config)#vlan2sw2950(config-vlan)#nameVLAN2sw2950(config)#vlan3sw2950(config-vlan)#nameVLAN3sw2950(config)#vlan4sw2950(config-vlan)#nameVLAN4sw2950(config)#intrangef0/1-6sw2950(config-if-range)#switchportmodeaccesssw2950(config-if-range)#switchportaccessvlan2sw2950(config)#intrangef0/7-12sw2950(config-if-range)#switchportmodeaccesssw2950(config-if-range)#switchportaccessvlan3sw2950(config)#intrangef0/13-18sw2950(config-if-range)#switchportmodeaccesssw2950(config-if-range)#switchportaccessvlan4LAB14–IP列Naxxr3實驗一:將R2,R3認(rèn)為是一臺計算機(jī),R1是路由器,配置標(biāo)準(zhǔn)列表,不允許R2做好基本配置,R1#conftR1(config)#ints0R1(config-if)#noshR1(config-if)#ipaddR1(config-if)#clockrR1(config)#ints1R1(config-if)#ipaddR1(config-if)#noshR1(config-if)#clockrR2#conftEnterconfigurationcommands,oneperline. EndwithR2(config)#hostnameR2R2(config-if)#ipaddressR2(config-if)#noshR2(config)#iprouteR2#TypeescapesequencetoSending5,100-byteICMPEchosto,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=4/7/8msRouter#conftEnterconfigurationcommands,oneperline. EndwithCNTL/Z.Router(config)#hostnameR3R3(config)#interfaceserial0R3(config-if)#noshutdownR3(config-if)#ipaddR3(config)#iprouteR3#TypeescapesequencetoSending5,100-byteICMPEchosto,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=4/6/8msR1(config)#access-list1denyR1(config)#access-list1permitanyR1(config)#interfaces1R1(config-if)#ipaccess-group1 !如將列表應(yīng)用在S0口,怎么配置呢R1#showaccess-list !或者使用showipaccess-listR1#showipinterface在R2上測試R2# !是否能通R2#net !能net到成功馬?R1#conft )#noaccess-list1 !刪除列表1R1#show !檢查列表1,還有列表嗎實驗二:不允許R2R3,其他的連接可R1#conftR1(config)#ints0R1(config-if)#noshR1(config-if)#ipaddR1(config-if)#clockrR1(config)#ints1R1(config-if)#ipaddR1(config-if)#noshR1(config-if)#clockrR2#conftEnterconfigurationcommands,oneperline. EndwithR2(config)#hostnameR2R2(config)#ints0R2(config-if)#ipaddressR2(config-if)#noshR2(config)#iprouteR2#TypeescapesequencetoSending5,100-byteICMPEchosto,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=4/7/8msRouter#conftEnterconfigurationcommands,oneperline. EndwithCNTL/Z.Router(config)#hostnameR3R3(config)#interfaceserial0R3(config-if)#noshutdownR3(config-if)#ipaddR3(config)#iprouteR3#TypeescapesequencetoSending5,100-byteICMPEchosto,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=4/6/8ms2.配置列表R1(config)#access-list101deny icmphostR1(config)#access-list101permitipanyR1(config)#interfaceR1(config-if)#ipaccess-group101out !如將列表應(yīng)用在S0口,怎么配置呢?R1#showaccess-list !或者使用showipaccess-listR1#showip在R2上測試R2# !是否能通R2#net !能net到成功馬?R1#conft )#noaccess-list101 !刪除列表1R1#showrun !檢查列表1,還有列表嗎?LAB15 Inthislab,youwillconfigureNAT/PATfunctionR1.Youwillconfigurethreeformsoftranslation:staticnetworkaddresstranslation,dynamictranslation,andoverloading(portaddresstranslation).Remembertodisabletheaccesslistsyourconfiguredinthepreviouslabbeforecontinuingthislab.R1,configureNATtostaticallytranslateR2’sEthernetaddresstoR1(config)#ipnatinsidesourcestaticR1(config)#interfaceethernet0R1(config-if)#ipaddressR1(config-if)#ipnatinsideR1(config-if)#interfaceR1(config-if)#ipaddressR1(config-if)#ipnatoutsideR1(config-if)#noTestthestaticNATtranslationbynet’ingfromR2toR3.OnceintoR3,issuetheshowuserscommand.Theoutputofthiscommandshouldshowthat(thetranslatedIPaddress)isthelogged-indevice. netR3#showDisytheNATTranslationtable在R1.TheoutputofthedisyshouldshowthattheinsidelocalIPaddress()istranslatedtotheinsideglobalIPaddress().問題A:doesthe“insideglobalIPaddress”normallyrepresentapublicoraprivateIPR1#showipnatR1,removethepreviousstaticNATcommandsandconfigureNATtotranslateR2’sEthernetaddresstoadynamicallyassignedaddress.Youwillutilizeapoolofpublicaddressesintherangeof0to00.AifthepoolofdynamicallyassignedaddressesonlycontainsoneIPaddressentry,what’sanothertermforthisformofNATtranslation?R1(config)#noipnatinsidesourcestaticR1(config)#ipnatpoolpool1000netmaskR1(config)#ipnatinsidesourcelist1poolpool1R1(config)#access-list1permit55TestthedynamicNATtranslationfunction net’ingfromR2toR3.OnceintoR3,theshowuserscommand.Theoutputofthiscommandshouldshowthatthelogged-indeviceis0(thetranslatedaddress).Also,disytheNATtranslationtable在R1usingtheshowipnattranslationscommand. netR3#showR1#showipnatRemovethepreviousNATcommands.ConfigureNAToverloadingportaddresstranslation)R1totranslateR2’sEthernetaddress(totheserial0interfaceaddress)R1(config)#ipnatinsidesourcelist1interfaceserial0overloadR1(config)#interfaceEthernet0R1(config-if)#ipaddressR1(config-if)#ipnatinsideR1(config-if)#interfaceserialR1(config-if)#ipaddressR1(config-if)#ipnatoutsideR1(config-if)#R1(config)#access-list1permitTesttheoverloading(PAT)functionbynet’ingfromR2toR3.IssuetheshowuserscommandR3.Itshouldshowthatthelogged-indeviceis(thetranslatedIPaddress).Also,issuetheshowipnattranslationscommand在R1todisytheNATtranslationtable. netR3#showR1#showipnatRemoveallNAT/PATconfigurationcommandsfromR1beforecontinuingonwiththeCCNAlabs.LAB16-PPP&R1#conftR1(config)#ints0R1(config-if)#noshR1(config-if)#ipaddR1(config-if)#clockrR1(config)#ints1R1(config-if)#ipaddR1(config-if)#noshR1(config-if)#clockrtR2(config)#hostnameR2R2(config)#ints0R2(config-if)#ipaddressR2(config-if)#noshR1#showinterfacesserialR1和R2上配置PPP封裝R1(config)#interfaceserial0R1(config-if)#encapsulationpppR2(config)#interfaceserial0R2(config-if)#encapsulationppprouterx#showinterfacesserial0!PPP了嗎?R1#配置R1(config)#usernameR2passwordciscoR1(config)#interfaceserial0R1(config-if)#pppauthenticationchapR2(config)#usernameR1passwordciscoR2(config)#interfaceserial0R2(config-if)#pppauthentication檢查接口狀態(tài)R1#showinterfacesserial0R1#R1(config)#interfaceserial0R1#debugpppR1(config-if)#noPPPLAB17ISDNBRI-BRIDDR配ISDN#--R1(config)#isdnswitch-typebasic-net3R1(config)#dialer-list1protocolippermitR1(config)#usernameR2passwordciscoR1(config)#interfacebri0R1(config-if)#encapR1(config-if)#ipaddressR1(config-if)#dialer-groupR1(config-if)#dialermapipnameR2broadcastR1(config-if)#pppauthenticationchapR1(config-if)#noR2(config)#isdnswitch-typebasic-net3R2(config)#dialer-list1protocolippermitR2(config)#usernameR1passwordciscoR2(config)#interfacebri0/0R2(config-if)#encapR2(config-if)#ipaddressR2(config-if)#dialer-groupR2(config-if)#dialermapipnameR1broadcastR2(config-if)#pppauthenticationchapR2(config-if)#no檢查ISDN鏈路狀態(tài)Layer1:Layer2:MultipleFrameEstablishedwithspid1routerx#showisdnA:whatstatusaretheBchannels?R1#showinterfaces !顯示DR1#showinterfacesbri01 !顯示BAwhichconfigurationparameter(s)R1identifiestheinterestingtrafficthatwilltriggeracall?R1#檢查ISDNA:whatdoesitshowforthe‘Layer3R1#showisdn檢查BA:whatisthestatusofthetwoBR1#showinterfacesbri01LAB18ISDNBRI-BRIusingDialerProfiles(不要求掌握#-i-iISDNInthislab,youwillconfigureISDNBRI在R1andR2usingdialerprofiles.Withdialerprofiles,youareeffectivelymovingsomeofthelogicalISDNparametersfromthephysicalBRI/PRIinterfacetoadialerinterface.AnyIPpacketshouldrepresent‘interestingtraffic’inthislabandeitherroutershouldbeabletoinitiatethecall.PPPencapsulationandCHAPauthenticationshouldbeused.RefertothetableaboveforISDNswitch-type,IPaddresses,subnetmasks,andephonenumbers.R1(config)#isdnswitch-typebasic-net3R1(config)#dialer-list1protocolippermitR1(config)#usernameR2passwordciscoR1(config)#interfacebri0R1(config-if)#encapR1(config-if)#pppauthenticationchapR1(config-if)#isdnspid132122094760100R1(config-if)#dialerpool-member1R1(config-if)#noshutR1(config-if)#interfacedialer1R1(config-if)#noshutR1(config-if)#ipaddressR1(config-if)#encappppR1(config-if)#dialer-group1R1(config-if)#dialerpool1R1(config-if)#dialerremote-nameR2R1(config-if)#dialerstring pppauthenticationchapR2(config)#isdnswitch-typebasic-net3R2(config)#dialer-list1protocolippermitR2(config)#usernameR1passwordciscoR2(config)#interfacebri0/0R2(config-if)#encapR2(config-if)#pppauthenticationchapR2(config-if)#isdnspid132177820020100R2(config-if)#dialerpool-member1R2(config-if)#noshutR2(config-if)#interfacedialer1R2(config-if)#noshutR2(config-if)#ipaddressR2(config-if)#encappppR2(config-if)#dialer-group1R2(config-if)#dialerpool1R2(config-if)#dialerremote-nameR1R2(config-if)#dialerstring pppauthenticationIssuetheshowisdnstatuscommandonbothR1andR2.YoushouldLayer1:Layer2:MultipleFrameEstablishedwithspid1valid.routerx#showisdnstatusIssuetheshowinterfacesbri0command在R1.ThisdisysthesignalingorChannel.Itshouldshow‘UpandUp(spoofing)’ifitisreadytohandleacallrequest. issuethecommandshowinterfacesbri012.Thisshouldshowthestatusofthetwodata,orBR1#showinterfacesbri0R1#showinterfacesbri012FromR1,theISDNinterfaceofR2.ThisshouldcauseanISDNcalltobeinitiatedthesshouldR1#IssuetheshowisdnstatuscommandR1.UndertheLayer3statusintheoutputitshouldshowonecallactive.R1#showisdnIssuetheshowinterfacesbri012commandR1.ThisshowsthestatusoftheBchannels(datachannels).OneoftheBchannelsshouldhaveastatusof‘UPandUP’indicatingasuccessfulcallisinprogress.R1#showinterfacesbri01LAB19–ISDNPRIusingDialer (

溫馨提示

  • 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
  • 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
  • 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負(fù)責(zé)。
  • 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請與我們聯(lián)系,我們立即糾正。
  • 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時也不承擔(dān)用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。

評論

0/150

提交評論