模擬器ccnp交換實驗手冊_第1頁
模擬器ccnp交換實驗手冊_第2頁
模擬器ccnp交換實驗手冊_第3頁
模擬器ccnp交換實驗手冊_第4頁
模擬器ccnp交換實驗手冊_第5頁
已閱讀5頁,還剩90頁未讀 繼續(xù)免費閱讀

下載本文檔

版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進行舉報或認領

文檔簡介

實驗1.1交換機的基本配置批注[yeslab2]:設批注[yeslab2]:設 為[yeslab3]:進入配置從交換機的為ciscologin默認時,交換機的以太網(wǎng)接口是開啟的,對于交換機的以太網(wǎng)接口可以配置器雙工模式和速率等。配置舉例: SW(config)#interfaceSW(config-if)#duplex{full|half|auto}SW(config-if)#speed{10|100|1000|auto}SW(config)#intvlan1SW(config-if)#ipadd0[A6]:配置默認網(wǎng)關(guān)目的是讓其他網(wǎng)段上的主機也能夠[A6]:配置默認網(wǎng)關(guān)目的是讓其他網(wǎng)段上的主機也能夠net該交換SW(config)#ipdefault-gatewaySW1#copySW1#copyrunning-cionfigstartup-configDestinationfilename[startup-config]?Building理解交換機的CAM表;]:]:[yeslab10]:配置接口在接入了MACdown[yeslab11進入配置接口vlan1]:R1能夠與vlan1[yeslab13配置R1的f0/0j接口vlan1的管理地址是直連網(wǎng)段,使vlan1中能和交換機的f0/9FastEthernet0/0isup,lineprotocolis]:MACMTU1500bytes,BW100000Kbit,DLY100usec,reliability255/255,txload1/255,rxload1/255EncapsulationARPA,loopbacknotsetKeepaliveset(10sec)Full-duplex,100Mb/s,100BaseTX/FXARPtype:ARPA,ARPTimeout04:00:00SW1#showmacaddress-MacAddress MacAddress R1(config)#intR1(config-if)#mac-addressSW1#_SECURITY-2-PSECURE_VIOLATION:Securityviolationoccurred,causedbyMACaddress0012.0012.0012onportFastEthernet0/9.*MarR1(config)#intR1(config-if)#mac-addressSW1#_SECURITY-2-PSECURE_VIOLATION:Securityviolationoccurred,causedbyMACaddress0012.0012.0012onportFastEthernet0/9.*Mar100:21:40.275:%PM-4-ERR_DISABLE:psecure-violationerrordetectedonFa0/9,puttingFa0/9inerr-disablestate*Mar100:21:41.279:%LINEPROTO-5-UPDOWN:LineprotocolonInterfacechangedstateto[yeslab16更改接口的MAC地[yeslab15]:輸出表明SW1f0/9R1f0/0MAC[yeslab17SW1上的輸出顯示,因是端口安全機制檢測到該端口上接入了除R1以外的設備(被認為是f0/9shutdown,防止設備[yeslab17SW1上的輸出顯示,因是端口安全機制檢測到該端口上接入了除R1以外的設備(被認為是f0/9shutdown,防止設備SW1#shintFastEthernet0/9isSW1#shintFastEthernet0/9isdown,lineprotocolisdown(err-HardwareisFastEthernet,addressis000b.5f85.1389(bia000b.5f85.1389)MTU1500bytes,BW100000Kbit,DLY100usec,批注[yeslab18]:批注[yeslab18]:當交換機上有新的MAC地址條數(shù)超過最大數(shù)量則接批注[yeslab19]:當有新的計算機從MAC地址條數(shù)超過最大數(shù)量則批注[yeslab20]:當有新的計算機從noshutdownSW1(config-if)#switchport-securityviolationSecurityviolationprotectSecurityviolationrestrictSecurityviolationshutdown實驗1.3交換機的恢Cisco交換機的恢復步驟和路由器的恢復有很大差別,并且不同型號的交換機恢復的方法也不盡相同。以下是:CiscoCatalyst3560(Catalyst2950也類似)交換碼恢復步驟:MACAddress:00:18:ba:11:f5:00XmodemfilesystemisThepassword-recoverymechanismisThesystemhasbeeninterruptedpriortoinitializingtheFlashfilesystem.ThefollowingcommandswillinitializeTheflashfilesystem,andfinishloadingtheoperatingSystemsoftware:]:flash]:批注[yeslab24]:交換機會提問是否 批注[yeslab25]:將當前的啟動配置批注yelb26]:使交換機下次啟動時候從內(nèi)存中加載當前保存到內(nèi)存(修改了的配置文批注[yeslab27]:將修改完 置文件保存到NVRAM中。以后啟動 掌握交換機的IOS如果交換機能夠正常開啟后IOSIOSTFTPIOS復步驟。然而如果交換機無法正常開啟,IOSXmodem通過Console口從計算機IOS,速度為9600bps,一次速度會比較慢。步驟如下:Console]:ipdefault-SwitchmodeSwitchport-Switchport-securitiyum該端口下最多允許MAC 作Switchport-securitiymac-addressShowmac-address-Mac-addressRenameflash:config.text 通過Xmodem協(xié)議將文件2.1sw1#confsw1#confsw1(config)#intsw1(config-if)#switchmodeaccesssw1(config-if)#switchaccessvlansw1(config-if)#intf0/2sw1(config-if)#switchmodeaccesssw1(config-if)#switchaccessvlan

]:vlan2r1(config-if)#intr1(config-if)#intr1(config-if)#ipaddr1(config-if)#noshur2(config-if)#intr2(config-if)#intr2(config-if)#ipaddr2(config-if)#noshu查看vlan信息。sw1#shvlan-switch VLAN12Fa0/0,Fa0/3,Fa0/4,Fa0/5Fa0/6,Fa0/7,Fa0/8,Fa0/9Fa0/10,Fa0/11,Fa0/12,Fa0/13Fa0/14,31002fddi-1003token-ring-1004fddinet-default

于活躍狀態(tài),且f0/1、f09/2已經(jīng)非1)測試r1和r2間的連通性。因為配置了IP地址,相當于直連網(wǎng)段應該能夠 souTypeescapesequencetoSending5,100-byteICMPEchosto,timeoutis2seconds:PacketsentwithasourceaddressofSuccessrateis100percent(5/5),round-tripmin/avg/max=32/50/722.2理解DTP的協(xié)商規(guī)律。 ]:]:]:vlan]:trunk。SW2的配置命令和SW1的一SW2(config)#SW2(config)#switchportmodeSW2#vlandataSW2(vlan)#vlanVLAN2modified:SW2(config)#intf0/1SW2(config-if)#switchmodeacceSW2(config-if)#switchaccessvlanSW2(config)#int[yeslab43]:配置接口IP本實驗中為了驗證R1和R2sousouTypeescapesequencetoSending5,100-byteICMPEchosto,timeoutis2seconds:PacketsentwithasourceaddressofSuccessrateis80percent(4/5),round-tripmin/avg/max=16/33/60ms批注[yeslab44]:此處測試加上了源IP地址,是為了更加精確的驗證R1R2R1的非f0/0口作為源發(fā)包到R2f0/0口來準確的驗證R1、R2sw1#shintf0/5

NativeNative

EncapsulationEncapsulation

]:[yeslab52端口的trunk

VlansallowedontrunkVlansallowedandactiveinmanagementVlansinspanningtreeforwardingstateandnotpruned

]:批注[yeslab55]:中文翻譯是“本征有vlan都打 在通過trunk鏈路時候;但是如果封裝為802.1q則除了本證vlan不 器其他vlan都 sw2#shintf0/5

vlan是vlan1較 情況下是不支持nativevlan和其他

Encapsulation Native

n-

Vlansallowedontrunk

Vlansallowedandactiveinmanagement

VlansinspanningtreeforwardingstateandnotprunedSwitchportmode{trunk|dynamicdesirable|dynamicDynamicDynamic批注[yeslab56]:將接口 trunk模式。封裝類型有DynamicDynamic掌握VTP配置。

2.3VTP

[yeslab58]:協(xié)商,如果另一類型會是802.1q。[yeslab60配置交換機的vtp的server。 namealreadysettoSW2(config)#vtppasswordSettingdeviceVLANdatabasepasswordtocciesSW2(config)#vtpmodeSettingdeviceto SW2#shVLANSW2#shVLAN ]:1 002 003 00 00 001004fdnet ieee001005trnet ibm00RemoteSPAN2.4EhernetChannel掌握etherchannel的配置。SW2(config)#hostnameSW2(config)#port-channelload-balancedst-macSW2(config)#interfacePort-channel1SW2(config-if)#switchporttrunkencapsulationdot1qSW2(config-if)#switchportmodetrunkSW2(config-if)#speed100SW2(config-if)#duplexfullSW2(config-if)#interfaceFastEthernet0/5SW2(config-if)#switchporttrunkencapsulationdot1qSW2(config-if)#switchportmodetrunkSW2(config-if)#speed100SW2(config-if)#duplexfullSW2(config-if)#channel-group1modeSW2(config)#interfaceSW2(config-if)#switchporttrunkencapsulationSW2(config-if)#switchportmodeSW2(config-if)#speedSW2(config-if)#duplexSW2(config-if)#channel-groupSW2(config-if)#channel-group1mode[yeslab74查看etherchannel的[yeslab75etherchannel已經(jīng)正“SDetherchannel關(guān)掉重[yeslab76channel-group[yeslab78]:默認情況下交換機[yeslab78]:默認情況下交換機工輸入,且不會在show[yeslab79]:配置etherchannelswitch(config)#hostnameSW2SW2(config)#interfaceFastEthernet0/5SW2(config-if)#switchportmodedynamicSW2(config-if)#channel-group1modeSW2(config)#interfaceFastEthernet0/6SW2(config-if)#switchportmodedynamicdesirableSW2(config-if)#channel-group1modeactive[yeslab80配置etherchannel的模式為LACPactive。批注yelb77]:都配置使用相同的協(xié)議才可成功協(xié)商建立hrChannl(不關(guān)心接口的annl的形式,否則會在tecanl中體現(xiàn)是終止狀態(tài)。一etherchannel;PAgP;[yeslab84f0/6端口上協(xié)商SW1#shetherchannelFlags:D-down P-bundledinport-channelI-stand-alones-suspendedH-Hot-standby(LACPonly)R-Layer3 S-Layer2U-in f-failedtoallocateM-notinuse,minimumlinksnotmetu-unsuitableforbundlingw-waitingtobeaggregatedd-defaultportNumberofchannel-groupsinuse:1Numberofaggregators: GroupPort-channel SW2#SW2#showetherchannelFlags:D-down P-bundledinport-channelI-stand-alones-suspendedH-Hot-standby(LACPonly)R-Layer3 S-Layer2U-in f-failedtoallocateM-notinuse,minimumlinksnotmetu-unsuitableforbundlingw-waitingtobed-defaultNumberofchannel-groupsinuse:Numberof GroupPort-channel + 配置不同的接口形式進行協(xié)商建立[yeslab85配置etherchannel的模式為PAgP的auto。SW2(config)#hostnamesw3550SW2(config)#interfaceSW2(config)#hostnamesw3550SW2(config)#interfaceFastEthernet0/5SW2(config-if)#switchportmodedynamicSW2(config-if)#channel-group1modeSW2(config)#interfaceFastEthernet0/6SW2(config-if)#switchportmodedynamicdesirableSW2(config-if)#channel-group1modedesirable[yeslab86配置etherchannel的模式為PAgP的desirable。SW1#shetherchannelSW1#shetherchannelFlags:D-down P-bundledinport-channelI-stand-alones-suspendedH-Hot-standby(LACPonly)R-Layer3 S-Layer2U-in f-failedtoallocateM-notinuse,minimumlinksnotmetu-unsuitableforbundlingw-waitingtobeaggregatedd-defaultportNumberofchannel-groupsinuse:NumberofGroupPort-channel1 +SW2#shetherchannelSW2#shetherchannelFlags:D-down P-bundledinport-channelI-stand-alones-suspended[yeslab87]:表明etherchannel已商成trunk,只要配置了相同的協(xié)議HH-Hot-standby(LACPR- S-U-in f-failedtoallocateM-notinuse,minimumlinksnotmetu-unsuitableforbundlingw-waitingtobed-defaultNumberofchannel-groupsinuse:Numberof GroupPort-channel + VlanVlan2namevlanSwitchaccessvlanInterfacerangeF0/2–ShowSwitchporttrunkSwitchportmode間端口配置為trunk形式ShowinterfaceF0/3SwitchportVtpmode配置交換機為vtpserverVtpVtpVtpmodeVtpmodeShowvtpVtpVtpversion1nterfaceport-channelChannel-groupmodePort-channelload-balancedst-Showetherchannel Showetherchannelport-3.1STPciscodesirabletrunk(3550)是“n-isltrunk。2950trunk802.1q。sw3560(vlan)#vlansw3560(vlan)#vlanVLAN2Name:APPLYcompleted.APPLYcompleted.sw3560(config)#vtpChangingVTPnamefromNULLtoyeslabsw3560(config)#vtppasswordccies[yeslab88]:高版本的IOS可以不創(chuàng)建VLAN。注意:[yeslab89交換機VTP默認就server的模式因此可不必要進行3276832769是[yeslab91跟橋的MAC]:該設備在該vlan1DesgFWDDesgFWD[yeslab93]:通過查看表明vlan1vlan2DesgFWDDesgFWDsw3560#shintsw3560#shintFastEthernet0/1isup,lineprotocolisupHardwareisFastEthernet,addressis(bia[yeslab94f0/1MAC地址,spanning-treevlan1priorityspanning-treevlanspanning-treevlan1priorityspanning-treevlan2priorityspanning-treevlan1rootprimaryspanning-treevlan2root]: 4096使之成為vlan1[yeslab96SW3550vlan1的優(yōu)先級改4096使之成為vlan2[yeslab97]:通過命令將sw3550分別該成vlan1、vlan2的]:vlan1DesgFWDDesgFWDDesgFWDDesgFWDRootFWDsw3550#showsw3550#showspanning-SpanningtreeenabledprotocolieeeRootID 5o 2secMaxAge20secForwardDelay15BridgeID 32769(priority32768sys-id-ext oTime 2secMaxAge20secForwardDelay15secAgingTime300 RoleSts Prio.Nbr DesgFWD RootFWD SpanningtreeenabledprotocolieeeRootID Thisbridgeistheo 2secMaxAge20secForwardDelay15BridgeID (priority4096sys-id-ext oTime 2secMaxAge20secForwardDelay15secAgingTime300 RoleSts Prio.Nbr[yeslab100此處表明在vlan2中SW3550是跟橋。DesgFWDDesgFWDRootFWDAltnBLK RootFWD F0/2處于轉(zhuǎn)發(fā)狀態(tài)轉(zhuǎn)發(fā)數(shù)據(jù)幀。這樣起到了負載均衡的作用。3.21)理解Portfast的工作原理;2)理解Uplinkfast的工作原理;3)PC1(config)#interfacePC1(config)#noipPC1(config)#interfacePC1(config)#noipSW3560(config)#hostnameSW3560(config)#spanning-treevlan1priority批注yelb101]:以上配置是將路由器的路由功能關(guān)掉,設置接口的IPPC1(config)#hostname[yeslab102]:默認情況下所有端vlan1中,所以在配置文件中批注yelb103]:以上配置是將路由器的路由功能關(guān)掉,設置接口的IP作為一臺主機使用,同時在實驗3.1的基礎上對W3560A交換機的配置做了添加,使模擬的C主機能夠和W3560交換機進行通信shspvlanSpanningtreeenabledprotocolieeeRootID Thisbridgeistherooto 2secMaxAge20secForwardDelay15BridgeID (priority4096sys-id-ext oTime 2secMaxAge20secForwardDelay15secAgingTime300 RoleSts Prio.Nbr DesgFWD DesgFWD F0/9vlan1PC1f0/0noPC1(config)#intf0/0PC1(config-if)#nosw3560#debugspanning-tree*Mar103:13:42.163:setportid:PC1(config)#intf0/0PC1(config-if)#nosw3560#debugspanning-tree*Mar103:13:42.163:setportid:VLAN0001Fa0/9:newportid*Mar103:13:42.163:STP:VLAN0001Fa0/9->listening*Mar103:13:44.159:%LINK-3-UPDOWN:InterfaceFastEthernet0/9,changedstateto 103:13:45.159:%LINEPROTO-5-UPDOWN:LineprotocolonInterfaceFastEthernet0/9,changedstatetoup*Mar*Mar103:13:57.163:STP:VLAN0001Fa0/9->learning*Mar103:14:12.163:STP:VLAN0001Fa0/9->批注[yeslab106]:以上表明配置了portfastf0/9接口在接入了計算機后立即由原來的bloking進入了即切換到備份鏈,而不需要等30s或50s。本例中假設SW3(2950)是接入層交換機。SW2950(config)#spanning-treeSW2950(config)#spanning-treeSW2950#debugspanning-treesw3560(config)#int03:44:48:STP:VLAN0001newrootportFa0/2,cost]:批注[yeslab107]:以上表明sw3560(config)#spanning-treesw3560(config)#spanning-treesw3550(config)#spanning-treebackbonefastsw2950(config)#spanning-tree:STP:VLAN0001Fa0/2->:STP:VLAN0001Fa0/2->批注批注[yeslab114]:通過查看可看到默PVST模式。]:3.3[yel[yelb10]:將交換機端口配置為rk后就能夠查看到P得狀態(tài),交換上默認是有SP存在的。因此在本實驗中可以使用默認的SP封裝類型為dot1q]:Sw2(config-if)#intSw2(config-if)#intragef0/5–Sw2(config-if)#switchportencapsulationdot1qSw2(config-if)#switchportmodetrunk[yeslab113]:CISCO交換機的默spannning-tree模式是PVST[yeslab113]:CISCO交換機的默spannning-tree模式是PVST,本命SpanningtreeenabledprotocolieeeRootID ThisbridgeistherootoTime 2secMaxAge20secForwardDelay15secBridgeIDPriority 32769(priority32768sys-id-ext1)]:]:DesgFWDDesgFWDRootFWDAltnBLK步驟:1)在SW1上關(guān)閉interfacef0/5SW1(config)#intf0/5*Mar101:27:14.115:STP:VLAN0001newrootportFa0/6,cost*Mar101:27:14.115:STP:VLAN0001Fa0/6-> 101:27:15.107:%LINEPROTO-5-UPDOWN:LineprotocolonInterfacechangedstateto*Mar101:27:16.115:STP:VLAN0001sentTopologyChangeNoticeon*Mar101:27:16.123:%LINK-3-UPDOWN:InterfaceFastEthernet0/5,changedstateto1.115:STP:VLAN0001Fa0/6->1.115:STP:VLAN0001Fa0/6->SW1(config)#spanning-treemoderapid-SW2(config)#spanning-treemodeSW1(config)#spanning-treemoderapid-SW2(config)#spanning-treemoderapid-]:rstpRoleStsDesgFWDDesgFWDSW2#shRootFWDAltnBLK[yeslab119此輸出表明:在F0/5down掉后,立即有F0/63.4批注批注[yeslab120]:注意:用vlandatabase創(chuàng)建vlan后要退出后配置才]:[yeslab122mst的配置模[yeslab123mst的。[yeslab124mst的修訂版本號。只有相同的和版本號才能出在同一個mst域中。[yeslab125vlan1、vlan2映射到實例1中。[yeslab126vlan3、vlan4映射到實例2中。[yeslab127配置SW1在mst實為mst的實例一的跟橋。trunk(SW1、SW2dot1qSW3550SW2950的trunk鏈路可自動進行協(xié)商建立,因為默認情況下接口都是desirable)SW1(vlan)#vlanVLAN1SW1(vlan)#vlanVLAN2Name:SW1(vlan)#vlanVLAN3Name:SW1(vlan)#vlanVLAN4Name:SW1(config)#hostnameSW1SW1(config)#spanning-treemodemstSW1(config-mst)#instance1vlan1-SW1(config-mst)#instance2vlan3-SW1(config)#spanning-treemst1priority4096SW1(config)#intf0/5SW1(config-if)#switchporttrunkencapsulationSW1(config-if)#switchportmodeSW1(config-if)#switchportmodeSwitch(config)#hostnameSW2SW2(config)#spanning-treemodemstSW2(config)#spanning-treemstconfigurationSW2(config-mst)#nameSW2(config-mst)#revision1SW2(config-mst)#instance1vlan1-SW2(config-mst)#instance2vlan3-SW2(config)#spanning-treemst2prioritySW2(config)#interfaceSW2(config-if)#switchporttrunkencapsulationdot1qSW2(config-if)#switchportmodetrunk[yeslab128配置SW2在mst實28192,即:配置mst實例一中SW2為跟橋。SW3(config)#hostnameSW1是實例1的跟橋,SW2是實例2的跟橋。SW1#showVLANSW1#showVLAN Fa0/2,Fa0/3,Fa0/4,Fa0/7,Fa0/8,Fa0/9,Fa0/11,Fa0/12,Fa0/13,Fa0/15,Fa0/16,Fa0/17,Fa0/19,Fa0/20,Fa0/21,Fa0/23,Fa0/24,Fa0/25,Fa0/27,Fa0/28,Fa0/29,Fa0/31,Fa0/32,Fa0/33,Fa0/35,Fa0/36,Fa0/37,Fa0/39,Fa0/40,Fa0/41,Fa0/43,Fa0/44,Fa0/45,Fa0/47,Fa0/48,Gi0/1, 1002fddi-1003token-ring-1004fddinet-1005trnet-]:SW2#showVLAN SW2#showVLAN Fa0/1,Fa0/3,Fa0/4,Fa0/7,Fa0/8,Fa0/9,Fa0/10Fa0/11,Fa0/12,Fa0/13,Fa0/14Fa0/15,Fa0/16,Fa0/17,Fa0/18Fa0/19,Fa0/20,Fa0/21,Fa0/22Fa0/23,Fa0/24,Fa0/25,Fa0/26Fa0/27,Fa0/28,Fa0/29,Fa0/30Fa0/31,Fa0/32,Fa0/33,Fa0/34Fa0/35,Fa0/36,Fa0/37,Fa0/38Fa0/39,Fa0/40,Fa0/41,Fa0/42Fa0/43,Fa0/44,Fa0/45,Fa0/47,Fa0/48,Gi0/1, 1002fddi- 1003token-ring- 1004fddinet- 1005trnet- VLANType ParentRingNoBridgeNoStpBrdgModeTrans11 002 003 004 00 00 001004fdnet ieee001005trnet ibm00RemoteSPAN1 1 002 003 004 00 00 001004fdnet -001005trnet -00RemoteSPAN1 002 003 004 00 00 00 ieee0010051005trnet1500--ibm00RemoteSPANPrimarySecondaryDesgFWDP2pDesgFWD[yeslab131MST1SW1是跟DesgFWDP2pDesgFWD[yeslab132MST2SW2是跟DesgFWDP2pRootFWDDesgFWDP2pRootFWDDesgFWDP2pRootFWDDesgFWDP2pDesgFWDSW3#shspanning-SpanningSW3#shspanning-SpanningtreeenabledprotocolieeeRootID 1o 2secMaxAge20secForwardDelay15BridgeIDPriority 32769(priority32768sys-id-ext1) RoleSts00:55:12:Prio.NbrRoleSts00:55:12:Prio.NbrRootLISAltnBLKRootLISAltnBLKRootLISAltnBLKSpanningtreeenabledprotocolieeeRootID 1o 2secMaxAge20secForwardDelay15BridgeID 32772(priority32768sys-id-ext oTime 2secMaxAge20secForwardDelay15secAgingTime15 RoleSts Prio.NbrRootLISAltnBLK[yeslab133配置SW2在vlan1時要通過MST0來控制。[yeslab134SW2 Desg DesgFWD SpanningtreeenabledprotocolmstpRootID 5o 2secMaxAge20secForwardDelay15BridgeID 32769(priority32768sys-id-ext o 2secMaxAge20secForwardDelay15 RoleSts Prio.Nbr DesgFWD P2p RootFWD SpanningtreeenabledprotocolmstpRootID ThisistheBridgeo2secMaxAge20secForwardDelay15 (priority8192sys-id-ext2)2secMaxAge20secForwardDelay15secStsCost Prio.NbrTypeFWD P2pFWD [yeslab135MST0實例SW3#showSW3#showspanning-SpanningtreeenabledprotocolieeeRootID AltnBLKAltnBLKRootFWDAltnBLKRootFWDAltnBLKRootFWDAltnBLKRootFWDSW3(config)#intSW3(config-if)#spanning-treevlan3 Changeaninterface'sperVLANspanningtreepathport-priorityChangeaninterface'sspanningtreeportSW3(config-if)#spanning-treevlan3costSW3(config-if)#spanning-treevlan4costSW3#shspanning-SW3#shspanning-SpanningtreeenabledprotocolRoot2o2secMaxAge20secForwardDelay15BridgeID 32769(priority32768sys-id-ext oTime 2secMaxAge20secForwardDelay15secAgingTime300RoleStsPrio.NbrAltnBLKRootFWDSpanningtreeenabledprotocolRoot2o2secMaxAge20secForwardDelay15BridgeID 32770(priority32768sys-id-ext oTime 2secMaxAge20secForwardDelay15secAgingTime300RoleRoleStsPrio.NbrAltnBLK RootFWD 仍然是f0/2為根端口轉(zhuǎn)發(fā)數(shù)據(jù)。SpanningtreeenabledprotocolRoot1RootFWDAltnBLKRootFWDRootFWD AltnBLK ]:]:f0/1BPDUGUARDCISCO35502900trunk列交換機的端口默認是模式都是desirable模式,所以如不進行配置可自動協(xié)商為trunk,封裝形式將是[yeslab139配置接口的trunkdot1q]:]:說明:完成本配置步驟后可用“showinterface+{接口名字及編號}+trunktrunkSW1#shintf0/5

EncapsulationStatusVlansallowedontrunk[yeslab142[yeslab142通過查看可觀察到f0/5802.1q(即:配置的dot1q).trunk的工作模式是VlansVlansallowedandactivein1Vlansinspanningtreeforwardingstateandnot1SW2#shintf0/5 Encapsulation Native n- Vlansallowedon 1- Vlansallowedandactiveinmanagement Vlansinspanningtreeforwardingstateandnotpruned 批注[yeslab143]:可觀察到SW2的f0/5接口的封裝是動態(tài)協(xié)商起來的,所以通過以上配置可見SW1/SW2之trunk是自動協(xié)商起來的。SW1#showspanning-SW1#showspanning-SpanningtreeenabledprotocolieeeRootID 5 2secMaxAge20secForwardDelay15BridgeID 32769(priority32768sys-id-ext 2secMaxAge20secForwardDelay15secAgingTime300RoleStsPrio.NbrRootFWD SW2#showspanning-[yeslab144通過查看SW2是跟DesgDesgFWDDesgFWDSW1(config)#spanning-treevlan1prioritySW1(config)#spanning-treevlan1priority4096SW2(config-if)#spanning-treeguardroot 101:07:54.439:%SPANTREE-2-ROOTGUARD_CONFIG_CHANGE:Rootguardenabledonport*Mar101:07:54.443:%SPANTREE-2-ROOTGUARD_BLOCK:RootguardblockingportonSW1#shSW1#shspanning-SpanningtreeenabledprotocolieeeRootID Thisbridgeistherooto 2secMaxAge20secForwardDelay15BridgeIDo(priority4096sys-id-ext2secMaxAge20secForwardDelay15AgingTimeRoleStsPrio.NbrDesgFWD DesgFWD RootFWD SW3(config)#spanning-treevlan1SW3(config)#spanning-treevlan1prioritySW2#shspanning-SpanningtreeenabledprotocolieeeRootID ThisbridgeistherootBridgeIDPriority 32769(priority32768sys-id-ext1) AgingTime RoleSts Prio.Nbr Desg P2p DesgFWD BPDUSW2(config-if)#spanning-treeportfastSW2(config-if)#spanning-treebpduguardenableSW2(config-if)#noshutdown*Mar100:21:55.859:%SPANTREE-2-BLOCK_BPDUGUARD:ReceivedBPDUonportFa0/1withBPDUGuardenabled.Disablingport.*Mar100:21:55.859:%PM-4-ERR_DISABLE:bpduguarderrordetectedonFa0/1,puttingFa0/1inerr-disablestate[yeslab147]:輸出已經(jīng)表明f0/1jinterfacef0/1”命令查看。statetodownFastEthernet0/1isdown,lineprotocolisdown(err-]:FastEthernet0/1isdown,lineprotocolisdown(err-]:HardwareisFastEthernet,addressis000b.5f85.1381(biaShowSpanning- Spanning-treevlan1prioritySpanning-tree配置接口為Spanning-treeSpanning-treeSpanning-treemoderapod-Spanning-treemodespanning-treemstNameRevisionInstance1vlan1-Spanning-treeguard在接口上配置RootSpanning-treebpduguard link-[yeslab149]:物理接口不需要配置ip地址[yeslab150Ethernet0/0默認是f0/0.2批注[yeslab152]:配置子接口封裝為并指明該子接口承載vlan2的流量。[yeslab153IP地IP地址就是PC的默認[yeslab154]:進入子接口、配置f0/0.3批注[yeslab155]:配置子接口封裝為dot1qtrunk的封裝類型統(tǒng)一。vlan3[yeslab156IP地IP地址就是PC的默認(1)配置實例:router1:router(config)#hostnamerouter1router1(config)#interfaceEthernet0/0router1(config-if)#noshutdownrouter1(config-if)#encapsulationdot1Q2router1(config-if)#encapsulationdot1Q3[yeslab157]:退出后配置生效。較高的交換機的IOS版本支持在全局模式下創(chuàng)建VLAN.[yeslab158]:默認配置,交換機swith(config)#hostnameSW1SW1#vlandatabaseSW1(vlan)#vlan2VLAN2SW1(vlan)#vlanVLAN3APPLYcompleted.APPLYcompleted.swith(config)#noiproutingswith(config)#intf0/3swith(config-if)#switchmodeaccessswith(config-if)#switchaccessvlan3swith(config-if)#noshutdownswith(config)#intf0/4swith(config-if)#switchmodeaccessswith(config-if)#switchaccessvlan4swith(config-if)#noshutdownswith(config)#intf0/0swith(config-if)#switchtrunkencapsulationdot1qswith(config-if)#switchmodetrunkswith(config-if)#noRouter(config)#hostnamePC1PC(config)#noiproutingPC(config)#interfaceFastEthernet0/3PC(config-if)#noswitchportRouter(config)#hostnamePC1PC(config)#noiproutingPC(config)#interfaceFastEthernet0/3PC(config-if)#noswitchportPC(config-if)#ipaddressPC(config)#ipdefault-gatewayrouter(config)#hostnamePC2PC2(config)#noiproutingPC2(config)#interfaceFastEthernet0/4PC2(config-if)#noswitchportPC2(config-if)#ipaddressPC2(config)#ipdefault-gatewaysousouTypeescapesequencetoSending5,100-byteICMPEchosto,timeoutis2seconds:PacketsentwithasourceaddressofSuccessrateis100percent(5/5),round-tripmin/avg/max=68/91/104PC1是為了精確的驗證PC1、PC2間SW1#vlandatabaseSW1(vlan)#vlan2SW1#vlandatabaseSW1(vlan)#vlan2VLAN2SW1(vlan)#vlanVLAN3modified:APPLYcompleted.SW1(config-if)#ipaddressSW1(config-if)#ipaddressinterface]:]:的管理地址,vlan1vlan2的管理地SW1(config-if)#ipaddressrouter(config)hostnamePC1PC1(config)#noiproutingPC1(config)#interfacerouter(config)hostnamePC1PC1(config)#noiproutingPC1(config)#interfaceFastEthernet0/2PC1(config-if)#noswitchportPC1(config-if)#ipaddressPC1(config)#ipdefault-gatewayrouter(config)#hostnamePC2PC2(config)#interfaceFastEthernet0/3PC2(config-if)#noswitchportPC2(config-if)#ipaddressPC2(config)#ipdefault-gateway sou souTypeescapesequencetoSending5,100-byteICMPEchosto,timeoutis2seconds:PacketsentwithasourceaddressofSuccessrateis100percent(5/5),round-tripmin/avg/max=64/87/128InterfaceEncapsulationdot1qvlan 指明了子接口的封裝類型及承載哪個vlan的流量同時該vlan是nativeIpNoIprouter(config)#hostnamerouter(config)#hostnamePC1PC1(config)#noiprouting擬IP地址。[yeslab162]:配置在組1中R2是若不配置優(yōu)先級則缺省時100。[yeslab163配置允許有更高優(yōu) loopback0批注[yeslab166]:配置路由協(xié)議是為 loopback0用以做測試rip的正常。但是在做track時候一定要將其從rip中no掉?;亟涌诘穆酚刹豢蛇_了,而VRRPO或者HSRP的TRACK選項都將不能識別到這一變化從而導致track的驗證試驗 PC1(config)#interfacePC1(config)#interfaceFastEthernet0/0PC1(config-if)#noswitchportPC1(config-if)#ipaddressPC1(config)#ipdefault-gatewayrouter(config)#hostnameR2R2(config)#interfaceLoopback0R2(config-if)#ipaddressR2(config)#interfaceFastEthernet0/2R2(config-if)#noswitchportR2(config-if)#ipaddressR2(config-if)#standby1ipR2(config-if)#standby1priorityR2(config-if)#standby1R2(config-if)#standby1authenticationmd5key-stringR2(config-if)#standby1trackLoopback0R2(config)#routerripR2(config-router)#version2R2(config-router)#networkR2(config-router)#noauto-router(config)#hostnameR3R3(config)#interfaceFastEthernet0/3R3(config-if)#noswitchportR3(config-if)#ipaddressR3(config-if)#standby1ipR3(config-if)#standby1R3(config-if)#standby1authenticationmd5key-stringciscoR3(config)#routerripR3(config-router)#versionR3(config-router)#networkR3(config-router)#noauto-summaryR2#shstandbyFastEthernet0/2-Group1Stateis2statechanges,laststatechange00:13:24VirtualIPaddressis54ActiveActivevirtualMACaddressisLocalvirtualMACaddressis0000.0c07.ac01(v1default)otime3sec,holdtime10sec osentin1.304secsAuthenticationMD5,key-string"cisco"PreemptionenabledActiverouterisStandbyrouteris,priority100(expiresin7.316sec)Priority120(configured120)TrackinterfaceLoopback0stateUpdecrement100IPredundancynameis"hsrp-Fa0/2-1"(default)R2#shstandby

Pindicatesconfiguredto|GrpPrioP Virtual 120P R3#shstandby

Pindicatesconfiguredto|GrpPrioP Virtual 100PStandbyR3#show[yeslab168輸出表明R3是備是配置的120、而R3則是默認的優(yōu)先級為100。R2(config)#intR2(config)#intloopback100:29:08.707:%HSRP-5-STATECHANGE:FastEthernet0/2Grp1stateActive->todown*Mar100:29:18.707:%HSRP-5-STATECHANGE:FastEthernet0/2Grp1stateSpeak-> R3#shstandby

Pindicatesconfiguredto|GrpPrioPVirtual 100PR3#shstandbyR3#shstandbyFastEthernet0/3-Group1Stateis5statechanges,laststatechange00:01:32VirtualIPaddressis54ActivevirtualMACaddressisLocalvirtualMACaddressis0000.0c07.ac01(v1default)otime3sec,holdtime10sec osentin0.612secsAuthenticationMD5,key-string"cisco"PreemptionenabledActiverouterisStandbyrouteris,priority20(expiresin8.592sec)Priority100(default100)IPredundancynameis"hsrp-Fa0/3-1"R3R2ActivePC1HSRP用另一臺路由器進不影響網(wǎng)絡的工作正常,而且要求當兩臺路由器同時處在正常的情況下時要能夠分擔網(wǎng)HSRP的多組來實router(config)#hostnamePC1PC1(config)#interfaceFastEthernet0/1PC1(config)#noswitchportPC1(config-if)#ipaddressPC1(config)#ipdefault-gatewayrouter(config)#hostnameR2PC1(config)#interfaceFastEthernet0/0PC1(config-if)#noswitchportPC1(config-if)#ipaddressR2PC1(config-if)#standby1priorityPC1(config-if)#standby1PC1(config-if)#standby1authenticationmd5key-stringciscoPC1(config-if)#standby1trackLoopback0100批注批注[yeslab170]:說明:此處可loopback0用以做測試rip的正常。但是在做track時候一定要將其從ripno而VRRPO或者HSRPTRACK選項track的驗證試驗失?。ū緦嶒灜h(huán)境 R3PC1(config-if)#standby2ipPC1(config-if)#standby2PC1(config-if)#standby2authenticationmd5key-stringPC1(config-router)#versionPC1(config-router)#networkPC1(config-router)#noauto-summaryrouter(config)#hostnameR3R3(config)#interfaceFastEthernet0/0R3(config-if)#noswitchportR3(config-if)#ipaddressR3(config-if)#standby1ipR3(config-if)#standby1R3(config-if)#standby1authenticationmd5key-stringciscoR3(config-if)#standby2ip1R3(config-if)#standby2priorityR3(config-if)#standby2R3(config-if)#standby2authenticationmd5key-stringciscoR3(config-if)#standby2trackLoopback0100versionnetworknoauto-summaryrouter(config)#hostnamePC2PC2(config)#noiproutingPC2(config)#interfacefastethernet0/2PC2(config-if)#ipaddressPC2(config-if)#noshutdownPC2(config)#ipdefault-gatewayR2#shstandbyFastEthernet0/0R2#shstandbyFastEthernet0/0-Group1Stateis2statechanges,laststatechange00:21:19VirtualIPaddressis0ActivevirtualMACaddressisLocalvirtualMACaddressis0000.0c07.ac01(v1default)otime3sec,holdtime10sec osentin0.412AuthenticationAuthenticationMD5,key-string"cisco"PreemptionenabledActiverouterisStandbyrouteris,priority100(expiresin7.508sec)Priority120(configured120)TrackinterfaceLoopback0stateUpdecrement100IPredundancynameis"hsrp-Fa0/0-1"(default)FastEthernet0/0-Group2StateisStandby4statechanges,laststatechange00:16:09VirtualIPaddressis1ActivevirtualMACaddressisLocalvirtualMACaddressis0000.0c07.ac02(v1default)otim

溫馨提示

  • 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預覽,若沒有圖紙預覽就沒有圖紙。
  • 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
  • 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負責。
  • 6. 下載文件中如有侵權(quán)或不適當內(nèi)容,請與我們聯(lián)系,我們立即糾正。
  • 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。

最新文檔

評論

0/150

提交評論