预览加载中,请您耐心等待几秒...
1/7
2/7
3/7
4/7
5/7
6/7
7/7

在线预览结束,喜欢就下载吧,查找使用更方便

如果您无法下载资料,请参考说明:

1、部分资料下载需要金币,请确保您的账户上有足够的金币

2、已购买过的文档,再次下载不重复扣费

3、资料包下载后请先用软件解压,在使用对应软件打开

热备份加nat转换及端口跟踪 实验环境:一台防火墙,两台pc机,两台路由器,两台交换机(连接外网的可以使防火墙可以使路由器) 配置防火墙: [r1]firepacketdefaultpermit [r1]firewallzonetrust [r1-zone-trust]addintere0/0 [r1-zone-trust]addintere0/1 [r1-zone-trust]addintere0/2 [r1-zone-trust]intereth0/0 [r1-Ethernet0/0]ipaddress192.168.5.1255.255.255.0 [r1-Ethernet0/0]intereth0/1 [r1-Ethernet0/1]ipaddress192.168.4.1255.255.255.0 [r1-zone-trust]intereth0/2 [r1-Ethernet0/2]ipaddress192.168.3.1255.255.255.0 [r1-Ethernet0/2]loopback 配置r2: [r2-Ethernet0]intere1 [r2-Ethernet1]ipaddress192.168.4.2255.255.255.0 [r2-Ethernet0]intere0.10 [r2-Ethernet0.10]vlan-typedot1qvid10 [r2-Ethernet0.10]ipaddress192.168.10.1255.255.255.0 [r2-Ethernet0.10]intere0.20 [r2-Ethernet0.20]vlan-typedot1qvid20 [r2-Ethernet0.20]ipaddress192.168.20.1255.255.255.0 配置静态路由: [r2]iproute0.0.0.00.0.0.0192.168.4.1 R2做nat转换: [r2]acl2000 [r2-acl-2000]rulepermitsourceany [r2]intere1 [r2-Ethernet1]natoutbound2000interface 配置r3: [r3]iproute0.0.0.00.0.0.0192.168.5.1 [r3]intere0 [r3-Ethernet0]ipaddress192.168.5.2255.255.255.0 [r3-Ethernet0] %01:20:09:LineprotocolipontheinterfaceEthernet0isUP [r3-Ethernet0]undoshut [r3]intereth1.10 [r3-Ethernet1.10]vlan-typedo1qvid10 Incorrectcommand [r3-Ethernet1.10]vlan-typedot1qvid10 [r3-Ethernet1.10]ipaddress192.168.10.2255.255.255.0 [r3-Ethernet1.10]intereth0.20 [r3-Ethernet1.20]vlan-typedot1qvid20 [r3-Ethernet1.20]ipaddress192.168.20.2255.255.255.0 Nat转换: [r3]acl2000 [r3-acl-2000]rulepermitsourceany Rulehasbeenaddedtonormalpacket-filteringrules [r3-acl-2000]intere0 [r3-Ethernet0]natoutbound2000interface Sw1配置: [sw1]vlan10 [sw1-vlan10]porte0/10 [sw1-vlan10]vlan20 [sw1-vlan20]porte0/20 [sw1]intere0/1 [sw1-Ethernet0/1]portlink-typetrunk [sw1-Ethernet0/1]porttrunkpermitvlanall Pleasewait...........................................Done. [sw1-Ethernet0/5]portlink-typetrunk [sw1-Ethernet0/5]porttrunkpermitvlanall Pleasewait...........................................Done. Sw2配置: [sw2]vlan10 [sw2-vlan10]porte0/10 [sw2-vlan10]vlan20 [sw2-vlan20]porte0