Center(config)#ip dhcp pool vlan40
Center(dhcp-config)# network 172.16.40.0 255.255.255.0 Center(dhcp-config)# default-router 172.16.40.254 Center(dhcp-config)#dns-server 172.16.5.107
Center(config)#ip dhcp pool vlan50
Center(dhcp-config)# network 172.16.50.0 255.255.255.0 Center(dhcp-config)# default-router 172.16.50.254 Center(dhcp-config)# dns-server 172.16.5.107
Center(config)#ip dhcp pool vlan10_management------//vlan10,¹ÜÀíÔ±vlanÓò Center(dhcp-config)# network 172.16.10.0 255.255.255.0 Center(dhcp-config)# default-router 172.16.10.254 Center(dhcp-config)# dns-server 172.16.5.107
°²È«ÅäÖãº
°²È«²ßÂÔ1£º
ACL:£¨inner Router-f0/0 in£©
1.ÄÚÍø¿ÉÒÔ·ÃÎÊDMZÄڵķþÎñÆ÷£¨FTP,WEB,DNS¡£ 2.DMZÇøÓò²»ÄÜÖ÷¶¯·ÃÎÊÄÚÍø¡£
3.ÄÚÍø¿ÉÒÔping·þÎñÆ÷£¬·þÎñÆ÷²»ÄÜpingÄÚÍø¡£
Extended IP access list dmz-intranet
permit tcp 172.16.5.0 0.0.0.255 172.16.0.0 0.0.255.255 established deny tcp 172.16.5.0 0.0.0.255 172.16.0.0 0.0.255.255 deny icmp 172.16.5.0 0.0.0.255 172.16.0.0 0.0.255.255 echo permit ip any any
Inner_Router(config)#ip access-list extended dmz-intranet
Inner_Router(config-ext-nacl)#permit tcp 172.16.5.0 0.0.0.255 172.16.0.0 0.0.255.255 established Inner_Router(config-ext-nacl)#deny tcp 172.16.5.0 0.0.0.255 172.16.0.0 0.0.255.255 Inner_Router(config-ext-nacl)#deny icmp 172.16.5.0 0.0.0.255 172.16.0.0 0.0.255.255 echo Inner_Router(config-ext-nacl)#permit ip any any Ч¹û£º
10
°²È«²ßÂÔ2£º
ACL£ºInternet(ABR)--F0/1 OUT---Internet-dmz 1.ÄÚÍø¿ÉÒÔ·ÃÎÊÍâÍøµÄ·þÎñ--Web. 2.ÍâÍø¿ÉÒÔ·ÃÎÊDMZÇøÓòµÄ·þÎñ¡£ 3.DMZ²»ÄÜ·ÃÎÊÍâÍø
4.ÄÚÍø¿ÉÒÔpingͨÍâÍø£¬ÍâÍø²»ÄÜPingÄÚÍø
Extended IP access list internet
permit tcp 200.1.10.0 0.0.0.255 172.16.0.0 0.0.255.255 established deny tcp 200.1.10.0 0.0.0.255 172.16.0.0 0.0.255.255 deny icmp 200.1.10.0 0.0.0.255 172.16.0.0 0.0.255.255 echo permit ip any any
ip access-list extended Internet-dmz
permit tcp 172.16.0.0 0.0.255.255 any established deny tcp 172.16.0.0 0.0.255.255 any
deny icmp 172.16.0.0 0.0.255.255 any echo-reply permit ip any any
VPN_°²È«½ÓÈëÅäÖãº
¹«Ë¾×¤ÍâÈËÔ±µÄÖ÷»úÖ±½ÓÁ¬Í¨Internet£¬ÕâÖÖÇé¿öϱØÐëÔÚѧУµÄVPN·ÓÉÆ÷ÉϽøÐÐÅäÖ㬿ͻ§»úʹÓÃVPN¿Í»§¶ËÁ¬½Ó
ÔÚ¹«Ë¾VPN·ÓÉÆ÷ÉÏÅäÖÃEasy VPN£¬Easy VPNÊÇCisco¶ÀÓеÄÔ¶³Ì½ÓÈëVPN£¬ÅäÖùý³ÌÈçÏ£º
aaa new-model Æô¶¯AAAÈÏÖ¤
aaa authentication login vpn-a local aaa authorization network vpn-o local
username vpn password 0 vpn ½¨Á¢±¾µØÓû§ÃûÃÜÂë crypto isakmp enable
crypto isakmp policy 10 ½¨Á¢ipsec°²È«²ÎÊýÅäÖà hash md5
authentication pre-share group 2
ip local pool VPN-POOL 172.16.6.1 172.16.6.254 £¨½¨Á¢·ÖÅ䏸VPNÓû§µÄµØÖ·³Ø£© crypto isakmp client configuration group vpngroup £¨easyvpnµÄ×é¼°ÃÜÂëÅäÖÃ,vpngroup
11
Ϊ×éÃû£© key vpn
domain cisco.com pool VPN-POOL
crypto ipsec transform-set hw esp-3des esp-md5-hmac £¨Ipsec½×¶Î2ÅäÖã© crypto dynamic-map d-map 10 £¨¶¯Ì¬¼ÓÃÜͼ£© set transform-set hw
reverse-route £¨·´Ïò·ÓÉ×¢È룩
EasyvpnÓû§µÄÈÏÖ¤ÊÚȨÅäÖãºno ip domain-lookup crypto map hw-map client authentication list vpn-a crypto map hw-map isakmp authorization list vpn-o crypto map hw-map client configuration address respond crypto map hw-map 10 ipsec-isakmp dynamic d-map ×îºóÔÚ¶Ë¿ÚÉϰ󶨣º interface FastEthernet1/0 crypto map hw-map
ÅäÖÃÍê±ÏÖ®ºóÔÚ¹«Ë¾·Ö²¿ÈËÔ±µÄPCÉÏͨ¹ývpn¿Í»§¶Ë£¬×éÃûΪvpngroup£¬keyΪvpn£¬·þÎñÆ÷µØÖ·ÎªHuaWei.com_CenterµÄFa10µØÖ·£¬Óû§ÃûÃÜÂë¾ùΪvpn£¬¼´¿É¿´µ½Á¬½Ó³É¹¦£¬·Öµ½Ò»¸ö172.16.100.1~172.16.100.254µÄµØÖ·£¬Ö®ºó¾Í¿ÉÒÔÕý³£Ó빫˾ÄÚÖ÷»úͨÐÅÁË¡£
µÇ½ºó£º
µ½ÕâÀ¹«Ë¾ÍⲿµÄÈËÔ±ÔÚ·Ö¹«Ë¾¾Í¿ÉÒÔʹÓò¦ºÅVPNµÇ½µ½¹«Ë¾×ܲ¿£¬µÇ½ºó£¬¾Í¿ÉÒÔÍêÈ«ºÍ×ܹ«Ë¾ÄÚ²¿µÄ»úÆ÷ÏíÓй²Í¬µÄ×ÊÔ´ºÍ²ßÂÔ¡£ WEB·þÎñÆ÷£º
ÓòÃûΪ£ºwww.hw.com µØÖ·Îª£º172.16.5.100
12
Îå¡¢GREËíµÀÅäÖÃ
ÍØÆËͼ£º
ʵÑé²½Öè¼°ÒªÇó£º
1¡¢ÅäÖø÷̨·ÓÉÆ÷µÄIPµØÖ·£¬²¢ÇÒʹÓÃPingÃüÁîÈ·Èϸ÷·ÓÉÆ÷µÄÖ±Á¬¿ÚµÄ»¥Í¨¡£ 2¡¢ÔÚR1ºÍR3ÉÏÅäÖþ²Ì¬Â·ÓÉ¡£È·±£InternetÍøÂç¹Ç¸É¿ÉÒÔÏ໥ͨÐÅ¡£
ÔÚR1ÓëR3ÉÏÅäÖþ²Ì¬Ä¬ÈÏ·ÓÉ£¬²»½ö½öÊÇÓÃÓÚÄ£Äâ½ÓÈë·ÓÉÆ÷¡£Í¬Ê±»¹ÎªÁËÈ·±£ÔÚ´´½¨ËíµÀʱ£¬ËíµÀÔ´ÓëËíµÀÄ¿±êµÄIPµØÖ·Ï໥¿É¼û¡£ÒÔ±ãÓÚʵÏÖËíµÀ¡£ 3¡¢È·ÈÏR1Äܹ»PingͨR3·ÓÉÆ÷µÄ¹«Íø½Ó¿ÚIP¡£
4¡¢ÔÚR1»òR3·ÓÉÆ÷ÉÏPing·ÓÉÆ÷R3»òR1µÄ»Ø»·¿Ú¡£ 5¡¢ÔÚR1·ÓÉÆ÷ÉÏÅäÖÃGREËíµÀ¡£ 6¡¢ÔÚR2·ÓÉÆ÷ÉÏÅäÖÃGREËíµÀ¡£ 7¡¢ÔÚR1Éϲ鿴ËíµÀ½Ó¿ÚÐÅÏ¢¡£ 8¡¢²é¿´R1µÄ·ÓÉ±í¡£
9¡¢ÔÚR1ÉÏPING·ÓÉÆ÷R3µÄËíµÀ½Ó¿Ú¡£
10¡¢ÔÚR1ºÍR3·Ö±ðÅäÖÃÄ¿±êΪR1ºÍR3µÄ»Ø»·½Ó¿Ú£¬ÏÂÒ»ÌøÎªËíµÀ½Ó¿ÚµÄ·ÓÉ¡£
Áù¡¢°²È«²âÊÔ
°²È«Êý¾Ý¸ñʽ°üÉè¼ÆÓë·â×°
ICMP±¨ÎÄ£¬È»ºóʹÓõ÷ÖÆÄ£Ê½£¬²é¿´ÆäÔÚÍøÂçÖеķâ×°Çé¿ö¡£
Èçͼ£ºÎÒÃÇÀ´¹Û²ìÏÂÊý¾Ý°üµÄ¸ñʽ:
13
14
Ïà¹ØÍÆ¼ö£º