基于ipv6的多分支大学校园网设计与实现

eNSP虚拟环境的搭建

IP 地址规划

接入单位

地址

所属vlan

宿舍网络1

2001:200:3C02:1::/64

10

宿舍网络2

2001:200:3C02:2::/64

20

办公室网络

2001:200:3C02:3::/64

30

机房1网络

2001:200:3C02:4::/64

40

机房2网络

2001:200:3C02:5::/64

50

教学楼1网络

2001:200:3C02:6::/64

60

教学楼2网络

2001:200:3C02:7::/64

70

图书馆网络

2001:200:3C02:8::/64

80

服务器网络

2001:200:3C02:A::/64

-

整体拓扑图

Vlan创建

[ss_HJA]vlan  batch  10 20 30 40 50 60 70 80 90 100

其他交换机配置相同

[Acc-01]vlan  batch  100 10 20 30 40 50 60 70 80 90  //创建vlan

配置接入用户接口

[Acc-01-Ethernet0/0/3]port link-type access

[Acc-01-Ethernet0/0/3]port default  vlan  10

[Acc-01-Ethernet0/0/4]port link-type access

[Acc-01-Ethernet0/0/4]port default  vlan  10

[Acc-02-Ethernet0/0/3]port link-type access

[Acc-02-Ethernet0/0/3]port default  vlan  20

[Acc-02-Ethernet0/0/4]port link-type access

[Acc-02-Ethernet0/0/4]port default  vlan  20

配置上行口

[Acc-01-Ethernet0/0/1]port link-type trunk

[Acc-01-Ethernet0/0/1]port trunk allow-pass vlan all

[Acc-01-Ethernet0/0/1]int e0/0/2

[Acc-01-Ethernet0/0/2]port link-type trunk              

[Acc-01-Ethernet0/0/2]port trunk allow-pass vlan all

    port link-type trunk

    port trunk allow-pass vlan 10 to 100

[Huawei]ipv6 route-static 2001:200:3C02:: 48 2001::1

[Huawei]dhcpv6  pool  vlan10

[Huawei-dhcpv6-pool-vlan10]address  prefix  2001:200:3C02:1::/64

[Huawei-dhcpv6-pool-vlan10]dns-server 88::88

关闭ra报文抑制

[ss_HJA-Vlanif10]undo ipv6 nd ra halt

配置自动配置 RA标志位 使用有状态dhcpv6 获取地址

[ss_HJA-Vlanif10]ipv6  nd autoconfig  managed-address-flag 

[ss_HJA-Vlanif10]ipv6 nd autoconfig other-flag

DHCP中继配置

[ss_HJA-Vlanif10]dhcpv6 relay  destination  2001:200:3C02:A::FFFE

[ss_HJA-Vlanif10]vrrp6 vrid 10 virtual-ip  fe80::1 link-local    //必须配置链路本地地址

[ss_HJA-Vlanif10]vrrp6 vrid  10 virtual-ip  2001:200:3C02:1::1

[ss_HJA-Vlanif10]vrrp6 vrid  10 priority 120

备份组

[ss_HJB-Vlanif10] vrrp6 vrid 10 virtual-ip FE80::1 link-local

[ss_HJB-Vlanif10] vrrp6 vrid 10 virtual-ip 2001:200:3C02:1::1

实现NAT

sys

acl 2999 

  rule 5 permit source 0.0.0.0 0.0.255.255

quit

int g5/0/1  | int g2/0/2

 nat out bound 2999

quit

实现OSPFV3

[ss_HJA]ospfv3  1

[ss_HJA-ospfv3-1]router-id 3.3.3.3

[ss_HJA]int vlan 10

[ss_HJA-Vlanif10]ospfv3  1 area  1

防火墙,去往ISP路由

ipv6 route-static :: 0 2001::2

Ospfv3 引入默认

default-route-advertise

安全区域配置

firewall zone trust

 set priority 85

 add interface GigabitEthernet0/0/0

 add interface GigabitEthernet1/0/0

 add interface GigabitEthernet1/0/4

firewall zone untrust

 set priority 5

 add interface GigabitEthernet1/0/1

firewall zone dmz

 set priority 50

 add interface GigabitEthernet1/0/2


测试

DNS服务器配置

DNS主机端测试

以上是本人做的一个课程设计,交流请加扣1425166971 

猜你喜欢

转载自blog.csdn.net/weixin_46568591/article/details/125472540