网络拓扑图:
如上图所示:内网为三层网络架构,核心交换机上连两个防火墙(两个防火墙互为主备关系),两个防火墙上联两个路由器(可做策略路由,起负载均衡的作用)。
配置思路:
一、先配置内网环境
核心交换机配置VLAN、开启DHCP、开启MSTP、创建地址池、配置VLAN地址、配置OSPF、配置静态路由。(上联两个接口g0/0/23、g0/0/24配置和上连防火墙虚拟地址同网段地址)
sys
sys XIAN_CORE_SW_01
stp enable
dhcp enable
vlan batch 10 20 30 99
int vlanif 99
ip add 10.100.99.99 29
q
port-group 1
group-member g0/0/23 to g0/0/24
p l a
p d v 99
q
port-group 2
group-member g0/0/1 to g0/0/3
p l t
p t a v a
q
ip pool 10
network 10.100.101.1 mask 24
gateway-list 10.100.101.1
dns-list 61.134.1.5 114.114.114.114
ip pool 20
network 10.100.102.1 mask 24
gateway-list 10.100.102.1
dns-list 61.134.1.5 114.114.114.114
ip pool 30
network 10.100.103.1 mask 24
gateway-list 10.100.103.1
dns-list 61.134.1.5 114.114.114.114
q
int vlanif 10
ip add 10.100.101.1 24
dhcp select global
int vlanif 20
ip add 10.100.102.1 24
dhcp select global
int vlanif 30
ip add 10.100.103.1 24
dhcp select global
q
int lo 1
ip add 10.100.99.205 32
ospf 1 router-id