
企业级三层网—OSPF + VLAN + DHCP + NAT + ACL 综合实验部署案例
某中型企业 IT 网络需要搭建完整内部网络,要求:
需求类型 | 说明 |
|---|---|
多部门隔离通信 | VLAN划分 |
内部动态路由 | OSPF |
访问公网业务 | NAT |
地址动态分配 | DHCP |
网络安全 | ACL过滤 |
冗灾设计 | 双上行路由冗余 |
管理入口规划 | Loopback管理地址 |
┌────Router2────Internet
│
DeptA---SwitchA─┤
│
DeptB---SwitchA─┤────Router1────ISP
│
Server---SwitchA┘
三层结构类比:
层次 | 设备 |
|---|---|
Access | SwitchA |
Distribution | Router1 |
Core | Router2 |
部门 | VLAN | 网段 |
|---|---|---|
DeptA | 10 | 192.168.10.0/24 |
DeptB | 20 | 192.168.20.0/24 |
Server | 30 | 192.168.30.0/24 |
OSPF单区域:
Router | Area |
|---|---|
R1、R2 | Area 0 |
上网 NAT:
sys
vlan batch 10 20 30
interface g0/0/1
port link-type access
port default vlan 10
interface g0/0/2
port link-type access
port default vlan 20
interface g0/0/3
port link-type access
port default vlan 30
interface g0/0/10
port link-type trunk
port trunk allow-pass vlan 10 20 30
interface g0/0/1.10
vlan-type dot1q 10
ip address 192.168.10.1 24
interface g0/0/1.20
vlan-type dot1q 20
ip address 192.168.20.1 24
interface g0/0/1.30
vlan-type dot1q 30
ip address 192.168.30.1 24
ospf 1
area 0
network 192.168.10.0 0.0.0.255
network 192.168.20.0 0.0.0.255
network 192.168.30.0 0.0.0.255
network 10.10.10.0 0.0.0.255
ospf 1
area 0
network 10.10.10.0 0.0.0.255
dhcp enable
ip pool vlan10
gateway-list 192.168.10.1
network 192.168.10.0 mask 255.255.255.0
dns-list 8.8.8.8
ip pool vlan20
gateway-list 192.168.20.1
network 192.168.20.0 mask 255.255.255.0
ip pool vlan30
gateway-list 192.168.30.1
network 192.168.30.0 mask 255.255.255.0
acl 2000
rule permit ip source 192.168.0.0 0.0.255.255
interface g0/0/2
nat outbound 2000
Server VLAN需阻止DeptB访问:
acl 3000
rule deny ip source 192.168.20.0 0.0.0.255 destination 192.168.30.0 0.0.0.255
rule permit ip
interface g0/0/1.30
packet-filter 3000 inbound
display ip pool statistics
DeptA ping DeptB:
fail
DeptA ping Server:
OK
display ospf peer
display ospf routing
结果应看到:
内部终端:
ping 114.114.114.114
DeptB → Server:
ping fail
排查:
可能原因:
检查:
MTU
area ID
network命令范围
检查:
本综合实验体现企业三层网关键技术:
技术 | 目标 |
|---|---|
VLAN | 部门隔离 |
Inter-VLAN Routing | 跨网通信 |
OSPF | 动态路径收敛 |
ACL | 安全访问控制 |
NAT | 业务上网 |
DHCP | 自动地址分配 |