Professional Documents
Culture Documents
2007年最新CCNA实验手册
2007年最新CCNA实验手册
http://www.GXcisco.com 技术支持:广西南宁欧朋信息技术有限公司
广西权威IT认证培训中心
广西专业的 Cisco 实验室
多名CCNA CCNP资深讲师 100多套 Cisco 设备
写在文前: 在此特别感谢CCIE#12421 田家昌老师 郭老师 CCIE#16192 董 智老师
网络小菜鸟 315 安全网许子华老师等无私的帮助!感谢欧朋公司 周老师
代老师 黎老师 宋老师等提供原资料!
由于比较匆忙,如有错误之处,请大家谅解!! 2007 年元月15 日
172.16.1.1
172.16.1.254
R1 E0
12.1.1.1 S1
S0 13.1.1.1
12.1.1.2
13.1.1.3
S0 S0
S1 S1
220.1.1.2
R2 R3 33.1.1.3
23.1.1.2 23.1.1.3
CCNA 实验拓图
实验目录:
•Lab 1 - Basic Router Configuration
•Lab 2 - Advanced Router Configuration
•Lab 3 - CDP
•Lab 4 - Telnet
•Lab 5 - TFTP
•Lab 6 - RIP
•Lab 7 - IGRP
•Lab 8 - EIGRP
•Lab 9 - OSPF
•Lab 10 –Catalyst 1900 Switch Configuration
•Lab 11 - VLANs & Trunking (Catalyst 1900)
•Lab 12 - Catalyst 2950 Switch Configuration
•Lab 13 - VLANs and Trunking (Catalyst 2950)
•Lab 13-1 Routing inter VLAN(Dot1q)
•Lab 14 - IP Access Lists
•Lab 15 - NAT/PAT
•Lab 16 - PPP & CHAP
•Lab 17 - ISDN BRI-BRI using Legacy DDR
•Lab 18 - ISDN BRI-BRI using Dialer Profiles
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com 技术支持:广西南宁欧朋信息技术有限公司
LAB 1 – 基本配置
1.
Router>
3.
Router> ?
4. Router> enable
Router#
5. Router# ?
6. Router# disable
Router>
7. Router> enable
Router# configure terminal
Router(config)#
8. 配置路由器名字如 ‘naxxr1’(注:如果你用的试验台号是 03,则命名为 na03r1,如果
为
12,则命名 na12r1,依次类推).
Router(config)# hostname naxxr1
naxxr1(config)#
9. 修改特权模式密码
问题 A: when both encrypted and unencrypted enable passwords are configured, which one is
used?
naxxr1(config)# enable ?
naxxr1(config)# enable password
ccnalab naxxr1(config)# enable secret
cisco
10. 在接口配置 IP
naxxr1(config)# int<tab>
naxxr1(config)# interface ethernet0
naxxr1(config-if)# ip address 172.16.1.1 255.255.255.0
naxxr1(config-if)# no shutdown
11. 在 S0 口配置
naxxr1(config-if)# int s0
naxxr1(config-if)# ip address 12.1.1.1 255.255.255.0
naxxr1(config-if)# no shut
12. 测试 ctrl-z 的作用
naxxr1(config-if)# ctrl-
z naxxr1#
13. 退出路由器
naxxr1# logout
14. 回到特权模式
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
naxxr1> enable
password:
cisco naxxr1#
15.显示接口的概况:
naxxr1# show ip interface brief
16. 显示详细信息:
naxxr1# show interfaces
17.显示内存信息:
naxxr1# show running-config
18. 显示 NVRAM? If not, why not?
naxxr1# show startup-config
19. 保存配置:
naxxr1# copy running-config startup-config
20. 现在显示 NVRAM.
naxxr1# show startup-config
21. 使用 Show version:
问题 A: What IOS release is running 在 naxxr1?
问题 B: What are the contents of the configuration register?
naxxr1# show version
22. 查看运行的协议
问题 A:which protocols are currently running on the router?
naxxr1# show protocols
23. 进入另一台 Router.
Router> enable
Router# configure terminal
Router(config)#
24. 配置主机名,配置密码.
Router(config)# hostname naxxr2
naxxr2(config)# enable secret cisco
25. 配置以太网 IP.
naxxr2(config)# interface E0
naxxr2(config-if)# ip address 220.1.1.2 255.255.255.0
naxxr2(config-if)# no shut
26. 显示所有接口简单信息
naxxr2(config-if)# ctrl-z
naxxr2# show ip interface
brief
LAB 2 – 路由器配置
2. 配置路由器 Console 接口的密码 wisdom
naxxr1(config)# line console 0
naxxr1(config-line)# login
naxxr1(config-line)# password wisdom
3. 配置 Banner” Welcome to WISDOM LAB - Authorized Users Only”.
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
naxxr1(config)# banner motd #
Welcome to WISDOM LAB - Authorized Users Only #
4. 退出路由器,重新登录.
naxxr1# logout
enter
password:
wisdom naxxr1>
enable
password: cisco
naxxr1#
5. 配置 Telnet 密码:
naxxr2(config)# line vty 0 4
naxxr2(config-line)# login
naxxr2(config-line)# password
cisco
6. 在 Naxxr1 上将 Naxxr2 和 12.1.1.2 对应起来
(相当于 Windows 里的 Hosts 文件的作
用)。
.
naxxr1(config)# ip host naxxr2 12.1.1.2
7. 检查 Naxxr1 中主机名和 IP 地址的对应.
naxxr1# show hosts
8. Ping ‘naxxr2’看是否成功.
naxxr1# ping naxxr2
9.显示 naxxr2 上的 Flash.
问题 A: what is the name of the IOS image in flash and how large is it?
naxxr2# show flash
10. 显示 Naxxr1 上曾经敲入的命令,可以看到前 10 条,可以通过 Ctrl+P 或向上箭头调
出 这些命令.
naxxr1# show history
naxxr1# ctrl-p (to see previously entered commands)
11.
naxxr1# show interfaces serial 0
naxxr1# configure terminal
naxxr1(config)# interface serial
0
如果 Naxxr1 的 S0 口接的线是 DCE 接头,输入下面命令,使得这个接口能根对端的接口建立串行连接,
否
则即使你配置了 IP 也没法连通。
naxxr1(config-if)# clock rate 64000
naxxr1(config-if)# ctrl-z
naxxr1# show interfaces serial 0
12. 配置接口的 LABEL.
naxxr1(config)# interface serial 0
naxxr1(config-if)# description Serial Link to Naxxr2
naxxr1(config-if)# exit
naxxr1(config)# exit
naxxr1# show interfaces serial 0
13. 配置 naxxr3
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
LAB 3 –CDP
1. 做好基本配置
naxxr1# config t
naxxr1(config)# interface serial 0
naxxr1(config-if)# no sh
naxxr1(config-if)# clock rate 4000000
naxxr1(config-if)# ip add 12.1.1.1 255.255.255.0
naxxr1(config-if)#exit
naxxr1(config)# interface serail 1
naxxr1(config-if)# clock rate 4000000
naxxr1(config-if)# ip add 13.1.1.1 255.255.255.0
naxxr1(config-if)# end
naxxr2# config t
naxxr2(config)# interface serial 0
naxxr2(config-if)# no sh
naxxr2(config-if)# ip add 12.1.1.2 255.255.255.0
naxxr2(config-if)#end
naxxr3# config t
naxxr3(config)# interface serial 0
naxxr3(config-if)# no sh
naxxr3(config-if)# ip add 13.1.1.3 255.255.255.0
naxxr3(config-if)#end
2. 在 Naxxr1.
naxxr1# sh cdp neighbors
3. 显示邻居的详细信息.
naxxr1# show cdp neighbors
detail naxxr1# show cdp entry *
4. 查看那个接口运行 CDP.
问题 A: what is the CDP advertisement interval?
问题 B: what is the holdtime interval and what does it signify?
naxxr1# show cdp interface
5.在 naxxr1,改变 CDP 的计时器.
naxxr1(config)# cdp timer 50
naxxr1(config)# cdp holdtime
170 naxxr1(config)# exit
naxxr1# sh cdp interface
6. 启用和禁用 CDP
Naxxr1(config)#no cdp run !禁止路由器运行 CDP
naxxr1#show cdp nei !检查看到没有 CDP 运行
naxxr1#configure terminal
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
naxxr1(config)#interface serial0
naxxr1(config-if)#no cdp enable !禁止此接口运行 CDP
naxxr1#show cdp interface !看不到 Serial0 运行 CDP
启用 CDP
naxxr1(config)#cdp run
naxxr1(config)#interface serial0
naxxr1(config
-if)#cdp enable
LAB 4 –TELNET
1. 基本配置要配置好
naxxr1# config t
naxxr1(config)# interface serial 0
naxxr1(config-if)# no sh
naxxr1(config-if)# clock rate 4000000
naxxr1(config-if)# ip add 12.1.1.1 255.255.255.0
naxxr1(config-if)#exit
naxxr1(config)# interface serail 1
naxxr1(config-if)# clock rate 4000000
naxxr1(config-if)# ip add 13.1.1.1 255.255.255.0
naxxr1(config-if)# end
naxxr2# config t
naxxr2(config)# interface serial 0
naxxr2(config-if)# no sh
naxxr2(config-if)# ip add 12.1.1.2 255.255.255.0
naxxr2(config-if)#end
naxxr3# config t
naxxr3(config)# interface serial 0
naxxr3(config-if)# no sh
naxxr3(config-if)# ip add 13.1.1.3 255.255.255.0
naxxr3(config-if)#end
naxxr3>
naxxr3# config t
naxxr3(config)#line vty 0 4
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
naxxr3(config-line)#login
naxxr3(config-line)#password cisco
3. 在 Naxxr1 上登录到 Naxxr2.
naxxr1# telnet 12.1.1.2
naxxr2>
naxxr2# show users
4. 在 Naxxr2 上输入 CTRL-SHIFT-6 ,松开手然后输入 X. 将回到 Naxxr1
naxxr2# ctrl-shift-6
x naxxr1#
naxxr1# show sessions
5. Telnet 到 Naxxr3.
naxxr1# telnet 13.1.1.3
naxxr3>
naxxr3> ctrl-shift-6
x naxxr1#
naxxr1# show sessions
6. 在 Naxxr1 上断开连接
naxxr1# disconnect
2 naxxr1# disconnect
1 naxxr1# show
sessions
config
LAB 6 - RIP
假设所有路由器已经配置好了 IP 地址(路已经修好了)
路由器基本配置:
naxxr1# config t
naxxr1(config)# interface serial 0
naxxr1(config-if)# no sh
naxxr1(config-if)# clock rate 4000000
naxxr1(config-if)# ip add 12.1.1.1 255.255.255.0
naxxr1(config-if)#exit
naxxr1(config)# interface serail 1
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
naxxr2# config t
naxxr2(config)# interface serial 0
naxxr1(config-if)# clock rate 4000000
naxxr2(config-if)# no sh
naxxr2(config-if)# ip add 12.1.1.2 255.255.255.0
naxxr2(config-if)#exit
naxxr2(config)#interface ethernet0
naxxr2(config-if)#ip add 220.1.1.2 255.255.255.0
naxxr2(config-if)#no shut
naxxr2(config-if)#no keepalive
naxxr2(config-if)#end
naxxr3# config t
naxxr3(config)# interface serial 0
naxxr3(config-if)# no sh
naxxr1(config-if)# clock rate 4000000
naxxr3(config-if)# ip add 13.1.1.3 255.255.255.0
naxxr3(config-if)#exit
naxxr3(config)#interface ethernet0
naxxr3(config-if)#ip add 33.1.1.3 255.255.255.0
naxxr3(config-if)#no shut
naxxr3(config-if)#no keepalive
naxxr3(config-if)#end
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
LAB 7 –IGRP
假设所有路由器已经配置好了 IP 地址(路已经修好了)
清除刚才配置的 RIP
routerx(config)# no router
rip routerx# show ip protocols
2. 在 naxxr1, naxxr2, naxxr3,使用自治系统号 100.
naxxr1(config)# router igrp 100
naxxr1(config-router)# network
172.16.0.0 naxxr1(config-router)#
network 12.0.0.0 naxxr1(config-router)#
network 13.0.0.0 naxxr2(config)# router
igrp 100 naxxr2(config-router)# network
12.0.0.0 naxxr2(config-router)# network
220.1.1.0 naxxr3(config)# router igrp 100
naxxr3(config-router)# network 13.1.0.0
naxxr3(config-router)# network 33.0.0.0
3.显示动态路由协议.
问题 A: how frequently does IGRP send out routing updates?
问题 B: what is the holddown interval for IGRP?
问题 C: what is the default hop count for IGRP?
naxxr1# show ip protocols
4. 显示 IP 路由.
问题 A: what is the administrative distance for IGRP?
Naxxr1# show ip route
5. 在 naxxr2, ping naxxr3.
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
6.
问题 A: what is the difference between the two debug ip igrp commands?
naxxr1# debug ip igrp events
naxxr1# debug ip igrp
transactions
LAB 8 –EIGRP
1. 清除刚才配置的 IGRP
routerx(config)# no router igrp 100
2.
naxxr1(config)# router eigrp 1
naxxr1(config-router)# network
172.16.0.0 naxxr1(config-router)#
network 12.0.0.0 naxxr1(config-router)#
network 13.0.0.0 naxxr2(config)# router
eigrp 1 naxxr2(config-router)# network
12.0.0.0 naxxr2(config-router)# network
220.1.1.0 naxxr3(config)# router eigrp 1
naxxr3(config-router)# network 13.0.0.0
naxxr3(config-router)# network 33.0.0.0
3. 查看路由协议.
问题 A: what is the maximum router hop count with EIGRP?
router4# show ip protocols
4.在 naxxr1 上显示 EIGRP 邻居.
naxxr1# show ip eigrp neighbors
5.在 naxxr1 是能够显示 EIGRP 包的发送和接受数量.
naxxr1# show ip eigrp traffic
6.在 naxxr1 上显示 EIGRP topology database.
问题 A: what does the EIGRP topology database contain?
naxxr1# show ip eigrp topology
7. 在 naxxr2 上显示路由
问题 A: EIGRP 的管理距离多少?
router4# show ip route
8. 在 naxxr2, ping naxxr3.
naxxr2# ping 33.1.1.3
naxxr2# ping 13.1.1.3
9.
naxxr1# debug ip eigrp
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
LAB 9 - OSPF
naxxx(config)# no router eigrp 100
2..
naxxr1(config)# router ospf 1
naxxr1(config-router)# network 172.16.1.0 0.0.0.255
area 0 naxxr1(config-router)# network 12.1.1.0 0.0.0.255
area 0 naxxr1(config-router)# network 13.1.1.0 0.0.0.255
area 0 naxxr2(config)# router ospf 1
naxxr2(config-router)# network 12.1.1.0 0.0.0.255
area 0 naxxr2(config-router)# network 220.1.1.0
0.0.0.255 area 0 naxxr3(config)# router ospf 1
naxxr3(config-router)# network 13.1.1.0 0.0.0.255 area 0
naxxr3(config-router)# network 33.1.1.0 0.0.0.255 area 0
3. 显示路由协议信息.
问题 A: How frequently does OSPF send routing updates?
Naxxr1# sh ip protocols
4.在 naxxr1 上检查邻居.
naxxr1# sh ip ospf neighbor
5.在 naxxr1 检查运行 OSPF 的接口.
问题 A: 10Mbps 以太网接口中的 COST 是多少?
naxxr1# sh ip ospf interface
6. 检查路由表.
问题 A: OSPF 的管理距离多少?
router4# show ip route
7. 在 naxxr2, ping naxxr3.
naxxr2# ping 33.1.1.3
naxxr2# ping 13.1.1.3
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
12. On switch1, issue the show mac-address-table command. This shows which devices are
attached to which switch ports.
1900sw1# show mac-address-table
13. On switch1, permanently assign a device with MAC address 1111-1111-1111 to port
E0/5. Issue the show mac-address-table command to verify the device is in the table as
a permanent entry.
1900sw1(config)# mac-address-table permanent 1111-1111-1111 e0/5
1900sw1(config)# exit
1900sw1# show mac-address-table
14. On switch1, configure port security for port e0/9. The switch will ‘sticky-learn’the MAC
address of the device connected to port e0/9 and will only allow that device to connect to this
port in the future.
1900sw1(config)# interface e0/9
1900sw1(config-if)# port secure
1900sw1(config-if)# port secure max-mac-count 1
8. Now that both router4 and PC1 are in VLAN10, try to ping from the PC1 to router4. It
should fail.
问题 A: if both devices are in the same VLAN, why should the pings fail?
c:> ping 195.10.1.1
9. Make the link between switch1 and switch2 a trunk line capable of carrying traffic for any
VLAN. Use the show trunk a command to verify trunking is enabled on port fa0/26 on both
switches (it should say “Trunking: on”)
问题 A: what trunking protocol does the 1900 use –ISL or 802.1Q?
1900swx(config)# interface fa0/26
1900swx(config-if)# trunk on
1900swx(config-if)# ctrl-z
1900swx# show trunk a
10. Now ping between PC1 and router4. The pings should succeed because both devices are in
the same VLAN and the inter-switch link is a trunk line capable of carrying traffic for any
VLAN.
c:> ping 195.10.1.1
Switch> enable
Switch# ?
Switch#
disable Switch>
3.
Switch> enable
Switch# configure terminal
Switchconfig)# hostname
sw2950 sw2050(config)# exit
sw2950#
4. 检查运行配置
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
1. 检查交换机上的 VLAN
sw01# show vlan
2. 配置 Trunk
ISL 封装方式:
Sw01(config)# interface fa0/1
sw01(config-if)# switchport mode trunk
Sw01(conifg-if)#swtichport trunk encapsulation isl !2950 交换机不能敲入此命令
sw01(config-if)# ctrl-z
sw01# show interface fa0/1 switchport
DOT1Q 封装方式:
Sw01(config)# interface fa0/1
sw01(config-if)# switchport mode trunk
Sw01(conifg-if)#swtichport trunk encapsulation dot1q !2950 交换机不用敲入此命令
sw01(config-if)# ctrl-z
sw01# show interface fa0/1 switchport
3. 配置 VTP(两种方法)
第一种:
sw01# vlan database
sw01(vlan)# vtp domain wisdom
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
HTTP://WWW.WISDOMINFO.COM
sw01(vlan)#vtp server
sw01(vlan)# ctrl-z
sw01# show vtp
status
第二种:
sw01(config)#vtp domain wisdom
sw01(vlan)#vtp mode server
sw01(config)#end
sw01#show vtp status
4.创建 Vlan
sw01# vlan database
sw01(vlan)# vlan 2 name
vlan2 sw01(vlan)# vlan 3
name vlan3 sw01(vlan)# exit
sw01# show vlan
6.配置 R1、R2 和 R3 的 IP
Naxxr1(config)#interfacee0
Naxxr1(config-if)#ipadd 1.1.1.1
Naxxr2(config)#interfacee0
Naxxr2(config-if)#ipadd 1.1.1.2
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
Naxxr3(config)#interfacee0
Naxxr3(config-if)#ipadd 1.1.1.3
7. 测试
在 naxxr1 上能 ping 通 1.1.1.2,不能 ping 通 1.1.1.3
naxxr1#ping 1.1.1.2
naxxr1#ping 1.1.1.3
LAB 13 –1 VLAN间路由
R2610
TRUNK
路由器配置:
Router>
Router>
R ou ter>enab le
Router#conf
R ou ter#con figu re t
R ou ter#con figu re term i na l
R ou ter(con fig)#ho stna m e R 2610
R2610(config)#interface e0/0
R2610(config-if)#no shutdown
R 2610 (con fig-i f)#no i p
add ress R2610(config-if)#exit
R 2610 (con fig)#i nterface e0 /0.2
R 2610 (con fig-sub if)#en cap sul ati
on do t1Q 2
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
交换机配置:
Sw itch>
Switch>
Switch>en able
Switch#conf
Switch#configure t
Switch#configure terminal
Switch(config)#host sw2950
sw2950(config)#int f0/24
sw2950(config-if)#switchpo rt mode trunk
sw2950(config-if)#exit
sw2950(config)#vlan 2
sw2950(config-vlan)#nam e VLAN2
sw2950(config-vlan)#exit
sw2950(config)#vlan 3
sw2950(config-vlan)#name VLAN3
sw2950(config-vlan)#exit
sw2950(config)#vlan 4
sw2950(config-vlan)#nam e VLAN4
sw2950(config-vlan)#exi
sw2950(config)#int f0/1 - 6
range
sw2950(config-if -range)#switchportmode access
sw2950(config-if -range)#switchport access vlan 2
sw2950(config-if -range)#exit
sw2950(config)#int range - 12
f0/7
sw2950(config-if -range)#switchport m ode access
sw2950(config-if -range)#switchport access vlan 3
sw2950(config-if -range)#exit
sw2950(config)#int range - 18
f0/13
sw2950(config-if -range)#switchport mo de access
sw2950(config-if -range)#switchport access vlan 4
sw2950(config-if-range)#end
sw2950#
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
172.16.1.1
172.16.1.254
Naxxr1 E0
12.1.1.1 S1
S0 13.1.1.1
12.1.1.2
13.1.1.3
S0 S0
220.1.1.2 naxxr2 Naxxr3
33.1.1.3
172.16.1.254
naxxr2:
naxxr2>en
naxxr2#conf t
Enter configuration commands, one per line. End with CNTL/Z.
naxxr2(config)#hostname naxxr2
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
naxxr2(config)#int s0
naxxr2(config-if)#ip address 12.1.1.2 255.255.255.0
naxxr2(config-if)#no sh
naxxr2(config-if)#exi
naxxr2(config)#ip route 0.0.0.0 0.0.0.0 12.1.1.1
naxxr2(config)#end
naxxr2#ping 13.1.1.3
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 13.1.1.3, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 4/7/8 ms
naxxr2#
NAXXR3:
Router>en
Router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#hostname naxxr3
naxxr3(config)#interface serial 0
naxxr3(config-if)#no shutdown
naxxr3(config-if)#
naxxr3(config-if)#ip add 13.1.1.3 255.255.255.0
naxxr3(config-if)#exit
naxxr3(config)#ip route 0.0.0.0 0.0.0.0 13.1.1.1
naxxr3(config)#end
naxxr3#ping 12.1.1.2
naxxr2:
naxxr2>en
naxxr2#conf t
Enter configuration commands, one per line. End with CNTL/Z.
naxxr2(config)#hostname naxxr2
naxxr2(config)#int s0
naxxr2(config-if)#ip address 12.1.1.2 255.255.255.0
naxxr2(config-if)#no sh
naxxr2(config-if)#exi
naxxr2(config)#ip route 0.0.0.0 0.0.0.0 12.1.1.1
naxxr2(config)#end
naxxr2#ping 13.1.1.3
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 13.1.1.3, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 4/7/8 ms
naxxr2#
NAXXR3:
Router>en
Router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#hostname naxxr3
naxxr3(config)#interface serial 0
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
naxxr3(config-if)#no shutdown
naxxr3(config-if)#
naxxr3(config-if)#ip add 13.1.1.3 255.255.255.0
naxxr3(config-if)#exit
naxxr3(config)#ip route 0.0.0.0 0.0.0.0 13.1.1.1
naxxr3(config)#end
naxxr3#ping 12.1.1.2
LAB 15 - NAT/PAT
1. In this lab, you will configure NAT/PAT function 在 naxxr1. You will configure three forms
of translation: static network address translation, dynamic translation, and overloading
(port address translation). Remember to disable the access lists your configured in the
previous lab before continuing this lab.
2.在 naxxr1, configure NAT to statically translate naxxr2’s Ethernet address 220.1.1.2 to
169.10.1.2.
naxxr1(config)# ip nat inside source static 220.1.1.2 169.10.1.2
naxxr1(config)# interface ethernet0
naxxr1(config-if)# ip address 160.10.1.1 255.255.255.0
naxxr1(config-if)# ip nat inside
naxxr1(config-if)# interface
serial0
naxxr1(config-if)# ip address 12.1.1.1 255.255.255.0
naxxr1(config-if)# ip nat
outside naxxr1(config-if)# no
shut
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
3. Test the static NAT translation by Telnet’ing from naxxr2 to naxxr3. Once into
naxxr3, issue the show users command. The output of this command should show that
169.10.1.2 (the translated IP address) is the logged-in device.
naxxr2# telnet 175.10.1.2
naxxr3# show users
4. Display the NAT Translation table 在 naxxr1. The output of the display should show that the
inside local IP address (220.1.1.2) is translated to the inside global IP address (169.10.1.2).
问题 A: does the “inside global IP address”normally represent a public or a private IP
address?
naxxr1# show ip nat translations
5.在 naxxr1, remove the previous static NAT commands and configure NAT to translate
naxxr2’s Ethernet address to a dynamically assigned address. You will utilize a pool of public
addresses in the range of 169.10.1.50 to 169.10.1.100.
问题 A: if the pool of dynamically assigned addresses only contains one IP address
entry, what’s another term for this form of NAT translation?
naxxr1(config)# no ip nat inside source static 220.1.1.2 169.10.1.2
naxxr1(config)# ip nat pool pool1 169.10.1.50 169.10.1.100 netmask 255.255.255.0
naxxr1(config)# ip nat inside source list 1 pool pool1
naxxr1(config)# access-list 1 permit 160.10.1.0 0.0.0.255
6. Test the dynamic NAT translation function by Telnet’ing from naxxr2 to naxxr3. Once into
naxxr3, issue the show users command. The output of this command should show that the
logged-in device is 169.10.1.50 (the translated address). Also, display the NAT translation table
在 naxxr1 using the show ip nat translations command.
naxxr2# telnet 175.10.1.2
naxxr3# show users
naxxr1# show ip nat translations
7. Remove the previous NAT commands. Configure NAT overloading (port address translation)
在 naxxr1 to translate naxxr2’s Ethernet address
(220.1.1.2) to the serial0 interface address (12.1.1.1)在 naxxr1.
naxxr1(config)# ip nat inside source list 1 interface serial0 overload
naxxr1(config)# interface Ethernet 0
naxxr1(config-if)# ip address 160.10.1.1 255.255.255.0
naxxr1(config-if)# ip nat inside
naxxr1(config-if)# interface serial
0
naxxr1(config-if)# ip address 12.1.1.1 255.255.255.0
naxxr1(config-if)# ip nat
outside naxxr1(config-if)# exit
naxxr1(config)# access-list 1 permit 160.10.1.0 0.0.0.255
8. Test the overloading (PAT) function by Telnet’ing from naxxr2 to naxxr3. Issue the show
users command 在 naxxr3. It should show that the logged-in device is 12.1.1.1 (the translated IP
address). Also, issue the show ip nat translations command 在 naxxr1 to display the NAT
translation table.
naxxr2# telnet
175.10.1.2 naxxr3#
show users
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
12.1.1.1
12.1.1.2
NAXXR1 NAXXR2
DDN
1. 做好最基本配置,先检查原来接口的封装方式.
Naxxr1:
naxxr1#conf t
naxxr1(config)#int s0
naxxr1(config-if)#no sh
naxxr1(config-if)#ip add 12.1.1.1 255.255.255.0
naxxr1(config-if)#clock r 4000000
naxxr1(config-if)#exi
naxxr1(config)#int s1
naxxr1(config-if)#ip add 13.1.1.1 255.255.255.0
naxxr1(config-if)#no sh
naxxr1(config-if)#clock r 4000000
naxxr1(config-if)#end
naxxr2:
naxxr2>en
naxxr2#conf t
naxxr2(config)#hostname naxxr2
naxxr2(config)#int s0
naxxr2(config-if)#ip address 12.1.1.2 255.255.255.0
naxxr2(config-if)#no sh
naxxr2(config-if)#exi
naxxr2(config)#end
naxxr1# show interfaces serial 0
2.在 naxxr1 和 naxxr2 上配置 PPP 封装.
Naxxr1(config)# interface serial0
naxxr1(config-if)# encapsulation
ppp Naxxr2(config)# interface
serial0 naxxr2(config-if)#
encapsulation ppp
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
3.检查接口的封装方式
routerx# show interfaces serial 0 !看到 PPP 了吗?
naxxr1# ping 12.1.1.2
4. 配置 CHAP.
naxxr1(config)# username naxxr2 password
cisco naxxr1(config)# interface serial 0
naxxr1(config-if)# ppp authentication chap
naxxr2(config)# username naxxr1 password
cisco naxxr2(config)# interface serial 0
naxxr2(config-if)# ppp authentication chap
5.检查接口状态.
Naxxr1# show interfaces serial0
naxxr1# ping 12.1.1.2
6.监视认证过程.
Naxxr1(config)#interface serial 0
Naxxr1(config-if)#shutdown
Naxxr1#debug ppp
authentication Naxxr1(config-
if)#no sh 现在应该看到 PPP 认证
的过程 .
ISDN 参数
Router IP Mask SPID1 Local ISDN Switch
Address Tel#
Na11r1 10.1.1.1 /24 2209476 basic-net3
Na11r2 10.1.1.2 /24 2212406 basic-net3
1. 配置过程
naxxr1(config)# isdn switch-type basic-net3
naxxr1(config)# dialer-list 1 protocol ip permit
naxxr1(config)# username naxxr2 password cisco
naxxr1(config)# interface bri0
naxxr1(config-if)# encap ppp
naxxr1(config-if)# ip address 10.1.1.1 255.255.255.0
naxxr1(config-if)# dialer-group 1
naxxr1(config-if)# dialer map ip 10.1.1.2 name naxxr2 broadcast 2212406
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
1. In this lab, you will configure ISDN BRI 在 naxxr1 and naxxr2 using dialer profiles.
With dialer profiles, you are effectively moving some of the logical ISDN parameters from the
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
physical BRI/PRI interface to a dialer interface. Any IP packet should represent ‘interesting
traffic’in this lab and either router should be able to initiate the call. PPP encapsulation and
CHAP authentication should be used. Refer to the table above for ISDN switch-type, IP
addresses, subnet masks, and telephone numbers.
naxxr1(config)# isdn switch-type basic-net3
naxxr1(config)# dialer-list 1 protocol ip permit
naxxr1(config)# username naxxr2 password cisco
naxxr1(config)# interface bri0
naxxr1(config-if)# encap ppp
naxxr1(config-if)# ppp authentication chap
naxxr1(config-if)# isdn spid1
32122094760100 naxxr1(config-if)# dialer
pool-member 1 naxxr1(config-if)# no shut
naxxr1(config-if)# interface dialer 1
naxxr1(config-if)# no shut
naxxr1(config-if)# ip address 10.1.1.1 255.255.255.0
naxxr1(config-if)# encap ppp
naxxr1(config-if)# dialer-group
1 naxxr1(config-if)# dialer pool
1
naxxr1(config-if)# dialer remote-name naxxr2
naxxr1(config-if)# dialer string 7782002
naxxr1(config-if)# ppp authentication chap
naxxr2(config)# isdn switch-type basic-net3
naxxr2(config)# dialer-list 1 protocol ip permit
naxxr2(config)# username naxxr1 password cisco
naxxr2(config)# interface bri0/0
naxxr2(config-if)# encap ppp
naxxr2(config-if)# ppp authentication chap
naxxr2(config-if)# isdn spid1
32177820020100 naxxr2(config-if)# dialer
pool-member 1 naxxr2(config-if)# no shut
naxxr2(config-if)# interface dialer 1
naxxr2(config-if)# no shut
naxxr2(config-if)# ip address 10.1.1.2 255.255.255.0
naxxr2(config-if)# encap ppp
naxxr2(config-if)# dialer-group
1 naxxr2(config-if)# dialer pool
1
naxxr2(config-if)# dialer remote-name
naxxr1 naxxr2(config-if)# dialer string
2209476 naxxr2(config-if)# ppp
authentication chap
2. Issue the show isdn status command on both naxxr1 and naxxr2. You should see:
Layer1: Active
Layer2: Multiple Frame Established with spid1 valid.
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com
1. In this lab, you will configure ISDN BRI 在 naxxr1 and ISDN PRI 在 naxxr2 using dialer
profiles. Naxxr2 has a primary rate ISDN interface (S0) as well as a basic rate ISDN
interface. Any IP packet should represent ‘interesting traffic’in this lab and either
router should be able to initiate the call. PPP encapsulation and CHAP authentication
should be used. Refer to the table above for ISDN switch-type, IP addresses, subnet
masks, and telephone numbers.
问题 A: if this PRI was being configured in Europe, what would the options be for controller
type, framing, and linecode?
问题 B: On the PRI interface statement, what is the significance of :23
naxxr1(config)# isdn switch-type basic-net3
naxxr1(config)# dialer-list 1 protocol ip permit
naxxr1(config)# username naxxr2 password cisco
naxxr1(config)# interface bri0/0
naxxr1(config-if)# encap ppp
naxxr1(config-if)# ppp authentication chap
naxxr1(config-if)# isdn spid1
32122094760100
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
HTTP://WWW.WISDOMINFO.COM
5. Issue the show interfaces bri0 1 2 command 在 naxxr1. This shows the status of the B
channels (data channels). One of the B channels should
have a status of ‘UP and UP’indicating a successful call is in progress.
naxxr1# show interfaces bri0 1 2
DLCI=102
R1 DLCI=201
帧中继交换机
R2
12.1.1.1 12.1.1.2
实验拓扑
1. 配置帧中继交换机
Router(config)#hostname frsw !命名主机名
Frsw(config)#frame-relay switching !启用帧中继交换功能
!
Frsw(config)#interface Serial0
Frsw(config-if)# no ip address
Frsw(config-if)# no shutdown
Frsw(config-if)# encapsulation frame-relay
Frsw(config-if)# clock rate 4000000
Frsw(config-if)# frame-relay intf-type dce
Frsw(config-if)# frame-relay route 102 interface serial1 201
Frsw(config-if)# frame-relay lmi-type ansi
2.
问题 A: what is the default lmi-type on Cisco routers?
naxxr1(config)# interface serial0
naxxr1(config-if)# encapsulation frame-relay
地址:广西省南宁市火炬路金达花园8 栋101 室
电话::
(0771)-2655215 3832816
广西思科认证培训中心
http://www.GXcisco.com