Professional Documents
Culture Documents
Cn b hng dn:
inh Trng Th
V Thng
MSSV: 1091629
LI CM N
hon thnh hc phn thc tp thc t ny, em xin chn thnh cm n trung tm
Athena to iu kin cho em c mt mi trng thch hp lm vic.
Xin chn thnh cm n thy V Thng, Gim c trung tm Qun tr mng v
An ninh mng quc t Athena tn tnh hng dn, gip em trong thi gian thc tp
va qua.
Trong thi gian hc tp ti trng i hc Cn Th, em tch ly c nhiu
kin thc qu bo, cng l nh cng dy d tn tnh ca thy c trng i hc Cn
Th ni chung v thy c ti khoa Cng ngh thng tin & Truyn thng trng i hc
Cn Th.
Ngoi ra, trong qu trnh thc tp nh c s ng vin gip ca cc bn sinh
vin cng thc tp ti trung tm, cc anh ch nhn vin trong cng ty nhit tnh gip
nn em mi hon thnh c chng trnh thc tp ny.
Xin cm n gia nh, cha m ng h v mt tinh thn.
Mt ln na em xin chn thnh cm n v xin gi li chc sc khe n ton th
cn b, nhn vin ti trung tm Athena. Chc cho cng ty gt hi c nhiu thnh cng.
Chn thnh cm n.
TP H Ch Minh, Ngy 01/07/2013
inh Trng Th
NHN XT CA CN B HNG DN
..................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
.............................................................................................................................................
TP. H Ch Minh, ngythng nm 2013
V Thng
MC LC
LI CM N........................................................................................................... 2
NHN XT CA CN B HNG DN ........................................................... 3
MC LC ................................................................................................................ 4
Chng I. TM HIU V ROUTER ..................................................................... 5
I.
Gii thiu chung .......................................................................................... 5
II. Chc nng chnh ca Router ........................................................................ 5
III. Nguyn tc chn ng ............................................................................... 5
IV. Cc thnh phn phn cng ........................................................................... 6
V. Phn loi: ..................................................................................................... 7
Chng II. C ch o ha Router Cisco trn GNS3 ............................................. 8
I.
Gii thiu ..................................................................................................... 8
II. Ci t GNS3 ............................................................................................... 9
Chng III. L THUYT GII THUT NH TUYN .................................. 14
I.
Chc nng ca gii thut nh tuyn ......................................................... 14
II. i lng o lng (Metric): .................................................................... 14
III. Mc tiu thit k ........................................................................................ 14
IV. Phn loi gii thut chn ng ................................................................ 14
V. Gii thut vch ng theo kiu trng thi ni kt Link state ................ 15
VI. Gii thut chn ng theo kiu vect khong cch ................................. 15
Chng IV. CU HNH NH TUYN CHO ROUTER CISCO ..................... 15
I.
Cc mode lm vic ca Router Mode config.......................................... 15
II. Cc lnh c bn trn Router ...................................................................... 17
III. Cu hnh nh tuyn tnh............................................................................ 19
IV. Cu hnh nh tuyn RIP - Routing Information Protocol ........................ 20
V. Cu hnh nh tuyn OSPF ........................................................................ 23
VI. Filter Router - Access List ......................................................................... 28
VII. Load balancing ....................................................................................... 31
VIII. Cu hnh VPN Client to Site .................................................................. 33
Chng V. Cu hnh VPCS m phng PC n gin ..................................... 35
TM HIU V ROUTER
I. Gii thiu chung
Router, hay thit b nh tuyn hoc b nh tuyn, l mt thit b lin mng, c
chc nng t tng 1 n tng 3 trong m hnh OSI, dng chuyn cc gi d liu qua
mt lin mng v n cc u cui, thng qua mt tin trnh c gi l nh tuyn. nh
tuyn xy ra tng 3 tng mng ca m hnh OSI 7 tng. Router cho php ni hai hay
nhiu nhnh mng li vi nhau to thnh mt lin mng. Chuyn tip cc gi tin t
mng ny n mng kia c th n c my nhn. Mi mt router thng tham gia
vo t nht l 2 mng. N c th l mt thit b chuyn dng hoc c th l mt my tnh
vi nhiu card mng v mt phn mm ci t gii thut chn ng cho router.
V. Phn loi:
Router c nhiu cch phn loi khc nhau Tuy nhin ngi ta thng c hai cch
phn loi ch yu sau:
Da theo cng dng ca Router: theo cch phn loi ny ngi ta chia
router thnh remote access router, ISDN router, Serial router, router/hub
Da theo cu trc ca router: fixed configuration router, modular router.
II. Ci t GNS3
Ti phn mm v t a ch: http://www.gns3.net/download/. Hin ti phin bn
y l GNS3 v0.8.3.1 all-in-one
Kch p vo file va download v v tin hnh ci t theo ch mc nh
Nhn next
Nhn I Agree
Nhn Next
Nhn Next
Nhn next
Cc mode cu hnh:
Exec mode: Router> y l mode u tin khi bn bt u mt phin lm
vic vi router (qua Console hay Telnet). mode ny bn ch c th thc
hin c mt s lnh thng thng ca router. Cc lnh ny s khng
c ghi vo file cu hnh ca router v do khng gy nh hng n
cc ln khi ng sau ca router.
Privileged exec mode: Router# Privileged EXEC Mode cung cp cc lnh
quan trng theo di hot ng ca router, truy cp vo cc file cu hnh,
IOS, t password... Privileged EXEC Mode l cha kha vo
Configuration Mode.
Configuration mode: Router(config)# Configuration mode cho php cu
hnh tt c cc chc nng ca Cisco router bao gm cc interface, cc
routing protocol, cc line console, vty (telnet), tty (async connection). Cc
lnh trong configuration mode s nh hng trc tip n cu hnh hin
hnh ca router cha trong RAM (running-configuration). Nu cu hnh
ny c ghi li vo NVRAM, cc lnh ny s c tc dng trong nhng ln
khi ng sau ca router. Configuration mode c nhiu mode nh, ngoi
cng l global configuration mode, sau l cc interface configuration
mode, line configuration mode.
Ngay sau khi nhn phm Enter thc thi cu lnh, du nhc s i t tn mc
nh (Router) sang tn va mi t.
2. Cu hnh t mt khu cho Router
t mt khu cho ng console:
AthenaR1(config)#line console 0
AthenaR1(config-line)#password <<password>>
AthenaR1(config-line)#login
Router#show ARP
Cu hnh
Trn Router R1, vo mode cofig v cu hnh nh sau :
R1#configuture terminal
R1(config)#ip route 11.0.0.0 255.255.255.0 Serial0/0
c lng ging lan truyn tip cho cc lng ging khc v c th lan truyn ra mi router
trn ton mng. Kiu trao i thng tin nh th cn c gi l lan truyn theo tin n.
( y, ta c th hiu router lng ging l router kt ni trc tip vi router ang xt).
Metric trong RIP c tnh theo hop count s node lp 3 (router) phi i qua
trn ng i n ch. Vi RIP, gi tr metric ti a l 15, gi tr metric = 16 c
gi l infinity metric (metric v hn), c ngha l mt mng ch c php cch ngun
tin 15 router l ti a, nu n cch ngun tin t 16 router tr ln, n khng th nhn c
ngun tin ny v c ngun tin xem l khng th i n c.
RIP chy trn nn UDP port 520.
RIPv2 l mt giao thc classless cn RIPv1 li l mt giao thc classful.
Cch hot ng ca RIP c th dn n loop nn mt s quy tc chng loop v
mt s timer c a ra. Cc quy tc v cc timer ny c th lm gim tc hi t ca
RIP.
AD ca RIP l 120.
3. Demo RIPv1
Topology
Cu hnh
Cc Router v PC t IP nh hnh trn.
Trn router R1, ta vo mode config v cu hnh nh sau:
R1#configure terminal
R1(config)#router rip
R1(config-router)#net 10.0.0.0
R1(config-router)#net 192.168.1.0
R1(config-router)#exit
R1(config)#
4. Demo RIPv2
Topology
Cu hnh
Sau khi cu hnh cc Interface cho cc Router ta tin hnh nh tuyn cho cc
Router.
Router R2
R2(config)#router rip
R2(config-router)#version 2
R2(config-router)#net 192.168.1.0
R2(config-router)#net 192.168.2.0
R2(config-router)#exit
Router R3
R3(config)#router rip
R3(config-router)#net 172.16.20.0
R3(config-router)#net 172.16.30.0
R3(config-router)#net 192.168.2.0
R3(config-router)#exit
R3(config)#
khi ng v khi h thng mng c s thay i. Chng khng pht qung b bng nh
tuyn theo nh k nh cc router nh tuyn theo distance vector. Do , cc router nh
tuyn theo trng thi ng lin kt s dng t bng thng hn cho hot ng duy tr
bng nh tuyn.
RIP ph hp vi cc mng nh v ng tt nht i vi RIP l ng c s hop
t nht. OSPF th ph hp vi mng ln, c kh nng m rng, ng i tt nht ca
OSPF c xc nh da trn tc ca ng truyn. RIP cng nh cc giao thc nh
tuyn theo distance vector khc u s dng thut ton chn ng n gin. Cn thut
ton SPF th phc tp. Do , nu router chy theo giao thc nh tuyn theo distance
vector th s t tn b nh v cn nng lc x l thp hn so vi khi chy OSPF.
OSPF chn ng da trn chi ph c tnh t tc ca ng truyn. ng
truyn c tc cng cao th chi ph OSPF tng ng cng thp.
OSPF chn ng tt nht t cy SPF.
OSPF bo m khng b nh tuyn lp vng. Cn giao thc nh tuyn theo
distance vector vn c th b loop.
Nu mt kt ni khng n nh, chp chn, vic pht lin tc cc thng tin v
trng thi ca ng kin kt ny s dn n tnh trng cc thng tin qung co khng
ng b lm cho kt qu chn ng ca cc router b o ln.
3. OSPF gii quyt c cc vn sau
-Tc hi t.
-H tr VLSM (Variable Length Subnet Mask).
-Kch c mng.
-Chn ng.
-Nhm cc thnh vin.
Trong mt h thng mng ln, RIP phi mt t nht vi pht mi c th hi t
c v mi router ch trao i bng nh tuyn vi cc router lng ging kt ni trc tip
vi mnh m thi. Cn i vi OSPF sau khi hi t vo lc khi ng, khi c thay i
th vic hi t s rt nhanh v ch c thng tin v s thay i c pht ra cho mi router
trong vng.
Gi hello mang nhng thng tin thng nht gia mi lng ging vi nhau trc
khi c th thit lp mi quan h lng ging thn mt v trao i thng tin v trng thi
ng lin kt.
Trn router R2 :
R2(config)#router ospf 1
R2(config-router)#network 192.168.1.0 0.0.0.255 area 0
R2(config-router)#network 192.168.2.0 0.0.0.255 area 0
R2(config-router)#network 172.16.2.0 0.0.0.255 area 0
R2(config-router)#exit
Router R3
R3(config)#router ospf 1
R3(config-router)#network 192.168.2.0 0.0.0.255 area 0
R3(config-router)#network 172.16.3.0 0.0.0.255 area 0
R3(config-router)#exit
R3(config)#
gi tin s c cp php hay b t chi. Ch cho php mt danh sch trn mt giao thc
trn mt giao din.
VII.
Load balancing
Gii thiu
Cn bng ti l mt chc nng tiu chun trong cc phn mm nh tuyn ca
Cisco v c th tn ti trn hu ht cc router ca cc nh sn xut khc. Cn bng ti gn
lin vi qu trnh vn chuyn trong cc router v c t ng kch hot nu bng nh
tuyn c nhiu nh tuyn n mt mc tiu. Cn bng ti c c s l cc giao thc nh
tuyn chun nh RIP, RIP V2 (Routing Information Protocol), OSPF (Open Shortest Path
First), IGRP (Interior Gateway Routing Protocol), EIGRP (Enhanced Interior Gateway
Routing Protocol); hoc t cc nh tuyn tnh v cc c ch vn chuyn gi tin. C ch
cn bng ti cho php mt router s dng nhiu nh tuyn n mt mc tiu khi vn
chuyn cc gi tin.
Khi mt router nhn bit nhiu nh tuyn n mt lp mng thng qua cc qu
trnh x l a nh tuyn (hoc cc giao thc nh tuyn nh RIP, RIPv2, IGRP, EIGRP
v OSPF), n s ghi nh tuyn c gi tr administrative distance thp nht vo bng nh
tuyn.
i khi cc router phi chn mt trong s nhiu nh tuyn c cng gi tr
administrative distance. Trong trng hp ny, cc router s chn nh tuyn c cost
hoc metric thp nht n mc tiu. Mi qu trnh nh tuyn c c ch xc nh cost
khc nhau. i khi, gi tr cost cn c iu chnh t cn bng ti.
Cn bng ti kh thi khi ng vi mt mc tiu, router cung cp nhiu ng dn
c cng gi tr administrative distance v cost. S lng ng dn kh dng b gii hn
bi s mc m cc giao thc nh tuyn ghi vo bng nh tuyn. S lng mc nh
trong h thng xut nhp (IOS-Input Output System) ca hu ht giao thc nh tuyn l
VIII.
1. VPN l g?
VPN (virtual private network) l cng ngh xy dng h thng mng ring o
nhm p ng nhu cu chia s thng tin, truy cp t xa v tit kim chi ph. Trc y,
truy cp t xa vo h thng mng, ngi ta thng s dng phng thc Remote
Access quay s da trn mng in thoi. Phng thc ny va tn km va khng an
ton. VPN cho php cc my tnh truyn thng vi nhau thng qua mt mi trng chia
s nh mng Internet nhng vn m bo c tnh ring t v bo mt d liu. cung
cp kt ni gia cc my tnh, cc gi thng tin c bao bc bng mt header c cha
nhng thng tin nh tuyn, cho php d liu c th gi t my truyn qua mi trng
mng chia s v n c my nhn, nh truyn trn cc ng ng ring c gi l
tunnel. bo m tnh ring t v bo mt trn mi trng chia s ny, cc gi tin c
m ho v ch c th gii m vi nhng kha thch hp, ngn nga trng hp "trm" gi
tin trn ng truyn.
2. Cc tnh hung thng dng ca VPN:
- Remote Access: p ng nhu cu truy cp d liu v ng dng cho ngi dng
xa, bn ngoi cng ty thng qua Internet. V d khi ngi dng mun truy cp vo c
s d liu hay cc file server, gi nhn email t cc mail server ni b ca cng ty.
- Site To Site: p dng cho cc t chc c nhiu vn phng chi nhnh, gia cc
vn phng cn trao i d liu vi nhau. V d mt cng ty a quc gia c nhu cu chia
s thng tin gia cc chi nhnh t ti Singapore v Vit Nam, c th xy dng mt h
thng VPN Site-to-Site kt ni hai site Vit Nam v Singapore to mt ng truyn
ring trn mng Internet phc v qu trnh truyn thng an ton, hiu qu.
- Intranet/ Internal VPN: Trong mt s t chc, qu trnh truyn d liu gia mt
s b phn cn bo m tnh ring t, khng cho php nhng b phn khc truy cp. H
thng Intranet VPN c th p ng tnh hung ny.
5. TUNNELING
Tunneling l k thut s dng mt h thng mng trung gian (thng l mng
Internet) truyn d liu t mng my tnh ny n mt mng my tnh khc nhng vn
duy tr c tnh ring t v ton vn d liu. D liu truyn sau khi c chia nh thnh
nhng frame hay packet (gi tin) theo cc giao thc truyn thng s c bc thm 1 lp
header cha nhng thng tin nh tuyn gip cc packet c th truyn qua cc h thng
mng trung gian theo nhng ng ring (tunnel). Khi packet c truyn n ch,
chng c tch lp header v chuyn n cc my trm cui cng cn nhn d liu.
thit lp kt ni tunnel, my client v server phi s dng chung mt giao thc (tunnel
protocol).
- PPTP (Point-to-Point Tunneling Protocol): PPTP c th s dng cho Remote
Access hay Site-to-Site VPN. Nhng thun li khi p dng PPTP cho VPN l khng yu
cu certificate cho qu trnh chng thc v client c th t pha sau NAT Router.
- L2TP ( Layer 2 Tunneling Protocol): L2TP l s kt hp ca PPTP v Layer 2
Forwading (L2F, giao thc c pht trin bi Cisco System). So vi PPTP th L2TP c
nhiu c tnh mnh v an ton hn.
Trn h thng Microsoft, L2TP c kt hp vi IPSec Encapsulating Security
Payload (ESP) cho qu trnh m ha d liu, gi l L2TP/IPSec. S kt hp ny khng
ch cho php chng thc i vi ngi dng PPTP m cn cho php chng thc i vi
cc my tnh thng qua cc chng ch, nng cao hn an ton ca d liu khi truyn, v
qu trnh tunnel c th din ra trn nhiu h thng mng khc nhau. Tuy nhin trong mi
trng L2TP/IPSec cc VPN Client khng th t pha sau NAT Router. Trong trng
hp ny chng ta cn phi c VPN Server v VPN Client h tr IPSec NAT-T.
Tip tc, trong phn System variables tm n mc Path, nhn p hoc chn
Edit.. thm ng dn n th mc VPCS vo y bng cch thm ; vo pha sau
cc ng dn trc , ri t ng dn C:\Program Files\GNS3\vpcs vo pha sau
; .