路由器(1)
int f0/0
ip add 17.1.1.1 255.255.255.252
int f0/1
ip add 17.1.1.5 255.255.255.252
int f0/2
ip add 99.9.9.1 255.255.255.0
router ospf 100
network 17.1.1.0 255.255.255.252 area 0
network 17.1.1.4 255.255.255.252 area 0
exit
int range f0/0 -1
ip nat inside
int f0/2
ip nat outside
ip access-list standard 10
permit 172.1.1.0 0.0.0.255
permit 172.1.2.0 0.0.0.255
ip access-list standard 11
permit 172.1.3.0 0.0.0.255
permit 172.1.4.0 0.0.0.255
ip nat pool pool1 99.1.1.3 99.1.1.5 netmask 255.255.255.240
ip nat pool pool2 99.1.1.6 99.1.1.8 netmask 255.255.255.240
ip nat inside source list 10 pool pool1 overload
ip nat inside source list 11 pool pool2 overload
time-range aa
periodic weekdays 09:00 to 18:00
exit
access-list 20 permit 172.1.1.0 0.0.0.255 time-range aa
access-list 20 permit 172.1.2.0 0.0.0.255 time-range aa
access-list 20 permit 172.1.3.0 0.0.0.255 time-range aa
access-list 20 permit 172.1.4.0 0.0.0.255
access-list 20 permit 17.1.1.0 0.0.0.3
access-list 20 permit 17.1.1.4 0.0.0.3
int f0/0
ip access-group 20 in
int f0/1
ip access-group 20 in
交换机(1)
int f0/1
no swi
ip add 17.1.1.2 255.255.255.252
no shut
vlan 10
vlan 20
vlan 30
vlan 40
int vlan 10
ip add 172.1.1.1 255.255.255.0
no shut
int vlan 20
ip add 172.1.2.1 255.255.255.0
no shut
int vlan 30
ip add 172.1.3.1 255.255.255.0
no shut
int vlan 40
ip add 172.1.4.1 255.255.255.0
no shut
router ospf 100
network 17.1.1.0 255.255.255.252 area 0
network 172.1.1.0 255.255.255.0 area 0
network 172.1.2.0 255.255.255.0 area 0
network 172.1.3.0 255.255.255.0 area 0
network 172.1.4.0 255.255.255.0 area 0
spanning-tree mst configuration
revision 1
name 11
instance 0 vlan 1-9
instance 10 vlan 10,20
instance 20 vlan 30,40
spannig-tree mst 10 priority 4096
spannin-tree mst 20 priority 8192
int range f0/21 -22
port-group 1
int range f0/23 -24
port-group 3
int agg 1
swi mode trunk
int agg 3
swi mode trunk
int vlan 10
vrrp 10 priority 120
vrrp 10 ip 172.1.1.254
int vlan 20
vrrp 20 priority 120
vrrp 20 ip 172.1.2.254
int vlan 30
vrrp 30 ip 172.1.3.254
int vlan 40
vrrp 40 ip 172.1.4.254
access-list 120 deny ip 172.1.1.0 0.0.0.255 172.1.2.0 0.0.0.255
access-list 120 permit ip any any
int vlan 10
ip access-group 120 in
交换机(2)
int f0/1
no swi
ip add 17.1.1.6 255.255.255.252
no shut
vlan 10
vlan 20
vlan 30
vlan 40
int vlan 10
ip add 172.1.1.2 255.255.255.0
no shut
int vlan 20
ip add 172.1.2.2 255.255.255.0
no shut
int vlan 30
ip add 172.1.3.2 255.255.255.0
no shut
int vlan 40
ip add 172.1.4.2 255.255.255.0
no shut
spanning mst configuration
revision 1
name 11
instance 0 vlan 1-9
instance 10 vlan 10,20
instance 20 vlan 30,40
spanning mst 10 priority 8192
spanning mst 20 priority 4096
router ospf 100
network 17.1.1.4 255.255.255.252 area 0
network 172.1.1.0 255.255.255.0 area 0
network 172.1.2.0 255.255.255.0 area 0
network 172.1.3.0 255.255.255.0 area 0
network 172.1.4.0 255.255.255.0 area 0
int range f0/21 -22
port-group 2
int range f0/23 -24
port-group 3
int agg 2
swi mode trunk
int agg 3
swi mode trunk
int vlan 10
vrrp 10 ip 172.1.1.254
int vlan 20
vrrp 20 ip 172.1.2.254
int vlan 30
vrrp 30 priority 120
vrrp 30 ip 172.1.3.254
int vlan 40
vrrp 40 priority 120
vrrp 40 ip 172.1.4.254
access-list 120 deny ip 172.1.1.0 0.0.0.255 172.1.2.0 0.0.0.255
access-list 120 permit ip any any
int vlan 10
ip access-group 120 in
交换机(3)
vlan 10
vlan 20
vlan 30
vlan 40
spanning mst configuration
revision 1
name 11
instance 0 vlan 1-9
instance 10 vlan 10,20
instance 20 vlan 30,40
int range f0/21 -22
port-group 1
int range f0/23 -24
port-group 2
int agg 1
swi mode trunk
int agg 2
swi mode trunk
int range f0/1 -5
swi acc vlan 10
int range f0/6 -10
swi acc vlan 20
int range f0/11 -15
swi acc vlan 30
int range f0/16 -20
swi acc vlan 40
interface range f0/5 -24
switchport port-security
switchport port-security maximum 2
switchport port-security rioiation shutdown
可以根据ISP商提供给你的IP做一个NAT,其 中一台路由器只连接到服务器,另一台路由器连接PC。
外网光猫下来的ETH口接到一台路由1上,然后把路由1的一个LAN接到另外一台接有服务器的路由2上。路由2这时做一个静态的NAT(因为有两台服务器,要消耗2个外网IP),路由1的另一个LAN接交换机,交换机下接四台PC。把接交换机的路由1上的那个端口用剩下的IP做一个PNT(端口复用)。PC的IP可以做一个子网,用192IP段。
当然,还有多种组网方法,这只是其中一种,抛砖引玉,希望看到更好的方式。
看你的具体要求,如果只是简单的文件共享,那只需要用到:一个路由品,一个交换机,六台电脑。
如果上面存在一个文件服务器,或WEB服务器,配置也不同,看你主要实现什么功能。
没有型号、规格、功能要求等,无法配置,要到现场,见实物。