Environment Introduction Three floor 12 floor 4 Two layer switch, 4 cameras, 2 wireless APs, one access 11 floor one router, one three layer switch, four two layer switch, 4 cameras, 2 wireless APs, one access control, 4 servers, two fiber switches, one SAN storage, one Internet behavior management, 10 Floor 4 x Two layer switch, 4 cameras, 2 wireless APs, one access Note: Server LENOVO thinkserver RD440 router Huawei S5700 v200r003c00spc300 switch Huawei S5700 v200r003c00spc300 24 Gigabit Ethernet Interface
Objective to ensure the automatic acquisition of IP address, and to achieve broadcast isolation, internal and external network can communicate
Network planning
1. Network topology
2. Network Segment Division
Floor network Segment (VLAN12) ip:192.168.12.0/24Floor Network Segment (a)VLAN11 ip:192.168.11.0/24Floor Network Segment (a)VLAN10 ip:192.168.10.0/24
Server network SegmentVLAN18 ip:192.168.18.0/24
Virtual Desktop Segment VLAN16 ip:192.168.16.0/24
Network Device segment VLAN8 IP:192.168.8.0/24
Router segment VLAN6 IP:192.168.6.0/24
Wireless VLAN11 IP:192.168.9.0/24
each network segment gateway is 192.168.*.254
The 23,24 of the first switch on each layer is configured for wireless access mode, 19,20,21,22 for the camera for access mode, and the first interface for each switch is configured as a cascade
Vlan1 as the management interface for each switch
3. Network Configuration
Router configuration
==================================================================================
Three-layer switch configuration Basic User Configuration <>sys[]sysname hx-switch[hx-switch]user-interface vty 0 4
[Hx-switch-vty0-4]authencation-mode AAA[Hx-switch-vty0-4]aaa[Hx-switch-AAA][Hx-switch-AAA]local-user pxtadmin password cipher xxx[Hx-switch-AAA]local-user pxtadmin Privilege Level 5[Hx-switch-AAA]local-user pxtadmin service-type telnet terminal ssh http[Hx-switch-aaa]quit[Hx-switch]telnet Server enable Telnet service
IP Management[Hx-switch]Interface VLANF 1
[Hx-switch]IP address 192.168.16.253 255.255.255.0
Partitioning and configuring VLAN gateways and opening dhcp[Hx-switch]interface Vlanif6
IP address 192.168.6.254 255.255.255.0 DHCP Select interface DHCP server Excluded-ip -address 192.168.6.180 192.168.6.253 DHCP server dns-list 192.168.8.1 192.168.18.2
[Hx-switch]interface Vlanif8
IP address 192.168.8.254 255.255.255.0DHCP Select interfaceDHCP server excluded-ip-address 192.168.8.1 192.168.8.100DHCP server excluded-ip-address 192.168.8.180 192.168.8.254DHCP server dns-list 192.168.8.1 192.168.18.2
[Hx-switch]interface vlanif9
IP address 192.168.9.254 255.255.255.0 DHCP Select interface DHCP server Excluded-ip -address 192.168.9.1240 192.168.9.254 DHCP server dns-list 192.168.8.1 192.168.18.2
[Hx-switch]interface VLANIF10
IP address 192.168.6.254 255.255.255.0 DHCP Select interface DHCP server Excluded-ip -address 192.168.10.240 192.168.10.253 DHCP server dns-list 192.168.8.1 192.168.18.2
[Hx-switch]interface vlanif11
IP address 192.168.11.254 255.255.255.0 DHCP Select interface DHCP server excluded-i P-address 192.168.11.240 192.168.11.248DHCP server excluded-ip-address 192.168.11.250 192.168.11.253DHCP server dns-list 192.168.8.1 192.168.18.2
[Hx-switch]interface vlanif12
IP address 192.168.12.254 255.255.255.0 DHCP Select interface DHCP server excluded-i P-address 192.168.12.240 192.168.12.248DHCP server excluded-ip-address 192.168.12.250 192.168.12.253DHCP server dns-list 192.168.8.1 192.168.18.2
[Hx-switch]interface vlanif18
IP address 192.168.18.254 255.255.255.0 [Hx-switch]interface vlanif110
IP address 192.168.110.254 255.255.255.0 DHCP Select interface DHCP server excluded- Ip-address 192.168.110.240 192.168.110.248DHCP server excluded-ip-address 192.168.110.250 192.168.6.253DHCP server dns-list 202.96.134.133 8.8.8.8
Interface METH0/0/1
Interface Configuration Interface Gigabitehternet0/0/1port link-type accessport default VLAN 6
Interface GIGABITEHTERNET0/0/2Port link-type trunkport trunk allow-pass VLAN 2 to 4094
Interface GIGABITEHTERNET0/0/3Port link-type trunkport trunk allow-pass VLAN 2 to 4094
Interface GIGABITEHTERNET0/0/4Port link-type trunkport trunk allow-pass VLAN 2 to 4094
Interface GIGABITEHTERNET0/0/5Port link-type trunkport trunk allow-pass VLAN 2 to 4094
Interface GIGABITEHTERNET0/0/6Port link-type trunkport trunk allow-pass VLAN 2 to 4094
Interface GIGABITEHTERNET0/0/7Port link-type trunkport trunk allow-pass VLAN 2 to 4094
Interface GIGABITEHTERNET0/0/8Port link-type trunkport trunk allow-pass VLAN 2 to 4094
Interface GIGABITEHTERNET0/0/9Port link-type trunkport trunk allow-pass VLAN 2 to 4094
Interface GIGABITEHTERNET0/0/10Port link-type trunkport trunk allow-pass VLAN 2 to 4094
Interface Gigabitehternet0/0/11port link-type accessport default VLAN 18
Interface Gigabitehternet0/0/12port link-type accessport default VLAN 8
Interface Gigabitehternet0/0/13port link-type accessport default VLAN 8
Interface Gigabitehternet0/0/14port link-type accessport default VLAN 8
Interface Gigabitehternet0/0/15port link-type accessport default VLAN 8
Interface Gigabitehternet0/0/16port link-type accessport default VLAN 8
Interface Gigabitehternet0/0/17port link-type accessport default VLAN 8
Interface Gigabitehternet0/0/18port link-type accessport default VLAN 8
Interface Gigabitehternet0/0/19port link-type accessport default VLAN 8
Interface Gigabitehternet0/0/20port link-type accessport default VLAN 8
Interface Gigabitehternet0/0/21port link-type accessport default VLAN 18
Interface Gigabitehternet0/0/22port link-type accessport default VLAN 18
Interface Gigabitehternet0/0/23port link-type accessport default VLAN 6
Interface Gigabitehternet0/0/24port link-type accessport default VLAN 6
DHCP server group 12gateway 192.168.12.254
Interface Vlanif1ip address 192.168.6.254 255.255.255.0dhcp Select Interfacedhcp Server exclude-ip-address 192.168.6.180 192.168.6.253dhcp server Dns-list 192.168.18.2 192.168.8.1
=================================================================================================
Two layer switch 12 floor configuration S1201:Configure user remote login password and 3A authentication
<>sys into global configuration mode[s1201]sysname xxx to switch name[s1201]user-interface vty 0 4 configuration vty virtual remote login Port[s1201-ui-vty0-4] authentication-mode AAA configuration authentication mode for 3A authentication[S1201-ui-vty0-4] AAA enters 3A authentication mode
[S1201-AAA] local-user pxtadmin password cipher xxxxx Add user
[S1201-aaa]local-user pxtadmin Privilege level 15 to set permission levels for users
[S1201-aaa]local-user pxtadmin service-type telnet terminal ssh http Allow remote Login service type
[S1201-aaa]quit launches AAA mode
[S1201]telnet Server enable Telnet service
Configure the management IP[S1201] interface vlanf 1 Enter VLAN 1 interface[S1201]ip address 192.168.16.121 255.255.255.0
Configure VLANsTrunk mode (connect switch)[S1201]Interface G0/0/1[S1201-gigabitethernet0/0/1]port link-type Trunk Configuration interface type is trunk
[S1201-gigabitethernet0/0/1]port trunk Allow-pass VLAN 2 to 4094 allows Vlan2 to vlan4094 through
Access mode (host access)[S1201]VLAN 12 Add VLAN[S1201-vlan10]quit[s1201]interface G0/0/2
[S1201-GIGABITETHERNET0/0/2]Port Link-type Access interface mode for access
[S1201-gigabitethernet0/0/2]port default VLAN 12 interface joined to VLAN10
Wireless-user[s1201]vlan 9 Adding VLANs 9
[S1201-vlan9] Quit
[S1201]interface G0/0/23
[S1201-gigabitethernet0/0/23]port Link-type Trunk
[S1201-GIGABITETHERNET0/0/23]Port Trunk allow-pass VLAN 2 to 4094
Wireless-admin[S1201]vlan 110 Add vlan110[s1201-vlan110] Quit
[S1201]interface g0/0/24
[S1201-GIGABITETHERNET0/0/24]Port Link-type Trunk
[S1201-GIGABITETHERNET0/0/24]Port Trunk allow-pass VLAN 2 to 4094
Monitor
Configure static routes [S1201]ip route-static 0.0.0.0 0.0.0.0 192.168.16.253 Configure default routes
From for notes (Wiz)
Company basic network architecture and implementation