1. 程式人生 > >華為路由交換ENSP 模擬 NAT+Firewall+DNS+DHCP 功能

華為路由交換ENSP 模擬 NAT+Firewall+DNS+DHCP 功能

ENSP2.0 模擬 NAT+Firewall+DNS+DHCP 功能,主要涉及在華為路由器上面,如何實現防火牆特性、NAT、DNS、DHCP 功能.
在這裡插入圖片描述
掌握目標
1、路由器 DHCP 客戶端配置(模擬 PC)
2、防火牆特性配置
3、NAT 配置
4、DNS 與 DHCP 的配置掌握

一、實驗拓撲:
二、PC 的配置

sysname PC
dhcp enable
dns resolve
dns server 8.8.8.8

interface GigabitEthernet0/0/0
ip address dhcp-alloc
三、閘道器路由器的配置

sysname GW

dhcp enable
dns resolve
dns server 8.8.8.8

acl number 3000
rule 5 permit ip source 192.168.10.0 0.0.0.255
acl number 3001
rule 5 deny icmp icmp-type echo
rule 10 permit ip

firewall zone trust
priority 10

firewall zone untrust
priority 5

firewall zone Local
priority 15

firewall interzone trust untrust
firewall enable
packet-filter 3001 inbound
detect aspf ftp
detect aspf sip
detect aspf rtsp
detect aspf http

interface GigabitEthernet0/0/0
ip address 192.168.10.1 255.255.255.0
zone trust
dhcp select interface
dhcp server dns-list 8.8.8.8

interface GigabitEthernet0/0/1
ip address 211.1.1.2 255.255.255.0
nat outbound 3000
zone untrust

ip route-static 0.0.0.0 0.0.0.0 GigabitEthernet0/0/1 211.1.1.1

user-interface vty 0 4
authentication-mode password
set authentication password cipher huawei
user privilege level 3
四、公網路由器的配置

sysname INTERNET

ip host www.baidu.com 100.100.100.100
ip host www.google.com 200.200.200.200
dns resolve
dns server 8.8.8.8
dns proxy enable

interface GigabitEthernet0/0/0
ip address 211.1.1.1 255.255.255.0

interface NULL0

interface LoopBack0
ip address 100.100.100.100 255.255.255.0

interface LoopBack1
ip address 200.200.200.200 255.255.255.0

interface LoopBack100
ip address 8.8.8.8 255.255.255.0

user-interface vty 0 4
authentication-mode password
set authentication password cipher huawei
user privilege level 3
五、測試 PC 上網
ping www.google.com
telnet www.baidu.com
dis access-user
dis ip inter bri
六、測試閘道器的狀態
[GW]dis nat session all