版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)
文檔簡(jiǎn)介
NAT“NetworkAddressTranslation它是一個(gè)IETF(InternetEngineeringTask,Internet工程任務(wù)組)標(biāo)準(zhǔn),允許一是一種把內(nèi)部私有網(wǎng)絡(luò)地址(IP)IPInternetIP192.1.1.1~192.1.1.10,使用路由器NAT功能進(jìn)行地址轉(zhuǎn)換,具體配置如下:Currentconfiguration:version11.3noservicepassword-encryptionhostname2501ipnatpoolaaa192.1.1.2192.1.1.10netmask255.255.255.0ipnatinsidesourcelist1poolaaainterfaceipaddress10.1.1.1255.255.255.0ipnatinsideinterfaceipaddress192.1.1.1ipnatnoipmroute-cachebandwidth2000nofair-queueinterfaceSerial1noipaddressnoipiproute0.0.0.00.0.0.0access-list1permit10.1.1.0lineconlineauxlinevty04passwordciscoPPP(Point-to-PointProtocol)是SLIP(SerialLineIPprotocol)的繼承者,它提供了跨過同步CHAP(ChallengeHandshakeAuthenticationProtocol)(-握手驗(yàn)證協(xié)議)和PAP(PasswordAuthenticationProtocol)(PAP)(口令驗(yàn)證協(xié)議)通常被用于在PPP封裝的串行線提供安 的路由器Router1和Router2的S0口均封裝PPP協(xié)議,采用CHAP做認(rèn)證。hostnameusernamerouter1passwordxxxinterfaceSerial0ipaddress192.200.10.1encapsulationppppppauthentication!hostnameusernamerouter2passwordxxxinterfaceSerial0ipaddress192.200.10.2encapsulationpppauthentication格式。X.25的第一層定義了電氣和物理端口特性。interfaceSerial0encapsulationx25ipaddress192.200.10.1x25addressx25htcx25nvcx25mapip192.200.10.2110102x25mapip192.200.10.3110103!interfaceSerial0encapsulationx25ipaddress192.200.10.2x25addressx25htcx25nvcx25mapip192.200.10.1110101x25mapip192.200.10.3110103!interfaceSerial0encapsulationx25ipaddress192.200.10.3x25addressx25htcx25nvcx25mapip192.200.10.1110101x25mapip192.200.10.2110102!E164K專線連接注:1.T1時(shí),channel-group0-23,Timeslot1-24;E1時(shí),channel-group0-30,Timeslot1-31.Current!versionnoserviceudp-small-serversnoservicetcp-small-servers!hostname!enablesecret5$1$XN08$Ttr8nfLoP9.2RgZhcBzkk/enablepasswordcisco!!ipsubnet-!controllerE1framingNO-CRC4channel-group0timeslotschannel-group1timeslotschannel-group2timeslots!interfaceipaddress133.118.40.1media-type!interfaceEthernet1noipaddress!interfaceipaddress202.119.96.1encapsulationhdlcnoipmroute-!interfaceipaddress202.119.96.5encapsulationhdlcnoipmroute-!interfaceipaddress202.119.96.9encapsulationhdlcnoipmroute-!noipiproute133.210.40.0255.255.255.0iproute133.210.41.0255.255.255.0iproute133.210.42.0255.255.255.0!lineconlineauxlinevty04passwordcicso!1】E1CE123現(xiàn)以一臺(tái)服務(wù)器(RAS,RemoteAccessServer)Cisco2509、RJ45為例RAS---Cisco2509、RJ45線,RJ45轉(zhuǎn)9針串口轉(zhuǎn)換器、計(jì)算機(jī)。第二步,硬件連接,RJ45Cisco2509consoleRJ459·第三步,RASWINDOWS98Cisco設(shè)備的虛擬操作臺(tái)。Cisco2509IOS1RASRJ45console”與“AUX”,請(qǐng)問這兩個(gè)端口的用途是什么?(100)2Cisco(1003IOShostnameCisco enable ip- ip-name-server202.112.77.2【1(3async-bootpsubnet-maskasync-bootpgatewayasync-bootpdns-server★配置Ethenlei (略iplocalpoolpool2509202.112.79.1202.112.79.8iPAsynchronousRASmodem,interfaceGroup-Async1group-range1818encapsulationpap【2(2ansyncdynamicansyncdefaultaddresspoolpool2509//pool2509pppauthenticationpapppprouter【3(3routernetworknetwork★配置撥號(hào)服務(wù)器的缺省路 (略access-list1pormit202.112.77.0.0.0.255★配置Asynchronous (略★配置Iinevty04【4(3access-class1in//access-classpaswordIPSec【問題1】簡(jiǎn)述IPSec實(shí) 2】解釋配置中畫線部分含義。17221ipinternetipipipcryptoisakmp1authenticationpre-sharegroupcryptoisakmpkeytest123addresscryptoipsectransform-settagah-md5-hmacesp-descryptomapdemp10ipsec-isakmpsetpeersettransform-set matchaddress101!interfaceipaddress192.168.1.1noipdirected-broadcasttunnelsourcetunneldestination202.96.1.2cryptomapdemointerfaceserial0/0ipaddress202.96.1.1noipdirected-broadcastcryptomapdemo!interfaceipaddress168.1.1.1noipdirected-broadcastinterfaceEthernet0/0ipaddress172.22.1.100noipdirected-!ipiproute0.0.0.00.0.0.0iproute172.22.2.0255.255.0.0access-lost101permitgrehost202.96.1.1hostcryptoisakmp1authenticationpre-sharegroupcryptoisakmpkeytest123addresscryptoipsectransform- tagah-md5-hmacesp-!cryptomap demo10ipsec-isakmpsetpeer202.96.1.1settransform-settagmatchaddress101!interfaceipaddress192.168.1.2noipdirected-broadcasttunnrlsourceSerial0/0tunneldestination202.96.1.1cryptomapdemointerfaceipaddress202.96.1.2noipdirected-broadcastcryptomapdemo!interfaceipaddress167.1.1.1noipdirected-broadcastinterfaceEthernet0/0ipaddress172.22.2.100noipdirected-!HardwareHardwareisMTU1500bytes,BW1544Kbit,DLY1000usec,rely255/255,loadipiproute0.0.0.00.0.0.0iproute172.22.1.0255.255.0.0access-lost101permitgrehost202.96.1.2host【問題1】列表可以幫助我們控制網(wǎng)上IP包的傳輸,其主要應(yīng)用在哪幾個(gè)方面【問題2】標(biāo)準(zhǔn)的IP列表和擴(kuò)展的IP列表主要區(qū)別是什么【問題3】下面是一臺(tái)使用了標(biāo)準(zhǔn)列表的路由器的部分配置,請(qǐng)其中的錯(cuò)誤并access-list1deny172.16.4.13interfaceserialipaccess-group1我們?cè)谌展ぷ髦谐J褂脀nrae端口及]查看端的運(yùn)行態(tài)。下面的例子是我們?cè)诓煌闆r下看到的端口狀態(tài)行的內(nèi)容,請(qǐng)分析其產(chǎn)生的原因及解決方法。1Router#show Serial0isup,lineprotocolisHardwareisMTU1500bytes,BW1544Kbit,DLY1000usec,rely255/255,load1/255EncapsulationHDLC,loopbacknotset,keepaliveset(10sec)Lastinput00:00:00,output00:00:00,outputhangneverLastclearingofshowinterfacecountersneverQueueingstrategy:fifoOutputqueue0/40,0drops;inputqueue0/75,0drops5minuteinputrate1000bits/sec,2packets/sec5minuteoutputrate1000bits/sec,20packetsinput,0bytes,0noReceived0broadcasts,0runts,0giants,00inputerrors,0CRC,0frame,0overrun,0ignored,0abort0inputpacketswithdribbleconditiondetected0packetsoutput,0bytes,00outputerrors,0collisions,0interface0babbles,0latecollision,00lostcarrier,0no0outputbufferfailures,0outputbuffersswapped2Router#show Serial0isdown,lineprotocolisEncapsulationHDLC,loopbacknotset,keepaliveset(10sec)Lastinput00:00:00,output00:00:00,outputhangneverLastclearingofshowinterfacecountersneverQueueingstrategy:fifoOutputqueue0/40,0drops;inputqueue0/75,0drops5minuteinputrate1000bits/sec,2packets/sec5minuteoutputrate1000bits/sec,20packetsinput,0bytes,0noReceived0broadcasts,0runts,0giants,00inputerrors,0CRC,0frame,0overrun,0ignored,0abort0inputpacketswithdribbleconditiondetected0packetsoutput,0bytes,00outputerrors,0collisions,0interface0babbles,0latecollision,00lostcarrier,0no0outputbufferfailures,0outputbuffersswapped3Router#show Serial0isup,lineprotocolisHardwareisMTU1500bytes,BW1544Kbit,DLY1000usec,rely255/255,load1/255EncapsulationHDLC,loopbacknotset,keepaliveset(10sec)Lastinput00:00:00,output00:00:00,outputhangneverLastclearingofshowinterfacecountersneverQueueingstrategy:fifoOutputqueue0/40,0drops;inputqueue0/75,0drops5minuteinputrate1000bits/sec,2packets/sec5minuteoutputrate1000bits/sec,20packetsinput,0bytes,0noReceived0broadcasts,0runts,0giants,00inputerrors,0CRC,0frame,0overrun,0ignored,0abort0inputpacketswithdribbleconditiondetected0packetsoutput,0bytes,00outputerrors,0collisions,0interface0babbles,0latecollis
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。
最新文檔
- 2025-2030汽車輪胎行業(yè)產(chǎn)業(yè)鏈風(fēng)險(xiǎn)多元化投資進(jìn)度報(bào)告
- 2025-2030汽車自動(dòng)駕駛技術(shù)市場(chǎng)供需分析及未來發(fā)展規(guī)劃研究
- 2025-2030汽車環(huán)保排放檢測(cè)行業(yè)市場(chǎng)供需分析及尾氣治理規(guī)劃
- 2025-2030汽車后市場(chǎng)服務(wù)模式深度解析及未來發(fā)展趨勢(shì)
- 2025-2030汽車后市場(chǎng)供需研究及資金配置規(guī)劃分析研究報(bào)告書
- 2025-2030汽車制造業(yè)發(fā)展前景趨勢(shì)預(yù)測(cè)與投資分析規(guī)劃研究報(bào)告
- 2025-2030汽車S店行業(yè)市場(chǎng)現(xiàn)狀供需分析及投資評(píng)估規(guī)劃分析研究報(bào)告
- 2025-2030江蘇省科技創(chuàng)新獎(jiǎng)勵(lì)制度下150家重點(diǎn)企業(yè)創(chuàng)新競(jìng)爭(zhēng)力觀察
- 學(xué)生綜合素質(zhì)評(píng)價(jià)檔案管理制度
- 基層中醫(yī)藥服務(wù)醫(yī)保支付改革課題申報(bào)書
- 北京通州產(chǎn)業(yè)服務(wù)有限公司招聘參考題庫必考題
- 催收管理制度及流程規(guī)范
- 交通安全志愿者培訓(xùn)課件
- 化工防止靜電安全培訓(xùn)課件
- 護(hù)理不良事件根本原因分析
- AI藥物研發(fā)中的倫理風(fēng)險(xiǎn)防控
- 社會(huì)心理學(xué)考試題及答案
- 出鐵廠鐵溝澆注施工方案
- 現(xiàn)代企業(yè)管理體系架構(gòu)及運(yùn)作模式
- 2025年江蘇省泰州市保安員理論考試題庫及答案(完整)
- 公司酶制劑發(fā)酵工工藝技術(shù)規(guī)程
評(píng)論
0/150
提交評(píng)論