配置交换机标准命名访问控制列表项目报告.docx
精品齐鲁行业资料 欢迎下载 赵鲁宾编辑配置交换机标准命名访问控制列表项目报告项目名称:配置交换机标准命名访问控制列表项目情境:XXX学校为了实现内部网络中不同网络用户之间安全防范措施,学校需要将学生网隔离出来,各部门之间的网络仍然可以实现互连互通。项目目标:学生网不能访问办公网,也不能访问教师网。组网设备:PC机3台,网线若干,RG3760-24交换机1台PC1PC2FA0/10FA0/20PC3FA0/1学生网教师网办公网S3760网络拓扑:小组成员分工:张春林、翟 玮:负责网络连接和PC机的IP地址设置任建强、辛北辰:负责网络连通测试阚 青、刘海沧:负责交换机配置郭 敏、段 炼:负责实验记录及文档整理施工过程:步骤一:安装网络工作环境按上图中的网络拓扑结构安装和连接设备,注意设备连接的接口标识,连接完成后检查连接线缆指示灯的工作状态,清除原来的配置信息。步骤二:IP地址规划与设置设备名称IP地址子网掩码网关接口PC1192.168.1.6255.255.255.0192.168.1.1FA0/1PC2192.168.2.11255.255.255.0192.168.2.1FA0/10PC3192.168.3.14255.255.255.0192.168.3.1FA0/20步骤三:配置交换机S3760-24#conEnter configuration commands, one per line. End with CNTL/Z.S3760-24(config)#no lo conS3760-24(config)#int fa0/1S3760-24(config-if-FastEthernet 0/1)#no switchS3760-24(config-if-FastEthernet 0/1)#ip address 192.168.1.1 255.255.255.0S3760-24(config-if-FastEthernet 0/1)#no shutS3760-24(config-if-FastEthernet 0/1)#int fa0/10S3760-24(config-if-FastEthernet 0/10)#no switchS3760-24(config-if-FastEthernet 0/10)#ip address 192.168.2.1 255.255.255.0S3760-24(config-if-FastEthernet 0/10)#no shutS3760-24(config-if-FastEthernet 0/10)#int fa0/20S3760-24(config-if-FastEthernet 0/20)#no switchS3760-24(config-if-FastEthernet 0/20)#ip address 192.168.3.1 255.255.255.0S3760-24(config-if-FastEthernet 0/20)#no shutS3760-24(config-if-FastEthernet 0/20)#exitS3760-24(config)#ip access-list standard deny-studentS3760-24(config-std-nacl)#deny 192.168.1.0 0.0.0.255S3760-24(config-std-nacl)#permit anyS3760-24(config-std-nacl)#exitS3760-24(config)#int fa0/1S3760-24(config-if-FastEthernet 0/1)#ip accS3760-24(config-if-FastEthernet 0/1)#ip access-group deny-student inS3760-24(config-if-FastEthernet 0/1)#no shutS3760-24(config-if-FastEthernet 0/1)#exitS3760-24(config)#步骤四:网络测试 用ping命令从PC1测试:C:Documents and SettingsAdministrator>ipconfigWindows IP ConfigurationEthernet adapter test: Connection-specific DNS Suffix . : IP Address. . . . . . . . . . . . : 192.168.1.6 Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : 192.168.1.1C:Documents and SettingsAdministrator>ping 192.168.3.14Pinging 192.168.3.14 with 32 bytes of data:Request timed out.Request timed out.Request timed out.Request timed out.Ping statistics for 192.168.3.14: Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),C:Documents and SettingsAdministrator>ping 192.168.2.11Pinging 192.168.2.11 with 32 bytes of data:Request timed out.Request timed out.Request timed out.Request timed out.Ping statistics for 192.168.2.11:Packets: Sent = 4, Received = 0, Lost = 4 (100% loss)可见,学生机不能访问其他网络,实现学生网的隔离。用ping命令从PC2测试:C:Documents and SettingsAdministrator>ping 192.168.3.14Pinging 192.168.3.14 with 32 bytes of data:Reply from 192.168.3.14: bytes=32 time=1ms TTL=127Reply from 192.168.3.14: bytes=32 time<1ms TTL=127Reply from 192.168.3.14: bytes=32 time<1ms TTL=127Reply from 192.168.3.14: bytes=32 time<1ms TTL=127Ping statistics for 192.168.3.14: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 1ms, Average = 0msC:Documents and SettingsAdministrator>可见,办公网与教师网仍然可以互连互通。