1、实验四HSRP实验四 :HSRP一:实验目标(1) 组网需求:企业总部局域网采用两台核心交换机,为防止二层环路,需全网运行STP:将SW1部署为根网桥,SW2部署为备份根网桥,并将接入PC的接口配置为portfast端口;同时部署HSRP为内部vlan提供网关冗余。本局域网有4个vlan,生产业务vlan10,办公业务vlan11,服务器vlan12,二层交换机网管vlan8,将SW1部署为vlan8/10/12主网关,将sw2部署为vlan11的主网关,要求vlan10、11的主网关跟踪上行链路。(2) 测试HSRP主备网关倒换。(3) 分析pc1 ping pc2的三层通信过程和二层通信过
2、程。二:拓扑图三:预期结果 当vlan10或vlan11的上行链路shutdown时,HSRP组的主备网关会倒换。四:调试二层接口配置:SW3:show ip int bri:三层接口配置:SW1:show ip int bri:SW2:show ip int bri:STP配置:SW1:SW2:SW3:HSRP配置:SW1中:VLAN8:VLAN 10:VLAN 11:VLAN 12:SW2中:Vlan8:Vlan10:Vlan11:Vlan12:Sw1中vlan10的上行链路跟踪:Sw2中vlan11的上行链路跟踪:五:测试SW1中Show ip int bri:SW2中Show ip i
3、nt bri:未将sw1的上行链路showdown时:Sw1中:Show standby bri:Sw2中:Show standby bri:将sw1上行链路接口fa0/12 shutdown后:Sw1中:Show standby bri:Sw2中:Show standby bri:重新将SW1中的fa0/12口打开:Pc1 ping pc2:六:总结与原理分析PC1 ping PC2的数据流分析:PC1SW3SW1SW3PC2PC2SW3SW1SW2SW1SW3PC11 Pc1封装icmp包,发现未知目的MAC地址且目的IP与自己不在同一个网段,则封装一个ARP请求,请求的目的IP为网关IP
4、,目的MAC为全F;2 在通过fa0/10口时,arp请求被打上了vlan10 的标签;3 进入sw3,sw3查询mac地址表,发现没有pc1 的mac地址,便更新mac表;4 由于配置了生成树协议,相对于vlan10,sw3的fa0/2口是阻塞的,所以arp请求被 交换机从fa0/1口发送到三层交换机sw1;5 Sw1收到arp请求后,发现目的ip是自身的,然后拆vlan10标,更新mac地址表,便封装一个arp应答,封装时打上vlan10的标, 从fa0/3口单播出去;6 Sw3收到arp应答,查询mac地址表后,从fa0/10转发出去,在出口拆掉vlan10的标签;7 Pc1收到arp应
5、答,更新自身的arp缓存表,重新封装icmp包,其目的mac是网关,目的IP是pc2的IP地址,将封装好的icmp包,通过fa0/10口送往SW3;8 Icmp包在fa0/10口被打上vlan10的标签;9 Icmp包进入sw3,sw3查询mac地址表,把icmp包从fa0/1口转发出去;10 SW1收到icmp包,拆vlan10标,发现目的IP地址不是自己的,但是网关却是已知的vlan11,且不知道目的mac地址,便封装一个arp请求,并打上vlan11的标签,洪泛出去;11 由于配置了生成树协议,所以SW3的Fa0/2口相对于vlan11是阻塞的,所以ARP请求从fa0/3口发送到SW3;
6、12 SW3收到了arp请求后将其洪泛,arp请求从fa0/11口出去,在通过fa0/11口时被拆掉vlan11的标签;13 Pc2收到arp请求,更新自己的arp缓存表后,封装一个arp应答;14 Arp应答从fa0/11口进入SW3时被打vlan11的标签;15 SW3收到arp应答后,更新mac地址表,然后从fa0/1口转发给SW1;16 SW1收到arp应答后,拆除arp应答的vlan11的标签,更新mac地址表,重新封装icmp包,将ICMP转发给SW3;17 SW3收到ICMP包后,将ICMP包转发给PC2,在通过sw3的fa0/11口时,icmp包的vlan11标签被拆除;18
7、Pc2收到icmp包后,发现目的IP地址,mac地址均为自己的后,封装一个icmp回应包,通过SW3的fa0/11口时被打上vlan11的标签,之后进入SW3;19 Icmp回应包进入SW3后被SW3通过fa0/1口转发到SW1;20 由于配置了HSRP,且SW1是vlan11的备份路由,所以SW1需通过查路由表,将icmp回应包转发给SW2;21 SW2收到icmp回应包后,拆掉vlan11的标签,更新mac地址表和路由表,发现icmp包的目的IP是自己网段内的IP地址,重新封装一个icmp回应包,并打上vlan10的标签,SW2的端口Fa0/3连接的SW3的Fa0/2相对于vlan10是阻
8、塞的,所以打了vlan10标签的数据流将被发送到SW1;22 SW1收到icmp回应包后,更新自己的mac地址表和路由表,并查询mac地址表后,将其转发到SW3;23 SW3收到icmp回应包后,查询mac地址表,将其通过fa0/10口转发,icmp包在通过fa0/10口时,被拆除vlan10的标签;24 Pc1收到icmp回应包。七:配置show runSw1:!version 12.3service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption
9、!hostname SW1!boot-start-markerboot-end-marker!no aaa new-model!resource policy!memory-size iomem 5ip subnet-zero!ip cefno ip dhcp use vrf connected!no ip domain lookupno ftp-server write-enable!spanning-tree vlan 8 priority 0spanning-tree vlan 10 priority 0spanning-tree vlan 11 priority 0spanning-t
10、ree vlan 12 priority 0!interface FastEthernet0/0!interface FastEthernet0/1 switchport mode trunk!interface FastEthernet0/2!interface FastEthernet0/3 switchport mode trunk!interface FastEthernet0/4!interface FastEthernet0/5!interface FastEthernet0/6!interface FastEthernet0/7!interface FastEthernet0/8
11、!interface FastEthernet0/9!interface FastEthernet0/10!interface FastEthernet0/11!interface FastEthernet0/12 no switchport ip address 192.168.9.1 255.255.255.252!interface FastEthernet0/13!interface FastEthernet0/14!interface FastEthernet0/15!interface Vlan1 no ip address!interface Vlan8 ip address 1
12、92.168.8.130 255.255.255.128 standby 8 ip 192.168.8.129 standby 8 priority 120 standby 8 preempt!interface Vlan10 ip address 192.168.10.2 255.255.255.0 standby 10 ip 192.168.10.1 standby 10 priority 120 standby 10 preempt standby 10 track FastEthernet0/12 30!interface Vlan11 ip address 192.168.11.2
13、255.255.255.0 standby 11 ip 192.168.11.1 standby 11 preempt!interface Vlan12 ip address 192.168.12.2 255.255.255.0 standby 12 ip 192.168.12.1 standby 12 priority 120 standby 12 preempt!ip http serverip classless!control-plane!line con 0 exec-timeout 0 0 logging synchronousline aux 0line vty 0 4!EndS
14、w2:!version 12.3service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname SW2!boot-start-markerboot-end-marker!no aaa new-model!resource policy!memory-size iomem 5ip subnet-zero!ip cefno ip dhcp use vrf connected!no ip domain lookupno ftp-serve
15、r write-enable!spanning-tree vlan 8 priority 4096spanning-tree vlan 10 priority 4096spanning-tree vlan 11 priority 4096spanning-tree vlan 12 priority 4096!interface FastEthernet0/0!interface FastEthernet0/1 switchport mode trunk!interface FastEthernet0/2!interface FastEthernet0/3 switchport mode tru
16、nk!interface FastEthernet0/4!interface FastEthernet0/5!interface FastEthernet0/6!interface FastEthernet0/7!interface FastEthernet0/8!interface FastEthernet0/9!interface FastEthernet0/10!interface FastEthernet0/11!interface FastEthernet0/12 no switchport ip address 192.168.9.5 255.255.255.252!interfa
17、ce FastEthernet0/13!interface FastEthernet0/14!interface FastEthernet0/15!interface Vlan1 no ip address!interface Vlan8 ip address 192.168.8.131 255.255.255.128 standby 8 ip 192.168.8.129 standby 8 preempt!interface Vlan10 ip address 192.168.10.3 255.255.255.0 standby 10 ip 192.168.10.1 standby 10 p
18、reempt!interface Vlan11 ip address 192.168.11.3 255.255.255.0 standby 11 ip 192.168.11.1 standby 11 priority 120 standby 11 preempt standby 11 track FastEthernet0/12 30!interface Vlan12 ip address 192.168.12.3 255.255.255.0 standby 12 ip 192.168.12.1 standby 12 preempt!ip http serverip classless!con
19、trol-plane!line con 0 exec-timeout 0 0 logging synchronousline aux 0line vty 0 4!EndSw3:!version 12.3service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname SW3!boot-start-markerboot-end-marker!no aaa new-model!resource policy!memory-size iom
20、em 5ip subnet-zero!ip cefno ip dhcp use vrf connected!no ip domain lookupno ftp-server write-enable!interface FastEthernet0/0!interface FastEthernet0/1 switchport mode trunk!interface FastEthernet0/2 switchport mode trunk!interface FastEthernet0/3!interface FastEthernet0/4!interface FastEthernet0/5!
21、interface FastEthernet0/6!interface FastEthernet0/7!interface FastEthernet0/8!interface FastEthernet0/9!interface FastEthernet0/10 switchport access vlan 10 spanning-tree portfast!interface FastEthernet0/11 switchport access vlan 11 spanning-tree portfast!interface FastEthernet0/12!interface FastEth
22、ernet0/13!interface FastEthernet0/14!interface FastEthernet0/15!interface Vlan1 no ip address!interface Vlan8 ip address 192.168.8.132 255.255.255.128!ip default-gateway 192.168.8.129ip http serverip classless!control-plane!line con 0 exec-timeout 0 0 logging synchronousline aux 0line vty 0 4!EndRT5
23、:!version 12.3service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname RT5!boot-start-markerboot-end-marker!no aaa new-model!resource policy!memory-size iomem 5ip subnet-zero!ip cefno ip dhcp use vrf connected!no ip domain lookupno ftp-server
24、write-enable!interface Ethernet0/0 ip address 192.168.9.2 255.255.255.252 full-duplex!interface Ethernet0/1 no ip address shutdown half-duplex!interface Ethernet0/2 no ip address shutdown half-duplex!interface Ethernet0/3 no ip address shutdown half-duplex!interface Serial1/0 no ip address shutdown
25、serial restart-delay 0 no dce-terminal-timing-enable!interface Serial1/1 no ip address shutdown serial restart-delay 0 no dce-terminal-timing-enable!interface Serial1/2 no ip address shutdown serial restart-delay 0 no dce-terminal-timing-enable!interface Serial1/3 no ip address shutdown serial resta
26、rt-delay 0 no dce-terminal-timing-enable!ip http serverip classless!control-plane!line con 0 exec-timeout 0 0 logging synchronousline aux 0line vty 0 4!endRT6:!version 12.3service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname RT6!boot-start
27、-markerboot-end-marker!no aaa new-model!resource policy!memory-size iomem 5ip subnet-zero!ip cefno ip dhcp use vrf connected!no ip domain lookupno ftp-server write-enable!interface Ethernet0/0 ip address 192.168.9.6 255.255.255.252 full-duplex!interface Ethernet0/1 no ip address shutdown half-duplex
28、!interface Ethernet0/2 no ip address shutdown half-duplex!interface Ethernet0/3 no ip address shutdown half-duplex!interface Serial1/0 no ip address shutdown serial restart-delay 0 no dce-terminal-timing-enable!interface Serial1/1 no ip address shutdown serial restart-delay 0 no dce-terminal-timing-
29、enable!interface Serial1/2 no ip address shutdown serial restart-delay 0 no dce-terminal-timing-enable!interface Serial1/3 no ip address shutdown serial restart-delay 0 no dce-terminal-timing-enable!ip http serverip classless!control-plane!line con 0 exec-timeout 0 0 logging synchronousline aux 0line vty 0 4!end
copyright@ 2008-2022 冰豆网网站版权所有
经营许可证编号:鄂ICP备2022015515号-1