VLAN配置?
建6個(gè)VLAN??
conf t?
vlan 100-105?
show vlan
配置服務(wù)器的vlan地址?
int vlan 100?
ip add 192.168.80.254 255.255.255.0?
no shut
配置各個(gè)小組的
vlan? VLAN 101??
int vlan 101?
ip add 172.20.101.254 255.255.255.0
VLAN 102??
int vlan 102?
ip add 172.20.102.254 255.255.255.0
VLAN 103??
int vlan 103?
ip add 172.20.103.254 255.255.255.0
VLAN 104??
int vlan 104?
ip add 172.20.104.254 255.255.255.0
VLAN 105??
int vlan 105?
ip add 172.20.105.254 255.255.255.0
end??
conf t
配置網(wǎng)口為access
int e1/0/1-20?
switch mo access exit
給每個(gè)vlan劃分3個(gè)網(wǎng)口
VLAN 101??
int e1/0/1-3?
sw access vlan 101
VLAN 102??
int e1/0/4-6?
sw access vlan 102
VLAN 103??
int e1/0/7-9?
sw access vlan 103
VLAN 104??
int e1/0/10-12?
sw access vlan 104
VLAN 105??
int e1/0/13-15?
sw access vlan 105
劃分2個(gè)管理口
int e1/0/19-20?
sw access vlan 100
劃分4個(gè)數(shù)據(jù)口為trunk
int e1/0/21-24?
sw mo trunk?
sw trunk allowed vlan all
ACL配置?
ip access-list extended HZ101
permit udp any-source any-destination d-port range 67 68??
從設(shè)備靶機(jī)能獲取到主設(shè)備上的DHCP
deny ip any-source host-destination 172.20.101.253??
拒絕選手訪問到253的dhcp地址
permit ip 172.20.101.0 0.0.0.255 172.20.101.0 0.0.0.255??
前半個(gè)小時(shí)能訪問自己的靶機(jī)??
permit ip 172.20.0.0 0.0.255.255 172.20.0.0 0.0.255.255??
半個(gè)小時(shí)后大家能互相訪問各自的靶機(jī)
permit tcp any-source host-destination 192.168.80.1 d-port 80??
只能訪問服務(wù)器80端口
permit tcp any-source host-destination 192.168.80.1 d-port range 8000 9000??
讓虛擬機(jī)VNC的端口可以訪問
deny ip any-source any-destination? 拒絕所有
exit?
firewall enable??
開啟防火墻
vacl ip access-group HZ101 in vlan 101??
應(yīng)用到vlan