阅读以下说明,回答问题 1 至问题 3,将解答填入答题纸对应的解答栏内。 【说明】 某企业的网络结构如图 4-1 所示。企业使用双出口,其中 ISP1 是高速链路,网关为 202.100.1.2, ISP2 是低速链路,网关为 104.114.128.2。
[SwitchB] acl 3000
[SwitchB-acl-adv-3000] rule permit ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
[SwitchB-acl-adv-3000] rule permit ip source 192.168.2.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
[SwitchB-acl-adv-3000] quit
[SwitchB] acl 3001 //匹配内网 192. 168.1.0/24 网段的用户数据流
[SwitchB-acl-adv-3001] rule permit ip source (1) 0.0.0.255
[SwitchB acl-adv-3001] quit
[SwitchB] acl 3002 //匹配内网 192.168.2.0/24 网段的用户数据流
[SwitchB-acl-adv-3002] rule permit ip (2) 192.168.2.0 0.0.0.255
[SwitchB-acl-adv-3002] quit
[SwitchB] traffic classifier c0 operator or
[SwitchB-classifier-c0] (3) acl 3000
[SwitchB-classifer-c0] quit
[SwitchB] traffic classifier c1 (4) or
[SwitchB-classifier-c1] if-match acl 3001
[SwitchB-classifer-c1] quit
[SwitchB] traffic classifier c2 operator or
[SwitchB-classifer-c2] if-match acl (5)
[SwitchB-classfer-c2] (6) quit
[SwitchB] traffic behavior. b0
[SwitchB-behavior-b0] (7)
[SwitchB-behavior-bO] quit
[SwitchB] traffic behavior. bl
[SwitchB-behavior-b1] redirect ip-nexthop (8)
[SwitchB-behavior-b1] quit
[SwitchB] traffic behavior. b2
[SwitchB-behavior-b2] redirect ip-nexthop (9)
[SwitchB-behavior-b2] quit
[SwitchB] traffic policy p1
[SwitchB-trafficpolicy-p1] classifier c0 behavior. (10)
[SwitchB-trafficpolicy-p1] classifier c1 behavior. (11)
[SwitchB-trafficpolicy-p1] classifier c2 behavior. b2
[SwitchB-trafficpolicy-p1] quit
[SwitchB] interface (12)
[SwitchB-GigabitEthenet0/0/3] traffic-policy pl (13) SwitchB-GigabitEthernet0/0/3] return
【问题 2】(2 分) 在问题 1 的配置代码中,配置 ACL 3000 的作用是: (14)。
【问题 3】(5 分,每空 1 分) 公司需要访问 Intermet 公网,计划通过配置 NAT 实现私网地址到公网地址的转换,ISP1 公 网地址范围为 202.100.1.1~202.100.1.5 ;ISP2 公网地址范围为 104.114.128.1~104.114.128.5。
请根据描述,将下面的配置代码补充完整。
.....
[SwitchB]nat address-group 0 202.100.1.3 202.100.1.5
[SwitchB]nat address-group 1 104.114.128.3 104.114.128.5
[SwitchB]acl number 2000
[SwitchB-acl-basic-2000]rule 5 (15) source 192.168.1.0 0.0.0.255
[SwitchB]acl number 2001
[SwitchB-acl-basic-2001]rule 5 permit source 192.168.2.0 0.0.0.255
[SwitchB]interface GigabitEthernet0/0/3
[SwitchB-GigabitEthernet0/0/3]nat outbound (16) address group 0 no-pat
[SwitchB-GigabitEthernnet0/0/3]nat outbound (17) address group 1 no-pat
[SwitchB-GigabitEthernet0/0/3]quit
[SwitchB] ip route-static 192.168.1.0 0.0.0.255 (18)
[SwitchB] ip route-static 192.168.2.0 0.0.0.255 (19) ...
订单号:
遇到问题请联系在线客服
订单号:
遇到问题请联系在线客服