企业网or校园网络拓扑搭建(课设可用)
资源文件列表(大概)
网络拓扑/02064200-E638-48c2-B4E4-C30037712365/
-
网络拓扑/02064200-E638-48c2-B4E4-C30037712365/vrpcfg.zip
607B
网络拓扑/0602B7F5-8E1C-46de-A064-798744625540/
-
网络拓扑/0602B7F5-8E1C-46de-A064-798744625540/PC.xml
1.06KB
网络拓扑/0CA3C84F-00A7-4e89-8004-D530C46A2D04/
-
网络拓扑/0CA3C84F-00A7-4e89-8004-D530C46A2D04/flash.efz
6.66KB
网络拓扑/10388ED9-B845-4d3a-BC74-E128AD9D2501/
-
网络拓扑/10388ED9-B845-4d3a-BC74-E128AD9D2501/flash.efz
5.3KB
网络拓扑/13620E9B-D1E5-4c3a-95B1-0FA73ACAB17C/
-
网络拓扑/13620E9B-D1E5-4c3a-95B1-0FA73ACAB17C/vrpcfg.zip
680B
网络拓扑/20A28684-E929-4f0c-8195-7A166160947E/
-
网络拓扑/2618E044-517B-4220-B980-0449CEA8E4D9/
-
网络拓扑/2618E044-517B-4220-B980-0449CEA8E4D9/flash.efz
5.3KB
网络拓扑/2F165CD7-3812-4993-ACD2-D715B763F4C5/
-
网络拓扑/2F165CD7-3812-4993-ACD2-D715B763F4C5/flash.efz
4.57KB
网络拓扑/2FAA334E-F61B-43dc-9C49-8F6F068F0B11/
-
网络拓扑/2FAA334E-F61B-43dc-9C49-8F6F068F0B11/PC.xml
1.05KB
网络拓扑/36CA3628-5FA9-4944-8ECA-7CAD1DE4F072/
-
网络拓扑/36CA3628-5FA9-4944-8ECA-7CAD1DE4F072/flash.efz
5.3KB
网络拓扑/412CA58C-FFD2-4131-88FD-7271FA9D6B77/
-
网络拓扑/412CA58C-FFD2-4131-88FD-7271FA9D6B77/vrpcfg.zip
1.59KB
网络拓扑/465F3C89-ABEA-4ddf-A96B-900CE48DF379/
-
网络拓扑/465F3C89-ABEA-4ddf-A96B-900CE48DF379/PC.xml
1.03KB
网络拓扑/49AF4614-CEEB-4de8-8E60-AC5E05E0F2B8/
-
网络拓扑/49AF4614-CEEB-4de8-8E60-AC5E05E0F2B8/PC.xml
1.05KB
网络拓扑/86F5EA65-245D-49aa-AEAD-916006E7C8E9/
-
网络拓扑/86F5EA65-245D-49aa-AEAD-916006E7C8E9/flash.efz
6.55KB
网络拓扑/93FD5AC5-9E1C-4a59-9E86-6F20DBFD6FCE/
-
网络拓扑/93FD5AC5-9E1C-4a59-9E86-6F20DBFD6FCE/PC.xml
1.03KB
网络拓扑/945C03EB-D058-4616-8D6D-B1C7F56F858B/
-
网络拓扑/945C03EB-D058-4616-8D6D-B1C7F56F858B/PC.xml
1.05KB
网络拓扑/946DF97D-CEBF-405a-B614-48F27909D153/
-
网络拓扑/946DF97D-CEBF-405a-B614-48F27909D153/PC.xml
1.05KB
网络拓扑/A79FDF53-EE63-4d9e-A3ED-7A1A21D545E5/
-
网络拓扑/A79FDF53-EE63-4d9e-A3ED-7A1A21D545E5/PC.xml
1.05KB
网络拓扑/B948B8A0-560C-46e2-875D-17F8193979BB/
-
网络拓扑/B948B8A0-560C-46e2-875D-17F8193979BB/vrpcfg.cfg
5.99KB
网络拓扑/BDE80E7E-06BC-43cd-BC7C-014C016115FA/
-
网络拓扑/BDE80E7E-06BC-43cd-BC7C-014C016115FA/PC.xml
1.06KB
网络拓扑/D81C4A7F-6648-4f27-83A1-E1A94DD00B3D/
-
网络拓扑/D81C4A7F-6648-4f27-83A1-E1A94DD00B3D/PC.xml
1.03KB
网络拓扑/E3B7F6EF-91C1-4b2f-AC6A-DEB94A7EDC3B/
-
网络拓扑/E3B7F6EF-91C1-4b2f-AC6A-DEB94A7EDC3B/flash.efz
5.3KB
网络拓扑/E7FEF924-12DA-4319-A03B-85457FD258D3/
-
网络拓扑/E7FEF924-12DA-4319-A03B-85457FD258D3/flash.efz
5.3KB
网络拓扑/E9F4B0E5-1AFC-4f7a-BB12-B2E4139A0C72/
-
网络拓扑/E9F4B0E5-1AFC-4f7a-BB12-B2E4139A0C72/vrpcfg.zip
679B
网络拓扑/F9D87BA1-9447-49f4-A45C-F3791AA2EE98/
-
网络拓扑/F9D87BA1-9447-49f4-A45C-F3791AA2EE98/PC.xml
1.03KB
网络拓扑/FBCD961B-0AEE-496f-996A-D7E226281F91/
-
网络拓扑/FBCD961B-0AEE-496f-996A-D7E226281F91/flash.efz
5.3KB
资源内容介绍
本文通过在华为eNSP部署路由器、交换机以及防火墙等网络设备以及运用多种计算机网络协议和技术。在设计原则以及设计需求的前提下,对企业办公园区进行网络规划设计,其中分为两大部分,一部分是进行网络拓扑结构搭建,其中包括对设备及端口进行了相应的配置;另一部分是对整体、部分的网络功能进行相关的网络仿真测试和分析。该企业包括六个部门:行政、财务、产品开发、营销、生产和人事。通过建设一个高速、高安全性、高可靠性、可扩展的网络结构,使整个办公园区的网络系统通过一张网连接在一起,实现企业内部信息的共享,以及在工作协助中更高效、迅速地传递至相关部门,同时也便于管理层管理,能对当前企业的生产、销售额、财务、人事调动各方面情况及时地了解,并对潜在的问题及时发现处理。且企业采用防火墙技术来提高网络安全性,监控网络信息存取和传递以符合相关的安全策略。 <link href="/image.php?url=https://csdnimg.cn/release/download_crawler_static/css/base.min.css" rel="stylesheet"/><link href="/image.php?url=https://csdnimg.cn/release/download_crawler_static/css/fancy.min.css" rel="stylesheet"/><link href="/image.php?url=https://csdnimg.cn/release/download_crawler_static/89501068/raw.css" rel="stylesheet"/><div id="sidebar" style="display: none"><div id="outline"></div></div><div class="pf w0 h0" data-page-no="1" id="pf1"><div class="pc pc1 w0 h0"><img alt="" class="bi x0 y0 w1 h1" src="/image.php?url=https://csdnimg.cn/release/download_crawler_static/89501068/bg1.jpg"/><div class="t m0 x1 h2 y1 ff1 fs0 fc0 sc0 ls0 ws0">一、远<span class="_ _0"></span>程控<span class="_ _0"></span>制端的<span class="_ _0"></span>配置</div><div class="t m0 x1 h2 y2 ff1 fs0 fc0 sc0 ls0 ws0">(一<span class="_ _0"></span>)远程<span class="_ _0"></span>端的配<span class="_ _0"></span>置</div><div class="t m0 x2 h3 y3 ff1 fs1 fc0 sc1 ls0 ws0">接入<span class="_ _0"></span>层的<span class="_ _0"></span>远<span class="_ _0"></span>程控<span class="_ _0"></span>制端主<span class="_ _0"></span>要<span class="_ _0"></span>由<span class="_ _1"> </span>PC、<span class="_ _0"></span>Client<span class="_ _1"> </span>和二<span class="_ _0"></span>层交<span class="_ _0"></span>换机<span class="_ _2"> </span>LSW<span class="_ _1"> </span>组成<span class="_ _0"></span>,由<span class="_ _0"></span>于简<span class="_ _0"></span>化</div><div class="t m0 x1 h3 y4 ff1 fs1 fc0 sc1 ls0 ws0">部门的用户布局,<span class="_ _3"></span>每台二层交换机下由一台<span class="_ _1"> </span>PC<span class="_ _4"> </span>机和一台<span class="_ _4"> </span>Client<span class="_ _1"> </span>客户端组成,<span class="_ _3"></span>并</div><div class="t m0 x1 h3 y5 ff1 fs1 fc0 sc1 ls0 ws0">连接至两台三层核<span class="_ _0"></span>心交换机的<span class="_ _1"> </span>GE<span class="_ _1"> </span>端口,如表,代表<span class="_ _0"></span>接入层网络设<span class="_ _0"></span>备的物理连接</div><div class="t m0 x1 h3 y6 ff1 fs1 fc0 sc1 ls0 ws0">状态,其连接情况如下:</div><div class="c x3 y7 w2 h4"><div class="t m0 x4 h5 y8 ff1 fs2 fc0 sc1 ls0 ws0">设备名称</div></div><div class="c x5 y7 w3 h4"><div class="t m0 x6 h6 y8 ff1 fs2 fc0 sc1 ls0 ws0">状态(连接<span class="ff2">√</span>)</div></div><div class="c x3 y9 w2 h7"><div class="t m0 x4 h5 ya ff1 fs2 fc0 sc1 ls0 ws0">连接设备</div></div><div class="c x5 y9 w4 h7"><div class="t m0 x7 h6 ya ff2 fs2 fc0 sc1 ls0 ws0">LSW1</div></div><div class="c x8 y9 w4 h7"><div class="t m0 x7 h6 ya ff2 fs2 fc0 sc1 ls0 ws0">LSW2</div></div><div class="c x9 y9 w4 h7"><div class="t m0 x7 h6 ya ff2 fs2 fc0 sc1 ls0 ws0">LSW3</div></div><div class="c xa y9 w4 h7"><div class="t m0 x7 h6 ya ff2 fs2 fc0 sc1 ls0 ws0">LSW4</div></div><div class="c xb y9 w4 h7"><div class="t m0 x7 h6 ya ff2 fs2 fc0 sc1 ls0 ws0">LSW5</div></div><div class="c xc y9 w5 h7"><div class="t m0 x7 h6 ya ff2 fs2 fc0 sc1 ls0 ws0">LSW6</div></div><div class="c x3 yb w2 h8"><div class="t m0 x7 h6 yc ff2 fs2 fc0 sc1 ls0 ws0">PC1<span class="ff1">、</span>Client1</div></div><div class="c x5 yb w4 h8"><div class="t m0 xd h6 yc ff2 fs2 fc0 sc1 ls0 ws0">√</div></div><div class="c x3 yd w2 h8"><div class="t m0 x7 h6 ye ff2 fs2 fc0 sc1 ls0 ws0">PC2<span class="ff1">、</span>Client2</div></div><div class="c x8 yd w4 h8"><div class="t m0 xd h6 ye ff2 fs2 fc0 sc1 ls0 ws0">√</div></div><div class="c x3 yf w2 h8"><div class="t m0 x7 h6 y10 ff2 fs2 fc0 sc1 ls0 ws0">PC3</div><div class="t m0 xe h5 y11 ff1 fs2 fc0 sc1 ls0 ws0">、</div><div class="t m0 xf h6 y10 ff2 fs2 fc0 sc1 ls0 ws0">Client3</div></div><div class="c x9 yf w4 h8"><div class="t m0 xd h6 y10 ff2 fs2 fc0 sc1 ls0 ws0">√</div></div><div class="c x3 y12 w2 h8"><div class="t m0 x7 h6 yc ff2 fs2 fc0 sc1 ls0 ws0">PC4<span class="ff1">、</span>Client4</div></div><div class="c xa y12 w4 h8"><div class="t m0 xd h6 yc ff2 fs2 fc0 sc1 ls0 ws0">√</div></div><div class="c x3 y13 w2 h8"><div class="t m0 x7 h6 ye ff2 fs2 fc0 sc1 ls0 ws0">PC5<span class="ff1">、</span>Client5</div></div><div class="c xb y13 w4 h8"><div class="t m0 xd h6 ye ff2 fs2 fc0 sc1 ls0 ws0">√</div></div><div class="c x3 y14 w2 h9"><div class="t m0 x7 h6 y15 ff2 fs2 fc0 sc1 ls0 ws0">PC6</div><div class="t m0 xe h5 y16 ff1 fs2 fc0 sc1 ls0 ws0">、</div><div class="t m0 xf h6 y15 ff2 fs2 fc0 sc1 ls0 ws0">Client6</div></div><div class="c xc y14 w5 h9"><div class="t m0 xd h6 y15 ff2 fs2 fc0 sc1 ls0 ws0">√</div></div><div class="t m0 x1 h3 y17 ff1 fs1 fc0 sc1 ls0 ws0">PC<span class="_ _4"> </span>的配置如下,<span class="_ _5"></span>以<span class="_ _4"> </span>PC1<span class="_ _1"> </span>为例,<span class="_ _5"></span>配置<span class="_ _4"> </span>IP<span class="_ _1"> </span>导致、<span class="_ _5"></span>子网掩码和网关,<span class="_ _6"></span>由于属于<span class="_ _1"> </span>VLAN10</div><div class="t m0 x1 h3 y18 ff1 fs1 fc0 sc1 ls0 ws0">网段,将<span class="_ _1"> </span>IP<span class="_ _4"> </span>地址<span class="_ _0"></span>设置为<span class="_ _1"> </span>192.168.10.1、子<span class="_ _0"></span>网掩码设置为<span class="_ _1"> </span>255.255.255.0<span class="_ _0"></span>、网关</div><div class="t m0 x1 h3 y19 ff1 fs1 fc0 sc1 ls0 ws0">设置为<span class="_ _4"> </span>192.168.10.252:</div></div><div class="pi" data-data='{"ctm":[1.611830,0.000000,0.000000,1.611830,0.000000,0.000000]}'></div></div><div id="pf2" class="pf w0 h0" data-page-no="2"><div class="pc pc2 w0 h0"><img class="bi x0 y0 w1 h1" alt="" src="/image.php?url=https://csdnimg.cn/release/download_crawler_static/89501068/bg2.jpg"><div class="t m0 x1 h3 y1a ff1 fs1 fc0 sc1 ls0 ws0">各网络终端<span class="_ _4"> </span>IP<span class="_ _1"> </span>规划表如下:</div><div class="c x10 y1b w6 h8"><div class="t m0 x11 h5 y1c ff1 fs2 fc0 sc1 ls0 ws0">设备名称</div></div><div class="c x12 y1b w7 h8"><div class="t m0 xe h6 y1d ff2 fs2 fc0 sc1 ls0 ws0">IP</div><div class="t m0 x13 h5 y1c ff1 fs2 fc0 sc1 ls0 ws0">地址</div></div><div class="c x14 y1b w7 h8"><div class="t m0 x15 h5 y1c ff1 fs2 fc0 sc1 ls0 ws0">子网掩码</div></div><div class="c x16 y1b w7 h8"><div class="t m0 x17 h5 y1c ff1 fs2 fc0 sc1 ls0 ws0">网关</div></div><div class="c xc y1b w8 h8"><div class="t m0 x15 h6 y1d ff2 fs2 fc0 sc1 ls0 ws0">VLAN<span class="_ _7"> </span>ID</div></div><div class="c x10 y1e w6 h8"><div class="t m0 x18 h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">PC1</div></div><div class="c x12 y1e w7 h8"><div class="t m0 x19 h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">192.168.10.1</div></div><div class="c x14 y1e w7 h8"><div class="t m0 x1a h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">255.255.255.0</div></div><div class="c x16 y1e w7 h8"><div class="t m0 x1b h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">192.168.10.252</div></div><div class="c xc y1e w8 h8"><div class="t m0 x15 h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">VLAN<span class="_ _7"> </span>10</div></div><div class="c x10 y20 w6 h8"><div class="t m0 x1c h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">Client1</div></div><div class="c x12 y20 w7 h8"><div class="t m0 x19 h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">192.168.10.2</div></div><div class="c x14 y20 w7 h8"><div class="t m0 x1a h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">255.255.255.0</div></div><div class="c x16 y20 w7 h8"><div class="t m0 x1b h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">192.168.10.252</div></div><div class="c xc y20 w8 h8"><div class="t m0 x15 h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">VLAN<span class="_ _7"> </span>10</div></div><div class="c x10 y22 w6 h8"><div class="t m0 x18 h6 y1d ff2 fs2 fc0 sc1 ls0 ws0">PC2</div></div><div class="c x12 y22 w7 h8"><div class="t m0 x19 h6 y1d ff2 fs2 fc0 sc1 ls0 ws0">192.168.20.1</div></div><div class="c x14 y22 w7 h8"><div class="t m0 x1a h6 y1d ff2 fs2 fc0 sc1 ls0 ws0">255.255.255.0</div></div><div class="c x16 y22 w7 h8"><div class="t m0 x1b h6 y1d ff2 fs2 fc0 sc1 ls0 ws0">192.168.20.252</div></div><div class="c xc y22 w8 h8"><div class="t m0 x15 h6 y1d ff2 fs2 fc0 sc1 ls0 ws0">VLAN<span class="_ _7"> </span>20</div></div><div class="c x10 y23 w6 h8"><div class="t m0 x1c h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">Client2</div></div><div class="c x12 y23 w7 h8"><div class="t m0 x19 h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">192.168.20.2</div></div><div class="c x14 y23 w7 h8"><div class="t m0 x1a h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">255.255.255.0</div></div><div class="c x16 y23 w7 h8"><div class="t m0 x1b h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">192.168.20.252</div></div><div class="c xc y23 w8 h8"><div class="t m0 x15 h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">VLAN<span class="_ _7"> </span>20</div></div><div class="c x10 y24 w6 h8"><div class="t m0 x18 h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">PC3</div></div><div class="c x12 y24 w7 h8"><div class="t m0 x19 h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">192.168.30.1</div></div><div class="c x14 y24 w7 h8"><div class="t m0 x1a h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">255.255.255.0</div></div><div class="c x16 y24 w7 h8"><div class="t m0 x1b h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">192.168.30.252</div></div><div class="c xc y24 w8 h8"><div class="t m0 x15 h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">VLAN<span class="_ _7"> </span>30</div></div><div class="c x10 y25 w6 h8"><div class="t m0 x1c h6 y1d ff2 fs2 fc0 sc1 ls0 ws0">Client3</div></div><div class="c x12 y25 w7 h8"><div class="t m0 x19 h6 y1d ff2 fs2 fc0 sc1 ls0 ws0">192.168.30.2</div></div><div class="c x14 y25 w7 h8"><div class="t m0 x1a h6 y1d ff2 fs2 fc0 sc1 ls0 ws0">255.255.255.0</div></div><div class="c x16 y25 w7 h8"><div class="t m0 x1b h6 y1d ff2 fs2 fc0 sc1 ls0 ws0">192.168.30.252</div></div><div class="c xc y25 w8 h8"><div class="t m0 x15 h6 y1d ff2 fs2 fc0 sc1 ls0 ws0">VLAN<span class="_ _7"> </span>30</div></div><div class="c x10 y26 w6 h8"><div class="t m0 x18 h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">PC4</div></div><div class="c x12 y26 w7 h8"><div class="t m0 x19 h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">192.168.40.1</div></div><div class="c x14 y26 w7 h8"><div class="t m0 x1a h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">255.255.255.0</div></div><div class="c x16 y26 w7 h8"><div class="t m0 x1b h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">192.168.40.252</div></div><div class="c xc y26 w8 h8"><div class="t m0 x15 h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">VLAN<span class="_ _7"> </span>40</div></div><div class="c x10 y27 w6 h8"><div class="t m0 x1c h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">Client4</div></div><div class="c x12 y27 w7 h8"><div class="t m0 x19 h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">192.168.40.2</div></div><div class="c x14 y27 w7 h8"><div class="t m0 x1a h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">255.255.255.0</div></div><div class="c x16 y27 w7 h8"><div class="t m0 x1b h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">192.168.40.252</div></div><div class="c xc y27 w8 h8"><div class="t m0 x15 h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">VLAN<span class="_ _7"> </span>40</div></div><div class="c x10 y28 w6 h8"><div class="t m0 x18 h6 y1d ff2 fs2 fc0 sc1 ls0 ws0">PC5</div></div><div class="c x12 y28 w7 h8"><div class="t m0 x19 h6 y1d ff2 fs2 fc0 sc1 ls0 ws0">192.168.50.1</div></div><div class="c x14 y28 w7 h8"><div class="t m0 x1a h6 y1d ff2 fs2 fc0 sc1 ls0 ws0">255.255.255.0</div></div><div class="c x16 y28 w7 h8"><div class="t m0 x1b h6 y1d ff2 fs2 fc0 sc1 ls0 ws0">192.168.50.252</div></div><div class="c xc y28 w8 h8"><div class="t m0 x15 h6 y1d ff2 fs2 fc0 sc1 ls0 ws0">VLAN<span class="_ _7"> </span>50</div></div><div class="c x10 y29 w6 h8"><div class="t m0 x1c h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">Client5</div></div><div class="c x12 y29 w7 h8"><div class="t m0 x19 h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">192.168.50.2</div></div><div class="c x14 y29 w7 h8"><div class="t m0 x1a h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">255.255.255.0</div></div><div class="c x16 y29 w7 h8"><div class="t m0 x1b h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">192.168.50.252</div></div><div class="c xc y29 w8 h8"><div class="t m0 x15 h6 y1f ff2 fs2 fc0 sc1 ls0 ws0">VLAN<span class="_ _7"> </span>50</div></div><div class="c x10 y2a w6 h8"><div class="t m0 x18 h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">PC6</div></div><div class="c x12 y2a w7 h8"><div class="t m0 x19 h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">192.168.60.1</div></div><div class="c x14 y2a w7 h8"><div class="t m0 x1a h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">255.255.255.0</div></div><div class="c x16 y2a w7 h8"><div class="t m0 x1b h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">192.168.60.252</div></div><div class="c xc y2a w8 h8"><div class="t m0 x15 h6 y21 ff2 fs2 fc0 sc1 ls0 ws0">VLAN<span class="_ _7"> </span>60</div></div><div class="c x10 y2b w6 h9"><div class="t m0 x1c h6 y2c ff2 fs2 fc0 sc1 ls0 ws0">Client6</div></div><div class="c x12 y2b w7 h9"><div class="t m0 x19 h6 y2c ff2 fs2 fc0 sc1 ls0 ws0">192.168.60.2</div></div><div class="c x14 y2b w7 h9"><div class="t m0 x1a h6 y2c ff2 fs2 fc0 sc1 ls0 ws0">255.255.255.0</div></div><div class="c x16 y2b w7 h9"><div class="t m0 x1b h6 y2c ff2 fs2 fc0 sc1 ls0 ws0">192.168.60.252</div></div><div class="c xc y2b w8 h9"><div class="t m0 x15 h6 y2c ff2 fs2 fc0 sc1 ls0 ws0">VLAN<span class="_ _7"> </span>60</div></div><div class="t m0 x1 h2 y2d ff1 fs0 fc0 sc0 ls0 ws0">(二<span class="_ _0"></span>)远程<span class="_ _0"></span>端测试<span class="_ _0"></span>的可<span class="_ _0"></span>行性</div><div class="t m0 x1 h3 y2e ff1 fs1 fc0 sc1 ls0 ws0">远程端主要的测试如下:</div><div class="t m0 x2 ha y2f ff1 fs1 fc0 sc1 ls0 ws0">主要运用<span class="ff3">ping</span>命令,<span class="_ _8"></span>其原理是使用<span class="ff3">ICMP</span>差错报告报文的回送请求和回答进行</div><div class="t m0 x1 h3 y30 ff1 fs1 fc0 sc1 ls0 ws0">测试,<span class="_ _6"></span>该命令通常除了测试网络连通性,<span class="_ _6"></span>也还可以测试网络的速度,<span class="_ _9"></span>同时其中返</div><div class="t m0 x1 ha y31 ff1 fs1 fc0 sc1 ls0 ws0">回的<span class="ff3">TTL</span>值以及<span class="ff3">TIME</span>值可以查看具体数据包经过的网段数量和反应时长。</div><div class="t m0 x2 h3 y32 ff1 fs1 fc0 sc1 ls0 ws0">在本企业园区中,<span class="_ _8"></span>需要进行以下测试项目:<span class="_ _8"></span>内网主机内网互通测试、<span class="_ _8"></span>内网主</div><div class="t m0 x1 h3 y33 ff1 fs1 fc0 sc1 ls0 ws0">机外网互通测试、<span class="_ _3"></span>无线网络主机内网测试、<span class="_ _3"></span>无线网络主机外网测试和互联网主机</div><div class="t m0 x1 h3 y34 ff1 fs1 fc0 sc1 ls0 ws0">内网互通测试,由于在防火墙配置了相应的策略,预测会有以下情况:</div><div class="t m0 x2 ha y35 ff3 fs1 fc0 sc1 ls0 ws0">①<span class="ff1">内<span class="_ _0"></span>网主<span class="_ _0"></span>机<span class="_ _0"></span>内<span class="_ _0"></span>网<span class="_ _0"></span>互通<span class="_ _0"></span>测<span class="_ _0"></span>试<span class="_ _0"></span>:<span class="_ _0"></span>由于<span class="_ _0"></span>各<span class="_ _0"></span>个<span class="_ _0"></span>部<span class="_ _0"></span>门之<span class="_ _0"></span>间<span class="_ _0"></span>在各<span class="_ _0"></span>部<span class="_ _0"></span>门<span class="_ _0"></span>的交<span class="_ _0"></span>换<span class="_ _0"></span>机<span class="_ _0"></span>上配<span class="_ _0"></span>置<span class="_ _0"></span>的</span></div><div class="t m0 x1 ha y36 ff3 fs1 fc0 sc1 ls0 ws0">VLAN<span class="ff1">是互通的,当使用</span>p<span class="_ _0"></span>ing<span class="ff1">命令测试本</span>V<span class="_ _0"></span>LAN<span class="ff1">至本</span>VLAN<span class="ff1">以及至其他部门</span>VLA<span class="_ _0"></span>N<span class="ff1">时,</span></div><div class="t m0 x1 h3 y37 ff1 fs1 fc0 sc1 ls0 ws0">是都可到达的;</div><div class="t m0 x2 ha y38 ff3 fs1 fc0 sc1 ls0 ws0">②<span class="ff1">内网主机外网互通测试:<span class="_ _a"></span>由于在防火墙上配置了相关的策略,<span class="_ _a"></span>允许各部门</span></div><div class="t m0 x1 ha y39 ff1 fs1 fc0 sc1 ls0 ws0">的<span class="ff3">VLAN</span>可通过防火墙接口<span class="ff3">GE1/0/2<span class="_ _0"></span></span>传输数据流量至<span class="ff3">ISP</span>区域内的网络设备,<span class="_ _a"></span>所以是</div><div class="t m0 x1 h3 y3a ff1 fs1 fc0 sc1 ls0 ws0">可到达的;</div><div class="t m0 x2 ha y3b ff3 fs1 fc0 sc1 ls0 ws0">③<span class="ff1">无线网络主机内、<span class="_ _a"></span>外网测试:<span class="_ _a"></span>由于处于无线局域网内的无线网络的安全策</span></div><div class="t m0 x1 ha y3c ff1 fs1 fc0 sc1 ls0 ws0">略与各部门之间的网络设备一样,所以其情况与<span class="ff3">①</span>、<span class="ff3">②</span>相同,也是可到达的;</div><div class="t m0 x2 ha y3d ff3 fs1 fc0 sc1 ls0 ws0">④<span class="ff1">互联<span class="_ _0"></span>网主机内<span class="_ _0"></span>网互<span class="_ _0"></span>通测试<span class="_ _0"></span>:<span class="_ _0"></span></span>ISP<span class="ff1">属于<span class="_ _0"></span></span>Untrust<span class="ff1">区域,<span class="_ _0"></span>由于设置<span class="_ _0"></span>了相<span class="_ _0"></span>关的安<span class="_ _0"></span>全</span></div><div class="t m0 x1 ha y3e ff1 fs1 fc0 sc1 ls0 ws0">策略,来自该区域的数据流量无法保证一定的安全<span class="_ _0"></span>性,所以互联网主机<span class="ff3">ISP<span class="_ _0"></span>-PC</span>使</div><div class="t m0 x1 ha y3f ff1 fs1 fc0 sc1 ls0 ws0">用<span class="ff3">ping</span>命令测试到内网主机和客户端是无法到达的。</div></div><div class="pi" data-data='{"ctm":[1.611830,0.000000,0.000000,1.611830,0.000000,0.000000]}'></div></div><div id="pf3" class="pf w0 h0" data-page-no="3"><div class="pc pc3 w0 h0"><img class="bi x0 y0 w1 h1" alt="" src="/image.php?url=https://csdnimg.cn/release/download_crawler_static/89501068/bg3.jpg"><div class="t m0 x1 h2 y40 ff1 fs0 fc0 sc0 ls0 ws0">(二<span class="_ _0"></span>)远程<span class="_ _0"></span>端测试</div><div class="t m0 x1 h3 y41 ff1 fs1 fc0 sc1 ls0 ws0">验证结果如下:</div><div class="t m0 x2 ha y42 ff1 fs1 fc0 sc1 ls0 ws0">(<span class="ff3">1</span>)<span class="_ _3"></span>内网主机内网互通<span class="_ _0"></span>测试,<span class="_ _b"></span>由于各部门的交换机都有配置了相应的<span class="ff3">VLAN</span>,</div><div class="t m0 x1 ha y43 ff1 fs1 fc0 sc1 ls0 ws0">所以各<span class="_ _0"></span>部门<span class="_ _0"></span>主机<span class="_ _0"></span>之间<span class="_ _0"></span>是可以<span class="_ _0"></span>互相<span class="_ _0"></span>正常<span class="_ _0"></span>访问<span class="_ _0"></span>的。以<span class="_ _0"></span>行政<span class="_ _0"></span>部的<span class="_ _0"></span><span class="ff3">PC1</span>为<span class="_ _0"></span>例,<span class="_ _0"></span>在<span class="ff3">PC1</span>的<span class="_ _0"></span><span class="ff3">CLI</span></div><div class="t m0 x1 ha y44 ff1 fs1 fc0 sc1 ls0 ws0">中输入<span class="ff3">p<span class="_ _0"></span>ing</span>命<span class="_ _0"></span>令后<span class="_ _0"></span>加上<span class="_ _0"></span>相应<span class="ff3">PC2<span class="_ _0"></span></span>的<span class="ff3">IP<span class="_ _0"></span></span>地址<span class="ff3">19<span class="_ _0"></span>2.168.20.1</span>,<span class="_ _0"></span>此时使<span class="_ _0"></span>用的<span class="_ _0"></span>是默<span class="_ _0"></span>认发<span class="_ _0"></span>送的</div><div class="t m0 x1 ha y45 ff1 fs1 fc0 sc1 ls0 ws0">相应大小数据包<span class="_ _8"></span>(<span class="_ _c"></span>即不配置任何参数的<span class="ff3">ping</span>命令)<span class="_ _8"></span>传输至财务部的<span class="ff3">PC2</span>,<span class="_ _5"></span>如下图:</div><div class="t m0 x2 ha y46 ff1 fs1 fc0 sc1 ls0 ws0">经过测试网络<span class="_ _0"></span>可达,且<span class="_ _1"> </span><span class="ff3">0.00%</span>丢包率,<span class="_ _0"></span>发送的包<span class="_ _0"></span>均可达,内<span class="_ _0"></span>网主机内网互通</div><div class="t m0 x1 h3 y47 ff1 fs1 fc0 sc1 ls0 ws0">测试成功,符合预期!</div><div class="t m0 x2 ha y48 ff1 fs1 fc0 sc1 ls0 ws0">(<span class="ff3">2</span>)<span class="_ _5"></span>内网主机外网互通<span class="_ _0"></span>测试,<span class="_ _8"></span>各部门主机可正常访问外网。<span class="_ _5"></span>以行政部的<span class="ff3">PC1</span></div><div class="t m0 x1 ha y49 ff1 fs1 fc0 sc1 ls0 ws0">为例,在<span class="ff3">PC1</span>的<span class="ff3">CLI</span>中输入<span class="ff3">ping</span>命令加上相应<span class="ff3">ISP-PC</span>的<span class="ff3">IP</span>地址<span class="ff3">200.10.20.2</span>,如下图:</div></div><div class="pi" data-data='{"ctm":[1.611830,0.000000,0.000000,1.611830,0.000000,0.000000]}'></div></div><div id="pf4" class="pf w0 h0" data-page-no="4"><div class="pc pc4 w0 h0"><img class="bi x0 y0 w1 h1" alt="" src="/image.php?url=https://csdnimg.cn/release/download_crawler_static/89501068/bg4.jpg"><div class="t m0 x2 ha y1a ff1 fs1 fc0 sc1 ls0 ws0">经过测试网络<span class="_ _0"></span>可达,且<span class="_ _1"> </span><span class="ff3">0.00%</span>丢包率,<span class="_ _0"></span>发送的包<span class="_ _0"></span>均可达,<span class="_ _0"></span>内网主机<span class="_ _0"></span>外网互通</div><div class="t m0 x1 h3 y4a ff1 fs1 fc0 sc1 ls0 ws0">测试成功,符合预期!</div><div class="t m0 x2 ha y4b ff1 fs1 fc0 sc1 ls0 ws0">(<span class="ff3">3</span>)无线网络主机内、外网测试,无线局域网内的无线设备与部门间的<span class="_ _4"> </span><span class="ff3">P<span class="_ _0"></span>C</span></div><div class="t m0 x1 ha y4c ff1 fs1 fc0 sc1 ls0 ws0">一<span class="_ _0"></span>样<span class="_ _0"></span>的<span class="_ _0"></span>安<span class="_ _0"></span>全<span class="_ _d"></span>策略<span class="_ _d"></span>,<span class="_ _0"></span>可<span class="_ _0"></span>正<span class="_ _0"></span>常<span class="_ _0"></span>访<span class="_ _d"></span>问内<span class="_ _d"></span>、<span class="_ _0"></span>外<span class="_ _0"></span>网<span class="_ _0"></span>。<span class="_ _0"></span>以<span class="_ _d"></span>无线<span class="_ _d"></span>局<span class="_ _0"></span>域<span class="_ _0"></span>网<span class="_ _0"></span>的<span class="_ _2"> </span><span class="ff3">STA1<span class="_ _2"> </span></span>为<span class="_ _0"></span>例<span class="_ _0"></span>,<span class="_ _0"></span>在<span class="_ _2"> </span><span class="ff3">STA1</span></div><div class="t m0 x1 ha y4d ff1 fs1 fc0 sc1 ls0 ws0">的<span class="_ _1"> </span><span class="ff3">CLI<span class="_ _2"> </span></span>中<span class="_ _d"></span>输<span class="_ _0"></span>入<span class="_ _2"> </span><span class="ff3">ping<span class="_ _1"> </span></span>命<span class="_ _d"></span>令<span class="_ _0"></span>加<span class="_ _d"></span>上<span class="_ _0"></span>相<span class="_ _0"></span>应<span class="_ _d"></span>行<span class="_ _0"></span>政<span class="_ _0"></span>部<span class="_ _2"> </span><span class="ff3">P<span class="_ _0"></span>C1<span class="_ _1"> </span></span>的<span class="_ _2"> </span><span class="ff3">IP<span class="_ _2"> </span></span>地<span class="_ _0"></span>址<span class="_ _2"> </span><span class="ff3">19<span class="_ _0"></span>2.168.10.1<span class="_ _1"> </span></span>以<span class="_ _d"></span>及<span class="_ _1"> </span><span class="ff3">ISP-<span class="_ _0"></span>PC</span></div><div class="t m0 x1 ha y4e ff1 fs1 fc0 sc1 ls0 ws0">的<span class="_ _4"> </span><span class="ff3">IP<span class="_ _1"> </span></span>地址<span class="_ _4"> </span><span class="ff3">2<span class="_ _0"></span>00.10.20.2</span>,如下图:</div><div class="t m0 x2 ha y4f ff1 fs1 fc0 sc1 ls0 ws0">经过测试网络<span class="_ _0"></span>可达,且<span class="_ _1"> </span><span class="ff3">0.00%</span>丢包率,<span class="_ _0"></span>发送的包<span class="_ _0"></span>均可达,<span class="_ _0"></span>无线网络<span class="_ _0"></span>主机内网</div><div class="t m0 x1 h3 y50 ff1 fs1 fc0 sc1 ls0 ws0">互通测试成功,符合预期!</div><div class="t m0 x2 ha y51 ff1 fs1 fc0 sc1 ls0 ws0">经过测试网络<span class="_ _0"></span>可达,且<span class="_ _1"> </span><span class="ff3">0.00%</span>丢包率,<span class="_ _0"></span>发送的包<span class="_ _0"></span>均可达,<span class="_ _0"></span>无线网络<span class="_ _0"></span>主机外网</div><div class="t m0 x1 h3 y52 ff1 fs1 fc0 sc1 ls0 ws0">互通测试成功,符合预期!</div></div><div class="pi" data-data='{"ctm":[1.611830,0.000000,0.000000,1.611830,0.000000,0.000000]}'></div></div><div id="pf5" class="pf w0 h0" data-page-no="5"><div class="pc pc5 w0 h0"><img class="bi x0 y0 w1 h1" alt="" src="/image.php?url=https://csdnimg.cn/release/download_crawler_static/89501068/bg5.jpg"><div class="t m0 x2 ha y1a ff1 fs1 fc0 sc1 ls0 ws0">(<span class="ff3">4</span>)互联网主机内网互通测<span class="_ _0"></span>试,互联网主机<span class="_ _4"> </span><span class="ff3">ISP-<span class="_ _0"></span>PC<span class="_ _4"> </span></span>无法<span class="_ _1"> </span><span class="ff3">ping<span class="_ _4"> </span></span>通企业内<span class="_ _0"></span>网主</div><div class="t m0 x1 ha y4a ff1 fs1 fc0 sc1 ls0 ws0">机<span class="_ _e"> </span><span class="ff3">PC1<span class="_ _f"> </span></span>,<span class="_ _f"> </span>在<span class="_ _e"> </span><span class="ff3">ISP-PC<span class="_ _e"> </span></span>的<span class="_ _e"> </span><span class="ff3">CLI<span class="_ _e"> </span></span>中<span class="_ _f"> </span>输<span class="_ _f"> </span>入<span class="_ _e"> </span><span class="ff3">ping<span class="_ _e"> </span></span>命<span class="_ _f"> </span>令<span class="_ _f"> </span>加<span class="_ _f"> </span>上<span class="_ _10"> </span>相<span class="_ _f"> </span>应<span class="_ _10"> </span>行<span class="_ _f"> </span>政<span class="_ _f"> </span>部<span class="_ _e"> </span><span class="ff3">PC1<span class="_ _e"> </span></span>的<span class="_ _e"> </span><span class="ff3">IP<span class="_ _e"> </span></span>地<span class="_ _f"> </span>址</div><div class="t m0 x1 ha y4b ff3 fs1 fc0 sc1 ls0 ws0">192.168.10.1<span class="ff1">,如下图。</span></div><div class="t m0 x2 h3 y53 ff1 fs1 fc0 sc1 ls0 ws0">由于配置的相关安全策略中外网是无法访问内网主机的,<span class="_ _9"></span>所以经过测试网络</div><div class="t m0 x1 ha y54 ff1 fs1 fc0 sc1 ls0 ws0">是不可达,<span class="_ _a"></span>显示<span class="_ _1"> </span><span class="ff3">Request<span class="_ _4"> </span>timeout<span class="_ _4"> </span></span>请求超时,<span class="_ _a"></span><span class="ff3">10<span class="_ _0"></span>0.00%<span class="ff1">丢包率,<span class="_ _a"></span>发送的<span class="_ _0"></span>包均不可达,</span></span></div><div class="t m0 x1 h3 y55 ff1 fs1 fc0 sc1 ls0 ws0">无线网络主机外网互通测试不成功,符合预期!</div><div class="t m0 x1 h2 y56 ff1 fs0 fc0 sc0 ls0 ws0">二、防<span class="_ _0"></span>火墙<span class="_ _0"></span>策略及<span class="_ _0"></span>配置</div><div class="t m0 x1 h2 y57 ff1 fs0 fc0 sc0 ls0 ws0">(一<span class="_ _0"></span>)区域<span class="_ _0"></span>划分和<span class="_ _0"></span>分析</div><div class="t m0 x2 ha y58 ff1 fs1 fc0 sc1 ls0 ws0">对于防火墙、核心路由器、三层交换机、二层交换机的相关<span class="_ _4"> </span><span class="ff3">IP<span class="_ _1"> </span></span>规划如下表,</div><div class="t m0 x1 ha y59 ff1 fs1 fc0 sc1 ls0 ws0">其中每个网络设备对应的端口<span class="_ _1"> </span><span class="ff3">IP<span class="_ _4"> </span></span>需通过先通过<span class="_ _0"></span>命令<span class="_ _a"></span>“<span class="ff3">intface</span>”<span class="_ _a"></span>进入相应的端口进</div><div class="t m0 x1 ha y5a ff1 fs1 fc0 sc1 ls0 ws0">行配置<span class="_ _1"> </span><span class="ff3">IP<span class="_ _1"> </span></span>地<span class="_ _0"></span>址和子<span class="_ _0"></span>网掩<span class="_ _0"></span>码。<span class="_ _0"></span>相应<span class="_ _0"></span>端口对<span class="_ _0"></span>接的<span class="_ _0"></span>防火<span class="_ _0"></span>墙安<span class="_ _0"></span>全级<span class="_ _0"></span>别默<span class="_ _0"></span>认区<span class="_ _0"></span>域对<span class="_ _0"></span>应表中</div><div class="t m0 x1 ha y5b ff1 fs1 fc0 sc1 ls0 ws0">的业务描述,<span class="_ _9"></span>其中<span class="_ _1"> </span><span class="ff3">T<span class="_ _8"></span>rust<span class="_ _4"> </span><span class="ff1">对应受信区域、<span class="_ _9"></span><span class="ff3">Untrust<span class="_ _4"> </span><span class="ff1">对应非受信区域、<span class="_ _6"></span><span class="ff3">DMZ<span class="_ _4"> </span><span class="ff1">对应非军</span></span></span></span></span></span></div><div class="t m0 x1 ha y5c ff1 fs1 fc0 sc1 ls0 ws0">事化区域,防火墙<span class="_ _4"> </span><span class="ff3">FW1<span class="_ _1"> </span></span>各个接口的<span class="_ _4"> </span><span class="ff3">IP<span class="_ _1"> </span></span>地址以及子网掩码规划如下表:</div></div><div class="pi" data-data='{"ctm":[1.611830,0.000000,0.000000,1.611830,0.000000,0.000000]}'></div></div>