: Internet
NAT- 1/3
DGS-3324SR:
1. IP- “Basic IP Route”.
2., -
-: create iproute default 192.168.1.1
3.- RIP, RIP DGS3324SR :
config rip ipif all tx_mode v2_only rx_mode v2_only state enable enable rip
- (NAT-) Proxy-:
1. RIP, RIP LAN-.
2. RIP , (2 3, 4), Internet.
192.168.2.0 mask 255.255.255.0 192.168.1.254 192.168.3.0 mask 255.255.255.0 192.168.1.254
(4 Internet,
4).
PC: 1. DNS = DNS- ISP
.
: 1/4
L3
V2 V3 V4
(,
, Internet)
, (/).
L2: 802.1q Asymmetric VLAN Traffic Segmentation
L3: L3 + ACL
.
: 2/4
1 2 3 4
DGS-3324SR
.254 .254 .254 .254
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
192.168.1.x/24 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|||||||||||||||||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
||||||||||||||||||||||
|
|
192.168.2.x/24 |
|
|
192.168.3.x/24 |
192.168.4.x/24 |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
192.168.1.254 |
|
|
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
192.168.2.254 |
|
|
192.168.3.254 |
192.168.4.254 |
:
4 (192.168.4.x) -
2, 3, 4.
2, 3, 4 .
:
: |
3/4 |
1. IP- = 192.168.4.x,
2. IP- = 192.168.4.x,
3. IP- = 192.168.1.x IP- = 192.168.1.x,
4. IP- = 192.168.2.x IP- = 192.168.2.x,
5. IP- = 192.168.3.x IP- =192.168.3.x,
6.
# |
|
|
|
192.168.4.x |
|
# |
||
create access_profile ip destination_ip_mask 255.255.255.0 profile_id |
||
config access_profile profile_id 1 add access_id 1 ip destination_ip 192.168.4.0 port 1:1 permit |
||
config access_profile profile_id 1 add access_id 2 ip destination_ip 192.168.4.0 port 1:7 permit |
||
config access_profile profile_id 1 add access_id 3 ip destination_ip 192.168.4.0 port 1:13 permit |
||
config access_profile profile_id 1 add access_id 4 ip destination_ip 192.168.4.0 port 1:19 permit |
||
# |
|
|
192.168.1.x, 192.168.2.x 192.168.3.x |
||
create access_profile ip source_ip_mask 255.255.255.0 destination_ip_mask 255.255.255.0 profile_id 2 |
||
config access_profile profile_id 2 add access_id 1 ip source_ip 192.168.1.0 destination_ip 192.168.1.0 port 1:1 permit |
||
config access_profile profile_id 2 add access_id 2 ip source_ip 192.168.2.0 destination_ip 192.168.2.0 port 1:7 permit |
||
config access_profile profile_id 2 add access_id 3 ip source_ip 192.168.3.0 destination_ip 192.168.3.0 port 1:13 permit |
||
config access_profile profile_id 2 add access_id 4 ip source_ip 192.168.4.0 destination_ip 192.168.4.0 port 1:19 permit |
||
#### |
||
# |
|
|
create access_profile ip source_ip_mask 0.0.0.0 profile_id 3 |
||
config access_profile profile_id 3 add access_id 1 ip source_ip 0.0.0.0 port 1:1 deny |
||
config access_profile profile_id 3 add access_id 2 ip source_ip 0.0.0.0 port 1:7 deny |
||
config access_profile profile_id 3 add access_id 3 ip source_ip 0.0.0.0 port 1:13 deny |
||
config access_profile profile_id 3 add access_id 4 ip source_ip 0.0.0.0 port 1:19 deny |
: 4/4
:
1.PC 1 (192.168.2.x), 2, 3 4 (192.168.4.x).
2.1, 2, 3 .
:
DHCP/Bootp Relay 1/3
DGS-3324SR:
1. IP- “BasicIPRoute”: enable bootp_relay
config bootp_relay add ipif net1 192.168.4.2 config bootp_relay add ipif net2 192.168.4.2 config bootp_relay add ipif net3 192.168.4.2
DHCP- (, WinNT4 Win2000 Advanced Server):
1. DHCP Server Service
2. “Scope” .
PC:
1. TCP/IP :
IP-.