1.配置公網,使其連通
[dianxin-Serial4/0/0]ip add 12.1.1.2 24
[dianxin-Serial4/0/1]ip add 23.1.1.2 24
[dianxin-LoopBack0]ip ad 2.2.2.2 32
[dianxin]rip
[dianxin-rip-1]version 2
[dianxin-rip-1]undo summary
[dianxin-rip-1]network 23.0.0.0
[dianxin-rip-1]network 12.0.0.0
[dianxin-rip-1]network 2.0.0.0
[yidong-Serial4/0/0]ip add 23.1.1.3 24
[yidong-Serial4/0/1]ip add 13.1.1.3 24
[yidong-LoopBack0]ip add 3.3.3.3 32
[yidong]rip
[yidong-rip-1]version 2
[yidong-rip-1]undo summary
[yidong-rip-1]network 3.0.0.0
[yidong-rip-1]network 23.0.0.0
[yidong-rip-1]network 13.0.0.0
[AR1-Serial4/0/0]ip add 12.1.1.1 24
[AR1-Serial4/0/1]ip add 13.1.1.1 24
[AR1]rip 1
[AR1-rip-1]version 2
[AR1-rip-1]ud
[AR1-rip-1]undo summary
[AR1-rip-1]network 12.0.0.0
[AR1-rip-1]network 13.0.0.0
2.配置內網地址及劃分vlan
[AR1-GigabitEthernet0/0/1]ip add 14.1.1.1 24
[AR1-GigabitEthernet0/0/2]ip add 15.1.1.1 24
[SW1]vlan 10
[SW1]int Vlanif 10
[SW1-Vlanif10]ip add 192.168.10.254 24
[SW1-GigabitEthernet0/0/2]port link-type access
[SW1-GigabitEthernet0/0/2]port default vlan 10
[SW1-GigabitEthernet0/0/1]port link-type trunk
[SW1-GigabitEthernet0/0/1]port trunk allow-pass vlan all
[SW2-GigabitEthernet0/0/1]port link-type access
[SW2-GigabitEthernet0/0/1]port default vlan 20
[SW2]int Vlanif 20
[SW2-Vlanif20]ip address 192.168.20.254 24
[SW2-GigabitEthernet0/0/2]port link-type trunk
[SW2-GigabitEthernet0/0/2]port trunk allow-pass vlan all
3.配置內網及OSPF
[AR1-ospf-1-area-0.0.0.0]network 14.1.1.0 0.0.0.255
[AR1-ospf-1-area-0.0.0.0]network 15.1.1.0 0.0.0.255
[AR1-ospf-1]default-route-advertise //向ospf自治系統中引入默認路由
[SW1-ospf-1-area-0.0.0.0]network 192.168.10.0 0.0.0.255
[SW1-Vlanif1]ip add 14.1.1.4 24
[SW1-ospf-1-area-0.0.0.0]network 14.1.1.0 0.0.0.255
[SW2-Vlanif1]ip add 15.1.1.5 24
[SW2-ospf-1-area-0.0.0.0]network 15.1.1.0 0.0.0.255
[SW2-ospf-1-area-0.0.0.0]network 192.168.20.0 0.0.0.255
4.配置NAT
[AR1-acl-basic-2000]rule permit source 192.168.10.0 0.0.0.255
[AR1-acl-basic-2000]rule permit source 192.168.20.0 0.0.0.255
[AR1-Serial4/0/0]nat outbound 2000
[AR1-Serial4/0/1]nat outbound 2000
5.經過配置路由策略,調整數據流量方向
[AR1]ip route-static 0.0.0.0 0.0.0.0 13.1.1.3
[AR1]ip route-static 0.0.0.0 0.0.0.0 12.1.1.2 //配置兩條靜態路由,用於鏈路故障時自動切換
[AR1-acl-basic-2001]rule permit source 192.168.20.0 0.0.0.255
[AR1-acl-basic-2002]rule permit source 192.168.10.0 0.0.0.255
[AR1]traffic classifier pc1
[AR1-classifier-pc1]if-match acl 2002
[AR1]traffic behavior pc1
[AR1-behavior-pc1]redirect ip-nexthop 12.1.1.2
[AR1]traffic policy pc1
[AR1-trafficpolicy-pc1]classifier pc1 behavior pc1
[AR1-GigabitEthernet0/0/1]traffic-policy pc1 inbound
[AR1]traffic classifier pc2
[AR1-classifier-pc2]if-match acl 2001
[AR1]traffic behavior pc2
[AR1-behavior-pc2]redirect ip-nexthop 13.1.1.3
[AR1]traffic policy pc2
[AR1-trafficpolicy-pc2]classifier pc2 behavior pc2
[AR1-GigabitEthernet0/0/2]traffic-policy pc2 inboundide