Sie sind auf Seite 1von 2

eNSP Test Instruction of Test B

eNSP Test Instruction of Test B


Background:

There are two branches in the company. We want to make the configuration to let these two branches to
communicate with each other. And also the company want to communicate with the Internet.

Networking Instruction:

1 * AR2220 router, 2 * S5700 switches, 1 * USG6000V firewall (password: huawei123)

Device Name Interface IP address


SW1 Vlan-if 10 192.168.10.1/24
SW1 Vlan-if 20 192.168.20.1/24
SW1 Vlan-if 30 192.168.30.2/24
R1 G0/0/0 192.168.30.1/24
R1 G0/0/1 192.168.40.1/24
FW1 G1/0/0 192.168.40.2/24
FW1 G1/0/1 100.1.1.1/24
INTERNET G0/0/0 100.1.1.2/24
INTETNET Loopback 0 1.1.1.1/32

Note: Please follow the instruction to configure the device name, policy ID, pool name, etc. Do not make the
other naming by yourself. Otherwise you will get no point at that configuration.
eNSP Test Instruction of Test B

Requirements:

1. Configure IP addresses and names of network devices according to the addressing table above. (10 points)
2. Create VLANs on switches: VLAN10 and VLAN20 on SW1 and SW2. G0/0/3 of SW1 is in VLAN10, G0/0/3
of SW2 is in VLAN20. (10 points)
3. Create Eth-Trunk: Configure link aggregation with the name “1” on SW1 and SW2. Configure this Eth-Trunk
to work in static LACP mode and only allow VLAN10 and VLAN20 to pass. (10 points)
4. Create L3 port on SW1: (5 points)
a) VLAN10 management IP: 192.168.10.1/24
b) VLAN20 management IP: 192.168.20.1/24
c) VLAN30 management IP: 192.168.30.1/24, and Assign G0/0/4 to VLAN30
5. Enable the DHCP service in the SW1: (10 points)
a) Create pool1:192.168.10.0/24 and pool2:192.168.20.0/24, both are global address pools.
b) Set DNS 8.8.8.8 for both two pools.
c) Set the gateway configuration (by using Switch VLANIF address) for both two pools.
d) Lease time is 2 days for both two pools.
6. For FW1, assign G1/0/0 into trust zone, assign G1/0/1 into untrusted zone. When configure the OSPF for
FW need to set security policy, name the policy to OSPF, in policy allow traffic to forward from trust zone
to local zone. (10 points)
7. Deploy the OSPF on FW1, R1 and SW1, all OSPF interfaces belong to area 0. When network the interface
use wild mask 0.0.0.255. (15 points):
a) Network VLANIF 10, VLANIF 20, VLANIF 30 on SW1
b) Network G0/0/1 and G0/0/0 on R1
c) Network G1/0/0 on FW1
8. Set R1 as telnet server, set password to huawei123 and set the password to be stored in ciphertext.(5
points)
9. Configure the static route entry on FW1, R1, SW1, so that the traffic can send to public network. Configure
the security policy on firewall and name it outside, allow traffic forward from trust zone to untrusted zone.
(10 points)
10. Configure the NAPT on FW1, name the address pool huawei, only one address (100.1.1.10) in this address
pool, name the policy nat and only allow the traffic from 192.168.10.0/24 and 192.168.20.0/24 can
forward to Internet(use 1.1.1.1/32 as Internet Server) (15 points)

After all the configuration, you can use ping to test connectivity of PC1 and PC2. And you can ping internet
Server from both PC1 and PC2

Das könnte Ihnen auch gefallen