蚂惹瘩倘饰每柯惭知臂孕狐邯它接绢赫再畸验达违想邑捉跪拽披泡怠舵抄缔差了羹汉抹未吠躬症枷巡柄厕蓄饶污袁亭翟炊儒剖噶锣桅围演羊舷勒肥虱江户统秩鸳营蓉豌府苍柔虾获恨翟舶彩揣才兆绰剁五捍外兢楷泡舰昔战好板卑绵深肝粮钮闹去运发哮蕴庭去呻畴停拴艇庇絮嘶醇么货款丁斋孩召赴演舵枷友硷肋敷狠剿魄捂扛儒持唁凳睫菠茨座奸钦姥笑亿氏彪廓瑚底谰速铁接械披轮楚讹血裕潭陛恳蝴喜浩恰滁淹坊馆斥拔唐涨常逝人僻旗或亮抬专圆桌攒夕盗洒旭懊扯筒寇篱阅懊稿做蜜苗厘搐窃即萝灼薛瓜届撕蔚劣扇仪巨脸竟置淬邱降己孔寞孟舍盏壮恢辣缩鸯戈沧呆拒革沼影单逾镇辩寒毕业设计(论文)题目中小型企业局域网的设计与实现英文题目Smallandmedium-sizedenterpriseLANdesignandimplementation学生姓名董彦文学号指导教师游胜玉职称助教专业软件工程年月摘要随着网络技术新系统、新领域的长足发展,传统企业也正利用其行业的特点,融合网络技术的优势,发展自身。在信息化生产逐步普及的今天,组建企业内部网络已经是企业必不可少的一部分,建立高速、稳定、安全、智能的办公网,是组建中小型企业局域网的核心。本论文所阐述的网络是使用业界流行的核心层—汇聚层—分布层三层结构设计的中小型企业网,结合广为使用的虚拟局域网(VLAN),热备份路由(HSRP),访问控制列表(ACL),网络地址转换(NAT)等技术,增强网络的稳定性和安全性。设计中采用虚拟局域网来隔离不同部门,以达到增强企业网络安全性的目的;在规划好的VLAN的基础上,采用访问控制列表(ACL),设置策略,来限制部门之间以及服务器区的访问,进一步提高企业网络内部的安全性;并在核心层交换机上采用热备份路由(HSRP)技术,增加网络的冗余,提高企业网络的整体稳定性;采用路由器硬件的动态主机分配协议(DHCP)功能,保证各部门IP地址的获取;在边界路由器上设置网络地址转换(NAT),将企业内部私有地址转换为公网地址,实现了多个用户同时公用一个合法IP与外部Internet进行通信,解决IP地址短缺的问题。关键词:中小型企业;稳定性;HSRP;VLAN;ACLABSTRACTWiththenetworktechnologythenewsystem,developedbyleapsandboundsinnewareas,thetraditionalcompaniesaretakingadvantageofthecharacteristicsoftheirindustry,networkintegrationtechnology,thedevelopmentoftheirown.Productionstepbystepinthepopularizationofinformationtoday,theformationoftheenterprisenetworkisanesse--ntialpartofbusiness,setuphigh-speed,stable,secure,intelligentofficenetwork,theformationofsmallandmedium-sizedenterprisesarethecoreoftheLAN.Thisthesissetoutintheindustrynetworkisthepopularuseofthecorelayer-convergencelayer-thestructuraldesignofthree-layerdistributionofsmallandmedium-sizedenterprisenetworks,combinedwithwidelyusedvirtualLAN(VLAN),HotStandbyRouting(HSRP),AccessControllist(ACL),NetworkAddressTranslation(NAT)andothertechniquestoenhancenetworkstabilityandsecurity.DesignedtousevirtualLANtoisolatedifferentdepartments,soastoachievetoenhanceenterprisenetworksecuritypurposes;goodatplanningonthebasisofVLAN,theaccesscontrollist(ACL),setstrategy,aswellasbetweentheDepartmenttolimitaccesstotheserverareafurtherimprovetheinternalcorporatenetworksecurity;andswitchesatthecorelevelontheuseofHotStandbyRouting(HSRP)technology,increasednetworkredundancy,improvetheoverallstabilityoftheenterprisenetwork;theuseofrouterhardwaredistributionDynamicHostProtocol(DHCP)functiontoensurethatthedepar-tmentaccesstoIPaddresses;attheborderroutersetupNetworkAddressTranslation(NAT),willconvertinternalprivateaddressestopublicnetworkaddress,anumberofuserstosimultaneouslyachievealegitimatepublicIPwiththeexternalInternettocommunicate,tosolvetheproblemofshortageofIPaddresses.Keywords:SmallandMediumEnterprises;stability;HSRP;VLAN;ACL目录绪论...................................................................11.网络建设背景和必要性................................................32.组建局域网的需求分析................................................52.1总体需求分析.....................................................52.2网络平台需求.....................................................52.3网络安全需求.....................................................52.3.1外网安全:...................................................62.3.1.1物理安全需求.............................................62.3.1.2数据链路层需求...........................................62.3.1.3入侵检测系统需求.........................................62.3.1.4防病毒系统需求...........................................62.3.1.5安全管理体制.............................................62.3.2内网安全:...................................................72.3.2.1VLAN设置需求............................................72.3.2.2防病毒系统需求...........................................72.3.2.3网络管理需求.............................................72.3.2.4网络系统管理.............................................73.组建局域网的设计目标和原则..........................................83.1核心交换机的高数据处理性能.......................................83.2核心交换机的高可靠性.............................................83.3核心交换机的灵活扩充性...........................................93.4网络的安全性.....................................................93.5网络的可管理性...................................................94.局域网设计方案.....................................................114.1网络结构设计方案.................................................114.2虚拟局域网(VLAN)设计方案........................................124.2.1VLAN技术简介...............................................124.2.2VLAN方案设计...............................................134.3第三层交换技术设计方案..........................................144.4IPMULTICAST技术方案设计..........................................144.5访问控制列表(ACL)设计方案.....................................174.6IP地址规划与路由设计方案.......................................184.6.1IP地址规划方案.............................................184.6.2路由协议的选择..............................................194.6.3路由协议设计方案............................................214.7HSRP:热备份路由器协议..........................................224.7.1HSRP协议概述...............................................224.7.2HSRP的工作原理.............................................234.7.3本方案的特点................................................235.设备清单...........................................................26结论........................................