第1页共142页目录课程表:···························································································································(1)第一讲:·······················································(2)资源环境及路由机架拓扑分析·······································································(2)第二讲:路由器及通信服务器的基本配置、思科认证···············································(5)第三讲:路由器的各种密码设置及接口地址设置·······················································(7)第四讲:两地互连路由配置,路由变PC,模拟器的使用,静态路由····················(9)第五讲:三地互连路由配置,环回接口的使用,动态RIP路由······························(16)第六讲:路由器优化配置,默认路由,上下文帮助,IGRP路由协议····················(22)第七讲:有类路由与无类路由及IP地址的企业化应用·············································(28)第八讲:EIGRP路由协议及CCNA认证考试及考题分析········································(33)第九讲:OSPF路由协议及MD7密码破解·································································(38)第十讲:路由原理、编辑命令及网络案例故障分析···················································(40)第十一讲:标准访问控制列表·······················································································(43)第十二讲:扩展访问控制列表·······················································································(47)第十三讲:命名及VTY访问控制列表,静态NAT···················································(50)第十四讲:动态NAT及端口NAT················································································(53)第十五讲:路由器的启动过程及特权密码破解···························································(58)第十六讲:PPP配置、IOS及配置文件的升级与备份·············(62)第十七讲:帧中继的配置·······························································································(74)第十八讲:帧中继的配置及排错···················································································(78)第十九讲:交换机的启动、工作原理及基本配置·······················································(85)第二十讲:交换机的安全配置·······················································································(86)第二十一讲:交换机的VLAN配置··············································································(90)第二十二讲:单臂路由、VTP·······················································································(96)网络案例及通信服务器(总路由器)的配置·······································(97)第二十三讲:综合练习·································································································(105);开学、师资、教材、路由器及模块介绍CCNA教材第5页共142页第二讲路由器及通信服务器的基本配置思科认证体系介绍本课重点:掌握终端服务器及路由器的基本配置实验一:COMM_SERV_RACK1r1回车Translatingr1再回车Tryingr1(1.1.1.1,2001)...OpenR1--------------如要从该路由器返回到通信服务器ctrl+shift+6x---返回到总路由器(通信服务器)showsession-----显示会话数(占用了几个路由器)showhost--------显示总路由器所连的设备代号disconnect1------主动释放某台路由器showuser--------显示连接到总路由器的用户clearline19---踢除某个用户clearline5----踢除5号线所连设备quit/exit----------退出总路由器,释放所有路由器实验二:R1:enable-----进入特权模式disable-----从特权模式返回到用户模式enable-----再次进入特权模式configterminal----进入全局模式exit----返回上一层相当于DOS环境中的cd..configterminalinterfaceserial0---进入接口模式(26xx系列路由器如:r5则使用serial0/0)ipaddress192.168.51.1255.255.255.0clockrate64000----配置时钟(DCE)noshutdown-----------激活启用当前接口end------返回到最顶层相当于DOS环境中的cd\configterminalhostnamer100----给路由器命名(区分大小写r1,从通信服务器转过来还用线名r1,非路由器名)enddisableping192.168.xy.x/y!!!!!---拼通.....---查错第6页共142页ICND2.2CCNA640-802ICND2.0=CCNA4.0InterconnectionCiscoNetworkDeviceCCNACCNPCCIE认证CCNA(CiscoCertifiedNetworkAssocite思科认证网络助理工程师)CCNP(CiscoCertifiedNetworkProfessional思科认证专业网络工程师)CCIE(CiscoCertifiedInternetworkExpert思科认证互联网络专家)ICND第三级网络的三级体系结构核心层------------------CCIE会聚层--分发层CCNP访问层--桌面层—接入层CCNA本讲练习:1、从内网进入通信服务器,进入r1路由器,之后再进入r11、r10、r9路由器,之后释放r92、从外网进入通信服务器,进入r2与r5路由器,之后踢掉内网进入的r11路由器3、配置r1、r3、r5路由器,确保r1、r3、r5之间通够互相拼通4、在通信服务器上显示通信服务器所连接的设备代号及线号第7页共142页第三讲路由器的各种密码设置及接口地址设置本课重点:理解路由器的各种密码使用环境及相应的设置方法实验一:查看路由器的相关配置enable---------------------进入路由器的特权模式showipinterfacebrief---显示接口的摘要信息showflash------显示IOS信息showversion----显示版本等相关信息showrunning-config--显示RAM中正在起作用的路由配置信息showstartup-config--显示NVRAM中已经存盘的路由配置信息copyrunning-configstartup-config---保存路由配置write-----------------------------------保存路由配置(推荐)r1?----------------查看用户模式下能够使用的配置命令r1enabler1#?----------------查看特权模式下能够使用的配置命令enableconfigterminallinevty04-------进入虚拟终端线模式passwordcisco2------设置telnet的密码login-----------------启用身份验证r5#telnet192.168.51.5---验证r1的vty远程登录功能end使用同一密码进入路由器;linevty04/password/login使用不同密码进入路由器;linevtyx/passwordy/login不需要密码进入路由器;linevty04/nologin使用不同用户名与密码进入路由器linevty04/loginlocal/exitusernameabcpasswordaaaconfigterminalenablesecretcisco---设置特权加密密码enablepasswordcisco---设置特权明文密码(明文密码不能与加密码相同)enablepasswordcisco1--设置特权明文密码(密码区分大小写,空格也可做密码)endshowrunning-config---------明文密码与加密密码的对比configterminalservicepassword-encryption-----使明文密码变为加密形式enddisableenable-------此时会要求输入特权密码configterminalusernamekxypasswordjxskxyinterfaceserial0clockrate64000--------配置时钟(只能在DCE端配置)end第8页共142页showcontrollersserial0-------查看接口的类型configterminalinterfaceserial0noipaddress192.168.xx.x255.255.255.0------去除相应接口的IP地址shutdown---------------禁用当前接口interfaceethernet0----进入以太口(快速以太网接口则f0如:r10--f0)ipaddress192.168.x.1255.255.0.0--设置IP地址noshutdown-----启用接口endping192.168.172.3---拼机房的某计算机地址pc:telnet192.168.x.1enableconfigterminallinevty04nologin!login!loginlocalnopasswordpc:telnet192.168.100.3---直接进路由器enableconfigtermina