70 phút
Routing và Static Routes
Routing và Static Routes
Router Fundamentals
Router Components
- CPU
- RAM (running-config, routing table)
- NVRAM (startup-config)
- Flash (IOS image)
- ROM (bootstrap)
- Interfaces
Boot Process
1. POST (Power-On Self Test)
2. Load bootstrap từ ROM
3. Load IOS từ Flash
4. Load startup-config từ NVRAM
5. Nếu không có → Setup mode
Router Configuration
Initial Config
Router> enable
Router# configure terminal
Router(config)# hostname R1
R1(config)# enable secret Cisco123
R1(config)# line console 0
R1(config-line)# password Console123
R1(config-line)# login
R1(config-line)# logging synchronous
R1(config-line)# exit
R1(config)# line vty 0 4
R1(config-line)# password Vty123
R1(config-line)# login
R1(config-line)# transport input ssh
R1(config-line)# exit
R1(config)# ip domain-name abc.local
R1(config)# crypto key generate rsa modulus 2048
R1(config)# username admin privilege 15 secret Admin123
R1(config)# service password-encryption
R1(config)# banner motd # Authorized access only #
R1(config)# end
R1# write memory
Interface Configuration
R1(config)# interface gi0/0
R1(config-if)# description "WAN to ISP"
R1(config-if)# ip address 203.0.113.2 255.255.255.252
R1(config-if)# no shutdown
R1(config-if)# exit
R1(config)# interface gi0/1
R1(config-if)# description "LAN Gateway"
R1(config-if)# ip address 192.168.1.1 255.255.255.0
R1(config-if)# no shutdown
R1(config-if)# exit
# Verify
R1# show ip interface brief
R1# show interfaces gi0/0
R1# show ip interface gi0/0
Static Routing
Cấu trúc lệnh
ip route <network> <mask> {next-hop | exit-interface} [AD] [permanent]
AD (Administrative Distance):
- Connected: 0
- Static: 1
- eBGP: 20
- EIGRP: 90
- OSPF: 110
- RIP: 120
- iBGP: 200
Các loại Static Route
1. Next-hop route
R1(config)# ip route 192.168.2.0 255.255.255.0 10.0.0.2
2. Directly connected route
R1(config)# ip route 192.168.2.0 255.255.255.0 gi0/0
3. Fully specified route (khuyến nghị)
R1(config)# ip route 192.168.2.0 255.255.255.0 gi0/0 10.0.0.2
4. Default route
R1(config)# ip route 0.0.0.0 0.0.0.0 203.0.113.1
5. Host route
R1(config)# ip route 192.168.1.100 255.255.255.255 10.0.0.2
6. Floating static route (backup)
# AD cao hơn để làm backup
R1(config)# ip route 192.168.2.0 255.255.255.0 10.0.0.2 1
R1(config)# ip route 192.168.2.0 255.255.255.0 10.0.0.6 5
IPv4 Routing Table
Cấu trúc
Codes: C - Connected, S - Static, R - RIP, O - OSPF, D - EIGRP
Gateway of last resort is 203.0.113.1 to network 0.0.0.0
S* 0.0.0.0/0 [1/0] via 203.0.113.1
C 192.168.1.0/24 is directly connected, GigabitEthernet0/1
L 192.168.1.1/32 is directly connected, GigabitEthernet0/1
S 192.168.2.0/24 [1/0] via 10.0.0.2
Xem routing table
R1# show ip route
R1# show ip route static
R1# show ip route connected
R1# show ip route 192.168.1.0
R1# show ip route summary
Longest Prefix Match
Destination 192.168.1.100:
- 0.0.0.0/0 (default) - /0
- 192.168.1.0/24 - /24
- 192.168.1.100/32 - /32 ← Chọn route này
Rule: Prefix dài nhất thắng
IPv6 Static Routes
# Enable IPv6 routing
R1(config)# ipv6 unicast-routing
# Configure interface
R1(config)# interface gi0/0
R1(config-if)# ipv6 address 2001:db8:1::1/64
R1(config-if)# ipv6 enable
R1(config-if)# no shutdown
R1(config-if)# exit
# Static IPv6 route
R1(config)# ipv6 route 2001:db8:2::/64 2001:db8:1::2
# Default IPv6 route
R1(config)# ipv6 route ::/0 2001:db8:1::2
# Verify
R1# show ipv6 route
R1# show ipv6 interface brief
R1# show ipv6 interface gi0/0
NAT (Network Address Translation)
NAT Types
Static NAT: 1-1 mapping (private to public)
Dynamic NAT: Pool to pool
PAT (Overload): Many to 1 (most common)
Static NAT
R1(config)# ip nat inside source static 192.168.1.10 203.0.113.10
R1(config)# interface gi0/1
R1(config-if)# ip nat inside
R1(config-if)# exit
R1(config)# interface gi0/0
R1(config-if)# ip nat outside
R1(config-if)# exit
Dynamic NAT
# Define pool
R1(config)# ip nat pool MYPOOL 203.0.113.10 203.0.113.20 netmask 255.255.255.0
# ACL cho inside
R1(config)# access-list 1 permit 192.168.1.0 0.0.0.255
# NAT rule
R1(config)# ip nat inside source list 1 pool MYPOOL
# Apply to interfaces
R1(config)# interface gi0/1
R1(config-if)# ip nat inside
R1(config-if)# exit
R1(config)# interface gi0/0
R1(config-if)# ip nat outside
PAT (Overload)
# Với interface
R1(config)# ip nat inside source list 1 interface gi0/0 overload
# Với pool
R1(config)# ip nat inside source list 1 pool MYPOOL overload
# Verify
R1# show ip nat translations
R1# show ip nat statistics
R1# clear ip nat translation *
Port Forwarding
# Forward port 80 to internal server
R1(config)# ip nat inside source static tcp 192.168.1.100 80 203.0.113.10 80
R1(config)# ip nat inside source static tcp 192.168.1.100 443 203.0.113.10 443
DHCP
DHCP Server trên Router
# Enable service
R1(config)# service dhcp
# Exclude IPs
R1(config)# ip dhcp excluded-address 192.168.1.1 192.168.1.10
R1(config)# ip dhcp excluded-address 192.168.1.100 192.168.1.110
# DHCP Pool
R1(config)# ip dhcp pool LAN-POOL
R1(dhcp-config)# network 192.168.1.0 255.255.255.0
R1(dhcp-config)# default-router 192.168.1.1
R1(dhcp-config)# dns-server 8.8.8.8 8.8.4.4
R1(dhcp-config)# domain-name abc.local
R1(dhcp-config)# lease 7
R1(dhcp-config)# exit
# Static binding
R1(config)# ip dhcp pool PRINTER
R1(dhcp-config)# host 192.168.1.50 255.255.255.0
R1(dhcp-config)# hardware-address 0011.2233.4455
R1(dhcp-config)# client-name Printer
R1(dhcp-config)# default-router 192.168.1.1
R1(dhcp-config)# exit
# Verify
R1# show ip dhcp binding
R1# show ip dhcp pool
R1# show ip dhcp statistics
DHCP Relay
# Trên router (khi DHCP server ở subnet khác)
R1(config)# interface gi0/1.10
R1(config-subif)# ip helper-address 10.0.0.10
R1(config-subif)# exit
Bài tập thực hành
Hãy cấu hình routing và NAT!