华为设备总部与分部配置

1.要求:

(1)总部实现高可靠性设计,接入层断掉一根线或汇聚、核心设备故障都不能影响数据正常转发

(2)分部1人数较少,采用单臂路由互通

(3)总部、分部1、2之间都能访问互联网

(4)外网能够访问总部的HTTP server 和FTP server

(5)总部和两个分部之间通过DSVPN实现内网互通

2.总部配置

(1)创建vlan并加入接口,将核心交换机之间链路捆绑为e-trunk,确保任何一台故障时另一台能正常转发数据

LSW3vlan batch 10 20 30

LSW3int g0/0/3

LSW3-GigabitEthernet0/0/3port link-type access

LSW3-GigabitEthernet0/0/3port default vlan 10

LSW3-GigabitEthernet0/0/3int g0/0/1

LSW3-GigabitEthernet0/0/1port link-type trunk

LSW3-GigabitEthernet0/0/1port trunk allow-pass vlan 10 20 30

LSW3-GigabitEthernet0/0/1int g0/0/2

LSW3-GigabitEthernet0/0/2port link-type trunk

LSW3-GigabitEthernet0/0/2port trunk allow-pass vlan 10 20 30

LSW4vlan batch 10 20 30

LSW4int g0/0/3

LSW4-GigabitEthernet0/0/3port link-type access

LSW4-GigabitEthernet0/0/3port default vlan 20

LSW4-GigabitEthernet0/0/3int g0/0/1

LSW4-GigabitEthernet0/0/1port link-type trunk

LSW4-GigabitEthernet0/0/1port trunk allow-pass vlan 10 20 30

LSW4-GigabitEthernet0/0/1int g0/0/2

LSW4-GigabitEthernet0/0/2port link-type trunk

LSW4-GigabitEthernet0/0/2port trunk allow-pass vlan 10 20 30

LSW5vlan batch 10 20 30

LSW5int g0/0/3

LSW5-GigabitEthernet0/0/3port link-type access

LSW5-GigabitEthernet0/0/3port default vlan 30

LSW5-GigabitEthernet0/0/3int g0/0/1

LSW5-GigabitEthernet0/0/1port link-type trunk

LSW5-GigabitEthernet0/0/1port trunk allow-pass vlan 10 20 30

LSW5-GigabitEthernet0/0/1int g0/0/2

LSW5-GigabitEthernet0/0/2port link-type trunk

LSW5-GigabitEthernet0/0/2port trunk allow-pass vlan 10 20 30

LSW1vlan batch 10 20 30 11 12

LSW1int g0/0/1

LSW1-GigabitEthernet0/0/1port link-type access

LSW1-GigabitEthernet0/0/1port default vlan 11

LSW1-GigabitEthernet0/0/1int g0/0/2

LSW1-GigabitEthernet0/0/2port link-type access

LSW1-GigabitEthernet0/0/2port default vlan 12

LSW1-GigabitEthernet0/0/2int g0/0/3

LSW1-GigabitEthernet0/0/3port link-type trunk

LSW1-GigabitEthernet0/0/3port trunk allow-pass vlan 10 20 30 11 12

LSW1-GigabitEthernet0/0/3int g0/0/4

LSW1-GigabitEthernet0/0/4port link-type trunk

LSW1-GigabitEthernet0/0/4port trunk allow-pass vlan 10 20 30 11 12 13 14

LSW1-GigabitEthernet0/0/4int g0/0/5

LSW1-GigabitEthernet0/0/5port link-type trunk

LSW1-GigabitEthernet0/0/5port trunk allow-pass vlan 10 20 30 11 12 13 14

LSW1-GigabitEthernet0/0/5quit

LSW1int Eth-Trunk 1

LSW1-Eth-Trunk1trunkport GigabitEthernet 0/0/6 to 0/0/7

LSW1-Eth-Trunk1port link-type trunk

LSW1-Eth-Trunk1port trunk allow-pass vlan 10 20 30 11 12 13 14

LSW2vlan batch 10 20 30 13 14

LSW2int g0/0/1

LSW2-GigabitEthernet0/0/1port link-type access

LSW2-GigabitEthernet0/0/1port default vlan 14

LSW2-GigabitEthernet0/0/1int g0/0/2

LSW2-GigabitEthernet0/0/2port link-type access

LSW2-GigabitEthernet0/0/2port default vlan 13

LSW2-GigabitEthernet0/0/2int g0/0/3

LSW2-GigabitEthernet0/0/3port link-type t

LSW2-GigabitEthernet0/0/3port link-type trunk

LSW2-GigabitEthernet0/0/3port trunk allow-pass vlan 10 20 30 11 12 13 14

LSW2-GigabitEthernet0/0/3int g0/0/4

LSW2-GigabitEthernet0/0/4port link-type trunk

LSW2-GigabitEthernet0/0/4port trunk allow-pass vlan 10 20 30 11 12 13 14

LSW2-GigabitEthernet0/0/4int g0/0/5

LSW2-GigabitEthernet0/0/5port link-type trunk

LSW2-GigabitEthernet0/0/5port trunk allow-pass vlan 10 20 30 11 12 13 14

LSW2-GigabitEthernet0/0/5quit

LSW2int Eth-Trunk 1

LSW2-Eth-Trunk1trunkport GigabitEthernet 0/0/6 to 0/0/7

LSW2-Eth-Trunk1port link-type trunk

LSW2-Eth-Trunk1port trunk allow-pass vlan 10 20 30 11 12 13 14

(2)配置MSTP破除环路:LSW1为vlan 10 20的根桥、vlan 30 的次根,LSW2为vlan 30的根桥、vlan 10 20的次根;将连接终端的接口配置为边缘端口

LSW1stp region-configuration

LSW1-mst-regionregion-name 1

LSW1-mst-regionrevision-level 1

LSW1-mst-regioninstance 1 vlan 10 20

LSW1-mst-regioninstance 2 vlan 30

LSW1-mst-regionactive region-configuration

LSW1stp instance 1 priority 0

LSW1stp instance 2 priority 4096

LSW2stp region-configuration

LSW2-mst-regionregion-name 1

LSW2-mst-regionrevision-level 1

LSW2-mst-regioninstance 1 vlan 10 20

LSW2-mst-regioninstance 2 vlan 30

LSW2-mst-regionactive region-configuration

LSW2stp instance 1 priority 4096

LSW2stp instance 2 priority 0

LSW3stp region-configuration

LSW3-mst-regionregion-name 1

LSW3-mst-regionrevision-level 1

LSW3-mst-regioninstance 1 vlan 10 20

LSW3-mst-regioninstance 2 vlan 30

LSW3-mst-regionactive region-configuration

LSW3-mst-regionquit

LSW4stp region-configuration

LSW4-mst-regionregion-name 1

LSW4-mst-regionrevision-level 1

LSW4-mst-regioninstance 1 vlan 10 20

LSW4-mst-regioninstance 2 vlan 30

LSW4-mst-regionactive region-configuration

LSW4-mst-regionquit

LSW5stp region-configuration

LSW5-mst-regionregion-name 1

LSW5-mst-regionrevision-level 1

LSW5-mst-regioninstance 1 vlan 10 20

LSW5-mst-regioninstance 2 vlan 30

LSW5-mst-regionactive region-configuration

LSW3int g0/0/3

LSW3-GigabitEthernet0/0/3stp edged-port enable

LSW4int g0/0/3

LSW4-GigabitEthernet0/0/3stp edged-port enable

LSW5int g0/0/3

LSW5-GigabitEthernet0/0/3stp edged-port enable

(3)配置vlan间路由,使内网互通:配置vrrp,LSW1为vlan 10 20的master、为vlan 30的backup,LSW2为vlan 10 20的backup、为vlan 30的master

LSW1int Vlanif 10

LSW1-Vlanif10ip add 10.1.1.1 24

LSW1-Vlanif10int Vlanif 20

LSW1-Vlanif20ip add 10.1.2.1 24

LSW1-Vlanif20int Vlanif 30

LSW1-Vlanif30ip add 10.1.3.1 24

LSW2int Vlanif 10

LSW2-Vlanif10ip add 10.1.1.2 24

LSW2-Vlanif10int Vlanif 20

LSW2-Vlanif20ip add 10.1.2.2 24

LSW2-Vlanif20int Vlanif 30

LSW2-Vlanif30ip add 10.1.3.2 24

LSW1int Vlanif 10

LSW1-Vlanif10vrrp vrid 1 virtual-ip 10.1.1.254

LSW1-Vlanif10vrrp vrid 1 priority 200

LSW1-Vlanif10vrrp vrid 1 preempt-mode timer delay 60

LSW1-Vlanif10vrrp vrid 1 track interface GigabitEthernet 0/0/1 reduced 120

LSW1int Vlanif 20

LSW1-Vlanif20vrrp vrid 2 virtual-ip 10.1.2.254

LSW1-Vlanif20vrrp vrid 2 priority 200

LSW1-Vlanif20vrrp vrid 2 preempt-mode timer delay 60

LSW1-Vlanif20vrrp vrid 2 track interface GigabitEthernet 0/0/1 reduced 120

LSW1int Vlanif 30

LSW1-Vlanif30vrrp vrid 3 virtual-ip 10.1.3.254

LSW2int Vlanif 10

LSW2-Vlanif10vrrp vrid 1 virtual-ip 10.1.1.254

LSW2-Vlanif10int Vlanif 20

LSW2-Vlanif20vrrp vrid 2 virtual-ip 10.1.2.254

LSW2-Vlanif20int Vlanif 30

LSW2-Vlanif30vrrp vrid 3 virtual-ip 10.1.3.254

LSW2-Vlanif30vrrp vrid 3 priority 200

LSW2-Vlanif30vrrp vrid 3 preempt-mode timer delay 60

LSW2-Vlanif30vrrp vrid 3 track interface GigabitEthernet 0/0/1 reduced 120




(4)配置三层互联接口

LSW1int Vlanif 11

LSW1-Vlanif11ip add 192.168.11.1 24

LSW1-Vlanif11int Vlanif 12

LSW1-Vlanif12ip add 192.168.12.1 24

LSW2int Vlanif 13

LSW2-Vlanif13ip add 192.168.13.2 24

LSW2-Vlanif13int Vlanif 14

LSW2-Vlanif14ip add 192.168.14.2 24

FW1firewall zone trust

FW1-zone-trustadd interface GigabitEthernet 1/0/2

FW1-zone-trustadd interface GigabitEthernet 1/0/0

FW1firewall zone untrust

FW1-zone-untrustadd interface GigabitEthernet 1/0/1

FW1-zone-untrustfirewall zone dmz

FW1-zone-dmzadd interface GigabitEthernet 1/0/3

FW1-zone-dmzadd interface GigabitEthernet 1/0/4

FW1int g1/0/1

FW1-GigabitEthernet1/0/1ip add 20.1.1.3 24

FW1-GigabitEthernet1/0/1int g1/0/0

FW1-GigabitEthernet1/0/0ip add 192.168.13.3 24

FW1-GigabitEthernet1/0/0int g1/0/2

FW1-GigabitEthernet1/0/2ip add 192.168.11.3 24

FW1-GigabitEthernet1/0/2int g1/0/3

FW1-GigabitEthernet1/0/3ip add 192.168.15.3 24

FW1-GigabitEthernet1/0/3int g1/0/4

FW1-GigabitEthernet1/0/4ip add 192.168.16.3 24

AR2int g0/0/0

AR2-GigabitEthernet0/0/0ip add 192.168.12.4 24

AR2-GigabitEthernet0/0/0int g0/0/1

AR2-GigabitEthernet0/0/1ip add 192.168.14.4 24

AR2-GigabitEthernet0/0/1int g0/0/2

AR2-GigabitEthernet0/0/2ip add 20.1.1.4 24

AR1int g4/0/0

AR1-GigabitEthernet4/0/0ip add 50.1.1.5 24

AR1-GigabitEthernet4/0/0int g0/0/1

AR1-GigabitEthernet0/0/1ip add 30.1.1.5 24

AR1-GigabitEthernet0/0/1int g0/0/2

AR1-GigabitEthernet0/0/2ip add 40.1.1.5 24

AR1-GigabitEthernet0/0/2int g0/0/0

AR1-GigabitEthernet0/0/0ip add 20.1.1.5 24

(5)配置DMZ区域

1)配置vlan

LSW10vlan batch 100 101

LSW10int g0/0/3

LSW10-GigabitEthernet0/0/3port link-type access

LSW10-GigabitEthernet0/0/3port default vlan 100

LSW10-GigabitEthernet0/0/3int g0/0/4

LSW10-GigabitEthernet0/0/4port link-type access

LSW10-GigabitEthernet0/0/4port default vlan 101

LSW10-GigabitEthernet0/0/4int g0/0/1

LSW10-GigabitEthernet0/0/1port link-type trunk

LSW10-GigabitEthernet0/0/1port trunk allow-pass vlan 100 101

LSW10-GigabitEthernet0/0/1int g0/0/2

LSW10-GigabitEthernet0/0/2port link-type trunk

LSW10-GigabitEthernet0/0/2port trunk allow-pass vlan 100 101

LSW8vlan batch 15 100 101

LSW8int g0/0/1

LSW8-GigabitEthernet0/0/1port link-type access

LSW8-GigabitEthernet0/0/1port default vlan 15

LSW8-GigabitEthernet0/0/1int g0/0/2

LSW8-GigabitEthernet0/0/2port link-type trunk

LSW8-GigabitEthernet0/0/2port trunk allow-pass vlan 15 100 101

LSW8-GigabitEthernet0/0/2quit

LSW8int Eth-Trunk 1

LSW8-Eth-Trunk1trunkport GigabitEthernet 0/0/3 to 0/0/4

LSW8-Eth-Trunk1port link-type trunk

LSW8-Eth-Trunk1port trunk allow-pass vlan 15 100 101

LSW9vlan batch 16 100 101

LSW9int g0/0/1

LSW9-GigabitEthernet0/0/1port link-type access

LSW9-GigabitEthernet0/0/1port default vlan 16

LSW9-GigabitEthernet0/0/1int g0/0/2

LSW9-GigabitEthernet0/0/2port link-type trunk

LSW9-GigabitEthernet0/0/2po

LSW9-GigabitEthernet0/0/2port trunk allow-pass vlan 16 100 101

LSW9-GigabitEthernet0/0/2quit

LSW9int Eth-Trunk 1

LSW9-Eth-Trunk1trunkport GigabitEthernet 0/0/3 to 0/0/4

LSW9-Eth-Trunk1port link-type trunk

LSW9-Eth-Trunk1port trunk allow-pass vlan 16 100 101

2)配置MSTP(要求vlan 100的根桥为LSW8,vlan 101的根桥为LSW9)

LSW10stp region-configuration

LSW10-mst-regionregion-name DMZ1

LSW10-mst-regionrevision-level 1

LSW10-mst-regioninstance 1 vlan 100

LSW10-mst-regioninstance 2 vlan 101

LSW10-mst-regionactive region-configuration

LSW8stp region-configuration

LSW8-mst-regionregion-name DMZ1

LSW8-mst-regionrevision-level 1

LSW8-mst-regioninstance 1 vlan 100

LSW8-mst-regioninstance 2 vlan 101

LSW8-mst-regionactive region-configuration

LSW9stp region-configuration

LSW9-mst-regionregion-name DMZ1

LSW9-mst-regionrevision-level 1

LSW9-mst-regioninstance 1 vlan 100

LSW9-mst-regioninstance 2 vlan 101

LSW9-mst-regionactive region-configuration

LSW8stp instance 1 priority 0

LSW8stp instance 2 priority 4096

LSW9stp instance 1 priority 4096

LSW9stp instance 2 priority 0

LSW10int g0/0/3

LSW10-GigabitEthernet0/0/3stp edged-port enable

LSW10-GigabitEthernet0/0/3int g0/0/4

LSW10-GigabitEthernet0/0/4stp edged-port enable

3)配置VLAN间路由

LSW8int Vlanif 15

LSW8-Vlanif15ip add 192.168.15.1 24

LSW8int Vlanif 100

LSW8-Vlanif100ip add 10.1.100.1 24

LSW8-Vlanif100int Vlanif 101

LSW8-Vlanif101ip add 10.1.101.1 24

LSW9int Vlanif 16

LSW9-Vlanif16ip add 192.168.16.2 24

LSW9int Vlanif 100

LSW9-Vlanif100ip add 10.1.100.2 24

LSW9-Vlanif100int Vlanif 101

LSW9-Vlanif101ip add 10.1.101.2 24

4)配置VRRP,保证链路备份

LSW8int Vlanif 100

LSW8-Vlanif100vrrp vrid 1 virtual-ip 10.1.100.254

LSW8-Vlanif100vrrp vrid 1 priority 200

LSW8-Vlanif100vrrp vrid 1 preempt-mode timer delay 60

LSW8-Vlanif100vrrp vrid 1 track interface g0/0/1 reduced 120

LSW8-Vlanif100quit

LSW8int Vlanif 101

LSW8-Vlanif101vrrp vrid 2 virtual-ip 10.1.101.254

LSW9int Vlanif 100

LSW9-Vlanif100vrrp vrid 1 virtual-ip 10.1.100.254

LSW9-Vlanif100int Vlanif 101

LSW9-Vlanif101vrrp vrid 2 virtual-ip 10.1.101.254

LSW9-Vlanif101vrrp vrid 2 preempt-mode timer delay 60

LSW9-Vlanif101vrrp vrid 2 priority 200

LSW9-Vlanif101vrrp vrid 2 track interface g0/0/1 reduced 120

(6)配置全网路由:将总部在OSFP的area 0区域,服务器在 area 1区域,分部1在area 2区域,分部2在area 3区域

1)配置OSPF

LSW1ospf 1 router-id 11.1.1.1

LSW1-ospf-1area 0

LSW1-ospf-1-area-0.0.0.0ne

LSW1-ospf-1-area-0.0.0.0network 10.1.1.0 0.0.0.255

LSW1-ospf-1-area-0.0.0.0network 10.1.2.0 0.0.0.255

LSW1-ospf-1-area-0.0.0.0network 10.1.3.0 0.0.0.255

LSW1-ospf-1-area-0.0.0.0network 192.168.11.0 0.0.0.255

LSW1-ospf-1-area-0.0.0.0network 192.168.12.0 0.0.0.255

LSW2ospf 1 router-id 22.1.1.1

LSW2-ospf-1area 0

LSW2-ospf-1-area-0.0.0.0network 10.1.1.0 0.0.0.255

LSW2-ospf-1-area-0.0.0.0network 10.1.2.0 0.0.0.255

LSW2-ospf-1-area-0.0.0.0network 10.1.3.0 0.0.0.255

LSW2-ospf-1-area-0.0.0.0network 192.168.13.0 0.0.0.255

LSW2-ospf-1-area-0.0.0.0network 192.168.14.0 0.0.0.255

FW1ospf router-id 33.1.1.1

FW1-ospf-1ospf 1

FW1-ospf-1area 0

FW1-ospf-1-area-0.0.0.0network 192.168.11.0 0.0.0.255

FW1-ospf-1-area-0.0.0.0network 192.168.13.0 0.0.0.255

FW1-ospf-1-area-0.0.0.0network 192.168.15.0 0.0.0.255

FW1-ospf-1-area-0.0.0.0network 192.168.16.0 0.0.0.255

AR2ospf router-id 44.1.1.1

AR2-ospf-1area 0

AR2-ospf-1-area-0.0.0.0network 192.168.12.0 0.0.0.255

AR2-ospf-1-area-0.0.0.0network 192.168.14.0 0.0.0.255

LSW8ospf router-id 111.1.1.1

LSW8-ospf-1area 0

LSW8-ospf-1-area-0.0.0.0network 192.168.15.0 0.0.0.255

LSW8-ospf-1-area-0.0.0.0area 1

LSW8-ospf-1-area-0.0.0.1network 10.1.100.0 0.0.0.255

LSW8-ospf-1-area-0.0.0.1network 10.1.101.0 0.0.0.255

LSW9ospf router-id 222.1.1.1

LSW9-ospf-1area 0

LSW9-ospf-1-area-0.0.0.0net

LSW9-ospf-1-area-0.0.0.0network 192.168.16.0 0.0.0.255

LSW9-ospf-1-area-0.0.0.0area 1

LSW9-ospf-1-area-0.0.0.1network 10.1.101.0 0.0.0.255

LSW9-ospf-1-area-0.0.0.1network 10.1.100.0 0.0.0.255

2)将vlanif接口静默

LSW1ospf 1

LSW1-ospf-1silent-interface Vlanif 10

LSW1-ospf-1silent-interface Vlanif 20

LSW1-ospf-1silent-interface Vlanif 30

LSW2ospf 1

LSW2-ospf-1silent-interface Vlanif 10

LSW2-ospf-1silent-interface Vlanif 20

LSW2-ospf-1silent-interface Vlanif 30

LSW8-ospf-1silent-interface Vlanif 100

LSW8-ospf-1silent-interface Vlanif 101

LSW9-ospf-1silent-interface Vlanif 100

LSW9-ospf-1silent-interface Vlanif 101

(7)配置trust到dmz的安全策略

FW1security-policy

FW1-policy-securityrule name t-to-dmz

FW1-policy-security-rule-t-to-dmzsource-zone trust

FW1-policy-security-rule-t-to-dmzsource-address 10.1.0.0 16

FW1-policy-security-rule-t-to-dmzdestination-zone dmz

FW1-policy-security-rule-t-to-dmzaction permit

(8)配置 NAT

FW1nat-policy

FW1-policy-natrule name to-ISP

FW1-policy-nat-rule-to-ISPsource-zone trust

FW1-policy-nat-rule-to-ISPdestination-zone untrust

FW1-policy-nat-rule-to-ISPsource-address 10.1.0.0 16

FW1-policy-nat-rule-to-ISPaction source-nat easy-ip

FW1security-policy

FW1-policy-securityrule name to-ISP

FW1-policy-security-rule-to-ISPsource-zone trust

FW1-policy-security-rule-to-ISPdestination-zone untrust

FW1-policy-security-rule-to-ISPsource-address 10.1.0.0 16

FW1-policy-security-rule-to-ISPaction permit

FW1ip route-static 0.0.0.0 0.0.0.0 20.1.1.5

FW1ospf 1

FW1-ospf-1default-route-advertise

(9)公网访问 dmz 区域的 http 服务和 FTP 服务:通过 nat-server 进行映射

FW1nat server protocol tcp global 20.1.1.100 80 inside 10.1.100.10 80

FW1nat server protocol tcp global 20.1.1.101 21 inside 10.1.101.10 21

FW1security-policy

FW1-policy-securityrule name u-to-dmz

FW1-policy-security-rule-u-to-dmzsource-zone untrust

FW1-policy-security-rule-u-to-dmzdestination-zone dmz

FW1-policy-security-rule-u-to-dmzdestination-address 10.1.100.10 32

FW1-policy-security-rule-u-to-dmzdestination-address 10.1.101.10 32

FW1-policy-security-rule-u-to-dmzaction permit

4.分部1的配置:单臂路由和NAT

(1)单臂路由配置

LSW11vlan batch 10 20

LSW11int g0/0/2

LSW11-GigabitEthernet0/0/2port link-type access

LSW11-GigabitEthernet0/0/2port default vlan 10

LSW11-GigabitEthernet0/0/2int g0/0/3

LSW11-GigabitEthernet0/0/3port link-type access

LSW11-GigabitEthernet0/0/3port default vlan 20

LSW11-GigabitEthernet0/0/3int g0/0/1

LSW11-GigabitEthernet0/0/1port link-type trunk

LSW11-GigabitEthernet0/0/1port trunk allow-pass vlan 10 20

AR4int g0/0/1.10

AR4-GigabitEthernet0/0/1.10dot1q termination vid 10

AR4-GigabitEthernet0/0/1.10arp broadcast enable

AR4-GigabitEthernet0/0/1.10ip add 10.2.1.1 2

AR4-GigabitEthernet0/0/1.10int g0/0/1.20

AR4-GigabitEthernet0/0/1.20dot1q termination vid 20

AR4-GigabitEthernet0/0/1.20arp broadcast enable

AR4-GigabitEthernet0/0/1.20ip add 10.2.2.1 24

AR4int g0/0/0

AR4-GigabitEthernet0/0/0ip add 40.1.1.1 24

AR4ip route-static 0.0.0.0 0.0.0.0 40.1.1.5

AR4acl 2000

AR4-acl-basic-2000rule permit source 10.2.0.0 0.0.255.255

AR4-acl-basic-2000int g0/0/0

AR4-GigabitEthernet0/0/0nat outbound 2000

5.分部2的配置

(1)配置vlan

LSW13vlan batch 10 20 17

LSW13int g0/0/1

LSW13-GigabitEthernet0/0/1port link-type access

LSW13-GigabitEthernet0/0/1port default vlan 17

LSW13-GigabitEthernet0/0/1int g0/0/2

LSW13-GigabitEthernet0/0/2port link-type trunk

LSW13-GigabitEthernet0/0/2port trunk allow-pass vlan 10 20 17

LSW13-GigabitEthernet0/0/2int g0/0/3

LSW13-GigabitEthernet0/0/3port link-type trunk

LSW13-GigabitEthernet0/0/3port trunk allow-pass vlan 10 20 17

LSW13-GigabitEthernet0/0/3quit

LSW13int Eth-Trunk 1

LSW13-Eth-Trunk1trunkport GigabitEthernet 0/0/4 to 0/0/5

LSW13-Eth-Trunk1port link-type trunk

LSW13-Eth-Trunk1port trunk allow-pass vlan 10 20 17

LSW14vlan batch 10 20 18

LSW14int g0/0/1

LSW14-GigabitEthernet0/0/1port link-type access

LSW14-GigabitEthernet0/0/1port default vlan 18

LSW14-GigabitEthernet0/0/1int g0/0/2

LSW14-GigabitEthernet0/0/2port link-type trunk

LSW14-GigabitEthernet0/0/2port trunk allow-pass vlan 10 20 18

LSW14-GigabitEthernet0/0/2int g0/0/3

LSW14-GigabitEthernet0/0/3port link-type trunk

LSW14-GigabitEthernet0/0/3port trunk allow-pass vlan 10 20 18

LSW14-GigabitEthernet0/0/3quit

LSW14int Eth-Trunk 1

LSW14-Eth-Trunk1trunkport GigabitEthernet 0/0/4 to 0/0/5

LSW14-Eth-Trunk1port link-type trunk

LSW14-Eth-Trunk1port trunk allow-pass vlan 10 20 18

LSW15vlan batch 10 20

LSW15int g0/0/3

LSW15-GigabitEthernet0/0/3port link-type access

LSW15-GigabitEthernet0/0/3port default vlan 10

LSW15-GigabitEthernet0/0/3int g0/0/1

LSW15-GigabitEthernet0/0/1port link-type trunk

LSW15-GigabitEthernet0/0/1port trunk allow-pass vlan 10 20

LSW15-GigabitEthernet0/0/1int g0/0/2

LSW15-GigabitEthernet0/0/2port link-type trunk

LSW15-GigabitEthernet0/0/2port trunk allow-pass vlan 10 20

LSW16vlan batch 10 20

LSW16int g0/0/3

LSW16-GigabitEthernet0/0/3port link-type access

LSW16-GigabitEthernet0/0/3port default vlan 20

LSW16-GigabitEthernet0/0/3int g0/0/1

LSW16-GigabitEthernet0/0/1port link-type trunk

LSW16-GigabitEthernet0/0/1port trunk allow-pass vlan 10 20

LSW16-GigabitEthernet0/0/1int g0/0/2

LSW16-GigabitEthernet0/0/2port link-type trunk

LSW16-GigabitEthernet0/0/2port trunk allow-pass vlan 10 20

(2)配置MSTP:LSW13为vlan 10的主根、vlan 20的次根,LSW14为vlan 20的主根、vlan 10的次根

LSW13stp region-configuration

LSW13-mst-regionregion-name FB2

LSW13-mst-regionrevision-level 1

LSW13-mst-regioninstance 1 vlan 10

LSW13-mst-regioninstance 2 vlan 20

LSW13-mst-regionactive region-configuration

LSW14stp region-configuration

LSW14-mst-regionregion-name FB2

LSW14-mst-regionrevision-level 1

LSW14-mst-regioninstance 1 vlan 10

LSW14-mst-regioninstance 2 vlan 20

LSW14-mst-regionactive region-configuration

LSW15stp region-configuration

LSW15-mst-regionregion-name FB2

LSW15-mst-regionrevision-level 1

LSW15-mst-regioninstance 1 vlan 10

LSW15-mst-regioninstance 2 vlan 20

LSW15-mst-regionactive region-configuration

LSW16stp region-configuration

LSW16-mst-regionregion-name FB2

LSW16-mst-regionrevision-level 1

LSW16-mst-regioninstance 1 vlan 10

LSW16-mst-regioninstance 2 vlan 20

LSW16-mst-regionactive region-configuration

LSW13stp instance 1 priority 0

LSW13stp instance 2 priority 4096

LSW14stp instance 1 priority 4096

LSW14stp instance 2 priority 0

LSW16-GigabitEthernet0/0/3stp edged-port enable

LSW15-GigabitEthernet0/0/3stp edged-port enable

(3)配置vlan间路由

LSW13int Vlanif 10

LSW13-Vlanif10ip add 10.3.1.1 24

LSW13-Vlanif10int Vlanif 20

LSW13-Vlanif20ip add 10.3.2.1 24

LSW13-Vlanif20int Vlanif 10

LSW13-Vlanif10vrrp vrid 1 virtual-ip 10.3.1.254

LSW13-Vlanif10vrrp vrid 1 priority 200

LSW13-Vlanif10vrrp vrid 1 preempt-mode timer delay 60

LSW13-Vlanif10vrrp vrid 1 track interface g0/0/1 reduced 120

LSW13-Vlanif10int Vlanif 20

LSW13-Vlanif20vrrp vrid 2 virtual-ip 10.3.2.254

LSW14int Vlanif 10

LSW14-Vlanif10ip add 10.3.1.2 24

LSW14-Vlanif10int Vlanif 20

LSW14-Vlanif20ip add 10.3.2.2 24

LSW14-Vlanif20vrrp vrid 2 virtual-ip 10.3.2.254

LSW14-Vlanif20vrrp vrid 2 priority 200

LSW14-Vlanif20vrrp vrid 2 preempt-mode timer delay 60

LSW14-Vlanif20vrrp vrid 2 track interface GigabitEthernet 0/0/1 reduced 120

LSW14-Vlanif20int Vlanif 10

LSW14-Vlanif10vrrp vrid 1 virtual-ip 10.3.1.254

(4)配置全网路由

LSW13int Vlanif 17

LSW13-Vlanif17ip add 192.168.17.1 24

LSW13-Vlanif17quit

LSW13ospf 1 router-id 17.1.1.1

LSW13-ospf-1area 2

LSW13-ospf-1-area-0.0.0.2ne

LSW13-ospf-1-area-0.0.0.2network 192.168.17.0 0.0.0.255

LSW13-ospf-1-area-0.0.0.2network 10.3.1.0 0.0.0.255

LSW13-ospf-1-area-0.0.0.2network 10.3.2.0 0.0.0.255

LSW13-ospf-1-area-0.0.0.2qui

LSW13-ospf-1silent-interface Vlanif 10

LSW13-ospf-1silent-interface Vlanif 20

LSW14int Vlanif 18

LSW14-Vlanif18ip add 192.168.18.1 24

LSW14-Vlanif18quit

LSW14ospf 1 router-id 18.1.1.1

LSW14-ospf-1area 2

LSW14-ospf-1-area-0.0.0.2network 10.3.1.0 0.0.0.255

LSW14-ospf-1-area-0.0.0.2network 10.3.2.0 0.0.0.255

LSW14-ospf-1-area-0.0.0.2network 192.168.18.0 0.0.0.255

LSW14-ospf-1-area-0.0.0.2quit

LSW14-ospf-1silent-interface Vlanif 10

LSW14-ospf-1silent-interface Vlanif 20

AR5int g0/0/1

AR5-GigabitEthernet0/0/1ip add 192.168.17.6 24

AR5-GigabitEthernet0/0/1int g0/0/2

AR5-GigabitEthernet0/0/2ip add 192.168.18.6 24

AR5-GigabitEthernet0/0/2int g0/0/0

AR5-GigabitEthernet0/0/0ip add 50.1.1.6 24

AR5ospf 1 router-id 55.1.1.1

AR5-ospf-1area 2

AR5-ospf-1-area-0.0.0.2network 192.168.17.0 0.0.0.255

AR5-ospf-1-area-0.0.0.2network 192.168.18.0 0.0.0.255

AR5ip route-static 0.0.0.0 0.0.0.0 50.1.1.5

AR5ospf 1

AR5-ospf-1default-route-advertise

(5)源NAT地址转换

AR5acl 2000

AR5-acl-basic-2000rule permit source 10.3.0.0 0.0.255.255

AR5int g0/0/0

AR5-GigabitEthernet0/0/0nat outbound 2000

6.总校分校DSVPN配置:AR2作为hub端,AR4、AR5作为spoke端,三个接口配置在172.1.1.0网段

AR2int Tunnel 0/0/0

AR2-Tunnel0/0/0tunnel-protocol gre p2mp

AR2-Tunnel0/0/0ip add 172.1.1.1 24

AR2-Tunnel0/0/0source GigabitEthernet 0/0/2

AR2-Tunnel0/0/0nhrp entry multicast dynamic

AR2-Tunnel0/0/0ospf dr-priority 255 //调整优先级至最大,使其成为 DR

AR4int Tunnel 0/0/0

AR4-Tunnel0/0/0tunnel-protocol gre p2mp

AR4-Tunnel0/0/0ip add 172.1.1.3 24

AR4-Tunnel0/0/0source GigabitEthernet 0/0/0

AR4-Tunnel0/0/0nhrp entry 172.1.1.1 20.1.1.4 register

AR4-Tunnel0/0/0ospf network-type broadcast

AR4-Tunnel0/0/0ospf dr-priority 0

AR5int Tunnel 0/0/0

AR5-Tunnel0/0/0tunnel-protocol gre p2mp

AR5-Tunnel0/0/0ip add 172.1.1.2 24

AR5-Tunnel0/0/0source GigabitEthernet 0/0/0

AR5-Tunnel0/0/0nhrp entry 172.1.1.1 20.1.1.4 register

AR5-Tunnel0/0/0ospf network-type broadcast

AR5-Tunnel0/0/0ospf dr-priority 0

AR2ospf 1

AR2-ospf-1area 0

AR2-ospf-1-area-0.0.0.0network 172.1.1.0 0.0.0.255

AR4ospf 1

AR4-ospf-1area 0

AR4-ospf-1-area-0.0.0.0network 172.1.1.0 0.0.0.255

AR5ospf 1

AR5-ospf-1area 0

AR5-ospf-1-area-0.0.0.0network 172.1.1.0 0.0.0.255

相关推荐
特立独行的猫a2 小时前
Tauri 应用移植到 OpenHarmony/鸿蒙PC完整指南
华为·rust·harmonyos·tauri·移植·鸿蒙pc
weixin_604236672 小时前
华三 路由器 极简核心配置
运维·服务器·网络·h3c·h3c路由器
互联网散修2 小时前
鸿蒙实战:文字放大镜精确跟随手指放大
华为·harmonyos
金启攻5 小时前
【鸿蒙应用开发实战·食光篇】第二篇:首页与菜系导航——圆形封面与美食榜单
华为·harmonyos
换个昵称都难5 小时前
webrtc 音频模块FEC模块
网络·音视频·webrtc
youngerwang6 小时前
【从搬运工到协处理器:网卡芯片架构、算法、验证与边缘演进深度剖析】
网络·算法·架构·芯片
●VON7 小时前
AtomGit Flutter鸿蒙客户端:设置页面
flutter·华为·跨平台·harmonyos·鸿蒙
●VON7 小时前
AtomGit Flutter鸿蒙客户端:用户资料
flutter·华为·架构·跨平台·harmonyos·鸿蒙
智慧光迅AINOPOL8 小时前
校园在线巡课系统方案:督导全覆盖
网络·全光网解决方案·全光网·校园全光网·校园全光网解决方案
风华圆舞8 小时前
Stage 模型下 Flutter 鸿蒙壳工程怎么理解
flutter·华为·harmonyos