华为S6720S acl+策略流控制

配置acl策略,3000设置允许,3001设置拒绝所有:

acl 3001
rule  deny ip source 192.168.10.0 0.0.0.255 destination 192.168.20.0 0.0.0.255
rule  deny ip source 192.168.10.0 0.0.0.255 destination 192.168.30.0 0.0.0.255
rule  deny ip source 192.168.10.0 0.0.0.255 destination 192.168.40.0 0.0.0.255
rule  deny ip source 192.168.20.0 0.0.0.255 destination 192.168.30.0 0.0.0.255
rule  deny ip source 192.168.20.0 0.0.0.255 destination 192.168.40.0 0.0.0.255
rule  deny ip source 192.168.30.0 0.0.0.255 destination 192.168.40.0 0.0.0.255

acl 3000
rule  permit ip source 192.168.10.11 0
rule  permit ip source 192.168.20.222 0 destination 192.168.10.111 0

配置策略流应用到全局:

traffic classifier 3000 operator and
if-match acl 3000
q
traffic behavior 3000
traffic classifier 3001 operator and
if-match acl 3001
q
traffic behavior 3001

以上2台核心交换机配置一样

sw1:
traffic policy yunxu
classifier 3000 behavior 3000
classifier 3001 behavior 3001
traffic-policy yunxu global inbound

backup:
traffic policy yunxu-backup
classifier 3000 behavior 3000
classifier 3001 behavior 3001
traffic-policy yunxu-backup global inbound

设置端口组:

port-group g1-24
port-group group-member g0/0/1 to g0/0/24
port link-type trunk
port trunk allow-pass vlan all

配置端口聚合,将2台核心交换机通过线路捆绑:

interface Eth-Trunk 1
trunkport GigabitEthernet 0/0/10 to 0/0/12
port link-type trunk
port trunk allow-pass vlan 2 to 4094

以上2台核心交换机配置一样

配置vrrp,防止核心交换单点故障:

[sw1] 主走vlan10 vlan20,备走vlan30 vlan40

int vlan 10
vrrp vrid 10 virtual-ip 192.168.10.100
vrrp vrid 10 priority 150
vrrp vrid 10 track interface g0/0/24 reduced 100

int vlan 20
vrrp vrid 20 virtual-ip 192.168.20.100
vrrp vrid 20 priority 150
vrrp vrid 20 track interface g0/0/24 reduced 100

int vlan 30
vrrp vrid 30 virtual-ip 192.168.30.100

int vlan 40
vrrp vrid 40 virtual-ip 192.168.40.100

[backup] 主走vlan30 vlan40,备走vlan10 vlan 20

int vlan 10
vrrp vrid 10 virtual-ip 192.168.10.100

int vlan 20
vrrp vrid 20 virtual-ip 192.168.20.100

int vlan 30
vrrp vrid 30 virtual-ip 192.168.30.100
vrrp vrid 30 priority 150
vrrp vrid 30 track interface g0/0/24 reduced 100

int vlan 40
vrrp vrid 40 virtual-ip 192.168.40.100
vrrp vrid 40 priority 150
vrrp vrid 40 track interface g0/0/24 reduced 100

注:各vlan下设备网关配置为各自的虚拟ip。如果配置vlan ip的话当主出现故障将无法访问外网;配置虚拟ip就算主出现故障,数据会通过备出去,不影响上网。

  • 0
    点赞
  • 5
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值