总拓扑图
下层交换部分
网络基础配置:IP地址,VLAN,mstp,vrrp
IP地址划分和vlan
pc1---sw5 | 192.168.2.0/24 | vlan 2 |
pc2---sw5 | 192.168.3.0/24 | vlan 3 |
[sw3]undo info-center enable
[sw3]vlan batch 2 3
[sw3-GigabitEthernet0/0/4]port link-type trunk 猜测因为后续sw3需要成为两个网段的网关,应该需要修改为truck链路
[sw3-GigabitEthernet0/0/4]port trunk allow-pass vlan 2 to 3
[sw3-GigabitEthernet0/0/2]port link-type trunk
[sw3-GigabitEthernet0/0/2]port trunk allow-pass vlan 2 to 3
[sw3]interface Vlanif 2
[sw3-Vlanif2]ip address 192.168.2.254 24
[sw3]interface Vlanif 3
[sw3-Vlanif3]ip address 192.168.3.254 24
vrrp配置
sw3为vlan2的主网关,sw4为vlan3的主网关,互为对方的备网关
[sw3]interface Vlanif 2
[sw3-Vlanif2]vrrp vrid 1 virtual-ip 192.168.2.252 配置虚拟IP
[sw3-Vlanif2]vrrp vrid 1 priority 120 配置优先级
[sw3-Vlanif2]vrrp vrid 1 preempt-mode timer delay 20 配置抢占延迟
[sw3]interface Vlanif 3
[sw3-Vlanif3]vrrp vrid 2 virtual-ip 192.168.3.252
[sw3-Vlanif3]vrrp vrid 2 priority 80
[sw3-Vlanif3]vrrp vrid 2 preempt-mode timer delay 20
测试
关闭一个接口,ping虚拟网关可以ping通,交换层vrrp配置完成
配置mstp
[sw3]stp mode mstp
[sw3]stp region-configuration
[sw3-mst-region]region-name sw
[sw3-mst-region]instance 1 vlan 2
[sw3-mst-region]instance 2 vlan 3
[sw3-mst-region]active region-configuration
[sw3]stp instance 1 root primary
[sw3]stp instance 2 root secondary
sw4类似配置
[sw5]stp mode mstp
[sw5]stp region-configuration
[sw5-mst-region]region-name sw
[sw5-mst-region]instance 1 vlan 2
[sw5-mst-region]instance 2 vlan 3
[sw5-mst-region]active region-configuration
[sw5-GigabitEthernet0/0/3]stp edged-port enable
[sw5-GigabitEthernet0/0/4]stp edged-port enable 开启边缘接口
上层交换部分
IP地址划分和vlan
sw1---sw2 | 10.0.12.0/24 | vlan 12 |
sw1---sw3 | 10.0.13.0/24 | vlan 13 |
sw1---sw4 | 10.0.14.0/24 | vlan 14 |
sw2---sw3 | 10.0.23.0/24 | vlan 23 |
sw2---sw4 | 10.0.24.0/24 | vlan 24 |
sw3---sw4 | 10.0.34.0/24 | vlan 34 |
先将sw1和sw2分为vrf和public区域
[sw1]ip vpn-instance vrf
[sw1-vpn-instance-vrf]route-distinguisher 100:1
[sw1-vpn-instance-vrf-af-ipv4]vpn-target 100:1 both
[sw1-Vlanif13]ip address 10.0.13.1 24
[sw1-Vlanif13]ip binding vpn-instance vrf 接口划到vrf区域
将vlan划入接口
[sw1]interface g0/0/3
[sw1-GigabitEthernet0/0/3]port link-type access
[sw1-GigabitEthernet0/0/3]port default vlan 12
[sw1]interface g0/0/4
[sw1-GigabitEthernet0/0/4]port link-type access
[sw1-GigabitEthernet0/0/4]port default vlan 13
[sw1-GigabitEthernet0/0/5]port link-type access
[sw1-GigabitEthernet0/0/5]port default vlan 14
sw2类似,sw3和sw4之间的链路为truck,好像改为access也没事,因为是三层交换机,可以通过路由表转发
进接口关闭stp功能
[sw1-GigabitEthernet0/0/4]undo stp enable
尝试过配置mstp出现了很多不明所以的问题,例如vlan和实例划分问题和sw3和sw4同时运行了两个mstp,不知道如何分配的问题,而且因为这个网络有五个vlan,需要创建五个实例,非常麻烦,并不符合常理。而且理论上来说,上层交换机都是三层交换机,通过路由表转发,也不需要使用stp协议确保无环。
配置OSPF
[sw1]ospf 1 router-id 1.1.1.1 vpn-instance vrf
[sw1-ospf-1]area 0
[sw1-ospf-1-area-0.0.0.0]network 10.0.12.1 0.0.0.0
[sw1-ospf-1-area-0.0.0.0]network 10.0.13.1 0.0.0.0
[sw1-ospf-1-area-0.0.0.0]network 10.0.14.1 0.0.0.0
[sw3-ospf-1]silent-interface Vlanif 34 设置静默接口
[sw1]display ip routing-table vpn-instance vrf 查看vrf上的路由信息
发现去往192.168.2.0和192.168.3.0网段的流量形成等价路由了,需要通过策略在sw3和sw4上修改路由信息的cost值。
[sw3-Vlanif23]ospf cost 5
[sw3]ip ip-prefix aa permit 192.168.2.0 24
[sw3]ip ip-prefix bb permit 192.168.3.0 24
[sw3]route-policy aa permit node 10
[sw3-route-policy]if-match ip-prefix aa
[sw3-route-policy]apply cost 1
[sw3]route-policy bb permit node 20
[sw3-route-policy]if-match ip-prefix bb
[sw3-route-policy]apply cost 5
[sw3-ospf-1]import-route direct route-policy aa
[sw3-ospf-1]import-route direct route-policy bb
配置vrrp
vrrp 11 | vlan 101 10.0.101.0/24 | vsw1主vsw2备 虚拟IP10.0.101.100 |
vrrp 12 | vlan 102 10.0.102.0/24 | vsw2主vsw1备 虚拟IP10.0.102.100 |
vrrp 13 | vlan 103 10.0.103.0/24 | psw1主psw2备 虚拟IP10.0.103.100 |
vrrp 14 | vlan 104 10.0.104.0/24 | psw1主psw2备 虚拟IP10.0.104.100 |
vrrp 15 | vlan 101 10.0.101.0/24 | fw1主fw2备 虚拟IP10.0.101.200 |
vrrp 16 | vlan 102 10.0.102.0/24 | fw2主fw1备 虚拟IP10.0.102.200 |
vrrp 17 | vlan 103 10.0.103.0/24 | fw1主fw2备 虚拟IP10.0.103.200 |
vrrp 18 | vlan 104 10.0.104.0/24 | fw2主fw1备 虚拟IP10.0.104.200 |
[sw1]interface vlan 101
[sw1-Vlanif101]ip address 10.0.101.1 24
[sw1-Vlanif101]ip binding vpn-instance vrf 绑定vrf区域
[sw1]interface vlan 102
[sw1-Vlanif102]ip address 10.0.102.1 24
[sw1]interface Vlanif 101
[sw1-Vlanif101]vrrp vrid 11 virtual-ip 10.0.101.100
[sw1-Vlanif101]vrrp vrid 11 priority 120
[sw1-Vlanif101]vrrp vrid 11 preempt-mode timer delay 20
[sw2]interface vlan 101
[sw2-Vlanif101]ip address 10.0.101.2 24
[sw2-Vlanif101]interface vlan 102
[sw2-Vlanif102]ip address 10.0.102.2 24
[sw2]interface vlan 101
[sw2-Vlanif101]vrrp vrid 11 virtual-ip 10.0.101.100
[sw2-Vlanif101]vrrp vrid 11 preempt-mode timer delay 20
[sw2-Vlanif102]vrrp vrid 12 virtual-ip 10.0.102.100
[sw2-Vlanif102]vrrp vrid 12 priority 120
[sw2-Vlanif102]vrrp vrid 12 preempt-mode timer delay 20
重复以上步骤三次,分别为做好vrf区域的冗余;fw1,fw2对vrf区域的冗余;fw1,fw2对public区域的冗余;public区域的冗余。
[fw1-GigabitEthernet1/0/0.101]ip address 10.0.101.10 24
[fw1-GigabitEthernet1/0/0.101]vlan-type dot1q 101
[fw1-GigabitEthernet1/0/0.101]vrrp vrid 15 virtual-ip 10.0.101.200 active
[fw1-GigabitEthernet1/0/0.102]ip address 10.0.102.10 24
[fw1-GigabitEthernet1/0/0.102]vlan-type dot1q 102
[fw1-GigabitEthernet1/0/0.102]vrrp vrid 16 virtual-ip 10.0.102.200 standby
[fw2-GigabitEthernet1/0/1.101]ip address 10.0.101.20 24
[fw2-GigabitEthernet1/0/1.101]vlan-type dot1q 101
[fw2-GigabitEthernet1/0/1.101]vrrp vrid 15 virtual-ip 10.0.101.200 standby
[fw2-GigabitEthernet1/0/1.102]ip address 10.0.102.20 24
[fw2-GigabitEthernet1/0/1.102]vlan-type dot1q 102
[fw2-GigabitEthernet1/0/1.102]vrrp vrid 16 virtual-ip 10.0.102.200 active
别忘记激活主接口,配置IP再undo
防火墙基础配置
[fw1]hrp mirror session enable 开启防火墙快速备份
[fw1]hrp interface GigabitEthernet 1/0/2 remote 10.10.20.20 定义心跳线
[fw1]hrp enable
[fw2]hrp mirror session enable
[fw2]hrp interface GigabitEthernet 1/0/2 remote 10.10.20.10
[fw2]hrp enable
划分区域,配置安全策略
与vrf区域连接部分为 trust
与public区域连接部分为untrust
心跳线区域为DMZ
写上行流量静态路由,使fw1流量下一跳指向public区域虚拟路由
HRP_M[fw1]ip route-static 0.0.0.0 0 10.0.103.100
HRP_M[fw1]ip route-static 0.0.0.0 0 10.0.104.100 preference 70
HRP_M[fw2]ip route-static 0.0.0.0 0 10.0.103.100 preference 70
HRP_M[fw2]ip route-static 0.0.0.0 0 10.0.104.100
写下行流量静态路由,使fw1流量下一跳指向vrf区域虚拟路由
HRP_M[fw1]ip route-static 192.168.0.0 16 10.0.101.100
HRP_M[fw1]ip route-static 192.168.0.0 16 10.0.102.100 preference 70
HRP_M[fw2]ip route-static 192.168.0.0 16 10.0.101.100 preference 70
HRP_M[fw2]ip route-static 192.168.0.0 16 10.0.101