双机热备配置实验

总拓扑图

下层交换部分

网络基础配置:IP地址,VLAN,mstp,vrrp

IP地址划分和vlan

pc1---sw5192.168.2.0/24vlan 2
pc2---sw5192.168.3.0/24vlan 3
[sw3]undo info-center enable 
[sw3]vlan batch 2 3
[sw3-GigabitEthernet0/0/4]port link-type trunk      猜测因为后续sw3需要成为两个网段的网关,应该需要修改为truck链路
[sw3-GigabitEthernet0/0/4]port trunk allow-pass vlan 2 to 3
[sw3-GigabitEthernet0/0/2]port link-type trunk 	
[sw3-GigabitEthernet0/0/2]port trunk allow-pass vlan 2 to 3

[sw3]interface Vlanif 2
[sw3-Vlanif2]ip address 192.168.2.254 24
[sw3]interface Vlanif 3
[sw3-Vlanif3]ip address 192.168.3.254 24

vrrp配置

sw3为vlan2的主网关,sw4为vlan3的主网关,互为对方的备网关

[sw3]interface Vlanif 2
[sw3-Vlanif2]vrrp vrid 1 virtual-ip 192.168.2.252  配置虚拟IP
[sw3-Vlanif2]vrrp vrid 1 priority 120              配置优先级
[sw3-Vlanif2]vrrp vrid 1 preempt-mode  timer delay 20  配置抢占延迟
[sw3]interface Vlanif 3 
[sw3-Vlanif3]vrrp vrid 2 virtual-ip 192.168.3.252
[sw3-Vlanif3]vrrp vrid 2 priority 80
[sw3-Vlanif3]vrrp vrid 2 preempt-mode  timer delay 20

测试

关闭一个接口,ping虚拟网关可以ping通,交换层vrrp配置完成

配置mstp

[sw3]stp mode mstp 
[sw3]stp region-configuration   
[sw3-mst-region]region-name sw
[sw3-mst-region]instance 1 vlan 2
[sw3-mst-region]instance 2 vlan 3	
[sw3-mst-region]active region-configuration 
[sw3]stp instance 1 root primary 
[sw3]stp instance 2 root secondary 

sw4类似配置

[sw5]stp mode mstp 
[sw5]stp region-configuration 
[sw5-mst-region]region-name sw
[sw5-mst-region]instance 1 vlan 2
[sw5-mst-region]instance 2 vlan 3
[sw5-mst-region]active region-configuration 
[sw5-GigabitEthernet0/0/3]stp edged-port enable 
[sw5-GigabitEthernet0/0/4]stp edged-port enable   开启边缘接口

上层交换部分

IP地址划分和vlan

sw1---sw210.0.12.0/24vlan 12
sw1---sw310.0.13.0/24vlan 13
sw1---sw410.0.14.0/24vlan 14
sw2---sw310.0.23.0/24vlan 23
sw2---sw410.0.24.0/24vlan 24
sw3---sw410.0.34.0/24vlan 34

先将sw1和sw2分为vrf和public区域

[sw1]ip vpn-instance vrf
[sw1-vpn-instance-vrf]route-distinguisher 100:1
[sw1-vpn-instance-vrf-af-ipv4]vpn-target 100:1 both 

[sw1-Vlanif13]ip address 10.0.13.1 24
[sw1-Vlanif13]ip binding  vpn-instance vrf  接口划到vrf区域

将vlan划入接口

[sw1]interface g0/0/3
[sw1-GigabitEthernet0/0/3]port link-type access 
[sw1-GigabitEthernet0/0/3]port default vlan 12
[sw1]interface g0/0/4
[sw1-GigabitEthernet0/0/4]port link-type access 
[sw1-GigabitEthernet0/0/4]port default vlan 13
[sw1-GigabitEthernet0/0/5]port link-type  access
[sw1-GigabitEthernet0/0/5]port default vlan 14 

sw2类似,sw3和sw4之间的链路为truck,好像改为access也没事,因为是三层交换机,可以通过路由表转发

进接口关闭stp功能

[sw1-GigabitEthernet0/0/4]undo stp enable  

尝试过配置mstp出现了很多不明所以的问题,例如vlan和实例划分问题和sw3和sw4同时运行了两个mstp,不知道如何分配的问题,而且因为这个网络有五个vlan,需要创建五个实例,非常麻烦,并不符合常理。而且理论上来说,上层交换机都是三层交换机,通过路由表转发,也不需要使用stp协议确保无环。

配置OSPF

[sw1]ospf 1 router-id 1.1.1.1 vpn-instance vrf
[sw1-ospf-1]area 0
[sw1-ospf-1-area-0.0.0.0]network 10.0.12.1 0.0.0.0
[sw1-ospf-1-area-0.0.0.0]network 10.0.13.1 0.0.0.0
[sw1-ospf-1-area-0.0.0.0]network 10.0.14.1 0.0.0.0
[sw3-ospf-1]silent-interface Vlanif 34      设置静默接口

[sw1]display ip routing-table vpn-instance vrf  查看vrf上的路由信息

发现去往192.168.2.0和192.168.3.0网段的流量形成等价路由了,需要通过策略在sw3和sw4上修改路由信息的cost值。

[sw3-Vlanif23]ospf cost 5



[sw3]ip ip-prefix aa permit 192.168.2.0 24	
[sw3]ip ip-prefix bb permit 192.168.3.0 24
[sw3]route-policy aa permit node 10	
[sw3-route-policy]if-match ip-prefix aa
[sw3-route-policy]apply cost 1
[sw3]route-policy bb permit node 20
[sw3-route-policy]if-match ip-prefix bb
[sw3-route-policy]apply cost 5
[sw3-ospf-1]import-route direct route-policy aa
[sw3-ospf-1]import-route direct route-policy bb

配置vrrp

vrrp 11vlan 101   10.0.101.0/24vsw1主vsw2备   虚拟IP10.0.101.100
vrrp 12vlan 102   10.0.102.0/24vsw2主vsw1备  虚拟IP10.0.102.100
vrrp 13vlan 103   10.0.103.0/24psw1主psw2备  虚拟IP10.0.103.100
vrrp 14vlan 104   10.0.104.0/24psw1主psw2备  虚拟IP10.0.104.100
vrrp 15vlan 101  10.0.101.0/24fw1主fw2备        虚拟IP10.0.101.200
vrrp 16vlan 102   10.0.102.0/24fw2主fw1备       虚拟IP10.0.102.200
vrrp 17vlan 103   10.0.103.0/24fw1主fw2备       虚拟IP10.0.103.200
vrrp 18vlan 104   10.0.104.0/24fw2主fw1备       虚拟IP10.0.104.200
[sw1]interface vlan 101
[sw1-Vlanif101]ip address 10.0.101.1 24
[sw1-Vlanif101]ip binding vpn-instance vrf   绑定vrf区域
[sw1]interface vlan 102
[sw1-Vlanif102]ip address 10.0.102.1 24
[sw1]interface Vlanif 101
[sw1-Vlanif101]vrrp vrid 11 virtual-ip 10.0.101.100
[sw1-Vlanif101]vrrp vrid 11 priority 120	
[sw1-Vlanif101]vrrp vrid 11 preempt-mode timer delay 20


[sw2]interface vlan 101
[sw2-Vlanif101]ip address 10.0.101.2 24
[sw2-Vlanif101]interface vlan 102
[sw2-Vlanif102]ip address 10.0.102.2 24
[sw2]interface vlan 101
[sw2-Vlanif101]vrrp vrid 11 virtual-ip 10.0.101.100	
[sw2-Vlanif101]vrrp vrid 11 preempt-mode timer delay 20
[sw2-Vlanif102]vrrp vrid 12 virtual-ip 10.0.102.100	
[sw2-Vlanif102]vrrp vrid 12 priority 120	
[sw2-Vlanif102]vrrp vrid 12 preempt-mode timer delay 20

重复以上步骤三次,分别为做好vrf区域的冗余;fw1,fw2对vrf区域的冗余;fw1,fw2对public区域的冗余;public区域的冗余。

[fw1-GigabitEthernet1/0/0.101]ip address 10.0.101.10 24
[fw1-GigabitEthernet1/0/0.101]vlan-type dot1q 101
[fw1-GigabitEthernet1/0/0.101]vrrp vrid 15 virtual-ip 10.0.101.200 active 

[fw1-GigabitEthernet1/0/0.102]ip address 10.0.102.10 24
[fw1-GigabitEthernet1/0/0.102]vlan-type dot1q 102
[fw1-GigabitEthernet1/0/0.102]vrrp vrid 16 virtual-ip 10.0.102.200 standby 



[fw2-GigabitEthernet1/0/1.101]ip address 10.0.101.20 24
[fw2-GigabitEthernet1/0/1.101]vlan-type dot1q 101
[fw2-GigabitEthernet1/0/1.101]vrrp vrid 15 virtual-ip 10.0.101.200 standby 

[fw2-GigabitEthernet1/0/1.102]ip address 10.0.102.20 24
[fw2-GigabitEthernet1/0/1.102]vlan-type dot1q 102
[fw2-GigabitEthernet1/0/1.102]vrrp vrid 16 virtual-ip 10.0.102.200 active 
别忘记激活主接口,配置IP再undo

防火墙基础配置

[fw1]hrp mirror session enable      开启防火墙快速备份
[fw1]hrp interface GigabitEthernet 1/0/2 remote 10.10.20.20  定义心跳线
[fw1]hrp enable

[fw2]hrp mirror session enable 
[fw2]hrp interface GigabitEthernet 1/0/2 remote 10.10.20.10
[fw2]hrp enable

划分区域,配置安全策略

与vrf区域连接部分为 trust

与public区域连接部分为untrust

心跳线区域为DMZ


写上行流量静态路由,使fw1流量下一跳指向public区域虚拟路由
HRP_M[fw1]ip route-static 0.0.0.0 0 10.0.103.100
HRP_M[fw1]ip route-static 0.0.0.0 0 10.0.104.100 preference  70

HRP_M[fw2]ip route-static 0.0.0.0 0 10.0.103.100 preference 70
HRP_M[fw2]ip route-static 0.0.0.0 0 10.0.104.100



写下行流量静态路由,使fw1流量下一跳指向vrf区域虚拟路由
HRP_M[fw1]ip route-static 192.168.0.0 16 10.0.101.100
HRP_M[fw1]ip route-static 192.168.0.0 16 10.0.102.100 preference 70

HRP_M[fw2]ip route-static 192.168.0.0 16 10.0.101.100 preference 70
HRP_M[fw2]ip route-static 192.168.0.0 16 10.0.101

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值