SW3配置
[SW3]vlan 10
[SW3-vlan10]port g1/0/1
[SW3]vlan 20
[SW3-vlan20]port g1/0/2
[SW3]int ran g1/0/3 to g1/0/4
[SW3-if-range]port link-type trunk
[SW3-if-range]port trunk permit vlan 10 20
[SW3]stp region-configuration
[SW3-mst-region]region-name h3c
[SW3-mst-region]revision-level 0
[SW3-mst-region]instance 10 vlan 10
[SW3-mst-region]instance 20 vlan 20
[SW3-mst-region]active region-configuration
SW1配置
[SW1]int ran g1/0/1 to g1/0/3
[SW1-if-range]port link-type trunk
[SW1-if-range]port trunk permit vlan 10 20
[SW1]stp region-configuration
[SW1-mst-region]region-name h3c
[SW1-mst-region]revision-level 0
[SW1-mst-region]instance 10 vlan 10
[SW1-mst-region]ins
[SW1-mst-region]instance 20 vlan 20
[SW1-mst-region]active region-configuration
[SW1]int Bridge-Aggregation 1
[SW1-Bridge-Aggregation1]port link-type trunk
[SW1-Bridge-Aggregation1]port trunk permit vlan 10 20
[SW1]int ran g1/0/1 to g1/0/2
[SW1-if-range]port link-aggregation group 1
[SW1]stp instance 10 root primary
[SW1]stp instance 20 root secondary
[SW1]int vlan 10
[SW1-Vlan-interface10]ip address 192.168.10.252 24
[SW1-Vlan-interface10]vrrp vrid 10 virtual-ip 192.168.10.254
[SW1-Vlan-interface10]vrrp vrid 10 priority 120
[SW1]int vlan 20
[SW1-Vlan-interface20]ip address 192.168.20.252 24
[SW1-Vlan-interface20]vrrp vrid 20 virtual-ip 192.168.20.254
[SW1-LoopBack0]ip address 3.3.3.3 32
[SW1-GigabitEthernet1/0/4]port link-mode route
[SW1-GigabitEthernet1/0/4]ip address 10.0.1.1 24
[SW1]int vlan 10
[SW1-Vlan-interface10]vrrp vrid 10 track 1 priority reduced 30
[SW1]track 1 int g 1/0/4
!!!配置监视端口不仅可以监视上行端口的物理连接是否可达,还可以监视网络可达性,一旦网络不可达,也可以实现主备切换
track 2 ip route 1.1.1.1 32 reachability-------监视上行环回口可达!!!!
[SW1-ospf-1-area-0.0.0.0]network 192.168.10.0 0.0.0.255-----敲黑板!!!
这里之所以不宣告vlan20的网段是因为考虑安全,要保持vlan10的主机访问外部时来回报文的路径一致,不然一旦网络中有防火墙,可能会被拦截。
[SW1-ospf-1-area-0.0.0.0]network 10.0.1.0 0.0.0.255
[SW1-ospf-1]import-route direct-----路由备份
SW2的配置和SW1的配置基本一致,只是环回口和要宣告的网段不一样而已。
R1的配置
[R1]int g 0/1
[R1-GigabitEthernet0/1]ip address 10.0.1.2 24
[R1-GigabitEthernet0/0]ip address 10.0.2.1 24
[R1-LoopBack0]ip address 1.1.1.1 32
[R1-ospf-1-area-0.0.0.0]network 10.0.1.0 0.0.0.255
[R1-ospf-1-area-0.0.0.0]network 10.0.2.0 0.0.0.255
[R1-LoopBack0]ip address 1.1.1.1 32
R2的配置跟R1基本一致
结果是全网可达,并且在SW1和SW2上面可以实现vrrp主备的切换,在R1上看到学习到的vlan20网段的路由一下跳是R2的0/0端口;在R2上看到学习到的vlan10网段的路由一下跳是R1的0/0端口.