链路聚合、STP 、VRRP、IGP、DHCP、AP上线

R1 

[V200R003C00]

#

 sysname R1

#

 snmp-agent local-engineid 800007DB03000000000000

 snmp-agent

#

 clock timezone China-Standard-Time minus 08:00:00

#

portal local-server load flash:/portalpage.zip

#

 drop illegal-mac alarm

#

 wlan ac-global carrier id other ac id 0

#

 set cpu-usage threshold 80 restore 75

#

dhcp enable

#

ip pool A

 gateway-list 192.168.10.254

 network 192.168.10.0 mask 255.255.255.0

 static-bind ip-address 192.168.10.10 mac-address 5489-9868-778c

 static-bind ip-address 192.168.10.11 mac-address 5489-98aa-1299

 dns-list 8.8.8.8

#

ip pool B

 gateway-list 192.168.20.254

 network 192.168.20.0 mask 255.255.255.0

 static-bind ip-address 192.168.20.10 mac-address 5489-98af-524d

 static-bind ip-address 192.168.20.21 mac-address 5489-98b4-5ac6

 dns-list 114.114.114.114

#

aaa

 authentication-scheme default

 authorization-scheme default

 accounting-scheme default

 domain default

 domain default_admin

 local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$

 local-user admin service-type http

#

firewall zone Local

 priority 15

#

interface GigabitEthernet0/0/0

 ip address 192.168.11.1 255.255.255.0

 dhcp select global

#

interface GigabitEthernet0/0/1

 ip address 192.168.13.1 255.255.255.0

 dhcp select global

#

interface GigabitEthernet0/0/2

 ip address 10.1.12.1 255.255.255.0

#

interface NULL0

#

interface LoopBack0

 ip address 1.1.1.1 255.255.255.255

#

ospf 1

 area 0.0.0.0

  network 192.168.11.0 0.0.0.255

  network 192.168.13.0 0.0.0.255

#

user-interface con 0

 authentication-mode password

user-interface vty 0 4

user-interface vty 16 20

#

wlan ac

#

return

LSW1

#

sysname SW1

#

vlan batch 10 to 11 13 20 30

#

stp instance 1 root primary

stp instance 2 root secondary

stp bpdu-protection

#

cluster enable

ntdp enable

ndp enable

#

drop illegal-mac alarm

#

dhcp enable

#

diffserv domain default

#

stp region-configuration

 region-name huawei

 revision-level 1

 instance 1 vlan 10 to 11 30

 instance 2 vlan 13 20

 active region-configuration

#

drop-profile default

#

aaa

 authentication-scheme default

 authorization-scheme default

 accounting-scheme default

 domain default

 domain default_admin

 local-user admin password simple admin

 local-user admin service-type http

#

interface Vlanif1

#

interface Vlanif10

 ip address 192.168.10.1 255.255.255.0

 vrrp vrid 1 virtual-ip 192.168.10.254

 vrrp vrid 1 priority 200

 vrrp vrid 1 track interface GigabitEthernet0/0/2 reduced 110

 dhcp select relay

 dhcp relay server-ip 192.168.11.1

#

interface Vlanif11

 ip address 192.168.11.11 255.255.255.0

#

interface Vlanif20

 ip address 192.168.20.1 255.255.255.0

 vrrp vrid 2 virtual-ip 192.168.20.254

 dhcp select relay

 dhcp relay server-ip 192.168.13.1

#

interface MEth0/0/1

#

interface Eth-Trunk0

 port link-type trunk

 port trunk allow-pass vlan 10 to 11 13 20 30

 mode lacp-static

 max active-linknumber 2

#

interface GigabitEthernet0/0/1

 port link-type trunk

 port trunk allow-pass vlan 10 to 11 13 20 30

#

interface GigabitEthernet0/0/2

 port link-type access

 port default vlan 11

 stp edged-port enable

#

interface GigabitEthernet0/0/3

 eth-trunk 0

#

interface GigabitEthernet0/0/4

 eth-trunk 0

#

interface GigabitEthernet0/0/5

 eth-trunk 0

#

interface GigabitEthernet0/0/6

 port link-type trunk

 port trunk allow-pass vlan 10 to 11 13 20 30

#

interface GigabitEthernet0/0/7

 port link-type trunk

 port trunk allow-pass vlan 10 to 11 13 20 30

#

interface GigabitEthernet0/0/8

#

interface GigabitEthernet0/0/9

#

interface GigabitEthernet0/0/10

#

interface GigabitEthernet0/0/11

#

interface GigabitEthernet0/0/12

#

interface GigabitEthernet0/0/13

#

interface GigabitEthernet0/0/14

#

interface GigabitEthernet0/0/15

#

interface GigabitEthernet0/0/16

#

interface GigabitEthernet0/0/17

#

interface GigabitEthernet0/0/18

#

interface GigabitEthernet0/0/19

#

interface GigabitEthernet0/0/20

#

interface GigabitEthernet0/0/21

#

interface GigabitEthernet0/0/22

#

interface GigabitEthernet0/0/23

#

interface GigabitEthernet0/0/24

#

interface NULL0

#

ospf 1

 area 0.0.0.0

  network 192.168.10.0 0.0.0.255

  network 192.168.20.0 0.0.0.255

  network 192.168.11.0 0.0.0.255

  network 192.168.30.0 0.0.0.255

#

user-interface con 0

user-interface vty 0 4

#

return�

LSW2

#

sysname SW2

#

vlan batch 10 to 11 13 20 30

#

stp instance 1 root secondary

stp instance 2 root primary

stp bpdu-protection

#

lacp priority 10000

#

cluster enable

ntdp enable

ndp enable

#

drop illegal-mac alarm

#

dhcp enable

#

diffserv domain default

#

stp region-configuration

 region-name huawei

 revision-level 1

 instance 1 vlan 10 to 11 30

 instance 2 vlan 13 20

 active region-configuration

#

drop-profile default

#

aaa

 authentication-scheme default

 authorization-scheme default

 accounting-scheme default

 domain default

 domain default_admin

 local-user admin password simple admin

 local-user admin service-type http

#

interface Vlanif1

#

interface Vlanif10

 ip address 192.168.10.2 255.255.255.0

 vrrp vrid 1 virtual-ip 192.168.10.254

 dhcp select relay

 dhcp relay server-ip 192.168.11.1

#

interface Vlanif13

 ip address 192.168.13.12 255.255.255.0

#

interface Vlanif20

 ip address 192.168.20.2 255.255.255.0

 vrrp vrid 2 virtual-ip 192.168.20.254

 vrrp vrid 2 priority 200

 vrrp vrid 2 track interface GigabitEthernet0/0/1 reduced 110

 dhcp select relay

 dhcp relay server-ip 192.168.13.1

#

interface MEth0/0/1

#

interface Eth-Trunk0

 port link-type trunk

 port trunk allow-pass vlan 10 to 11 13 20 30

 mode lacp-static

 max active-linknumber 2

#

interface GigabitEthernet0/0/1

 port link-type access

 port default vlan 13

 stp edged-port enable

#

interface GigabitEthernet0/0/2

 port link-type trunk

 port trunk allow-pass vlan 10 to 11 13 20 30

#

interface GigabitEthernet0/0/3

 eth-trunk 0

#

interface GigabitEthernet0/0/4

 eth-trunk 0

#

interface GigabitEthernet0/0/5

 eth-trunk 0

#

interface GigabitEthernet0/0/6

 port link-type trunk

 port trunk allow-pass vlan 10 to 11 13 20 30

#

interface GigabitEthernet0/0/7

#

interface GigabitEthernet0/0/8

#

interface GigabitEthernet0/0/9

#

interface GigabitEthernet0/0/10

#

interface GigabitEthernet0/0/11

#

interface GigabitEthernet0/0/12

#

interface GigabitEthernet0/0/13

#

interface GigabitEthernet0/0/14

#

interface GigabitEthernet0/0/15

#

interface GigabitEthernet0/0/16

#

interface GigabitEthernet0/0/17

#

interface GigabitEthernet0/0/18

#

interface GigabitEthernet0/0/19

#

interface GigabitEthernet0/0/20

#

interface GigabitEthernet0/0/21

#

interface GigabitEthernet0/0/22

#

interface GigabitEthernet0/0/23

#

interface GigabitEthernet0/0/24

#

interface NULL0

#

ospf 1

 area 0.0.0.0

  network 192.168.13.0 0.0.0.255

  network 192.168.10.0 0.0.0.255

  network 192.168.20.0 0.0.0.255

#

user-interface con 0

user-interface vty 0 4

#

return�

LSW3

#

sysname Huawei

#

vlan batch 10 to 11 13 20 30

#

stp bpdu-protection

#

cluster enable

ntdp enable

ndp enable

#

drop illegal-mac alarm

#

diffserv domain default

#

stp region-configuration

 region-name huawei

 revision-level 1

 instance 1 vlan 10 to 11 30

 instance 2 vlan 13 20

 active region-configuration

#

drop-profile default

#

aaa

 authentication-scheme default

 authorization-scheme default

 accounting-scheme default

 domain default

 domain default_admin

 local-user admin password simple admin

 local-user admin service-type http

#

interface Vlanif1

#

interface MEth0/0/1

#

interface GigabitEthernet0/0/1

 port link-type trunk

 port trunk allow-pass vlan 10 to 11 13 20 30

#

interface GigabitEthernet0/0/2

 port link-type trunk

 port trunk allow-pass vlan 10 to 11 13 20 30

#

interface GigabitEthernet0/0/3

 port link-type access

 port default vlan 10

 stp edged-port enable

#

interface GigabitEthernet0/0/4

 port link-type access

 port default vlan 20

 stp edged-port enable

#

interface GigabitEthernet0/0/5

 port link-type trunk

 port trunk pvid vlan 30

 port trunk allow-pass vlan 10 to 11 13 20 30

#

interface GigabitEthernet0/0/6

#

interface GigabitEthernet0/0/7

#

interface GigabitEthernet0/0/8

#

interface GigabitEthernet0/0/9

#

interface GigabitEthernet0/0/10

#

interface GigabitEthernet0/0/11

#

interface GigabitEthernet0/0/12

#

interface GigabitEthernet0/0/13

#

interface GigabitEthernet0/0/14

#

interface GigabitEthernet0/0/15

#

interface GigabitEthernet0/0/16

#

interface GigabitEthernet0/0/17

#

interface GigabitEthernet0/0/18

#

interface GigabitEthernet0/0/19

#

interface GigabitEthernet0/0/20

#

interface GigabitEthernet0/0/21

#

interface GigabitEthernet0/0/22

#

interface GigabitEthernet0/0/23

#

interface GigabitEthernet0/0/24

#

interface NULL0

#

user-interface con 0

user-interface vty 0 4

#

return�

LSW4

#

sysname SW4

#

vlan batch 10 to 11 13 20 30

#

stp bpdu-protection

#

cluster enable

ntdp enable

ndp enable

#

drop illegal-mac alarm

#

diffserv domain default

#

stp region-configuration

 region-name huawei

 revision-level 1

 instance 1 vlan 10 to 11 30

 instance 2 vlan 13 20

 active region-configuration

#

drop-profile default

#

aaa

 authentication-scheme default

 authorization-scheme default

 accounting-scheme default

 domain default

 domain default_admin

 local-user admin password simple admin

 local-user admin service-type http

#

interface Vlanif1

#

interface MEth0/0/1

#

interface GigabitEthernet0/0/1

 port link-type trunk

 port trunk allow-pass vlan 10 to 11 13 20 30

#

interface GigabitEthernet0/0/2

 port link-type trunk

 port trunk allow-pass vlan 10 to 11 13 20 30

#

interface GigabitEthernet0/0/3

 port link-type access

 port default vlan 10

 stp edged-port enable

#

interface GigabitEthernet0/0/4

 port link-type access

 port default vlan 20

 stp edged-port enable

#

interface GigabitEthernet0/0/5

 port link-type trunk

 port trunk pvid vlan 30

 port trunk allow-pass vlan 10 to 11 13 20 30

#

interface GigabitEthernet0/0/6

#

interface GigabitEthernet0/0/7

#

interface GigabitEthernet0/0/8

#

interface GigabitEthernet0/0/9

#

interface GigabitEthernet0/0/10

#

interface GigabitEthernet0/0/11

#

interface GigabitEthernet0/0/12

#

interface GigabitEthernet0/0/13

#

interface GigabitEthernet0/0/14

#

interface GigabitEthernet0/0/15

#

interface GigabitEthernet0/0/16

#

interface GigabitEthernet0/0/17

#

interface GigabitEthernet0/0/18

#

interface GigabitEthernet0/0/19

#

interface GigabitEthernet0/0/20

#

interface GigabitEthernet0/0/21

#

interface GigabitEthernet0/0/22

#

interface GigabitEthernet0/0/23

#

interface GigabitEthernet0/0/24

#

interface NULL0

#

user-interface con 0

user-interface vty 0 4

#

return�

AC

[V200R007C10SPC300]

#

 set memory-usage threshold 0

#

ssl renegotiation-rate 1

#

vlan batch 10 to 11 13 20 30

#

authentication-profile name default_authen_profile

authentication-profile name dot1x_authen_profile

authentication-profile name mac_authen_profile

authentication-profile name portal_authen_profile

authentication-profile name macportal_authen_profile

#

vlan pool ap

 vlan 10 20

#

dhcp enable

#

diffserv domain default

#

radius-server template default

#

pki realm default

 rsa local-key-pair default

 enrollment self-signed

#

ike proposal default

 encryption-algorithm aes-256

 dh group14

 authentication-algorithm sha2-256

 authentication-method pre-share

 integrity-algorithm hmac-sha2-256

 prf hmac-sha2-256

#

free-rule-template name default_free_rule

#

portal-access-profile name portal_access_profile

#

aaa

 authentication-scheme default

 authentication-scheme radius

  authentication-mode radius

 authorization-scheme default

 accounting-scheme default

 domain default

  authentication-scheme radius

  radius-server default

 domain default_admin

  authentication-scheme default

 local-user admin password irreversible-cipher $1a$N6"y/KxG(-$0#%t<$bi4@Yb@p#KzJqJlL0$@1+=cCwxIJ3Sf7vA$

 local-user admin privilege level 15

 local-user admin service-type http

#

interface Vlanif30

 ip address 192.168.30.1 255.255.255.0

 dhcp select interface

#

interface MEth0/0/1

 undo negotiation auto

 duplex half

#

interface GigabitEthernet0/0/1

 port link-type trunk

 port trunk allow-pass vlan 10 to 11 13 20 30

#

interface GigabitEthernet0/0/2

#

interface GigabitEthernet0/0/3

#

interface GigabitEthernet0/0/4

#

interface GigabitEthernet0/0/5

#

interface GigabitEthernet0/0/6

#

interface GigabitEthernet0/0/7

#

interface GigabitEthernet0/0/8

#

interface GigabitEthernet0/0/9

#

interface GigabitEthernet0/0/10

#

interface GigabitEthernet0/0/11

#

interface GigabitEthernet0/0/12

#

interface GigabitEthernet0/0/13

#

interface GigabitEthernet0/0/14

#

interface GigabitEthernet0/0/15

#

interface GigabitEthernet0/0/16

#

interface GigabitEthernet0/0/17

#

interface GigabitEthernet0/0/18

#

interface GigabitEthernet0/0/19

#

interface GigabitEthernet0/0/20

#

interface GigabitEthernet0/0/21

 undo negotiation auto

 duplex half

#

interface GigabitEthernet0/0/22

 undo negotiation auto

 duplex half

#

interface GigabitEthernet0/0/23

 undo negotiation auto

 duplex half

#

interface GigabitEthernet0/0/24

 undo negotiation auto

 duplex half

#

interface XGigabitEthernet0/0/1

#

interface XGigabitEthernet0/0/2

#

interface NULL0

#

 snmp-agent local-engineid 800007DB03000000000000

 snmp-agent

#

ssh server secure-algorithms cipher aes256_ctr aes128_ctr

ssh server key-exchange dh_group14_sha1

ssh client secure-algorithms cipher aes256_ctr aes128_ctr

ssh client secure-algorithms hmac sha2_256

ssh client key-exchange dh_group14_sha1

#

capwap source interface vlanif30

#

user-interface con 0

 authentication-mode password

user-interface vty 0 4

 protocol inbound all

user-interface vty 16 20

 protocol inbound all

#

wlan

 traffic-profile name default

 security-profile name ap

  security wpa-wpa2 psk pass-phrase %^%#(yvR+H-c1Lwt!DN]i3z0etYq:Ey-}*AI%R*`Ap-M%^%# aes

 security-profile name default

 security-profile name default-wds

 security-profile name default-mesh

 ssid-profile name ap

  ssid 1

 ssid-profile name default

 vap-profile name ap

  service-vlan vlan-pool ap

  ssid-profile ap

  security-profile ap

 vap-profile name default

 wds-profile name default

 mesh-handover-profile name default

 mesh-profile name default

 regulatory-domain-profile name default

 air-scan-profile name default

 rrm-profile name default

 radio-2g-profile name default

 radio-5g-profile name default

 wids-spoof-profile name default

 wids-profile name default

 wireless-access-specification

 ap-system-profile name default

 port-link-profile name default

 wired-port-profile name default

 serial-profile name preset-enjoyor-toeap

 ap-group name ap1

  radio 0

   vap-profile ap wlan 1

 ap-group name ap2

  radio 0

   vap-profile ap wlan 1

   channel 20mhz 5

 ap-group name default

 ap-id 1 type-id 60 ap-mac 00e0-fc84-0260 ap-sn 210235448310C62F1E12

  ap-name ap1

  ap-group ap1

 ap-id 2 type-id 60 ap-mac 00e0-fca4-2500 ap-sn 210235448310B404FA30

  ap-name ap2

  ap-group ap2

 provision-ap

#

dot1x-access-profile name dot1x_access_profile

#

mac-access-profile name mac_access_profile

#

return

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值