目录
交换机远程登录路由器
拓扑图
R1
[R1]user-interface vty 0 4 # 创建会话
[R1-ui-vty0-4]authentication-mode aaaa # 开启aaa认证
[R1-ui-vty0-4]aaa
[R1-aaa]local-user HCIE password cipher 123456 # 设置账户密码
[R1-aaa]local-user HCIE privilege level 15 # 设置用户权限
[R1-aaa]local-user HCIE service-type telnet # 开启远程登录
#端口配置ip
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip add 192.168.1.254 24
SW1
[SW1]vlan 1
[SW1-Vlanif1]ip add 192.168.1.1 24
[SW1-Vlanif1]q
[SW1]int e0/0/1
[SW1-Ethernet0/0/1]port link-type acc
[SW1-Ethernet0/0/1]port def vlan 1
配置eth-trunk 链路聚合
拓扑图
手工配置eth-trunk 链路聚合
[SW1]int Eth-Trunk 1 //创建并进入 eth-trunk1
[SW1-Eth-Trunk1]mode manual load-balance //配置eth-trunk为手动模式
[SW1-Eth-Trunk1]trunkport g0/0/1 //加入成员端口
[SW1-Eth-Trunk1]trunkport g0/0/2
[SW1-Eth-Trunk1]port link-ty tr // 配置eth-tr 的类型为trunk
[SW1-Eth-Trunk1]port tr a v a // 允许所以vlan通过
[SW2]int Eth-Trunk 1 //创建并进入 eth-trunk1
[SW2-Eth-Trunk1]mode manual load-balance //配置eth-trunk为手动模式
[SW2-Eth-Trunk1]trunkport g0/0/1 //加入成员端口
[SW2-Eth-Trunk1]trunkport g0/0/2
[SW2-Eth-Trunk1]port link-ty tr // 配置eth-tr 的类型为trunk
[SW2-Eth-Trunk1]port tr a v a // 允许所以vlan通过
dis eth-trunk 1 //查看当前设备配置的物理接口
LACP配置eth-trunk
int eth-Trunk 1 # 创建并进入
mode lacp-static 开启为LACP模式
trunkport e0/0/1 加入端口
max active-linknumber 2 # 最大连接数 (默认为八个)
lacp preempt enable # 开启抢占功能
lacp preempt delay 10 # 抢占时间改为10秒(默认30 秒)
lacp priority 200 # 设置优先级为100 (默认为32768,数值越小优先级越高)
dis eth-trunk 1 # 查看链路聚合中有那些物理端口
undo trunkport e0/0/1 将端口从聚合端口中删除
mstp
mux-vlan
拓扑图
vlan10能ping通服务器 能相互ping通
外来访客不能相互访问,可以访问服务器 不能访问内部员工 vlan20
<Huawei>sy
[Huawei]vlan batch 10 20 60
[Huawei]vlan 60
[Huawei-vlan60]mux-vlan
[Huawei-vlan60]subordinate group 10 # 设置组vlan10
[Huawei-vlan60]subordinate separate 20 # 设置隔离vlan20
[Huawei-vlan60]q
[Huawei]int g
[Huawei]port-group 1
[Huawei-port-group-1]group-member e0/0/1 e0/0/2
[Huawei-port-group-1]port link-ty acc
[Huawei-port-group-1]port def vlan 10
[Huawei-Ethernet0/0/1]port def vlan 10
[Huawei-Ethernet0/0/2]port def vlan 10
[Huawei-port-group-1]port mux
[Huawei-port-group-1]port mux-vlan en
[Huawei-port-group-1]port mux-vlan enable
[Huawei-Ethernet0/0/1]port mux-vlan enable
Error: Please enable MUX-VLAN in vlan command mode.
[Huawei-Ethernet0/0/2]port mux-vlan enable
Error: Please enable MUX-VLAN in vlan command mode
单臂路由配置
拓扑图
R1
[R1]int g0/0/0.1 # 接口有1-4096
[R1-GigabitEthernet0/0/0.1]dot1q termination vid 10 #
[R1-GigabitEthernet0/0/0.1]ip add 192.168.10.1 24 #
[R1-GigabitEthernet0/0/0.1]arp broadcast enable #
[R1-GigabitEthernet0/0/0.1]int g0/0/0.2
[R1-GigabitEthernet0/0/0.2]dot1q termination vid 20
[R1-GigabitEthernet0/0/0.2]ip add 192.168.20.1 24
[R1-GigabitEthernet0/0/0.2]arp broadcast enable
SW1
[SW1]int e0/0/3
[SW1-Ethernet0/0/3]port link-ty tr
[SW1-Ethernet0/0/3]port tr a v a
[SW1-Ethernet0/0/3]int e0/0/1
[SW1-Ethernet0/0/1]port link-ty acc
[SW1-Ethernet0/0/1]port def vlan 10
[SW1-Ethernet0/0/1]int e0/0/2
[SW1-Ethernet0/0/2]port link-ty acc
[SW1-Ethernet0/0/2]port def vlan 20
测试 ping 192.168.20.2 能通
DHCP配置
[R1]dhcp en # 开启DHCP服务
[R1]ip pool vlan1 # 创建名称vlan1的地址池
[R1-ip-pool-vlan1]network 192.168.1.0 mask 24 # 网段
[R1-ip-pool-vlan1]gateway-list 192.168.1.254 # 网关
[R1-ip-pool-vlan1]dns-list 114.114.114.114 # DNS服务
[R1-ip-pool-vlan1]lease day 3 # 地址租期
[R1-ip-pool-vlan1]q
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip add 192.168.1.254 24
[R1-GigabitEthernet0/0/0]dhcp select global # 开启DHCP功能
pc端开启DHCP服务
ipconfig 查看是否获取到地址
DHCP中继
拓扑图
R1
[R1]dhcp en
[R1]ip pool vlan10
[R1-ip-pool-vlan10]network 192.168.10.0 mask 24
[R1-ip-pool-vlan10]gateway-list 192.168.10.254
[R1-ip-pool-vlan10]dns-list 114.114.114.114
[R1-ip-pool-vlan10]lease day 3
[R1-ip-pool-vlan10]q
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip add 10.10.10.1 24
[R1-GigabitEthernet0/0/0]dhcp select global
[R1]ip route-static 192.168.10.0 24 10.10.10.2 # 配一个静态路由到10.0网段
R2
[R2]dhcp en
[R2]int g0/0/0
[R2-GigabitEthernet0/0/0]ip add 10.10.10.2 24
[R2-GigabitEthernet0/0/0]int g0/0/1
[R2-GigabitEthernet0/0/1]ip add 192.168.10.254 24
[R2-GigabitEthernet0/0/1]dhcp select relay # 开启选择dhcp中继
[R2-GigabitEthernet0/0/1]dhcp relay server-ip 10.10.10.1 # 中继的端口ip
pc1 可以拿到IP地址
浮动路由
R1
[R1]int g0/0/1
[R1-GigabitEthernet0/0/1]ip add 192.168.40.1 24
[R1-GigabitEthernet0/0/1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip add 192.168.30.1 24
[R1-GigabitEthernet0/0/0]q
[R1]ip route-static 192.168.20.0 24 192.168.30.2
[R1]ip route-static 192.168.20.0 24 192.168.40.2 preference 100
// 因为主线路默认优先级是60,所以备线路的优先级需大于60,(静态路由选路原则是优先级越小就越优先)
[R1-GigabitEthernet2/0/1]ip add 192.168.10.254 24
[R2]int g0/0/0
[R2-GigabitEthernet0/0/0]ip add 192.168.30.2 24
[R2-GigabitEthernet0/0/0]int g0/0/1
[R2-GigabitEthernet0/0/1]ip add 192.168.40.2 24
[R2-GigabitEthernet0/0/1]q
[R2]ip route-static 192.168.10.0 24 192.168.30.1
[R2]ip route-static 192.168.10.0 24 192.168.40.1 preference 100
[R2-GigabitEthernet2/0/1]ip add 192.168.20.254 24
测试
关闭g0/0/0 接口 路由会切换到备份线路
VRRP配置
R1
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip add 192.168.1.252 24
[R1-GigabitEthernet0/0/0]vrrp vrid 1 virtual-ip 192.168.1.254 // 配置虚拟网关
[R1-GigabitEthernet0/0/0]vrrp vrid 1 priority 200
// 给优先级 优先级越大越高 默认情况下优先级为100,最大可以配置的优先级为1-254
[R1-GigabitEthernet0/0/0]q
[R1]dis vrrp br // 查看配置
Total:1 Master:1 Backup:0 Non-active:0
VRID State Interface Type Virtual IP
----------------------------------------------------------------
1 Master GE0/0/0 Normal 192.168.1.254
// Master 主
R2
[R2]int g0/0/0
[R2-GigabitEthernet0/0/0]ip add 192.168.1.253 24
[R2-GigabitEthernet0/0/0]vrrp vrid
[R2-GigabitEthernet0/0/0]vrrp vrid 1 vir
[R2-GigabitEthernet0/0/0]vrrp vrid 1 virtual-ip 192.168.1.254
[R2-GigabitEthernet0/0/0]q
[R2]dis vrrp br
Total:1 Master:0 Backup:1 Non-active:0
VRID State Interface Type Virtual IP
----------------------------------------------------------------
1 Backup GE0/0/0 Normal 192.168.1.254
Backup 从
vrrp vrid 1 track interface g0/0/1 reduced 110 进入vrrp接口 降低vrrp等级
ACL
R1
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip add 192.168.10.254 24
[R1-GigabitEthernet0/0/0]int g0/0/1
[R1-GigabitEthernet0/0/1]ip add 192.168.1.254 24
[R1-GigabitEthernet0/0/1]int g0/0/2
[R1-GigabitEthernet0/0/2]ip add 192.168.2.254 24
[R1-GigabitEthernet0/0/2]q
[R1]acl 2000
[R1-acl-basic-2000]rule 10 deny source 192.168.1.0 0.0.0.255
rule 10(名称靠前优先级高) deny(不允许) source 192.168.1.0 0.0.0.255 (整个1.0网段)
[R1-acl-basic-2000]int g0/0/0
[R1-GigabitEthernet0/0/0]traffic-filter outbound acl 2000
测试 192.168.1.0 网段不能ping通服务器