华为交换机3线机房策略路由和QoS的配置

3线机房的出口交换机的典型配置,注意以下几个方面:
1、内网网关的配置使用一个SVI vlan-interface 多个IP地址 
2、使用PBR加默认路由的静态路由方案
3、使用了NTP流量放大攻击防御技术
4、使用了端口聚合组技术(3层端口,负载均衡)
5、使用了QOS技术的拥塞管理和拥塞避免技术

既然是三线,那么先配置三线互联接口,三线互联接口这个案例是使用三层聚合端口组

[~HUAWEI]interface Eth-Trunk1

[*HUAWEI-Eth-Trunk1] undo portswitch

[*HUAWEI-Eth-Trunk1] description UPLink_YD

[*HUAWEI-Eth-Trunk1] ip address 192.168.1.2 255.255.255.252

[*HUAWEI-Eth-Trunk1] mode lacp-static

[*HUAWEI-Eth-Trunk1] traffic-filter acl DENY-UDP inbound 

[*HUAWEI-Eth-Trunk1]#新建三层接口用于和移动ISP互联,本端IP为192.168.1.2,对端为192.168.1.1并且调用之前写的ACL用于阻止入方向UDP协议的NTP协议,端口号123,可能是为了防止NTP流量放大攻击

[*HUAWEI]interface Eth-Trunk2

[*HUAWEI-Eth-Trunk2] undo portswitch

[*HUAWEI-Eth-Trunk2] description UPLink_DX

[*HUAWEI-Eth-Trunk2] ip address 192.168.11.2 255.255.255.252

[*HUAWEI-Eth-Trunk2] mode lacp-static

[*HUAWEI-Eth-Trunk2] traffic-filter acl DENY-UDP inbound 

[*HUAWEI-Eth-Trunk2]#新建三层接口用于和电信ISP互联,本端IP为192.168.11.2,对端为192.168.11.1并且调用之前写的ACL用于阻止入方向UDP协议的NTP协议,端口号123,可能是为了防止NTP流量放大攻击

[*HUAWEI]interface Eth-Trunk3

[*HUAWEI-Eth-Trunk3] undo portswitch

[*HUAWEI-Eth-Trunk3] description UPLink_WT

[*HUAWEI-Eth-Trunk3] ip address 192.168.22.2 255.255.255.252

[*HUAWEI-Eth-Trunk3] mode lacp-static

[*HUAWEI-Eth-Trunk3] traffic-filter acl DENY-UDP inbound 

[*HUAWEI-Eth-Trunk3]#新建三层接口用于和网通ISP互联,本端IP为192.168.22.2,对端为192.168.22.1并且调用之前写的ACL用于阻止入方向UDP协议的NTP协议,端口号123,可能是为了防止NTP流量放大攻击

将要加入端口组的端口做基本设置

[*HUAWEI]int range  10 1/0/1 to 10 1/0/5

[*HUAWEI-port-group]undo port default vlan 

[*HUAWEI-port-group]undo stp edged-port

[*HUAWEI-port-group]quit

将如下4个10G端口划分到端口组 eth-trunk 1

[*HUAWEI]int range 10GE2/0/1 to 10 2/0/2 10 1/0/1 to 1/0/2 

[*HUAWEI-10GE2/0/1] desc UPLink_YD

[*HUAWEI-10GE2/0/1] eth-trunk 1

将如下4个10G端口划分到端口组 eth-trunk 2

[*HUAWEI]int range 10GE2/0/3 to 10 2/0/4 10 1/0/3 to 1/0/4 

[*HUAWEI-10GE2/0/3] desc UPLink_DX

[*HUAWEI-10GE2/0/3] eth-trunk 

将如下3个10G端口划分到端口组 eth-trunk 3

[*HUAWEI-10GE1/0/4]int 10GE1/0/5 

[*HUAWEI-10GE1/0/5] desc UPLink_WT

[*HUAWEI-10GE1/0/5] eth-trunk 3

[*HUAWEI-10GE2/0/4]int 10GE2/0/5

[*HUAWEI-10GE2/0/5] desc UPLink_WT

[*HUAWEI-10GE2/0/5] eth-trunk 3

[*HUAWEI-10GE2/0/5]commit 

[*HUAWEI-10GE1/0/4]int 10GE1/0/5

[*HUAWEI-10GE1/0/5] desc UPLink_WT

[*HUAWEI-10GE1/0/5] eth-trunk 3

[*HUAWEI-10GE1/0/5]commit 

ACL2012匹配的是源自本地服务器源IP是移动IP

[~HUAWEI]acl number 2012

[*HUAWEI-acl4-basic-2012] rule 0 permit source 1.1.1.0 0.0.0.127

[*HUAWEI-acl4-basic-2012] rule 5 permit source 1.1.1.128 0.0.0.63

ACL2013匹配的是源自本地服务器源IP是网通IP

[*HUAWEI]acl number 2013

[*HUAWEI-acl4-basic-2013] rule 0 permit source 2.2.2.0 0.0.0.127

[*HUAWEI-acl4-basic-2013] rule 5 permit source 2.2.2.128 0.0.0.31

ACL 3012 用来匹配目标为到本地的流量,其中3.3.3.128 255.255.255.128 是本地服务器电信ip地址段

[*HUAWEI]acl number 3012

[*HUAWEI-acl4-advance-3012] rule 5 permit ip destination 1.1.1.0 0.0.0.127 

[*HUAWEI-acl4-advance-3012] rule 10 permit ip destination 1.1.1.128 0.0.0.63

[*HUAWEI-acl4-advance-3012] rule 15 permit ip destination 3.3.3.128 0.0.0.127

[*HUAWEI-acl4-advance-3012] rule 20 permit ip destination 224.0.0.0 0.0.0.255

[*HUAWEI-acl4-advance-3012] rule 40 permit ip destination 2.2.2.0 0.0.0.127 

[*HUAWEI-acl4-advance-3012] rule 45 permit ip destination 2.2.2.128 0.0.0.31

阻止NTP流量

[*HUAWEI]acl name DENY-UDP advance

[*HUAWEI-acl4-advance-DENY-UDP] rule 10 deny udp destination-port eq ntp

[*HUAWEI-acl4-advance-DENY-UDP] rule 65534 permit ip any any 

源IP是移动的走移动下一跳出口,源IP是网通的走网通下一跳出口,其余未匹配的源IP走默认路由,也就是走电信默认路由

[*HUAWEI]traffic classifier LOCAL type or

[*HUAWEI-classifier-LOCAL] if-match acl 3012

[*HUAWEI-classifier-LOCAL]#

[*HUAWEI]traffic classifier UPLink_WT type or

[*HUAWEI-classifier-UPLink_WT] if-match acl 2013

[*HUAWEI-classifier-UPLink_WT]#

[*HUAWEI]traffic classifier UPLink_YD type or

[*HUAWEI-classifier-UPLink_YD] if-match acl 2012

[*HUAWEI-classifier-UPLink_YD]#

[*HUAWEI]traffic behavior LOCAL

[*HUAWEI-behavior-LOCAL]permit

[*HUAWEI]traffic behavior UPLink_WT

[*HUAWEI-behavior-UPLink_WT] redirect load-balance nexthop 192.168.22.1

[*HUAWEI-behavior-UPLink_WT]#

[*HUAWEI]traffic behavior UPLink_YD

[*HUAWEI-behavior-UPLink_YD] redirect load-balance nexthop 192.168.1.1

[*HUAWEI-behavior-UPLink_YD]#

匹配目的为本地的流量的IP precedence 为 0 ,源为移动的IP precedence 为 5,源为联通的IP precedence 为 10,数值越小优先级越高,这里仅仅是给流量打上了标签,待后续设备处理。

MCQ技术配置顺序

https://support.huawei.com/hedex/hdx.do?lib=EDOC110013652931180BSB&docid=EDOC1100136529&lang=zh&v=11&tocLib=EDOC110013652931180BSB&tocV=11&id=ZH-CN_CLIREF_0141121987&tocURL=resources%2525252Fdc%2525252Fclassifier_behavior.html&p=t&fe=1&ui=3&keyword=%25252Bclassifier%25252Bbehavior
 

[*HUAWEI]traffic policy UPLink_YD&WT

[*HUAWEI-trafficpolicy-UPLink_YD&WT] classifier LOCAL behavior LOCAL precedence 0

[*HUAWEI-trafficpolicy-UPLink_YD&WT] classifier UPLink_YD behavior UPLink_YD precedence 5

[*HUAWEI-trafficpolicy-UPLink_YD&WT] classifier UPLink_WT behavior UPLink_WT precedence 10

业务网关为SVI Vlanif3 配置为3线的网关,注意它的sub写法,并在流量入口打上标签

[*HUAWEI]

[*HUAWEI]interface Vlanif3

[*HUAWEI-Vlanif3] ip address 3.3.3.129 255.255.255.128

[*HUAWEI-Vlanif3] ip address 2.2.2.1 255.255.255.128 sub

[*HUAWEI-Vlanif3] ip address 2.2.2.129 255.255.255.224 sub

[*HUAWEI-Vlanif3] ip address 1.1.1.1 255.255.255.128 sub

[*HUAWEI-Vlanif3] ip address 1.1.1.129 255.255.255.192 sub

[*HUAWEI-Vlanif3] traffic-policy UPLink_YD&WT inbound

[*HUAWEI]#

Committing.......done.

            

[~HUAWEI]int range 10 1/0/1 to 10 1/0/5 10 2/0/1 to 10 2/0/5

[~HUAWEI-port-group]qos drr 0 to 4

[*HUAWEI-port-group] qos queue 0 drr weight 65

[*HUAWEI-port-group] qos queue 1 drr weight 5

[*HUAWEI-port-group] qos queue 2 drr weight 10

[*HUAWEI-port-group] qos queue 3 drr weight 15

[*HUAWEI-port-group] qos queue 4 drr weight 5

[*HUAWEI-port-group] qos pq 5 to 7

[*HUAWEI-port-group]

[*HUAWEI-port-group]quit

#所有用于上联ISP的接口qos 拥塞管理机制

[*HUAWEI]ip route-static 0.0.0.0 0.0.0.0 Eth-Trunk2 192.168.11.1

[*HUAWEI]commit 

#默认路由走电信

华为交换机拥塞避免和拥塞管理综合配置案例

https://support.huawei.com/hedex/hdx.do?lib=EDOC110013652931180BSB&docid=EDOC1100136529&lang=zh&v=11&tocLib=EDOC110013652931180BSB&tocV=11&id=ZH-CN_CONCEPT_0141108347&tocURL=resources%2525252Fdc%2525252Fdc_cfg_qos_0151.html&p=t&fe=1&ui=3&keyword=qos%25252Bqueue
 

华为交换机优先级映射缺省配置

https://support.huawei.com/hedex/hdx.do?lib=EDOC110013652931180BSB&docid=EDOC1100136529&lang=zh&v=11&tocLib=EDOC110013652931180BSB&tocV=11&id=ZH-CN_CONCEPT_0141112362&tocURL=resources%2525252Fdc%2525252Fdc_cfg_qos_1004_CE6870EI.html&p=t&fe=1&ui=3&keyword=%2525252525u4f18%2525252525u5148%2525252525u7ea7%2525252525u6620%2525252525u5c04%2525252525u7f3a%2525252525u7701%2525252525u914d%2525252525u7f6e

  • 4
    点赞
  • 6
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值