3线机房的出口交换机的典型配置,注意以下几个方面: [~HUAWEI]interface Eth-Trunk1 [*HUAWEI-Eth-Trunk1] undo portswitch [*HUAWEI-Eth-Trunk1] description UPLink_YD [*HUAWEI-Eth-Trunk1] ip address 192.168.1.2 255.255.255.252 [*HUAWEI-Eth-Trunk1] mode lacp-static [*HUAWEI-Eth-Trunk1] traffic-filter acl DENY-UDP inbound [*HUAWEI-Eth-Trunk1]#新建三层接口用于和移动ISP互联,本端IP为192.168.1.2,对端为192.168.1.1并且调用之前写的ACL用于阻止入方向UDP协议的NTP协议,端口号123,可能是为了防止NTP流量放大攻击 [*HUAWEI]interface Eth-Trunk2 [*HUAWEI-Eth-Trunk2] undo portswitch [*HUAWEI-Eth-Trunk2] description UPLink_DX [*HUAWEI-Eth-Trunk2] ip address 192.168.11.2 255.255.255.252 [*HUAWEI-Eth-Trunk2] mode lacp-static [*HUAWEI-Eth-Trunk2] traffic-filter acl DENY-UDP inbound [*HUAWEI-Eth-Trunk2]#新建三层接口用于和电信ISP互联,本端IP为192.168.11.2,对端为192.168.11.1并且调用之前写的ACL用于阻止入方向UDP协议的NTP协议,端口号123,可能是为了防止NTP流量放大攻击 [*HUAWEI]interface Eth-Trunk3 [*HUAWEI-Eth-Trunk3] undo portswitch [*HUAWEI-Eth-Trunk3] description UPLink_WT [*HUAWEI-Eth-Trunk3] ip address 192.168.22.2 255.255.255.252 [*HUAWEI-Eth-Trunk3] mode lacp-static [*HUAWEI-Eth-Trunk3] traffic-filter acl DENY-UDP inbound [*HUAWEI-Eth-Trunk3]#新建三层接口用于和网通ISP互联,本端IP为192.168.22.2,对端为192.168.22.1并且调用之前写的ACL用于阻止入方向UDP协议的NTP协议,端口号123,可能是为了防止NTP流量放大攻击 将要加入端口组的端口做基本设置 [*HUAWEI]int range 10 1/0/1 to 10 1/0/5 [*HUAWEI-port-group]undo port default vlan [*HUAWEI-port-group]undo stp edged-port [*HUAWEI-port-group]quit 将如下4个10G端口划分到端口组 eth-trunk 1 [*HUAWEI]int range 10GE2/0/1 to 10 2/0/2 10 1/0/1 to 1/0/2 [*HUAWEI-10GE2/0/1] desc UPLink_YD [*HUAWEI-10GE2/0/1] eth-trunk 1 将如下4个10G端口划分到端口组 eth-trunk 2 [*HUAWEI]int range 10GE2/0/3 to 10 2/0/4 10 1/0/3 to 1/0/4 [*HUAWEI-10GE2/0/3] desc UPLink_DX [*HUAWEI-10GE2/0/3] eth-trunk 将如下3个10G端口划分到端口组 eth-trunk 3 [*HUAWEI-10GE1/0/4]int 10GE1/0/5 [*HUAWEI-10GE1/0/5] desc UPLink_WT [*HUAWEI-10GE1/0/5] eth-trunk 3 [*HUAWEI-10GE2/0/4]int 10GE2/0/5 [*HUAWEI-10GE2/0/5] desc UPLink_WT [*HUAWEI-10GE2/0/5] eth-trunk 3 [*HUAWEI-10GE2/0/5]commit [*HUAWEI-10GE1/0/4]int 10GE1/0/5 [*HUAWEI-10GE1/0/5] desc UPLink_WT [*HUAWEI-10GE1/0/5] eth-trunk 3 [*HUAWEI-10GE1/0/5]commit ACL2012匹配的是源自本地服务器源IP是移动IP [~HUAWEI]acl number 2012 [*HUAWEI-acl4-basic-2012] rule 0 permit source 1.1.1.0 0.0.0.127 [*HUAWEI-acl4-basic-2012] rule 5 permit source 1.1.1.128 0.0.0.63 ACL2013匹配的是源自本地服务器源IP是网通IP [*HUAWEI]acl number 2013 [*HUAWEI-acl4-basic-2013] rule 0 permit source 2.2.2.0 0.0.0.127 [*HUAWEI-acl4-basic-2013] rule 5 permit source 2.2.2.128 0.0.0.31 ACL 3012 用来匹配目标为到本地的流量,其中3.3.3.128 255.255.255.128 是本地服务器电信ip地址段 [*HUAWEI]acl number 3012 [*HUAWEI-acl4-advance-3012] rule 5 permit ip destination 1.1.1.0 0.0.0.127 [*HUAWEI-acl4-advance-3012] rule 10 permit ip destination 1.1.1.128 0.0.0.63 [*HUAWEI-acl4-advance-3012] rule 15 permit ip destination 3.3.3.128 0.0.0.127 [*HUAWEI-acl4-advance-3012] rule 20 permit ip destination 224.0.0.0 0.0.0.255 [*HUAWEI-acl4-advance-3012] rule 40 permit ip destination 2.2.2.0 0.0.0.127 [*HUAWEI-acl4-advance-3012] rule 45 permit ip destination 2.2.2.128 0.0.0.31 阻止NTP流量 [*HUAWEI]acl name DENY-UDP advance [*HUAWEI-acl4-advance-DENY-UDP] rule 10 deny udp destination-port eq ntp [*HUAWEI-acl4-advance-DENY-UDP] rule 65534 permit ip any any 源IP是移动的走移动下一跳出口,源IP是网通的走网通下一跳出口,其余未匹配的源IP走默认路由,也就是走电信默认路由 [*HUAWEI]traffic classifier LOCAL type or [*HUAWEI-classifier-LOCAL] if-match acl 3012 [*HUAWEI-classifier-LOCAL]# [*HUAWEI]traffic classifier UPLink_WT type or [*HUAWEI-classifier-UPLink_WT] if-match acl 2013 [*HUAWEI-classifier-UPLink_WT]# [*HUAWEI]traffic classifier UPLink_YD type or [*HUAWEI-classifier-UPLink_YD] if-match acl 2012 [*HUAWEI-classifier-UPLink_YD]# [*HUAWEI]traffic behavior LOCAL [*HUAWEI-behavior-LOCAL]permit [*HUAWEI]traffic behavior UPLink_WT [*HUAWEI-behavior-UPLink_WT] redirect load-balance nexthop 192.168.22.1 [*HUAWEI-behavior-UPLink_WT]# [*HUAWEI]traffic behavior UPLink_YD [*HUAWEI-behavior-UPLink_YD] redirect load-balance nexthop 192.168.1.1 [*HUAWEI-behavior-UPLink_YD]# 匹配目的为本地的流量的IP precedence 为 0 ,源为移动的IP precedence 为 5,源为联通的IP precedence 为 10,数值越小优先级越高,这里仅仅是给流量打上了标签,待后续设备处理。 MCQ技术配置顺序 [*HUAWEI]traffic policy UPLink_YD&WT [*HUAWEI-trafficpolicy-UPLink_YD&WT] classifier LOCAL behavior LOCAL precedence 0 [*HUAWEI-trafficpolicy-UPLink_YD&WT] classifier UPLink_YD behavior UPLink_YD precedence 5 [*HUAWEI-trafficpolicy-UPLink_YD&WT] classifier UPLink_WT behavior UPLink_WT precedence 10 业务网关为SVI Vlanif3 配置为3线的网关,注意它的sub写法,并在流量入口打上标签 [*HUAWEI] [*HUAWEI]interface Vlanif3 [*HUAWEI-Vlanif3] ip address 3.3.3.129 255.255.255.128 [*HUAWEI-Vlanif3] ip address 2.2.2.1 255.255.255.128 sub [*HUAWEI-Vlanif3] ip address 2.2.2.129 255.255.255.224 sub [*HUAWEI-Vlanif3] ip address 1.1.1.1 255.255.255.128 sub [*HUAWEI-Vlanif3] ip address 1.1.1.129 255.255.255.192 sub [*HUAWEI-Vlanif3] traffic-policy UPLink_YD&WT inbound [*HUAWEI]# Committing.......done.
[~HUAWEI]int range 10 1/0/1 to 10 1/0/5 10 2/0/1 to 10 2/0/5 [~HUAWEI-port-group]qos drr 0 to 4 [*HUAWEI-port-group] qos queue 0 drr weight 65 [*HUAWEI-port-group] qos queue 1 drr weight 5 [*HUAWEI-port-group] qos queue 2 drr weight 10 [*HUAWEI-port-group] qos queue 3 drr weight 15 [*HUAWEI-port-group] qos queue 4 drr weight 5 [*HUAWEI-port-group] qos pq 5 to 7 [*HUAWEI-port-group] [*HUAWEI-port-group]quit #所有用于上联ISP的接口qos 拥塞管理机制 [*HUAWEI]ip route-static 0.0.0.0 0.0.0.0 Eth-Trunk2 192.168.11.1 [*HUAWEI]commit #默认路由走电信 华为交换机拥塞避免和拥塞管理综合配置案例 华为交换机优先级映射缺省配置 |
10-26
4080
![](https://csdnimg.cn/release/blogv2/dist/pc/img/readCountWhite.png)
07-28
2895
![](https://csdnimg.cn/release/blogv2/dist/pc/img/readCountWhite.png)
“相关推荐”对你有帮助么?
-
非常没帮助
-
没帮助
-
一般
-
有帮助
-
非常有帮助
提交