校园网是一个综合高效的教学和科研的校园计算环境。它不仅是一个大型的网络通讯平台,而且是一个基于宽带网络,集成多种应用,并具有强大的资源管理和安全防范机制的综合服务体系。其主干网络采用光纤通讯介质,以622M ATM技术为基础,融合155M ATM和光纤快速以太网等多种通讯技术基本覆盖了整个校园。在高层网络协议方面以Intranet模型为基本架构,多数上层应用完全基于TCP/IP协议族实现。
- 网络结构
1.物理层:
校园网物理拓扑采用分级网络构,即将校园骨干网分为核心网和分支网两部分。核心网络层是整个系统的中心,它提供一个高速ATM的网络通信平台以及网络核心管理服务,由三个核心节点及一组12芯多模光纤、一组4芯单模光纤组成环型网络。分支网络由核心节点向外辐射到各院系大楼的4芯光缆和上行的节点设备组成。院系大楼的局域网则通过上行节点设备连入校园骨干网。现有分支网节点45个。分级网络的拓扑结构如下图所示。
校园网分级网络拓扑结构示意图
2.与ATM相关层次
校园网络以622M和155M ATM为基础通讯平台,采用LANE和MPOA技术实现与传统以太网和TCP/IP协议的融合,支持UNI 3.0/3.1UNI 4.0 IISP PNNI1.0等接口协议,支持SVC 、PVC和线路冗余,支持LANE 1.0和MPOA 1.0,可实现QoS(服务质量)控制。ATM网络拓扑结构示意图如下。
校园网ATM网络物理拓扑结构示意图
3.Ethernet 和TCP/IP层
提供符合IEEE 802.X标准的10M、100M双绞线和光纤以太网接口,并且具备千兆以太网的升级能力,系统支持基于MAC、Port、应用等多种VLAN的划分功能,虚网间通讯通过三层交换实现,虚网间有基于地址和应用的安全控制策略。作为支持路径选择和广播等功能的重要设备如MPOA(LANE) Server支持冗余,发生故障时可实现透明替换。
- 网络设备
- 核心交换机:
校园网的核心交换机为Cisco Catalyst 5500,模块配置如下:
- WS-X5530-E1 Catalyst 5000系列的主控模块(2/3宽)
- WS-U5533-FEFX-MMF 双口千兆以太网模块(1/3宽)
- WS-X5304-15 路由交换模块(占两个插槽)
- WS-X5161 双多模SC口,622M的 LANE模块(全宽)
- WS-X5225R 24个RJ45口10/100M自适应的以太网模块(全宽)
- WAI-OC12-1SS 622M的ATM模块,单口,单模SC接口(半宽)
- WAI-OC12-1MM 622M的ATM模块,单口,多模SC接口(半宽)
- WAI-OC3-4MM 155M的ATM模块,4口,多模SC接口(半宽)
- WAI-ATM25-12P 25M的ATM模块,12口(半宽)
- WATM-CAM-2P LightStream 1100,ATM控制模块(全宽)
其中,各交换机配置略有不同,基本都具有以上模块,但只有综合楼的Catalyst 5500配置有路由交换模块。各交换机内部,都有一对多模光纤将一块WAI-OC12-1MM与WS-X5161相连,解决ATM网络与LANE SERVER之间的连接问题;有一根双绞线将WS-X5225R的1号端口与WATM-CAM-2P相连,便于通过Telnet方式访问LightStream 1100。
各核心交换机的软件主要配置如下:
202.120.228.2:
begin
set password $1$zAMC$2LOVfCNiXBGB8SirgVHeD0
set enablepass $1$6IJa$u1GuPffajYwdanxTypoeQ0
set prompt 228.2>
set length 24 default
set logout 0
set banner motd ^C^C
!
#system
set system baud 9600
set system modem disable
set system name 5500-2
set system location Synthetics Building
set system contact Ye Jiawei
!
#snmp
set snmp community read-only public
set snmp community read-write fudan
set snmp community read-write-all root
set snmp rmon enable
set snmp trap enable module
set snmp trap enable chassis
set snmp trap enable bridge
set snmp trap enable repeater
set snmp trap enable vtp
set snmp trap enable auth
set snmp trap enable ippermit
set snmp trap enable vmps
set snmp trap disable entity
set snmp trap enable config
set snmp trap enable stpx
set snmp trap 202.120.228.128 fudan
!
#ip
set interface sc0 1 202.120.228.2 255.255.255.0 202.120.228.255
set interface sc0 up
set interface sl0 0.0.0.0 0.0.0.0
set interface sl0 up
set arp agingtime 1200
set ip redirect enable
set ip unreachable enable
set ip fragmentation enable
set ip route 0.0.0.0 202.120.228.1 1
set ip alias default 0.0.0.0
!
#Command alias
!
#vmps
set vmps server 202.120.228.18 primary
set vmps server retry 3
set vmps server reconfirminterval 60
set vmps tftpserver 202.120.228.18 vmps-config-database.1
set vmps state disable
!
#dns
set ip dns disable
!
#tacacs+
set tacacs attempts 3
set tacacs directedrequest disable
set tacacs timeout 5
set authentication login tacacs disable
set authentication login local enable
set authentication enable tacacs disable
set authentication enable local enable
!
#bridge
set bridge ipx snaptoether 8023raw
set bridge ipx 8022toether 8023
set bridge ipx 8023rawtofddi snap
!
#vtp
set vtp domain fdunet
set vtp mode server
set vtp v2 enable
set vtp pruning disable
set vtp pruneeligible 2-1000
clear vtp pruneeligible 1001-1005
set vlan 1 name default type ethernet mtu 1500 said 100001 state active
set vlan 2 name vlan2 type ethernet mtu 1500 said 100002 state active
…………
set vlan 79 name vlan79 type ethernet mtu 1500 said 100079 state active
set vlan 80 name vlan80 type ethernet mtu 1500 said 100080 state active
set vlan 1002 name fddi-default type fddi mtu 1500 said 101002 state active
set vlan 1004 name fddinet-default type fddinet mtu 1500 said 101004 state acti
set vlan 1005 name trbrf-default type trbrf mtu 4472 said 101005 state active b
set vlan 1003 name trcrf-default type trcrf mtu 4472 said 101003 state active p
!
#spantree
#uplinkfast groups
set spantree uplinkfast disable
#backbonefast
set spantree backbonefast disable
set spantree enable all
#vlan 1
set spantree fwddelay 15 1
set spantree hello 2 1
set spantree maxage 20 1
set spantree priority 32768 1
#vlan 2
set spantree fwddelay 15 2
set spantree hello 2 2
set spantree maxage 20 2
set spantree priority 32768 2
…………
#vlan 79
set spantree fwddelay 15 79
set spantree hello 2 79
set spantree maxage 20 79
set spantree priority 32768 79
#vlan 80
set spantree fwddelay 15 80
set spantree hello 2 80
set spantree maxage 20 80
set spantree priority 32768 80
#vlan 1003
set spantree fwddelay 4 1003
set spantree hello 2 1003
set spantree maxage 10 1003
set spantree priority 32768 1003
set spantree portstate 1003 auto 1005
set spantree portcost 1003 62
set spantree portpri 1003 4
set spantree portfast 1003 disable
#vlan 1005
set spantree fwddelay 4 1005
set spantree hello 2 1005
set spantree maxage 10 1005
set spantree priority 32768 1005
set spantree multicast-address 1005 ieee
!
#cgmp
set cgmp disable
set cgmp leave disable
!
#syslog
set logging console enable
set logging server disable
set logging level cdp 2 default
set logging level mcast 2 default
set logging level dtp 5 default
set logging level dvlan 2 default
set logging level earl 2 default
set logging level fddi 2 default
set logging level ip 2 default
set logging level pruning 2 default
set logging level snmp 2 default
set logging level spantree 2 default
set logging level sys 5 default
set logging level tac 2 default
set logging level tcp 2 default
set logging level telnet 2 default
set logging level tftp 2 default
set logging level vtp 2 default
set logging level vmps 2 default
set logging level kernel 2 default
set logging level filesys 2 default
set logging level drip 2 default
set logging level pagp 5 default
set logging level mgmt 5 default
set logging level mls 5 default
set logging level protfilt 2 default
set logging level security 2 default
!
#ntp
set ntp broadcastclient disable
set ntp broadcastdelay 3000
set ntp client disable
clear timezone
set summertime disable
!
#set boot command
set boot config-register 0x102
set boot system flash bootflash:cat5000-sup3.4-2-1.bin
!
#permit list
set ip permit disable
!
#drip
set tokenring reduction enable
set tokenring distrib-crf disable
!
#igmp
set igmp disable
!
#protocolfilter
set protocolfilter disable
!
#mls
set mls enable
set mls flow destination
set mls agingtime 256
set mls agingtime fast 0 0
set mls nde disable
!
#module 1 : 2-port 1000BaseSX Supervisor
set module name 1
set vlan 1 1/1-2
set port enable 1/1-2
set port level 1/1-2 normal
set port duplex 1/1-2 full
set port trap 1/1-2 enable
set port name 1/1-2
set port security 1/1-2 disable
set port broadcast 1/1-2 100%
set port membership 1/1-2 static
set port protocol 1/1-2 ip on
set port protocol 1/1-2 ipx auto
set port negotiation 1/1-2 enable
set port flowcontrol send 1/1-2 desired
set port flowcontrol receive 1/1-2 off
set cdp enable 1/1-2
set cdp interval 1/1-2 60
set trunk 1/1 auto negotiate 1-1005
set trunk 1/2 auto negotiate 1-1005
set spantree portfast 1/1-2 disable
set spantree portcost 1/1-2 4
set spantree portpri 1/1-2 32
set spantree portvlanpri 1/1 0
set spantree portvlanpri 1/2 0
set spantree portvlancost 1/1 cost 3
set spantree portvlancost 1/2 cost 3
!
#module 2 : 12-port 100BaseFX MM Ethernet
set module name 2
set module enable 2
set vlan 16 2/1
set vlan 29 2/2
set vlan 53 2/3
set vlan 55 2/4
set vlan 57 2/5
set vlan 59 2/6
set vlan 60 2/7
set vlan 62 2/8
set vlan 64 2/9
set vlan 68 2/10
set vlan 70 2/11
set vlan 73 2/12
set port channel 2/1-4 off
set port channel 2/5-8 off
set port channel 2/9-12 off
set port channel 2/1-4 auto
set port channel 2/5-8 auto
set port channel 2/9-12 auto
set port enable 2/1-12
set port level 2/1-12 normal
set port duplex 2/1-12 half
set port trap 2/1-12 enable
set port name 2/1-12
set port security 2/1-12 disable
set port broadcast 2/1-12 100%
set port membership 2/1-12 static
set port protocol 2/1-12 ip on
set port protocol 2/1-12 ipx auto
set port negotiation 2/1-12 enable
set port flowcontrol send 2/1-12 off
set port flowcontrol receive 2/1-12 on
set cdp enable 2/1-12
set cdp interval 2/1-12 60
set trunk 2/1 off isl 1-1005
set trunk 2/2 off negotiate 1-1005
…………
set trunk 2/12 off negotiate 1-1005
set spantree portfast 2/1-12 disable
set spantree portcost 2/1-12 19
set spantree portpri 2/1-12 32
set spantree portvlanpri 2/1 0
set spantree portvlanpri 2/2 0
…………
set spantree portvlanpri 2/12 0
set spantree portvlancost 2/1 cost 18
set spantree portvlancost 2/2 cost 18
…………
set spantree portvlancost 2/12 cost 18
!
#module 3 : 24-port 10/100BaseTX Ethernet
set module name 3
set module enable 3
set vlan 1 3/1,3/22
set vlan 2 3/2-4,3/6-13,3/18-19
set vlan 3 3/20
set vlan 4 3/16-17
set vlan 7 3/21
set vlan 8 3/15
set vlan 9 3/23-24
set vlan 10 3/14
set port channel 3/1-4 off
set port channel 3/5-8 off
set port channel 3/9-12 off
set port channel 3/13-16 off
set port channel 3/17-20 off
set port channel 3/21-24 off
set port channel 3/1-4 auto
set port channel 3/5-8 auto
set port channel 3/9-12 auto
set port channel 3/13-16 auto
set port channel 3/17-20 auto
set port channel 3/21-24 auto
set port enable 3/1-24
set port level 3/1-24 normal
set port speed 3/1-24 auto
set port trap 3/1-24 enable
set port name 3/1-24
set port security 3/1-24 disable
set port broadcast 3/1-24 100%
set port membership 3/1-24 static
set port protocol 3/1-24 ip on
set port protocol 3/1-24 ipx auto
set port negotiation 3/1-24 enable
set port flowcontrol send 3/1-24 off
set port flowcontrol receive 3/1-24 on
set cdp enable 3/1-24
set cdp interval 3/1-24 60
set trunk 3/1 auto negotiate 1-1005
set trunk 3/2 auto negotiate 1-1005
…………
set trunk 3/15 auto negotiate 1-1005
set trunk 3/16 off negotiate 1-1005
set trunk 3/17 auto negotiate 1-1005
…………
set trunk 3/21 auto negotiate 1-1005
set trunk 3/22 on isl 1-1005
set trunk 3/23 off negotiate 1-1005
set trunk 3/24 auto negotiate 1-1005
set spantree portfast 3/1-24 disable
set spantree portcost 3/2,3/7-9,3/15,3/21 19
set spantree portcost 3/1,3/3-6,3/10-14,3/16-20,3/22-24 100
set spantree portpri 3/1-24 32
set spantree portvlanpri 3/1 0
set spantree portvlanpri 3/2 0
…………
set spantree portvlanpri 3/23 0
set spantree portvlanpri 3/24 0
set spantree portvlancost 3/1 cost 99
set spantree portvlancost 3/2 cost 18
set spantree portvlancost 3/3 cost 99
…………
set spantree portvlancost 3/6 cost 99
set spantree portvlancost 3/7 cost 18
set spantree portvlancost 3/8 cost 18
set spantree portvlancost 3/9 cost 18
set spantree portvlancost 3/10 cost 99
…………
set spantree portvlancost 3/14 cost 99
set spantree portvlancost 3/15 cost 18
set spantree portvlancost 3/16 cost 99
…………
set spantree portvlancost 3/20 cost 99
set spantree portvlancost 3/21 cost 18
set spantree portvlancost 3/22 cost 99
set spantree portvlancost 3/23 cost 99
set spantree portvlancost 3/24 cost 99
!
#module 4 empty
!
#module 5 : 1-port Route Switch
set module name 5
set port level 5/1 normal
set port trap 5/1 enable
set port name 5/1
set cdp enable 5/1
set cdp interval 5/1 60
set trunk 5/1 on isl 1-1005
set spantree portcost 5/1 5
set spantree portpri 5/1 32
set spantree portvlanpri 5/1 0
set spantree portvlancost 5/1 cost 4
!
#module 6 empty
!
#module 7 empty
!
#module 8 : 2-port OC12 Dual PHY MMF
set module name 8
set port level 8/1 normal
set port name 8/1-2
set cdp enable 8/1
set cdp interval 8/1 60
set trunk 8/1 on LANE 1-1005
set spantree portcost 8/1 6
set spantree portpri 8/1 32
set spantree portvlanpri 8/1 0
set spantree portvlancost 8/1 cost 5
!
#module 9 empty
!
#module 10 empty
!
#module 11 empty
!
#module 12 empty
!
#module 13 empty
!
#switch port analyzer
set span 2 3/5 both inpkts enable
!set span enable
!
#cam
set cam agingtime 1-80,1003,1005 300
end
LANE模块:
Using 20151 out of 523258 bytes
!
version 11.3
no service password-encryption
!
hostname ATM
!
!
vtp enable
!
LANE database fdunet
name vlan2 server-atm-address 47.00918100000000906FBB1C01.00906FBB1871.02
name vlan2 server-atm-address 47.0091810000000050508FE801.0050508FE471.02
name vlan3 server-atm-address 47.00918100000000906FBB1C01.00906FBB1871.03
name vlan3 server-atm-address 47.0091810000000050508FE801.0050508FE471.03
…………
name vlan79 server-atm-address 47.00918100000000906FBB1C01.00906FBB1871.4F
name vlan79 server-atm-address 47.0091810000000050508FE801.0050508FE471.4F
name vlan80 server-atm-address 47.00918100000000906FBB1C01.00906FBB1871.50
name vlan80 server-atm-address 47.0091810000000050508FE801.0050508FE471.50
name default server-atm-address 47.00918100000000906FBB1C01.00906FBB1871.00
name default server-atm-address 47.0091810000000050508FE801.0050508FE471.00
!
interface ATM0
atm preferred phy A
atm pvc 1 0 5 qsaal
atm pvc 2 0 16 ilmi
LANE config auto-config-atm-address
LANE config database fdunet
LANE server-bus ethernet default
LANE client ethernet 1 default
!
interface ATM0.2 multipoint
LANE server-bus ethernet vlan2
LANE client ethernet 2 vlan2
!
interface ATM0.3 multipoint
LANE server-bus ethernet vlan3
LANE client ethernet 3 vlan3
!
…………
interface ATM0.78 multipoint
LANE server-bus ethernet vlan78
LANE client ethernet 78 vlan78
!
interface ATM0.79 multipoint
LANE server-bus ethernet vlan79
!
interface ATM0.80 multipoint
LANE server-bus ethernet vlan80
!
!
line con 0
line vty 0 4
no login
!
end
202.120.228.5(LightStream on 202.120.228.2):
Using 1835 out of 126968 bytes
!
version 11.2
no service pad
no service password-encryption
no service udp-small-servers
no service tcp-small-servers
!
hostname atm-228.5
!
enable secret 5 $1$kA9e$s6KpEBSZIaFf9IgSEukfa.
!
!
atm lecs-address-default 47.0091.8100.0000.0090.6fbb.1c01.0090.6fbb.1873.00 1
atm lecs-address-default 47.0091.8100.0000.0050.508f.e801.0050.508f.e473.00 2
atm address 47.0091.8100.0000.0050.508f.e801.0050.508f.e801.00
atm router pnni
node 1 level 56 lowest
redistribute atm-static
!
!
interface ATM9/0/0
!
interface ATM9/0/1
atm maxvp-number 0
atm maxvc-number 1024
!
interface ATM9/0/2
!
interface ATM9/0/3
!
interface ATM9/1/0
!
interface ATM9/1/1
atm maxvp-number 0
atm maxvc-number 1024
!
interface ATM9/1/2
!
interface ATM9/1/3
atm maxvp-number 0
atm maxvc-number 1024
!
interface ATM10/0/0
!
interface ATM10/0/1 此插槽上为一块12-96pin的25M ATM模块
! 所以有12个interface
…………
interface ATM10/1/11
!
interface ATM11/0/0
atm maxvp-number 4
atm maxvc-number 4096
!
interface ATM11/1/0
!
interface ATM11/1/1
!
interface ATM11/1/2
!
interface ATM11/1/3
!
interface ATM12/0/0
!
interface ATM12/1/0
!
interface ATM13/0/0
ip address 202.120.228.5 255.255.255.0
!
no ip classless
snmp-server community public RO
snmp-server community fudan RW
snmp-server trap-authentication
snmp-server system-shutdown
snmp-server enable traps config
snmp-server enable traps chassis-fail
snmp-server enable traps chassis-change
snmp-server enable traps atm-accounting
snmp-server host 202.120.228.18 fudan
!
line con 0
line aux 0
line vty 0 4
no login
!
end
202.120.228.3:
begin
set password $1$astB$sKT.tdR1GCM5a4wryf0Q/.
set enablepass $1$wJ/B$yhPcHHLBiv167f48DlIZP/
set prompt 228.3>
set length 24 default
set logout 0
set banner motd ^C^C
!
#system
set system baud 9600
set system modem disable
set system name 5500-3
set system location Synthetics Building
set system contact Ye Jiawei
!
&&&&&&&(与202.120.228.2上配置完全相同的内容)
#ip
set interface sc0 1 202.120.228.3 255.255.255.0 202.120.228.255
set interface sc0 up
set interface sl0 0.0.0.0 0.0.0.0
set interface sl0 up
set arp agingtime 1200
set ip redirect enable
set ip unreachable enable
set ip fragmentation enable
set ip route 0.0.0.0 202.120.228.1 1
set ip alias default 0.0.0.0
!
#Command alias
!
#vmps
set vmps server retry 3
set vmps server reconfirminterval 60
set vmps tftpserver 0.0.0.0 vmps-config-database.1
set vmps state disable
!
*******(内容与202.120.228.2上的配置雷同,不再详细列出)
LANE模块:
Using 201 out of 523258 bytes
!
version 11.3
no service password-encryption
!
hostname ATM
!
!
vtp enable
!
interface ATM0
atm preferred phy A
atm pvc 1 0 5 qsaal
atm pvc 2 0 16 ilmi
!
!
line con 0
line vty 0 4
no login
!
end
202.120.228.6(LightStream on 202.120.228.3):
Using 2001 out of 126968 bytes
!
version 11.2
no service pad
no service password-encryption
no service udp-small-servers
no service tcp-small-servers
!
hostname atm-228.6
!
enable secret 5 $1$Yxs5$LN2rdlfchbsgyiHarp9lu0
!
!
atm lecs-address-default 47.0091.8100.0000.0090.6fbb.1c01.0090.6fbb.1873.00 1
atm lecs-address-default 47.0091.8100.0000.0050.508f.e801.0050.508f.e473.00 2
atm address 47.0091.8100.0000.0090.6fba.c401.0090.6fba.c401.00
atm router pnni
node 1 level 56 lowest
redistribute atm-static
!
!
interface ATM9/0/0
atm maxvp-number 0
atm maxvc-number 1024
!
interface ATM9/0/1
atm maxvp-number 0
atm maxvc-number 1024
!
interface ATM9/0/2
atm maxvp-number 0
atm maxvc-number 1024
!
interface ATM9/0/3
atm maxvp-number 0
atm maxvc-number 1024
!
interface ATM9/1/0
atm maxvp-number 0
atm maxvc-number 1024
!
interface ATM9/1/1
atm maxvp-number 0
atm maxvc-number 1024
!
interface ATM9/1/2
atm maxvp-number 0
atm maxvc-number 1024
!
interface ATM9/1/3
atm maxvp-number 0
atm maxvc-number 1024
!
*******(与202.120.228.5上雷同的内容,不再重复)
interface ATM13/0/0
no ip address
atm maxvp-number 0
!
interface Ethernet13/0/0
ip address 202.120.228.6 255.255.255.0
!
no ip classless
snmp-server community public RO
snmp-server community fudan RW
snmp-server trap-authentication
snmp-server system-shutdown
snmp-server enable traps config
snmp-server enable traps chassis-fail
snmp-server enable traps chassis-change
snmp-server enable traps atm-accounting
snmp-server host 202.120.228.18 fudan
snmp-server host 202.120.228.128 fudan
!
line con 0
line aux 0
line vty 0 4
no login
!
end
202.120.228.4:
begin
set password $1$SIMh$mFRNKeFxt9A5r2D/gbKa2.
set enablepass $1$Ja8O$FO6QCvSoyaFLdc1t4jtr7/
set prompt 228.4>
set length 24 default
set logout 0
set banner motd ^C^C
!
#system
set system baud 9600
set system modem disable
set system name 5500-4
set system location Yi Fu Building
set system contact Gao Baiming
!
&&&&&&&(与202.120.228.2上配置完全相同的内容)
#ip
set interface sc0 1 202.120.228.4 255.255.255.0 202.120.228.255
set interface sc0 up
set interface sl0 0.0.0.0 0.0.0.0
set interface sl0 up
set arp agingtime 1200
set ip redirect enable
set ip unreachable enable
set ip fragmentation enable
set ip route 0.0.0.0 202.120.228.1 1
set ip alias default 0.0.0.0
!
#Command alias
!
#vmps
set vmps server retry 3
set vmps server reconfirminterval 60
set vmps tftpserver 0.0.0.0 vmps-config-database.1
set vmps state disable
!
*******(内容与202.120.228.2上的配置雷同,不再详细列出)
LANE模块:
*******(内容与202.120.228.2上的配置雷同,不再详细列出)
202.120.228.7(LightStream on 202.120.228.4):
Using 2361 out of 126968 bytes
!
version 11.2
no service pad
no service password-encryption
no service udp-small-servers
no service tcp-small-servers
!
hostname atm-228.7
!
enable secret 5 $1$oZ7Y$/YcZHbghugpqQ42ovGZEA0
!
!
atm lecs-address-default 47.0091.8100.0000.0090.6fbb.1c01.0090.6fbb.1873.00 1
atm lecs-address-default 47.0091.8100.0000.0050.508f.e801.0050.508f.e473.00 2
atm lecs-address-default 47.0091.8100.0000.0090.6fbb.1c01.0090.6fbb.1c05.00 3
atm address 47.0091.8100.0000.0090.6fbb.1c01.0090.6fbb.1c01.00
atm router pnni
node 1 level 56 lowest
redistribute atm-static
!
!
lane database cwsilecsdb1
name default server-atm-address 47.00918100000000906FBB1C01.00906FBB1C03.01
!
*******(内容与202.120.228.2上的配置雷同,不再详细列出)
interface ATM13/0/0
no ip address
atm maxvp-number 0
lane config config-atm-address ...
lane config config-atm-address 47.007900000000000000000000.00A03E000001.00
lane config database cwsilecsdb1
!
interface ATM13/0/0.1 multipoint
lane server-bus ethernet default
!
interface Ethernet13/0/0
ip address 202.120.228.7 255.255.255.0
!
no ip classless
snmp-server community public RO
snmp-server community fudan RW
snmp-server trap-authentication
snmp-server location Yi Fu Building
snmp-server contact Gao Baiming
snmp-server system-shutdown
snmp-server enable traps config
snmp-server enable traps chassis-fail
snmp-server enable traps chassis-change
snmp-server enable traps atm-accounting
snmp-server host 202.120.228.18 fudan
snmp-server host 202.120.228.128 fudan
!
line con 0
line aux 0
line vty 0 4
no login
!
end
- 边缘交换机:
校园网的边缘交换机共有两种:Cisco Catalyst 2820和Cisco Catalyst 1924C,根据不同的需求,分别放置在各校园网分支节点,作为各院系建筑的校园网接入设备。其具体分布图如下:
Catalyst 2820的配置如下:
(选择计算机系的设备作为范例。该设备属于vlan11)
Current configuration:
!
!
vtp domain "fdunet"
!
vlan 2 name "vlan2" sde 100002 state Operational mtu 1500
vlan 3 name "vlan3" sde 100003 state Operational mtu 1500
…………
vlan 79 name "vlan79" sde 100079 state Operational mtu 1500
vlan 80 name "vlan80" sde 100080 state Operational mtu 1500
mac-address-table permanent 0000.2141.2837 FastEthernet 1
mac-address-table permanent 0080.AD0E.0695 ATM 2
!
!
!
!
hostname computer science building2820
!
!
!
!
ip address 202.120.228.11 255.255.255.0
ip default-gateway 202.120.228.1
!
snmp-server community "fudan" rw
snmp-server host "202.120.228.128" "fudan"
snmp-server set-host "202.120.228.128"
snmp-server location "computer science building"
!
!
!
enable password level 15 PATTY2
!
interface Ethernet 0/1
vlan-membership static 11
!
interface Ethernet 0/2
vlan-membership static 11
!
…………
interface Ethernet 0/24
vlan-membership static 11
!
interface Ethernet 0/25
vlan-membership static 11
!
interface FastEthernet 1
!
vlan-membership static 11
!
!
interface ATM 2
!
!
!
line console
end
ATM配置:
Using 303 out of 65536 bytes
!
version 11.3
no service pad
no service password-encryption
!
hostname ATM
!
enable password patty2
!
!
interface ATM1 如果ATM模块在session a,则为ATM0
atm pvc 1 0 5 qsaal
atm pvc 2 0 16 ilmi
lane client ethernet 1 default
!
interface ATM1.1 multipoint 如果ATM模块在session a,则为ATM0.1
lane client ethernet 11 vlan11
! 可以通过增加ATM1.x(0.x)来增加vlan x
!
line con 0
stopbits 1
line aux 0 7
!
end
Catalyst 1924C配置如下:
(选择管理学院的设备为范例。该设备属于vlan 51)
Current configuration:
!
!
vtp domain "fdu"
vtp pruning enable
!
vlan 51 name "vlan51" sde 100051 state Operational mtu 1500
mac-address-table aging-time 10
!
!
!
!
hostname GuanLi XueYuan
!
!
!
!
ip address 10.51.0.4 255.255.0.0
ip default-gateway 10.51.0.1
ip mgmt-vlan 51
ip domain-name "fudan.edu.cn"
ip name-server 202.120.224.6
!
snmp-server host "fudan" ""
snmp-server set-host "202.120.228.18"
snmp-server location "GuanLi XueYuan"
snmp-server contact "Li Chen Sheng"
!
!
!
enable password level 15 PATTY2
!
interface Ethernet 0/1
vlan-membership static 51
!
interface Ethernet 0/2
vlan-membership static 51
…………
interface Ethernet 0/24
vlan-membership static 51
!
interface Ethernet 0/25
vlan-membership static 51
!
interface FastEthernet 0/26
!
trunk Desirable
vlan-membership static 51
!
!
interface FastEthernet 0/27
!
vlan-membership static 51
!
!
line console
end
Catalyst 2820的地址分配规则:202.120.228.x,其中x为所属vlan的vlan ID
Catalyst 1924C的地址分配原则:10.x.0.4,其中x为所属vlan的vlan ID