接入交换机业务配置(业务端口VLAN配置、聚合配置), 每个交换机16个万兆口配置示例, interface TenGigabitEthernet 0/1 description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U12.pci8port1.10GELAN port-group 11 mode active lacp short-timeout lacp individual-port enable interface AggregatePort 11 storm-control broadcast level 10 description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U12.Bond1 switchport mode trunk switchport trunk allowed vlan only 301 spanning-tree bpduguard enable spanning-tree portfast vap 11 ! |
SNMP 配置 (少一条扣1分) snmp-server user yundiao SNMPGROUP v3 encrypted auth sha 0D6410E856F4B79AF5331F69ADDB0A242D156F01 priv aes128 0D6410E856F4B79AF5331F69ADDB0A24 snmp-server group SNMPGROUP v3 priv read default write default access 2000 snmp-server trap-source Mgmt 0 snmp-server system-shutdown snmp-server host X.X.X..136 vrf NET-manage traps version 2c yundiao*&COC2016 snmp-server host X.X.X..137 vrf NET-manage traps version 2c yundiao*&COC2016 snmp-server enable traps snmp-server community 7 042e0d083a0a2e1a5861263d695f71437d ro 2000 |
交换机账户密码配置(每台交换机新增本地账户,每错1条(包括删除)扣6分) username XXXX privilege XX password XXXX |
Hash配置(每少1条扣1分) load-balance-profile ruijie ipv4 field src-ip dst-ip protocol l4-src-port l4-dst-port ipv6 field src-ip dst-ip protocol l4-src-port l4-dst-port hash-disturb 16 (核心为16,接入为8) aggregateport member linktrap aggregateport load-balance enhanced profile ruijie |
端口状态和描述(每个接入交换机2个uT,描述每错一个扣1.5分;每个核心交换机2个dT,描述每错1个扣1.5分,同时未使用端口需要shutdown,每少1个扣0.5分) 未使用端口需要shutdown,并添加描述NO-USE interface AggregatePort 59 description dT:SHDXYQB4-108-C-04_C-05-ASW-RGS6250-01U37.AGG1 interface HundredGigabitEthernet 0/49 description uT:SHDXYQB4-108-C-04-CSW-RGS6250-01U40.Hu0/49.Hulian |
NTP配置(每台交换机全局配置,每少或者错误1条2分) clock timezone beijing +8 0 ntp update-calendar ntp server x.x.x.x source Mgmt 0 prefer |
端口广播抑制配置(接入交换机下联服务器端口,每少或者错误1条0.5分) storm-control broadcast level 10 |
BPDU和边缘端口配置(接入交换机下联服务器端口,每少或者错误1条0.5分) spanning-tree bpduguard enable spanning-tree portfast |
Netconf最大会话数 netconf enable netconf max-sessions 10 |
LLDP配置 (接入交换机端口配置,每少或者错误1条6分) lldp management-address-tlv x.x.x.x (管理口地址) |
开启巨帧转发 mtu forwarding 9216 |
Telnet、SSH配置(每个交换机配置,每少或者错误1条0.5分) enable service ssh-server no enable service telnet-server line vty 0 9 transport input ssh access-class 2001 in session-timeout 10 login local width 256 |
ACL配置 (配置示例,需要配置acl 2000和2001,每错或者删除1条扣3分) ip access-list extended 2000 10 permit ip 192.168.0.0 0.0.7.255 any 15 permit ip 192.168.8.0 0.0.7.255 any 20 permit ip 192.168.120.0 0.0.0.255 any … 1000 deny ip any any ip access-list extended 2001 10 permit ip 192.168.0.0 0.0.7.255 any 15 permit ip 192.168.8.0 0.0.7.255 any 20 permit ip 192.168.120.0 0.0.0.255 any … 1000 deny ip any any |
初学组网-mlag
最新推荐文章于 2024-10-30 07:30:00 发布