一种高可用网络的实现

1.      网络拓扑图:


2.      网络要求:

                        1)      VLAN 10和VLAN 20的用户能够访问Internet;

                        2)      正常情况下,VLAN 10的用户访问Internet走的是电信提供的链路,VLAN 20的用户访问Internet走的是网通提供的链路;

                        3)      若电信链路故障,所有的用户走网通链路。若网通链路故障,所有用户走电信链路。

3.      各设备的基本配置情况:

1)      SW1

system-view

sysname SW1

int vlan-int 1

ip add 1.1.1.1 24

local-user admin

password simple admin

service-type telnet level 3

quit

user-interface vty 0 4

authen scheme

quit

vlan 10

port e1/0/10

vlan 20

port e1/0/20

quit

#stp

stp enable

stp mode rstp 

int e1/0/22

port link-type trunk

port trunk permit vlan all

int e1/0/23

port link-type trunk

port trunk permit vlan all

int e1/0/24

port link-type trunk

port trunk permit vlan all

quit

#链路聚合

link-aggregation group 1 mode manual

int e1/0/23

port link-aggregation group 1

int e1/0/24

port link-aggregation group 1

#查看

dis link-aggregation summay

dis link-aggregation verbose

 

2)      SW2

system-view

sysname SW2

int vlan-int 1

ip add 1.1.1.2 24

quit

vlan 10

port e1/0/10

vlan 20

port e1/0/20

quit

#stp

stp enable

stp mode rstp

int e1/0/22

port link-type trunk

port trunk permit vlan all

int e1/0/23

port link-type trunk

port trunk permit vlan all

int e1/0/24

port link-type trunk

port trunk permit vlan all

quit

#链路聚合

link-aggregation group 1 mode manual

int e1/0/23

port link-aggregation group 1

int e1/0/24

port link-aggregation group 1

#测试

ping 1.1.1.1

3)      FW1

system-view

sysname FW1

int eth0/0

ip add 1.1.1.253 24

int eth0/0.1

vlan-type dot1q vid 10

ip add 192.168.10.1 24

int eth0/0.2

vlan-type dot1q vid 20

ip add 192.168.20.1 24

int eth0/4

ip add 61.130.130.1 30

quit

ip route-static 0.0.0.0 0 61.130.130.2

undo insulate

firewall zone trust

add int eth0/0.1

add int eth0/0.2

quit

firewall zone untrust

add int eth0/4

#查看

dis ip routing-table

#nat

acl number 2000 match-order auto

rule 10 permit source any

int eth0/4

nat outbound 2000

4)      FW2

system-view

sysname FW2

int eth0/0

ip add 1.1.1.254 24

int eth0/0.1

vlan-type dot1q vid 10

ip add 192.168.10.2 24

int eth0/0.2

vlan-type dot1q vid 20

ip add 192.168.20.2 24

int eth0/4

ip add 61.130.130.3 30

quit

undo insulate

firewall zone trust

add int eth0/0.1

add int eth0/0.2

quit

firewall zone untrust

add int eth0/4

quit

#测试

ping 192.168.10.1

ping 192.168.20.1

ip route-static 0.0.0.0 0 61.130.130.3

dis ip routing-table

acl number 2000 match-order auto

rule 10 permit source any

int eth0/4

nat outbound 2000

5)      Internet-FW

system-view

sysname ISP

int eth0/0

ip add 61.130.130.2 30

int eth0/4

ip add 61.130.130.4 30

int eth0/1

ip add 1.2.3.4 24

loopback

quit

firewall zone untrust

add int eth0/1

add int eth0/4

quit

dis ip routing-table

ping 61.130.130.1

ping 61.130.130.3

*检查测试

一台虚拟机(XP)ip:192.168.10.100 gateway:192.168.10.1   桥接模式

ping 192.168.10.1

ping 192.168.20.1

ping 192.168.10.2

ping 192.168.20.2

ping 61.130.130.2

ping 61.130.130.4

ping 1.2.3.4

更改虚拟机的网关为:192.168.10.2

ping 1.2.3.4

能够ping通说明基本的配置没有问题

4.      各设备的功能实现配置情况

1)      SW1

#为交换机指定网关

ip route 0.0.0.0 0 1.1.1.253

2)      SW2

Ip route 0.0.0.0 0 1.1.1.254

3)      FW1

vrrp ping-enable

#虚拟设备

int eth0/0.1

vrrp vrid 10 virtual-ip 192.168.10.254

vrrp vrid 10 priority 120

dis vrrp

#接口跟踪 当eth0/4接口上的链路出现故障时将优先级降低30

vrrp vrid 10 track eth0/4 reduced 30

int eth0/0.2

vrrp vrid 20 virtual-ip 192.168.20.254

dis vrrp

4)      FW2

vrrp ping-enable

int etn0/0.1

vrrp vrid 10 virtual-ip 192.168.10.254

int eth0/0.2

vrrp vrid 20 virtual-ip 192.168.20.254

vrrp vrid 20 priority 120

vrrp vrid 20 track eth0/4 reduced 30

dis vrrp

5.      测试网络功能的实现

1)      虚拟机(PC1)网关指向更改成:192.168.10.254;在与SW2相连的VLAN 20添加一台虚拟机(PC2)ip:192.168.20.100 网关指向:192.168.20.254

2)      PC1:tracert192.168.20.100


         PC2:tracret 192.168.10.100

模拟故障:PC1  ping 192.168.20.100 –t

     将FW1的e0/0shutdown

可以观察到ping的过程依然能够收到来自192.168.20.100的回复了。

          tracert 192.168.20.100


再将FW1的eth0/0取消shutdown后

3)      PC1访问Internet



模拟故障:将FW1的eth0/4shutdown

     当eth0/4恢复时


  • 1
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值