学习目的
·掌握VLAN的配置方法
·掌握Eth-trunk的配置方法
拓扑图
图1-1 VLAN配置
场景
你是公司的网络管理员。现在公司网络是由二台交换机组成的以太网环境。图中路由器模拟网络中的计算机,R3是一台服务器。为了优化这个网络,需要你提升S1和S2相连链路的速度和可靠性。并且创建二个VLAN,以实现广播域的互相隔离。R2和R3处于相同的VLAN中。同时为了方便访问服务器,你应该让R1和R3能够正常通信。
学习任务
步骤一.基础配置与IP编址
给所有设备配置IP地址和掩码。
system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R1
[R1]interface GigabitEthernet 0/0/1
[R1-GigabitEthernet0/0/1]ip address 10.0.10.1 24
system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R2
[R2]interface GigabitEthernet 0/0/1
[R2-GigabitEthernet0/0/1]ip address 10.0.10.2 24
system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R3
[R3]interface GigabitEthernet 0/0/2
[R3-GigabitEthernet0/0/2]ip address 10.0.10.3 24
给交换机配置名称。
system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname S1
system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname S2
步骤二.Eth-trunk链路聚合
Eth-trunk可以将二条或多条链路捆绑成一条链路以提升链路带宽和可靠性。将S1和S2的G0/0/9和G0/0/10接口加入到同一个Eth-trunk组可以实现企业需求。
创建Eth-trunk接口。
[S1]interface Eth-Trunk 1
[S1-Eth-Trunk1]
[S2]interface Eth-Trunk 1
[S2-Eth-Trunk1]
配置Eth-trunk的工作模式为LACP模式。
[S1-Eth-Trunk1]mode lacp
[S2-Eth-Trunk1]mode lacp
将S1和S2的G0/0/9和G0/0/10接口加入到Eth-trunk接口。
[S1]interface GigabitEthernet 0/0/9
[S1-GigabitEthernet0/0/9]eth-trunk 1
[S1-GigabitEthernet0/0/9]quit
[S1]interface GigabitEthernet 0/0/10
[S1-GigabitEthernet0/0/10]eth-trunk 1
[S2]interface GigabitEthernet 0/0/9
[S2-GigabitEthernet0/0/9]eth-trunk 1
[S2-GigabitEthernet0/0/9]quit
[S2]interface GigabitEthernet 0/0/10
[S2-GigabitEthernet0/0/10]eth-trunk 1
使用命令dispay eth-trunk查看配置情况。
[S1]display eth-trunk
Eth-Trunk1's state information is:
Local:
LAG ID: 1 WorkingMode: LACP
Preempt Delay: Disabled Hash arithmetic: According to SIP-XOR-DIP
System Priority: 32768 System ID: d0d0-4ba6-aab0
Least Active-linknumber: 1 Max Active-linknumber: 8
Operate status: up Number Of Up Port In Trunk: 2
--------------------------------------------------------------------------------
ActorPortName Status PortType PortPri PortNo PortKey PortState Weight
GigabitEthernet0/0/9 Selected 1GE 32768 1 305 10111100 1
GigabitEthernet0/0/10 Selected 1GE 32768 2 305 10111100 1
Partner:
--------------------------------------------------------------------------------
ActorPortName SysPri SystemID PortPri PortNo PortKey PortState
GigabitEthernet0/0/9 32768 d0d0-4ba6-ac20 32768 1 305 10111100
GigabitEthernet0/0/10 32768 d0d0-4ba6-ac20 32768 2 305 10111100
输出信息显示,此时链路运行模式为LACP模式,并且最大活动接口数阈值是8条链路。同时G0/0/9和G0/0/10接口都处于活动状态。
使用命令更改活动接口数阈值。
[S1-Eth-Trunk1]max active-linknumber 1
[S2-Eth-Trunk1]max active-linknumber 1
查看Eth-trunk链路配置情况。
[S1]display eth-trunk 1
Eth-Trunk1's state information is:
Local:
LAG ID: 1 WorkingMode: LACP
Preempt Delay: Disabled Hash arithmetic: According to SIP-XOR-DIP
System Priority: 32768 System ID: d0d0-4ba6-aab0
Least Active-linknumber: 1 Max Active-linknumber: 1
Operate status: up Number Of Up Port In Trunk: 1
--------------------------------------------------------------------------------
ActorPortName Status PortType PortPri PortNo PortKey PortState Weight
GigabitEthernet0/0/9 Selected 1GE 32768 1 305 10111100 1
GigabitEthernet0/0/10 Unselect 1GE 32768 2 305 10100000 1
Partner:
--------------------------------------------------------------------------------
ActorPortName SysPri SystemID PortPri PortNo PortKey PortState
GigabitEthernet0/0/9 32768 d0d0-4ba6-ac20 32768 1 305 10111100
GigabitEthernet0/0/10 32768 d0d0-4ba6-ac20 32768 2 305 10100000
从输出信息可以看到,G0/0/10接口状态改变为Unselect。实现了Eth-trunk聚合链路下一条链路传输数据,另一条链路备份的功能,提升了网络可靠性。
通过关闭S1的G0/0/9接口验证备份链路功能。
[S1]interface GigabitEthernet 0/0/9
[S1-GigabitEthernet0/0/9]shutdown
查看Eth-trunk链路信息。
[S1]display eth-trunk 1
Eth-Trunk1's state information is:
Local:
LAG ID: 1 WorkingMode: LACP
Preempt Delay: Disabled Hash arithmetic: According to SIP-XOR-DIP
System Priority: 32768 System ID: d0d0-4ba6-aab0
Least Active-linknumber: 1 Max Active-linknumber: 1
Operate status: up Number Of Up Port In Trunk: 1
--------------------------------------------------------------------------------
ActorPortName Status PortType PortPri PortNo PortKey PortState Weight
GigabitEthernet0/0/9 Unselect 1GE 32768 1 305 10100010 1
GigabitEthernet0/0/10 Selected 1GE 32768 2 305 10111100 1
Partner:
--------------------------------------------------------------------------------
ActorPortName SysPri SystemID PortPri PortNo PortKey PortState
GigabitEthernet0/0/9 0 0000-0000-0000 0 0 0 10100011
GigabitEthernet0/0/10 32768 d0d0-4ba6-ac20 32768 2 305 10111100
从输出信息看到Eth-trunk链路中G0/0/9已经变为Unselect状态,G0/0/10由Unselect状态自动转换为Selected状态继续传输数据。由此可知,实现了链路备份功能。
最终设备配置
[S1]dis current-configuration
!Software Version V200R008C00SPC500
#
sysname SW1
#
diffserv domain default
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password irreversible-cipher %^%#tK;J&jw0HG8<9-"zx!khwzxrnjuxn96[vn47f$*l~pxcroep3!>c)NV+:`i;%^%#
local-user admin service-type http
#
interface Vlanif1
#
interface MEth0/0/1
#
interface Eth-Trunk1
mode lacp
max active-linknumber 1
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
shutdown
eth-trunk 1
#
interface GigabitEthernet0/0/10
eth-trunk 1
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
#
interface GigabitEthernet0/0/25
#
interface GigabitEthernet0/0/26
#
interface GigabitEthernet0/0/27
#
interface GigabitEthernet0/0/28
#
interface XGigabitEthernet0/0/1
#
interface XGigabitEthernet0/0/2
#
interface XGigabitEthernet0/0/3
#
interface XGigabitEthernet0/0/4
#
interface NULL0
#
user-interface con 0
authentication-mode password
set authentication password cipher $1a$fcjGHMtb0U$^GKZ+`,g@DfG$:T/P,R~iJ&')|!O":$b4)0*~&c-$
idle-timeout 0 0
user-interface vty 0 4
user-interface vty 16 20
#
return
[S2]display current-configuration
!Software Version V200R008C00SPC500
#
sysname SW2
#
diffserv domain default
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password irreversible-cipher %^%#gI/bO8qF$HkpAPUgNd'GiYR4TC!>EK#oG("Wl4_#$G*OKo-'7*R[h3+49
local-user admin service-type http
#
interface Vlanif1
#
interface MEth0/0/1
#
interface Eth-Trunk1
mode lacp
max active-linknumber 1
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/02
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
eth-trunk 1
#
interface GigabitEthernet0/0/10
eth-trunk 1
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
#
interface GigabitEthernet0/0/25
#
interface GigabitEthernet0/0/26
#
interface GigabitEthernet0/0/27
#
interface GigabitEthernet0/0/28
#
interface XGigabitEthernet0/0/1
#
interface XGigabitEthernet0/0/2
#
interface XGigabitEthernet0/0/3
#
interface XGigabitEthernet0/0/4
#
interface NULL0
#
user-interface con 0
authentication-mode password
set authentication password cipher $1a$5"l`L7$/5T$,KFQ9dEy~'IggWOa7V(C+9fQOd*M;U6q,.Sl1y'H$
idle-timeout 0 0
user-interface vty 0 4
user-interface vty 16 20
#
Return