拓扑
一、VSU
VSU#show run
hostname VSU
!
!
username admin password admin1234
!
cwmp
!
service dhcp
!
ip dhcp pool Pool_VLAN10
network 192.1.10.0 255.255.255.0
default-router 192.1.10.254
!
no zam
enable password admin1234
enable service ssh-server
!
vlan 1
!
interface GigabitEthernet 1/0/1
no switchport
ip address 10.1.0.2 255.255.255.252
ip ospf network point-to-point
!
interface GigabitEthernet 1/0/2
no switchport
ip address 10.1.0.9 255.255.255.252
ip ospf network point-to-point
!
interface GigabitEthernet 1/0/3
!
interface GigabitEthernet 1/0/4
!
interface GigabitEthernet 1/0/5
!
interface GigabitEthernet 1/0/6
!
interface GigabitEthernet 1/0/7
!
interface GigabitEthernet 1/0/8
!
interface GigabitEthernet 1/0/9
!
interface GigabitEthernet 1/0/10
!
interface GigabitEthernet 1/0/11
!
interface GigabitEthernet 1/0/12
!
interface GigabitEthernet 1/0/13
!
interface GigabitEthernet 1/0/14
!
interface GigabitEthernet 1/0/15
!
interface GigabitEthernet 1/0/16
!
interface GigabitEthernet 1/0/17
!
interface GigabitEthernet 1/0/18
!
interface GigabitEthernet 1/0/19
!
interface GigabitEthernet 1/0/20
!
interface GigabitEthernet 1/0/21
!
interface GigabitEthernet 1/0/22
!
interface GigabitEthernet 1/0/23
!
interface GigabitEthernet 1/0/24
!
interface GigabitEthernet 1/0/25
!
interface GigabitEthernet 1/0/26
!
interface GigabitEthernet 1/0/27
!
interface GigabitEthernet 1/0/28
!
interface GigabitEthernet 1/0/29
!
interface GigabitEthernet 1/0/30
!
interface GigabitEthernet 1/0/31
!
interface GigabitEthernet 1/0/32
!
interface GigabitEthernet 1/0/33
!
interface GigabitEthernet 1/0/34
!
interface GigabitEthernet 1/0/35
!
interface GigabitEthernet 1/0/36
!
interface GigabitEthernet 1/0/37
!
interface GigabitEthernet 1/0/38
!
interface GigabitEthernet 1/0/39
!
interface GigabitEthernet 1/0/40
!
interface GigabitEthernet 1/0/41
!
interface GigabitEthernet 1/0/42
!
interface GigabitEthernet 1/0/43
!
interface GigabitEthernet 1/0/44
!
interface GigabitEthernet 1/0/45
!
interface GigabitEthernet 1/0/46
!
interface GigabitEthernet 1/0/47
!
interface GigabitEthernet 1/0/48
no switchport
!
interface GigabitEthernet 2/0/1
no switchport
ip address 10.1.0.6 255.255.255.252
ip ospf network point-to-point
!
interface GigabitEthernet 2/0/2
no switchport
ip address 10.1.0.13 255.255.255.252
ip ospf network point-to-point
!
interface GigabitEthernet 2/0/3
!
interface GigabitEthernet 2/0/4
!
interface GigabitEthernet 2/0/5
!
interface GigabitEthernet 2/0/6
!
interface GigabitEthernet 2/0/7
!
interface GigabitEthernet 2/0/8
!
interface GigabitEthernet 2/0/9
!
interface GigabitEthernet 2/0/10
!
interface GigabitEthernet 2/0/11
!
interface GigabitEthernet 2/0/12
!
interface GigabitEthernet 2/0/13
!
interface GigabitEthernet 2/0/14
!
interface GigabitEthernet 2/0/15
!
interface GigabitEthernet 2/0/16
!
interface GigabitEthernet 2/0/17
!
interface GigabitEthernet 2/0/18
!
interface GigabitEthernet 2/0/19
!
interface GigabitEthernet 2/0/20
!
interface GigabitEthernet 2/0/21
!
interface GigabitEthernet 2/0/22
!
interface GigabitEthernet 2/0/23
!
interface GigabitEthernet 2/0/24
!
interface GigabitEthernet 2/0/25
!
interface GigabitEthernet 2/0/26
!
interface GigabitEthernet 2/0/27
!
interface GigabitEthernet 2/0/28
!
interface GigabitEthernet 2/0/29
!
interface GigabitEthernet 2/0/30
!
interface GigabitEthernet 2/0/31
!
interface GigabitEthernet 2/0/32
!
interface GigabitEthernet 2/0/33
!
interface GigabitEthernet 2/0/34
!
interface GigabitEthernet 2/0/35
!
interface GigabitEthernet 2/0/36
!
interface GigabitEthernet 2/0/37
!
interface GigabitEthernet 2/0/38
!
interface GigabitEthernet 2/0/39
!
interface GigabitEthernet 2/0/40
!
interface GigabitEthernet 2/0/41
!
interface GigabitEthernet 2/0/42
!
interface GigabitEthernet 2/0/43
!
interface GigabitEthernet 2/0/44
!
interface GigabitEthernet 2/0/45
!
interface GigabitEthernet 2/0/46
!
interface GigabitEthernet 2/0/47
!
interface GigabitEthernet 2/0/48
no switchport
!
interface TenGigabitEthernet 1/0/49
!
interface TenGigabitEthernet 1/0/50
!
interface TenGigabitEthernet 1/0/51
!
interface TenGigabitEthernet 1/0/52
!
interface TenGigabitEthernet 2/0/49
!
interface TenGigabitEthernet 2/0/50
!
interface TenGigabitEthernet 2/0/51
!
interface TenGigabitEthernet 2/0/52
!
interface Loopback 0
ip address 11.1.0.67 255.255.255.255
!
interface Mgmt 1/0
!
interface Mgmt 2/0
!
router ospf 10
router-id 11.1.0.67
graceful-restart
network 10.1.0.0 0.0.0.3 area 0
network 10.1.0.4 0.0.0.3 area 0
network 10.1.0.8 0.0.0.3 area 0
network 10.1.0.12 0.0.0.3 area 0
network 11.1.0.67 0.0.0.0 area 0
!
switch virtual domain 1
dual-active detection bfd
dual-active bfd interface GigabitEthernet 1/0/48
dual-active bfd interface GigabitEthernet 2/0/48
!
snmp-server host 172.16.0.254 traps version 2c ruijie
snmp-server host 172.16.0.254 traps version 2c public
snmp-server enable traps
snmp-server community ruijie rw
snmp-server community public ro
!
line console 0
line vty 0 4
login local
!
end
VSU#
二、S1
S1#show run
hostname S1
!
spanning-tree mst configuration
revision 1
name test
!
spanning-tree
!
ip dhcp snooping
!
username admin password admin1234
!
enable password admin1234
enable service ssh-server
!
vlan range 1,10,20,30,100
!
interface GigabitEthernet 0/1
switchport access vlan 10
!
interface GigabitEthernet 0/2
errdisable recovery interval 300
switchport access vlan 10
spanning-tree bpduguard enable
rldp port loop-detect shutdown-port
switchport port-security maximum 1
switchport port-security
!
interface GigabitEthernet 0/3
switchport access vlan 10
!
interface GigabitEthernet 0/4
switchport access vlan 10
!
interface GigabitEthernet 0/5
switchport access vlan 20
!
interface GigabitEthernet 0/6
switchport access vlan 20
!
interface GigabitEthernet 0/7
switchport access vlan 20
!
interface GigabitEthernet 0/8
switchport access vlan 20
!
interface GigabitEthernet 0/9
switchport access vlan 30
!
interface GigabitEthernet 0/10
switchport access vlan 30
!
interface GigabitEthernet 0/11
switchport access vlan 30
!
interface GigabitEthernet 0/12
switchport access vlan 30
!
interface GigabitEthernet 0/13
!
interface GigabitEthernet 0/14
!
interface GigabitEthernet 0/15
!
interface GigabitEthernet 0/16
!
interface GigabitEthernet 0/17
!
interface GigabitEthernet 0/18
!
interface GigabitEthernet 0/19
!
interface GigabitEthernet 0/20
!
interface GigabitEthernet 0/21
!
interface GigabitEthernet 0/22
!
interface GigabitEthernet 0/23
switchport mode trunk
switchport trunk native vlan 100
switchport trunk allowed vlan only 10,20,30,100
ip dhcp snooping trust
!
interface GigabitEthernet 0/24
switchport mode trunk
switchport trunk native vlan 100
switchport trunk allowed vlan only 10,20,30,100
ip dhcp snooping trust
!
interface TenGigabitEthernet 0/25
!
interface TenGigabitEthernet 0/26
!
interface TenGigabitEthernet 0/27
!
interface TenGigabitEthernet 0/28
!
interface VLAN 1
!
interface VLAN 100
ip address 192.1.100.1 255.255.255.0
!
ip route 0.0.0.0 0.0.0.0 192.1.100.254
!
line console 0
line vty 0 4
login local
!
end
S1#
三、S2
S2(config)#show run
hostname S2
!
spanning-tree mst configuration
revision 1
name test
!
spanning-tree
!
ip dhcp snooping
!
username admin password admin1234
!
nfpp
log-buffer logs 1 interval 300
log-buffer entries 1024
log-buffer enable
!
cpu-protect cpu bandwidth 500
no service password-encryption
!
redundancy
!
no zam
enable password admin1234
enable service ssh-server
!
vlan range 1,10,20,30,100
!
interface GigabitEthernet 0/1
switchport access vlan 10
!
interface GigabitEthernet 0/2
switchport access vlan 10
!
interface GigabitEthernet 0/3
switchport access vlan 10
!
interface GigabitEthernet 0/4
switchport access vlan 10
!
interface GigabitEthernet 0/5
switchport access vlan 20
!
interface GigabitEthernet 0/6
switchport access vlan 20
!
interface GigabitEthernet 0/7
switchport access vlan 20
!
interface GigabitEthernet 0/8
switchport access vlan 20
!
interface GigabitEthernet 0/9
switchport access vlan 30
!
interface GigabitEthernet 0/10
switchport access vlan 30
!
interface GigabitEthernet 0/11
switchport access vlan 30
!
interface GigabitEthernet 0/12
switchport access vlan 30
!
interface GigabitEthernet 0/13
!
interface GigabitEthernet 0/14
!
interface GigabitEthernet 0/15
!
interface GigabitEthernet 0/16
!
interface GigabitEthernet 0/17
!
interface GigabitEthernet 0/18
!
interface GigabitEthernet 0/19
!
interface GigabitEthernet 0/20
!
interface GigabitEthernet 0/21
!
interface GigabitEthernet 0/22
!
interface GigabitEthernet 0/23
switchport mode trunk
switchport trunk native vlan 100
switchport trunk allowed vlan only 10,20,30,100
ip dhcp snooping trust
no nfpp arp-guard enable
!
interface GigabitEthernet 0/24
switchport mode trunk
switchport trunk native vlan 100
switchport trunk allowed vlan only 10,20,30,100
ip dhcp snooping trust
no nfpp arp-guard enable
!
interface TenGigabitEthernet 0/25
!
interface TenGigabitEthernet 0/26
!
interface TenGigabitEthernet 0/27
!
interface TenGigabitEthernet 0/28
!
interface VLAN 100
ip address 192.1.100.2 255.255.255.0
!
ip route 0.0.0.0 0.0.0.0 192.1.100.254
!
line console 0
line vty 0 4
login local
!
end
四、S3
S3#show ru
hostname S3
!
spanning-tree mst configuration
revision 1
name test
!
spanning-tree mst 0 priority 8192
spanning-tree
!
cwmp
!
service dhcp
ip helper-address 11.1.0.67
!
!
vlan range 1,10,20,30,100
!
interface GigabitEthernet 0/1
switchport mode trunk
switchport trunk native vlan 100
switchport trunk allowed vlan only 10,20,30,100
!
interface GigabitEthernet 0/2
switchport mode trunk
switchport trunk native vlan 100
switchport trunk allowed vlan only 10,20,30,100
!
interface GigabitEthernet 0/3
!
interface GigabitEthernet 0/4
!
interface GigabitEthernet 0/5
!
interface GigabitEthernet 0/6
!
interface GigabitEthernet 0/7
!
interface GigabitEthernet 0/8
!
interface GigabitEthernet 0/9
!
interface GigabitEthernet 0/10
!
interface GigabitEthernet 0/11
!
interface GigabitEthernet 0/12
!
interface GigabitEthernet 0/13
!
interface GigabitEthernet 0/14
!
interface GigabitEthernet 0/15
!
interface GigabitEthernet 0/16
!
interface GigabitEthernet 0/17
!
interface GigabitEthernet 0/18
!
interface GigabitEthernet 0/19
!
interface GigabitEthernet 0/20
!
interface GigabitEthernet 0/21
port-group 1
!
interface GigabitEthernet 0/22
port-group 1
!
interface GigabitEthernet 0/23
!
interface GigabitEthernet 0/24
no switchport
ip address 10.1.0.1 255.255.255.252
ip ospf network point-to-point
ip ospf cost 10
!
interface TenGigabitEthernet 0/25
!
interface TenGigabitEthernet 0/26
!
interface TenGigabitEthernet 0/27
!
interface TenGigabitEthernet 0/28
!
interface AggregatePort 1
switchport mode trunk
switchport trunk native vlan 100
switchport trunk allowed vlan only 10,20,30,100
!
interface VLAN 10
ip address 192.1.10.252 255.255.255.0
vrrp 10 ip 192.1.10.254
vrrp 10 ipv6 FE80::64
vrrp 10 ipv6 2001:193:10::254
ipv6 address 2001:193:10::252/64
ipv6 enable
no ipv6 nd suppress-ra
vrrp ipv6 10 priority 120
vrrp ipv6 10 accept_mode
vrrp 10 priority 120
!
interface VLAN 20
ip address 192.1.20.252 255.255.255.0
vrrp 20 ip 192.1.20.254
vrrp 20 ipv6 FE80::64
vrrp 20 ipv6 2001:193:20::254
ipv6 address 2001:193:20::252/64
ipv6 enable
no ipv6 nd suppress-ra
vrrp ipv6 20 priority 120
vrrp ipv6 20 accept_mode
vrrp 20 priority 120
!
interface VLAN 30
ip address 192.1.30.252 255.255.255.0
vrrp 30 ip 192.1.30.254
vrrp 30 ipv6 FE80::64
vrrp 30 ipv6 2001:193:30::254
ipv6 address 2001:193:30::252/64
ipv6 enable
no ipv6 nd suppress-ra
vrrp ipv6 30 priority 120
vrrp ipv6 30 accept_mode
vrrp 30 priority 120
!
interface VLAN 100
ip address 192.1.100.252 255.255.255.0
vrrp 100 ip 192.1.100.254
vrrp 100 priority 120
ip ospf network point-to-point
!
router ospf 10
router-id 10.1.0.1
graceful-restart
passive-interface VLAN 10
passive-interface VLAN 20
passive-interface VLAN 30
network 10.1.0.1 0.0.0.0 area 0
network 10.1.0.0 0.0.0.3 area 0
network 192.1.10.0 0.0.0.255 area 0
network 192.1.20.0 0.0.0.255 area 0
network 192.1.30.0 0.0.0.255 area 0
network 192.1.100.0 0.0.0.255 area 0
!
line console 0
line vty 0 4
login
!
end
五、S4
S4#show run
hostname S4
!
spanning-tree mst configuration
revision 1
name test
!
spanning-tree mst 0 priority 4096
spanning-tree
!
service dhcp
ip helper-address 11.1.0.67
!
!
vlan range 1,10,20,30,100
!
interface GigabitEthernet 0/1
switchport mode trunk
switchport trunk native vlan 100
switchport trunk allowed vlan only 10,20,30,100
!
interface GigabitEthernet 0/2
switchport mode trunk
switchport trunk native vlan 100
switchport trunk allowed vlan only 10,20,30,100
!
interface GigabitEthernet 0/3
!
interface GigabitEthernet 0/4
!
interface GigabitEthernet 0/5
!
interface GigabitEthernet 0/6
!
interface GigabitEthernet 0/7
!
interface GigabitEthernet 0/8
!
interface GigabitEthernet 0/9
!
interface GigabitEthernet 0/10
!
interface GigabitEthernet 0/11
!
interface GigabitEthernet 0/12
!
interface GigabitEthernet 0/13
!
interface GigabitEthernet 0/14
!
interface GigabitEthernet 0/15
!
interface GigabitEthernet 0/16
!
interface GigabitEthernet 0/17
!
interface GigabitEthernet 0/18
!
interface GigabitEthernet 0/19
!
interface GigabitEthernet 0/20
!
interface GigabitEthernet 0/21
port-group 1
!
interface GigabitEthernet 0/22
port-group 1
!
interface GigabitEthernet 0/23
!
interface GigabitEthernet 0/24
no switchport
ip address 10.1.0.5 255.255.255.252
ip ospf network point-to-point
!
interface TenGigabitEthernet 0/25
!
interface TenGigabitEthernet 0/26
!
interface TenGigabitEthernet 0/27
!
interface TenGigabitEthernet 0/28
!
interface AggregatePort 1
switchport mode trunk
switchport trunk native vlan 100
switchport trunk allowed vlan only 10,20,30,100
!
interface Loopback 0
ip address 11.1.0.34 255.255.255.255
!
interface VLAN 10
ip address 192.1.10.253 255.255.255.0
vrrp 10 ip 192.1.10.254
vrrp 10 ipv6 FE80::64
vrrp 10 ipv6 2001:193:10::254
ipv6 address 2001:193:10::253/64
ipv6 enable
no ipv6 nd suppress-ra
vrrp ipv6 10 priority 150
vrrp ipv6 10 accept_mode
vrrp 10 priority 150
!
interface VLAN 20
ip address 192.1.20.253 255.255.255.0
vrrp 20 ip 192.1.20.254
vrrp 20 ipv6 FE80::64
vrrp 20 ipv6 2001:193:20::254
ipv6 address 2001:193:20::253/64
ipv6 enable
no ipv6 nd suppress-ra
vrrp ipv6 20 priority 150
vrrp ipv6 20 accept_mode
vrrp 20 priority 150
!
interface VLAN 30
ip address 192.1.30.253 255.255.255.0
vrrp 30 ip 192.1.30.254
vrrp 30 ipv6 FE80::64
vrrp 30 ipv6 2001:193:30::254
ipv6 address 2001:193:30::253/64
ipv6 enable
no ipv6 nd suppress-ra
vrrp ipv6 30 priority 150
vrrp ipv6 30 accept_mode
vrrp 30 priority 150
!
interface VLAN 100
ip address 192.1.100.253 255.255.255.0
vrrp 100 ip 192.1.100.254
vrrp 100 priority 150
ip ospf network point-to-point
!
router ospf 10
router-id 11.1.0.34
graceful-restart
passive-interface VLAN 10
passive-interface VLAN 20
passive-interface VLAN 30
network 10.1.0.4 0.0.0.3 area 0
network 11.1.0.34 0.0.0.0 area 0
network 192.1.10.0 0.0.0.255 area 0
network 192.1.20.0 0.0.0.255 area 0
network 192.1.30.0 0.0.0.255 area 0
network 192.1.100.0 0.0.0.255 area 0
!
line console 0
line vty 0 4
login
!
end
六、S5
S5#show run
hostname S5
!
no spanning-tree
!
username admin password admin1234
!
no cwmp
!
service dhcp
!
ip dhcp pool vl10
option 138 ip 11.1.0.204 11.1.0.205
network 194.1.10.0 255.255.255.0
default-router 194.1.10.254
!
ip dhcp pool vl20
network 194.1.20.0 255.255.255.0
default-router 194.1.20.254
!
ip dhcp pool vl30
network 194.1.30.0 255.255.255.0
default-router 194.1.30.254
!
enable password admin1234
enable service ssh-server
!
vlan range 1,10,20,30,100
!
interface GigabitEthernet 0/1
switchport mode trunk
switchport trunk native vlan 10
switchport trunk allowed vlan only 10,20
!
interface GigabitEthernet 0/2
switchport mode trunk
switchport trunk native vlan 10
switchport trunk allowed vlan only 10,30
!
interface GigabitEthernet 0/3
switchport mode trunk
switchport trunk native vlan 10
switchport trunk allowed vlan only 10,20,30
!
interface GigabitEthernet 0/4
switchport mode trunk
switchport trunk native vlan 10
switchport trunk allowed vlan only 10,20,30
!
interface GigabitEthernet 0/5
switchport mode trunk
switchport trunk native vlan 10
switchport trunk allowed vlan only 10,20,30
rate-limit input 10000 1024
!
interface GigabitEthernet 0/6
switchport mode trunk
switchport trunk native vlan 10
switchport trunk allowed vlan only 10,20,30
rate-limit input 10000 1024
!
interface GigabitEthernet 0/7
switchport mode trunk
switchport trunk native vlan 10
switchport trunk allowed vlan only 10,20,30
rate-limit input 10000 1024
!
interface GigabitEthernet 0/8
switchport mode trunk
switchport trunk native vlan 10
switchport trunk allowed vlan only 10,20,30
rate-limit input 10000 1024
!
interface GigabitEthernet 0/9
switchport mode trunk
switchport trunk native vlan 10
switchport trunk allowed vlan only 10,20,30
rate-limit input 10000 1024
!
interface GigabitEthernet 0/10
switchport mode trunk
switchport trunk native vlan 10
switchport trunk allowed vlan only 10,20,30
rate-limit input 10000 1024
!
interface GigabitEthernet 0/11
rate-limit input 10000 1024
!
interface GigabitEthernet 0/12
rate-limit input 10000 1024
!
interface GigabitEthernet 0/13
!
interface GigabitEthernet 0/14
!
interface GigabitEthernet 0/15
!
interface GigabitEthernet 0/16
!
interface GigabitEthernet 0/17
!
interface GigabitEthernet 0/18
!
interface GigabitEthernet 0/19
!
interface GigabitEthernet 0/20
!
interface GigabitEthernet 0/21
switchport mode trunk
switchport trunk native vlan 100
switchport trunk allowed vlan only 10,20,30,100
!
interface GigabitEthernet 0/22
switchport mode trunk
switchport trunk native vlan 100
switchport trunk allowed vlan only 10,20,30,100
!
interface GigabitEthernet 0/23
!
interface GigabitEthernet 0/24
no switchport
ip address 10.1.0.17 255.255.255.252
ip ospf network point-to-point
!
interface TenGigabitEthernet 0/25
!
interface TenGigabitEthernet 0/26
!
interface TenGigabitEthernet 0/27
!
interface TenGigabitEthernet 0/28
!
interface Loopback 0
ip address 11.1.0.5 255.255.255.255
!
interface VLAN 10
ip address 194.1.10.254 255.255.255.0
!
interface VLAN 20
ip address 194.1.20.254 255.255.255.0
!
interface VLAN 30
ip address 194.1.30.254 255.255.255.0
!
interface VLAN 100
ip address 194.1.100.254 255.255.255.0
!
router ospf 10
router-id 11.1.0.5
graceful-restart
network 10.1.0.16 0.0.0.3 area 0
network 11.1.0.5 0.0.0.0 area 0
network 194.1.10.0 0.0.0.255 area 0
network 194.1.20.0 0.0.0.255 area 0
network 194.1.30.0 0.0.0.255 area 0
network 194.1.100.0 0.0.0.255 area 0
!
line console 0
line vty 0 4
login local
!
end
S5#
七、AC1
AC1#show run
hostname AC1
!
wlan-config 1 Ruijie-CW_01
wlan-based per-user-limit down-streams average-data-rate 800 burst-data-rate 1600
!
wlan-config 2 Ruijie-YF_01
!
ap-group ZB
interface-mapping 1 20 ap-wlan-id 1
interface-mapping 2 30 ap-wlan-id 2
!
ap-group default
!
ap-config all
!
ac-controller
country CN
802.11g network rate 1 disabled
802.11g network rate 2 disabled
802.11g network rate 5 disabled
802.11g network rate 6 supported
802.11g network rate 9 supported
802.11g network rate 11 mandatory
802.11g network rate 12 supported
802.11g network rate 18 supported
802.11g network rate 24 supported
802.11g network rate 36 supported
802.11g network rate 48 supported
802.11g network rate 54 supported
802.11b network rate 1 disabled
802.11b network rate 2 disabled
802.11b network rate 5 disabled
802.11b network rate 11 mandatory
802.11a network rate 6 disabled
802.11a network rate 9 disabled
802.11a network rate 12 mandatory
802.11a network rate 18 supported
802.11a network rate 24 mandatory
802.11a network rate 36 supported
802.11a network rate 48 supported
802.11a network rate 54 supported
!
tftp-server enable
schedule session 1
schedule session 1 time-range 1 period Mon to Fri time 21:00 to 23:30
!
!
enable password admin1234
enable service ssh-server
vlan 1
!
vlan 20
!
vlan 30
!
vlan 100
!
interface GigabitEthernet 0/1
switchport mode trunk
switchport trunk native vlan 100
switchport trunk allowed vlan only 10,20,30,100
!
interface GigabitEthernet 0/2
!
interface GigabitEthernet 0/3
!
interface GigabitEthernet 0/4
!
interface GigabitEthernet 0/5
!
interface GigabitEthernet 0/6
!
interface GigabitEthernet 0/7
!
interface GigabitEthernet 0/8
!
interface Loopback 0
ip address 11.1.0.204 255.255.255.255
!
interface VLAN 1
!
interface VLAN 100
ip address 194.1.100.251 255.255.255.0
!
wlan hot-backup 11.1.0.205
!
context 7
priority level 7
ap-group ZB
!
wlan hot-backup enable
!
wlansec 1
security rsn enable
security rsn ciphers aes enable
security rsn akm psk enable
security rsn akm psk set-key ascii 12345678
!
wlansec 2
security rsn enable
security rsn ciphers aes enable
security rsn akm psk enable
security rsn akm psk set-key ascii 12345678
!
router ospf 10
router-id 11.1.0.204
graceful-restart
network 11.1.0.204 0.0.0.0 area 0
network 194.1.100.0 0.0.0.255 area 0
!
line console 0
line vty 0 4
login local
!
end
八、AC2
AC2#show run
hostname AC2
!
wlan-config 1 Ruijie-CW_01
wlan-based per-user-limit down-streams average-data-rate 800 burst-data-rate 1600
!
wlan-config 2 Ruijie-YF_01
!
ap-group ZB
interface-mapping 1 20 ap-wlan-id 1
interface-mapping 2 30 ap-wlan-id 2
!
ap-group default
!
ap-config all
!
ac-controller
country CN
802.11g network rate 1 disabled
802.11g network rate 2 disabled
802.11g network rate 5 disabled
802.11g network rate 6 supported
802.11g network rate 9 supported
802.11g network rate 11 mandatory
802.11g network rate 12 supported
802.11g network rate 18 supported
802.11g network rate 24 supported
802.11g network rate 36 supported
802.11g network rate 48 supported
802.11g network rate 54 supported
802.11b network rate 1 disabled
802.11b network rate 2 disabled
802.11b network rate 5 disabled
802.11b network rate 11 mandatory
802.11a network rate 6 disabled
802.11a network rate 9 disabled
802.11a network rate 12 mandatory
802.11a network rate 18 supported
802.11a network rate 24 mandatory
802.11a network rate 36 supported
802.11a network rate 48 supported
802.11a network rate 54 supported
!
tftp-server enable
schedule session 1
schedule session 1 time-range 1 period Mon to Fri time 21:00 to 23:30
!
link-check disable
!
nfpp
!
wids
!
enable password admin1234
enable service ssh-server
vlan 1
!
vlan 20
!
vlan 30
!
vlan 100
!
interface GigabitEthernet 0/1
switchport mode trunk
switchport trunk native vlan 100
switchport trunk allowed vlan only 10,20,30,100
!
interface GigabitEthernet 0/2
!
interface GigabitEthernet 0/3
!
interface GigabitEthernet 0/4
!
interface GigabitEthernet 0/5
!
interface GigabitEthernet 0/6
!
interface GigabitEthernet 0/7
!
interface GigabitEthernet 0/8
!
interface Loopback 0
ip address 11.1.0.205 255.255.255.255
!
interface VLAN 1
!
interface VLAN 100
ip address 194.1.100.252 255.255.255.0
!
wlan hot-backup 11.1.0.204
!
context 7
ap-group ZB
!
wlan hot-backup enable
!
wlansec 1
security rsn enable
security rsn ciphers aes enable
security rsn akm psk enable
security rsn akm psk set-key ascii 12345678
!
wlansec 2
security rsn enable
security rsn ciphers aes enable
security rsn akm psk enable
security rsn akm psk set-key ascii 12345678
!
router ospf 10
router-id 11.1.0.205
graceful-restart
network 11.1.0.205 0.0.0.0 area 0
network 194.1.100.0 0.0.0.255 area 0
!
line console 0
line vty 0 4
login local
!
end
AC2#
九、R1
R1#show run
hostname R1
interface Serial 2/0
encapsulation PPP
ip ospf network point-to-point
ip address 12.1.0.1 255.255.255.252
clock rate 64000
!
interface GigabitEthernet 0/0
ip address 20.1.0.6 255.255.255.248
duplex auto
speed auto
!
interface GigabitEthernet 0/1
ip address 20.1.0.14 255.255.255.248
duplex auto
speed auto
!
interface Loopback 0
ip address 11.1.0.1 255.255.255.255
!
!
!
!
!
!
!
!
!
!
!
!
!
router bgp 64512
bgp confederation identifier 100
bgp log-neighbor-changes
neighbor 11.1.0.2 remote-as 64512
neighbor 11.1.0.2 update-source Loopback 0
!
address-family ipv4
network 20.1.0.0 mask 255.255.0.0
neighbor 11.1.0.2 activate
neighbor 11.1.0.2 next-hop-self
exit-address-family
!
!
!
!
router ospf 20
router-id 11.1.0.1
network 11.1.0.1 0.0.0.0 area 0
network 12.1.0.0 0.0.0.3 area 0
!
!
!
!
!
ip route 20.1.0.0 255.255.0.0 Null 0
!
!
!
!
!
ref parameter 75 140
line con 0
line aux 0
line vty 0 4
login
!
!
end
R1#
十、R2
R2#show run
hostname R2
!
!
!
interface Serial 2/0
encapsulation PPP
ip ospf network point-to-point
ip address 12.1.0.2 255.255.255.252
!
interface Serial 3/0
encapsulation PPP
ip ospf network point-to-point
ip address 23.1.0.1 255.255.255.252
!
!
interface GigabitEthernet 0/0
ip address 30.1.0.6 255.255.255.248
duplex auto
speed auto
!
interface GigabitEthernet 0/1
ip address 30.1.0.14 255.255.255.248
duplex auto
speed auto
!
interface Loopback 0
ip address 11.1.0.2 255.255.255.255
!
!
!
router bgp 64512
bgp confederation identifier 100
bgp confederation peers 64523
bgp log-neighbor-changes
neighbor 11.1.0.1 remote-as 64512
neighbor 11.1.0.1 update-source Loopback 0
neighbor 11.1.0.3 remote-as 64523
neighbor 11.1.0.3 ebgp-multihop 255
!
address-family ipv4
network 30.1.0.0 mask 255.255.0.0
neighbor 11.1.0.1 activate
neighbor 11.1.0.1 next-hop-self
neighbor 11.1.0.3 activate
neighbor 11.1.0.3 next-hop-self
exit-address-family
!
!
!
!
router ospf 20
router-id 11.1.0.2
network 11.1.0.2 0.0.0.0 area 0
network 12.1.0.0 0.0.0.3 area 0
network 23.1.0.0 0.0.0.3 area 0
!
!
!
!
!
ip route 30.1.0.0 255.255.0.0 Null 0
!
end
R2#
十一、R3
R3#show run
hostname R3
!
interface Serial 3/0
encapsulation PPP
ip ospf network point-to-point
ip address 23.1.0.2 255.255.255.252
clock rate 64000
traffic-shape rate 2000000 40000 40000 1000
!
interface GigabitEthernet 0/0
ip address 40.1.0.6 255.255.255.248
duplex auto
speed auto
rate-limit input 10000000 1000000 2000000 conform-action drop exceed-action drop
!
interface GigabitEthernet 0/1
ip address 40.1.0.14 255.255.255.248
duplex auto
speed auto
!
interface Loopback 0
ip address 11.1.0.3 255.255.255.255
!
!
!
!
!
!
router bgp 64523
bgp confederation identifier 100
bgp confederation peers 64512
bgp log-neighbor-changes
neighbor 11.1.0.2 remote-as 64512
neighbor 11.1.0.2 update-source Loopback 0
!
address-family ipv4
network 40.1.0.0 mask 255.255.0.0
neighbor 11.1.0.2 activate
neighbor 11.1.0.2 next-hop-self
exit-address-family
!
!
!
!
router ospf 10
!
router ospf 20
router-id 11.1.0.3
redistribute connected metric-type 1 subnets
network 11.1.0.3 0.0.0.0 area 0
network 23.1.0.0 0.0.0.3 area 0
!
!
!
!
!
ip route 40.1.0.0 255.255.0.0 Null 0
!
end
十二、EG1
hostname EG1
!
convert port 1 to lan
convert port 2 to wan
!
ip access-list standard 1
10 permit any
!
ip access-list extended 101
10 permit ip 194.1.0.0 0.0.255.255 192.1.0.0 0.0.255.255
!
ip access-list extended 110
10 deny ip 194.1.0.0 0.0.255.255 192.1.0.0 0.0.255.255
1000 permit ip any any
!
time-range any
periodic Daily 0:00 to 23:59
!
time-range day_time
periodic Daily 6:00 to 18:00
!
time-range night_time
periodic Weekdays 0:00 to 5:59
periodic Daily 18:01 to 23:59
!
time-range unwork_time
periodic Weekdays 0:00 to 7:59
periodic Weekdays 12:00 to 13:00
periodic Weekdays 18:01 to 23:59
!
time-range weekend
periodic Weekend 0:00 to 23:59
!
time-range work
periodic Weekdays 9:00 to 17:00
!
time-range work_time
periodic Weekdays 8:00 to 12:00
periodic Weekdays 13:00 to 18:00
!
time-range working_time
periodic Weekdays 0:00 to 23:59
!
route-auto-choose cernet GigabitEthernet 0/4 40.1.0.6
route-auto-choose cnc GigabitEthernet 0/2 20.1.0.6
route-auto-choose cnii GigabitEthernet 0/3 30.1.0.6
!
!
crypto isakmp policy 1
encryption 3des
authentication pre-share
hash md5
group 2
!
crypto isakmp key 7 0134465023 address 20.1.0.9
crypto ipsec transform-set myset esp-3des esp-md5-hmac
!
crypto map mymap 5 ipsec-isakmp
set peer 20.1.0.9
set transform-set myset
set autoup
match address 101
!
!
flow-control Gi0/4
comment tpl-college
!
channel-tree inbound
no auto-pir enable
!
channel-group root parent null cir 1000000 pir 1000000 pri 4 per-net per-pir 2000 limit 100
channel-group key parent root cir 800000 pir 1000000 pri 3 per-net per-pir 5000 limit 100
channel-group default parent root pir 1000000 pri 3 per-net per-pir 10000 limit 100
channel-default default
!
channel-tree outbound
auto-pir enable root-rate 92 pernet-mode
!
channel-group root parent null cir 1000000 pir 1000000 pri 4 per-net per-cir 25 per-pir 2000 limit 100
channel-group key parent root cir 800000 pir 1000000 pri 3 per-net per-cir 25 per-pir 5000 limit 100
channel-group default parent root pir 1000000 pri 3 per-net per-cir 25 per-pir 10000 limit 100
channel-default default
!
flow-rule 999 time-range any
flow-rule 999 action pass in-channel default out-channel default comment Match_ALL_NON_VPN
flow-rule 998 subscriber VIP time-range any
flow-rule 998 action pass in-channel key out-channel key comment Match_VIP_Group_of_NON_VPN
flow-rule 997 network-group Out_Server time-range any
flow-rule 997 action pass in-channel key out-channel key comment Match_Out_Server_of_NON_VPN
!
flow-control Gi0/2
comment tpl-college
!
channel-tree inbound
no auto-pir enable
!
channel-group root parent null cir 100000000 pir 100000000 pri 4 per-net per-pir 2000 limit 100
channel-group key parent root cir 80000000 pir 100000000 pri 3 per-net per-pir 5000 limit 100
channel-group default parent root pir 100000000 pri 3 per-net per-pir 10000 limit 100
channel-group WEB parent root cir 50000 pir 50000 pri 4 per-net per-pir 1000 limit 100
channel-default default
!
channel-tree outbound
auto-pir enable root-rate 92 pernet-mode
!
channel-group root parent null cir 100000000 pir 100000000 pri 4 per-net per-cir 25 per-pir 2000 limit 100
channel-group key parent root cir 80000000 pir 100000000 pri 3 per-net per-cir 25 per-pir 5000 limit 100
channel-group default parent root pir 100000000 pri 3 per-net per-cir 25 per-pir 10000 limit 100
channel-group WEB parent root cir 50000 pir 50000 pri 4 per-net per-pir 1000 limit 100
channel-default default
!
flow-rule 1 time-range any
flow-rule 1 action pass in-channel WEB out-channel WEB comment WEB
!
flow-control Gi0/3
comment tpl-college
!
channel-tree inbound
no auto-pir enable
!
channel-group root parent null cir 1000000 pir 1000000 pri 4 per-net per-pir 2000 limit 100
channel-group key parent root cir 800000 pir 1000000 pri 3 per-net per-pir 5000 limit 100
channel-group default parent root pir 1000000 pri 3 per-net per-pir 10000 limit 100
channel-default default
!
channel-tree outbound
auto-pir enable root-rate 92 pernet-mode
!
channel-group root parent null cir 1000000 pir 1000000 pri 4 per-net per-cir 25 per-pir 2000 limit 100
channel-group key parent root cir 800000 pir 1000000 pri 3 per-net per-cir 25 per-pir 5000 limit 100
channel-group default parent root pir 1000000 pri 3 per-net per-cir 25 per-pir 10000 limit 100
channel-default default
!
flow-rule 999 time-range any
flow-rule 999 action pass in-channel default out-channel default comment Match_ALL_NON_VPN
flow-rule 998 subscriber VIP time-range any
flow-rule 998 action pass in-channel key out-channel key comment Match_VIP_Group_of_NON_VPN
flow-rule 997 network-group Out_Server time-range any
flow-rule 997 action pass in-channel key out-channel key comment Match_Out_Server_of_NON_VPN
!
enable secret 5 $1$7eyy$wrD70zy8F8x9wtwD
interface GigabitEthernet 0/0
reverse-path
no ip unreachables
no ip redirects
no ip mask-reply
ip address 10.1.0.18 255.255.255.252
ip ospf network point-to-point
ip nat inside
!
interface GigabitEthernet 0/1
ip ospf network point-to-point
!
interface GigabitEthernet 0/2
bandwidth 100000000
nexthop 20.1.0.6
reverse-path
ip address 20.1.0.1 255.255.255.248
crypto map mymap
ip nat outside
flow-policy Gi0/2
!
interface GigabitEthernet 0/3
bandwidth 1000000
nexthop 30.1.0.6
reverse-path
ip address 30.1.0.1 255.255.255.248
ip nat outside
!
interface GigabitEthernet 0/4
bandwidth 1000000
nexthop 40.1.0.6
reverse-path
ip address 40.1.0.1 255.255.255.248
ip nat outside
!
interface Loopback 0
ip address 11.1.0.11 255.255.255.255
!
router ospf 10
router-id 11.1.0.11
graceful-restart
network 10.1.0.16 0.0.0.3 area 0
network 11.1.0.11 0.0.0.0 area 0
default-information originate always metric-type 1
!
ip nat pool nat_pool prefix-length 24
address interface GigabitEthernet 0/2 match interface GigabitEthernet 0/2
address interface GigabitEthernet 0/3 match interface GigabitEthernet 0/3
address interface GigabitEthernet 0/4 match interface GigabitEthernet 0/4
!
ip nat inside source list 110 pool nat_pool overload
!
ip route 0.0.0.0 0.0.0.0 GigabitEthernet 0/2 20.1.0.6
ip route 0.0.0.0 0.0.0.0 GigabitEthernet 0/3 30.1.0.6
ip route 0.0.0.0 0.0.0.0 GigabitEthernet 0/4 40.1.0.6
ip route 192.1.0.0 255.255.0.0 GigabitEthernet 0/2 20.1.0.6
!
!
end
十三、EG2
EG2#show run
hostname EG2
!
convert port 1 to lan
convert port 2 to wan
!
ip access-list standard 1
10 permit any
!
ip access-list extended 101
10 permit ip 192.1.0.0 0.0.255.255 194.1.0.0 0.0.255.255
!
ip access-list extended 110
10 deny ip 192.1.0.0 0.0.255.255 194.1.0.0 0.0.255.255
10000 permit ip any any
!
time-range any
periodic Daily 0:00 to 23:59
!
time-range day_time
periodic Daily 6:00 to 18:00
!
time-range night_time
periodic Weekdays 0:00 to 5:59
periodic Daily 18:01 to 23:59
!
time-range unwork_time
periodic Weekdays 0:00 to 7:59
periodic Weekdays 12:00 to 13:00
periodic Weekdays 18:01 to 23:59
!
time-range weekend
periodic Weekend 0:00 to 23:59
!
time-range work_time
periodic Weekdays 8:00 to 12:00
periodic Weekdays 13:00 to 18:00
!
time-range working_time
periodic Weekdays 0:00 to 23:59
!
route-auto-choose cernet GigabitEthernet 0/4 40.1.0.14
route-auto-choose cnc GigabitEthernet 0/2 20.1.0.14
route-auto-choose cnii GigabitEthernet 0/3 30.1.0.14
!
!
mail-service enable
feedback frequency 60
flow-audit enable
flow-audit intf-rt refresh 1
flow-audit intf-rt storage 10 max
!
crypto isakmp policy 1
encryption 3des
authentication pre-share
hash md5
group 2
!
crypto isakmp key 7 123300015e address 20.1.0.1
crypto ipsec transform-set myset esp-3des esp-md5-hmac
!
crypto map mymap 1 ipsec-isakmp
set peer 20.1.0.1
set transform-set myset
set autoup
match address 101
!
crypto map mymap 5 ipsec-isakmp
set peer 20.1.0.1
set transform-set myset
set autoup
match address 101
specify interface GigabitEthernet 0/1 lan
specify interface GigabitEthernet 0/2 wan
specify interface GigabitEthernet 0/3 wan
!
wids
!
frn
!
flow-control Gi0/2
channel-tree inbound
no auto-pir enable
!
channel-group root parent null cir 1000000 pir 1000000 pri 4 fifo
channel-default root
!
channel-tree outbound
no auto-pir enable
!
channel-group root parent null cir 1000000 pir 1000000 pri 4 fifo
channel-default root
!
!
flow-control Gi0/3
channel-tree inbound
no auto-pir enable
!
channel-group root parent null cir 1000000 pir 1000000 pri 4 fifo
channel-default root
!
channel-tree outbound
no auto-pir enable
!
channel-group root parent null cir 1000000 pir 1000000 pri 4 fifo
channel-default root
!
!
flow-control Gi0/4
channel-tree inbound
no auto-pir enable
!
channel-group root parent null cir 1000000 pir 1000000 pri 4 fifo
channel-default root
!
channel-tree outbound
no auto-pir enable
!
channel-group root parent null cir 1000000 pir 1000000 pri 4 fifo
channel-default root
!
!
enable secret 5 $1$7eyy$wrD70zy8F8x9wtwD
interface GigabitEthernet 0/0
reverse-path
ip address 10.1.0.10 255.255.255.252
ip ospf network point-to-point
ip nat inside
!
interface GigabitEthernet 0/1
reverse-path
no ip unreachables
no ip redirects
no ip mask-reply
ip address 10.1.0.14 255.255.255.252
ip ospf network point-to-point
ip nat inside
!
interface GigabitEthernet 0/2
bandwidth 1000000
nexthop 20.1.0.14
reverse-path
ip address 20.1.0.9 255.255.255.248
crypto map mymap
ip nat outside
!
interface GigabitEthernet 0/3
bandwidth 1000000
nexthop 30.1.0.14
reverse-path
ip address 30.1.0.9 255.255.255.248
ip nat outside
!
interface GigabitEthernet 0/4
bandwidth 1000000
nexthop 40.1.0.14
reverse-path
ip address 40.1.0.9 255.255.255.248
ip nat outside
!
interface Loopback 0
ip address 11.1.0.12 255.255.255.255
!
interface SSLVPN 0
!
interface SSLVPN 1
!
router ospf 10
router-id 11.1.0.12
graceful-restart
network 10.1.0.8 0.0.0.3 area 0
network 10.1.0.12 0.0.0.3 area 0
network 11.1.0.12 0.0.0.0 area 0
default-information originate always metric-type 1
!
ip nat pool nat_pool prefix-length 24
address interface GigabitEthernet 0/2 match interface GigabitEthernet 0/2
address interface GigabitEthernet 0/3 match interface GigabitEthernet 0/3
address interface GigabitEthernet 0/4 match interface GigabitEthernet 0/4
!
ip nat inside source list 110 pool nat_pool overload
!
ip route 0.0.0.0 0.0.0.0 GigabitEthernet 0/2 20.1.0.14
ip route 0.0.0.0 0.0.0.0 GigabitEthernet 0/3 30.1.0.14
ip route 0.0.0.0 0.0.0.0 GigabitEthernet 0/4 40.1.0.14
ip route 194.1.0.0 255.255.0.0 GigabitEthernet 0/2 20.1.0.14
!
总结
提示:主要是看关键命令不懂就私信。