网络运维network总结知识五

网络运维network总结知识

01: 计算机网络 、 网络通信参考模型 、 交换机命令行 、 交换机命令行配置 、 数据链路层解析

02: VLAN技术及应用 、 TRUNK 、 网络层解析
03: OSPF 、 传输层 、 ACL
04: NAT 、 VRRP
05: 综合项目 、 网络升级


综合项目 、 网络升级


综合网络搭建

问题

现有网络问题分析:

接入层交换机只与同一个三层交换机相连,存在单点故障而影响网络通信。 互联网连接单一服务商 现有网络需求:

随着企业发展,为了保证网络的高可用性,需要使用很多的冗余技术 保证局域网络不会因为线路故障而导致的网络故障
保证客户端机器不会因为使用单一网关而出现的单点失败 保证到互联网的高可用接入使用冗余互联网连接

方案

基于项目的需求,需要用到如下技术:

OSPF路由协议:实现网络路径的自动学习 VRRP:实现网关冗余 重新规划后的网络拓扑如图-1:

在这里插入图片描述

图-1

步骤

实现此案例需要按照如下步骤进行,为了配置过程中不被弹出信息干扰,可以关闭信息提示

一:S3700交换机配置

SW1配置
<Huawei>system-view
[Huawei]vlan batch 10 20 30 40
[Huawei]port-group 1
[Huawei-port-group-1]group-member Ethernet 0/0/1 to Ethernet 0/0/2
[Huawei-port-group-1]port link-type  trunk
[Huawei-port-group-1]port trunk allow-pass vlan all
[Huawei-port-group-1]quit
[Huawei]interface Ethernet 0/0/5
[Huawei-Ethernet0/0/5] port link-type access
[Huawei-Ethernet0/0/5] port default vlan 10
SW2配置
<Huawei>system-view
[Huawei]vlan batch 10 20 30 40
[Huawei]port-group 1
[Huawei-port-group-1]group-member Ethernet 0/0/1 to Ethernet 0/0/2
[Huawei-port-group-1]port link-type  trunk
[Huawei-port-group-1]port trunk allow-pass vlan all
[Huawei-port-group-1]quit
[Huawei]interface Ethernet 0/0/5
[Huawei-Ethernet0/0/5] port link-type access
[Huawei-Ethernet0/0/5] port default vlan 20
SW3配置
<Huawei>system-view
[Huawei]vlan batch 10 20 30 40
[Huawei]port-group 1
[Huawei-port-group-1]group-member Ethernet 0/0/1 to Ethernet 0/0/2
[Huawei-port-group-1]port link-type  trunk
[Huawei-port-group-1]port trunk allow-pass vlan all
[Huawei-port-group-1]quit
[Huawei]interface Ethernet 0/0/5
[Huawei-Ethernet0/0/5] port link-type access
[Huawei-Ethernet0/0/5] port default vlan 30
SW4配置
<Huawei>system-view
[Huawei]vlan batch 10 20 30 40
[Huawei]port-group 1
[Huawei-port-group-1]group-member Ethernet 0/0/1 to Ethernet 0/0/2
[Huawei-port-group-1]port link-type  trunk
[Huawei-port-group-1]port trunk allow-pass vlan all
[Huawei-port-group-1]quit
[Huawei]interface Ethernet 0/0/5
[Huawei-Ethernet0/0/5] port link-type access
[Huawei-Ethernet0/0/5] port default vlan 40

二:S5700交换机配置

MS1配置
<Huawei>system-view
[Huawei]vlan batch 10 20 30 40 50 60
[Huawei]port-group 1
[Huawei-port-group-1]group-member GigabitEthernet 0/0/1 to GigabitEthernet 0/0/5
[Huawei-port-group-1]port link-type  trunk
[Huawei-port-group-1]port trunk allow-pass vlan all
[Huawei-port-group-1]quit
[Huawei]interface Vlanif 10
[Huawei-Vlanif10]ip address 192.168.10.252 24
[Huawei-Vlanif10]vrrp vrid 1 virtual-ip 192.168.10.254
[Huawei-Vlanif10]vrrp vrid 1 priority 110
[Huawei]interface Vlanif 20
[Huawei-Vlanif20]ip address 192.168.20.252 24
[Huawei-Vlanif20]vrrp vrid 2 virtual-ip 192.168.20.254
[Huawei-Vlanif20]vrrp vrid 2 priority 110
[Huawei]interface Vlanif 30
[Huawei-Vlanif30]ip address 192.168.30.252 24
[Huawei-Vlanif30]vrrp vrid 3 virtual-ip 192.168.30.254
[Huawei]interface Vlanif 40
[Huawei-Vlanif40]ip address 192.168.40.252 24
[Huawei-Vlanif40]vrrp vrid 4 virtual-ip 192.168.40.254
[Huawei]interface Vlanif 50
[Huawei-Vlanif50]ip address 192.168.50.2 24
[Huawei]interface GigabitEthernet 0/0/23
[Huawei-GigabitEthernet0/0/23]port link-type access
[Huawei-GigabitEthernet0/0/23]port default vlan 50
[Huawei]interface Vlanif 60
[Huawei-Vlanif60]ip address 192.168.60.2 24
[Huawei]interface GigabitEthernet 0/0/24
[Huawei-GigabitEthernet0/0/24]port link-type access
[Huawei-GigabitEthernet0/0/24]port default vlan 60
[Huawei]ospf    
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.10.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 192.168.20.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 192.168.30.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 192.168.40.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 192.168.50.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 192.168.60.0 0.0.0.255
MS2配置
<Huawei>system-view
[Huawei]vlan batch 10 20 30 40 70 80
[Huawei]port-group 1
[Huawei-port-group-1]group-member GigabitEthernet 0/0/1 to GigabitEthernet 0/0/5
[Huawei-port-group-1]port link-type  trunk
[Huawei-port-group-1]port trunk allow-pass vlan all
[Huawei-port-group-1]quit
[Huawei]interface Vlanif 10
[Huawei-Vlanif10]ip address 192.168.10.253 24
[Huawei-Vlanif10]vrrp vrid 1 virtual-ip 192.168.10.254
[Huawei]interface Vlanif 20
[Huawei-Vlanif20]ip address 192.168.20.253 24
[Huawei-Vlanif20]vrrp vrid 2 virtual-ip 192.168.20.254
[Huawei]interface Vlanif 30
[Huawei-Vlanif30]ip address 192.168.30.253 24
[Huawei-Vlanif30]vrrp vrid 3 virtual-ip 192.168.30.254
[Huawei-Vlanif20]vrrp vrid 3 priority 110
[Huawei]interface Vlanif 40
[Huawei-Vlanif40]ip address 192.168.40.253 24
[Huawei-Vlanif40]vrrp vrid 4 virtual-ip 192.168.40.254
[Huawei-Vlanif20]vrrp vrid 4 priority 110
[Huawei]interface Vlanif 70
[Huawei-Vlanif70]ip address 192.168.70.2 24
[Huawei]interface GigabitEthernet 0/0/23
[Huawei-GigabitEthernet0/0/23]port link-type access
[Huawei-GigabitEthernet0/0/23]port default vlan 70
[Huawei]interface Vlanif 80
[Huawei-Vlanif80]ip address 192.168.80.2 24
[Huawei]interface GigabitEthernet 0/0/24
[Huawei-GigabitEthernet0/0/24]port link-type access
[Huawei-GigabitEthernet0/0/24]port default vlan 80
[Huawei]ospf    
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.10.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 192.168.20.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 192.168.30.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 192.168.40.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 192.168.70.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 192.168.80.0 0.0.0.255
然后测试目前网络是否可以达成全网互通

三:路由器配置

按图-2为路由器与三层交换机相连的接口配置ip

注:50.1表示ip需要配置为192.168.50.1

在这里插入图片描述

图-2

R1
<Huawei>system-view 
[Huawei]acl 2000    
[Huawei-acl-basic-2000]rule permit source any 
[Huawei]interface GigabitEthernet 0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.50.1 24
[Huawei]interface GigabitEthernet 0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 192.168.70.1 24
[Huawei]interface GigabitEthernet 0/0/2
[Huawei-GigabitEthernet0/0/2]ip address 100.0.0.1 8
[Huawei-GigabitEthernet0/0/2]nat outbound 2000
[Huawei-GigabitEthernet0/0/2]quit
[Huawei]ip route-static 0.0.0.0 0 100.0.0.10
[Huawei]ospf
[Huawei-ospf-1]default-route-advertise
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.50.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 192.168.70.0 0.0.0.255
R2
<Huawei>system-view 
[Huawei]acl 2000    
[Huawei-acl-basic-2000]rule permit source any 
[Huawei]interface GigabitEthernet 0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.60.1 24
[Huawei]interface GigabitEthernet 0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 192.168.80.1 24
[Huawei]interface GigabitEthernet 0/0/2
[Huawei-GigabitEthernet0/0/2]ip address 100.0.0.2 8
[Huawei-GigabitEthernet0/0/0]nat outbound 2000
[Huawei-GigabitEthernet0/0/2]quit
[Huawei]ip route-static 0.0.0.0 0 100.0.0.10
[Huawei]ospf
[Huawei-ospf-1]default-route-advertise 
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.60.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 192.168.80.0 0.0.0.255
三层交换机如果看不到从路由器学习来的默认路由就去检查路由器G0/2地址是否配置,之后验证从内网可以访问外网设备,ping通证明项目升级成功

重要的事情说三遍

作为一个为linux奉献一生的码员,很是荣幸和骄傲,这里我总结了一些linux的精华,也就是速成文章,后面还会继续更新,望大家关注,绝对有用!

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值