核心h3一
sysname SHDXYQB4-108-C-04_C-05-ASW-S6900-M1-01U34 |
# |
clock timezone UTC+8 add 08:00:00 |
clock protocol ntp |
# |
ip vpn-instance NET-manage |
route-distinguisher 1:1 |
description NET-manage |
# |
irf mac-address persistent timer |
irf auto-update enable |
undo irf link-delay |
irf member 1 priority 1 |
# |
link-aggregation global load-sharing mode destination-ip source-ip destination-port source-port |
# |
ip ttl-expires enable |
# |
max-ecmp-num 64 |
ip load-sharing mode per-flow dest-ip src-ip ip-pro dest-port src-port global |
# |
dhcp enable |
# |
lldp global enable |
lldp global tlv-enable basic-tlv management-address-tlv 172.16.30.3 |
# |
burst-mode enable |
# |
password-recovery enable |
# |
vlan 1 |
# |
vlan 300 to 302 |
# |
stp region-configuration |
region-name ctyun |
revision-level 255 |
instance 1 vlan 1 to 4094 |
active region-configuration |
# |
stp bpdu-protection |
stp port shutdown permanent |
stp global enable |
# |
monitor-link group 1 |
downlink up-delay 10 |
# |
interface Bridge-Aggregation1 |
description uT:SHDXYQB4-108-C-04_C-05-CSW-RGS6250-M1_M2-01U40.AGG59 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 200 to 209 300 to 309 500 to 3999 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 1 |
undo stp enable |
stp port bpdu-filter enable |
# |
interface Bridge-Aggregation12 |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.bond1 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 301 to 302 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 12 |
stp edged-port |
stp port bpdu-protection enable |
port monitor-link group 1 downlink |
# |
interface Bridge-Aggregation13 |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.bond1 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 302 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 13 |
stp edged-port |
stp port bpdu-protection enable |
port monitor-link group 1 downlink |
# |
interface Bridge-Aggregation14 |
description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.bond1 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 302 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 14 |
stp edged-port |
stp port bpdu-protection enable |
port monitor-link group 1 downlink |
# |
interface Bridge-Aggregation15 |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.bond1 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 302 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 15 |
stp edged-port |
stp port bpdu-protection enable |
port monitor-link group 1 downlink |
# |
interface Bridge-Aggregation34 |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U15.bond2 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 300 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 34 |
stp edged-port |
stp port bpdu-protection enable |
port monitor-link group 1 downlink |
# |
interface Bridge-Aggregation35 |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.bond2 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 300 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 35 |
stp edged-port |
stp port bpdu-protection enable |
port monitor-link group 1 downlink |
# |
interface Bridge-Aggregation36 |
description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.bond2 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 300 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 36 |
stp edged-port |
stp port bpdu-protection enable |
port monitor-link group 1 downlink |
# |
interface Bridge-Aggregation37 |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.bond2 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 300 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 37 |
stp edged-port |
stp port bpdu-protection enable |
port monitor-link group 1 downlink |
# |
interface Bridge-Aggregation1024 |
description pT:SHDXYQB4-108-C-04_C-05-A1P1-ASW-S6900-M2-01U34:172.16.30.4.HundredGigE1/0/53_M-LAG_PeerLink |
port link-type trunk |
undo port trunk permit vlan 1 |
link-aggregation mode dynamic |
port m-lag peer-link 1 |
# |
interface Route-Aggregation1023 |
description For_DAD_Keepalive |
ip address 1.1.1.1 255.255.255.0 |
link-aggregation mode dynamic |
# |
interface NULL0 |
# |
interface FortyGigE1/0/49 |
port link-mode bridge |
description uT:SHDXYQB4-108-C-04-CSW-RGS6250-01U40:172.16.30.1.HundredGigabitEthernet0/49 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 200 to 209 300 to 309 500 to 3999 |
port monitor-link group 1 uplink |
port link-aggregation group 1 |
# |
interface FortyGigE1/0/50 |
port link-mode bridge |
description uT:SHDXYQB4-108-C-05-CSW-RGS6250-01U40:172.16.30.2.HundredGigabitEthernet0/49 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 200 to 209 300 to 309 500 to 3999 |
port monitor-link group 1 uplink |
port link-aggregation group 1 |
# |
interface FortyGigE1/0/51 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface FortyGigE1/0/52 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface HundredGigE1/0/53 |
port link-mode bridge |
description pT:SHDXYQB4-108-C-04_C-05-ASW-S6900-M2-01U34:172.16.30.4.HundredGigE1/0/53_M-LAG_PeerLink |
port link-type trunk |
undo port trunk permit vlan 1 |
port link-aggregation group 1024 |
# |
interface HundredGigE1/0/54 |
port link-mode bridge |
description pT:SHDXYQB4-108-C-04_C-05-ASW-S6900-M2-01U34:172.16.30.4.HundredGigE1/0/54_M-LAG_PeerLink |
port link-type trunk |
undo port trunk permit vlan 1 |
port link-aggregation group 1024 |
# |
interface M-GigabitEthernet0/0/0 |
description For_NetworkManage |
ip binding vpn-instance NET-manage |
ip address 172.16.30.3 255.255.255.0 |
# |
interface Ten-GigabitEthernet1/0/47 |
port link-mode route |
description pT:SHDXYQB4-108-C-04_C-05-ASW-S6900-M2-01U34:172.16.30.4.Ten-GigabitEthernet1/0/47_M-LAG_KeepAlive |
port link-aggregation group 1023 |
# |
interface Ten-GigabitEthernet1/0/48 |
port link-mode route |
description pT:SHDXYQB4-108-C-04_C-05-ASW-S6900-M2-01U34:172.16.30.4.Ten-GigabitEthernet1/0/48_M-LAG_KeepAlive |
port link-aggregation group 1023 |
# |
interface Ten-GigabitEthernet1/0/1 |
port link-mode bridge |
# |
interface Ten-GigabitEthernet1/0/2 |
port link-mode bridge |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.slot4-0 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 301 to 302 |
broadcast-suppression 10 |
port monitor-link group 1 downlink |
lacp period short |
port link-aggregation group 12 |
# |
interface Ten-GigabitEthernet1/0/3 |
port link-mode bridge |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.slot4-0 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 302 |
broadcast-suppression 10 |
port monitor-link group 1 downlink |
lacp period short |
port link-aggregation group 13 |
# |
interface Ten-GigabitEthernet1/0/4 |
port link-mode bridge |
description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.slot4-0 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 302 |
broadcast-suppression 10 |
port monitor-link group 1 downlink |
lacp period short |
port link-aggregation group 14 |
# |
interface Ten-GigabitEthernet1/0/5 |
port link-mode bridge |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.slot4-0 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 302 |
broadcast-suppression 10 |
port monitor-link group 1 downlink |
lacp period short |
port link-aggregation group 15 |
# |
interface Ten-GigabitEthernet1/0/6 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/7 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/8 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/9 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/10 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/11 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/12 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/13 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/14 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/15 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/16 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/17 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/18 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/19 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/20 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/21 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/22 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/23 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/24 |
port link-mode bridge |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.slot4-1 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 300 |
broadcast-suppression 10 |
port monitor-link group 1 downlink |
lacp period short |
port link-aggregation group 34 |
# |
interface Ten-GigabitEthernet1/0/25 |
port link-mode bridge |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.slot4-1 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 300 |
broadcast-suppression 10 |
port monitor-link group 1 downlink |
lacp period short |
port link-aggregation group 35 |
# |
interface Ten-GigabitEthernet1/0/26 |
port link-mode bridge |
description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.slot4-1 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 300 |
broadcast-suppression 10 |
port monitor-link group 1 downlink |
lacp period short |
port link-aggregation group 36 |
# |
interface Ten-GigabitEthernet1/0/27 |
port link-mode bridge |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.slot4-1 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 300 |
broadcast-suppression 10 |
port monitor-link group 1 downlink |
lacp period short |
port link-aggregation group 37 |
# |
interface Ten-GigabitEthernet1/0/28 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/29 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/30 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/31 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/32 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/33 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/34 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/35 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/36 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/37 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/38 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/39 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/40 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/41 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/42 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/43 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/44 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/45 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/46 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
m-lag mad exclude interface Route-Aggregation1023 |
m-lag restore-delay 180 |
m-lag role priority 100 |
m-lag system-mac 0001-0001-0001 |
m-lag system-number 1 |
m-lag system-priority 100 |
m-lag keepalive ip destination 1.1.1.2 source 1.1.1.1 |
# |
scheduler logfile size 16 |
# |
line class aux |
user-role network-admin |
# |
line class usb |
user-role network-admin |
# |
line class vty |
user-role network-operator |
# |
line aux 0 |
user-role network-admin |
# |
line vty 0 9 |
authentication-mode scheme |
user-role level-15 |
user-role network-admin |
user-role network-operator |
idle-timeout 10 59 |
# |
line vty 10 63 |
user-role network-operator |
# |
ip route-static vpn-instance NET-manage 0.0.0.0 0 172.16.30.254 |
# |
info-center timestamp loghost iso |
info-center loghost source M-GigabitEthernet0/0/0 |
info-center loghost vpn-instance NET-manage 10.100.1.136 port 5000 facility local4 |
info-center loghost vpn-instance NET-manage 10.100.1.137 port 5000 facility local4 |
# |
snmp-agent |
snmp-agent local-engineid 800063A280A069D913678400000001 |
snmp-agent community read cipher $c$3$LxG0cnqk/Pu+Jy710ljwj3YHM+Okj01TQ9GT3e2fRVue0HQ= acl 2000 |
snmp-agent sys-info version v2c v3 |
snmp-agent target-host trap address udp-domain 10.100.1.136 vpn-instance NET-manage params securityname yundiao*&COC2016 v2c |
snmp-agent target-host trap address udp-domain 10.100.1.137 vpn-instance NET-manage params securityname yundiao*&COC2016 v2c |
snmp-agent trap enable arp |
snmp-agent trap enable radius |
snmp-agent trap enable stp |
snmp-agent trap enable syslog |
snmp-agent trap source M-GigabitEthernet0/0/0 |
# |
ssh server enable |
ssh server acl 2001 |
# |
ntp-service enable |
ntp-service unicast-server 172.16.30.254 vpn-instance NET-manage |
# |
acl basic 2000 |
description For_SNMP_NTP |
rule 10 permit vpn-instance NET-manage source 10.100.1.136 0 |
rule 15 permit vpn-instance NET-manage source 10.100.1.137 0 |
rule 20 permit vpn-instance NET-manage source 172.16.30.254 0 |
rule 1000 deny |
# |
acl basic 2001 |
description For_Login |
rule 10 permit vpn-instance NET-manage source 192.168.0.0 0.0.7.255 |
rule 15 permit vpn-instance NET-manage source 192.168.8.0 0.0.7.255 |
rule 20 permit vpn-instance NET-manage source 192.168.1.0 0.0.0.255 |
rule 25 permit vpn-instance NET-manage source 10.252.134.0 0.0.1.255 |
rule 30 permit vpn-instance NET-manage source 10.254.181.0 0.0.0.255 |
rule 35 permit vpn-instance NET-manage source 10.100.1.128 0.0.0.127 |
rule 40 permit vpn-instance NET-manage source 172.16.30.0 0.0.0.255 |
rule 45 permit vpn-instance NET-manage source 10.30.0.0 0.0.1.255 |
rule 50 permit vpn-instance NET-manage source 10.243.72.0 0.0.0.255 |
rule 1000 deny |
# |
password-control login-attempt 3 exceed lock-time 10 |
# |
radius scheme system |
user-name-format without-domain |
# |
domain system |
# |
aaa session-limit http 64 |
aaa session-limit https 64 |
domain default enable system |
# |
role name level-0 |
description Predefined level-0 role |
# |
role name level-1 |
description Predefined level-1 role |
# |
role name level-2 |
description Predefined level-2 role |
# |
role name level-3 |
description Predefined level-3 role |
# |
role name level-4 |
description Predefined level-4 role |
# |
role name level-5 |
description Predefined level-5 role |
# |
role name level-6 |
description Predefined level-6 role |
# |
role name level-7 |
description Predefined level-7 role |
# |
role name level-8 |
description Predefined level-8 role |
# |
role name level-9 |
description Predefined level-9 role |
# |
role name level-10 |
description Predefined level-10 role |
# |
role name level-11 |
description Predefined level-11 role |
# |
role name level-12 |
description Predefined level-12 role |
# |
role name level-13 |
description Predefined level-13 role |
# |
role name level-14 |
description Predefined level-14 role |
# |
user-group system |
# |
local-user admin class manage |
password hash $h$6$FY8SKcM3uwGwUCsZ$pIcy8xZXaqjOs/k9faqSF8Ca5TnUS7TbRNBBAwS2PoZnfO4sknLbB/QcscYmUHXQykNoPy1VBLI8wFwON5Zdjg== |
service-type ssh |
authorization-attribute idle-cut 10 |
authorization-attribute user-role level-15 |
authorization-attribute user-role network-admin |
authorization-attribute user-role network-operator |
# |
local-user shixun class manage |
password hash $h$6$dmcpBV3yTWEENpIs$SgnMVx3Ql8XgmdrR/dS1Pd4tIB5YvezQe++bAet4kySDaWzQyrVNzWqgrIsW2ry3H+WhIqQr2at50GRhj+juiQ== |
service-type http ssh terminal |
authorization-attribute idle-cut 10 |
authorization-attribute user-role level-15 |
authorization-attribute user-role network-operator |
# |
security-enhanced level 1 |
# |
netconf soap http enable |
netconf soap http acl 2001 |
netconf ssh server enable |
# |
return |
核心h3二
sysname SHDXYQB4-108-C-04_C-05-ASW-S6900-M2-01U34 |
# |
clock timezone UTC+8 add 08:00:00 |
clock protocol ntp |
# |
ip vpn-instance NET-manage |
route-distinguisher 1:1 |
description NET-manage |
# |
irf mac-address persistent timer |
irf auto-update enable |
undo irf link-delay |
irf member 1 priority 1 |
# |
link-aggregation global load-sharing mode destination-ip source-ip destination-port source-port |
# |
ip ttl-expires enable |
# |
max-ecmp-num 64 |
ip load-sharing mode per-flow dest-ip src-ip ip-pro dest-port src-port global |
# |
dhcp enable |
# |
lldp global enable |
lldp global tlv-enable basic-tlv management-address-tlv 172.16.30.4 |
# |
burst-mode enable |
# |
password-recovery enable |
# |
vlan 1 |
# |
vlan 300 to 302 |
# |
stp region-configuration |
region-name ctyun |
revision-level 255 |
instance 1 vlan 1 to 4094 |
active region-configuration |
# |
stp bpdu-protection |
stp port shutdown permanent |
stp global enable |
# |
monitor-link group 1 |
downlink up-delay 10 |
# |
interface Bridge-Aggregation1 |
description uT:SHDXYQB4-108-C-04_C-05-CSW-RGS6250-M1_M2-01U40.AGG59 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 200 to 209 300 to 309 500 to 3999 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 1 |
undo stp enable |
stp port bpdu-filter enable |
# |
interface Bridge-Aggregation12 |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.bond1 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 301 to 302 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 12 |
stp edged-port |
stp port bpdu-protection enable |
port monitor-link group 1 downlink |
# |
interface Bridge-Aggregation13 |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.bond1 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 302 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 13 |
stp edged-port |
stp port bpdu-protection enable |
port monitor-link group 1 downlink |
# |
interface Bridge-Aggregation14 |
description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.bond1 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 302 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 14 |
stp edged-port |
stp port bpdu-protection enable |
port monitor-link group 1 downlink |
# |
interface Bridge-Aggregation15 |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.bond1 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 302 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 15 |
stp edged-port |
stp port bpdu-protection enable |
port monitor-link group 1 downlink |
# |
interface Bridge-Aggregation34 |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U15.bond2 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 300 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 34 |
stp edged-port |
stp port bpdu-protection enable |
port monitor-link group 1 downlink |
# |
interface Bridge-Aggregation35 |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.bond2 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 300 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 35 |
stp edged-port |
stp port bpdu-protection enable |
port monitor-link group 1 downlink |
# |
interface Bridge-Aggregation36 |
description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.bond2 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 300 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 36 |
stp edged-port |
stp port bpdu-protection enable |
port monitor-link group 1 downlink |
# |
interface Bridge-Aggregation37 |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.bond2 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 300 |
jumboframe enable 9216 |
link-aggregation mode dynamic |
port m-lag group 37 |
stp edged-port |
stp port bpdu-protection enable |
port monitor-link group 1 downlink |
# |
interface Bridge-Aggregation1024 |
description pT:SHDXYQB4-108-C-04_C-05-A1P1-ASW-S6900-M2-01U34:172.16.30.3.HundredGigE1/0/53_M-LAG_PeerLink |
port link-type trunk |
undo port trunk permit vlan 1 |
link-aggregation mode dynamic |
port m-lag peer-link 1 |
# |
interface Route-Aggregation1023 |
description For_DAD_Keepalive |
ip address 1.1.1.2 255.255.255.0 |
link-aggregation mode dynamic |
# |
interface NULL0 |
# |
interface FortyGigE1/0/49 |
port link-mode bridge |
description uT:SHDXYQB4-108-C-04-CSW-RGS6250-01U40:172.16.30.1.HundredGigabitEthernet0/50 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 200 to 209 300 to 309 500 to 3999 |
port monitor-link group 1 uplink |
port link-aggregation group 1 |
# |
interface FortyGigE1/0/50 |
port link-mode bridge |
description uT:SHDXYQB4-108-C-05-CSW-RGS6250-01U40:172.16.30.2.HundredGigabitEthernet0/50 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 200 to 209 300 to 309 500 to 3999 |
port monitor-link group 1 uplink |
port link-aggregation group 1 |
# |
interface FortyGigE1/0/51 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface FortyGigE1/0/52 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface HundredGigE1/0/53 |
port link-mode bridge |
description pT:SHDXYQB4-108-C-04_C-05-ASW-S6900-M1-01U34:172.16.30.3.HundredGigE1/0/53_M-LAG_PeerLink |
port link-type trunk |
undo port trunk permit vlan 1 |
port link-aggregation group 1024 |
# |
interface HundredGigE1/0/54 |
port link-mode bridge |
description pT:SHDXYQB4-108-C-04_C-05-ASW-S6900-M1-01U34:172.16.30.3.HundredGigE1/0/54_M-LAG_PeerLink |
port link-type trunk |
undo port trunk permit vlan 1 |
port link-aggregation group 1024 |
# |
interface M-GigabitEthernet0/0/0 |
ip binding vpn-instance NET-manage |
ip address 172.16.30.4 255.255.255.0 |
# |
interface Ten-GigabitEthernet1/0/47 |
port link-mode route |
description pT:SHDXYQB4-108-C-04_C-05-ASW-S6900-M1-01U34:172.16.30.3.Ten-GigabitEthernet1/0/47_M-LAG_KeepAlive |
port link-aggregation group 1023 |
# |
interface Ten-GigabitEthernet1/0/48 |
port link-mode route |
description pT:SHDXYQB4-108-C-04_C-05-ASW-S6900-M1-01U34:172.16.30.3.Ten-GigabitEthernet1/0/48_M-LAG_KeepAlive |
port link-aggregation group 1023 |
# |
interface Ten-GigabitEthernet1/0/1 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/2 |
port link-mode bridge |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.slot8-0 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 301 to 302 |
broadcast-suppression 10 |
port monitor-link group 1 downlink |
lacp period short |
port link-aggregation group 12 |
# |
interface Ten-GigabitEthernet1/0/3 |
port link-mode bridge |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.slot8-0 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 302 |
broadcast-suppression 10 |
port monitor-link group 1 downlink |
lacp period short |
port link-aggregation group 13 |
# |
interface Ten-GigabitEthernet1/0/4 |
port link-mode bridge |
description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.slot8-0 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 302 |
broadcast-suppression 10 |
port monitor-link group 1 downlink |
lacp period short |
port link-aggregation group 14 |
# |
interface Ten-GigabitEthernet1/0/5 |
port link-mode bridge |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.slot8-0 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 302 |
broadcast-suppression 10 |
port monitor-link group 1 downlink |
lacp period short |
port link-aggregation group 15 |
# |
interface Ten-GigabitEthernet1/0/6 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/7 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/8 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/9 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/10 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/11 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/12 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/13 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/14 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/15 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/16 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/17 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/18 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/19 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/20 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/21 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/22 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/23 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/24 |
port link-mode bridge |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.slot8-1 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 300 |
broadcast-suppression 10 |
port monitor-link group 1 downlink |
lacp period short |
port link-aggregation group 34 |
# |
interface Ten-GigabitEthernet1/0/25 |
port link-mode bridge |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.slot8-1 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 300 |
broadcast-suppression 10 |
port monitor-link group 1 downlink |
lacp period short |
port link-aggregation group 35 |
# |
interface Ten-GigabitEthernet1/0/26 |
port link-mode bridge |
description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.slot8-1 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 300 |
broadcast-suppression 10 |
port monitor-link group 1 downlink |
lacp period short |
port link-aggregation group 36 |
# |
interface Ten-GigabitEthernet1/0/27 |
port link-mode bridge |
description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.slot8-1 |
port link-type trunk |
undo port trunk permit vlan 1 |
port trunk permit vlan 300 |
broadcast-suppression 10 |
port monitor-link group 1 downlink |
lacp period short |
port link-aggregation group 37 |
# |
interface Ten-GigabitEthernet1/0/28 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/29 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/30 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/31 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/32 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/33 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/34 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/35 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/36 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/37 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/38 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/39 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/40 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/41 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/42 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/43 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/44 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/45 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
interface Ten-GigabitEthernet1/0/46 |
port link-mode bridge |
description NO-USE |
shutdown |
# |
m-lag mad exclude interface Route-Aggregation1023 |
m-lag restore-delay 180 |
m-lag role priority 150 |
m-lag system-mac 0001-0001-0001 |
m-lag system-number 2 |
m-lag system-priority 100 |
m-lag keepalive ip destination 1.1.1.1 source 1.1.1.2 |
# |
scheduler logfile size 16 |
# |
line class aux |
user-role network-admin |
# |
line class usb |
user-role network-admin |
# |
line class vty |
user-role network-operator |
# |
line aux 0 |
user-role network-admin |
# |
line vty 0 9 |
authentication-mode scheme |
user-role level-15 |
user-role network-admin |
user-role network-operator |
idle-timeout 10 59 |
# |
line vty 10 63 |
user-role network-operator |
# |
ip route-static vpn-instance NET-manage 0.0.0.0 0 172.16.30.254 |
# |
info-center timestamp loghost iso |
info-center loghost source M-GigabitEthernet0/0/0 |
info-center loghost vpn-instance NET-manage 10.100.1.136 port 5000 facility local4 |
info-center loghost vpn-instance NET-manage 10.100.1.137 port 5000 facility local4 |
# |
snmp-agent |
snmp-agent local-engineid 800063A280A069D913562C00000001 |
snmp-agent community read cipher $c$3$8e+fw/dbr0/wvq1YTkpHTklWYu5djeIUAGRW5BIFTJqrRFY= acl 2000 |
snmp-agent sys-info version v2c v3 |
snmp-agent target-host trap address udp-domain 10.100.1.136 vpn-instance NET-manage params securityname yundiao*&COC2016 v2c |
snmp-agent target-host trap address udp-domain 10.100.1.137 vpn-instance NET-manage params securityname yundiao*&COC2016 v2c |
snmp-agent trap enable arp |
snmp-agent trap enable radius |
snmp-agent trap enable stp |
snmp-agent trap enable syslog |
snmp-agent trap source M-GigabitEthernet0/0/0 |
# |
ssh server enable |
ssh server acl 2001 |
# |
ntp-service enable |
ntp-service source M-GigabitEthernet0/0/0 |
ntp-service unicast-server 172.16.30.254 vpn-instance NET-manage |
# |
acl basic 2000 |
description For_SNMP_NTP |
rule 10 permit vpn-instance NET-manage source 10.100.1.136 0 |
rule 15 permit vpn-instance NET-manage source 10.100.1.137 0 |
rule 20 permit vpn-instance NET-manage source 172.16.30.254 0 |
rule 1000 deny |
# |
acl basic 2001 |
description For_Login |
rule 10 permit vpn-instance NET-manage source 192.168.0.0 0.0.7.255 |
rule 15 permit vpn-instance NET-manage source 192.168.8.0 0.0.7.255 |
rule 20 permit vpn-instance NET-manage source 192.168.1.0 0.0.0.255 |
rule 25 permit vpn-instance NET-manage source 10.252.134.0 0.0.1.255 |
rule 30 permit vpn-instance NET-manage source 10.254.181.0 0.0.0.255 |
rule 35 permit vpn-instance NET-manage source 10.100.1.128 0.0.0.127 |
rule 40 permit vpn-instance NET-manage source 172.16.30.0 0.0.0.255 |
rule 45 permit vpn-instance NET-manage source 10.30.0.0 0.0.1.255 |
rule 50 permit vpn-instance NET-manage source 10.243.72.0 0.0.0.255 |
rule 1000 deny |
# |
password-control login-attempt 3 exceed lock-time 10 |
# |
radius scheme system |
user-name-format without-domain |
# |
domain system |
# |
aaa session-limit http 64 |
aaa session-limit https 64 |
domain default enable system |
# |
role name level-0 |
description Predefined level-0 role |
# |
role name level-1 |
description Predefined level-1 role |
# |
role name level-2 |
description Predefined level-2 role |
# |
role name level-3 |
description Predefined level-3 role |
# |
role name level-4 |
description Predefined level-4 role |
# |
role name level-5 |
description Predefined level-5 role |
# |
role name level-6 |
description Predefined level-6 role |
# |
role name level-7 |
description Predefined level-7 role |
# |
role name level-8 |
description Predefined level-8 role |
# |
role name level-9 |
description Predefined level-9 role |
# |
role name level-10 |
description Predefined level-10 role |
# |
role name level-11 |
description Predefined level-11 role |
# |
role name level-12 |
description Predefined level-12 role |
# |
role name level-13 |
description Predefined level-13 role |
# |
role name level-14 |
description Predefined level-14 role |
# |
user-group system |
# |
local-user admin class manage |
password hash $h$6$mRyG+4BruRgs5d70$ZVnWtJjULkdBGvkzXfOCJQvxlL4PX3LJX9w38godB6jVbAATg8ems7nAB1dxkZPMZ0XmKvAD3mI8KeWvujMsvw== |
service-type ssh |
authorization-attribute idle-cut 10 |
authorization-attribute user-role level-15 |
authorization-attribute user-role network-admin |
authorization-attribute user-role network-operator |
# |
local-user shixun class manage |
password hash $h$6$WsRrHezotwuwWL0C$DylusMzehpIBXu8Nkp1ArVDOLW7DV+8CrjxT/S1ybQ3mn3zUVvlHTbx7NgeZm4oCVdDOPg47eL0hjv8tDd770w== |
service-type http ssh terminal |
authorization-attribute idle-cut 10 |
authorization-attribute user-role level-15 |
authorization-attribute user-role network-operator |
# |
security-enhanced level 1 |
# |
netconf soap http enable |
netconf soap http acl 2001 |
netconf ssh server enable |
# |
return |
公共配置
# |
max-ecmp-num 64 |
# |
ip vpn-instance NET-manage |
route-distinguisher 1:1 |
description For_NetworkManage |
quit |
# |
interface M-GigabitEthernet 0/0/0 |
ip binding vpn-instance NET-manage |
description For_NetworkManage |
undo dhcp client identifier |
ip address <mgmt_ip> <mgmt_mask> |
quit |
# |
ip route-static vpn-instance NET-manage 0.0.0.0 0 <mgmt_gw> preference 1 |
# |
lldp global enable |
lldp global tlv-enable basic-tlv management-address-tlv interface M-GigabitEthernet0/0/0 |
# |
################################################## snmp acl |
# |
acl basic 2000 |
description For_SNMP |
rule 10 permit vpn-instance NET-manage source <Yundiao_CN2_1> 0 |
rule 15 permit vpn-instance NET-manage source <Yundiao_CN2_2> 0 |
rule 20 permit vpn-instance NET-manage source <YF_jiankong> 0 |
rule 1000 deny vpn-instance NET-manage |
quit |
# |
################################################## ssh acl |
#### 放行region集群CN2和网络设备带外地址段 #### |
# |
acl basic 2001 |
description For_Login |
rule 10 permit vpn-instance NET-manage source 192.168.0.0 0.0.7.255 |
rule 15 permit vpn-instance NET-manage source 192.168.8.0 0.0.7.255 |
rule 20 permit vpn-instance NET-manage source 192.168.120.0 0.0.0.255 |
rule 25 permit vpn-instance NET-manage source 10.252.134.0 0.0.1.255 |
rule 30 permit vpn-instance NET-manage source 10.254.181.0 0.0.0.255 |
rule 35 permit vpn-instance NET-manage source <Region_CN2_segment_1> #Region_CN2_segment_1#ip_wild_mask |
rule 40 permit vpn-instance NET-manage source <Region_mgmt_segment_1> #Region_mgmt_segment_1#ip_wild_mask |
rule 45 permit vpn-instance NET-manage source <Region_CN2_segment_2> #Region_CN2_segment_2#ip_wild_mask |
rule 50 permit vpn-instance NET-manage source <Region_mgmt_segment_2> #Region_mgmt_segment_2#ip_wild_mask |
rule 55 permit vpn-instance NET-manage source <Region_CN2_segment_3> #Region_CN2_segment_3#ip_wild_mask |
rule 60 permit vpn-instance NET-manage source <Region_mgmt_segment_3> #Region_mgmt_segment_3#ip_wild_mask |
rule 1000 deny vpn-instance NET-manage |
quit |
# |
################################################## 日志 |
# |
info-center enable |
info-center timestamp loghost iso |
info-center loghost vpn-instance NET-manage <Yundiao_CN2_1> port 5000 facility local4 |
info-center loghost vpn-instance NET-manage <Yundiao_CN2_2> port 5000 facility local4 |
info-center loghost vpn-instance NET-manage <YF_jiankong> |
info-center loghost source M-GigabitEthernet 0/0/0 |
# |
################################################## clock和ntp |
# |
clock timezone beijing add 08:00:00 |
clock protocol ntp |
# |
ntp-service enable |
ntp-service source M-GigabitEthernet 0/0/0 |
ntp-service unicast-server <Yundiao_CN2_1> vpn-instance NET-manage priority |
ntp-service unicast-server <Yundiao_CN2_2> vpn-instance NET-manage priority |
# |
################################################## snmp |
# |
snmp-agent |
snmp-agent community read simple yundiao*&COC2016 acl 2000 |
snmp-agent sys-info version v2c v3 |
snmp-agent target-host trap address udp-domain <Yundiao_CN2_1> vpn-instance NET-manage params securityname yundiao*&COC2016 v2c |
snmp-agent target-host trap address udp-domain <Yundiao_CN2_2> vpn-instance NET-manage params securityname yundiao*&COC2016 v2c |
snmp-agent target-host trap address udp-domain <YF_jiankong> vpn-instance NET-manage params securityname yundiao*&COC2016 v2c |
snmp-agent trap enable |
snmp-agent trap source M-GigabitEthernet 0/0/0 |
# |
################################################## ssh和netconf |
# |
undo ftp server enable |
undo telnet server enable |
ssh server enable |
ssh server acl 2001 |
# |
netconf ssh server enable |
netconf soap http enable |
netconf soap http acl 2001 |
aaa session-limit http 64 |
aaa session-limit https 64 |
# |
ip ttl-expires enable |
# |
undo stp global enable |
# |
################################################## 创建用户 |
# |
undo local-user h3c class manage |
# |
local-user openstackadmin class manage |
password simple Pr@ject2018 |
service-type ssh http terminal |
authorization-attribute user-role level-15 |
undo authorization-attribute user-role network-operator |
authorization-attribute idle-cut 10 |
quit |
# |
local-user AutoDevOps class manage |
####运维验收自动化账号,咨询运维部信息 |
!!!password simple {咨询COC确认} |
service-type ssh terminal |
authorization-attribute user-role level-15 |
undo authorization-attribute user-role network-operator |
authorization-attribute idle-cut 10 |
quit |
# |
local-user COC_operator class manage |
password simple Pr@ject2018 |
service-type ssh terminal |
authorization-attribute user-role level-15 |
undo authorization-attribute user-role network-operator |
authorization-attribute idle-cut 10 |
quit |
# |
local-user COC_monitor class manage |
password-control length 9 |
password simple Pr@ject94 |
service-type ssh terminal |
authorization-attribute user-role level-1 |
undo authorization-attribute user-role network-operator |
authorization-attribute idle-cut 10 |
quit |
# |
local-user yundiao_read class manage |
password simple yundiao*&COC2016 |
service-type ssh terminal |
authorization-attribute user-role level-1 |
undo authorization-attribute user-role network-operator |
authorization-attribute idle-cut 10 |
quit |
# |
################################################## vty |
# |
line vty 0 9 |
authentication-mode scheme |
user-role level-15 |
user-role network-admin |
user-role network-operator |
protocol inbound ssh |
idle-timeout 10 0 |
# |