华三*锐捷M-LAG模拟实验(核)

核心h3一

 sysname SHDXYQB4-108-C-04_C-05-ASW-S6900-M1-01U34
#
 clock timezone UTC+8 add 08:00:00
 clock protocol ntp
#
ip vpn-instance NET-manage
 route-distinguisher 1:1
 description NET-manage
#
 irf mac-address persistent timer
 irf auto-update enable
 undo irf link-delay
 irf member 1 priority 1
#
 link-aggregation global load-sharing mode destination-ip source-ip destination-port source-port 
#
 ip ttl-expires enable
#
 max-ecmp-num 64
 ip load-sharing mode per-flow dest-ip src-ip ip-pro dest-port src-port global
#              
 dhcp enable
#
 lldp global enable
 lldp global tlv-enable basic-tlv management-address-tlv 172.16.30.3
#
 burst-mode enable
#
 password-recovery enable
#
vlan 1
#
vlan 300 to 302
#
stp region-configuration
 region-name ctyun
 revision-level 255
 instance 1 vlan 1 to 4094 
 active region-configuration
#
 stp bpdu-protection
 stp port shutdown permanent
 stp global enable
#              
monitor-link group 1
 downlink up-delay 10
#
interface Bridge-Aggregation1
 description uT:SHDXYQB4-108-C-04_C-05-CSW-RGS6250-M1_M2-01U40.AGG59
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 200 to 209 300 to 309 500 to 3999
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 1
 undo stp enable
 stp port bpdu-filter enable
#
interface Bridge-Aggregation12
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.bond1
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 301 to 302
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 12
 stp edged-port
 stp port bpdu-protection enable
 port monitor-link group 1 downlink
#
interface Bridge-Aggregation13
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.bond1
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 302
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 13
 stp edged-port
 stp port bpdu-protection enable
 port monitor-link group 1 downlink
#
interface Bridge-Aggregation14
 description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.bond1
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 302
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 14
 stp edged-port
 stp port bpdu-protection enable
 port monitor-link group 1 downlink
#
interface Bridge-Aggregation15
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.bond1
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 302
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 15
 stp edged-port
 stp port bpdu-protection enable
 port monitor-link group 1 downlink
#
interface Bridge-Aggregation34
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U15.bond2
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 300
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 34
 stp edged-port
 stp port bpdu-protection enable
 port monitor-link group 1 downlink
#
interface Bridge-Aggregation35
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.bond2
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 300
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 35
 stp edged-port
 stp port bpdu-protection enable
 port monitor-link group 1 downlink
#
interface Bridge-Aggregation36
 description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.bond2
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 300
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 36
 stp edged-port
 stp port bpdu-protection enable
 port monitor-link group 1 downlink
#
interface Bridge-Aggregation37
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.bond2
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 300
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 37
 stp edged-port
 stp port bpdu-protection enable
 port monitor-link group 1 downlink
#
interface Bridge-Aggregation1024
 description pT:SHDXYQB4-108-C-04_C-05-A1P1-ASW-S6900-M2-01U34:172.16.30.4.HundredGigE1/0/53_M-LAG_PeerLink
 port link-type trunk
 undo port trunk permit vlan 1
 link-aggregation mode dynamic
 port m-lag peer-link 1
#
interface Route-Aggregation1023
 description For_DAD_Keepalive
 ip address 1.1.1.1 255.255.255.0
 link-aggregation mode dynamic
#
interface NULL0
#
interface FortyGigE1/0/49
 port link-mode bridge
 description uT:SHDXYQB4-108-C-04-CSW-RGS6250-01U40:172.16.30.1.HundredGigabitEthernet0/49
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 200 to 209 300 to 309 500 to 3999
 port monitor-link group 1 uplink
 port link-aggregation group 1
#
interface FortyGigE1/0/50
 port link-mode bridge
 description uT:SHDXYQB4-108-C-05-CSW-RGS6250-01U40:172.16.30.2.HundredGigabitEthernet0/49
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 200 to 209 300 to 309 500 to 3999
 port monitor-link group 1 uplink
 port link-aggregation group 1
#
interface FortyGigE1/0/51
 port link-mode bridge
 description NO-USE
 shutdown
#
interface FortyGigE1/0/52
 port link-mode bridge
 description NO-USE
 shutdown
#
interface HundredGigE1/0/53
 port link-mode bridge
 description pT:SHDXYQB4-108-C-04_C-05-ASW-S6900-M2-01U34:172.16.30.4.HundredGigE1/0/53_M-LAG_PeerLink
 port link-type trunk
 undo port trunk permit vlan 1
 port link-aggregation group 1024
#
interface HundredGigE1/0/54
 port link-mode bridge
 description pT:SHDXYQB4-108-C-04_C-05-ASW-S6900-M2-01U34:172.16.30.4.HundredGigE1/0/54_M-LAG_PeerLink
 port link-type trunk
 undo port trunk permit vlan 1
 port link-aggregation group 1024
#
interface M-GigabitEthernet0/0/0
 description For_NetworkManage
 ip binding vpn-instance NET-manage
 ip address 172.16.30.3 255.255.255.0
#
interface Ten-GigabitEthernet1/0/47
 port link-mode route
 description pT:SHDXYQB4-108-C-04_C-05-ASW-S6900-M2-01U34:172.16.30.4.Ten-GigabitEthernet1/0/47_M-LAG_KeepAlive
 port link-aggregation group 1023
#
interface Ten-GigabitEthernet1/0/48
 port link-mode route
 description pT:SHDXYQB4-108-C-04_C-05-ASW-S6900-M2-01U34:172.16.30.4.Ten-GigabitEthernet1/0/48_M-LAG_KeepAlive
 port link-aggregation group 1023
#
interface Ten-GigabitEthernet1/0/1
 port link-mode bridge
#              
interface Ten-GigabitEthernet1/0/2
 port link-mode bridge
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.slot4-0
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 301 to 302
 broadcast-suppression 10
 port monitor-link group 1 downlink
 lacp period short
 port link-aggregation group 12
#
interface Ten-GigabitEthernet1/0/3
 port link-mode bridge
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.slot4-0
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 302
 broadcast-suppression 10
 port monitor-link group 1 downlink
 lacp period short
 port link-aggregation group 13
#
interface Ten-GigabitEthernet1/0/4
 port link-mode bridge
 description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.slot4-0
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 302
 broadcast-suppression 10
 port monitor-link group 1 downlink
 lacp period short
 port link-aggregation group 14
#
interface Ten-GigabitEthernet1/0/5
 port link-mode bridge
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.slot4-0
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 302
 broadcast-suppression 10
 port monitor-link group 1 downlink
 lacp period short
 port link-aggregation group 15
#
interface Ten-GigabitEthernet1/0/6
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/7
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/8
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/9
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/10
 port link-mode bridge
 description NO-USE
 shutdown
#              
interface Ten-GigabitEthernet1/0/11
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/12
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/13
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/14
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/15
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/16
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/17
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/18
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/19
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/20
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/21
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/22
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/23
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/24
 port link-mode bridge
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.slot4-1
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 300
 broadcast-suppression 10
 port monitor-link group 1 downlink
 lacp period short
 port link-aggregation group 34
#
interface Ten-GigabitEthernet1/0/25
 port link-mode bridge
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.slot4-1
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 300
 broadcast-suppression 10
 port monitor-link group 1 downlink
 lacp period short
 port link-aggregation group 35
#
interface Ten-GigabitEthernet1/0/26
 port link-mode bridge
 description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.slot4-1
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 300
 broadcast-suppression 10
 port monitor-link group 1 downlink
 lacp period short
 port link-aggregation group 36
#
interface Ten-GigabitEthernet1/0/27
 port link-mode bridge
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.slot4-1
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 300
 broadcast-suppression 10
 port monitor-link group 1 downlink
 lacp period short
 port link-aggregation group 37
#
interface Ten-GigabitEthernet1/0/28
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/29
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/30
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/31
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/32
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/33
 port link-mode bridge
 description NO-USE
 shutdown      
#
interface Ten-GigabitEthernet1/0/34
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/35
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/36
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/37
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/38
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/39
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/40
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/41
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/42
 port link-mode bridge
 description NO-USE
 shutdown
#              
interface Ten-GigabitEthernet1/0/43
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/44
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/45
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/46
 port link-mode bridge
 description NO-USE
 shutdown
#
 m-lag mad exclude interface Route-Aggregation1023
 m-lag restore-delay 180
 m-lag role priority 100
 m-lag system-mac 0001-0001-0001
 m-lag system-number 1
 m-lag system-priority 100
 m-lag keepalive ip destination 1.1.1.2 source 1.1.1.1
#
 scheduler logfile size 16
#
line class aux
 user-role network-admin
#
line class usb
 user-role network-admin
#
line class vty
 user-role network-operator
#
line aux 0
 user-role network-admin
#
line vty 0 9
 authentication-mode scheme
 user-role level-15
 user-role network-admin
 user-role network-operator
 idle-timeout 10 59
#
line vty 10 63
 user-role network-operator
#
 ip route-static vpn-instance NET-manage 0.0.0.0 0 172.16.30.254
#
 info-center timestamp loghost iso
 info-center loghost source M-GigabitEthernet0/0/0
 info-center loghost vpn-instance NET-manage 10.100.1.136 port 5000 facility local4
 info-center loghost vpn-instance NET-manage 10.100.1.137 port 5000 facility local4
#
 snmp-agent
 snmp-agent local-engineid 800063A280A069D913678400000001
 snmp-agent community read cipher $c$3$LxG0cnqk/Pu+Jy710ljwj3YHM+Okj01TQ9GT3e2fRVue0HQ= acl 2000
 snmp-agent sys-info version v2c v3 
 snmp-agent target-host trap address udp-domain 10.100.1.136 vpn-instance NET-manage params securityname yundiao*&COC2016 v2c
 snmp-agent target-host trap address udp-domain 10.100.1.137 vpn-instance NET-manage params securityname yundiao*&COC2016 v2c
 snmp-agent trap enable arp 
 snmp-agent trap enable radius 
 snmp-agent trap enable stp 
 snmp-agent trap enable syslog 
 snmp-agent trap source M-GigabitEthernet0/0/0
#
 ssh server enable
 ssh server acl 2001
#
 ntp-service enable
 ntp-service unicast-server 172.16.30.254 vpn-instance NET-manage
#
acl basic 2000
 description For_SNMP_NTP
 rule 10 permit vpn-instance NET-manage source 10.100.1.136 0
 rule 15 permit vpn-instance NET-manage source 10.100.1.137 0
 rule 20 permit vpn-instance NET-manage source 172.16.30.254 0
 rule 1000 deny
#
acl basic 2001
 description For_Login
 rule 10 permit vpn-instance NET-manage source 192.168.0.0 0.0.7.255
 rule 15 permit vpn-instance NET-manage source 192.168.8.0 0.0.7.255
 rule 20 permit vpn-instance NET-manage source 192.168.1.0 0.0.0.255
 rule 25 permit vpn-instance NET-manage source 10.252.134.0 0.0.1.255
 rule 30 permit vpn-instance NET-manage source 10.254.181.0 0.0.0.255
 rule 35 permit vpn-instance NET-manage source 10.100.1.128 0.0.0.127
 rule 40 permit vpn-instance NET-manage source 172.16.30.0 0.0.0.255
 rule 45 permit vpn-instance NET-manage source 10.30.0.0 0.0.1.255
 rule 50 permit vpn-instance NET-manage source 10.243.72.0 0.0.0.255
 rule 1000 deny
#
 password-control login-attempt 3 exceed lock-time 10
#
radius scheme system
 user-name-format without-domain
#
domain system
#
 aaa session-limit http 64
 aaa session-limit https 64
 domain default enable system
#
role name level-0
 description Predefined level-0 role
#
role name level-1
 description Predefined level-1 role
#
role name level-2
 description Predefined level-2 role
#
role name level-3
 description Predefined level-3 role
#
role name level-4
 description Predefined level-4 role
#
role name level-5
 description Predefined level-5 role
#
role name level-6
 description Predefined level-6 role
#
role name level-7
 description Predefined level-7 role
#
role name level-8
 description Predefined level-8 role
#
role name level-9
 description Predefined level-9 role
#              
role name level-10
 description Predefined level-10 role
#
role name level-11
 description Predefined level-11 role
#
role name level-12
 description Predefined level-12 role
#
role name level-13
 description Predefined level-13 role
#
role name level-14
 description Predefined level-14 role
#
user-group system
#
local-user admin class manage
 password hash $h$6$FY8SKcM3uwGwUCsZ$pIcy8xZXaqjOs/k9faqSF8Ca5TnUS7TbRNBBAwS2PoZnfO4sknLbB/QcscYmUHXQykNoPy1VBLI8wFwON5Zdjg==
 service-type ssh
 authorization-attribute idle-cut 10
 authorization-attribute user-role level-15
 authorization-attribute user-role network-admin
 authorization-attribute user-role network-operator
#
local-user shixun class manage
 password hash $h$6$dmcpBV3yTWEENpIs$SgnMVx3Ql8XgmdrR/dS1Pd4tIB5YvezQe++bAet4kySDaWzQyrVNzWqgrIsW2ry3H+WhIqQr2at50GRhj+juiQ==
 service-type http ssh terminal
 authorization-attribute idle-cut 10
 authorization-attribute user-role level-15
 authorization-attribute user-role network-operator
#
 security-enhanced level 1
#
 netconf soap http enable
 netconf soap http acl 2001
 netconf ssh server enable
#
return

核心h3二

 sysname SHDXYQB4-108-C-04_C-05-ASW-S6900-M2-01U34
#
 clock timezone UTC+8 add 08:00:00
 clock protocol ntp
#
ip vpn-instance NET-manage
 route-distinguisher 1:1
 description NET-manage
#
 irf mac-address persistent timer
 irf auto-update enable
 undo irf link-delay
 irf member 1 priority 1
#
 link-aggregation global load-sharing mode destination-ip source-ip destination-port source-port 
#
 ip ttl-expires enable
#
 max-ecmp-num 64
 ip load-sharing mode per-flow dest-ip src-ip ip-pro dest-port src-port global
#              
 dhcp enable
#
 lldp global enable
 lldp global tlv-enable basic-tlv management-address-tlv 172.16.30.4
#
 burst-mode enable
#
 password-recovery enable
#
vlan 1
#
vlan 300 to 302
#
stp region-configuration
 region-name ctyun
 revision-level 255
 instance 1 vlan 1 to 4094 
 active region-configuration
#
 stp bpdu-protection
 stp port shutdown permanent
 stp global enable
#              
monitor-link group 1
 downlink up-delay 10
#
interface Bridge-Aggregation1
 description uT:SHDXYQB4-108-C-04_C-05-CSW-RGS6250-M1_M2-01U40.AGG59
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 200 to 209 300 to 309 500 to 3999
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 1
 undo stp enable
 stp port bpdu-filter enable
#
interface Bridge-Aggregation12
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.bond1
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 301 to 302
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 12
 stp edged-port
 stp port bpdu-protection enable
 port monitor-link group 1 downlink
#
interface Bridge-Aggregation13
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.bond1
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 302
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 13
 stp edged-port
 stp port bpdu-protection enable
 port monitor-link group 1 downlink
#
interface Bridge-Aggregation14
 description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.bond1
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 302
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 14
 stp edged-port
 stp port bpdu-protection enable
 port monitor-link group 1 downlink
#
interface Bridge-Aggregation15
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.bond1
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 302
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 15
 stp edged-port
 stp port bpdu-protection enable
 port monitor-link group 1 downlink
#
interface Bridge-Aggregation34
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U15.bond2
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 300
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 34
 stp edged-port
 stp port bpdu-protection enable
 port monitor-link group 1 downlink
#
interface Bridge-Aggregation35
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.bond2
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 300
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 35
 stp edged-port
 stp port bpdu-protection enable
 port monitor-link group 1 downlink
#
interface Bridge-Aggregation36
 description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.bond2
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 300
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 36
 stp edged-port
 stp port bpdu-protection enable
 port monitor-link group 1 downlink
#
interface Bridge-Aggregation37
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.bond2
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 300
 jumboframe enable 9216
 link-aggregation mode dynamic
 port m-lag group 37
 stp edged-port
 stp port bpdu-protection enable
 port monitor-link group 1 downlink
#
interface Bridge-Aggregation1024
 description pT:SHDXYQB4-108-C-04_C-05-A1P1-ASW-S6900-M2-01U34:172.16.30.3.HundredGigE1/0/53_M-LAG_PeerLink
 port link-type trunk
 undo port trunk permit vlan 1
 link-aggregation mode dynamic
 port m-lag peer-link 1
#
interface Route-Aggregation1023
 description For_DAD_Keepalive
 ip address 1.1.1.2 255.255.255.0
 link-aggregation mode dynamic
#
interface NULL0
#
interface FortyGigE1/0/49
 port link-mode bridge
 description uT:SHDXYQB4-108-C-04-CSW-RGS6250-01U40:172.16.30.1.HundredGigabitEthernet0/50
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 200 to 209 300 to 309 500 to 3999
 port monitor-link group 1 uplink
 port link-aggregation group 1
#
interface FortyGigE1/0/50
 port link-mode bridge
 description uT:SHDXYQB4-108-C-05-CSW-RGS6250-01U40:172.16.30.2.HundredGigabitEthernet0/50
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 200 to 209 300 to 309 500 to 3999
 port monitor-link group 1 uplink
 port link-aggregation group 1
#
interface FortyGigE1/0/51
 port link-mode bridge
 description NO-USE
 shutdown
#
interface FortyGigE1/0/52
 port link-mode bridge
 description NO-USE
 shutdown
#
interface HundredGigE1/0/53
 port link-mode bridge
 description pT:SHDXYQB4-108-C-04_C-05-ASW-S6900-M1-01U34:172.16.30.3.HundredGigE1/0/53_M-LAG_PeerLink
 port link-type trunk
 undo port trunk permit vlan 1
 port link-aggregation group 1024
#
interface HundredGigE1/0/54
 port link-mode bridge
 description pT:SHDXYQB4-108-C-04_C-05-ASW-S6900-M1-01U34:172.16.30.3.HundredGigE1/0/54_M-LAG_PeerLink
 port link-type trunk
 undo port trunk permit vlan 1
 port link-aggregation group 1024
#
interface M-GigabitEthernet0/0/0
 ip binding vpn-instance NET-manage
 ip address 172.16.30.4 255.255.255.0
#
interface Ten-GigabitEthernet1/0/47
 port link-mode route
 description pT:SHDXYQB4-108-C-04_C-05-ASW-S6900-M1-01U34:172.16.30.3.Ten-GigabitEthernet1/0/47_M-LAG_KeepAlive
 port link-aggregation group 1023
#
interface Ten-GigabitEthernet1/0/48
 port link-mode route
 description pT:SHDXYQB4-108-C-04_C-05-ASW-S6900-M1-01U34:172.16.30.3.Ten-GigabitEthernet1/0/48_M-LAG_KeepAlive
 port link-aggregation group 1023
#
interface Ten-GigabitEthernet1/0/1
 port link-mode bridge
 description NO-USE
 shutdown      
#
interface Ten-GigabitEthernet1/0/2
 port link-mode bridge
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.slot8-0
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 301 to 302
 broadcast-suppression 10
 port monitor-link group 1 downlink
 lacp period short
 port link-aggregation group 12
#
interface Ten-GigabitEthernet1/0/3
 port link-mode bridge
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.slot8-0
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 302
 broadcast-suppression 10
 port monitor-link group 1 downlink
 lacp period short
 port link-aggregation group 13
#              
interface Ten-GigabitEthernet1/0/4
 port link-mode bridge
 description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.slot8-0
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 302
 broadcast-suppression 10
 port monitor-link group 1 downlink
 lacp period short
 port link-aggregation group 14
#
interface Ten-GigabitEthernet1/0/5
 port link-mode bridge
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.slot8-0
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 302
 broadcast-suppression 10
 port monitor-link group 1 downlink
 lacp period short
 port link-aggregation group 15
#
interface Ten-GigabitEthernet1/0/6
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/7
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/8
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/9
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/10
 port link-mode bridge
 description NO-USE
 shutdown      
#
interface Ten-GigabitEthernet1/0/11
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/12
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/13
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/14
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/15
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/16
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/17
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/18
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/19
 port link-mode bridge
 description NO-USE
 shutdown
#              
interface Ten-GigabitEthernet1/0/20
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/21
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/22
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/23
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/24
 port link-mode bridge
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.slot8-1
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 300
 broadcast-suppression 10
 port monitor-link group 1 downlink
 lacp period short
 port link-aggregation group 34
#
interface Ten-GigabitEthernet1/0/25
 port link-mode bridge
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.slot8-1
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 300
 broadcast-suppression 10
 port monitor-link group 1 downlink
 lacp period short
 port link-aggregation group 35
#
interface Ten-GigabitEthernet1/0/26
 port link-mode bridge
 description dT:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.slot8-1
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 300
 broadcast-suppression 10
 port monitor-link group 1 downlink
 lacp period short
 port link-aggregation group 36
#
interface Ten-GigabitEthernet1/0/27
 port link-mode bridge
 description dT:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.slot8-1
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 300
 broadcast-suppression 10
 port monitor-link group 1 downlink
 lacp period short
 port link-aggregation group 37
#
interface Ten-GigabitEthernet1/0/28
 port link-mode bridge
 description NO-USE
 shutdown
#              
interface Ten-GigabitEthernet1/0/29
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/30
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/31
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/32
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/33
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/34
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/35
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/36
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/37
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/38
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/39
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/40
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/41
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/42
 port link-mode bridge
 description NO-USE
 shutdown      
#
interface Ten-GigabitEthernet1/0/43
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/44
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/45
 port link-mode bridge
 description NO-USE
 shutdown
#
interface Ten-GigabitEthernet1/0/46
 port link-mode bridge
 description NO-USE
 shutdown
#
 m-lag mad exclude interface Route-Aggregation1023
 m-lag restore-delay 180
 m-lag role priority 150
 m-lag system-mac 0001-0001-0001
 m-lag system-number 2
 m-lag system-priority 100
 m-lag keepalive ip destination 1.1.1.1 source 1.1.1.2
#
 scheduler logfile size 16
#
line class aux
 user-role network-admin
#
line class usb
 user-role network-admin
#
line class vty
 user-role network-operator
#
line aux 0
 user-role network-admin
#
line vty 0 9
 authentication-mode scheme
 user-role level-15
 user-role network-admin
 user-role network-operator
 idle-timeout 10 59
#
line vty 10 63
 user-role network-operator
#
 ip route-static vpn-instance NET-manage 0.0.0.0 0 172.16.30.254
#
 info-center timestamp loghost iso
 info-center loghost source M-GigabitEthernet0/0/0
 info-center loghost vpn-instance NET-manage 10.100.1.136 port 5000 facility local4
 info-center loghost vpn-instance NET-manage 10.100.1.137 port 5000 facility local4
#
 snmp-agent
 snmp-agent local-engineid 800063A280A069D913562C00000001
 snmp-agent community read cipher $c$3$8e+fw/dbr0/wvq1YTkpHTklWYu5djeIUAGRW5BIFTJqrRFY= acl 2000
 snmp-agent sys-info version v2c v3 
 snmp-agent target-host trap address udp-domain 10.100.1.136 vpn-instance NET-manage params securityname yundiao*&COC2016 v2c
 snmp-agent target-host trap address udp-domain 10.100.1.137 vpn-instance NET-manage params securityname yundiao*&COC2016 v2c
 snmp-agent trap enable arp 
 snmp-agent trap enable radius 
 snmp-agent trap enable stp 
 snmp-agent trap enable syslog 
 snmp-agent trap source M-GigabitEthernet0/0/0
#
 ssh server enable
 ssh server acl 2001
#
 ntp-service enable
 ntp-service source M-GigabitEthernet0/0/0
 ntp-service unicast-server 172.16.30.254 vpn-instance NET-manage
#
acl basic 2000
 description For_SNMP_NTP
 rule 10 permit vpn-instance NET-manage source 10.100.1.136 0
 rule 15 permit vpn-instance NET-manage source 10.100.1.137 0
 rule 20 permit vpn-instance NET-manage source 172.16.30.254 0
 rule 1000 deny
#
acl basic 2001
 description For_Login
 rule 10 permit vpn-instance NET-manage source 192.168.0.0 0.0.7.255
 rule 15 permit vpn-instance NET-manage source 192.168.8.0 0.0.7.255
 rule 20 permit vpn-instance NET-manage source 192.168.1.0 0.0.0.255
 rule 25 permit vpn-instance NET-manage source 10.252.134.0 0.0.1.255
 rule 30 permit vpn-instance NET-manage source 10.254.181.0 0.0.0.255
 rule 35 permit vpn-instance NET-manage source 10.100.1.128 0.0.0.127
 rule 40 permit vpn-instance NET-manage source 172.16.30.0 0.0.0.255
 rule 45 permit vpn-instance NET-manage source 10.30.0.0 0.0.1.255
 rule 50 permit vpn-instance NET-manage source 10.243.72.0 0.0.0.255
 rule 1000 deny
#
 password-control login-attempt 3 exceed lock-time 10
#
radius scheme system
 user-name-format without-domain
#
domain system
#
 aaa session-limit http 64
 aaa session-limit https 64
 domain default enable system
#
role name level-0
 description Predefined level-0 role
#
role name level-1
 description Predefined level-1 role
#
role name level-2
 description Predefined level-2 role
#
role name level-3
 description Predefined level-3 role
#
role name level-4
 description Predefined level-4 role
#
role name level-5
 description Predefined level-5 role
#
role name level-6
 description Predefined level-6 role
#
role name level-7
 description Predefined level-7 role
#
role name level-8
 description Predefined level-8 role
#
role name level-9
 description Predefined level-9 role
#
role name level-10
 description Predefined level-10 role
#
role name level-11
 description Predefined level-11 role
#
role name level-12
 description Predefined level-12 role
#
role name level-13
 description Predefined level-13 role
#
role name level-14
 description Predefined level-14 role
#
user-group system
#
local-user admin class manage
 password hash $h$6$mRyG+4BruRgs5d70$ZVnWtJjULkdBGvkzXfOCJQvxlL4PX3LJX9w38godB6jVbAATg8ems7nAB1dxkZPMZ0XmKvAD3mI8KeWvujMsvw==
 service-type ssh
 authorization-attribute idle-cut 10
 authorization-attribute user-role level-15
 authorization-attribute user-role network-admin
 authorization-attribute user-role network-operator
#
local-user shixun class manage
 password hash $h$6$WsRrHezotwuwWL0C$DylusMzehpIBXu8Nkp1ArVDOLW7DV+8CrjxT/S1ybQ3mn3zUVvlHTbx7NgeZm4oCVdDOPg47eL0hjv8tDd770w==
 service-type http ssh terminal
 authorization-attribute idle-cut 10
 authorization-attribute user-role level-15
 authorization-attribute user-role network-operator
#
 security-enhanced level 1
#
 netconf soap http enable
 netconf soap http acl 2001
 netconf ssh server enable
#
return

公共配置

#
max-ecmp-num 64
#
ip vpn-instance NET-manage
  route-distinguisher 1:1
  description For_NetworkManage
  quit
#
interface M-GigabitEthernet 0/0/0
  ip binding vpn-instance NET-manage
  description For_NetworkManage
  undo dhcp client identifier
  ip address <mgmt_ip> <mgmt_mask>
  quit
#
ip route-static vpn-instance NET-manage 0.0.0.0 0 <mgmt_gw> preference 1
#
lldp global enable
lldp global tlv-enable basic-tlv management-address-tlv interface M-GigabitEthernet0/0/0
#
################################################## snmp acl
#
acl basic 2000
  description For_SNMP
  rule 10 permit vpn-instance NET-manage source <Yundiao_CN2_1> 0
  rule 15 permit vpn-instance NET-manage source <Yundiao_CN2_2> 0
  rule 20 permit vpn-instance NET-manage source <YF_jiankong> 0
  rule 1000 deny vpn-instance NET-manage
  quit
#
################################################## ssh acl
#### 放行region集群CN2和网络设备带外地址段 ####
#
acl basic 2001
  description For_Login
  rule 10 permit vpn-instance NET-manage source 192.168.0.0 0.0.7.255
  rule 15 permit vpn-instance NET-manage source 192.168.8.0 0.0.7.255
  rule 20 permit vpn-instance NET-manage source 192.168.120.0 0.0.0.255
  rule 25 permit vpn-instance NET-manage source 10.252.134.0 0.0.1.255
  rule 30 permit vpn-instance NET-manage source 10.254.181.0 0.0.0.255
  rule 35 permit vpn-instance NET-manage source <Region_CN2_segment_1> #Region_CN2_segment_1#ip_wild_mask
  rule 40 permit vpn-instance NET-manage source <Region_mgmt_segment_1> #Region_mgmt_segment_1#ip_wild_mask
  rule 45 permit vpn-instance NET-manage source <Region_CN2_segment_2> #Region_CN2_segment_2#ip_wild_mask
  rule 50 permit vpn-instance NET-manage source <Region_mgmt_segment_2> #Region_mgmt_segment_2#ip_wild_mask
  rule 55 permit vpn-instance NET-manage source <Region_CN2_segment_3> #Region_CN2_segment_3#ip_wild_mask
  rule 60 permit vpn-instance NET-manage source <Region_mgmt_segment_3> #Region_mgmt_segment_3#ip_wild_mask
  rule 1000 deny vpn-instance NET-manage
  quit
#
################################################## 日志
#
info-center enable
info-center timestamp loghost iso
info-center loghost vpn-instance NET-manage <Yundiao_CN2_1> port 5000 facility local4
info-center loghost vpn-instance NET-manage <Yundiao_CN2_2> port 5000 facility local4
info-center loghost vpn-instance NET-manage <YF_jiankong> 
info-center loghost source M-GigabitEthernet 0/0/0
#
################################################## clock和ntp
#
clock timezone beijing add 08:00:00
clock protocol ntp
#
ntp-service enable
ntp-service source M-GigabitEthernet 0/0/0
ntp-service unicast-server <Yundiao_CN2_1> vpn-instance NET-manage priority
ntp-service unicast-server <Yundiao_CN2_2> vpn-instance NET-manage priority
#
################################################## snmp
#
snmp-agent
snmp-agent community read simple yundiao*&COC2016 acl 2000
snmp-agent sys-info version v2c v3
snmp-agent target-host trap address udp-domain <Yundiao_CN2_1> vpn-instance NET-manage params securityname yundiao*&COC2016 v2c
snmp-agent target-host trap address udp-domain <Yundiao_CN2_2> vpn-instance NET-manage params securityname yundiao*&COC2016 v2c
snmp-agent target-host trap address udp-domain <YF_jiankong> vpn-instance NET-manage params securityname yundiao*&COC2016 v2c
snmp-agent trap enable
snmp-agent trap source M-GigabitEthernet 0/0/0
#
################################################## ssh和netconf
#
undo ftp server enable
undo telnet server enable 
ssh server enable
ssh server acl 2001
#
netconf ssh server enable
netconf soap http enable
netconf soap http acl 2001
aaa session-limit http 64
aaa session-limit https 64
#
ip ttl-expires enable
#
undo stp global enable
#
################################################## 创建用户
#
undo local-user h3c class manage
#
local-user openstackadmin class manage
  password simple Pr@ject2018
  service-type ssh http terminal
  authorization-attribute user-role level-15
  undo authorization-attribute user-role network-operator
  authorization-attribute idle-cut 10
  quit
#
local-user AutoDevOps class manage
####运维验收自动化账号,咨询运维部信息
  !!!password simple {咨询COC确认}
  service-type ssh terminal
  authorization-attribute user-role level-15
  undo authorization-attribute user-role network-operator
  authorization-attribute idle-cut 10
  quit
#
local-user COC_operator class manage
  password simple Pr@ject2018
  service-type ssh terminal
  authorization-attribute user-role level-15
  undo authorization-attribute user-role network-operator
  authorization-attribute idle-cut 10
  quit
#
local-user COC_monitor class manage
  password-control length 9
  password simple Pr@ject94
  service-type ssh terminal
  authorization-attribute user-role level-1
  undo authorization-attribute user-role network-operator
  authorization-attribute idle-cut 10
  quit
#
local-user yundiao_read class manage
  password simple yundiao*&COC2016
  service-type ssh terminal
  authorization-attribute user-role level-1
  undo authorization-attribute user-role network-operator
  authorization-attribute idle-cut 10
  quit
#
################################################## vty
#
line vty 0 9
  authentication-mode scheme
  user-role level-15
  user-role network-admin
  user-role network-operator
  protocol inbound ssh
  idle-timeout 10 0
#
  • 20
    点赞
  • 12
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值