典型企业设备链路冗余备份方案

典型企业设备链路冗余备份方案

拓扑图
在这里插入图片描述
拓扑简介(思路)
经典企业内网设备链路冗余备份方案
核心层:双核心交换机做虚拟化(IRF)(51/52端口)配置做到设备备份,
MAD状态检测(50端口)
主设备(CORE_A)故障自动切换备设备(CORE_B),
上联配置三层链路聚合(链路备份)对接出口设备,
下联配置二层静态聚合(链路备份)对接接入交换机
接入层:上联配置链路聚合,达到链路备份目的
设备相关接口及IP如拓扑所示
负载均衡配置:内网vlan10出口联通,内网vlan20出口移动,且两条外网链路互为
备份(策略路由)

设备内部配置:
出口设备(FW):

sysname FW
策略路由配置
policy-based-route neiwang permit node 5
if-match acl 3000
apply next-hop 202.100.1.2

policy-based-route neiwang permit node 10
if-match acl 3001
apply next-hop 101.100.1.2

三层静态聚合
interface Route-Aggregation33
ip address 10.1.1.1 255.255.255.252
ip policy-based-route neiwang
#出口链路(联通)
interface GigabitEthernet1/0/1
port link-mode route
combo enable copper
ip address 202.100.1.1 255.255.255.0
nat outbound
#出口链路(移动)
interface GigabitEthernet1/0/2
port link-mode route
combo enable copper
ip address 101.100.1.1 255.255.255.0
nat outbound
#模拟器内部WEB界面登录测试(现网无需配置)
interface GigabitEthernet1/0/3
port link-mode route
combo enable copper
ip address 172.16.1.2 255.255.255.0
#加入三层静态聚合组
interface GigabitEthernet1/0/6
port link-mode route
combo enable copper
port link-aggregation group 33

interface GigabitEthernet1/0/8
port link-mode route
combo enable copper
port link-aggregation group 33

security-zone name Local
#Trust端口
security-zone name Trust
import interface GigabitEthernet1/0/3
import interface GigabitEthernet1/0/6
import interface GigabitEthernet1/0/8
import interface Route-Aggregation33

security-zone name DMZ
#Untrust端口
security-zone name Untrust
import interface GigabitEthernet1/0/1
import interface GigabitEthernet1/0/2

security-zone name Management

line con 0
authentication-mode scheme
user-role network-admin
idle-timeout 0 0
ip route-static 0.0.0.0 0 202.100.1.2
ip route-static 0.0.0.0 0 101.100.1.2 preference 100
ip route-static 192.168.0.0 16 10.1.1.2
#抓取内网使用网段
acl advanced 3000
rule 0 permit ip source 192.168.10.0 0.0.0.255

acl advanced 3001
rule 0 permit ip source 192.168.20.0 0.0.0.255

ip http enable
ip https enable
#安全策略配置
security-policy ip
rule 0 name trust_local
action pass
source-zone trust
destination-zone local
rule 1 name trust_untrust
action pass
source-zone trust
destination-zone untrust

return
[FW]
核心交换机cCORE_A

sysname CORE_A

irf mac-address persistent timer
irf auto-update enable
undo irf link-delay
#核心交换机虚拟化
irf member 1 priority 32
irf member 2 priority 10

lldp global enable

vlan 10

vlan 20

vlan 4000
#虚拟化
irf-port 1/2
port group interface Ten-GigabitEthernet1/0/51
port group interface Ten-GigabitEthernet1/0/52

irf-port 2/1
port group interface Ten-GigabitEthernet2/0/51
port group interface Ten-GigabitEthernet2/0/52

stp global enable
#二层静态聚合
interface Bridge-Aggregation11
port link-type trunk
port trunk permit vlan all
link-aggregation load-sharing mode destination-mac source-mac
#二层静态聚合
interface Bridge-Aggregation22
port link-type trunk
port trunk permit vlan all
#三层静态聚合
interface Route-Aggregation33
ip address 10.1.1.2 255.255.255.252

interface NULL0
#业务网关
interface Vlan-interface10
ip address 192.168.10.1 255.255.255.0
#业务网关
interface Vlan-interface20
ip address 192.168.20.1 255.255.255.0
#MAD检测
interface Vlan-interface4000
mad bfd enable
mad ip address 2.2.2.1 255.255.255.252 member 1
mad ip address 2.2.2.2 255.255.255.252 member 2

interface GigabitEthernet1/0/3
port link-mode route
combo enable fiber
shutdown
port link-aggregation group 33

interface GigabitEthernet2/0/3
port link-mode route
combo enable fiber
port link-aggregation group 33

interface GigabitEthernet1/0/1
port link-mode bridge
port link-type trunk
port trunk permit vlan all
combo enable fiber
port link-aggregation group 11

interface GigabitEthernet1/0/2
port link-mode bridge
port link-type trunk
port trunk permit vlan all
combo enable fiber
port link-aggregation group 22

interface GigabitEthernet1/0/8
port link-mode bridge
combo enable fiber

interface GigabitEthernet2/0/1
port link-mode bridge
port link-type trunk
port trunk permit vlan all
combo enable fiber
port link-aggregation group 11

interface GigabitEthernet2/0/2
port link-mode bridge
port link-type trunk
port trunk permit vlan all
combo enable fiber
port link-aggregation group 22

interface Ten-GigabitEthernet1/0/50
port link-mode bridge
port access vlan 4000
combo enable fiber
undo stp enable

interface Ten-GigabitEthernet2/0/50
port link-mode bridge
port access vlan 4000
combo enable fiber
undo stp enable

interface Ten-GigabitEthernet1/0/51
combo enable fiber

interface Ten-GigabitEthernet1/0/52
combo enable fiber

interface Ten-GigabitEthernet2/0/51
combo enable fiber

interface Ten-GigabitEthernet2/0/52
combo enable fiber
#路由设置:默认路由
ip route-static 0.0.0.0 0 10.1.1.1
<CORE_A>

  • 0
    点赞
  • 11
    收藏
    觉得还不错? 一键收藏
  • 1
    评论
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值