华为策略路由关联NQA
华为产品的NQA配置,配置NQA联动策略路由检测线路是否故障来达到智能切换线路
需求:某企业网关有电信和移动两条线路,要求10网段的流量走电信,20网段的流量走移动,如果电信线路故障时,要快速切换到移动线路,保障网络正常
拓扑图:
配置汇聚交换机
[Huawei]sys
[Huawei]sysname SW-HuiJu
[SW-HuiJu]dhcp enable
[SW-HuiJu]vlan 10
[SW-HuiJu-vlan10]interface GigabitEthernet 0/0/1
[SW-HuiJu-GigabitEthernet0/0/1]port link-type access
[SW-HuiJu-GigabitEthernet0/0/1]port default vlan 10
[SW-HuiJu-GigabitEthernet0/0/1]interface vlanif 10
[SW-HuiJu-Vlanif10]ip address 172.29.10.1 255.255.255.0
[SW-HuiJu-Vlanif10]dhcp select interface
------------------------------------------------------------------------------------
[SW-HuiJu-Vlanif10]vlan 20
[SW-HuiJu-vlan20]interface GigabitEthernet 0/0/2
[SW-HuiJu-GigabitEthernet0/0/2]port link-type access
[SW-HuiJu-GigabitEthernet0/0/2]port default vlan 20
[SW-HuiJu-GigabitEthernet0/0/2]interface vlanif 20
[SW-HuiJu-Vlanif20]ip address 172.29.20.1 255.255.255.0
[SW-HuiJu-Vlanif20]dhcp select interface
------------------------------------------------------------------------------------
[SW-HuiJu]vlan 24
[SW-HuiJu-vlan24]interface g0/0/24
[SW-HuiJu-GigabitEthernet0/0/24]port link-type access
[SW-HuiJu-GigabitEthernet0/0/24]port default vlan 24
[SW-HuiJu-GigabitEthernet0/0/24]interface vlanif 24
[SW-HuiJu-Vlanif24]ip address 172.29.24.1 255.255.255.252
--------------------------------------------------------------------------------------
配置默认路由 下一跳路由器的Lan口IP
[SW-HuiJu]ip route-static 0.0.0.0 0.0.0.0 172.29.24.2
--------------------------------------------------------------------------------------
模拟电信网关
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 12.12.12.2 255.255.255.252
[Huawei]interface LoopBack 1
[Huawei-LoopBack1]ip address 114.114.114.114 255.255.255.255
模拟移动网关
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 13.13.13.2 255.255.255.252
[Huawei]interface LoopBack 1
[Huawei-LoopBack1]ip address 114.114.114.114 255.255.255.255
配置路由器
1.配置互联接口
[Huawei]sysname route
[route]interface GigabitEthernet 0/0/0
[route-GigabitEthernet0/0/0]ip address 172.29.24.2 255.255.255.252
[route-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[route-GigabitEthernet0/0/1]ip address 12.12.12.1 255.255.255.252
[route-GigabitEthernet0/0/1]interface GigabitEthernet 0/0/2
route-GigabitEthernet0/0/2]ip address 13.13.13.1 255.255.255.252
配置nat
[route]acl 2000
[route-acl-basic-2000]rule 0 permit source 172.29.0.0 0.0.255.255
[route]interface GigabitEthernet 0/0/1
[route-GigabitEthernet0/0/1]nat outbound 2000
[route-GigabitEthernet0/0/1]interface GigabitEthernet 0/0/2
[route-GigabitEthernet0/0/2]nat outbound 2000
配置NQA实例
1.监视电信网关的nqa
[route]nqa test-instance admin dianxin
[route-nqa-admin-dianxin]test-type icmp ----监视icmp协议
[route-nqa-admin-dianxin]destination-address ipv4 12.12.12.2 ----目的地址电信网关
[route-nqa-admin-dianxin]source-interface g0/0/1 -----源接口or 下一跳
[route-nqa-admin-dianxin]frequency 6 -----每隔6秒执行一次nqa任务
[route-nqa-admin-dianxin]timeout 2 -----超时时间
[route-nqa-admin-dianxin]probe-count 1 -----每次任务只探测一个包
[route-nqa-admin-dianxin]start now -----现在开始监视
2.监视移动网关的nqa
[route]nqa test-instance admin yidong
[route-nqa-admin-dianxin]test-type icmp
[route-nqa-admin-dianxin]destination-address ipv4 13.13.13.2
[route-nqa-admin-dianxin]source-interface g0/0/2
[route-nqa-admin-dianxin]frequency 6
[route-nqa-admin-dianxin]timeout 2
[route-nqa-admin-dianxin]probe-count 1
[route-nqa-admin-dianxin]start now
配置默认路由关联NQA
[route]ip route-static 0.0.0.0 0 12.12.12.2 track nqa admin dianxin
[route]ip route-static 0.0.0.0 0 13.13.13.2 track nqa admin yidong
[route]ip route-static 172.29.0.0 16 172.29.24.1
配置流分类
1.创建ACL
[route]acl 2001
[route-acl-basic-2001]rule 0 permit source 172.29.10.0 0.0.0.255
[route]acl 2002
[route-acl-basic-2002]rule 0 permit source 172.29.20.0 0.0.0.255
2.创建流分类
[route]traffic classifier v10
[route-classifier-v10]if-match acl 2001
[route]traffic classifier v20
[route-classifier-v20]if-match acl 2002
3.创建流行为
[route]traffic behavior dianxin
[route-behavior-dianxin]redirect ip-nexthop 12.12.12.2 track nqa admin dianxin
[route]traffic behavior yidong
[route-behavior-yidong]redirect ip-nexthop 13.13.13.2 track nqa admin yidong
4.创建流策略
[route]traffic policy xuanlu
[route-trafficpolicy-xuanlu]classifier v10 behavior dianxin
[route-trafficpolicy-xuanlu]classifier v20 behavior yidong
5.应用流策略
[route]interface g0/0/0
[route-GigabitEthernet0/0/0]traffic-policy xuanlu inbound
测试
当断开电信光猫0/1口时,所有的流量走移动宽带
当断开移动光猫0/1口时,所有的流量走电信宽带
有需求可咨询我,15088620473(微信同号)