拿到一台H3C交换机,需要做哪些配置?

1. Vlan 配置模版
1.1 创建Vlan
[Switch]vlan 100
[Switch]quit
1.2 将端口划入vlan
[Switch]interface GigabitEthernet 3/0/1
[Switch-GigabitEthernet3/0/1] port link-mode bridge
[Switch-GigabitEthernet3/0/1] port link-type access
[Switch-GigabitEthernet5/0/1] port access vlan 100
1.3 创建三层虚接口
[Switch]interface Vlan-interface 100
[Switch-Vlan-interface100]description ****
[Switch-Vlan-interface3]ip address X.X.X.X X.X.X.X
2. 三层接口配置模板
2.1 修改端口为三层接口
[Switch]interface GigabitEthernet 3/0/1
[Switch-GigabitEthernet3/0/1]port link-mode route
[Switch-GigabitEthernet3/0/1]description ****
[Switch-GigabitEthernet3/0/1]ip address X.X.X.X X.X.X.X
[Switch-GigabitEthernet3/0/1]undo shutdown
3. 创建链路聚合模版
3.1 创建2层链路聚合口
[Switch]interface Bridge-Aggregation 1
[Switch]quit
[Switch]interface range GigabitEthernet 3/0/1 to GigabitEthernet 3/0/4
[Switch-if-range]port link-mode bridge
[Switch-if-range]port link-aggregation group 11
[Switch-if-range]quit
[Switch]interface Bridge-Aggregation 11
[Switch-Bridge-Aggregation1]port link-type trunk
[Switch-Bridge-Aggregation1]port trunk permit vlan 10 20 30
[Switch-Bridge-Aggregation1]quit
3.2 创建3层链路聚合口
[Switch]interface Route-Aggregation 2
[Switch]quit
[Switch]interface range GigabitEthernet 3/0/5 to GigabitEthernet 3/0/8
[Switch-if-range]port link-mode route
[Switch-if-range]port link-aggregation group 2
[Switch-if-range]quit
[Switch]interface Route-Aggregation 2
[Switch-Route-Aggregation12]description ****
[Switch-Route-Aggregation12]ip address X.X.X.X X.X.X.X
[Switch-Route-Aggregation12]undo shutdown
4. QOS配置限速
4.1 基于策略限速
[Switch]traffic classifier test operator or //创建traffic类‘test’
[Switch-classifier-test]if-match any
[Switch-classifier-test]quit
[Switch]traffic behavior 10M
//创建traffic行为‘10M’
[Switch-behavior-10M]car cir 10000
[Switch-behavior-10M]quit
[Switch] qos policy xiansu10M//创建qos策略‘xiansu10M’
[Switch-qospolicy-xiansu10M] classifier test behavior 10M //绑定traffic类和traffic行为
[Switch-qospolicy-xiansu10M]quit
[Switch]interface GigabitEthernet 3/0/1
[Switch-GigabitEthernet3/0/1] qos apply policy xiansu10M inbound //应用qos策略
[Switch-GigabitEthernet3/0/1] qos apply policy xiansu10M outbound
4.2 基于端口限速
[Switch]interface GigabitEthernet 3/0/1
[Switch-GigabitEthernet3/0/1] qos lr inbound cir 1000
[Switch-GigabitEthernet3/0/1] qos lr outbound cir 1000
4.3 基于Vlan限速
[Switch]traffic classifier test operator or //创建traffic类‘test’
[Switch-classifier-test]if-match any
[Switch-classifier-test]quit
[Switch]traffic behavior 10M //创建traffic行为‘10M’
[Switch-behavior-10M]car cir 10000
[Switch-behavior-10M]quit
[Switch] qos policy xiansu10M//创建qos策略‘xiansu10M’
[Switch-qospolicy-xiansu10M] classifier test behavior 10M //绑定traffic类和traffic行为
[Switch-qospolicy-xiansu10M]quit
[Switch]qos vlan-policy xiansu10M vlan 100 inbound
[Switch]qos vlan-policy xiansu10M vlan 100 outbound
5. 备份与还原
5.1 备份
<Switch>tftp X.X.X.X put startup.cfg XXX.cfg
5.2 还原
<Switch>tftp X.X.X.X get XXX.cfg startup.cfg
6. 配置举例
6.1 客户二层接入(客户网关为我方交换机接口地址)且限速100M
vlan 10
description ***
quit
int vlanif 10
description ***
ip addr x.x.x.x xx
quit
interface GigabitEthernet3/0/1
port link-mode bridge
description ***
port access vlan 10
qos lr outbound cir 102400
undo shutdown
quit
6.2 客户三层接入(客户与我方交换机互联并配有互联地址)
6.2.1互联接口配置:
interface Ten-GigabitEthernet3/0/46
port link-mode route
description ***
ip address x.x.x.x xx
6.2.2 配置前缀列表允许ospf引入客户网段
ip prefix-list OSPF100-OUT index 60 permit x.x.x.x 24 less-equal 32
6.2.3 配置指向客户设备的回程路由
ip route-static x.x.x.x xx x.x.x.x tag 21
6.2.4 将受攻击ip指向黑洞路由
单独ip: ip route-static x.x.x.x 32 null0
网段:ip route-static x.x.x.x xx null0

  • 44
    点赞
  • 21
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 1
    评论
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

诺然晴

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值