#设备命名
hostname SHDXYQB4-108-C-05_CSW-RGS6250-01U40
#vlan创建
vlan range 1,197,200-399,500-3999,4090,4093
#M-lag
vap domain 1
no fast-convergence
recover up-delay 120 none-vap 60
priority 7
data-sync local 1.1.1.5 peer 1.1.1.6
peer-keepalive local 1.1.1.1 peer 1.1.1.2
dual-active auto recovery
#peer-link配置
interface AggregatePort 255
description Fof_peerlink
no mac-address-learning
switchport mode trunk
peer-link
interface HundredGigabitEthernet 0/55
description pT:SHDXYQB4-108-C-04_C-05-ASW-RGS6250-M2-01U37:10.30.0.24.Hun0/55_M-LAG_PeerLink
carrier-delay up 2 down 0
port-group 255 mode active
interface HundredGigabitEthernet 0/56
description pT:SHDXYQB4-108-C-04_C-05-ASW-RGS6250-M2-01U37:10.30.0.24.Hun0/56_M-LAG_PeerLink
carrier-delay up 2 down 0
port-group 255 mode active
interface VLAN 4094
description For_VAP
ip address 1.1.1.5 255.255.255.252
#peer-keepalive配置(三层接口)
interface AggregatePort 254
no switchport
description For_DAD
ip address 1.1.1.1 255.255.255.252
vap error-down except
interface TenGigabitEthernet 0/47
no switchport
description pT:SHDXYQB4-108-C-04_C-05-ASW-RGS6250-M2-01U37:10.30.0.24.Ten0/47_M-LAG_KeepAlive
port-group 254 mode active
interface TenGigabitEthernet 0/48
no switchport
description pT:SHDXYQB4-108-C-04_C-05-ASW-RGS6250-M2-01U37:10.30.0.24.Ten0/48_M-LAG_KeepAlive
port-group 254 mode active
--------------------------------------------------------------------------------------------------
#端口9-22、31-46、51-54未使用
interface TenGigabitEthernet 0/9
description NO-USE
shutdown
#uT上行链路
interface AggregatePort 1
description uT:SHDXYQB4-108-C-04_C-05-CSW-RGS6250-M1&M2-01U40:10.30.0.21&22.Agg59
switchport mode trunk
switchport trunk allowed vlan only 200-209,300-309,500-3999
vap 1
interface HundredGigabitEthernet 0/49
description uT:SHDXYQB4-108-C-04_C-05-CSW-RGS6250-M1-01U40:10.30.0.21.Hun0/49
carrier-delay up 2 down 0
port-group 1 mode active
interface HundredGigabitEthernet 0/50
description uT:SHDXYQB4-108-C-04_C-05-CSW-RGS6250-M2-01U40:10.30.0.22.Hun0/50
carrier-delay up 2 down 0
port-group 1 mode active
#dT下行链路
interface AggregatePort 11
storm-control broadcast level 10
description dT:Jisuan:SHDXYQB4-108-C-04-SEV-ZXR5300-02U12.bond1
switchport mode trunk
switchport trunk allowed vlan only 301
spanning-tree bpduguard enable
spanning-tree portfast
vap 11
interface AggregatePort 12
storm-control broadcast level 10
description dT:Jisuan:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.bond1
switchport mode trunk
switchport trunk allowed vlan only 301
spanning-tree bpduguard enable
spanning-tree portfast
vap 12
interface AggregatePort 16
storm-control broadcast level 10
description dT:Cunchu:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.bond1
switchport mode trunk
switchport trunk allowed vlan only 302
spanning-tree bpduguard enable
spanning-tree portfast
vap 16
interface AggregatePort 17
storm-control broadcast level 10
description dT:Cunchu:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.bond1
switchport mode trunk
switchport trunk allowed vlan only 302
spanning-tree bpduguard enable
spanning-tree portfast
vap 17
interface AggregatePort 18
storm-control broadcast level 10
description dT:Cunchu:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.bond1
switchport mode trunk
switchport trunk allowed vlan only 302
spanning-tree bpduguard enable
spanning-tree portfast
vap 18
interface AggregatePort 33
storm-control broadcast level 10
description dT:Jisuan:SHDXYQB4-108-C-04-SEV-ZXR5300-02U12.bond2
switchport mode trunk
switchport trunk allowed vlan only 300
spanning-tree bpduguard enable
spanning-tree portfast
vap 33
interface AggregatePort 34
storm-control broadcast level 10
description dT:Jisuan:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.bond2
switchport mode trunk
switchport trunk allowed vlan only 300
spanning-tree bpduguard enable
spanning-tree portfast
vap 34
interface AggregatePort 38
storm-control broadcast level 10
description dT:Cunchu:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.bond2
switchport mode trunk
switchport trunk allowed vlan only 300
spanning-tree bpduguard enable
spanning-tree portfast
vap 38
interface AggregatePort 39
storm-control broadcast level 10
description dT:Cunchu:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.bond2
switchport mode trunk
switchport trunk allowed vlan only 300
spanning-tree bpduguard enable
spanning-tree portfast
vap 39
interface AggregatePort 40
storm-control broadcast level 10
description dT:Cunchu:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.bond2
switchport mode trunk
switchport trunk allowed vlan only 300
spanning-tree bpduguard enable
spanning-tree portfast
vap 40
interface TenGigabitEthernet 0/1
description dT:Jisuan:SHDXYQB4-108-C-04-SEV-ZXR5300-02U12.slot8-1.10GELAN
port-group 11 mode active
lacp short-timeout
interface TenGigabitEthernet 0/2
description dT:Jisuan:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.slot8-1.10GELAN
port-group 12 mode active
lacp short-timeout
interface TenGigabitEthernet 0/3
storm-control broadcast level 10
description dT:Guanli:SHDXYQB4-108-C-04-SEV-ZXR5300-02U09.slot8-1.10GELAN
switchport mode trunk
switchport trunk allowed vlan only 301
spanning-tree bpduguard enable
spanning-tree portfast
interface TenGigabitEthernet 0/4
storm-control broadcast level 10
description dT:Guanli:SHDXYQB4-108-C-05-SEV-ZXR5300-02U09.slot8-1.10GELAN
switchport mode trunk
switchport trunk allowed vlan only 301
spanning-tree bpduguard enable
spanning-tree portfast
interface TenGigabitEthernet 0/5
storm-control broadcast level 10
description dT:Guanli:SHDXYQB4-108-C-04-SEV-ZXR5300-02U06.slot8-1.10GELAN
switchport mode trunk
switchport trunk allowed vlan only 301
spanning-tree bpduguard enable
spanning-tree portfast
interface TenGigabitEthernet 0/6
description dT:Cunchu:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.slot8-1.10GELAN
port-group 16 mode active
lacp short-timeout
interface TenGigabitEthernet 0/7
description dT:Cunchu:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.slot8-1.10GELAN
port-group 17 mode active
lacp short-timeout
interface TenGigabitEthernet 0/8
description dT:Cunchu:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.slot8-1.10GELAN
port-group 18 mode active
lacp short-timeout
interface TenGigabitEthernet 0/23
description dT:Jisuan:SHDXYQB4-108-C-04-SEV-ZXR5300-02U12.slot8-2.10GELAN
port-group 33 mode active
lacp short-timeout
interface TenGigabitEthernet 0/24
description dT:Jisuan:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.slot8-2.10GELAN
port-group 34 mode active
lacp short-timeout
interface TenGigabitEthernet 0/25
storm-control broadcast level 10
description dT:Guanli:SHDXYQB4-108-C-04-SEV-ZXR5300-02U09.slot8-2.10GELAN
switchport mode trunk
switchport trunk allowed vlan only 200,300
spanning-tree bpduguard enable
spanning-tree portfast
interface TenGigabitEthernet 0/26
storm-control broadcast level 10
description dT:Guanli:SHDXYQB4-108-C-05-SEV-ZXR5300-02U09.slot8-2.10GELAN
switchport mode trunk
switchport trunk allowed vlan only 200,300
spanning-tree bpduguard enable
spanning-tree portfast
interface TenGigabitEthernet 0/27
storm-control broadcast level 10
description dT:Guanli:SHDXYQB4-108-C-04-SEV-ZXR5300-02U06.slot8-2.10GELAN
switchport mode trunk
switchport trunk allowed vlan only 200,300
spanning-tree bpduguard enable
spanning-tree portfast
interface TenGigabitEthernet 0/28
description dT:Cunchu:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.slot8-2.10GELAN
port-group 38 mode active
lacp short-timeout
interface TenGigabitEthernet 0/29
description dT:Cunchu:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.slot8-2.10GELAN
port-group 39 mode active
lacp short-timeout
interface TenGigabitEthernet 0/30
description dT:Cunchu:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.slot8-2.10GELAN
port-group 40 mode active
lacp short-timeout
--------------------------------------------------------------------------------------------------
#配置NTP(ntp server 10.30.1.254)
ntp update-calendar
ntp server vrf NET-manage 10.30.1.254 source Mgmt 0
ntp server 10.30.1.254 source Mgmt 0 prefer
clock timezone beijing +8 0
#按规范配置远程ssh并调用相应的acl
svi acl enable
svi router-acls enable
ip access-list standard 65
10 permit 10.30.0.0 0.0.1.255
1000 deny any
ip access-list extended 2000
10 permit ip host 10.10.0.136 any
15 permit ip host 10.10.0.137 any
20 permit ip host 10.30.0.0 any
25 permit ip host 10.10.0.0 any
1000 deny ip any any
list-remark FOR_SNMP
ip access-list extended 2001
10 permit ip 192.168.0.0 0.0.7.255 any
15 permit ip 192.168.8.0 0.0.7.255 any
20 permit ip 192.168.120.0 0.0.0.255 any
25 permit ip 10.254.181.0 0.0.0.255 any
30 permit ip 10.252.134.0 0.0.1.255 any
35 permit ip 10.10.0.0 0.0.0.127 any
40 permit ip 10.30.0.0 0.0.1.255 any
45 permit ip 10.243.72.0 0.0.0.255 any
list-remark For_SSH_Login
#关闭telnet服务、web服务、开启巨帧转发、开启netconf并且最大会话次数为10
no enable service telnet-server
no enable service web-server
enable service ssh-server
mtu forwarding 9216
netconf enable
netconf max-sessions 10
#开启LLDP,指定为管理IP
lldp management-address-tlv 10.30.0.23
#根据规范正确的配置本地登录账户名和密码(COC确认的密码统一使用:shixun@2023)
service password-encryption
username COC_monitor password shixun@2023
username COC_operator privilege 15 password shixun@2023
username openstackadmin privilege 15 password Pr@ject2018
username sdnadmin privilege 15 password Pr@ject2018
username yundiao_read password shixun@2023
username shixun privilege 15 password shixun@2023
#SNMP
snmp-server view GNCVIEW 1.3.6.1.2.1 include
snmp-server view GNCVIEW 1.3.6.1.4.1.9 include
snmp-server view GNCVIEW 1.3.6.1.4.1.4881 include
snmp-server user yundiao SNMPGROUP v3 encrypted auth sha 0A9F2A9F45240C74EC0D985C3D7A66EF3DD4414D priv aes128 0A9F2A9F45240C74EC0D985C3D7A66EF
snmp-server group SNMPGROUP v3 priv read defu write de access 2000
enable service snmp-agent
snmp-server system-shutdown
no snmp-server enable version v1
snmp-server community yundiao*&COC2016 ro 2000
snmp-server community COC2016 view GNCVIEW ro 65
snmp-server enable traps
snmp-server trap-source Mgmt 0
snmp-server host 10.10.0.136 vrf NET-manage traps version 2c yundiao*&2016
snmp-server host 10.10.0.137 vrf NET-manage traps version 2c yundiao*&2016
snmp-server host 10.10.0.137 vrf NET-manage traps version 3 priv yundiao*&2016
snmp-server host 10.10.0.136 vrf NET-manage traps version 3 priv yundiao*&2016
#HASH配置
load-balance-profile ruijie
ipv4 field src-ip dst-ip protocol l4-src-port l4-dst-port
ipv6 field src-ip dst-ip protocol l4-src-port l4-dst-port
hash-disturb 8
aggregateport member linktrap
aggregateport load-balance enhanced profile ruijie
#ssh登录限制
line console 0
session-timeout 10
login local
width 256
line vty 0 9
transport input ssh
access-class 2001 in
session-timeout 10
login local
width 256
#logging配置
logging userinfo command-log
logging trap warnings
logging source interface Mgmt 0
logging server 10.10.0.136 vrf NET-manage udp-port 5000 level warnings
logging server 10.10.0.137 vrf NET-manage udp-port 5000 level warnings
#mode1管理不做聚合,mode4、mode6做聚合