A-ASW-24

#设备命名
    hostname SHDXYQB4-108-C-05-ASW-RGS6250-01U37

#vlan创建
    vlan range 1,197,200-399,500-3999,4090,4093

#M-lag
    vap domain 1
    no fast-convergence
    recover up-delay 120 none-vap 60
    priority 7
    data-sync local 1.1.1.5 peer 1.1.1.6
    peer-keepalive local 1.1.1.1 peer 1.1.1.2
    dual-active auto recovery   

#peer-link配置
    interface AggregatePort 255
    description For_peerlink
    no mac-address-learning
    switchport mode trunk
    peer-link

    interface HundredGigabitEthernet 0/55
    description pT:SHDXYQB4-108-C-04_C-05-ASW-RGS6250-M1-01U37:10.30.0.23.Hun0/55_M-LAG_PeerLink
    carrier-delay up 2 down 0
    port-group 255 mode active

    interface HundredGigabitEthernet 0/56
    description pT:SHDXYQB4-108-C-04_C-05-ASW-RGS6250-M1-01U37:10.30.0.23.Hun0/56_M-LAG_PeerLink
    carrier-delay up 2 down 0
    port-group 255 mode active

    vlan 4094
    name vap

    interface VLAN 4094
    description For_VAP
    ip address 1.1.1.6 255.255.255.252


#peer-keepalive配置(三层接口)
    interface AggregatePort 254
    no switchport
    description For_DAD
    ip address 1.1.1.2 255.255.255.252
    vap error-down except

    interface TenGigabitEthernet 0/47
    no switchport
    description pT:SHDXYQB4-108-C-04_C-05-ASW-RGS6250-M1-01U37:10.30.0.23.Ten0/47_M-LAG_KeepAlive
    port-group 254 mode active

    interface TenGigabitEthernet 0/48
    no switchport
    description pT:SHDXYQB4-108-C-04_C-05-ASW-RGS6250-M1-01U37:10.30.0.23.Ten0/48_M-LAG_KeepAlive
    port-group 254 mode active

--------------------------------------------------------------------------------------------------
#端口9-22、31-46未使用端口
    interface TenGigabitEthernet 0/9
    description NO-USE
    shutdown

#uT上行链路
    interface AggregatePort 1
    description uT:SHDXYQB4-108-C-04_C-05-CSW-RGS6250-M1&M2-01U40:10.30.0.21&22.Agg59
    switchport mode trunk
    switchport trunk allowed vlan only 200-209,300-309,500-3999
    vap 1

    interface HundredGigabitEthernet 0/49
     description uT:SHDXYQB4-108-C-04_C-05-CSW-RGS6250-M1-01U40:10.30.0.21.Hun0/49
     carrier-delay up 2 down 0
     port-group 1 mode active

    interface HundredGigabitEthernet 0/50
     description uT:SHDXYQB4-108-C-04_C-05-CSW-RGS6250-M2-01U40:10.30.0.22.Hun0/50
     carrier-delay up 2 down 0
     port-group 1 mode active


#dT下行链路
    interface AggregatePort 11
    storm-control broadcast level 10
    description dT:Jisuan:SHDXYQB4-108-C-04-SEV-ZXR5300-02U12.bond1
    switchport mode trunk
    switchport trunk allowed vlan only 301
    spanning-tree bpduguard enable
    spanning-tree portfast
    vap 11

    interface AggregatePort 12
    storm-control broadcast level 10
    description dT:Jisuan:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.bond1
    switchport mode trunk
    switchport trunk allowed vlan only 301
    spanning-tree bpduguard enable
    spanning-tree portfast
    vap 12

    interface AggregatePort 16
    storm-control broadcast level 10
    description dT:Cunchu:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.bond1
    switchport mode trunk
    switchport trunk allowed vlan only 302
    spanning-tree bpduguard enable
    spanning-tree portfast
    vap 16

    interface AggregatePort 17
    storm-control broadcast level 10
    description dT:Cunchu:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.bond1
    switchport mode trunk
    switchport trunk allowed vlan only 302
    spanning-tree bpduguard enable
    spanning-tree portfast
    vap 17

    interface AggregatePort 18
    storm-control broadcast level 10
    description dT:Cunchu:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.bond1
    switchport mode trunk
    switchport trunk allowed vlan only 302
    spanning-tree bpduguard enable
    spanning-tree portfast
    vap 18

    interface AggregatePort 33
    storm-control broadcast level 10
    description dT:Jisuan:SHDXYQB4-108-C-04-SEV-ZXR5300-02U12.bond2
    switchport mode trunk
    switchport trunk allowed vlan only 300
    spanning-tree bpduguard enable
    spanning-tree portfast
    vap 33

    interface AggregatePort 34
    storm-control broadcast level 10
    description dT:Jisuan:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.bond2
    switchport mode trunk
    switchport trunk allowed vlan only 300
    spanning-tree bpduguard enable
    spanning-tree portfast
    vap 34

    interface AggregatePort 38
    storm-control broadcast level 10
    description dT:Cunchu:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.bond2
    switchport mode trunk
    switchport trunk allowed vlan only 300
    spanning-tree bpduguard enable
    spanning-tree portfast
    vap 38

    interface AggregatePort 39
    storm-control broadcast level 10
    description dT:Cunchu:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.bond2
    switchport mode trunk
    switchport trunk allowed vlan only 300
    spanning-tree bpduguard enable
    spanning-tree portfast
    vap 39

    interface AggregatePort 40
    storm-control broadcast level 10
    description dT:Cunchu:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.bond2
    switchport mode trunk
    switchport trunk allowed vlan only 300
    spanning-tree bpduguard enable
    spanning-tree portfast
    vap 40

    #物理接口
    interface TenGigabitEthernet 0/1
    description dT:Jisuan:SHDXYQB4-108-C-04-SEV-ZXR5300-02U12.slot4-1.10GELAN
    port-group 11 mode active
    lacp short-timeout
    lacp individual-port enable

    interface TenGigabitEthernet 0/2
    description dT:Jisuan:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.slot4-1.10GELAN
    port-group 12 mode active
    lacp short-timeout

    interface TenGigabitEthernet 0/3
    storm-control broadcast level 10
    description dT:Guanli:SHDXYQB4-108-C-04-SEV-ZXR5300-02U09.slot4-1.10GELAN
    switchport mode trunk
    switchport trunk allowed vlan only 301
    spanning-tree bpduguard enable
    spanning-tree portfast

    interface TenGigabitEthernet 0/4
    storm-control broadcast level 10
    description dT:Guanli:SHDXYQB4-108-C-05-SEV-ZXR5300-02U09.slot4-1.10GELAN
    switchport mode trunk
    switchport trunk allowed vlan only 301
    spanning-tree bpduguard enable
    spanning-tree portfast

    interface TenGigabitEthernet 0/5
    storm-control broadcast level 10
    description dT:Guanli:SHDXYQB4-108-C-04-SEV-ZXR5300-02U06.slot4-1.10GELAN
    switchport mode trunk
    switchport trunk allowed vlan only 301
    spanning-tree bpduguard enable
    spanning-tree portfast

    interface TenGigabitEthernet 0/6
    description dT:Cunchu:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.slot4-1.10GELAN
    port-group 16 mode active
    lacp short-timeout

    interface TenGigabitEthernet 0/7
    description dT:Cunchu:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.slot4-1.10GELAN
    port-group 17 mode active
    lacp short-timeout

    interface TenGigabitEthernet 0/8
    description dT:Cunchu:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.slot4-1.10GELAN
    port-group 18 mode active
    lacp short-timeout


    interface TenGigabitEthernet 0/23
    description dT:Jisuan:SHDXYQB4-108-C-04-SEV-ZXR5300-02U12.slot4-2.10GELAN
    port-group 33 mode active
    lacp short-timeout

    interface TenGigabitEthernet 0/24
    description dT:Jisuan:SHDXYQB4-108-C-05-SEV-ZXR5300-02U12.slot4-2.10GELAN
    port-group 34 mode active
    lacp short-timeout

    interface TenGigabitEthernet 0/25
    storm-control broadcast level 10
    description dT:Guanli:SHDXYQB4-108-C-04-SEV-ZXR5300-02U09.slot4-2.10GELAN
    switchport mode trunk
    switchport trunk allowed vlan only 200,300
    spanning-tree bpduguard enable
    spanning-tree portfast

    interface TenGigabitEthernet 0/26
    storm-control broadcast level 10
    description dT:Guanli:SHDXYQB4-108-C-05-SEV-ZXR5300-02U09.slot4-2.10GELAN
    switchport mode trunk
    switchport trunk allowed vlan only 200,300
    spanning-tree bpduguard enable
    spanning-tree portfast

    interface TenGigabitEthernet 0/27
    storm-control broadcast level 10
    description dT:Guanli:SHDXYQB4-108-C-04-SEV-ZXR5300-02U06.slot4-2.10GELAN
    switchport mode trunk
    switchport trunk allowed vlan only 200,300
    spanning-tree bpduguard enable
    spanning-tree portfast

    interface TenGigabitEthernet 0/28
    description dT:Cunchu:SHDXYQB4-108-C-05-SEV-ZXR5300-02U06.slot4-2.10GELAN
    port-group 38 mode active
    lacp short-timeout

    interface TenGigabitEthernet 0/29
    description dT:Cunchu:SHDXYQB4-108-C-04-SEV-ZXR5300-02U03.slot4-2.10GELAN
    port-group 39 mode active
    lacp short-timeout

    interface TenGigabitEthernet 0/30
    description dT:Cunchu:SHDXYQB4-108-C-05-SEV-ZXR5300-02U03.slot4-2.10GELAN
    port-group 40 mode active
    lacp short-timeout
--------------------------------------------------------------------------------------------------
#配置NTP(ntp server 10.30.1.254)
    ntp update-calendar
    ntp server vrf NET-manage 10.30.1.254 source Mgmt 0
    ntp server 10.30.1.254 source Mgmt 0 prefer
    clock timezone beijing +8 0    

#按规范配置远程ssh并调用相应的acl
    svi acl enable
    svi router-acls enable

    ip access-list standard 65
    10 permit 10.30.0.0 0.0.1.255

    ip access-list extended 2000
    10 permit ip host 10.10.0.136 any
    15 permit ip host 10.10.0.137 any
    20 permit ip host 10.30.0.0 any
    25 permit ip host 10.10.0.0 any
    1000 deny ip any any
    list-remark For_SNMP

    ip access-list extended 2001
    10 permit ip 192.168.0.0 0.0.7.255 any
    15 permit ip 192.168.8.0 0.0.7.255 any
    20 permit ip 192.168.120.0 0.0.0.255 any
    25 permit ip 10.254.181.0 0.0.0.255 any
    30 permit ip 10.252.134.0 0.0.1.255 any
    35 permit ip 10.10.0.0 0.0.0.255 any
    40 permit ip 10.30.0.0 0.0.1.255 any
    45 permit ip 10.243.72.0 0.0.0.255 any
    list-remark For_SSH_Login

#关闭telnet服务、web服务、开启巨帧转发、开启netconf并且最大会话次数为10
    no enable service  telnet-server 
    no enable service web-server
    enable service ssh-server
    mtu forwarding 9216
    netconf enable
    netconf max-sessions 10


#开启LLDP,指定为管理IP
    lldp management-address-tlv 10.30.0.24

#根据规范正确的配置本地登录账户名和密码(COC确认的密码统一使用:shixun@2023)
    service password-encryption
    username COC_monitor password shixun@2023
    username COC_operator privilege 15 password shixun@2023
    username openstackadmin privilege 15 password Pr@ject2018
    username sdnadmin privilege 15 password Pr@ject2018
    username yundiao_read password shixun@2023
    username shixun privilege 15 password shixun@2023


#SNMP
    snmp-server view GNCVIEW 1.3.6.1.2.1 include
    snmp-server view GNCVIEW 1.3.6.1.4.1.9 include
    snmp-server view GNCVIEW 1.3.6.1.4.1.4881 include
    snmp-server user yundiao SNMPGROUP v3 encrypted auth sha 0A9F2A9F45240C74EC0D985C3D7A66EF3DD4414D priv aes128 0A9F2A9F45240C74EC0D985C3D7A66EF
    snmp-server group SNMPGROUP v3 priv read defu write de access 2000
    enable service snmp-agent 
    snmp-server system-shutdown
    no snmp-server enable version v1
    snmp-server community yundiao*&COC2016 ro 2000
    snmp-server community COC2016 view GNCVIEW ro 65
    snmp-server enable traps
    snmp-server trap-source Mgmt 0
    snmp-server host 10.10.0.136 vrf NET-manage traps version 2c yundiao*&2016
    snmp-server host 10.10.0.137 vrf NET-manage traps version 2c yundiao*&2016
    snmp-server host 10.10.0.137 vrf NET-manage traps version 3 priv yundiao*&2016
    snmp-server host 10.10.0.136 vrf NET-manage traps version 3 priv yundiao*&2016


#HASH配置
    load-balance-profile ruijie
    ipv4 field src-ip dst-ip protocol l4-src-port l4-dst-port
    ipv6 field src-ip dst-ip protocol l4-src-port l4-dst-port
    hash-disturb 8
    aggregateport member linktrap
    aggregateport load-balance enhanced profile ruijie


#ssh登录限制
    line console 0
    session-timeout 10
    login local
    width 256

    line vty 0 9
    transport input ssh
    access-class 2001 in
    session-timeout 10
    login local
    width 256


#logging配置
    logging userinfo command-log
    logging trap warnings
    logging source interface Mgmt 0
    logging server 10.10.0.136 vrf NET-manage udp-port 5000 level warnings
    logging server 10.10.0.137 vrf NET-manage udp-port 5000 level warnings

--------------------------------------------------------------------------------------------------

spanning-tree mst 1 priority 4096
spanning-tree
!
link state track 1 up-delay 10
!
vrf definition NET-manage
description For_NetworkManage
rd 1:1
route-target both 1:1
address-family ipv4
exit-address-family
address-family ipv6
exit-address-family
!
no auto-provision
!
install 0 RG-S6250-48XS8CQ
!
logging userinfo command-log
logging buffered 1048576
logging file flash:LOG
logging flash interval 1
logging trap warnings
logging source interface Mgmt 0
logging facility local4
logging server 10.10.0.136 vrf NET-manage udp-port 5000 level warnings
logging server 10.10.0.137 vrf NET-manage udp-port 5000 level warnings
!
interface VLAN 200
description For_Internet
!
interface VLAN 300
description For_Storage_Outside
!
interface VLAN 301
description For_Compute_Inside
!
interface VLAN 302
description For_Ceph_Inside
!
interface Mgmt 0
description uT:SHDXYQB4-108-C-04_05-MSW-RGS5750-01U31:10.30.0.25.Gi1/0/4
vrf forwarding NET-manage
ip address 10.30.0.24 255.255.254.0
!
ip route vrf NET-manage 0.0.0.0 0.0.0.0 10.30.1.254 description For_NET-manage
!

评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值