hcie datacome mpls

所有设备改名

关闭超时
user con 0
idle 0

isis基础配置
X_PE1
router id 1.0.0.1
isis 1
is-level level-2
cost-style wide
network-entity 49.0001.0010.0000.0001.00
domain-authentication-mode md5 cipher Huawei@123

interface loop 0
isis enable

int g0/0/0
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

int g0/0/1
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

int g0/0/2
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

X_PE2
router id 2.0.0.2
isis 1
is-level level-2
cost-style wide
network-entity 49.0001.0020.0000.0002.00
domain-authentication-mode md5 cipher Huawei@123

interface loop 0
isis enable

int g0/0/0
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

int g0/0/1
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

int g0/0/2
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

Y_PE1
router id 3.0.0.3
isis 1
is-level level-2
cost-style wide
network-entity 49.0001.0030.0000.0003.00
domain-authentication-mode md5 cipher Huawei@123

interface loop 0
isis enable

int g0/0/0
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

int g0/0/1
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

int g0/0/2
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

Y_PE2
router id 4.0.0.4
isis 1
is-level level-2
cost-style wide
network-entity 49.0001.0040.0000.0004.00
domain-authentication-mode md5 cipher Huawei@123

interface loop 0
isis enable

int g0/0/0
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

int g0/0/1
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

int g0/0/2
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

Z_PE1
router id 5.0.0.5
isis 1
is-level level-2
cost-style wide
network-entity 49.0001.0050.0000.0005.00
domain-authentication-mode md5 cipher Huawei@123

interface loop 0
isis enable

int g0/0/0
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

int g0/0/1
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

int g0/0/2
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

Z_PE2
router id 6.0.0.6
isis 1
is-level level-2
cost-style wide
network-entity 49.0001.0060.0000.0006.00
domain-authentication-mode md5 cipher Huawei@123

interface loop 0
isis enable

int g0/0/0
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

int g0/0/1
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

int g0/0/2
isis enable 1
isis circuit-type p2p
isis ppp-negotiation 2-way
isis authentication-mode md5 cipher Huawei@123

dis isis router 查看路由学习
dis isis peer

bfd调整
X_PE1
bfd
isis
bfd all-interface enable
bfd all-interface min-rx-interval 15 min-tx-interval 15 frr-binding //ensp 1500
frr
loop-free-alternate level-2

X_PE2
bfd
isis
bfd all-interface enable
bfd all-interface min-rx-interval 15 min-tx-interval 15 frr-binding
frr
loop-free-alternate level-2

Y_PE1
bfd
isis
bfd all-interface enable
bfd all-interface min-rx-interval 15 min-tx-interval 15 frr-binding
frr
loop-free-alternate level-2

Y_PE2
bfd
isis
bfd all-interface enable
bfd all-interface min-rx-interval 15 min-tx-interval 15 frr-binding
frr
loop-free-alternate level-2

Z_PE1
bfd
isis
bfd all-interface enable
bfd all-interface min-rx-interval 15 min-tx-interval 15 frr-binding
frr
loop-free-alternate level-2

Z_PE2
bfd
isis
bfd all-interface enable
bfd all-interface min-rx-interval 15 min-tx-interval 15 frr-binding
frr
loop-free-alternate level-2

dis isis bfd session all 查看

路径优选
X_PE1
interface g0/0/0
isis cost 4 level-2

X_PE2
interface g0/0/0
isis cost 4 level-2

Y_PE1
interface g0/0/0
isis cost 4 level-2

Y_PE2
interface g0/0/0
isis cost 4 level-2

Z_PE1
interface g0/0/0
isis cost 3 level-2

Z_PE2
interface g0/0/0
isis cost 3 level-2

关闭X_PE1的g0/0/2口测试
tracert -a 1.0.0.1 5.0.0.5

mpls ldp配置
X_PE1
mpls lsr-id 1.0.0.1
mpls
mpls ldp

int g0/0/0
mpls mtu 1382
mpls
mpls ldp

int g0/0/1
mpls mtu 1382
mpls
mpls ldp

int g0/0/2
mpls mtu 1382
mpls
mpls ldp

X_PE2
mpls lsr-id 2.0.0.2
mpls
mpls ldp

int g0/0/0
mpls mtu 1382
mpls
mpls ldp

int g0/0/1
mpls mtu 1382
mpls
mpls ldp

int g0/0/2
mpls mtu 1382
mpls
mpls ldp

Y_PE1
mpls lsr-id 3.0.0.3
mpls
mpls ldp

int g0/0/0
mpls mtu 1382
mpls
mpls ldp

int g0/0/1
mpls mtu 1382
mpls
mpls ldp

int g0/0/2
mpls mtu 1382
mpls
mpls ldp

Y_PE2
mpls lsr-id 4.0.0.4
mpls
mpls ldp

int g0/0/0
mpls mtu 1382
mpls
mpls ldp

int g0/0/1
mpls mtu 1382
mpls
mpls ldp

int g0/0/2
mpls mtu 1382
mpls
mpls ldp

Z_PE1
mpls lsr-id 5.0.0.5
mpls
mpls ldp

int g0/0/0
mpls mtu 1382
mpls
mpls ldp

int g0/0/1
mpls mtu 1382
mpls
mpls ldp

int g0/0/2
mpls mtu 1382
mpls
mpls ldp

Z_PE2
mpls lsr-id 6.0.0.6
mpls
mpls ldp

int g0/0/0
mpls mtu 1382
mpls
mpls ldp

int g0/0/1
mpls mtu 1382
mpls
mpls ldp

int g0/0/2
mpls mtu 1382
mpls
mpls ldp

dis mpls ldp session all 查看

MPLS快速收敛
X_PE1
bfd
mpls-passive
mpls
mpls bfd enable
mpls bfd-trigger host
mpls bfd min-tx-interval 15 min-rx-interval 15 /ensp1500ms
inter g0/0/0
isis ldp-sync
inter g0/0/1
isis ldp-sync
inter g0/0/2
isis ldp-sync

X_PE2
bfd
mpls-passive
mpls
mpls bfd enable
mpls bfd-trigger host
mpls bfd min-tx-interval 15 min-rx-interval 15
inter g0/0/0
isis ldp-sync
inter g0/0/1
isis ldp-sync
inter g0/0/2
isis ldp-sync

Y_PE1
bfd
mpls-passive
mpls
mpls bfd enable
mpls bfd-trigger host
mpls bfd min-tx-interval 15 min-rx-interval 15
inter g0/0/0
isis ldp-sync
inter g0/0/1
isis ldp-sync
inter g0/0/2
isis ldp-sync

Y_PE2
bfd
mpls-passive
mpls
mpls bfd enable
mpls bfd-trigger host
mpls bfd min-tx-interval 15 min-rx-interval 15
inter g0/0/0
isis ldp-sync
inter g0/0/1
isis ldp-sync
inter g0/0/2
isis ldp-sync

Z_PE1
bfd
mpls-passive
mpls
mpls bfd enable
mpls bfd-trigger host
mpls bfd min-tx-interval 15 min-rx-interval 15
inter g0/0/0
isis ldp-sync
inter g0/0/1
isis ldp-sync
inter g0/0/2
isis ldp-sync

Z_PE2
bfd
mpls-passive
mpls
mpls bfd enable
mpls bfd-trigger host
mpls bfd min-tx-interval 1500 min-rx-interval 1500
inter g0/0/0
isis ldp-sync
inter g0/0/1
isis ldp-sync
inter g0/0/2
isis ldp-sync

dis mpls bfd session 查看状态
dis mpls lsp

BGP基础配置
X_PE1
bgp 65000
router-id 1.0.0.1
undo default ipv4-unicast
group rrclient internal
peer rrclient connect-interface loopback 0
peer rrclient password cipher Huawei@123
peer rrclient bfd enable
peer rrclient bfd min-rx-interval 15 min-tx-interval 15
peer 2.0.0.2 group rrclient
peer 3.0.0.3 group rrclient
peer 5.0.0.5 group rrclient
ipv4-family vpnv4
undo policy vpn-target
peer rrclient enable
peer 2.0.0.2 group rrclient
peer 3.0.0.3 group rrclient
peer 5.0.0.5 group rrclient
peer 5.0.0.5 reflect-client
peer 3.0.0.3 reflect-client

X_PE2
bgp 65000
router-id 2.0.0.2
undo default ipv4-unicast
group rrclient internal
peer rrclient connect-interface loopback 0
peer rrclient password cipher Huawei@123
peer rrclient bfd enable
peer rrclient bfd min-rx-interval 15 min-tx-interval 15
peer 1.0.0.1 group rrclient
peer 4.0.0.4 group rrclient
peer 6.0.0.6 group rrclient
ipv4-family vpnv4
undo policy vpn-target
peer rrclient enable
peer 1.0.0.1 group rrclient
peer 4.0.0.4 group rrclient
peer 6.0.0.6 group rrclient
peer 4.0.0.4 reflect-client
peer 6.0.0.6 reflect-client

Y_PE1
bgp 65000
router-id 3.0.0.3
undo default ipv4-unicast
peer 1.0.0.1 as-number 65000
peer 1.0.0.1 connect-interface loop 0
peer 1.0.0.1 password cipher Huawei@123
peer 1.0.0.1 bfd enable
peer 1.0.0.1 bfd min-rx-interval 15 min-tx-interval 15
ipv4-family vpnv4
peer 1.0.0.1 enable

X_PE2
bgp 65000
router-id 4.0.0.4
undo default ipv4-unicast
peer 2.0.0.2 as-number 65000
peer 2.0.0.2 connect-interface loop 0
peer 2.0.0.2 password cipher Huawei@123
peer 2.0.0.2 bfd enable
peer 2.0.0.2 bfd min-rx-interval 15 min-tx-interval 15
ipv4-family vpnv4
peer 2.0.0.2 enable

Z_PE1
bgp 65000
router-id 5.0.0.5
undo default ipv4-unicast
peer 1.0.0.1 as-number 65000
peer 1.0.0.1 connect-interface loop 0
peer 1.0.0.1 password cipher Huawei@123
peer 1.0.0.1 bfd enable
peer 1.0.0.1 bfd min-rx-interval 15 min-tx-interval 15
ipv4-family vpnv4
peer 1.0.0.1 enable

Z_PE2
bgp 65000
router-id 6.0.0.6
undo default ipv4-unicast
peer 2.0.0.2 as-number 65000
peer 2.0.0.2 connect-interface loop 0
peer 2.0.0.2 password cipher Huawei@123
peer 2.0.0.2 bfd enable
peer 2.0.0.2 bfd min-rx-interval 15 min-tx-interval 15
ipv4-family vpnv4
peer 2.0.0.2 enable

vpn实例部署
X_PE1
ip vpn-instance OA
ipv4-family
route-distinguisher 65000:1
vpn-target 100:1 import-extcommunity
vpn-target 200:2 export-extcommunity

X_PE2
ip vpn-instance OA
ipv4-family
route-distinguisher 65000:2
vpn-target 100:1 import-extcommunity
vpn-target 200:2 export-extcommunity

Y_PE1
ip vpn-instance OA
ipv4-family
route-distinguisher 65000:3
vpn-target 100:1 import-extcommunity
vpn-target 200:2 export-extcommunity

ip vpn-instance R&D
ipv4-family
route-distinguisher 65000:31
vpn-target 300:1

Y_PE2
ip vpn-instance OA
ipv4-family
route-distinguisher 65000:4
vpn-target 100:1 import-extcommunity
vpn-target 200:2 export-extcommunity

ip vpn-instance R&D
ipv4-family
route-distinguisher 65000:41
vpn-target 300:1 both

Z_PE1
ip vpn-instance OA_In
ipv4-family
route-distinguisher 65000:5
vpn-target 200:2 import

ip vpn-instance OA_Out
ipv4-family
route-distinguisher 6500:51
vpn-target 100:1 export

ip vpn-instance R&D
ipv4-family
route-distinguisher 65000:52
vpn-target 300:1 both

Z_PE2
ip vpn-instance OA_In
ipv4-family
route-distinguisher 65000:6
vpn-target 200:2 import

ip vpn-instance OA_Out
ipv4-family
route-distinguisher 6500:61
vpn-target 100:1 export

ip vpn-instance R&D
ipv4-family
route-distinguisher 65000:62
vpn-target 300:1 both

Y_Export1
ip vpn-instance OA
ipv4-family
route-distinguisher 65000:100

ip vpn-instance R&D
ipv4-family
route-distinguisher 65000:101

Z_Export1
ip vpn-instance OA
ipv4-family
route-distringuisher 65000:300

ip vpn-instance R&D
ipv4-family
route-distringuisher 65000:301

PE互联地址配置
X_Export1
g0/07
undo portswitch
10.20.1.1 30

ge0/0/8
undo portswitch
10.20.1.5 30

X_Export2
g0/0/7
undo portswitch
10.20.1.9 30

g0/0/8
undo portswitch
10.20.1.6 30

X_PE1
g0/0/10
ip binding vpn-instance OA
10.20.1.2 30

X_PE2
g0/0/10
ip binding vpn-instance OA
10.20.1.10 30

Y_Export1
int g0/0/7
undo portswitch

g0/0/7.10
ip binding vpn-instance OA
dot1q termination vid 10
arp broadcast enable
10.20.2.1 30

g0/0/7.20
ip binding vpn-instance R&D
dot1q ermination vid 20
arp broadcast enable
10.20.2.5 30

g0/0/6
undo portswitch

g0/0/6.10
ip binding vpn-stance OA
dot1q termination vid 10
arp broadcast enable
10.20.2.9 30

g0/0/6.20
ip binding vpn-stance R&D
dot1q termination vid 20
arp broadcast enable
10.20.2.13 30

Y_PE1
g0/0/10.10
ip binding vpn-instance OA
dot1q termination vid 10
arp broadcast enable
10.20.2.2 30

g0/0/10.20
ip binding vpn-instance R&D
dot1q termination vid 20
arp broadcast enable
10.20.2.6 30

YPE2
g0/0/010.10
ip binding vpn-instance OA
dot1q termination vid 10
arp broadcast enable
10.20.2.10 30

g0/0/10.20
ip binding vpn-instance R&D
dot1q termination vid 20
arp broadcast enable
10.20.2.14 30

Z_Export
g0/0/7
undo portswitch

g0/0/06
undo portswitch

g0/0/6.10
ip binding vpn-instance OA
dot1q termination vid 10
arp broadcast enable
10.20.3.1 30

g0/0/6.11
ip binding vpn-instance OA
dot1q termination vid 11
arp broadcast enable
10.20.3.5 30

g0/0/6.20
ip binding vpn-instance R&D
dot1q termination vid 20
arp broadcast enable
10.20.3.9 30

g0/0/7.10
ip binding vpn-instance OA
dot1q termination vid 10
arp broadcast enable
10.20.3.13 30

g0/0/7.11
ip binding vpn-instance OA
dot1q termination vid 11
arp broadcast enable
ip add 10.20.3.17 30

g0/0/7.20
ip binding vpn-instance R&D
dot1q termination vid 20
arp broadcast enable
ip add 10.20.3.21 30

int loop 0
ip binding vpn-instance OA
ip add 10.3.101.254 24

int loop 1
ip binding vpn-instance R&D
ip add 10.3.99.254 24

int loop 2
ip binding vpn-instance R&D
ip add 10.3.100.254 24

Z_PE1
g0/0/10.10
ip binding vpn-instance OA_In
dot1q termination vid 10
arp broadcast enable
10.20.3.2 30

g0/0/10.11
ip binding vpn-instance OA_Out
dot1q termination vid 11
arp broadcast enable
10.20.3.6 30

g0/0/10.20
ip binding vpn-instance R&D
dot1q termination vid 20
arp broadcast enable
10.20.3.10 30

Z_PE2
int g0/0/0.10
ip binding vpn-instance OA_In
dot1q termination vid 10
arp broadcast enable
ip add 10.20.3.14 30

int g0/0/0.11
ip binding vpn-instance OA_Out
dot1q termination vid 11
arp broadcast enable
ip add 10.20.3.18 30

int g0/0/0.20
ip binding vpn-instance R&D
dot1q termination vid 20
arp broadcast enable
ip add 10.20.3.22 30

CE和PE之间BGP建立
X_PE1
bgp 65000
ipv4-family vpn-instance OA
peer 10.20.1.1 as 65001

X_PE2
bgp 65000
ipv4-family vpn-instance OA
peer 10.20.1.9 as 65001

X_Export1
bgp 65001
router-id 10.1.0.1
peer 10.20.1.2 as 65000

X_Export2
bgp 65001
router-id 10.1.0.2
peer 10.20.1.10 as 65000

验证
dis bgp peer

Y_PE1
bgp 65000
ipv4-family vpn-instance OA
peer 10.20.2.1 as 65003
quit
ipv4-family vpn-instance R&D
peer 10.20.2.5 as 65003

Y_PE2
bgp 65000
ipv4-family vpn-instance OA
peer 10.20.2.9 as 65003
quit
ipv4-family vpn-instance R&D
peer 10.20.2.13 as 65003

Y_Export1
bgp 65003
ipv4-family vpn-instance OA
peer 10.20.2.2 as 65000
peer 10.20.2.10 as 65000
quit
ipv4-family vpn-instance R&D
peer 10.20.2.6 as 65000
peer 10.20.2.14 as 65000

dis bgp vpnv4 all peer
验证

Z_PE1
bgp 65000
ipv4-family vpn-instance OA_In
peer 10.20.3.1 as 65004
quit
ipv4-family vpn-instance OA_Out
peer 10.20.3.5 as 65004
peer 10.20.3.5 allow-as-loop
quit
ipv4-family vpn-instance R&D
peer 10.20.3.9 as 65004

Z_PE2
bgp 65000
ipv4-family vpn-instance OA_In
peer 10.20.3.13 as 65004
quit
ipv4-family vpn-instance OA_Out
peer 10.20.3.17 as 65004
peer 10.20.3.17 allow-as-loop
quit
ipv4-family vpn-instance R&D
peer 10.20.3.21 as 65004

Z_Export
bgp 65004
router-id 10.3.0.1
ipv4-family vpn-instance OA
peer 10.20.3.2 as 65000
peer 10.20.3.6 as 65000
peer 10.20.3.14 as 65000
peer 10.20.3.18 as 65000
network 10.3.101.0 24
quit
ipv4-family vpn-instance R&D
peer 10.20.3.10 as 65000
peer 10.20.3.22 as 65000
network 10.3.99.0 24
network 10.3.100.0 24

查看
dis bgp vpnv4 all peer

双点双向重分布
X_Export1
ospf 1
area 0
network 10.20.1.5 0.0.0.0

X_Export2
ospf 1
area 0
network 10.20.1.6 0.0.0.0

X_Export1
ospf 1
default cost inherit-metric tag 100
import-route bgp

ip ip-prefix Guest permit 10.1.101.0 24
ip ip-prefix Guest permit 10.1.102.0 24
ip ip-prefix Guest permit 10.1.103.0 24
ip ip-prefix Guest permit 10.1.104.0 24
ip ip-prefix Guest permit 10.1.105.0 24

route-policy o2b deny node 10
if-match tag 100

route-policy o2b deny node 20
if-match ip-prefix Guest

route-policy o2b permit node 30

bgp 65001
import-route ospf 1 route-policy o2b
preference 120 255 255

X_Export2
ospf 1
default cost inherit-metric tag 100
import-route bgp

ip ip-prefix Guest permit 10.1.101.0 24
ip ip-prefix Guest permit 10.1.102.0 24
ip ip-prefix Guest permit 10.1.103.0 24
ip ip-prefix Guest permit 10.1.104.0 24
ip ip-prefix Guest permit 10.1.105.0 24

route-policy o2b deny node 10
if-match tag 100

route-policy o2b deny node 20
if-match ip-prefix Guest

route-policy o2b permit node 30

bgp 65001
import-route ospf 1 route-policy o2b
preference 120 255 255

Y_Export1
ospf 2
default cost inherit-metric
import-route bgp

ospf 3
default cost inherit-metric
import-route bgp

ip ip-prefix deny_default deny 0.0.0.0 0
ip ip-prefix deny_default permit 0.0.0.0 0 less 32

bgp 65003
ipv4-family vpn-instance OA
import-route ospf 2
peer 10.20.2.2 ip-prefix deny_default export
peer 10.20.2.10 ip-prefix deny_default export
ipv4-family vpn-instance R&D
import-route ospf 3

流量负载调整三个区域OA的流量
X_PE2
route-policy MED permit node 10
apply cost 100

bgp 65000
ipv4-family vpn-instance OA
peer 10.20.1.9 route-policy MED export

Z_PE2
route-policy MED permit node 10
apply cost 100

bgp 65000
ipv4-family vpn-instance OA_In
peer 10.20.3.13 route-policy MED export

Y_PE2
route-policy MED permit node 10
apply cost 100

bgp 65000
ipv4-family vpn-instance OA
peer 10.20.2.9 route-policy MED export

调整R&D的流量负载
Z_PE1
route-policy MED permit node 10
apply cost 100

bgp 65000
ipv4-family vpn-instance R&D
peer 10.20.3.9 route-policy MED export

Y_PE1
route-policy MED permit node 10
apply cost 100

bgp 65000
ipv4-family vpn-instance R&D
peer 10.20.2.5 route-policy MED export

vpn frr部署
X_PE1
ip ip-prefix vpn_frr permit 5.0.0.5 32

route-policy vpn_frr permit node 10
if-match ip next-hop ip-prefix vpn_frr
apply backup-nexthop 6.0.0.6

ip vpn-instance OA
vpn frr route-policy vpn_frr

Y_PE1
ip ip-prefix vpn_frr permit 5.0.0.5 32

route-policy vpn_frr permit node 10
if-match ip next-hop ip-prefix vpn_frr
apply backup-nexthop 6.0.0.6

ip vpn-instance OA
vpn frr route-policy vpn_frr

验证
Y_PE1
dis ip routing-table vpn-instance R&D 10.3.99.0 verbose

X_Export1
tracert -a 10.1.0.1 10.100.2.1

QoS配置
Y_Export1
acl 3001
rule permit ip source 10.2.11.0 0.0.0.255 destination 10.3.99.0 0.0.0.255
rule permit ip source 10.2.11.0 0.0.0.255 destination 10.3.100.0 0.0.0.255
rule permit ip source 10.2.12.0 0.0.0.255 destination 10.3.99.0 0.0.0.255
rule permit ip source 10.2.12.0 0.0.0.255 destination 10.3.100.0 0.0.0.255
rule permit ip source 10.2.13.0 0.0.0.255 destination 10.3.99.0 0.0.0.255
rule permit ip source 10.2.13.0 0.0.0.255 destination 10.3.100.0 0.0.0.255
rule permit ip source 10.2.14.0 0.0.0.255 destination 10.3.99.0 0.0.0.255
rule permit ip source 10.2.14.0 0.0.0.255 destination 10.3.100.0 0.0.0.255
rule permit ip source 10.2.15.0 0.0.0.255 destination 10.3.99.0 0.0.0.255
rule permit ip source 10.2.15.0 0.0.0.255 destination 10.3.100.0 0.0.0.255

acl 3002
rule permit ip source 10.2.21.0 0.0.0.255 destination 10.3.99.0 0.0.0.255
rule permit ip source 10.2.21.0 0.0.0.255 destination 10.3.100.0 0.0.0.255
rule permit ip source 10.2.22.0 0.0.0.255 destination 10.3.99.0 0.0.0.255
rule permit ip source 10.2.22.0 0.0.0.255 destination 10.3.100.0 0.0.0.255
rule permit ip source 10.2.23.0 0.0.0.255 destination 10.3.99.0 0.0.0.255
rule permit ip source 10.2.23.0 0.0.0.255 destination 10.3.100.0 0.0.0.255
rule permit ip source 10.2.24.0 0.0.0.255 destination 10.3.99.0 0.0.0.255
rule permit ip source 10.2.24.0 0.0.0.255 destination 10.3.100.0 0.0.0.255
rule permit ip source 10.2.25.0 0.0.0.255 destination 10.3.99.0 0.0.0.255
rule permit ip source 10.2.25.0 0.0.0.255 destination 10.3.100.0 0.0.0.255

traffice classifier RD
if-match acl 3001

traffic classifier Production
if-match acl 3002

traffice behavior RD
remark dscp af41
gts cir 307200

traffice behavior Production
remark dscp ef
car cir 102400

traffic policy R&D
classifier RD behavior RD
classifier Production behavior Production

int g2/0/0.20
traffic-policy R&D outbound

int g2/0/1.20
traffic-policy R&D outbound

Y_PE1
drop-profile RD
wred dscp
dscp af41 low-limit 80 high-limit 100 discard-percentage 20

traffic classifier RD
if-match dscp af41

traffic classifier Production
if-match dscp ef

traffic behavior RD
queue af bandwidth 307200
drop-profile RD

traffic behavior Production
queue llq bandwidth 102400

traffic policy R&D
classifier RD behavior RD
classifier Production behavior Production

int g0/0/0
traffic-policy R&D outbound

int g0/0/02
traffic-policy R&D outbound

Y_PE2
drop-profile RD
wred dscp
dscp af41 low-limit 80 high-limit 100 discard-percentage 20

traffic classifier RD
if-match dscp af41

traffic classifier Production
if-match dscp ef

traffic behavior RD
queue af bandwidth 307200
drop-profile RD

traffic behavior Production
queue llq bandwidth 102400

traffic policy R&D
classifier RD behavior RD
classifier Production behavior Production

inter g0/0/0
traffic-policy R&D outbound

inter g0/0/2
traffic-policy R&D outbound

Z_PE1
drop-profile RD
wred dscp
dscp af41 low-limit 80 high-limit 100 discard-percentage 20

traffic classifier RD
if-match dscp af41

traffic classifier Production
if-match dscp ef

traffic behavior RD
queue af bandwidth 307200
drop-profile RD

traffic behavior Production
queue llq bandwidth 102400

traffic policy R&D
classifier RD behavior RD
classifier Production behavior Production

inter g0/0/0
traffic-policy R&D outbound

int g0/0/0.20
traffic-policy R&D outbound

Z_PE2
drop-profile RD
wred dscp
dscp af41 low-limit 80 high-limit 100 discard-percentage 20

traffic classifier RD
if-match dscp af41

traffic classifier Production
if-match dscp ef

traffic behavior RD
queue af bandwidth 307200
drop-profile RD

traffic behavior Production
queue llq bandwidth 102400

traffic policy R&D
classifier RD behavior RD
classifier Production behavior Production

inter g0/0/0
traffic-policy R&D outbound

int g0/0/0.20
traffic-policy R&D outbound

  • 15
    点赞
  • 18
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

项目工程师余工

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值