admin 发表于 2021-12-16 22:00:39

新华三H3C MSTP+VRRP综合配置

新华三H3C MSTP+VRRP综合配置


JRSW1<H3C>system-viewsysname jrsw1配置vlanvlan 10 20 //创建vlaninterface range GigabitEthernet 1/0/47 toGigabitEthernet 1/0/48//进入接口范围视图port link-type trunk//配置端口链路类型为trunkport trunk permit vlan 10 20//配置trunk放行的vlanundo port trunk permit vlan 1//取消trunk默认放行vlan1interface gigabitethernet 1/0/1port link-type access//配置端口链路类型为accessport access vlan 10//配置access默认vlanquitport link-type accessport access vlan 20quit配置多生成树stp mode mstp //配置生成树模式为多生成树stp region-configuration//进入生成树区域配置region-name vrrp//配置区域名称revision-level 1//修订级别为1instance 10 vlan 10//配置实例10映射vlan10instance 20 vlan 20//配置实例20映射vlan20active region-configuration//激活区域配置quitstp global enable//开启全局生成树 JRSW2<H3C>system-viewsysname jrsw2vlan 10 20interface range gigabitethernet 1/0/47 togigabitethernet 1/0/48port link-type trunkport trunk permit vlan 10 20undo port trunk permit vlan 1interface gigabitethernet 1/0/1port link-type accessport access vlan 20interface gigabitethernet1/0/2port link-type accessport access vlan 10quitstp mode mstpstp region-configurationregion-name vrrprevision-level 1instance 10 vlan 10instance 20 vlan 20active region-configurationquitstp global enable HJSW1创建VLAN划分接口vlan 10vlan 20vlan 100quitinterface range gigabitethernet 1/0/3 togigabitethernet 1/0/4port link-type trunkport trunk permit vlan 10 20undo port trunk permit vlan 1 quitinterface gigabitethernet 1/0/48port link-type accessport access vlan 100quit创建二层链路聚合接口1lacp system-priority 100//配置交换机链路聚合控制协议的优先级为100;越小优先级越高,默认为32768。interface bridge-aggregation 1//创建二层桥聚合接口link-aggregation modedynamic//链路聚合模式为动态link-aggregationselected-port maximum 2//配置链路聚合最大限度选择两个端口quit接口加入聚合接口interface range GigabitEthernet 1/0/10 toGigabitEthernet 1/0/12port link-aggregation group 1//端口加入链路聚合组quitinterface range gigabitethernet 1/0/10 togigabitethernet 1/0/11link-aggregation port-priority 100//配置链路聚合端口优先级为100quit配置聚合口为Trunk口,并配置放行VLANinterface bridge-aggregation 1//进入二层桥聚合接口port link-type trunkport trunk permit vlan 1020undo port trunk permit vlan1quit配置上行接口interface vlan-interface 100//进入逻辑三层接口vlanif100ip address 172.16.100.2 24//配置接口地址创建Track项1,监视上行接口的物理状态track 1 interface vlan-interface 100//配置对上行vlanif100接口进行跟踪quit创建vrrp组10,配置HJSW1在备份组1中的优先级为110interface vlan-interface 10ip address 192.168.10.2 24vrrp vrid 10 virtual-ip192.168.10.1//接口加入vrrp并配置虚拟网关地址vrrp vrid 10 priority 110//配置vrrp的优先级(默认100)数值大为master配置vrrp备份组1监视track项1的状态,当Track项上行down掉时,HJSW1在备份组中的优先级降低20;使得HJSW2的优先组高于1,成为新Master。vrrp vrid 10 track 1 weightreduced 20//配置当上行链路down掉时,将vrrp优先级降低20,即110-20=90,低于对端100,即对端成为masterquit创建vrrp组20interface vlan-interface 20ip address 192.168.20.2 24vrrp vrid 20 virtual-ip 192.168.20.1quit配置MSTPstp mode mstpstp region-configurationregion-name vrrprevision-level 1instance 10 vlan 10instance 20 vlan 20active region-configurationquitstp instance 10 root primarystp instance 20 root secondarystp global enable
在上行口关闭STP功能interface gigabitethernet 1/0/48undo stp enablequit配置OSPF发布网段路由ospfarea 0network 172.16.100.00.0.0.255network 192.168.10.00.0.0.255network 192.168.20.00.0.0.255network 101.101.101.1010.0.0.255quitquit   配置默认路由ip route-static 0.0.0.0 0.0.0.0 172.16.100.1配置DHCP中继dhcp enable //开启dhcp功能interface vlan-interface 10dhcp select relay//接口选择dhcp中继dhcp relay server-address172.16.100.1//配置中继dhcp的服务地址interface vlan-interface 20dhcp select relaydhcp relay server-address172.16.100.1quit配置环回口作为管理地址及配置管理功能telnet server enable//开启telnet远程ip address 101.101.101.101 32quituser-interface vty 0 4//进入vty用户视图authentication-mode scheme//配置身份认证模式为计划(AAA)quitlocal-user zurkj//创建本地用户password simple Aleadmin1234//配置用户密码(简单)authorization-attributeuser-role network-admin//配置授权属性 用户角色为网络管理员(level 15)service-type telnet terminal//配置服务类型为telnet及终端(console)quituser-interface console 0//进入consoleauthentication-mode scheme quit配置登录设备头部信息header login "Welcome to ipgzj.com"header shell "Welcome to zurkj.com"开启telnet远程服务telnet server enable HJSW2创建VLAN划分接口<H3C>system-viewsysname hjsw2vlan 10vlan 20vlan 101quitinterface range gigabitethernet 1/0/3 togigabitethernet 1/0/4port link-type trunkport trunk permit vlan 10 20undo port trunk permit vlan 1interface gigabitethernet 1/0/48port link-type trunkport trunk pvid vlan 101port trunk permit vlan101undo port trunk permitvlan 1undo stp enablequit创建二层链路聚合接口1interface bridge-aggregation 1link-aggregation modedynamiclink-aggregationselected-port maximum 2接口加入聚合接口interface rangegigabitethernet 1/0/10 to gigabitethernet 1/0/12port link-aggregation group 1quit配置聚合口为Trunk口,并配置放行VLANinterface Bridge-Aggregation 1port link-type trunkport trunk permit vlan 1020undo port trunk permit vlan1quit配置上行接口interface vlan-interface 101ip address 172.16.101.2 24quit创建Track项1,监视上行接口的物理状态track 1 interface vlan-interface 101quit创建vrrp组10,配置HJSW2在备份组10中的优先级为默认100interface vlan-interface 10ip address 192.168.10.3 24vrrp vrid 10 virtual-ip192.168.10.1quit创建vrrp组20,配置HJSW2在备份组20中的优先级为110interface vlan-interface 20ip address 192.168.20.3 24vrrp vrid 20 virtual-ip192.168.20.1vrrp vrid 20 priority 110配置vrrp备份组20监视track项1的状态,当Track项上行down掉时,HJSW2在备份组中的优先级降低20;使得HJSW2的优先组高于HJSW1,成为新Master。vrrp vrid 20 track 1 weightreduced 20quit配置MSTPstp mode mstpstp region-configurationregion-name vrrprevision-level 1instance 10 vlan 10instance 20 vlan 20active region-configurationstp instance 10 root secondarystp instance 20 root primarystp global enable在上行口关闭STP功能interface GigabitEthernet 1/0/48undo stp enablequit配置OSPF发布网段路由ospf 1area 0network 192.168.10.00.0.0.255network 192.168.20.00.0.0.255network 172.16.101.00.0.0.255network 102.102.102.1020.0.0.0quitquit配置默认路由ip route-static 0.0.0.0 0.0.0.0 172.16.101.1配置DHCP中继dhcp enableinterface vlan-interface 10dhcp select relaydhcp relay server-address 172.16.101.1interface vlan-interface 20dhcp select relaydhcp relay server-address172.16.101.1quit配置环回口作为管理地址及配置管理功能interface loopback 0ip address 102.102.102.102 32quituser-interface vty 0 4authentication-mode schemequituser-interface console 0authentication-mode schemequitlocal-user zurkjpassword simple Admin1234service-type telnet terminalauthorization-attributeuser-role network-adminquit配置登录设备头部信息header login "Welcome to ipgzj.com"header shell "Welcome to zurkj.com"开启telnet远程服务telnet server enable R1基本配置<H3C>system-viewsysname r1interface gigabitethernet 0/0ip address 172.16.100.1 24interface gigabitethernet 0/1ip address 172.16.101.1 24quitinterface gigabitethernet 0/2ip address 200.1.1.2 24quitinterface LoopBack 0ip address 100.100.100.100 32quit配置DHCP服务dhcp enabledhcp server ip-pool vlan10network 192.168.10.0 mask255.255.255.0dns-list 114.114.114.114 8.8.8.8expired day 2 hour 2 minute 2second 2forbidden-ip-range 192.168.10.200192.168.10.254quitdhcp server ip-pool vlan20gateway-list 192.168.20.1network 192.168.20.0 mask255.255.255.0dns-list 114.114.114.114 8.8.8.8expired day 2 hour 2 minute 2second 2forbidden-ip-range 192.168.20.200192.168.20.254quit接口应用DHCPinterface GigabitEthernet 0/0dhcp select serverinterface gigabitethernet 0/1dhcp select serverquit配置OSPFospf 1area 0network 172.16.100.0 0.0.0.255network 172.16.200.0 0.0.0.255network 100.100.100.100 0.0.0.0quitquit配置默认路由ip route-static 0.0.0.0 0.0.0.0 200.1.1.2nat address-group 1address 200.1.1.10 200.1.1.20quit配置NAT转换acl number 2000step 20rule 20permit source anyinterface gigabitethernet 0/2nat outbound address-group 1quit配置设备管理用户user-interface vty 0 4authentication-mode schemequituser-interface console 0authentication-mode schemequitlocal-user zurkjpassword simple Admin1234service-type telnet terminalauthorization-attributeuser-role network-adminquit打开远程服务telnet server enable Network<H3C>system-viewsysname networkinterface gigabitethernet 0/0ip address 200.1.1.1 24interface loopback 0ip address 200.200.200.200 32quit

页: [1]
查看完整版本: 新华三H3C MSTP+VRRP综合配置

公司网站