6、ospf三區(qū)域分部1SW1SW2SW3運(yùn)行MSTP,SW1和SW2VRR_第1頁(yè)
6、ospf三區(qū)域分部1SW1SW2SW3運(yùn)行MSTP,SW1和SW2VRR_第2頁(yè)
6、ospf三區(qū)域分部1SW1SW2SW3運(yùn)行MSTP,SW1和SW2VRR_第3頁(yè)
6、ospf三區(qū)域分部1SW1SW2SW3運(yùn)行MSTP,SW1和SW2VRR_第4頁(yè)
6、ospf三區(qū)域分部1SW1SW2SW3運(yùn)行MSTP,SW1和SW2VRR_第5頁(yè)
已閱讀5頁(yè),還剩28頁(yè)未讀 繼續(xù)免費(fèi)閱讀

下載本文檔

版權(quán)說(shuō)明:本文檔由用戶(hù)提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)

文檔簡(jiǎn)介

1、OSPF 三區(qū)域+分部拓?fù)湫枨?、SW1,SW2,SW3運(yùn)行 MSTP,SW1 和 SW2 運(yùn)行 VRRP 并采用認(rèn)證保證安全性。A 業(yè)務(wù)主走 SW1,非 A 業(yè)務(wù)主走 SW2。2、SW1 與 SW2 之間采用鏈路聚合保證可靠性。3、總部與分支運(yùn)行 OSPF 路由協(xié)議:總部區(qū)域 1。交換機(jī) SW1 和 SW2 的所有接口,SW1 與 R1 的互聯(lián)接口,SW2 與 R2 的互聯(lián)接口在R1,R2 的Lo R3,R4 的Lo域 100ack 接口,R1 與 R2 的互聯(lián)接口,R1 與 R3,R1 與 R4 的互聯(lián)接口均在區(qū)域 0 ack 接口,R3 與 R4 的互聯(lián)接口,R3 于 SW4,R4 與

2、SW4 的互聯(lián)接口均在區(qū)4、為減少分支的路由條目, 區(qū)域 100 設(shè)置為 STUB 區(qū)域5、總部與分支通過(guò)電信和的線(xiàn)路互聯(lián)。電信鏈路為 PPP 專(zhuān)線(xiàn),并采用 chap 雙向認(rèn)證。為雙鏈路采用 PPP(MP-GROUP)不需要認(rèn)證。6、SW5 模擬ernet,總部與辦事處之間采用 GRE over IPSEC 保護(hù) A 業(yè)務(wù)的數(shù)據(jù)流,在 R1在使用策略模板。7、總部與辦事處之間運(yùn)行 RIP 路由協(xié)議。8、在 R1 上做靜態(tài)路由,一條為到所有辦事處 A 業(yè)務(wù)的聚合路由,一條為到總部和分支 A業(yè)務(wù)的聚合路由,下一跳均為 NULL。且都引入到 ospf 和 rip 中。9、為保證總部與辦事處互訪(fǎng),在

3、R1 對(duì) rip 路由和 ospf 路由做雙向引入。10、總部與分支所有業(yè)務(wù)可以互訪(fǎng),辦事處與總部,分支只允許 A 業(yè)務(wù)互訪(fǎng)。辦事處之間的 A 業(yè)務(wù)可以互訪(fǎng)。11、通過(guò)修改 OSPFcost 值,當(dāng)所有鏈路正常時(shí),總部與分支業(yè)務(wù)互訪(fǎng)走,當(dāng)斷了,只在電信鏈業(yè)務(wù)路由)保證 A 業(yè)務(wù)的傳輸。(提示:使用 ospf 路由聚合使總部學(xué)習(xí)不到分支的非 A12、所有業(yè)務(wù)網(wǎng)段不應(yīng)該出現(xiàn)協(xié)議報(bào)文。OSPF 區(qū)域不能出現(xiàn) RIP 的協(xié)議報(bào)文。13、全網(wǎng)除了 SW5,其他設(shè)備都可。14、在鏈采用 QOS 保證業(yè)務(wù) A 傳輸帶寬最少為 128K15、適當(dāng)修改 COST 值,使全網(wǎng)不能出現(xiàn)等價(jià)路由。雙塔奇兵,物理接口不

4、變;創(chuàng)建一個(gè)子接口封裝 802.1q。分配地址總部雙塔奇兵是從 RT2 轉(zhuǎn)發(fā)走鏈路,sw1 將路由信息交給了 RT1,按照 ospf 的 spf 算法,rt1 直接通過(guò) 3 類(lèi)型的 lsa 將路由交給電信鏈路,不走 RT2.解決辦法在 rt1 和 rt2 加子接口將子接口發(fā)布在 area1 中,通過(guò) type1 類(lèi)型路由將出路由交給 RT2.或在 sw1 和 sw2 上用import direct 方式,讓 rt2 學(xué)習(xí)到的路由都是 type5 類(lèi)型的路由不受三類(lèi)型的影響。分支當(dāng) RT4 和 SW4 斷開(kāi),業(yè)務(wù) b 的路由交給了 RT3,RT3 不會(huì)將路由交給 RT4,按照 ospf的 lsa

5、 先交給骨干區(qū)域,所以讓 RT3 和 RT4 做子接口,讓它也為骨干路由回程,解決這個(gè)問(wèn)題,也可用虛連接來(lái)學(xué)習(xí)。#配置Rt1#sysname rt1#ike local-name rt1#router id 1.1.1.1#net server enable#ip ttl-expires enableip unreachables enable#acl number 2000rule 0 permit source 192.168.0.0 0.0.255.255#ike peer rt5exchange-mode aggressivepre-shared-key cipher TEzJOUGC

6、muE= id-type nameremote-name rt5#ipsec pro#al rt5ipsec policy-template rt5 1ike-peer rt5proal rt5#ipsec policy rt55 1 isakmp template rt5 #local-user adminpassword simple adminauthorization-attribuevel 3service-typelocal-user rt3netpassword simple rt3service-type ppp#erfaerial0/2/0link-protocol pppp

7、pp authentication-mode chap ppp chap user rt1ppp chap password simple rt1ip address 10.0.0.5 255.255.255.252ospf cost 1000#erface Loack0ip address 1.1.1.1 255.255.255.255#erface Loack1ip address 30.0.0.1 255.255.255.255#erface GigabitEthernet0/1/0port link-mode routeip address 10.0.0.1 255.255.255.2

8、52#erface GigabitEthernet0/1/0.1vlan-type dot1q vid 100ip address 11.0.0.1 255.255.255.252#erface GigabitEthernet0/1/1port link-mode routeip address 10.0.0.25 255.255.255.252#erface GigabitEthernet0/1/2port link-mode routeip address 10.0.0.33 255.255.255.252ipsec policy rt55#erface Tunnel1ip address

9、 20.0.1.1 255.255.255.252source Loack1destination 30.0.0.2keepalive 10 3#ospf 1import-route sic import-route rip 1area 0.0.0.0network 1.1.1.1 0.0.0.0network 10.0.0.0 0.0.0.3network 10.0.0.4 0.0.0.3area 0.0.0.1network 10.0.0.24 0.0.0.3network 11.0.0.1 0.0.0.0#rip 1undo summaryver2network 20.0.0.0sile

10、nt-silent- silent-erfaerial0/2/0erface GigabitEthernet0/1/1erface GigabitEthernet0/1/0import-route sicimport-route ospf 1 route-policy 1#route-policy 1 permit node 1if-match acl 2000#ip route-sic 0.0.0.0 0.0.0.0 10.0.0.34ip route-sip route-s ip route-sic 20.0.0.0 255.255.255.0 10.0.0.34ic 192.168.0.

11、0 255.255.0.0 NULL0ic 192.168.0.0 255.255.252.0 NULL0 disp ip routing-tableRouting Tables: PublicDestinations : 34Routes : 34Destination/MaskProtoPreCostNextHoperface0.0.0.0/01.1.1.1/322.2.2.2/323.3.3.3/324.4.4.4/3210.0.0.0/3010.0.0.1/3210.0.0.4/3010.0.0.5/3210.0.0.6/3210.0.0.8/3010.0.0.12/3010.0.0.

12、16/3010.0.0.20/3010.0.0.24/3010.0.0.25/3210.0.0.28/3010.0.0.32/3010.0.0.33/3211.0.0.0/3011.0.0.1/3220.0.0.0/2420.0.1.0/3020.0.1.1/3230.0.0.1/32127.0.0.0/8127.0.0.1/32172.16.1.0/24172.16.2.1/32192.168.0.0/16192.168.0.0/22192.168.1.0/24192.168.2.1/32192.168.3.1/32Sic 60Direct 0 OSPF OSPF OSPFDirect 0D

13、irect 0Direct 0Direct 0Direct 0 OSPF OSPF OSPF OSPFDirect 0Direct 0 OSPFDirect 0Direct 0Direct 0Direct 0Sic 60Direct 0Direct 0Direct 0Direct 0Direct 0 OSPF OSPFSic 60Sic 60 OSPF OSPF0010.0.0.34127.0.0.110.0.0.210.0.0.210.0.0.210.0.0.1127.0.0.110.0.0.5127.0.0.110.0.0.610.0.0.210.0.0.210.0.0.210.0.0.2

14、10.0.0.25127.0.0.111.0.0.210.0.0.33127.0.0.111.0.0.1127.0.0.110.0.0.3420.0.1.1127.0.0.1127.0.0.1127.0.0.1127.0.0.111.0.0.210.0.0.20.0.0.00.0.0.010.0.0.2610.0.0.220.0.1.2GE0/1/2InLoop0 GE0/1/0 GE0/1/0 GE0/1/0GE0/1/0InLoop0 S0/2/0 InLoop0 S0/2/0GE0/1/0 GE0/1/0 GE0/1/0 GE0/1/0GE0/1/1InLoop0 GE0/1/0.1GE

15、0/1/2InLoop0 GE0/1/0.1InLoop0 GE0/1/2Tun1 InLoop0 InLoop0 InLoop0 InLoop0GE0/1/0.1 GE0/1/0NULL0 NULL0GE0/1/1 GE0/1/0Tun110101013200000101010103832001020000000000101033001010231RIP100die satotal phase-1 SAs:1connection-idpeerflagphase12820.0.0.25320.0.0.253RDRD21IPSECIPSECflag meaningRD-READY ST-STAY

16、ALIVE RL-REPLACED FD-FADING TO-TIMEOUTdisp ipsec sa=erface: GigabitEthernet0/1/2 path MTU: 1500=IPsec policy name: rt55sequence number: 1 mode: templateconnection id: 6encapsulation mode: tunnel perfect forward secrecy:tunnel:localaddress: 10.0.0.33remote address: 20.0.0.253 flow:sour addr: 30.0.0.1

17、/255.255.255.255dest addr: 30.0.0.2/255.255.255.255port: 0protocol: IPport: 0protocol: IPinbound ESP SAsspi: 1298632742 (0 x4d679026)proal: ESP-ENCRYPT-DES ESP-AUTH-MD5sa duration (kilobytes/sec): 1843200/3600sa remaining duration (kilobytes/sec): 1843187/2513 max received sequence-number: 248anti-r

18、eplay check enable: Y anti-replay window size: 32udp encapsulation used for nat traversal: Noutbound ESP SAsspi: 3117657473 (0 xb9d3ad81)proal: ESP-ENCRYPT-DES ESP-AUTH-MD5sa duration (kilobytes/sec): 1843200/3600sa remaining duration (kilobytes/sec): 1843184/2513max received sequence-number: 254udp

19、 encapsulation used for nat traversal: Nrt2#sysname rt2#router id 2.2.2.2#net server enable#ip ttl-expires enableip unreachables enable#acl number 2000rule 0 permit source 192.168.0.0 0.0.255.255#traffic classifier a operator and if-match acl 2000#traffic behavior aqueue af bandwidth 128#qos policy

20、aclassifier a behavior a#local-user admin password simple adminauthorization-attribuevel 3service-typenet#erfaerial0/2/0link-protocol pppppp mp Mp-group 1#erfaerial0/2/1link-protocol pppppp mp Mp-group 1#erface Mp-group1qos max-bandwidth 4000ip address 10.0.0.22 255.255.255.252ospf cost 1qos apply p

21、olicy a outbound#erface Loack0ip address 2.2.2.2 255.255.255.255#erface GigabitEthernet0/1/0port link-mode routeip address 10.0.0.2 255.255.255.252#erface GigabitEthernet0/1/0.1vlan-type dot1q vid 100ip address 11.0.0.2 255.255.255.252#erface GigabitEthernet0/1/1port link-mode routeip address 10.0.0

22、.29 255.255.255.252#ospf 1area 0.0.0.0network 2.2.2.2 0.0.0.0network 10.0.0.0 0.0.0.3network 10.0.0.20 0.0.0.3area 0.0.0.1network 10.0.0.28 0.0.0.3network 11.0.0.2 0.0.0.0disp ip routing-table Routing Tables: PublicDestinations : 28Routes : 28Destination/MaskProtoPreCostNextHoperface1.1.1.1/322.2.2.

23、2/323.3.3.3/324.4.4.4/3210.0.0.0/3010.0.0.2/3210.0.0.4/3010.0.0.8/3010.0.0.12/30OSPFDirect 0 OSPF OSPFDirect 0Direct 0 OSPF OSPF OSPF10110.0.0.1127.0.0.110.0.0.2110.0.0.2110.0.0.2127.0.0.110.0.0.110.0.0.2110.0.0.21GE0/1/0InLoop0Mp-group1 Mp-group1GE0/1/0InLoop0 GE0/1/0Mp-group1Mp-group10101021001010

24、1010012710.0.0.16/3010.0.0.20/3010.0.0.21/3210.0.0.22/3210.0.0.24/3010.0.0.28/3010.0.0.29/3211.0.0.0/3011.0.0.2/3220.0.0.0/24127.0.0.0/8127.0.0.1/32172.16.1.0/24172.16.2.1/32192.168.0.0/16192.168.0.0/22192.168.1.0/24192.168.2.1/32192.168.3.1/32OSPFDirect 0Direct 0Direct 0 OSPFDirect 0Direct 0Direct

25、0Direct 0 O_ASEDirect 0Direct 0 OSPF OSPF O_ASE O_ASE OSPF OSPF O_ASE10210.0.0.2110.0.0.2210.0.0.21127.0.0.111.0.0.110.0.0.29127.0.0.111.0.0.2127.0.0.111.0.0.1127.0.0.1127.0.0.110.0.0.3010.0.0.2111.0.0.111.0.0.111.0.0.110.0.0.2111.0.0.1Mp-group1Mp-group1 Mp-group1 InLoop0GE0/1/0.1 GE0/1/1InLoop0 GE0

26、/1/0.1InLoop0GE0/1/0.1InLoop0 InLoop0GE0/1/1Mp-group1 GE0/1/0.1 GE0/1/0.1 GE0/1/0.1Mp-group1GE0/1/0.10001020000150001010150150101015012211321rt3#sysname rt3#router id 3.3.3.3#net server enable#ip ttl-expires enableip unreachables enable#local-user admin password simple admin authorization-attribueve

27、l 3service-typelocal-user rt1netpassword simple rt1service-type ppp#erfaerial0/2/0link-protocol pppppp authentication-mode chap ppp chap user rt3ppp chap password simple rt3ip address 10.0.0.6 255.255.255.252ospf cost 1000#erface Loack0ip address 3.3.3.3 255.255.255.255#erface GigabitEthernet0/1/0po

28、rt link-mode routeip address 10.0.0.9 255.255.255.252#erface GigabitEthernet0/1/1port link-mode routeip address 10.0.0.13 255.255.255.252ospf cost 5#ospf 1area 0.0.0.0network 10.0.0.4 0.0.0.3area 0.0.0.100abr-summary 172.16.2.0 255.255.255.0 not-advertisenetwork 10.0.0.8 0.0.0.3network 10.0.0.12 0.0

29、.0.3network 3.3.3.3 0.0.0.0 stub#nqa entry admtype icmp-echoestdestination ip 10.0.0.22frequency 100reaction 1 checked-element probe-fail threshold-type consecutive 3 action-type trigger-only#ip route-sip route-s ip route-s ip route-sic 192.168.0.0 255.255.0.0 10.0.0.10 track 1 preference 6ic 192.16

30、8.0.0 255.255.252.0 10.0.0.10 track 1 preference 6ic 192.168.1.0 255.255.255.0 10.0.0.10 track 1 preference 6ic 192.168.3.1 255.255.255.255 10.0.0.10 track 1 preference 6#track 1 nqa entry admest reaction 1#nqa schedule admest start-time now lifetime foreverrt3 disp ip routing-tableRouting Tables: P

31、ublicDestinations : 27Routes : 27Destination/MaskProtoPreCostNextHoperface1.1.1.1/322.2.2.2/323.3.3.3/324.4.4.4/3210.0.0.0/3010.0.0.4/3010.0.0.5/3210.0.0.6/3210.0.0.8/3010.0.0.9/3210.0.0.12/3010.0.0.13/3210.0.0.16/3010.0.0.20/3010.0.0.24/3010.0.0.28/3011.0.0.0/3020.0.0.0/24127.0.0.0/8127.0.0.1/32172

32、.16.1.0/24172.16.2.1/32192.168.0.0/16192.168.0.0/22192.168.1.0/24192.168.2.1/32192.168.3.1/32OSPFOSPFDirect 0 OSPF OSPFDirect 0Direct 0Direct 0Direct 0Direct 0Direct 0Direct 0 OSPF OSPF OSPF OSPF OSPF O_ASEDirect 0Direct 0 OSPF OSPF10101000100110.0.0.510.0.0.5127.0.0.110.0.0.1010.0.0.510.0.0.610.0.0

33、.5127.0.0.110.0.0.9127.0.0.110.0.0.13127.0.0.110.0.0.1010.0.0.510.0.0.510.0.0.510.0.0.510.0.0.5127.0.0.1127.0.0.110.0.0.510.0.0.1010.0.0.1010.0.0.1010.0.0.1010.0.0.1010.0.0.10S0/2/0S0/2/0 InLoop0GE0/1/0S0/2/0 S0/2/0 S0/2/0 InLoop0 GE0/1/0InLoop0 GE0/1/1InLoop0 GE0/1/0S0/2/0 S0/2/0 S0/2/0 S0/2/0 S0/2

34、/0InLoop0 InLoop0S0/2/0 GE0/1/0GE0/1/0 GE0/1/0 GE0/1/0GE0/1/0GE0/1/001010110010000000101010101015000101000010021002100110021001110032SS Sic 6ic 6ic 6OSPFSic 62rt4#sysname rt4#router id 4.4.4.4#net server enable#ip ttl-expires enableip unreachables enable#acl number 2000rule 0 permit source 192.168.2

35、.0 0.0.0.255#traffic classifier a operator and if-match acl 2000#traffic behavior aqueue af bandwidth 128#qos policy aclassifier a behavior a#local-user admin password simple adminauthorization-attribuevel 3service-typenet#erfaerial0/2/0link-protocol pppppp mp Mp-group 1#erfaerial0/2/1link-protocol

36、pppppp mp Mp-group 1#erface Mp-group1qos max-bandwidth 4000ip address 10.0.0.21 255.255.255.252ospf cost 1qos apply policy a outbound#erface Loack0ip address 4.4.4.4 255.255.255.255port link-mode bridge#erface GigabitEthernet0/1/0port link-mode routeip address 10.0.0.10 255.255.255.252#erface Gigabi

37、tEthernet0/1/1port link-mode routeip address 10.0.0.18 255.255.255.252#ospf 1area 0.0.0.0network 10.0.0.20 0.0.0.3area 0.0.0.100network 10.0.0.8 0.0.0.3network 10.0.0.16 0.0.0.3network 4.4.4.4 0.0.0.0 stubrt4 disp ip routing-table Routing Tables: PublicDestinations : 27Routes : 27Destination/MaskPro

38、toPreCostNextHoperface1.1.1.1/322.2.2.2/323.3.3.3/324.4.4.4/3210.0.0.0/3010.0.0.4/3010.0.0.8/3010.0.0.10/3210.0.0.12/3010.0.0.16/3010.0.0.18/3210.0.0.20/3010.0.0.21/3210.0.0.22/3210.0.0.24/3010.0.0.28/3011.0.0.0/3020.0.0.0/24127.0.0.0/8127.0.0.1/32172.16.1.0/24172.16.2.1/32192.168.0.0/16192.168.0.0/

39、22192.168.1.0/24192.168.2.1/32192.168.3.1/32OSPFOSPF OSPFDirect 0 OSPF OSPFDirect 0Direct 0 OSPFDirect 0Direct 0Direct 0Direct 0Direct 0 OSPF OSPF OSPF O_ASEDirect 0Direct 0 OSPF OSPF O_ASE O_ASE OSPF OSPF O_ASE10101021110.0.0.2210.0.0.2210.0.0.9127.0.0.110.0.0.2210.0.0.2210.0.0.10127.0.0.110.0.0.91

40、0.0.0.18127.0.0.110.0.0.21127.0.0.110.0.0.2210.0.0.2210.0.0.2210.0.0.2210.0.0.22127.0.0.1127.0.0.110.0.0.2210.0.0.1710.0.0.2210.0.0.2210.0.0.2210.0.0.1710.0.0.22Mp-group1Mp-group1 GE0/1/0InLoop0Mp-group1 Mp-group1GE0/1/0InLoop0 GE0/1/0GE0/1/1InLoop0 Mp-group1 InLoop0 Mp-group1Mp-group1 Mp-group1 Mp-

41、group1 Mp-group1InLoop0 InLoop0Mp-group1 GE0/1/1Mp-group1 Mp-group1 Mp-group1 GE0/1/1Mp-group101010210020010600000101010150001010150150101032213111411501rt5#sysname rt5#ike local-name rt5#router id 5.5.5.5#net server enable#ip ttl-expires enableip unreachables enable#acl number 3000rule 0 permit ip

42、source 30.0.0.2 0 destination 30.0.0.1 0#ike peer rt1exchange-mode aggressivepre-shared-key cipher TEzJOUGCmuE= id-type nameremote-name rt1remote-address 10.0.0.33#ipsec pro#al rt1ipsec policy rt1 1 isakmpsecurity acl 3000 ike-peer rt1proal rt1#local-user admin password simple admin authorization-at

43、tribu service-typenet#evel 3erface Loack0ip address 5.5.5.5 255.255.255.255#erface Loack1ip address 30.0.0.2 255.255.255.255#erface Loack11ip address 192.168.3.1 255.255.255.255#erface GigabitEthernet0/1/0port link-mode route ip address dhcp-alloc ipsec policy rt1#erface Tunnel1ip address 20.0.1.2 2

44、55.255.255.252source Loack1destination 30.0.0.1keepalive 10 3#rip 1undo summaryver2network 192.168.3.0network 20.0.0.0#ip route-sic 0.0.0.0 0.0.0.0 20.0.0.254 disp ip routing-table Routing Tables: PublicDestinations : 14Routes : 14Destination/MaskProtoPreCostNextHoperface0.0.0.0/05.5.5.5/3220.0.0.0/

45、2420.0.0.253/3220.0.1.0/3020.0.1.2/3230.0.0.2/32127.0.0.0/8127.0.0.1/32192.168.0.0/16192.168.0.0/22192.168.1.0/24192.168.2.1/32192.168.3.1/32Sic 60Direct 0Direct 0Direct 0Direct 0Direct 0Direct 0Direct 0Direct 000000000020.0.0.254127.0.0.120.0.0.253127.0.0.120.0.1.2127.0.0.1127.0.0.1127.0.0.1127.0.0

46、.120.0.1.120.0.1.120.0.1.120.0.1.1127.0.0.1GE0/1/0InLoop0 GE0/1/0InLoop0 Tun1 InLoop0 InLoop0 InLoop0 InLoop0Tun1 Tun1 Tun1 Tun1InLoop0RIPRIP RIP RIPDirect 010010010010011110die satotal phase-1 SAs:1connection-idpeerflagphase181410.0.0.3310.0.0.33RD|STRD|ST21IPSECIPSECflag meaningRD-READY ST-STAYALI

47、VE RL-REPLACED FD-FADING TO-TIMEOUTdisp ipsec sa=erface: GigabitEthernet0/1/0 path MTU: 1500=IPsec policy name: rt1sequence number: 1 mode: isakmpconnection id: 7encapsulation mode: tunnel perfect forward secrecy:tunnel:localaddress: 20.0.0.253remote address: 10.0.0.33 flow:sour addr: 30.0.0.2/255.2

48、55.255.255dest addr: 30.0.0.1/255.255.255.255port: 0protocol: IPport: 0protocol: IPinbound ESP SAsspi: 3117657473 (0 xb9d3ad81)proal: ESP-ENCRYPT-DES ESP-AUTH-MD5sa duration (kilobytes/sec): 1843200/3600sa remaining duration (kilobytes/sec): 1843182/2426 max received sequence-number: 280anti-replay

49、check enable: Y anti-replay window size: 32udp encapsulation used for nat traversal: Noutbound ESP SAsspi: 1298632742 (0 x4d679026)proal: ESP-ENCRYPT-DES ESP-AUTH-MD5sa duration (kilobytes/sec): 1843200/3600sa remaining duration (kilobytes/sec): 1843186/2426 max received sequence-number: 276udp enca

50、psulation used for nat traversal: Nsw1#sysname sw1#router id 6.6.6.6#net server enable#ip ttl-expires enableip unreachables enable#vlan 11 to 12 #local-user adminpassword simple admin authorization-attribuevel 3service-typenet#stp instance 1 root primarystp instance 2 root secondary stp enablestp re

51、gion-configuration region-name h3c instance 1 vlan 11instance 2 vlan 12active region-configuration#erface Loack0ip address 6.6.6.6 255.255.255.255#erface Vlan-erface11ip address 192.168.1.252 255.255.255.0vrrp vrid 1 virtual-ip 192.168.1.254vrrp vrid 1 priority 120vrrp vrid 1 timer advertise 10vrrp

52、vrid 1 trackerface GigabitEthernet0/1/1 reduced 30vrrp vrid 1 authentication-mode simple h3c#erface Vlan-erface12ip address 172.16.1.252 255.255.255.0ospf cost 100vrrp vrid 2 virtual-ip 172.16.1.254vrrp vrid 2 timer advertise 10vrrp vrid 2 authentication-mode simple h3c#erface Bridge-Aggregation1por

53、t link-type trunkport trunk permit vlan 1 11 to 12 #erface Ethernet0/4/0 port link-mode bridge port link-type trunkport trunk permit vlan 1 11 to 12 port link-aggregation group 1#erface Ethernet0/4/1 port link-mode bridge port link-type trunkport trunk permit vlan 1 11 to 12 port link-aggregation gr

54、oup 1#erface Ethernet0/4/2 port link-mode bridge port link-type trunkport trunk permit vlan 1 11 to 12#erface GigabitEthernet0/1/1 port link-mode routeip address 10.0.0.26 255.255.255.252#ospf 1silent- erface Vlan- erface11 silent- erface Vlan- erface12 area 0.0.0.1network 10.0.0.0 0.0.0.255network

55、172.16.1.252 0.0.0.0network 192.168.1.252 0.0.0.0disp ip routing-table Routing Tables: PublicDestinations : 28Routes : 28Destination/MaskProtoPreCostNextHoperface1.1.1.1/322.2.2.2/323.3.3.3/32OSPFOSPF OSPF10101012410.0.0.2510.0.0.2510.0.0.25GE0/1/1GE0/1/1 GE0/1/14.4.4.4/326.6.6.6/3210.0.0.0/3010.0.0

56、.4/3010.0.0.8/3010.0.0.12/3010.0.0.16/3010.0.0.20/3010.0.0.24/3010.0.0.26/3210.0.0.28/3011.0.0.0/3020.0.0.0/24127.0.0.0/8127.0.0.1/32172.16.1.0/24172.16.1.252/32172.16.2.1/32192.168.0.0/16192.168.0.0/22192.168.1.0/24192.168.1.252/32192.168.1.254/32192.168.2.1/32192.168.3.1/32OSPFDirect 0 OSPF OSPF O

57、SPF OSPF OSPF OSPFDirect 0Direct 0 OSPF OSPF O_ASEDirect 0Direct 0Direct 0Direct 0 OSPF O_ASE O_ASEDirect 0Direct 0Direct 1 OSPF O_ASE10310.0.0.25127.0.0.110.0.0.2510.0.0.2510.0.0.2510.0.0.2510.0.0.2510.0.0.2510.0.0.26127.0.0.110.0.0.2510.0.0.2510.0.0.25127.0.0.1127.0.0.1172.16.1.252127.0.0.110.0.0.

58、2510.0.0.2510.0.0.25192.168.1.252127.0.0.1127.0.0.110.0.0.2510.0.0.25GE0/1/1InLoop0 GE0/1/1 GE0/1/1 GE0/1/1 GE0/1/1 GE0/1/1 GE0/1/1GE0/1/1InLoop0 GE0/1/1 GE0/1/1 GE0/1/1InLoop0 InLoop0 Vlan12 InLoop0GE0/1/1 GE0/1/1 GE0/1/1Vlan11 InLoop0 InLoop0GE0/1/1GE0/1/1010101010101021001494300101015000001015015

59、00001015032141141disp stp briMSTID001122PortEthernet0/4/0 Ethernet0/4/2 Ethernet0/4/0 Ethernet0/4/2 Ethernet0/4/0 Ethernet0/4/2RoleDESI DESI DESI DESI ROOT DESISTP SeProtectionNONE NONE NONE NONE NONE NONEFORWARDINGFORWARDING FORWARDING FORWARDING FORWARDING FORWARDINGdisp stp regOper configuration

60、Format selector Region name:0:h3cRevilevel:0Instance012Vlans Mapped1 to 10, 13 to 40941112disp vrrp vIPv4 Standby Information:Run ModeRun Method: Standard: Virtual MACTotal number of virtual routers : 2erface Vlan-VRIDerface11: 1: Up: 120Adver Timer: 10Admin SConfig PriusSe: MasterRunning Pri: 120Pr

溫馨提示

  • 1. 本站所有資源如無(wú)特殊說(shuō)明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶(hù)所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁(yè)內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒(méi)有圖紙預(yù)覽就沒(méi)有圖紙。
  • 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
  • 5. 人人文庫(kù)網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶(hù)上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶(hù)上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
  • 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
  • 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶(hù)因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。

評(píng)論

0/150

提交評(píng)論