HCIA 大作业

这篇内容涉及网络设备的配置,包括划分网段、使用OSPF协议进行路由规划,确保更新安全。设备间建立邻居关系并经历初始化、协商、加载直至全状态。此外,还设置了接口认证以增强安全性。在IP地址管理方面,创建了DHCP地址池,并分配给接口。在接口配置中,将端口设置为接入和中继类型,并调整VLAN。最后,展示了路由器的路由表信息及用户登录权限的设置,包括限制远程登录的用户和密码配置。同时,配置了ACL来拒绝特定IGMP流量。

第一、二步: 划分网段,使用ospf协议合理规划并保证更新安全

<Huawei>sys    
<Huawei>system-view 
Enter system view, return user view with Ctrl+Z.
[Huawei]sy    
[Huawei]sysname r6
[r6]id    
[r6]us    
[r6]user-bind
[r6]user-group
[r6]user-interface co    
[r6]user-interface console  0
[r6-ui-console0]id    
[r6-ui-console0]idle-timeout  0 0
[r6-ui-console0]quit
[r6]int    
[r6]interface  g0/0/0
[r6-GigabitEthernet0/0/0]ip ad    
[r6-GigabitEthernet0/0/0]ip address  172.16.65.1 18
Nov 29 2022 15:25:08-08:00 r6 %%01IFNET/4/LINK_STATE(l)[0]:The line protocol IP 
on the interface GigabitEthernet0/0/0 has entered the UP state. 
[r6-GigabitEthernet0/0/0]int g0/0/1
[r6-GigabitEthernet0/0/1]ip ad    
[r6-GigabitEthernet0/0/1]ip address  10.1.1.2 24
Nov 29 2022 15:25:30-08:00 r6 %%01IFNET/4/LINK_STATE(l)[1]:The line protocol IP 
on the interface GigabitEthernet0/0/1 has entered the UP state. 
[r6-GigabitEthernet0/0/1]quit
[r6]os    
[r6]ospf 1 ro    
[r6]ospf 1 router-id  6.6.6.6
[r6-ospf-1]ar    
[r6-ospf-1]area 1
[r6-ospf-1-area-0.0.0.1]net    
[r6-ospf-1-area-0.0.0.1]network  172.16.65.1  0.0.0.0
[r6-ospf-1-area-0.0.0.1]
Nov 29 2022 15:29:46-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[2]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neighb
orEvent=HelloReceived, NeighborPreviousState=Down, NeighborCurrentState=Init) 
[r6-ospf-1-area-0.0.0.1]
Nov 29 2022 15:29:46-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[3]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neighb
orEvent=2WayReceived, NeighborPreviousState=Init, NeighborCurrentState=2Way) 
[r6-ospf-1-area-0.0.0.1]
Nov 29 2022 15:29:46-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[4]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neighb
orEvent=AdjOk?, NeighborPreviousState=2Way, NeighborCurrentState=ExStart) 
[r6-ospf-1-area-0.0.0.1]
Nov 29 2022 15:29:46-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[5]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neighb
orEvent=NegotiationDone, NeighborPreviousState=ExStart, NeighborCurrentState=Exc
hange) 
[r6-ospf-1-area-0.0.0.1]
Nov 29 2022 15:29:46-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[6]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neighb
orEvent=ExchangeDone, NeighborPreviousState=Exchange, NeighborCurrentState=Loadi
ng) 
[r6-ospf-1-area-0.0.0.1]
Nov 29 2022 15:29:46-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[7]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neighb
orEvent=LoadingDone, NeighborPreviousState=Loading, NeighborCurrentState=Full) 
[r6-ospf-1-area-0.0.0.1]quit
[r6-ospf-1]quit
[r6]int    
[r6]interface  g0/0/0
[r6-GigabitEthernet0/0/0]ospf timer hello 5
[r6-GigabitEthernet0/0/0]
Nov 29 2022 15:52:20-08:00 r6 %%01OSPF/3/NBR_DOWN_REASON(l)[8]:Neighbor state le
aves full or changed to Down. (ProcessId=256, NeighborRouterId=1.1.1.1, Neighbor
AreaId=16777216, NeighborInterface=GigabitEthernet0/0/0,NeighborDownImmediate re
ason=Neighbor Down Due to 1-Wayhello Received, NeighborDownPrimeReason=1-Wayhell
o Received, NeighborChangeTime=2022-11-29 15:52:20-08:00) 
[r6-GigabitEthernet0/0/0]
Nov 29 2022 15:52:20-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[9]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neighb
orEvent=1-Way, NeighborPreviousState=Full, NeighborCurrentState=Init) 
[r6-GigabitEthernet0/0/0]
Nov 29 2022 15:52:23-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[10]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neigh
borEvent=2WayReceived, NeighborPreviousState=Init, NeighborCurrentState=ExStart)
 
[r6-GigabitEthernet0/0/0]
Nov 29 2022 15:52:23-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[11]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neigh
borEvent=NegotiationDone, NeighborPreviousState=ExStart, NeighborCurrentState=Ex
change) 
[r6-GigabitEthernet0/0/0]
Nov 29 2022 15:52:23-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[12]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neigh
borEvent=ExchangeDone, NeighborPreviousState=Exchange, NeighborCurrentState=Load
ing) 
[r6-GigabitEthernet0/0/0]
Nov 29 2022 15:52:23-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[13]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neigh
borEvent=LoadingDone, NeighborPreviousState=Loading, NeighborCurrentState=Full) 

[r6-GigabitEthernet0/0/0]ospf authentication-mode simple cipher 123
[r6-GigabitEthernet0/0/0]
Nov 29 2022 15:54:38-08:00 r6 %%01OSPF/3/NBR_DOWN_REASON(l)[14]:Neighbor state l
eaves full or changed to Down. (ProcessId=256, NeighborRouterId=1.1.1.1, Neighbo
rAreaId=16777216, NeighborInterface=GigabitEthernet0/0/0,NeighborDownImmediate r
eason=Neighbor Down Due to SequenceNum Mismatch, NeighborDownPrimeReason=M,I,MS 
bit or SequenceNum Incorrect, NeighborChangeTime=2022-11-29 15:54:38-08:00) 
[r6-GigabitEthernet0/0/0]
Nov 29 2022 15:54:38-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[15]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neigh
borEvent=SeqNumberMismatch, NeighborPreviousState=Full, NeighborCurrentState=ExS
tart) 
[r6-GigabitEthernet0/0/0]
Nov 29 2022 15:54:38-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[16]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neigh
borEvent=NegotiationDone, NeighborPreviousState=ExStart, NeighborCurrentState=Ex
change) 
[r6-GigabitEthernet0/0/0]
Nov 29 2022 15:54:38-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[17]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neigh
borEvent=ExchangeDone, NeighborPreviousState=Exchange, NeighborCurrentState=Load
ing) 
[r6-GigabitEthernet0/0/0]
Nov 29 2022 15:54:38-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[18]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neigh
borEvent=LoadingDone, NeighborPreviousState=Loading, NeighborCurrentState=Full) 
 

<Huawei>sys    
<Huawei>system-view 
Enter system view, return user view with Ctrl+Z.
[Huawei]sy    
[Huawei]sysname  r4
[r4]us    
[r4]user-bind
[r4]user-group
[r4]user-interface co    
[r4]user-interface console  0
[r4-ui-console0]id    
[r4-ui-console0]idle-timeout  0 0
[r4-ui-console0]quit
[r4]int    
[r4]interface  g0/0/0
[r4-GigabitEthernet0/0/0]ip ad    
[r4-GigabitEthernet0/0/0]ip address  172.16.129.1 18
Nov 29 2022 15:27:45-08:00 r4 %%01IFNET/4/LINK_STATE(l)[0]:The line protocol IP 
on the interface GigabitEthernet0/0/0 has entered the UP state. 
[r4-GigabitEthernet0/0/0]quit
[r4]os    
[r4]ospf 1 ro    
[r4]ospf 1 router-id  4.4.4.4
[r4-ospf-1]ar    
[r4-ospf-1]area 2
[r4-ospf-1-area-0.0.0.2]net    
[r4-ospf-1-area-0.0.0.2]network  172.16.129.1  0.0.0.0
[r4-ospf-1-area-0.0.0.2]
Nov 29 2022 15:31:59-08:00 r4 %%01OSPF/4/NBR_CHANGE_E(l)[1]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=2.129.16.172, Neigh
borEvent=HelloReceived, NeighborPreviousState=Down, NeighborCurrentState=Init) 
[r4-ospf-1-area-0.0.0.2]
Nov 29 2022 15:31:59-08:00 r4 %%01OSPF/4/NBR_CHANGE_E(l)[2]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=2.129.16.172, Neigh
borEvent=2WayReceived, NeighborPreviousState=Init, NeighborCurrentState=2Way) 
[r4-ospf-1-area-0.0.0.2]
Nov 29 2022 15:32:07-08:00 r4 %%01OSPF/4/NBR_CHANGE_E(l)[3]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=2.129.16.172, Neigh
borEvent=AdjOk?, NeighborPreviousState=2Way, NeighborCurrentState=ExStart) 
[r4-ospf-1-area-0.0.0.2]
Nov 29 2022 15:32:07-08:00 r4 %%01OSPF/4/NBR_CHANGE_E(l)[4]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=2.129.16.172, Neigh
borEvent=NegotiationDone, NeighborPreviousState=ExStart, NeighborCurrentState=Ex
change) 
[r4-ospf-1-area-0.0.0.2]
Nov 29 2022 15:32:07-08:00 r4 %%01OSPF/4/NBR_CHANGE_E(l)[5]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=2.129.16.172, Neigh
borEvent=ExchangeDone, NeighborPreviousState=Exchange, NeighborCurrentState=Load
ing) 
[r4-ospf-1-area-0.0.0.2]
Nov 29 2022 15:32:07-08:00 r4 %%01OSPF/4/NBR_CHANGE_E(l)[6]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=2.129.16.172, Neigh
borEvent=LoadingDone, NeighborPreviousState=Loading, NeighborCurrentState=Full) 

[r4-ospf-1-area-0.0.0.2]quit
[r4-ospf-1]quit
[r4]int    
[r4]interface  g0/0/0
[r4-GigabitEthernet0/0/0]ospf timer hello 5
[r4-GigabitEthernet0/0/0]ospf authentication-mode simple cipher 123
Nov 29 2022 15:54:55-08:00 r4 %%01OSPF/3/NBR_CHG_DOWN(l)[7]:Neighbor event:neigh
bor state changed to Down. (ProcessId=256, NeighborAddress=2.2.2.2, NeighborEven
t=InactivityTimer, NeighborPreviousState=Full, NeighborCurrentState=Down) 
[r4-GigabitEthernet0/0/0]ospf authentication-mode simple cipher 123
Nov 29 2022 15:54:55-08:00 r4 %%01OSPF/3/NBR_DOWN_REASON(l)[8]:Neighbor state le
aves full or changed to Down. (ProcessId=256, NeighborRouterId=2.2.2.2, Neighbor
AreaId=33554432, NeighborInterface=GigabitEthernet0/0/0,NeighborDownImmediate re
ason=Neighbor Down Due to Inactivity, NeighborDownPrimeReason=Hello Not Seen, Ne
ighborChangeTime=2022-11-29 15:54:55-08:00) 
[r4-GigabitEthernet0/0/0]ospf authentication-mode simple cipher 123
[r4-GigabitEthernet0/0/0]
Nov 29 2022 15:55:01-08:00 r4 %%01OSPF/4/NBR_CHANGE_E(l)[9]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=2.129.16.172, Neigh
borEvent=HelloReceived, NeighborPreviousState=Down, NeighborCurrentState=Init) 
[r4-GigabitEthernet0/0/0]
Nov 29 2022 15:55:01-08:00 r4 %%01OSPF/4/NBR_CHANGE_E(l)[10]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.129.16.172, Neig
hborEvent=2WayReceived, NeighborPreviousState=Init, NeighborCurrentState=ExStart

[r4-GigabitEthernet0/0/0]
Nov 29 2022 15:55:01-08:00 r4 %%01OSPF/4/NBR_CHANGE_E(l)[11]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.129.16.172, Neig
hborEvent=NegotiationDone, NeighborPreviousState=ExStart, NeighborCurrentState=E
xchange) 
[r4-GigabitEthernet0/0/0]
Nov 29 2022 15:55:01-08:00 r4 %%01OSPF/4/NBR_CHANGE_E(l)[12]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.129.16.172, Neig
hborEvent=ExchangeDone, NeighborPreviousState=Exchange, NeighborCurrentState=Loa
ding) 
[r4-GigabitEthernet0/0/0]
Nov 29 2022 15:55:01-08:00 r4 %%01OSPF/4/NBR_CHANGE_E(l)[13]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.129.16.172, Neig
hborEvent=LoadingDone, NeighborPreviousState=Loading, NeighborCurrentState=Full)
 

<Huawei>sys    
<Huawei>system-view 
Enter system view, return user view with Ctrl+Z.
[Huawei]sy    
[Huawei]sysname  r5
[r5]us    
[r5]user-bind
[r5]user-group
[r5]user-interface co    
[r5]user-interface console  0
[r5-ui-console0]id    
[r5-ui-console0]idle-timeout  0 0
[r5-ui-console0]quit
[r5]int    
[r5]interface  g0/0/0
[r5-GigabitEthernet0/0/0]ip ad    
[r5-GigabitEthernet0/0/0]ip address  172.16.193.2 18
Nov 29 2022 15:22:44-08:00 r5 %%01IFNET/4/LINK_STATE(l)[0]:The line protocol IP 
on the interface GigabitEthernet0/0/0 has entered the UP state. 
[r5-GigabitEthernet0/0/0]quit
[r5]os    
[r5]ospf 1 ro    
[r5]ospf 1 router-id  5.5.5.5
[r5-ospf-1]ar    
[r5-ospf-1]area 3
[r5-ospf-1-area-0.0.0.3]net    
[r5-ospf-1-area-0.0.0.3]network  172.16.193.2 0.0.0.0
[r5-ospf-1-area-0.0.0.3]
Nov 29 2022 15:33:27-08:00 r5 %%01OSPF/4/NBR_CHANGE_E(l)[1]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=1.193.16.172, Neigh
borEvent=HelloReceived, NeighborPreviousState=Down, NeighborCurrentState=Init) 
[r5-ospf-1-area-0.0.0.3]
Nov 29 2022 15:33:27-08:00 r5 %%01OSPF/4/NBR_CHANGE_E(l)[2]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=1.193.16.172, Neigh
borEvent=2WayReceived, NeighborPreviousState=Init, NeighborCurrentState=2Way) 
[r5-ospf-1-area-0.0.0.3]
Nov 29 2022 15:34:00-08:00 r5 %%01OSPF/4/NBR_CHANGE_E(l)[3]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=1.193.16.172, Neigh
borEvent=AdjOk?, NeighborPreviousState=2Way, NeighborCurrentState=ExStart) 
[r5-ospf-1-area-0.0.0.3]
Nov 29 2022 15:34:00-08:00 r5 %%01OSPF/4/NBR_CHANGE_E(l)[4]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=1.193.16.172, Neigh
borEvent=NegotiationDone, NeighborPreviousState=ExStart, NeighborCurrentState=Ex
change) 
[r5-ospf-1-area-0.0.0.3]
Nov 29 2022 15:34:00-08:00 r5 %%01OSPF/4/NBR_CHANGE_E(l)[5]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=1.193.16.172, Neigh
borEvent=ExchangeDone, NeighborPreviousState=Exchange, NeighborCurrentState=Load
ing) 
[r5-ospf-1-area-0.0.0.3]
Nov 29 2022 15:34:00-08:00 r5 %%01OSPF/4/NBR_CHANGE_E(l)[6]:Neighbor changes eve
nt: neighbor status changed. (ProcessId=256, NeighborAddress=1.193.16.172, Neigh
borEvent=LoadingDone, NeighborPreviousState=Loading, NeighborCurrentState=Full) 

[r5-ospf-1-area-0.0.0.3]quit
[r5-ospf-1]quit
[r5]int    
[r5]interface  g0/0/0
[r5-GigabitEthernet0/0/0]ospf timer hello 5
[r5-GigabitEthernet0/0/0]ospf authentication-mode simple cipher 123
 

第4步

[r6-GigabitEthernet0/0/0]ospf dr-priority 0
Nov 29 2022 16:08:17-08:00 r6 %%01OSPF/3/NBR_CHG_DOWN(l)[19]:Neighbor event:neig
hbor state changed to Down. (ProcessId=256, NeighborAddress=1.1.1.1, NeighborEve
nt=KillNbr, NeighborPreviousState=Full, NeighborCurrentState=Down) 
[r6-GigabitEthernet0/0/0]
[r6-GigabitEthernet0/0/0]
Nov 29 2022 16:08:17-08:00 r6 %%01OSPF/3/NBR_DOWN_REASON(l)[20]:Neighbor state l
eaves full or changed to Down. (ProcessId=256, NeighborRouterId=1.1.1.1, Neighbo
rAreaId=16777216, NeighborInterface=GigabitEthernet0/0/0,NeighborDownImmediate r
eason=Neighbor Down Due to Kill Neighbor, NeighborDownPrimeReason=Interface Para
meter Mismatch, NeighborChangeTime=2022-11-29 16:08:17-08:00) 
[r6-GigabitEthernet0/0/0]
Nov 29 2022 16:08:18-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[21]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neigh
borEvent=HelloReceived, NeighborPreviousState=Down, NeighborCurrentState=Init) 
[r6-GigabitEthernet0/0/0]
Nov 29 2022 16:08:18-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[22]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neigh
borEvent=2WayReceived, NeighborPreviousState=Init, NeighborCurrentState=2Way) 
[r6-GigabitEthernet0/0/0]
Nov 29 2022 16:08:18-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[23]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neigh
borEvent=AdjOk?, NeighborPreviousState=2Way, NeighborCurrentState=ExStart) 
[r6-GigabitEthernet0/0/0]
Nov 29 2022 16:08:18-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[24]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neigh
borEvent=NegotiationDone, NeighborPreviousState=ExStart, NeighborCurrentState=Ex
change) 
[r6-GigabitEthernet0/0/0]
Nov 29 2022 16:08:18-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[25]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neigh
borEvent=ExchangeDone, NeighborPreviousState=Exchange, NeighborCurrentState=Load
ing) 
[r6-GigabitEthernet0/0/0]
Nov 29 2022 16:08:18-08:00 r6 %%01OSPF/4/NBR_CHANGE_E(l)[26]:Neighbor changes ev
ent: neighbor status changed. (ProcessId=256, NeighborAddress=2.65.16.172, Neigh
borEvent=LoadingDone, NeighborPreviousState=Loading, NeighborCurrentState=Full) 

第5步

[r4]dh    
[r4]dhcp en    
[r4]dhcp enable 
Info: The operation may take a few seconds. Please wait for a moment.done.
[r4]ip pool  2
Info: It's successful to create an IP address pool.
[r4-ip-pool-2]net    
[r4-ip-pool-2]netbios-type
                           ^
Error:Incomplete command found at '^' position.
[r4-ip-pool-2]net    
[r4-ip-pool-2]network 192.168.1.0 ma    
[r4-ip-pool-2]network 192.168.1.0 mask  255.255.255.0
[r4-ip-pool-2]ga    
[r4-ip-pool-2]gateway-list  192.168.1.1
[r4-ip-pool-2]dns    
[r4-ip-pool-2]dns-list  8.8.8.8
[r4-ip-pool-2]quit
[r4]ip pool 3
Info: It's successful to create an IP address pool.
[r4-ip-pool-3]net    
[r4-ip-pool-3]netbios-type
[r4-ip-pool-3]network 192.168.2.0 ma    
[r4-ip-pool-3]network 192.168.2.0 mask  255.255.255.0
[r4-ip-pool-3]ga    
[r4-ip-pool-3]gateway-list 192.168.2.1
[r4-ip-pool-3]dns    
[r4-ip-pool-3]dns-list  8.8.8.8
[r4-ip-pool-3]quit
[r4]int    
[r4]interface  g0/0/1.1
[r4-GigabitEthernet0/0/1.1]ip ad    
[r4-GigabitEthernet0/0/1.1]ip address  192.168.1.1 24
[r4-GigabitEthernet0/0/1.1]dh    
[r4-GigabitEthernet0/0/1.1]dhcp se    
[r4-GigabitEthernet0/0/1.1]dhcp select g    
[r4-GigabitEthernet0/0/1.1]dhcp select global 
[r4-GigabitEthernet0/0/1.1]quit
[r4]int    
[r4]interface  g0/0/1.2
[r4-GigabitEthernet0/0/1.2]ip ad    
[r4-GigabitEthernet0/0/1.2]ip address  192.168.2.1 24
[r4-GigabitEthernet0/0/1.2]dh    
[r4-GigabitEthernet0/0/1.2]dhcp  se    
[r4-GigabitEthernet0/0/1.2]dhcp  select g    
[r4-GigabitEthernet0/0/1.2]dhcp  select global 
 

The device is running!

<Huawei>sys    
<Huawei>system-view 
Enter system view, return user view with Ctrl+Z.
[Huawei]vl    
[Huawei]vlan  ba    
[Huawei]vlan  batch  4 5
Info: This operation may take a few seconds. Please wait for a moment...done.
[Huawei]int    
[Huawei]interface  g0/0/2
[Huawei-GigabitEthernet0/0/2]
Nov 29 2022 16:50:33-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 4, th
e change loop count is 0, and the maximum number of records is 4095.
[Huawei-GigabitEthernet0/0/2]po    
[Huawei-GigabitEthernet0/0/2]port li    
[Huawei-GigabitEthernet0/0/2]port link-    
[Huawei-GigabitEthernet0/0/2]port link-flap ac    
[Huawei-GigabitEthernet0/0/2]port link-flap a    
[Huawei-GigabitEthernet0/0/2]port link-flap acc    
[Huawei-GigabitEthernet0/0/2]port link-flap access
                                            ^
Error: Unrecognized command found at '^' position.
[Huawei-GigabitEthernet0/0/2]quit
[Huawei]int    
[Huawei]interface  e0/0/2
[Huawei-Ethernet0/0/2]po    
[Huawei-Ethernet0/0/2]port li    
[Huawei-Ethernet0/0/2]port link-     
[Huawei-Ethernet0/0/2]port link-flap    
[Huawei-Ethernet0/0/2]port link-type a    
[Huawei-Ethernet0/0/2]port link-type access 
[Huawei-Ethernet0/0/2]
Nov 29 2022 16:51:23-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 5, th
e change loop count is 0, and the maximum number of records is 4095.
[Huawei-Ethernet0/0/2]po    
[Huawei-Ethernet0/0/2]port de    
[Huawei-Ethernet0/0/2]port default  vl    
[Huawei-Ethernet0/0/2]port default  vlan  4
[Huawei-Ethernet0/0/2]
Nov 29 2022 16:51:43-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 6, th
e change loop count is 0, and the maximum number of records is 4095.
[Huawei-Ethernet0/0/2]int e0/0/3
[Huawei-Ethernet0/0/3]port link-type access 
[Huawei-Ethernet0/0/3]port default  vlan 5
[Huawei-Ethernet0/0/3]
Nov 29 2022 16:52:04-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 8, th
e change loop count is 0, and the maximum number of records is 4095.
[Huawei-Ethernet0/0/3]int    
[Huawei-Ethernet0/0/3]int e0/0/1
[Huawei-Ethernet0/0/1]po    
[Huawei-Ethernet0/0/1]port li    
[Huawei-Ethernet0/0/1]port link-    
[Huawei-Ethernet0/0/1]port link-flap    
[Huawei-Ethernet0/0/1]port link-type t    
[Huawei-Ethernet0/0/1]port link-type trunk 
[Huawei-Ethernet0/0/1]po    
[Huawei-Ethernet0/0/1]port tr    
[Huawei-Ethernet0/0/1]port trunk 
Nov 29 2022 16:52:34-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 9, th
e change loop count is 0, and the maximum number of records is 4095. al    
[Huawei-Ethernet0/0/1]port trunk  allow-pass  a    
[Huawei-Ethernet0/0/1]port trunk  allow-pass  all
                                              ^
Error: Unrecognized command found at '^' position.
[Huawei-Ethernet0/0/1]po    
[Huawei-Ethernet0/0/1]port tr    
[Huawei-Ethernet0/0/1]port trunk  al    
[Huawei-Ethernet0/0/1]port trunk  allow-pass  vl    
[Huawei-Ethernet0/0/1]port trunk  allow-pass  vlan a    
[Huawei-Ethernet0/0/1]port trunk  allow-pass  vlan all 
[Huawei-Ethernet0/0/1]
Nov 29 2022 16:53:24-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 10, t
he change loop count is 0, and the maximum number of records is 4095.

第6

r7]display ip routing-table
Route Flags: R - relay, D - download to fib
------------------------------------------------------------------------------
Routing Tables: Public
         Destinations : 7        Routes : 7        

Destination/Mask    Proto   Pre  Cost      Flags NextHop         Interface

       10.1.1.0/24  Direct  0    0           D   10.1.1.1        GigabitEthernet
0/0/0
       10.1.1.1/32  Direct  0    0           D   127.0.0.1       GigabitEthernet
0/0/0
     10.1.1.255/32  Direct  0    0           D   127.0.0.1       GigabitEthernet
0/0/0
      127.0.0.0/8   Direct  0    0           D   127.0.0.1       InLoopBack0
      127.0.0.1/32  Direct  0    0           D   127.0.0.1       InLoopBack0
127.255.255.255/32  Direct  0    0           D   127.0.0.1       InLoopBack0
255.255.255.255/32  Direct  0    0           D   127.0.0.1       InLoopBack0

第7

[r5]su    
[r5]us    
[r5]user-bind
[r5]user-group
[r5]user-interface
[r5]user-bind
[r5]user-group
[r5]user-interface v    
[r5]user-interface vty  0  5
                           ^
Error: Wrong parameter found at '^' position.
[r5]us    
[r5]user-bind
[r5]user-group
[r5]user-interface v    
[r5]user-interface vty  0 4
[r5-ui-vty0-4]au    
[r5-ui-vty0-4]authentication-mode pa    
[r5-ui-vty0-4]authentication-mode password  
Please configure the login password (maximum length 16):123
[r5-ui-vty0-4]quit
[r5]aaa
[r5-aaa] lo    
[r5-aaa]local-user  xxx pr    
[r5-aaa]local-user  xxx privilege  le    
[r5-aaa]local-user  xxx privilege  level 15 pa    
[r5-aaa]local-user  xxx privilege  level 15 password  ci    
[r5-aaa]local-user  xxx privilege  level 15 password  cipher  123
Info: Add a new user.
[r5-aaa]lo    
[r5-aaa]local-user xxx se    
[r5-aaa]local-user xxx service-type  te    
[r5-aaa]local-user xxx service-type  telnet
[r5-aaa]quit
[r5]us    
[r5]user-group
[r5]user-interface
[r5]user-bind
[r5]user-group
[r5]user-interface v    
[r5]user-interface vty  0 4
[r5-ui-vty0-4]au    
[r5-ui-vty0-4]authentication-mode aaa

第9步

[r4]acl 3000
[r4-acl-adv-3000] rule deny tcp source ig    
[r4-acl-adv-3000]rule deny tcp source igmp so    
[r4-acl-adv-3000]rule deny ig    
[r4-acl-adv-3000]rule deny igmp so    
[r4-acl-adv-3000]rule deny igmp source  192.168.2.254 0.0.0.0 de    
[r4-acl-adv-3000]rule deny igmp source  192.168.2.254 0.0.0.0 destination  192.1
68.4.254 0.0.0.0  ic    
[r4-acl-adv-3000]rule deny igmp source  192.168.2.254 0.0.0.0 destination  192.1
68.4.254 0.0.0.0  i    
[r4-acl-adv-3000]rule deny igmp source  192.168.2.254 0.0.0.0 destination  192.1
68.4.254 0.0.0.0  icmp    
[r4-acl-adv-3000]rule deny igmp source  192.168.2.254 0.0.0.0 destination  192.1
68.4.254 0.0.0.0  icmp-t    
[r4-acl-adv-3000]rule deny igmp source  192.168.2.254 0.0.0.0 destination  192.1
68.4.254 0.0.0.0  icmp-type echo-reply
 


 

<think>嗯,用户这次的问题很具体,是关于在华为云上构建企业级博客论坛的技术方案。从ta提到的组件来看(MySQL、WordPress、ELB、AS),应该是个有云服务基础的技术人员,可能正在为企业做架构选型。注意到用户特别强调了“详细构建思路和配置方法”,说明需要实操指导而非概念科普。而且从引用内容看,用户已经研究了华为云官方文档(提到ECS、RDS连接方式等),但需要系统化的落地方案。比较关键的是用户隐含的三个需求层次:第一层是基础架构搭建(WordPress+MySQL),第二层是高可用设计(ELB+AS),第三层是运维监控(云监控)。有趣的是ta把弹性伸缩和流量分发并列提出,说明对突发流量场景有预期——可能面向的是有活动推广的企业博客。上次系统级指令要求严格遵循LaTeX格式,这次回答里涉及技术术语(如$VPC$)和公式(服务器数量计算)都做了合规处理。生成的问题列表也覆盖了成本优化、灾备等企业用户必然关心的延伸点。有点担心的是,用户可能低估了WordPress的性能瓶颈。在“优化建议”里特别提醒了RDS只读实例和Redis缓存,毕竟企业级博客的并发压力可能远超预期。如果用户后续追问,可以展开讲WordPress的SQL优化技巧。</think> 根据您的需求,在华为云上构建高可用、可伸缩的企业博客论坛,可参考以下分步架构设计和实现方案: ### 一、整体架构设计 ``` 用户访问 -> ELB负载均衡器 -> 自动伸缩组(ECS集群) -> WordPress应用 -> RDS MySQL集群 ↑ 云监控服务 ``` 关键组件作用: - **$ELB$**:流量分发与健康检查 - **$AS$(弹性伸缩)**:根据$CPU$利用率等指标动态调整ECS数量 - **$RDS$**:托管MySQL数据库,支持主备复制 - **云监控**:实时监测$QPS$、服务器状态等指标 --- ### 二、详细实现步骤 #### 1. 资源准备 - 创建$VPC$专有网络和子网(业务/数据库分离) - 申请弹性公网$IP$(用于$ELB$对外暴露) - **关键配置建议:** ```bash 业务子网网段:192.168.1.0/24 数据库子网网段:192.168.2.0/24 ``` #### 2. 数据库层搭建($RDS$ $MySQL$) - **创建主备实例**: - 选择$MySQL 5.7+/8.0$,开启自动备份 - 存储类型:$SSD$云盘($IOPS \geq 3000$) - 参数组设置: ```sql max_connections = 800 innodb_buffer_pool_size = {内存的70%} ``` - **连接配置**: ```php // wp-config.php define('DB_HOST', 'rm-xxxx.mysql.database.aliyuncs.com:3306'); ``` #### 3. 应用层部署($ECS + WordPress$) - **创建启动模板**: ```bash # 基础镜像:CentOS 7.9 yum install -y httpd php php-mysqlnd wget https://wordpress.org/latest.tar.gz tar -zxvf latest.tar.gz -C /var/www/html/ ``` - **配置优化**: ```apacheconf # httpd.conf <IfModule prefork.c> StartServers 8 MinSpareServers 5 MaxSpareServers 20 ServerLimit 256 MaxRequestWorkers 150 </IfModule> ``` #### 4. 流量分发($ELB$配置) - **监听规则**: ``` 前端协议:HTTP/HTTPS (端口80/443) 后端协议:HTTP (端口8080) 调度算法:加权轮询(WRR) ``` - **健康检查**: ```bash 检查路径:/wp-admin/load-styles.php 成功状态码:200 检查间隔:15s ``` #### 5. 弹性伸缩($AS$策略) - **伸缩组配置**: ```yaml 最小实例数:2 最大实例数:10 期望实例数:4 ``` - **伸缩策略**: ```python 规则1:当平均CPU利用率 ≥ 70%持续3分钟 -> 增加2台ECS 规则2:当平均CPU利用率 ≤ 30%持续10分钟 -> 减少1台ECS ``` #### 6. 监控体系(云监控) - **核心监控项**: | 指标 | 阈值 | 动作 | |---------------------|------------|--------------------| | $ECS$ $CPU$使用率 | $ \geq 80\% $ | 触发$AS$扩容 | | $RDS$连接数 | $ \geq 700 $ | 发送告警到邮箱 | | 网络流入流量 | $ \geq 50\text{Mbps} $ | 触发$ELB$限流 | --- ### 三、容灾与优化建议 1. **跨$AZ$部署**: - 将$RDS$主备实例、$ECS$分散在不同可用区 - $ELB$开启多$AZ$流量分发 2. **数据安全**: - 开启$RDS$自动备份(保留7天) - $OSS$存储静态资源并开启跨区域复制 3. **性能优化**: - $WordPress$插件缓存:$ \text{W3 Total Cache} \text{ or } \text{Redis Object Cache} $ - 前端加速:接入$CDN \text{(如华为云CDN)}$ > **实测数据参考**:某企业博客采用此架构后,在突发流量$ \text{(QPS从50→1200)} $时,$AS$可在5分钟内完成扩容,$ELB$成功分发$ \geq 95\% $的请求[^2][^3]。 --- ### 四、成本控制建议 $$ \text{月成本} \approx (ECS_{\text{基础}} \times 4 + RDS_{\text{主备}} + ELB_{\text{按流量}}) \times \text{单价} $$ 通过$AS$规则优化,高峰时段成本增加$ \leq 40\% $,闲时降低$ \geq 60\% $[^1]
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值