实验要求:
1、服务器组双链路 上联核心,调高数据可靠性
2、配置vlan,减小广播域范围
3、所有网关都设在核心上,部分ip需自动获取
4、业务端口,配置边缘端口,减小频繁up down对网络的影响
5、配置相关路由,使的用户可以访问外网及新校区
6、广域网出口做主备,线路正常走联通
7、所有设备可以被Telnet ,管理网段255.x,vlan999
8、vlan30 用户不能访问200.4
服务器sw网桥聚合
思路
1、起网桥聚合
2、聚合口为trunk
server-sw
[H3C]SY S-SW
[S-SW]vlan 200
[S-SW-vlan200]port g1/0/1
[S-SW-vlan200]port g1/0/2
dis
[S-SW-vlan200]int b 1
[S-SW-Bridge-Aggregation1]qu
[S-SW]int range Ten-GigabitEthernet1/0/50 to Ten-GigabitEthernet1/0/51
[S-SW-if-range]port link-aggregation group 1
[S-SW-if-range]qu
[S-SW]dis link-aggregation v
Port Status Priority Oper-Key
--------------------------------------------------------------------------------
XGE1/0/50 S 32768 1
XGE1/0/51 S 32768 1
没有设置网桥模式为dynamic(动态)就会出现上面情况
[S-SW]int b 1
[S-SW-Bridge-Aggregation1]link mode dynamic ==开启动态模式==
[S-SW-Bridge-Aggregation1]dis link-aggregation v
System ID: 0x8000, 6e7e-6251-1200
Local:
Port Status Priority Oper-Key Flag
--------------------------------------------------------------------------------
XGE1/0/50 S 32768 1 {
ACDEFG}
XGE1/0/51 U 32768 1 {
ACG}
Remote:
Actor Partner Priority Oper-Key SystemID Flag
--------------------------------------------------------------------------------
XGE1/0/50 0 32768 0 0x8000, 0000-0000-0000 {
DEF}
XGE1/0/51 0 32768 0 0x8000, 0000-0000-0000 {
DEF}
====================由于对端摸开启 显示上面的 U ====================================
[S-SW-Bridge-Aggregation1]dis link-aggregation v
System ID: 0x8000, 6e7e-6251-1200
Local:
Port Status Priority Oper-Key Flag
--------------------------------------------------------------------------------
XGE1/0/50 S 32768 1 {
ACDEF}
XGE1/0/51 S 32768 1 {
ACDEF}
Remote:
Actor Partner Priority Oper-Key SystemID Flag
--------------------------------------------------------------------------------
XGE1/0/50 51 32768 1 0x8000, 6e7d-01a4-0100 {
ACDEF}
XGE1/0/51 52 32768 1 0x8000, 6e7d-01a4-0100 {
ACDEF}
在PC14(服务器)上ping网关 200.1 不通,分析原因为没有设置trunk
[S-SW-Bridge-Aggregation1]qu
[S-SW]in b 1
[S-SW-Bridge-Aggregation1]port link-ty trunk
Configuring Ten-GigabitEthernet1/0/50 done. ==这两done要出现==
Configuring Ten-GigabitEthernet1/0/51 done.
[S-SW-Bridge-Aggregation1]por tr pe v a
Configuring Ten-GigabitEthernet1/0/50 done.
Configuring Ten-GigabitEthernet1/0/51 done.
核心sw
这个顺序好像很重要
sy SW1
vlan 200
int vlan 200
ip add 192.168.200.1 24
int b 1
qu
int range Ten-GigabitEthernet1/0/50 to Ten-GigabitEthernet1/0/51
port link-ag gr 1
int b 1
link mode dynamic
port link-ty trunk
port tr pe v all
验证
<H3C>PING 192.168.200.1
Ping 192.168.200.1 (192.168.200.1): 56 data bytes, press CTRL_C to break
56 bytes from 192.168.200.1: icmp_seq=0 ttl=255 time=0.000 ms
56 bytes from 192.168.200.1: icmp_seq=1 ttl=255 time=1.000 ms
56 bytes from 192.168.200.1: icmp_seq=2 ttl=255 time=1.000 m
2、配置vlan,减小广播域范围
思路
1、目标 vlan 10 vlan 20 vlan 30 vlan 40 vlan 80 vlan 200
疑问:服务器支路和pc9支路,如果按需开启vlan200 和999 会怎样 ?
答:就是要按需开启,没有必要开启其他的
2、用dis vlan b
vlan10段
核心sw1 起vlan trunk 虚接口
vlan 10
int vlan 10
ip ad 192.168.10.1 24
qu
iint Ten-GigabitEthernet1/0/52
port link-ty trunk
port trunk pe v all
检测 - vlan
[sw1]dis po tr
Interface PVID VLAN Passing
BAGG1 1 1, 10, 200, 999
XGE1/0/50 1 1, 10, 200, 999
XGE1/0/51 1 1, 10, 200, 999
XGE1/0/52 1 1, 10, 200, 999
检测 -trunk
10 VLAN 0010 BAGG1 XGE1/0/50 XGE1/0/51
XGE1/0/52
200 VLAN 0200 BAGG1 XGE1/0/50 XGE1/0/51
XGE1/0/52
999 VLAN 0999 BAGG1 XGE1/0/50 XGE1/0/51
XGE1/0/52
检测 -虚接口
[sw1]dis ip in b
*down: administratively down
(s): spoofing (l): loopback
Interface Physical Protocol IP Address Description
MGE0/0/0 down down -- --
Vlan10 up up 192.168.10.1 --
Vlan200 up up 192.168.200.1 --
汇聚sw2 起vlan, 并三个trunk口
1、起vlan, 并三个trunk口 就ok
[sw-核心]sy sw-汇聚
[sw-汇聚]vlan 10
[sw-汇聚-vlan10]vlan 20
[sw-汇聚-vlan20]vlan 999
[sw-汇聚-vlan999]qu
[sw-汇聚]int Ten-GigabitEthernet1/0/52
[sw-汇聚-Ten-GigabitEthernet1/0/52]port link-ty trunk
[sw-汇聚-Ten-GigabitEthernet1/0/52]port tr pe v a
[sw-汇聚-GigabitEthernet1/0/1]qu
[sw-汇聚]int g1/0/1
[sw-汇聚-GigabitEthernet1/0/1]port link-ty trunk
[sw-汇聚-GigabitEthernet1/0/1]port tr pe v a
[sw-汇聚-GigabitEthernet1/0/1]int g1/0/2
[sw-汇聚-GigabitEthernet1/0/2]port link-ty trunk
[sw-汇聚-GigabitEthernet1/0/2]port tr pe v a
[sw2]dis vlan b
.......
10 VLAN 0010 GE1/0/1 GE1/0/2 XGE1/0/52
20 VLAN 0020 GE1/0/1 GE1/0/2 XGE1/0/52
999 VLAN 0999 GE1/0/1 GE1/0/2 XGE1/0/52
[sw-汇聚]dis por tr
Interface PVID VLAN Passing
GE1/0/1 1 1, 10, 20, 999
GE1/0/2 1 1, 10, 20, 999
XGE1/0/52 1 1, 10, 20, 999
接入sw4 起vlan 开trunk
开通vlan10 (不用全部)并纳口 , 开通trunk 并all
[H3C]sy sw-接入
[sw-接入]vlan 10
[sw-接入-vlan10]port g1/0/2
[sw-接入-vlan10]port g1/0/3
[sw-接入-vlan10]int g1/0/1
[sw-接入-GigabitEthernet1/0/1]port link-ty tr
[sw-接入-GigabitEthernet1/0/1]port tr pe v a
========= 顺便业务端口
[sw4-vlan10]qu
[sw4]int range g1/0/2 to g1/0/3
[sw4-if-range]stp edged-port
10 VLAN 0010 GE1/0/1 GE1/0/2 GE1/0/3
999 VLAN 0999 GE1/0/1
pc9 能ping通网关10.1和200.1
<H3C>ping 192.168.10.1
Ping 192.168.10.1 (192.168.10.1): 56 data bytes, press CTRL_C to break
56 bytes from 192.168.10.1: icmp_seq=0 ttl=255 time=1.000 ms
<H3C>ping 192.168.200.1
Ping 192.168.200.1 (192.168.200.1): 56 data bytes, press CTRL_C to break
56 bytes from 192.168.200.1: icmp_seq=0 ttl=255 time=1.000 ms
56 bytes from 192.168.200.1: icmp_seq=1 ttl=255 time=1.000 ms
至此接入sw不能ping通 网关
[sw-接入]ping 192.168.10.1
Ping 192.168.10.1 (192.168.10.1): 56 data bytes, press CTRL_C to break
Request time out
Request time out
vlan 20段
sw1 起vlan 虚拟口
[sw1]vlan 20
[sw1-vlan20]int vlan 20
[sw1-Vlan-interface20]ip address 192.168.20.1 24
汇聚 sw 不用设置
sw5接入 起vlan 配trunk
[sw]sy sw5-接入
[sw5-接入]vlan 20
[sw5-接入-vlan20]por g1/0/1
[sw5-接入-vlan20]int g1/0/2
[sw5-接入-GigabitEthernet1/0/2]port link-ty tr
[sw5-接入-GigabitEthernet1/0/2]por tr pe v a
验证 ping 10.1 20.1 200.1都ok
<H3C>ping 192.168.200.1
Ping 192.168.200.1 (192.168.200.1): 56 data bytes