工具:HCL模拟器(安装自带VirtualBox)
配置任务如下:

irf堆叠的代码没有记录
- ### sw1
- sysname sw1
- [sw1]vlan10
- [sw1]quit
- [sw1]vlan 20
- [sw1]quit
- //链路聚合
- [sw1]interface Bridge-Aggregation 1
- [sw1-Bridge-Aggregation1]quit
- [sw1]interface range g1/0/7 g1/0/8
- [sw1-if-range]port link-aggregation group 1
- [sw1]interface Bridge-Aggregation 2
- [sw1-Bridge-Aggregation2]quit
- [sw1]interface range g1/0/3 g1/0/4
- [sw1-if-range]port link-aggregation group 2
- //配置trunk
- [sw1]interface Bridge-Aggregation 1
- [sw1-Bridge-Aggregation1]port link-type trunk
- [sw1-Bridge-Aggregation1]port trunk permit vlan all
- [sw1-Bridge-Aggregation1]quit
- [sw1]interface Bridge-Aggregation 2
- [sw1-Bridge-Aggregation2]port link-type trunk
- [sw1-Bridge-Aggregation2]port trunk permit vlan all
- //配置mstp(默认开启)
- [sw1]stp region-configuration
- [sw1-mst-region]region-name h3c
- [sw1-mst-region]revision-level 1
- [sw1-mst-region]instance 1 vlan 10
- [sw1-mst-region]instance 2 vlan 20
- [sw1-mst-region]active region-configuration
- //默认instance1的根端口在sw1,保证了vlan 10走左边
- [sw1]display stp instance 1 brief
- MST ID Port Role STP State Protection
- 1 Bridge-Aggregation1 DESI FORWARDING NONE
- 1 Bridge-Aggregation2 ROOT FORWARDING NONE
- //vrrp配置
- [sw1]interface Vlan-interface 10
- [sw1-Vlan-interface10]ip address 192.168.10.253 24
- [sw1-Vlan-interface10]vrrp vrid 1 virtual-ip 192.168.10.254
- [sw1-Vlan-interface10]vrrp vrid 1 priority 120
- [sw1-Vlan-interface10]vrrp vrid 1 preempt-mode
- [sw1]interface Vlan-interface 20
- [sw1-Vlan-interface20]ip address 192.168.20.252 24
- [sw1-Vlan-interface20]vrrp vrid 2 virtual-ip 192.168.20.254
- [sw1]display vrrp
- IPv4 virtual router information:
- Running mode : Standard
- Total number of virtual routers : 2
- Interface VRID State Running Adver Auth Virtual
- pri timer(cs) type IP
- ---------------------------------------------------------------------
- Vlan10 1 Master 120 100 None 192.168.10.254
- Vlan20 2 Backup 100 100 None 192.168.20.254
- //接口IP地址配置和ospf配置
- [sw1]interface g1/0/9
- [sw1-GigabitEthernet1/0/9]port link-mode route
- [sw1-GigabitEthernet1/0/9]ip address 10.0.0.1 30
- [sw1]ospf 1
- [sw1-ospf-1]area 0
- [sw1-ospf-1-area-0.0.0.0]network 10.0.0.1 0.0.0.0
- [sw1-ospf-1-area-0.0.0.0]network 192.168.10.0 0.0.0.255
- [sw1-ospf-1-area-0.0.0.0]network 192.168.20.0 0.0.0.255
-
-
- ### sw2
- sysname sw2
- [sw2]vlan10
- [sw2]quit
- [sw2]vlan 20
- [sw2]quit
- //链路聚合
- [sw2]interface Bridge-Aggregation 1
- [sw2-Bridge-Aggregation1]quit
- [sw2]interface range g1/0/7 g1/0/8
- [sw2-if-range]port link-aggregation group 1
- [sw2]interface Bridge-Aggregation 3
- [sw2-Bridge-Aggregation3]quit
- [sw2]interface range g1/0/5 g1/0/6
- [sw2-if-range]port link-aggregation group 3
- //配置trunk
- [sw2]interface Bridge-Aggregation 1
- [sw2-Bridge-Aggregation1]port link-type trunk
- [sw2-Bridge-Aggregation1]port trunk permit vlan all
- [sw2-Bridge-Aggregation1]quit
- [sw2]interface Bridge-Aggregation 3
- [sw2-Bridge-Aggregation3]port link-type trunk
- [sw2-Bridge-Aggregation3]port trunk permit vlan all
- //配置mstp(默认开启)
- [sw2]stp region-configuration
- [sw2-mst-region]region-name h3c
- [sw2-mst-region]revision-level 1
- [sw2-mst-region]instance 1 vlan 10
- [sw2-mst-region]instance 2 vlan 20
- [sw2-mst-region]active region-configuration
- //默认instance2的根端口在sw2,保证了vlan 20走右边
- [sw2]display stp instance 2 brief
- MST ID Port Role STP State Protection
- 2 Bridge-Aggregation1 ALTE DISCARDING NONE
- 2 Bridge-Aggregation3 ROOT FORWARDING NONE
- //vrrp配置
- [sw2]interface Vlan-interface 10
- [sw2-Vlan-interface10]ip address 192.168.10.252 24
- [sw2-Vlan-interface10]vrrp vrid 1 virtual-ip 192.168.10.254
- [sw2]interface Vlan-interface 20
- [sw2-Vlan-interface20]ip address 192.168.20.253 24
- [sw2-Vlan-interface20]vrrp vrid 2 virtual-ip 192.168.20.254
- [sw2-Vlan-interface20]vrrp vrid 2 priority 120
- [sw2]display vrrp
- IPv4 virtual router information:
- Running mode : Standard
- Total number of virtual routers : 2
- Interface VRID State Running Adver Auth Virtual
- pri timer(cs) type IP
- ---------------------------------------------------------------------
- Vlan10 1 Backup 100 100 None 192.168.10.254
- Vlan20 2 Master 120 100 None 192.168.20.254
- //接口IP地址配置和ospf配置
- [sw2]interface g1/0/9
- [sw2-GigabitEthernet1/0/9]port link-mode route
- [sw2-GigabitEthernet1/0/9]ip address 10.0.0.5 30
- [sw2]ospf 1
- [sw2-ospf-1]area 0
- [sw2-ospf-1-area-0.0.0.0]network 10.0.0.5 0.0.0.0
- [sw2-ospf-1-area-0.0.0.0]network 192.168.20.0 0.0.0.255
- [sw2-ospf-1-area-0.0.0.0]network 192.168.10.0 0.0.0.255
- //配置dhcp,给Vlan 20的主机分配IP地址
- [sw2]dhcp enable
- [sw2]dhcp server ip-pool 1
- [sw2-dhcp-pool-1]network 192.168.20.0 24
- [sw2-dhcp-pool-1]gateway-list 192.168.20.254
- [sw2-dhcp-pool-1]dns-list 114.114.114.114
-
-
- ### sw3
- sysname sw3
- [sw3]vlan10
- [sw3]quit
- [sw3]vlan 20
- [sw3]quit
- [sw3]interface g1/0/1
- [sw3-GigabitEthernet1/0/1]port link-type access
- [sw3-GigabitEthernet1/0/1]port access vlan 10
- [sw3-GigabitEthernet1/0/1]quit
- [sw3]interface g1/0/2
- [sw3-GigabitEthernet1/0/2]port link-type access
- [sw3-GigabitEthernet1/0/2]port access vlan 20
- //链路聚合
- [sw3]interface Bridge-Aggregation 2
- [sw3-Bridge-Aggregation2]quit
- [sw3]interface range g1/0/3 g1/0/4
- [sw3-if-range]port link-aggregation group 2
- [sw3]interface Bridge-Aggregation 3
- [sw3-Bridge-Aggregation3]quit
- [sw3]interface range g1/0/5 g1/0/6
- [sw3-if-range]port link-aggregation group 3
- //配置trunk
- [sw3]interface Bridge-Aggregation 2
- [sw3-Bridge-Aggregation2]port link-type trunk
- [sw3-Bridge-Aggregation2]port trunk permit vlan all
- [sw3-Bridge-Aggregation2]quit
- [sw3]interface Bridge-Aggregation 3
- [sw3-Bridge-Aggregation3]port link-type trunk
- [sw3-Bridge-Aggregation3]port trunk permit vlan all
- //配置mstp(默认开启)
- [sw3]stp region-configuration
- [sw3-mst-region]region-name h3c
- [sw3-mst-region]revision-level 1
- [sw3-mst-region]instance 1 vlan 10
- [sw3-mst-region]instance 2 vlan 20
- [sw3-mst-region]active region-configuration
-
-
- ### irf1
- sysname irf1
- //接口IP地址配置和ospf配置
- [irf1]interface g1/0/9
- [irf1-GigabitEthernet1/0/9]port link-mode route
- [irf1-GigabitEthernet1/0/9]ip address 10.0.0.2 30
- [irf1-GigabitEthernet1/0/9]quit
- [irf1]interface g1/0/1
- [irf1-GigabitEthernet1/0/1]port link-mode route
- [irf1-GigabitEthernet1/0/1]ip address 10.0.0.9 30
- [irf1-GigabitEthernet1/0/1]quit
- [irf1]interface g1/0/10
- [irf1-GigabitEthernet1/0/10]port link-mode route
- [irf1-GigabitEthernet1/0/10]ip address 10.1.1.2 24
- [irf1]ospf 1
- [irf1-ospf-1]area 0
- [irf1-ospf-1-area-0.0.0.0]network 10.0.0.9 0.0.0.0
- [irf1-ospf-1-area-0.0.0.0]network 10.0.0.2 0.0.0.0
- [irf1-ospf-1-area-0.0.0.0]network 10.1.1.2 0.0.0.0
-
-
- ### irf2
- sysname irf2
- //接口IP地址配置和ospf配置
- [irf2]interface g1/0/9
- [irf2-GigabitEthernet1/0/9]port link-mode route
- [irf2-GigabitEthernet1/0/9]ip address 10.0.0.6 30
- [irf2-GigabitEthernet1/0/9]quit
- [irf2]interface g1/0/1
- [irf2-GigabitEthernet1/0/1]port link-mode route
- [irf2-GigabitEthernet1/0/1]ip address 10.0.0.13 30
- [irf2]ospf 1
- [irf2-ospf-1]area 0
- [irf2-ospf-1-area-0.0.0.0]network 10.0.0.13 0.0.0.0
- [irf2-ospf-1-area-0.0.0.0]network 10.0.0.6 0.0.0.0
-
-
- ### NAT
- sysname NAT
- //接口IP地址配置和ospf配置
- [NAT]interface g0/0
- [NAT-GigabitEthernet0/0]ip address 10.0.0.10 30
- [NAT-GigabitEthernet0/0]quit
- [NAT]interface g0/1
- [NAT-GigabitEthernet0/1]ip address 10.0.0.14 30
- [NAT]ospf 1
- [NAT-ospf-1]area 0
- [NAT-ospf-1-area-0.0.0.0]network 10.0.0.10 0.0.0.0
- [NAT-ospf-1-area-0.0.0.0]network 10.0.0.14 0.0.0.0
- //NAT上配置easy ip,将vlan 10和vlan 20进行转换
- [NAT]acl
- [NAT]acl basic 2000
- [NAT-acl-ipv4-basic-2000]rule permit source 192.168.10.0 0.0.0.255
- [NAT-acl-ipv4-basic-2000]rule permit source 192.168.20.0 0.0.0.255
- [NAT]interface g0/2
- [NAT-GigabitEthernet0/2]nat outbound 2000
- //ISP和NAT之间配置PPPOE拨号
- [NAT]dialer-group 1 rule ip permit
- [NAT]interface Dialer 1
- [NAT-Dialer1]dialer bundle enable
- [NAT-Dialer1]dialer-group 1
- [NAT-Dialer1]ip address ppp-negotiate
- [NAT-Dialer1]ppp pap local-user fengyongxuan password simple 123
- [NAT-Dialer1]quit
- [NAT]interface g0/2
- [NAT-GigabitEthernet0/2]pppoe-client dial-bundle-number 1
- [NAT-GigabitEthernet0/2]quit
- [NAT]ip route-static 0.0.0.0 0 Dialer 1 ---配置拨号口为静态路由
- //通过ospf下发静态路由
- [NAT]ospf 1
- [NAT-ospf-1]default-route-advertise
- //修改:配置完拨号上网,NAT转换应往拨号口去转换,而非原来的物理接口
- [NAT]interface g0/2
- [NAT-GigabitEthernet0/2]undo nat outbound 2000
- [NAT-GigabitEthernet0/2]quit
- [NAT-Dialer1]nat outbound 2000
-
-
- ### ISP
- sysname ISP
- //ISP上配置loopback口模拟外网,地址5.5.5.5/32
- [ISP]interface LoopBack 0
- [ISP-LoopBack0]ip address 5.5.5.5 32
- //ISP和NAT之间配置PPPOE拨号
- [ISP]local-user fengyongxuan class network
- New local user added.
- [ISP-luser-network-fengyongxuan]password simple 123
- [ISP-luser-network-fengyongxuan]service-type ppp
- [ISP-luser-network-fengyongxuan]authorization-attribute user-role network-admin
- [ISP-luser-network-fengyongxuan]quit
- [ISP]domain system
- [ISP-isp-system]authentication ppp local
- [ISP-isp-system]quit
- [ISP]ip pool 1 200.0.0.1
- [ISP]interface Virtual-Template 1
- [ISP-Virtual-Template1]ppp authentication-mode pap domain system
- [ISP-Virtual-Template1]remote address pool 1
- [ISP-Virtual-Template1]quit
- [ISP-Virtual-Template1]ip address 200.0.0.2 24
- [ISP-Virtual-Template1]quit
- [ISP]interface g0/2
- [ISP-GigabitEthernet0/2]pppoe-server bind virtual-template 1
-
-
- ### 其它常用指令
- 查看路由表:display ip routing-table
- 查看端口状态:
- [NAT]interface g0/2
- [NAT-GigabitEthernet0/2]display this
- 撤销指令:undo 指令
- 一定要记得保存配置:save
- 有时候修改完还是没效果,保存配置,再重启设备试试
- 有时候ping不同,显示超时,不一定是配置出了问题,可能是网速的原因,多试试,比如依次去ping路径上的路由器
-