?本站以分享各種運維經(jīng)驗和運維所需要的技能為主
《python零基礎(chǔ)入門》:python零基礎(chǔ)入門學(xué)習(xí)
《python運維腳本》:?python運維腳本實踐
《shell》:shell學(xué)習(xí)
《terraform》持續(xù)更新中:terraform_Aws學(xué)習(xí)零基礎(chǔ)入門到最佳實戰(zhàn)
《k8》暫未更新
《docker學(xué)習(xí)》暫未更新
《ceph學(xué)習(xí)》ceph日常問題解決分享
《日志收集》ELK+各種中間件
《運維日?!愤\維日常
《linux》運維面試100問
一、網(wǎng)絡(luò)拓?fù)?/p>
1.網(wǎng)絡(luò)架構(gòu)
核心層:接入網(wǎng)絡(luò)----路由器
匯聚層:vlan間通信
-
創(chuàng)建vlan ---什么是vlan:虛擬局域網(wǎng),在大型平面網(wǎng)絡(luò)中,為了實現(xiàn)廣播控制引入了vlan,可以根據(jù)功能或者部門等創(chuàng)建vlan,再把相關(guān)的端口加入到vlan.為了實現(xiàn)不用交換機(jī)上的相同vlan通信,需要配置中繼,為了實現(xiàn)不同vlan間通信,需要配置三層交換
-
中繼:實現(xiàn)不同交換機(jī)上的相同vlan通信,封裝協(xié)議采用ieee802.1q
-
聚合鏈路, 以太通道
-
為了實現(xiàn)不同vlan互相通信,還需要配置三層交換
接入層:接入終端和服務(wù)器文章來源:http://www.zghlxwxcb.cn/news/detail-652458.html
文章來源地址http://www.zghlxwxcb.cn/news/detail-652458.html
交換機(jī)sw1上的配置:
<sw1>system-view 進(jìn)入系統(tǒng)視圖
[Huawei]sysname sw1 改設(shè)備名稱
[sw1]vlan batch 1 2 3 創(chuàng)建vlan
或者[sw1]vlan batch 1 to 3 創(chuàng)建連續(xù)vlan
[sw1]display vlan summary? 查看vlan
將端口加進(jìn)vlan
[sw1]int e 0/0/1
[sw1-Ethernet0/0/1]port link-type access
[sw1-Ethernet0/0/1]port default vlan 1
[sw1]int e 0/0/3
[sw1-Ethernet0/0/1]port link-type access
[sw1-Ethernet0/0/1]port default vlan 2
[sw1]int e 0/0/4
[sw1-Ethernet0/0/1]port link-type access
[sw1-Ethernet0/0/1]port default vlan 3
[sw1]int e 0/0/2
[sw1-Ethernet0/0/2]port link-type trunk
[sw1-Ethernet0/0/2]port trunk allow-pass vlan all
sw2 同上
補充:
批量將端口加進(jìn)vlan
[sw1]port-group 1
[sw1-port-group-1]group-member e0/0/1 e0/0/3? 不連續(xù)的端口加進(jìn)組里
[sw1-port-group-1]group-member e0/0/1 to e0/0/3 連續(xù)的端口加進(jìn)組里
[sw1-port-group-1]port link-type access
[sw1-port-group-1]port default vlan 1
交換機(jī)之間需要配trunk口
[sw1-Ethernet0/0/2]port link-type trunk
[sw1-Ethernet0/0/2]port trunk allow-pass vlan all
三層交換機(jī)上的配置:
[3sw]vlan batch 1 2 3
[3sw]int Vlanif 1
[3sw-Vlanif4]ip address 192.168.1.254 24
[3sw]int Vlanif 2
[3sw-Vlanif4]ip address 192.168.2.254 24
[3sw]int Vlanif 3
[3sw-Vlanif4]ip address 192.168.3.254 24
[3sw]int g 0/0/1
[3sw-GigabitEthernet0/0/1]port link-type trunk
[3sw-GigabitEthernet0/0/1]port trunk allow-pass vlan all
[3sw]int g 0/0/2
[3sw-GigabitEthernet0/0/2]port link-type trunk
[3sw-GigabitEthernet0/0/2]port trunk allow-pass vlan all
三層交換機(jī)的路由功能默認(rèn)是開著的,只需要將端口加進(jìn)vlan中給其配IP即可
[3sw]int g 0/0/3
[3sw-GigabitEthernet0/0/3]port link-type access
[3sw-GigabitEthernet0/0/3]port default vlan 4
[3sw-GigabitEthernet0/0/3]q
[3sw]int Vlanif 4
[3sw-Vlanif4]ip address 192.168.4.2 24
動態(tài)路由ospf配置
[3sw]ospf 1
[3sw-ospf-1]area 0
[3sw-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255
[3sw-ospf-1-area-0.0.0.0]network 192.168.2.0 0.0.0.255
[3sw-ospf-1-area-0.0.0.0]network 192.168.3.0 0.0.0.255
[3sw-ospf-1-area-0.0.0.0]network 192.168.4.0 0.0.0.255
[3sw]ip route-static 0.0.0.0 0.0.0.0 192.168.4.1 //默認(rèn)靜態(tài)指向R1的g0/0/0端口
R1的配置:
[R1]int g 0/0/0
[R1-GigabitEthernet0/0/0]ip address 192.168.4.1 24
[R1]int g 0/0/1
[R1-GigabitEthernet0/0/1]ip address 192.168.5.1 24
[R1]int g 0/0/2
[R1-GigabitEthernet0/0/2]ip address 192.168.6.1 24
[R1]ospf 1
[R1-ospf-1]area 0
[R1-ospf-1-area-0.0.0.0]network 192.168.4.0 0.0.0.255
[R1-ospf-1-area-0.0.0.0]network 192.168.5.0 0.0.0.255
[R1-ospf-1-area-0.0.0.0]network 192.168.6.0 0.0.0.255
R2的配置:
[R2]int g 0/0/0
[R2-GigabitEthernet0/0/0]ip address 192.168.5.1 24
[R1]ospf 1
[R1-ospf-1]area 0
[R1-ospf-1-area-0.0.0.0]network 192.168.5.0 0.0.0.255
R3的配置:
[R3]int g 0/0/0
[R3-GigabitEthernet0/0/0]ip address 192.168.6.1 24
[R3]ospf 1
[R3-ospf-1]area 0
[R3-ospf-1-area-0.0.0.0]network 192.168.6.0 0.0.0.255
刪除自動跳出的信息提醒:
undo terminal debugging
undo terminal monitor
undo terminal logging
undo terminal trapping
sys
user-interface console 0
idle-timeout 0
查看端口狀態(tài)命令:
[3SW1]display interface brief
查看路由狀態(tài):
[R1]display ip routing-table
[R1]display ip routing-table | include /24?? //過濾只要/24網(wǎng)段的
二層交換機(jī):
SW1:
[Huawei]sysname SW1
[SW1]port-group 1
[SW1-port-group-1]group-member Ethernet 0/0/4 Ethernet 0/0/5
[SW1-port-group-1]port link-type trunk
[SW1-port-group-1]port trunk allow-pass vlan all
[SW1-port-group-1]q
[SW1]vl batch 1 to 4
[SW1]int e 0/0/1
[SW1-Ethernet0/0/1]port link-type access
[SW1-Ethernet0/0/1]port default vlan 1
[SW1]int e 0/0/2
[SW1-Ethernet0/0/2]port link-type access
[SW1-Ethernet0/0/2]port default vlan 2
[SW1]int e 0/0/3
[SW1-Ethernet0/0/3]port link-type access
[SW1-Ethernet0/0/3]port default vlan 3
SW2 SW3 同上
SW4:
[SW4]port-group 1
[SW4-port-group-1]group-member Ethernet 0/0/4 Ethernet 0/0/5
[SW4-port-group-1]port link-type trunk
[SW4-port-group-1]port trunk allow-pass vlan all
[SW4]port-group 2
[SW4-port-group-2]group-member Ethernet 0/0/1? to Ethernet 0/0/3
[SW4-port-group-2]port link-type access
[SW4-port-group-2]port default vlan 4
三層交換機(jī)
3sw1:
[3SW1]port-group 1
[3SW1-port-group-1]group-member GigabitEthernet 0/0/1 to GigabitEthernet 0/0/5
[3SW1-port-group-1]port link-type trunk
[3SW1-port-group-1]port trunk allow-pass vlan all
[3SW1]vl batch 1 to 6
[3SW1]int Vlanif 1
[3SW1-Vlanif1]ip address 192.168.1.252 24
[3SW1-Vlanif1]vrrp vrid 1 virtual-ip 192.168.1.254
[3SW1-Vlanif1]vrrp vrid 1 priority 110
[3SW1]int Vlanif 2
[3SW1-Vlanif2]ip address 192.168.2.252 24
[3SW1-Vlanif2]vrrp vrid 2 virtual-ip 192.168.2.254
[3SW1-Vlanif2]vrrp vrid 2 priority 110
[3SW1]int Vlanif 3
[3SW1-Vlanif3]ip address 192.168.3.252 24
[3SW1-Vlanif3]vrrp vrid 3 virtual-ip 192.168.3.254
[3SW1]int Vlanif 4
[3SW1-Vlanif4] ip address 192.168.4.252 24
[3SW1-Vlanif4]vrrp vrid 4 virtual-ip 192.168.4.254
[3SW1]int g 0/0/6
[3SW1-GigabitEthernet0/0/6]port link-type access
[3SW1-GigabitEthernet0/0/6]port default vlan 5
[3SW1]int g 0/0/7
[3SW1-GigabitEthernet0/0/7]port link-type access
[3SW1-GigabitEthernet0/0/7]port default vlan 6
[3SW1]int Vlanif 5
[3SW1-Vlanif5]ip address 192.168.5.2 24
[3SW1]int Vlanif 6
[3SW1-Vlanif6]ip address 192.168.6.2 24
[3SW1]ospf 1
[3SW1-ospf-1]area 0
[3SW1-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255
[3SW1-ospf-1-area-0.0.0.0]network 192.168.2.0 0.0.0.255
[3SW1-ospf-1-area-0.0.0.0]network 192.168.3.0 0.0.0.255
[3SW1-ospf-1-area-0.0.0.0]network 192.168.4.0 0.0.0.255
[3SW1-ospf-1-area-0.0.0.0]network 192.168.5.0 0.0.0.255
[3SW1-ospf-1-area-0.0.0.0]network 192.168.6.0 0.0.0.255
3sw2:
[3SW2]port-group 1
[3SW2-port-group-1]group-member GigabitEthernet 0/0/1 to GigabitEthernet 0/0/5
[3SW2-port-group-1]port link-type trunk
[3SW2-port-group-1]port trunk allow-pass vlan all
[3SW2]vl batch 1 to 4 7 8
[3SW2]int Vlanif 1
[3SW2-Vlanif1]ip address 192.168.1.253 24
[3SW2-Vlanif1]vrrp vrid 1 virtual-ip 192.168.1.254
[3SW2]int Vlanif 2
[3SW2-Vlanif2]ip address 192.168.2.253 24
[3SW2-Vlanif2]vrrp vrid 2 virtual-ip 192.168.2.254
[3SW2]int Vlanif 3
[3SW2-Vlanif3]ip address 192.168.3.253 24
[3SW2-Vlanif3]vrrp vrid 3 virtual-ip 192.168.3.254
[3SW2-Vlanif1]vrrp vrid 1 priority 110
[3SW2]int Vlanif 4
[3SW2-Vlanif4] ip address 192.168.4.253 24
[3SW2-Vlanif4]vrrp vrid 4 virtual-ip 192.168.4.254
[3SW2-Vlanif2]vrrp vrid 2 priority 110
[3SW2]int g 0/0/6
[3SW2-GigabitEthernet0/0/6]port link-type access
[3SW2-GigabitEthernet0/0/6]port default vlan 7
[3SW2]int g 0/0/7
[3SW2-GigabitEthernet0/0/7]port link-type access
[3SW2-GigabitEthernet0/0/7]port default vlan 8
[3SW2]int Vlanif 7
[3SW2-Vlanif5]ip address 192.168.7.2 24
[3SW2]int Vlanif 8
[3SW2-Vlanif6]ip address 192.168.8.2 24
[3SW2]ospf 1
[3SW2-ospf-1]area 0
[3SW2-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255
[3SW2-ospf-1-area-0.0.0.0]network 192.168.2.0 0.0.0.255
[3SW2-ospf-1-area-0.0.0.0]network 192.168.3.0 0.0.0.255
[3SW2-ospf-1-area-0.0.0.0]network 192.168.4.0 0.0.0.255
[3SW2-ospf-1-area-0.0.0.0]network 192.168.7.0 0.0.0.255
[3SW2-ospf-1-area-0.0.0.0]network 192.168.8.0 0.0.0.255
路由器
R1:
[R1]acl 2000
[R1-acl-basic-2000]rule permit source any
[R1]int g 0/0/0
[R1-GigabitEthernet0/0/0]ip address 192.168.5.1 24
[R1]int g 0/0/1
[R1-GigabitEthernet0/0/1]ip address 192.168.8.1 24
[R1]int g 0/0/2
[R1-GigabitEthernet0/0/2]ip address 100.0.0.1 8
[R1-GigabitEthernet0/0/2]nat outbound 2000
[R1]ip route-static 0.0.0.0 0.0.0.0 100.0.0.10
[R1]ospf 1
[R1-ospf-1]default-route-advertise
[R1-ospf-1]area 0
[R1-ospf-1-area-0.0.0.0]network 192.168.5.0 0.0.0.255
[R1-ospf-1-area-0.0.0.0]network 192.168.8.0 0.0.0.255
R2:
R1:
[R2]acl 2000
[R2-acl-basic-2000]rule permit source any
[R2]int g 0/0/0
[R2-GigabitEthernet0/0/0]ip address 192.168.6.1 24
[R2]int g 0/0/1
[R2-GigabitEthernet0/0/1]ip address 192.168.7.1 24
[R2]int g 0/0/2
[R2-GigabitEthernet0/0/2]ip address 100.0.0.2 8
[R2-GigabitEthernet0/0/2]nat outbound 2000
[R2]ip route-static 0.0.0.0 0.0.0.0 100.0.0.10
[R2]ospf 1
[R2-ospf-1]default-route-advertise
[R2-ospf-1]area 0
[R2-ospf-1-area-0.0.0.0]network 192.168.6.0 0.0.0.255
[R2-ospf-1-area-0.0.0.0]network 192.168.7.0 0.0.0.255
最后的三層交換配個 vlan1 100.0.0.10 即可
到了這里,關(guān)于【網(wǎng)絡(luò)架構(gòu)】華為hw交換機(jī)網(wǎng)絡(luò)高可用網(wǎng)絡(luò)架構(gòu)拓?fù)鋱D以及配置的文章就介紹完了。如果您還想了解更多內(nèi)容,請在右上角搜索TOY模板網(wǎng)以前的文章或繼續(xù)瀏覽下面的相關(guān)文章,希望大家以后多多支持TOY模板網(wǎng)!