易陆发现互联网技术论坛

 找回密码
 开始注册
查看: 1059|回复: 1
收起左侧

实验AR1200+S5700+S3700网络组网

[复制链接]
发表于 2022-3-23 15:00:01 | 显示全部楼层 |阅读模式

马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。

您需要 登录 才可以下载或查看,没有账号?开始注册

x
AR1200+S5700+S3700访问外网的例子,其实也是我们公司实际的网络拓扑网,只是公司的还没有进行配置,AR2220做为路由访问外网,一台S5700是核心交换机,两台S3700做为接入层交换机使用,为每台S3700划分一个vlan,在本例中,一个是vlan 2,一个是vlan 4,只要这两个会了,再增加交换机也就没有问题了,希望对初学者有些帮助.网络拓扑图如下:
" K3 Y+ x5 Z  t) F+ D7 w# D

. T8 U4 P% w8 v  U
6 T+ {2 p2 S9 V2 `& T
                               
登录/注册后可看大图
画图水平不行, 凑活着看就行,下面配置主路由器AR1200,'号后面是备注信息,配置如下:

' @8 X2 F8 n0 i6 Z
[Huawei]acl number 2000                ' q# ~3 D- |3 Q8 p' w. E# D6 V
[Huawei-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255   '做个acl,可以根据自己需要配置IP,
4 O: J9 A+ v) L3 h[Huawei-acl-basic-2000]q% J" y4 J1 A- v7 Z3 S& }
[Huawei]vlan 100
8 h9 S5 c6 H( I[Huawei-vlan100]q& |; E& Q; D2 N6 T
[Huawei]interface giga 0/0/0- P0 W4 j8 o! ~% i
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.3 24  '配置外网IP地址,也就是联通呀,移动等运营商提供给你的IP址,24是掩码          * H) P1 l' r+ r0 N$ c. N. [7 y
[Huawei-GigabitEthernet0/0/0]q# |8 ^) |8 M7 o+ I
[Huawei]interface giga 0/0/15 M' S# D0 S# l& C" |  Z
[Huawei-GigabitEthernet0/0/1]ip address 1.1.1.1 24   
: L' E- @: P! y1 O! H7 `[Huawei-GigabitEthernet0/0/1]q$ k* V9 R5 v+ x
[Huawei]ip route-static 0.0.0.0 0.0.0.0 192.168.1.1       '静态路由,使内网的所有外部访问都指向外网网关,网关是运营商提供的.. ~. J( |6 o8 M, K. \) i0 \
[Huawei]ip route-static 192.168.2.0 255.255.255.0 1.1.1.3  '静态路由,所有访问192.168.2.X的请求指向1.1.1.3
" C* T1 f4 s+ L+ A" U& S2 g[Huawei]ip route-static 192.168.4.0 255.255.255.0 1.1.1.4  '静态路由,所有访问192.168.4.X的请求指向1.1.1.4
/ B9 o1 r& O  ~1 t/ s# v[Huawei]                                                                        '可以根据需要自己再增加
2 N$ {1 U7 E7 n7 k<Huawei>! o1 u1 r) t2 ~3 j* g' U3 O+ S" i
刚开始搞不明白为什么路由器上的接口可以设置IP地址,交换机上的就不行,输入命令时经常搞错,所以遇到路由器就在接口上设置IP,交换机就在Vlanif接口上设置IP就行,也不知我的想法对不.
+ E1 ]+ v# N0 y! @) Y% J, x( U# F: ^7 p/ c/ q6 f/ T3 P
接下来配置S5700核心交换机,配置如下:

[Huawei]undo info-center enable! e- T7 q/ D! f0 ^$ `
Info: Information center is disabled.
0 J6 x$ X+ z/ b2 a[Huawei]vlan 100' E/ t# Y$ G2 P9 P
[Huawei-vlan100]q0 c% ^) F" h) {$ m* q$ Y
[Huawei]interface vlanif 100( O  R$ x3 a. i' w
[Huawei-Vlanif100]ip address 1.1.1.2 246 Y9 X( V# w( t7 r; E) w; F
[Huawei-Vlanif100]q
, N6 ?) u2 U/ ?8 M% G5 ?. F7 d7 q) c[Huawei]interface giga 0/0/222 Z* w* H7 {" E: ^
[Huawei-GigabitEthernet0/0/22]port link-type trunk                      '交换机和交换机之间连接用trunk接口4 B( a, }$ I7 j9 {# E7 J- M* L
+ n6 F7 [8 Q0 T" U" C. y5 _% V
[Huawei-GigabitEthernet0/0/22]port trunk allow-pass vlan 100 2     '允许通过vlan100和vlan2
9 t5 s$ \) f: a. f[Huawei-GigabitEthernet0/0/22]q$ c( c% |' v& c: {
[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1- I; c2 }" ~0 N& `
[Huawei]interface giga 0/0/24* t$ Q6 d. D, w! O

" Z0 B; y' X4 k2 w3 [- f& S9 _7 l* `[Huawei-GigabitEthernet0/0/24]port link-type access9 U9 b2 j, q) i& l1 ?2 u+ @
[Huawei-GigabitEthernet0/0/24]port default vlan 100% A' S. L8 W- m! P
[Huawei-GigabitEthernet0/0/24]q
% `- g4 P0 F0 \( K[Huawei]interface giga 0/0/23
' f7 t* R  J% h1 U: ?) g+ {[Huawei-GigabitEthernet0/0/23]port link-type trunk                     '同上面22接口  J1 H9 U5 y  V
[Huawei-GigabitEthernet0/0/23]port trunk allow-pass vlan 100 4    '允许通过vlan100和vlan46 Y/ y+ \9 X, T; Z
[Huawei-GigabitEthernet0/0/23]q
% f1 z" e3 k" r2 ~" N; W8 Z/ s; _5 Q

; G4 J! z6 a9 D' n
$ f1 w/ _, J9 y6 q( O3 h  a0 h下面配置S3700交换机,属于vlan2
[Huawei]undo info-center enable: F0 O: y5 x9 Z% S
Info: Information center is disabled.+ d+ k- i& }9 |; a" m) w% q
[Huawei]vlan 100
# r3 o, k! b' W0 x8 |0 V' M[Huawei-vlan100]q
& ~# G- C8 g& l7 m- w[Huawei]interface eth 0/0/223 `; |# g0 [4 ]
[Huawei-Ethernet0/0/22]ip address 1.1.1.3 24  '在这个地方出错了,不允许在接口上设置IP0 H/ }6 F0 v' K7 n" F
                          ^8 A: F3 \/ O8 \/ f8 J
Error: Unrecognized command found at '^' position.! T3 q* H# e2 ?6 A; V
[Huawei-Ethernet0/0/22]port link-type trunk
- f; x8 B" k0 E' _. i9 n& ?[Huawei-Ethernet0/0/22]port trunk allow-pass vlan 100 2
4 c, r( A" ?. I: z' w[Huawei-Ethernet0/0/22]q. N( K; Y- D1 \# x* y' v
[Huawei]interface vlanif 100
. y5 Y/ j8 A; f[Huawei-Vlanif100]ip address 1.1.1.3 24
$ X2 z0 Z/ R! d, l% S' D. v/ H[Huawei-Vlanif100]q) K, i/ C! B, D, X6 Z: X
[Huawei]vlan 2* c; j" w; o2 Q, h5 H  R; ?
[Huawei-vlan2]q
8 B. l2 A6 J5 k6 G8 c[Huawei]interface vlanif 2
+ W# p' i1 `3 H! E: }[Huawei-Vlanif2]ip address 192.168.2.1 240 Y& d( E+ o5 d" u7 t
[Huawei-Vlanif2]q
, ?' a& B( X1 q' o[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1
5 \' G+ K6 k# d[Huawei]interface eth 0/0/1
2 n  T7 B1 N5 O+ M6 b/ Y[Huawei-Ethernet0/0/1]port hybrid untagged vlan 2
. B/ ^( l3 J3 I7 L8 N& {
[Huawei-Ethernet0/0/1]port hybrid pvid vlan 2% B2 S! F7 w& ^- P+ d
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 100 2
1 J8 E4 V9 `6 Q& ][Huawei-Ethernet0/0/1]dis this         ' 查看一下接口信息- U3 B5 S, w, y& a3 @
#& k2 c4 t* E3 W: @& p2 A: B
interface Ethernet0/0/1
9 t; f$ w% P7 Q8 z! M port hybrid pvid vlan 28 V( V7 M# a7 Q
port hybrid untagged vlan 2 100( y& q5 T, r+ r5 A1 [& i
#
4 \% [/ N. z# G' M& ]' Greturn: }5 ]9 w( i! p2 \4 Q

$ a# ~7 h0 o* h+ d! U/ z$ [
下面配置S3700-2交换机,属于vlan4

[Huawei]undo info-center enable! q2 a% x% z; [8 D: l9 U5 Y0 k- `
Info: Information center is disabled.
. l6 B, P3 F$ i5 w3 Q+ P[Huawei]vlan 100( v/ u. x( _9 b
[Huawei-vlan100]q
2 y2 X$ {, J" n2 ^5 V[Huawei]interface vlanif 100
2 }1 o) D6 D. z- p3 `# N* l6 q[Huawei-Vlanif100]ip address 1.1.1.4 24
* E$ ?' k1 [# H- m6 ?; C3 P' E9 u[Huawei-Vlanif100]q$ n9 E: G* ?  u, M5 v- t7 k4 g
[Huawei]interface eth 0/0/22' q6 n4 ]% p5 k. \* |. [0 Z, J
[Huawei-Ethernet0/0/22]port link-type trunk
0 j5 l* L2 a1 A' d[Huawei-Ethernet0/0/22]port trunk allow-pass vlan 100 4
0 I  d1 L1 M7 }0 P; `[Huawei-Ethernet0/0/22]dis this, n; Q0 T( Q3 [: b' y
#
. L! P3 d3 C! o( v- b8 Linterface Ethernet0/0/228 `' u9 y6 l8 D7 @
port link-type trunk
( g3 ~8 ]) @% Y# L8 s port trunk allow-pass vlan 4 100
" ~; C+ U( x- ]/ b#
) }  e5 Q1 }( z% G5 creturn( h0 M0 F# ]# T5 Y& T
[Huawei-Ethernet0/0/22]q9 q3 Z+ r: Y4 L* b( f9 D% C6 B& Q
[Huawei]vlan 4! P% a+ ^4 }& u6 Y! q9 L
[Huawei-vlan4]q6 Z, f" Z5 d$ ^9 i# [% @; }' A
[Huawei]interface vlanif 4
( ?$ f: V) D; P! d0 C+ K[Huawei-Vlanif4]ip address 192.168.4.1 24- M! E8 w  _' }" S5 E4 M& a" v0 S
[Huawei-Vlanif4]q
$ b( K, ?  K; N" l6 z[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.17 [* j: ]3 C8 `. |- ]9 A) a
[Huawei]ping 192.168.4.1- d( h6 i% X( c$ r1 a. D. N
  PING 192.168.4.1: 56  data bytes, press CTRL_C to break5 v. @- V9 M! V$ z1 x
    Reply from 192.168.4.1: bytes=56 Sequence=1 ttl=255 time=20 ms: }+ X' o1 U  I8 i, t9 G9 X
    Reply from 192.168.4.1: bytes=56 Sequence=2 ttl=255 time=10 ms
0 s4 N! v: i' ^    Reply from 192.168.4.1: bytes=56 Sequence=3 ttl=255 time=1 ms* M+ |" p& {# d' I6 v  e
    Reply from 192.168.4.1: bytes=56 Sequence=4 ttl=255 time=30 ms* \* p+ k& A7 y7 @; f2 ~
    Reply from 192.168.4.1: bytes=56 Sequence=5 ttl=255 time=1 ms
5 ]9 w' g! a+ k3 i- y% J  --- 192.168.4.1 ping statistics ---
/ T7 G5 m( z1 X/ C    5 packet(s) transmitted4 ?, _+ n+ p* C2 g0 ]
    5 packet(s) received
* k9 A# S$ z% R# Y    0.00% packet loss
: N' u$ h1 S* W! ~- E    round-trip min/avg/max = 1/12/30 ms$ J% |2 V; ~* U9 t
[Huawei]interface eth 0/0/1
6 o* U/ Z! H7 _( }( {
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 100 40 u, r) \4 [* Y/ X
[Huawei-Ethernet0/0/1]port hybrid pvid vlan 4/ e7 |  h  B2 X( O
[Huawei-Ethernet0/0/1]q
& Y1 [+ ~8 J3 D; a1 I1 {; P7 L% E/ ^
# e0 D# q& ?6 K0 R4 N) ~
好了,交换机和路由器的设置就完成了,把两个PC客户端配置好IP地址就可以试试效果了,但由于是模拟器的原因,在长间没有使用时,有时候会有ping不通的情况,在我这里两个都能ping通外网,vlan2和vlan4之间也能互通.在真实的设备上我们可以启用web界面和telnet,然后通过1.1.1.1,1.1.1.2,1.1.1.3这些地址来访问和管理路由器和交换机了,端口隔离,mac黑洞之类的配置可以在web界面上操作,谁让咱会的太少了.下面是前两个例子的地址,从简到稍难

2 o! P: E, n/ E0 m
 楼主| 发表于 2022-3-23 15:00:02 | 显示全部楼层
首先配置AR2220,设置GE0接口IP为固定外网地址,设置GE1接口IP为1.1.1.1,然后做两条静态路由,创建vlan 100,红色文本是需要特别多看几眼的,代码如下:

[Huawei]vlan 100

/ ^: `, |# y' M5 k8 L
[Huawei-vlan100]q
. y3 Y/ e2 f' f& _- i$ a5 H% V
[Huawei]acl number 2000

3 o! @. J" e% v) l
[Huawei-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255
; d  A/ O+ k& u& p; s
[Huawei-acl-basic-2000]q
5 [4 R+ s$ k- Z% R
[Huawei]interface giga 0/0/0
. d1 k* N" J( J% |3 S. j: L3 I. q
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.3 255.255.255.0
  C: b% `1 V4 @: L: }
[Huawei-GigabitEthernet0/0/0]
8 ]1 T+ s2 ?% J- O( Y4 k
Mar 13 2014 07:34:12-05:13 Huawei %IFNET/4/LINK_STATE(l)[1]:The line protocol

- D$ S" Y' F" |
IP on the interface GigabitEthernet0/0/0 has entered the UP state.
: U! N! g/ P5 K* b0 [) g  V
[Huawei-GigabitEthernet0/0/0]q

8 m9 p( _2 @6 X5 z" w
[Huawei]interface giga 0/0/1
  ?, I0 H. _- {) B5 ^+ C: S# p
[Huawei-GigabitEthernet0/0/1]ip address 1.1.1.1 255.255.255.0
% n8 I  L% F( i8 f6 A
[Huawei-GigabitEthernet0/0/1]q
) B0 d3 a0 j- |6 a. f0 j
[Huawei]ip route-static 0.0.0.0 0.0.0.0 192.168.1.1

4 n! O$ I; s+ j- J+ ]" \' u
[Huawei]ip route-static 192.168.0.0 255.255.0.0 1.1.1.2
  C3 q" D3 v6 ]  T. L
[Huawei]q

$ r/ L& n, U5 d( a2 v
save
" w( l  b: [, d8 z1 u4 r2 p/ E
  The current configuration will be written to the device.

2 O* J" Z0 W* L, l* f
  Are you sure to continue? (y/n)[n]:y

- X) I8 f$ n! R, v$ Z
  It will take several minutes to save configuration file, please wait..........

$ o$ n& p, ]% h* O2 z' p) X
) M! w+ A2 U5 i9 l, b" U+ i3 ^
# w; k. g0 a; {6 X) e
  Configuration file had been saved successfully
% z5 @8 e6 K! D% J2 u8 q
  Note: The configuration file will take effect after being activated
3 s' M6 {! u5 T5 U3 {; n
: Q  k% n" R9 Z/ O5 J
Mar 13 2014 07:37:25-05:13 Huawei ARP/4/ARP_IPCONFLICT_TRAP:OID 16777216.50331648
) N8 }* s  m; b: `
.100663296.16777216.67108864.16777216.3674669056.83886080.419430400.2063597568.33

' b  F: i& A# Q2 `) Z& D
554432.100663296 ARP detects IP conflict. (IP address=201.1.168.192, Local interf

; M0 R8 a2 o! K( \- l& X
ace=GigabitEthernet0/0/0, Local MAC=4437-e68c-b212, Local vlan=0, Local CE vlan=0

. H8 G' C5 D, \  d/ O
, Receive interface=GigabitEthernet0/0/0, Receive MAC=1c1a-c00f-253f, Receive vla

8 y+ j7 _- l- ?1 F6 ~9 r4 A. n
n=0, Receive CE vlan=0, IP conflict type=Remote IP conflict).

) s" F, K" e7 m$ o6 j' u; M6 M5 X: f" s. ]/ s- V
% C0 k8 k  r$ Y; Q: v: {

接下来配置S5700交换机,GE1接口IP为1.1.1.2,属于vlan100,GE2接口属于vlan1,GE3接口属于vlan2,代码如下

[Huawei]vlan batch 2 4 6 8 100
Info: This operation may take a few seconds. Please wait for a moment...done.

- _5 {5 e% `( p5 n' R6 \
[Huawei]
2 b$ H& u' d0 l, _5 G0 g/ I
Mar 13 2014 10:38:34-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.
+ ?& p9 ?6 I. n7 Y* Z
25.191.3.1 configurations have been changed. The current change number is 4, the
3 H/ r' j  _& x. Z, `4 K" p
change loop count is 0, and the maximum number of records is 4095.
" l+ k2 k: X. K: d4 ]4 M: ]% {- N# Y
[Huawei]interface vlanif 100

- E, H- U0 T, `; R( G4 |
[Huawei-Vlanif100]ip address 1.1.1.2 255.255.255.0

- ^: l: z5 y) ~  T6 v6 X& c
[Huawei-Vlanif100]

5 p3 V0 c6 d. B! Z
Mar 13 2014 10:40:14-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.
( d: q) O% R" S8 G. j
25.191.3.1 configurations have been changed. The current change number is 6, the
5 j# \3 a" G" V8 i1 ^# d0 m& d
change loop count is 0, and the maximum number of records is 4095.

' |( }+ y. e1 z8 y
[Huawei-Vlanif100]q
( D1 `& w* j; @: l* r3 J
[Huawei]interface giga 0/0/1

) t( w& w; ~$ c5 _
[Huawei-GigabitEthernet0/0/1]port link-type access

: C  i3 G$ ?5 u: k+ \7 s
[Huawei-GigabitEthernet0/0/1]port default vlan 100

' ~0 ?6 f: k6 k& n# u
[Huawei-GigabitEthernet0/0/1]q

$ I* O+ n3 W+ X: b
[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1
! U7 B8 N7 u0 k( Y# [( k$ P
[Huawei]
; {+ V. j# P7 H$ Z/ {0 m, K
Mar 13 2014 10:43:24-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.

: W6 ^& v8 Q$ N/ Z& g! B
25.191.3.1 configurations have been changed. The current change number is 9, the
! Y8 r# W3 b4 c# C: _5 ~4 {4 f
change loop count is 0, and the maximum number of records is 4095.

! q9 s3 h+ \5 d. j' j: R% d
[Huawei]interface vlanif 1

- e$ m! U$ T. o; R# E
[Huawei-Vlanif1]ip address 192.168.0.1 255.255.255.0

* g9 w3 C' Q! ]7 C
[Huawei-Vlanif1]q
7 s3 A$ e9 ]) P" u$ I* }/ c: m5 D, E
[Huawei]interface vlanif 2
1 j& Y" S2 ^; g. Z9 a/ y3 \
[Huawei-Vlanif2]ip address 192.168.2.1 255.255.255.0

& O( w. @. L3 o0 U" f2 |
[Huawei-Vlanif2]q
! j. _5 e( X- \  ^/ b6 Q! P' |/ I/ g
[Huawei]interface giga 0/0/3

2 P; r. O9 @) ~! I/ f. l7 T
[Huawei-GigabitEthernet0/0/3]port link-type access

3 O/ ?+ s; n" [8 k+ t3 N! A* W
[Huawei-GigabitEthernet0/0/3]port default vlan 2
& y: I2 _5 m( d6 X( [. n
[Huawei-GigabitEthernet0/0/3]
: g6 Y: [) U% q$ ]8 P, e
[Huawei]q
( }# h  M- U3 H1 @* d, K3 T( i' L6 o
save
8 ^* k5 [3 g1 T0 z
The current configuration will be written to the device.

0 q+ |- g7 c5 m- J. o2 O
Are you sure to continue?[Y/N]y
5 H/ P2 z1 E7 I) H/ X1 j# b
Now saving the current configuration to the slot 0.

  O& H/ e( U; A2 r
Mar 13 2014 11:02:44-08:00 Huawei %CFM/4/SAVE(l)[11]:The user chose Y when dec
) L0 h! Y' D( O" U' @0 K* _
iding whether to save the configuration to the device.

9 Y- \6 k9 a) z- [
Save the configuration successfully.
  p1 `' d; o3 ~

0 [) N6 K2 Y, Q/ ?2 B. j; o
然后设置PC1和PC2的IP地址,先ping 1.1.1.1,如果没有问题再ping 192.168.1.3,192.168.1.111,202.99.192.66,一路ping下来是不是感觉有点小成就感,如果PC2无法ping通,那么就像昨天一样,在自己的真实路由器上做个静态路由指向192.168.2.0便可以了.需要的可以下载附件导出配置文件看.
! X9 g4 l1 l- D' X1 q% W

. I) b, l$ M. D, W$ H. O# N
& y! [( [5 v/ ^* t# v6 ~
您需要登录后才可以回帖 登录 | 开始注册

本版积分规则

关闭

站长推荐上一条 /4 下一条

北京云银创陇科技有限公司以云计算运维,代码开发

QQ|返回首页|Archiver|小黑屋|易陆发现技术论坛 点击这里给我发消息

GMT+8, 2026-4-9 09:17 , Processed in 0.047126 second(s), 21 queries .

Powered by Discuz! X3.4 Licensed

© 2012-2025 Discuz! Team.

快速回复 返回顶部 返回列表