易陆发现互联网技术论坛

 找回密码
 开始注册
查看: 1058|回复: 1
收起左侧

实验AR1200+S5700+S3700网络组网

[复制链接]
发表于 2022-3-23 15:00:01 | 显示全部楼层 |阅读模式

马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。

您需要 登录 才可以下载或查看,没有账号?开始注册

x
AR1200+S5700+S3700访问外网的例子,其实也是我们公司实际的网络拓扑网,只是公司的还没有进行配置,AR2220做为路由访问外网,一台S5700是核心交换机,两台S3700做为接入层交换机使用,为每台S3700划分一个vlan,在本例中,一个是vlan 2,一个是vlan 4,只要这两个会了,再增加交换机也就没有问题了,希望对初学者有些帮助.网络拓扑图如下:
: y6 p6 D: H3 l$ n3 L# P
% M: I( M' l9 s! F! h3 n% W

, L% E7 K) l, B6 w# r; Y                               
登录/注册后可看大图
画图水平不行, 凑活着看就行,下面配置主路由器AR1200,'号后面是备注信息,配置如下:
. @. s# {* f+ ]3 D8 K

[Huawei]acl number 2000               
7 B  l2 M# u2 I9 {% e[Huawei-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255   '做个acl,可以根据自己需要配置IP,
% C+ S* Y- c) \* P+ d[Huawei-acl-basic-2000]q
' j9 X5 O0 X7 q( Y* B, u[Huawei]vlan 100
9 F* Q( m2 S7 s2 y[Huawei-vlan100]q0 ~1 q0 V' m% C( z& B3 H  V$ `
[Huawei]interface giga 0/0/0$ T! F0 L0 ^. b6 l4 N# a
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.3 24  '配置外网IP地址,也就是联通呀,移动等运营商提供给你的IP址,24是掩码         
; a5 k) y1 ^, O& o, Y[Huawei-GigabitEthernet0/0/0]q
0 T& a* B0 }' l- ~[Huawei]interface giga 0/0/1! s9 g8 x3 c0 z2 t+ @0 C
[Huawei-GigabitEthernet0/0/1]ip address 1.1.1.1 24   
0 o: h  @* `' e' B5 k5 i8 x0 h[Huawei-GigabitEthernet0/0/1]q3 U7 C% o  [0 }/ ]; {  \$ J
[Huawei]ip route-static 0.0.0.0 0.0.0.0 192.168.1.1       '静态路由,使内网的所有外部访问都指向外网网关,网关是运营商提供的.# E- a; X! q# u" `  f2 w8 `+ U# j* [0 p
[Huawei]ip route-static 192.168.2.0 255.255.255.0 1.1.1.3  '静态路由,所有访问192.168.2.X的请求指向1.1.1.32 Q  a, R& }+ V+ r! N
[Huawei]ip route-static 192.168.4.0 255.255.255.0 1.1.1.4  '静态路由,所有访问192.168.4.X的请求指向1.1.1.4& J/ @+ _- d6 i' N/ a
[Huawei]                                                                        '可以根据需要自己再增加' Y, ]/ ^% e9 t4 Q4 L
<Huawei>1 }; n+ h& R, {0 `- B
刚开始搞不明白为什么路由器上的接口可以设置IP地址,交换机上的就不行,输入命令时经常搞错,所以遇到路由器就在接口上设置IP,交换机就在Vlanif接口上设置IP就行,也不知我的想法对不.
4 [" V0 J6 N3 x, J) m- Z; i# o! o* Q
/ C, l: \# ~, P8 P/ H- `
接下来配置S5700核心交换机,配置如下:

[Huawei]undo info-center enable8 c) K# [! H" Y% D" {/ F
Info: Information center is disabled." d9 d+ ~# X( y5 }% g% j* h
[Huawei]vlan 100# o4 v1 X" F9 e) U9 x
[Huawei-vlan100]q, I* y5 k1 L5 ]& j
[Huawei]interface vlanif 100
) _. H1 K+ P+ [[Huawei-Vlanif100]ip address 1.1.1.2 24
* U7 J; a' \: S, z  ]1 N* ][Huawei-Vlanif100]q+ q) ^) x( S- q* k' q" a
[Huawei]interface giga 0/0/22
6 ~3 Z$ Q  [3 e: z[Huawei-GigabitEthernet0/0/22]port link-type trunk                      '交换机和交换机之间连接用trunk接口  S  f7 H" v$ a+ ~6 K

. A4 N1 u" V7 @# b[Huawei-GigabitEthernet0/0/22]port trunk allow-pass vlan 100 2     '允许通过vlan100和vlan2
+ D1 C5 D  g. A8 T8 Q[Huawei-GigabitEthernet0/0/22]q1 s) H' H) R  v
[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1
" B8 v% a" q+ G1 ][Huawei]interface giga 0/0/242 R2 D7 c, a. z- }% S

% |$ d) T2 v; N" L4 A7 T: d% j* c[Huawei-GigabitEthernet0/0/24]port link-type access$ P$ V& w# K2 V  v% ^
[Huawei-GigabitEthernet0/0/24]port default vlan 100
5 Y! j2 [' _: v5 s[Huawei-GigabitEthernet0/0/24]q5 q7 `& f3 v6 d  T9 o, [# P
[Huawei]interface giga 0/0/23
: g- g. Y, O& G, I5 A5 `1 w4 Y[Huawei-GigabitEthernet0/0/23]port link-type trunk                     '同上面22接口
! R8 G7 \# p  A! O3 M) h[Huawei-GigabitEthernet0/0/23]port trunk allow-pass vlan 100 4    '允许通过vlan100和vlan4
" ~7 K6 C6 e  S3 W9 `; {+ P[Huawei-GigabitEthernet0/0/23]q
' [$ M* g/ Z/ p/ K& q4 g/ R, |
8 Q+ _6 e- Y5 O
5 r- ?9 g! n0 p6 i1 s: ?- s2 o) T& F
下面配置S3700交换机,属于vlan2
[Huawei]undo info-center enable% h3 x7 r8 n8 n
Info: Information center is disabled.& `$ l1 |7 n8 x& p; B
[Huawei]vlan 100
8 J4 u7 w2 W0 H+ s[Huawei-vlan100]q; s% {8 W6 V; l: h7 E' v! D  U
[Huawei]interface eth 0/0/220 U3 m8 G% d. t, p4 d4 e
[Huawei-Ethernet0/0/22]ip address 1.1.1.3 24  '在这个地方出错了,不允许在接口上设置IP, i9 @* J. J9 s% `
                          ^+ e$ s" B- x& W; C# l
Error: Unrecognized command found at '^' position.
% N% j+ \( |+ f# |* ^; Q" k[Huawei-Ethernet0/0/22]port link-type trunk
6 C: F% P( \. r! U# v; L4 c8 I[Huawei-Ethernet0/0/22]port trunk allow-pass vlan 100 2
. l& G/ U. W7 A. }[Huawei-Ethernet0/0/22]q* U5 o/ l1 j/ P7 i! T
[Huawei]interface vlanif 100; {0 t1 r: o  Z2 D8 U- U/ o" M
[Huawei-Vlanif100]ip address 1.1.1.3 240 P; T, P5 F9 i  {; I0 `# q9 z
[Huawei-Vlanif100]q
. S) T' c) G% `- i# J" Z[Huawei]vlan 2$ y. d1 |2 T/ G) T  y' B
[Huawei-vlan2]q
# \+ X) ~& c( l& j* ^* ^& n7 x[Huawei]interface vlanif 2
/ M! ?. p9 q2 m" j+ K[Huawei-Vlanif2]ip address 192.168.2.1 245 h* [5 H+ i! Q! z$ u1 w0 i6 C5 n
[Huawei-Vlanif2]q
  v5 H- X  z- P' l) \. ^/ f# Z[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1
- p) i! `2 Q- C% G' _; a[Huawei]interface eth 0/0/1* U- N; @9 L" z' C
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 2+ D4 r7 N! C0 |8 \1 d
[Huawei-Ethernet0/0/1]port hybrid pvid vlan 2
+ C8 d" @3 f4 T" |/ z
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 100 2/ s+ }; V  b6 L5 A8 {% S
[Huawei-Ethernet0/0/1]dis this         ' 查看一下接口信息
% g! D! a/ K, I5 J8 x$ n$ J, B#
2 {! y: o4 d" g+ Finterface Ethernet0/0/12 u8 D# M+ M$ F3 R1 ]" _
port hybrid pvid vlan 2* m3 X( @+ l5 h  F% ~0 Q' {1 c
port hybrid untagged vlan 2 100) G: t. k+ c/ y( `' c
#0 `9 t- y. M, e: Z- C1 b+ N
return2 B9 ^) h% {  p4 g( C
0 N1 X/ ~0 i1 B7 i  d! e
下面配置S3700-2交换机,属于vlan4

[Huawei]undo info-center enable
. M% ]$ f0 H( J* eInfo: Information center is disabled.# E% ^' |- r+ R7 R2 |; B: a
[Huawei]vlan 100  [6 R7 @. p3 `* ]4 t; {
[Huawei-vlan100]q, \* c5 e, P1 W& l# t) ?
[Huawei]interface vlanif 100  P. y3 ~6 Y9 K$ R
[Huawei-Vlanif100]ip address 1.1.1.4 24
* u  p* J# U3 n1 G* U# t[Huawei-Vlanif100]q
. a+ W: m% W/ c5 r( U[Huawei]interface eth 0/0/22
4 c) S* u0 Y8 g9 f[Huawei-Ethernet0/0/22]port link-type trunk
5 j7 j0 q  F- |[Huawei-Ethernet0/0/22]port trunk allow-pass vlan 100 4
  o1 d; y1 v* f$ H2 t[Huawei-Ethernet0/0/22]dis this
" H" a4 ?+ i7 p, L#6 X& h- w! n/ O0 q* B
interface Ethernet0/0/22
( g' s2 n$ r% Z& A4 w' s port link-type trunk3 v; J8 P  @7 F9 g, F* Q% e
port trunk allow-pass vlan 4 1006 R8 [# B* d: `
#2 b! r- p* W% ]
return
* j( g! b  r+ c; w5 v/ j[Huawei-Ethernet0/0/22]q1 x! m: N: z2 w+ {7 D( g
[Huawei]vlan 4$ C1 }/ h. Y2 }# d
[Huawei-vlan4]q* P1 D% s7 d% x' q+ Z" W  F/ T
[Huawei]interface vlanif 44 Y  @& M# j1 O! m8 m3 k+ Q
[Huawei-Vlanif4]ip address 192.168.4.1 24
3 C+ c, ]9 z0 Z0 h6 g[Huawei-Vlanif4]q
4 V9 f3 v* X; X$ Z' d! V( f9 u6 g[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1! F0 h; U5 O+ M0 s
[Huawei]ping 192.168.4.1" f5 v) L" L' c# v$ g" K: F* D
  PING 192.168.4.1: 56  data bytes, press CTRL_C to break
4 K7 p$ U+ g8 U# u; @: h    Reply from 192.168.4.1: bytes=56 Sequence=1 ttl=255 time=20 ms( e, P9 |4 }( v5 U* ^0 |
    Reply from 192.168.4.1: bytes=56 Sequence=2 ttl=255 time=10 ms! n/ ?6 [  }% }7 F2 X( z, s
    Reply from 192.168.4.1: bytes=56 Sequence=3 ttl=255 time=1 ms! w4 l, @' w' ~4 Z( x
    Reply from 192.168.4.1: bytes=56 Sequence=4 ttl=255 time=30 ms
/ N; U9 S4 J( @* g. i    Reply from 192.168.4.1: bytes=56 Sequence=5 ttl=255 time=1 ms2 U7 z% c0 f/ l" ]
  --- 192.168.4.1 ping statistics ---1 ?# n" I  p& ^$ d# q4 x
    5 packet(s) transmitted3 }1 t0 H; E# N1 [$ Q) g3 u# b
    5 packet(s) received  ^3 n! t' U, s+ Y* Q* ~
    0.00% packet loss' S0 R, c9 e  O* ~
    round-trip min/avg/max = 1/12/30 ms# v2 V% b* ]5 `3 o0 R' s# X
[Huawei]interface eth 0/0/16 f) v0 V* Y1 X' C: C# ]
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 100 4$ M" Y: t; }5 D9 I
[Huawei-Ethernet0/0/1]port hybrid pvid vlan 4
9 c- ~# G2 E% L, p/ d% W5 y  U
[Huawei-Ethernet0/0/1]q
" U( o1 N' P3 f* F) W( D( q- u' k
& i4 r$ t3 V2 J# w* b0 t5 n
好了,交换机和路由器的设置就完成了,把两个PC客户端配置好IP地址就可以试试效果了,但由于是模拟器的原因,在长间没有使用时,有时候会有ping不通的情况,在我这里两个都能ping通外网,vlan2和vlan4之间也能互通.在真实的设备上我们可以启用web界面和telnet,然后通过1.1.1.1,1.1.1.2,1.1.1.3这些地址来访问和管理路由器和交换机了,端口隔离,mac黑洞之类的配置可以在web界面上操作,谁让咱会的太少了.下面是前两个例子的地址,从简到稍难
' S, A- p/ ]+ L# Q5 ^5 a$ l+ B- B
 楼主| 发表于 2022-3-23 15:00:02 | 显示全部楼层
首先配置AR2220,设置GE0接口IP为固定外网地址,设置GE1接口IP为1.1.1.1,然后做两条静态路由,创建vlan 100,红色文本是需要特别多看几眼的,代码如下:

[Huawei]vlan 100

+ N' l7 F+ j, R: T: {) A% v
[Huawei-vlan100]q

# s7 K% y" f5 v6 y2 E( Q" q
[Huawei]acl number 2000

7 H7 W" q+ U8 x& `
[Huawei-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255
1 E) J( W6 F3 d! t6 E" x
[Huawei-acl-basic-2000]q
: L% b6 f* b5 j# n. d5 [4 `/ u
[Huawei]interface giga 0/0/0

. B' q7 S& A; j, Z
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.3 255.255.255.0

: e- _- o6 h+ J1 Z; n
[Huawei-GigabitEthernet0/0/0]

9 B- o# z6 {+ b- f
Mar 13 2014 07:34:12-05:13 Huawei %IFNET/4/LINK_STATE(l)[1]:The line protocol

- D% z' K, ~" |. j5 ~/ {6 b
IP on the interface GigabitEthernet0/0/0 has entered the UP state.

  n6 f9 V, c& D' F
[Huawei-GigabitEthernet0/0/0]q

- W- N; l2 a2 E
[Huawei]interface giga 0/0/1
1 R: c4 X$ m# Z8 {$ G! d& o
[Huawei-GigabitEthernet0/0/1]ip address 1.1.1.1 255.255.255.0
  @& I1 L* E% ?: X
[Huawei-GigabitEthernet0/0/1]q

3 C+ M# i8 g* _+ @8 B. U, b- Y7 |
[Huawei]ip route-static 0.0.0.0 0.0.0.0 192.168.1.1
' W1 ^& E" }8 [. l( d# l5 |: n3 [
[Huawei]ip route-static 192.168.0.0 255.255.0.0 1.1.1.2

5 X% [6 D% [7 @  @9 U( T' h
[Huawei]q

/ S$ `+ _% j6 w( n- A8 K" y# i
save

$ g- F/ K8 c/ o3 c3 O$ k
  The current configuration will be written to the device.

  n6 j& x( B- Y' _5 Z# j
  Are you sure to continue? (y/n)[n]:y
7 u# v. Y+ U5 R! Z& f( F
  It will take several minutes to save configuration file, please wait..........

% f% R: C" b( A1 m/ a# j
2 R* M( j# Y+ g7 B% X1 w# p4 o+ W; ^; o0 j: S2 f7 p5 K: Q
  Configuration file had been saved successfully

9 T2 i2 g9 i# }5 c% E  Z' U
  Note: The configuration file will take effect after being activated
- f7 F6 k, ~+ f
  n( g* l$ c' X! ?  w( u
Mar 13 2014 07:37:25-05:13 Huawei ARP/4/ARP_IPCONFLICT_TRAP:OID 16777216.50331648
7 u' h3 m. S- Z2 R0 p
.100663296.16777216.67108864.16777216.3674669056.83886080.419430400.2063597568.33
1 o' h( Q3 _) I
554432.100663296 ARP detects IP conflict. (IP address=201.1.168.192, Local interf
) _5 `3 i) R! W0 |. T
ace=GigabitEthernet0/0/0, Local MAC=4437-e68c-b212, Local vlan=0, Local CE vlan=0

" X) S6 _- Z" f1 o, ?" T  O* K; o4 J
, Receive interface=GigabitEthernet0/0/0, Receive MAC=1c1a-c00f-253f, Receive vla
0 `$ t3 e) ~/ V. x
n=0, Receive CE vlan=0, IP conflict type=Remote IP conflict).
" Z( v' C4 l" q; u+ B9 j! l
* X1 E# |( A' Y

# f% G* \/ v- Q; R

接下来配置S5700交换机,GE1接口IP为1.1.1.2,属于vlan100,GE2接口属于vlan1,GE3接口属于vlan2,代码如下

[Huawei]vlan batch 2 4 6 8 100
Info: This operation may take a few seconds. Please wait for a moment...done.

# O  }% w, h$ V. j
[Huawei]

+ H0 Y( H1 ?( f. X: L
Mar 13 2014 10:38:34-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.

+ a6 n  ^0 V" q6 S
25.191.3.1 configurations have been changed. The current change number is 4, the
2 ?% D+ X9 [6 w* Y2 u
change loop count is 0, and the maximum number of records is 4095.
! {, `" S6 Y; U1 [" ~" W' c/ O
[Huawei]interface vlanif 100

6 u/ R- `' B' d' c9 k
[Huawei-Vlanif100]ip address 1.1.1.2 255.255.255.0

5 h7 I6 {1 \' W) D
[Huawei-Vlanif100]

. e% P/ N$ ~. n! x
Mar 13 2014 10:40:14-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.

5 f. L$ d1 H0 F. I; I, T
25.191.3.1 configurations have been changed. The current change number is 6, the
. ^4 ]  G# M; o" n9 z
change loop count is 0, and the maximum number of records is 4095.
9 f3 r, i1 m$ P' I/ U
[Huawei-Vlanif100]q
6 J* N1 Q, a- P6 v3 Q" a, B3 I4 M
[Huawei]interface giga 0/0/1
: h' V; j) V7 u8 S" \' H: D. v
[Huawei-GigabitEthernet0/0/1]port link-type access

/ E6 Z" u( c1 h1 ?# g7 z
[Huawei-GigabitEthernet0/0/1]port default vlan 100
3 [9 [- x& V6 J- _
[Huawei-GigabitEthernet0/0/1]q

2 h: n4 P* B. L+ S
[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1
" k# _" X- C: D4 o2 l  x; e, P
[Huawei]

+ Z: f. v# a; F, r. S0 }9 _
Mar 13 2014 10:43:24-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.
9 \' G# x( f1 U% w; d# X: ?! u; i
25.191.3.1 configurations have been changed. The current change number is 9, the
! e6 A/ z' x; q" \  h: q6 k
change loop count is 0, and the maximum number of records is 4095.
& U( n1 w; e: ~1 a& U3 `
[Huawei]interface vlanif 1
& M0 V. [* [# m( ^3 Y
[Huawei-Vlanif1]ip address 192.168.0.1 255.255.255.0

: ?" U1 X- L: D# f: Q0 H% V
[Huawei-Vlanif1]q

/ ]( r1 [+ g0 s) P
[Huawei]interface vlanif 2
1 [! H% b" G- u, _# Z* V
[Huawei-Vlanif2]ip address 192.168.2.1 255.255.255.0

( Z. r; I6 i2 l! \
[Huawei-Vlanif2]q
+ {9 v/ Y; ^( G1 ~
[Huawei]interface giga 0/0/3
# t- V/ \4 n. z9 P) G6 ]
[Huawei-GigabitEthernet0/0/3]port link-type access
6 F+ [9 h" |6 t- U$ Y
[Huawei-GigabitEthernet0/0/3]port default vlan 2

: {: d  W0 `8 N0 [
[Huawei-GigabitEthernet0/0/3]

' U/ u, z  h7 Q4 ~2 E$ |9 {5 C
[Huawei]q

( X7 u: M" ]; s: Q/ ^& G7 p
save

/ F5 U4 [" T, G! Y+ y' R" P$ O
The current configuration will be written to the device.
* f# c7 g; a, a* b
Are you sure to continue?[Y/N]y
# V& s5 m$ O( q6 V
Now saving the current configuration to the slot 0.

' M+ G+ {# b" c9 c; l6 B
Mar 13 2014 11:02:44-08:00 Huawei %CFM/4/SAVE(l)[11]:The user chose Y when dec

' g: ^: r2 n' B$ N5 m& w) \9 u
iding whether to save the configuration to the device.
1 |% |& T' @4 T; z  ]; w, d# Z
Save the configuration successfully.
. d3 c0 x  e* h+ T& D

. F: ]' p4 P' z% Q; q) B
然后设置PC1和PC2的IP地址,先ping 1.1.1.1,如果没有问题再ping 192.168.1.3,192.168.1.111,202.99.192.66,一路ping下来是不是感觉有点小成就感,如果PC2无法ping通,那么就像昨天一样,在自己的真实路由器上做个静态路由指向192.168.2.0便可以了.需要的可以下载附件导出配置文件看.

3 q, a5 G$ D) Q( e2 p1 o
1 K; G1 P! l0 F( D% _( z
3 b* a$ D) b; J; {
您需要登录后才可以回帖 登录 | 开始注册

本版积分规则

关闭

站长推荐上一条 /4 下一条

北京云银创陇科技有限公司以云计算运维,代码开发

QQ|返回首页|Archiver|小黑屋|易陆发现技术论坛 点击这里给我发消息

GMT+8, 2026-4-9 09:15 , Processed in 0.047621 second(s), 21 queries .

Powered by Discuz! X3.4 Licensed

© 2012-2025 Discuz! Team.

快速回复 返回顶部 返回列表