易陆发现互联网技术论坛

 找回密码
 开始注册
查看: 1054|回复: 1
收起左侧

实验AR1200+S5700+S3700网络组网

[复制链接]
发表于 2022-3-23 15:00:01 | 显示全部楼层 |阅读模式

马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。

您需要 登录 才可以下载或查看,没有账号?开始注册

x
AR1200+S5700+S3700访问外网的例子,其实也是我们公司实际的网络拓扑网,只是公司的还没有进行配置,AR2220做为路由访问外网,一台S5700是核心交换机,两台S3700做为接入层交换机使用,为每台S3700划分一个vlan,在本例中,一个是vlan 2,一个是vlan 4,只要这两个会了,再增加交换机也就没有问题了,希望对初学者有些帮助.网络拓扑图如下:% M- M  |: J: }; Q8 @- ^

/ B3 y# {: Q: w9 G

- X, I- _3 }5 D3 T                               
登录/注册后可看大图
画图水平不行, 凑活着看就行,下面配置主路由器AR1200,'号后面是备注信息,配置如下:
- u- \+ f% g! u6 H5 s5 u5 P/ d( w

[Huawei]acl number 2000               
& K0 R& \* ~5 R1 B, D[Huawei-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255   '做个acl,可以根据自己需要配置IP,, v9 N0 L7 k; T
[Huawei-acl-basic-2000]q
$ Y2 V$ u+ G. N! `" o0 |. E[Huawei]vlan 1007 v0 m4 E6 y/ n- m5 o' Y
[Huawei-vlan100]q
! H. S2 c5 @; F8 C& S1 w  r1 X' ?" _[Huawei]interface giga 0/0/0
2 m. H+ u  G4 j8 Z6 j: X[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.3 24  '配置外网IP地址,也就是联通呀,移动等运营商提供给你的IP址,24是掩码         
: J9 Y+ P% m/ m- D' Y8 v[Huawei-GigabitEthernet0/0/0]q
% r/ C4 f# Z/ |8 ][Huawei]interface giga 0/0/1$ P9 V: t( j; {0 |8 I, h
[Huawei-GigabitEthernet0/0/1]ip address 1.1.1.1 24   5 H5 F# J* s7 O1 R1 r4 h% ]/ ^
[Huawei-GigabitEthernet0/0/1]q
9 f) ~! i+ }, d$ e& U+ |0 e0 s[Huawei]ip route-static 0.0.0.0 0.0.0.0 192.168.1.1       '静态路由,使内网的所有外部访问都指向外网网关,网关是运营商提供的.0 o, s( ^4 v+ n9 S; [' P" M3 |
[Huawei]ip route-static 192.168.2.0 255.255.255.0 1.1.1.3  '静态路由,所有访问192.168.2.X的请求指向1.1.1.3
1 w9 ^* d7 A6 I$ K8 W0 y[Huawei]ip route-static 192.168.4.0 255.255.255.0 1.1.1.4  '静态路由,所有访问192.168.4.X的请求指向1.1.1.4! M8 [; A( L  a: T# l2 e. |! x4 y
[Huawei]                                                                        '可以根据需要自己再增加
, d0 p8 n. @7 W( `6 g2 {3 s; p+ j<Huawei>3 y! N. f( L4 X5 ^! N
刚开始搞不明白为什么路由器上的接口可以设置IP地址,交换机上的就不行,输入命令时经常搞错,所以遇到路由器就在接口上设置IP,交换机就在Vlanif接口上设置IP就行,也不知我的想法对不.' C0 w* `# n4 m6 Z: C4 @: c8 k

, h* o% e- L- J/ G; Y
接下来配置S5700核心交换机,配置如下:

[Huawei]undo info-center enable- l6 s* M( F# k
Info: Information center is disabled.
  A  y7 Q  o/ p1 x* F% n, D[Huawei]vlan 100+ y0 E* A: G3 H/ R, k$ Y
[Huawei-vlan100]q! K2 B& E# [" y& W1 B5 |1 T
[Huawei]interface vlanif 1006 A- J" d$ V" l: k9 t, ^* w+ a
[Huawei-Vlanif100]ip address 1.1.1.2 24
3 `$ x5 X, ?7 e[Huawei-Vlanif100]q2 J$ W+ c% R0 ?( F
[Huawei]interface giga 0/0/22' c1 r" g: w: J* s- Y
[Huawei-GigabitEthernet0/0/22]port link-type trunk                      '交换机和交换机之间连接用trunk接口' R7 `+ h! r3 Q

! s( N) K- x  V% a+ L3 j6 m5 t$ O6 k[Huawei-GigabitEthernet0/0/22]port trunk allow-pass vlan 100 2     '允许通过vlan100和vlan2
# v# i" ^" z+ a: N. O[Huawei-GigabitEthernet0/0/22]q) T$ o: j* G9 E; q% L; E6 J* p
[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1
4 ]$ z) P( `! Z, ]5 e9 K[Huawei]interface giga 0/0/24
. N7 x/ m$ K" j5 z2 Y& {/ `4 A. V8 ~9 \) ?) j5 `6 B" G9 l
[Huawei-GigabitEthernet0/0/24]port link-type access
' e! e: ?7 ~% k  r1 n3 k4 Y[Huawei-GigabitEthernet0/0/24]port default vlan 100# B& q# t& h! J# _' S
[Huawei-GigabitEthernet0/0/24]q7 n' {* S0 y' b0 Q- C7 ?
[Huawei]interface giga 0/0/23
! ?) m7 X( z/ X2 B! c) }[Huawei-GigabitEthernet0/0/23]port link-type trunk                     '同上面22接口
5 b( L. I4 ]+ i* u  r, U[Huawei-GigabitEthernet0/0/23]port trunk allow-pass vlan 100 4    '允许通过vlan100和vlan4
+ s8 S7 S/ @* G/ n* X4 M/ H; o0 k- u[Huawei-GigabitEthernet0/0/23]q
" A$ D' d( \9 h! e5 s) W4 g0 l5 r! E% Y) M. C

$ S6 W! c- A0 _% x' R- m( [  D% _) V1 O0 M' r5 L1 T
下面配置S3700交换机,属于vlan2
[Huawei]undo info-center enable
7 P* z4 |. V! ]6 U' c; B, _; K/ sInfo: Information center is disabled.
) g4 J0 q) j! d6 ~/ A) b1 c# y# x[Huawei]vlan 100
) g& Z( G4 c2 T) {% c) ^! }! h[Huawei-vlan100]q3 R- d" `1 e. S' \, T' I. ]
[Huawei]interface eth 0/0/22, y9 v- t4 v4 ]8 E% r  ?7 {3 T
[Huawei-Ethernet0/0/22]ip address 1.1.1.3 24  '在这个地方出错了,不允许在接口上设置IP
8 A% d1 }2 P. z( R+ _                          ^
  e; M" b) R) |: V% H; M0 \Error: Unrecognized command found at '^' position.1 z* I6 P. j- \& c1 C  Y+ N8 Z
[Huawei-Ethernet0/0/22]port link-type trunk8 @; ]0 s/ Z+ ^  n+ E$ \+ G
[Huawei-Ethernet0/0/22]port trunk allow-pass vlan 100 2. H/ c7 Z8 u+ J1 \7 m  M
[Huawei-Ethernet0/0/22]q
& H; P/ C7 B0 o/ y[Huawei]interface vlanif 100
# _3 C1 t% ~0 t8 h[Huawei-Vlanif100]ip address 1.1.1.3 247 V# {; N3 `# H' W) Q
[Huawei-Vlanif100]q% D' i2 c8 Y% e1 c. T! }& _
[Huawei]vlan 2
' B5 }0 k7 Y: G6 i+ M8 {( O[Huawei-vlan2]q1 ~3 B9 N/ H/ w. `  N9 Y
[Huawei]interface vlanif 2
* X! j/ M+ {* R: f* q2 m% u/ x. u8 w2 O[Huawei-Vlanif2]ip address 192.168.2.1 24
* n& @6 o9 F0 {[Huawei-Vlanif2]q
4 E" x) ^- W8 d[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.12 X) E  }  }! ~  ^2 }3 J
[Huawei]interface eth 0/0/1. q" n; \, o" `4 H
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 2( G5 c" ?3 a6 r, r: z
[Huawei-Ethernet0/0/1]port hybrid pvid vlan 2
8 V, F& M; D8 @/ K' ?
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 100 2
$ L( V7 t$ c, j. T/ e) R[Huawei-Ethernet0/0/1]dis this         ' 查看一下接口信息
1 l/ m" [; W# B" l) w+ ?5 Y#  m" Y. E; G( a4 J6 c, P
interface Ethernet0/0/1
* F2 Z  l7 p% o2 e; g& K8 h port hybrid pvid vlan 2: f7 D2 {, {. l1 S. ]! k. w
port hybrid untagged vlan 2 100
& |  U& T/ _# e2 R1 k#6 R7 c& f; m' k
return1 F: X  z, @0 Q
/ O( N$ a9 q3 K' O2 J
下面配置S3700-2交换机,属于vlan4

[Huawei]undo info-center enable
, H/ _, R* j3 NInfo: Information center is disabled." G: t. q. i1 K$ n, u
[Huawei]vlan 100
. q/ Z2 d1 N7 \" e[Huawei-vlan100]q% D& U) t: n7 V2 i
[Huawei]interface vlanif 100
9 i* I9 W5 O( z" d, }2 G& ~+ y  H" k[Huawei-Vlanif100]ip address 1.1.1.4 24
! E1 h. @/ r/ ^1 @/ N5 A8 M[Huawei-Vlanif100]q
- Q, I' i3 g; s$ q, j- f9 A9 D/ j' z. i[Huawei]interface eth 0/0/22( X4 q. k# K" ]. E
[Huawei-Ethernet0/0/22]port link-type trunk
* [7 Z( \: ~) J! O# K[Huawei-Ethernet0/0/22]port trunk allow-pass vlan 100 4
+ ^! y; F+ d/ A: a7 c[Huawei-Ethernet0/0/22]dis this
( o( f( v; H- p# H# @; C#3 h5 I) r* }0 V! U& J/ k1 ]. l. a
interface Ethernet0/0/22
( ~2 I  j  t8 R! P  r6 P" f port link-type trunk4 K" @& w% C5 e' @
port trunk allow-pass vlan 4 1001 R  [8 P" R( d& }2 U
#
0 x3 {  p0 f) zreturn
: }* T- V& Q0 M6 q$ w[Huawei-Ethernet0/0/22]q; J" f5 H& ^' {# v7 J4 @
[Huawei]vlan 4& t" J3 P1 e" ?  g* t" K
[Huawei-vlan4]q
5 R+ E. q. H( `/ _* ?; S( }
[Huawei]interface vlanif 4
$ R  g& Y) a: {/ ^( C; C0 }1 d[Huawei-Vlanif4]ip address 192.168.4.1 24" h) n' F! U( Y$ H. J8 I
[Huawei-Vlanif4]q
/ l3 m2 d2 S6 y3 R# _[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1
1 p, {% w2 M6 l& J; p[Huawei]ping 192.168.4.1
. s( q  u0 R& W' A( H" C  PING 192.168.4.1: 56  data bytes, press CTRL_C to break; L/ j- e, n% X( {, D1 T
    Reply from 192.168.4.1: bytes=56 Sequence=1 ttl=255 time=20 ms; o' r% g: B% y# g4 _/ ?
    Reply from 192.168.4.1: bytes=56 Sequence=2 ttl=255 time=10 ms
7 O: ?' M7 v% x8 I6 X' Z- Q    Reply from 192.168.4.1: bytes=56 Sequence=3 ttl=255 time=1 ms
6 q, `/ x5 K3 |' W; T0 O    Reply from 192.168.4.1: bytes=56 Sequence=4 ttl=255 time=30 ms
# g( z4 `9 h% i1 P, U' I    Reply from 192.168.4.1: bytes=56 Sequence=5 ttl=255 time=1 ms
$ v( S* }" w4 N  --- 192.168.4.1 ping statistics ---, q, d, K8 u0 M1 O" V4 a
    5 packet(s) transmitted; h+ r! U' V3 W8 t  R- M
    5 packet(s) received/ Z7 k4 L0 n+ i
    0.00% packet loss4 W4 i; z" s# g& e% p4 j8 ^+ [; k( y
    round-trip min/avg/max = 1/12/30 ms" i1 E3 z" T- Z/ t+ H
[Huawei]interface eth 0/0/18 V- P  \! A( }4 z. d9 V6 g( \
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 100 4
% q3 L8 p/ }, B/ f[Huawei-Ethernet0/0/1]port hybrid pvid vlan 4
1 g3 L0 B3 S9 T: V7 w
[Huawei-Ethernet0/0/1]q
% X3 e" v) W& Q, j7 j$ b, N+ }+ z7 M, A

好了,交换机和路由器的设置就完成了,把两个PC客户端配置好IP地址就可以试试效果了,但由于是模拟器的原因,在长间没有使用时,有时候会有ping不通的情况,在我这里两个都能ping通外网,vlan2和vlan4之间也能互通.在真实的设备上我们可以启用web界面和telnet,然后通过1.1.1.1,1.1.1.2,1.1.1.3这些地址来访问和管理路由器和交换机了,端口隔离,mac黑洞之类的配置可以在web界面上操作,谁让咱会的太少了.下面是前两个例子的地址,从简到稍难

* }4 t0 |/ q& D% P3 A$ q6 _1 R
 楼主| 发表于 2022-3-23 15:00:02 | 显示全部楼层
首先配置AR2220,设置GE0接口IP为固定外网地址,设置GE1接口IP为1.1.1.1,然后做两条静态路由,创建vlan 100,红色文本是需要特别多看几眼的,代码如下:

[Huawei]vlan 100
1 e) B- ~# k: m
[Huawei-vlan100]q

4 f) D" t% o! U- f3 a# J
[Huawei]acl number 2000
: K$ C, s+ m; B& i2 e  L7 s5 I
[Huawei-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255

# r; Z) ]8 u* o! e! ?
[Huawei-acl-basic-2000]q
2 A0 ?1 `" c- j3 @" D+ Q7 Y7 E
[Huawei]interface giga 0/0/0

. G! X+ c# ], d; t9 P- t, z
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.3 255.255.255.0
2 R1 k: m6 s- _$ c
[Huawei-GigabitEthernet0/0/0]
: H! M5 b/ n. C" _6 A( i
Mar 13 2014 07:34:12-05:13 Huawei %IFNET/4/LINK_STATE(l)[1]:The line protocol

* `5 s7 N7 S* @1 q  w. C
IP on the interface GigabitEthernet0/0/0 has entered the UP state.
0 A# \: M  n2 n# p
[Huawei-GigabitEthernet0/0/0]q

7 F2 ]! z2 y4 ^1 Y' H
[Huawei]interface giga 0/0/1
" ~7 w$ P% O+ H* N9 m
[Huawei-GigabitEthernet0/0/1]ip address 1.1.1.1 255.255.255.0
/ \: X) o6 G" D1 t% L. W% t
[Huawei-GigabitEthernet0/0/1]q

3 ?4 l: |! L1 I0 O
[Huawei]ip route-static 0.0.0.0 0.0.0.0 192.168.1.1
4 ?& N' O7 S6 Y+ u4 P6 z: I4 B; p
[Huawei]ip route-static 192.168.0.0 255.255.0.0 1.1.1.2
* j  L* y  {( O6 @, j
[Huawei]q
; ~: l6 H1 {* g" c& Y) d
save
& @5 y& @% p& Q2 J0 K: X
  The current configuration will be written to the device.
8 R7 R9 o# X' z5 F3 E9 H- X8 Q1 k
  Are you sure to continue? (y/n)[n]:y

- P; W8 ?) `( ]1 k+ o
  It will take several minutes to save configuration file, please wait..........

  ^2 Y$ J5 o! E+ A" @
2 s5 ^/ u$ a% m! D  N- _, k. r  ^4 i, H0 ^9 R
  Configuration file had been saved successfully
) R2 k* \, Z9 N; a
  Note: The configuration file will take effect after being activated

. @4 b1 r8 K8 t) i6 s/ y
0 c4 X' s9 u+ f: |) L: @5 \
Mar 13 2014 07:37:25-05:13 Huawei ARP/4/ARP_IPCONFLICT_TRAP:OID 16777216.50331648
" D  M. C7 ~) S7 c5 x- J/ X, k6 a- j
.100663296.16777216.67108864.16777216.3674669056.83886080.419430400.2063597568.33
  q' f0 V0 Z" T, b/ K5 K. c5 B( ^
554432.100663296 ARP detects IP conflict. (IP address=201.1.168.192, Local interf
0 }* g9 _' A. G6 P8 ^% x1 I
ace=GigabitEthernet0/0/0, Local MAC=4437-e68c-b212, Local vlan=0, Local CE vlan=0
' {& b) P- f) v0 [# v9 G' R
, Receive interface=GigabitEthernet0/0/0, Receive MAC=1c1a-c00f-253f, Receive vla
0 ^5 M/ _; n8 s* ?6 |/ G
n=0, Receive CE vlan=0, IP conflict type=Remote IP conflict).

; O2 W8 N: H/ N  G2 Y& n7 K: @, p- L' D& n0 Z8 w
4 N2 m0 k# a. \4 G

接下来配置S5700交换机,GE1接口IP为1.1.1.2,属于vlan100,GE2接口属于vlan1,GE3接口属于vlan2,代码如下

[Huawei]vlan batch 2 4 6 8 100
Info: This operation may take a few seconds. Please wait for a moment...done.

. k0 M/ Y6 O% k* \
[Huawei]
. c: z9 C- ?' C+ q1 p8 s1 Q9 H
Mar 13 2014 10:38:34-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.

% R2 \# O2 H, Q$ U" u7 o8 @
25.191.3.1 configurations have been changed. The current change number is 4, the
; Z/ `7 F/ H/ D6 T
change loop count is 0, and the maximum number of records is 4095.
5 s2 y/ C3 t' L6 P. S; I/ g2 o/ X
[Huawei]interface vlanif 100
# y0 A, c: q- V$ K! [# K
[Huawei-Vlanif100]ip address 1.1.1.2 255.255.255.0
) ]2 }( Z( O. e/ `% M, z* @5 ^8 ]
[Huawei-Vlanif100]
+ c" r$ Y1 k/ o
Mar 13 2014 10:40:14-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.

# o/ `( X  K4 P/ }8 I" \
25.191.3.1 configurations have been changed. The current change number is 6, the

  p$ l$ w% F% H+ f" Q- h5 N
change loop count is 0, and the maximum number of records is 4095.

0 B8 \. p3 ~2 }( U( R
[Huawei-Vlanif100]q

& Y0 S. K' ?1 U/ c1 w
[Huawei]interface giga 0/0/1
9 O) C/ L# U( {
[Huawei-GigabitEthernet0/0/1]port link-type access
' y! Q! D2 D6 y2 a+ V
[Huawei-GigabitEthernet0/0/1]port default vlan 100

/ k+ A# [* P9 r) l* Q0 ~
[Huawei-GigabitEthernet0/0/1]q

6 i: d  C8 f  Z
[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1
+ v- M* s; [5 D* F1 T5 Q: Y9 f
[Huawei]
/ p, b& ^$ [, I+ m, V& F  o
Mar 13 2014 10:43:24-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.

7 m2 T# Z- \1 J* a" v
25.191.3.1 configurations have been changed. The current change number is 9, the

4 r" b0 n& U4 [/ T
change loop count is 0, and the maximum number of records is 4095.
& H% H9 T3 v( [2 A' Y
[Huawei]interface vlanif 1

# g) i: ~. H' `; |4 j0 l/ a
[Huawei-Vlanif1]ip address 192.168.0.1 255.255.255.0
" V. \, e$ ^% I; ^5 M8 C" n
[Huawei-Vlanif1]q
  ^/ y  b1 Z, U9 n: D" V* y% {
[Huawei]interface vlanif 2
. r1 }' D1 m7 ~0 c, h, H) C4 g
[Huawei-Vlanif2]ip address 192.168.2.1 255.255.255.0

+ ]2 v) _0 e" Z$ v
[Huawei-Vlanif2]q
* R* a1 \5 G2 |# T( D$ ~$ c1 B
[Huawei]interface giga 0/0/3

5 f1 X. f8 i) y0 J: o3 ]
[Huawei-GigabitEthernet0/0/3]port link-type access
% n1 Q0 [, c) |
[Huawei-GigabitEthernet0/0/3]port default vlan 2

/ ?$ X: f5 D* C- u2 R
[Huawei-GigabitEthernet0/0/3]

+ s7 X, I$ m; f) z# [, d
[Huawei]q

9 ^  H8 O- R7 Y9 u) c
save

; J4 o4 W% t% J8 W0 V
The current configuration will be written to the device.

' |& @3 O- G+ Y) w5 P( }. g
Are you sure to continue?[Y/N]y
% f- A4 X4 {+ y9 V
Now saving the current configuration to the slot 0.
4 T% P* D3 w8 p3 x7 h0 T! A
Mar 13 2014 11:02:44-08:00 Huawei %CFM/4/SAVE(l)[11]:The user chose Y when dec

. _# Y/ y7 _- w/ d
iding whether to save the configuration to the device.

9 `' I* {, y6 v$ D& H+ n# B! Y' |
Save the configuration successfully.
4 h2 ]2 g& ^# u: I( n+ M, k

3 X7 n2 H5 J0 z
然后设置PC1和PC2的IP地址,先ping 1.1.1.1,如果没有问题再ping 192.168.1.3,192.168.1.111,202.99.192.66,一路ping下来是不是感觉有点小成就感,如果PC2无法ping通,那么就像昨天一样,在自己的真实路由器上做个静态路由指向192.168.2.0便可以了.需要的可以下载附件导出配置文件看.

% l% K; K* x# Y6 ?( H4 P3 g  H& s4 o" K  k7 C: P( z* _1 V4 a
1 O) U: h. r% W4 U& |
您需要登录后才可以回帖 登录 | 开始注册

本版积分规则

关闭

站长推荐上一条 /4 下一条

北京云银创陇科技有限公司以云计算运维,代码开发

QQ|返回首页|Archiver|小黑屋|易陆发现技术论坛 ( 蜀ICP备2026014127号-1 )点击这里给我发消息

GMT+8, 2026-4-9 00:03 , Processed in 0.054070 second(s), 22 queries .

Powered by Discuz! X3.4 Licensed

© 2012-2025 Discuz! Team.

快速回复 返回顶部 返回列表