找回密码
 注册
查看: 1063|回复: 1

实验AR1200+S5700+S3700网络组网

[复制链接]

1

主题

0

回帖

12

积分

管理员

积分
12
QQ
发表于 2022-3-23 15:00:01 | 显示全部楼层 |阅读模式
AR1200+S5700+S3700访问外网的例子,其实也是我们公司实际的网络拓扑网,只是公司的还没有进行配置,AR2220做为路由访问外网,一台S5700是核心交换机,两台S3700做为接入层交换机使用,为每台S3700划分一个vlan,在本例中,一个是vlan 2,一个是vlan 4,只要这两个会了,再增加交换机也就没有问题了,希望对初学者有些帮助.网络拓扑图如下:
& X& x4 y0 s9 |3 K
3 W  c9 F0 v. F* Z1 D
画图水平不行, 凑活着看就行,下面配置主路由器AR1200,'号后面是备注信息,配置如下:
" y4 \3 }* v& e1 y; m

[Huawei]acl number 2000                / B- Z6 D7 E! V; N2 t8 b
[Huawei-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255   '做个acl,可以根据自己需要配置IP,8 Q9 K" F, P6 U8 H- \; D
[Huawei-acl-basic-2000]q
8 S0 z- ?5 c7 G! S5 |[Huawei]vlan 100/ \1 E/ `+ B/ I, Q  O
[Huawei-vlan100]q
0 a- Y. b2 Q: A* B# I. a[Huawei]interface giga 0/0/03 s4 V1 @0 g1 @7 J- }+ h& b7 l
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.3 24  '配置外网IP地址,也就是联通呀,移动等运营商提供给你的IP址,24是掩码          5 V* \; E9 ^  i" S( y! J2 n
[Huawei-GigabitEthernet0/0/0]q
& J+ q6 O  E, Q* \2 r. s  _- h4 n. @[Huawei]interface giga 0/0/1
3 w) i1 ]/ g2 ]/ g' V1 V9 A[Huawei-GigabitEthernet0/0/1]ip address 1.1.1.1 24   8 ]4 U% N2 X  v
[Huawei-GigabitEthernet0/0/1]q
# n; G. L3 n; u* h5 F: c% q8 ]" R9 \8 |[Huawei]ip route-static 0.0.0.0 0.0.0.0 192.168.1.1       '静态路由,使内网的所有外部访问都指向外网网关,网关是运营商提供的.
* O: G, Y$ S; M) i  ~9 ~  E[Huawei]ip route-static 192.168.2.0 255.255.255.0 1.1.1.3  '静态路由,所有访问192.168.2.X的请求指向1.1.1.3
; K! @$ W" f! l; K[Huawei]ip route-static 192.168.4.0 255.255.255.0 1.1.1.4  '静态路由,所有访问192.168.4.X的请求指向1.1.1.4
2 S7 Z6 u  s' N, }0 c0 M: I1 p  ]1 ^[Huawei]                                                                        '可以根据需要自己再增加
# p  I6 A# V) d0 `% |9 A! M<Huawei>) z; w$ {- u8 @6 G
刚开始搞不明白为什么路由器上的接口可以设置IP地址,交换机上的就不行,输入命令时经常搞错,所以遇到路由器就在接口上设置IP,交换机就在Vlanif接口上设置IP就行,也不知我的想法对不.6 {$ Z0 m+ D+ E: C0 M, {

( c, U; f) C: e# q. E
接下来配置S5700核心交换机,配置如下:

[Huawei]undo info-center enable2 {( B3 `1 W9 F  r0 L& q/ o
Info: Information center is disabled.$ |0 N7 w0 l+ C. e# e
[Huawei]vlan 1004 R6 t$ b7 F( e
[Huawei-vlan100]q
8 ^) K) {8 h; m[Huawei]interface vlanif 100
( V! s2 ^" ?. t; F+ O/ Z- Y2 p. H[Huawei-Vlanif100]ip address 1.1.1.2 24+ m- W8 I5 t. k
[Huawei-Vlanif100]q4 n. b" Y9 d$ B/ f2 u5 [
[Huawei]interface giga 0/0/225 |4 s3 ?# }: v0 `: q
[Huawei-GigabitEthernet0/0/22]port link-type trunk                      '交换机和交换机之间连接用trunk接口- y. O+ v% Y/ @) ^
! n* ?5 g1 W3 G9 Q* {% m7 R* z. G# C
[Huawei-GigabitEthernet0/0/22]port trunk allow-pass vlan 100 2     '允许通过vlan100和vlan2; B4 a+ ^5 J: Y8 `! y- l
[Huawei-GigabitEthernet0/0/22]q
$ h# ]8 }: ^: v% X3 O) N[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1
8 c: |6 u& ?% B& i5 x[Huawei]interface giga 0/0/249 y3 o( J) B+ c4 I

7 z1 i4 ]  ~" W( R" X& @, L[Huawei-GigabitEthernet0/0/24]port link-type access- f$ C) |" \8 E4 X8 ?% J
[Huawei-GigabitEthernet0/0/24]port default vlan 100# [1 T7 C6 P' F0 b8 `9 b
[Huawei-GigabitEthernet0/0/24]q
7 d3 [$ `8 j1 m8 b. ^1 d[Huawei]interface giga 0/0/23) D& L3 F4 }8 v$ J  e4 E  y% }, t1 N
[Huawei-GigabitEthernet0/0/23]port link-type trunk                     '同上面22接口
# n0 B" W0 E5 }5 D[Huawei-GigabitEthernet0/0/23]port trunk allow-pass vlan 100 4    '允许通过vlan100和vlan4& |! P+ S3 k" M# Y! D1 U
[Huawei-GigabitEthernet0/0/23]q
% j, M) _$ G& |, J# T7 f9 s) Y* D$ e8 o3 _$ }6 I% S& \( j
8 r; ?% F) e! I" F7 S0 p. Q

( D, b" N$ T% X4 P) t' d+ I) \下面配置S3700交换机,属于vlan2
[Huawei]undo info-center enable/ x7 b! e. G0 K1 n  a+ L
Info: Information center is disabled.. m+ e9 e$ |% f9 Y  W
[Huawei]vlan 100
4 X) W: d% m: |, |[Huawei-vlan100]q
  V0 @1 s0 F# l/ s6 k[Huawei]interface eth 0/0/22
+ r( g6 d; z, R: p) Z( a[Huawei-Ethernet0/0/22]ip address 1.1.1.3 24  '在这个地方出错了,不允许在接口上设置IP  Z) T5 P1 y( @0 D3 `
                          ^
3 b. _$ n* `: CError: Unrecognized command found at '^' position.
+ Z2 ?9 F* m! k) {5 X4 ?3 f[Huawei-Ethernet0/0/22]port link-type trunk
/ C$ A- h! s! X) ^[Huawei-Ethernet0/0/22]port trunk allow-pass vlan 100 2* g9 ~+ }0 \3 M  H8 a8 G
[Huawei-Ethernet0/0/22]q
; v7 ~# l' L5 V; ~5 v8 a3 M$ f[Huawei]interface vlanif 100) u! Y; s( k+ {( @
[Huawei-Vlanif100]ip address 1.1.1.3 24
, t' R# M4 y$ g2 w0 R( H) Y+ f[Huawei-Vlanif100]q0 s: G# @+ Q) s, y/ K3 r/ M: ~
[Huawei]vlan 2
1 h, i6 D' E- R9 ~. f4 k[Huawei-vlan2]q
: c7 `. q. e0 V) g7 Y3 d2 V[Huawei]interface vlanif 2
. x! k" q( t, @( v& b[Huawei-Vlanif2]ip address 192.168.2.1 24% }, Z, |4 R0 C5 r
[Huawei-Vlanif2]q
2 C% I: E* W$ A7 s$ t[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1( |# [9 o% R7 C" x; i  ^2 X
[Huawei]interface eth 0/0/1
  a  y) X9 V. j& O9 u; E0 i' E[Huawei-Ethernet0/0/1]port hybrid untagged vlan 2
* D, Y) ?: t4 A
[Huawei-Ethernet0/0/1]port hybrid pvid vlan 2
0 S% q% A2 b8 o  Z+ E
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 100 2$ m7 G9 i5 x  m+ e1 K" E" D
[Huawei-Ethernet0/0/1]dis this         ' 查看一下接口信息$ g1 c$ m! e4 ^
#
  V% Q0 K' D$ S( ~. cinterface Ethernet0/0/1
  d  W5 @2 I: x3 v port hybrid pvid vlan 2
! v$ C$ J2 c/ g$ q. Z' F$ C port hybrid untagged vlan 2 100
" E' R6 x/ E2 D" p7 o#: Z1 f' g% {2 y) L- A: G( S) K' t
return
6 P% y, j+ H( z( T
- J0 u, Z) C0 n. P+ a* b
下面配置S3700-2交换机,属于vlan4

[Huawei]undo info-center enable
1 o+ p& J1 |& [+ C: wInfo: Information center is disabled.
" E* y  t9 [' i6 }+ T* {[Huawei]vlan 100" w- S0 {! p  P, g  v- R3 \
[Huawei-vlan100]q
6 D  n1 M- X9 v& l4 E5 ~1 L7 G[Huawei]interface vlanif 100) U7 ~+ y3 W: h' p* [
[Huawei-Vlanif100]ip address 1.1.1.4 246 t; ]" Z9 M- m# w0 d$ N0 f. ~% H% O
[Huawei-Vlanif100]q
, b3 Y! G% |3 Z7 r" `: Z3 c6 K: a[Huawei]interface eth 0/0/227 G! Y8 x/ g  {4 D4 J
[Huawei-Ethernet0/0/22]port link-type trunk% p( L' s( n2 ?8 Q+ @* X
[Huawei-Ethernet0/0/22]port trunk allow-pass vlan 100 4
+ y* V8 b) y. x- D* m[Huawei-Ethernet0/0/22]dis this: e% L2 {& g  F! u
#
/ ^. c2 N$ K& _3 \0 d4 j9 Rinterface Ethernet0/0/22
$ B( @1 }( |! `( e# p! o4 | port link-type trunk* Q' M- c! \9 E; D( K# B" X1 O9 Y
port trunk allow-pass vlan 4 1003 C7 h5 k  R, ^! z
#
$ T' k# K& }- w0 k. Yreturn
# T, y) a) i  J& K5 G4 W[Huawei-Ethernet0/0/22]q& B6 D1 d$ k6 Z) O+ S
[Huawei]vlan 4
& x& Z& l8 k! S3 {2 w1 X/ S) A[Huawei-vlan4]q1 C( ~- ~9 W/ E
[Huawei]interface vlanif 4
# f$ k9 N4 [$ g4 E$ K3 ?/ `[Huawei-Vlanif4]ip address 192.168.4.1 241 B" p6 J( `6 c( [
[Huawei-Vlanif4]q
1 X, Y6 g( Z! j% t- Z& u" R[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1) b4 j, n& m# `; X3 @
[Huawei]ping 192.168.4.1
9 H- M2 y% h& l) Z& q6 L  PING 192.168.4.1: 56  data bytes, press CTRL_C to break
# d) F: T7 Z1 Z7 w4 T    Reply from 192.168.4.1: bytes=56 Sequence=1 ttl=255 time=20 ms$ M0 N! T+ h0 b% r' L! e! r
    Reply from 192.168.4.1: bytes=56 Sequence=2 ttl=255 time=10 ms. V4 F6 u# Q, ]! I) |9 Q# R
    Reply from 192.168.4.1: bytes=56 Sequence=3 ttl=255 time=1 ms
- X0 J; A2 e$ ]    Reply from 192.168.4.1: bytes=56 Sequence=4 ttl=255 time=30 ms
% A) D+ J4 Z" X' W4 @    Reply from 192.168.4.1: bytes=56 Sequence=5 ttl=255 time=1 ms5 ]" G7 D8 k& d9 |. f, g: L
  --- 192.168.4.1 ping statistics ---) `/ Y: s2 |/ I
    5 packet(s) transmitted: m" P8 ]( ]$ M+ {/ S8 i  k
    5 packet(s) received' n3 b: d  P: G& U& l) j  t
    0.00% packet loss' W2 ?5 |% D" d( r6 @6 i8 t+ p+ ^
    round-trip min/avg/max = 1/12/30 ms; U6 i2 W! M. [' k( q4 W) S
[Huawei]interface eth 0/0/1
5 t6 E% ~( `; D( d" n5 _  W# {
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 100 4
+ N  z, e+ a5 B: O* x[Huawei-Ethernet0/0/1]port hybrid pvid vlan 45 h! ^7 z$ s/ S; x  b  D
[Huawei-Ethernet0/0/1]q
" U6 P/ ^% w5 R0 ]
0 }# E" v/ g" k
好了,交换机和路由器的设置就完成了,把两个PC客户端配置好IP地址就可以试试效果了,但由于是模拟器的原因,在长间没有使用时,有时候会有ping不通的情况,在我这里两个都能ping通外网,vlan2和vlan4之间也能互通.在真实的设备上我们可以启用web界面和telnet,然后通过1.1.1.1,1.1.1.2,1.1.1.3这些地址来访问和管理路由器和交换机了,端口隔离,mac黑洞之类的配置可以在web界面上操作,谁让咱会的太少了.下面是前两个例子的地址,从简到稍难
2 ~9 V$ a5 j1 |6 d$ S- t: m

1

主题

0

回帖

12

积分

管理员

积分
12
QQ
 楼主| 发表于 2022-3-23 15:00:02 | 显示全部楼层
首先配置AR2220,设置GE0接口IP为固定外网地址,设置GE1接口IP为1.1.1.1,然后做两条静态路由,创建vlan 100,红色文本是需要特别多看几眼的,代码如下:

[Huawei]vlan 100
+ d+ A/ M! t* b7 Z! e" j3 _3 g
[Huawei-vlan100]q
/ e0 n  x) D% G; T% d2 N
[Huawei]acl number 2000
# c7 `& @6 h/ \- c4 r
[Huawei-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255
( z7 T* S( L% u( u7 g# G  _" s" r
[Huawei-acl-basic-2000]q

, K% C6 Z+ y! g. U9 A) k3 a  B: L* l
[Huawei]interface giga 0/0/0
: y# r3 I# g' O! p; K9 \
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.3 255.255.255.0
4 S0 @2 R4 R- M' u- @
[Huawei-GigabitEthernet0/0/0]
% Y! l% d3 F9 j+ }3 T
Mar 13 2014 07:34:12-05:13 Huawei %IFNET/4/LINK_STATE(l)[1]:The line protocol
" T4 B) ^: h# I% T$ y' F
IP on the interface GigabitEthernet0/0/0 has entered the UP state.
) h: ?; j# ~0 P1 P
[Huawei-GigabitEthernet0/0/0]q

* Y  m* B) ]1 `
[Huawei]interface giga 0/0/1
: G. M. ^. L8 R+ J! k" @
[Huawei-GigabitEthernet0/0/1]ip address 1.1.1.1 255.255.255.0
  i4 X2 s" i2 ?5 z  T7 d( R+ J8 O
[Huawei-GigabitEthernet0/0/1]q
( {, Q$ }" \: U! I% M* Y
[Huawei]ip route-static 0.0.0.0 0.0.0.0 192.168.1.1

( T) @' n' f, m0 t! n2 N
[Huawei]ip route-static 192.168.0.0 255.255.0.0 1.1.1.2
( j0 K/ t9 p4 F6 C2 }
[Huawei]q

  W: w# I- [: ~
save
9 p! E; J5 G8 @+ ]4 ~  n
  The current configuration will be written to the device.

% ?+ X: b  }3 _8 f
  Are you sure to continue? (y/n)[n]:y
" Y" I* T  y) F
  It will take several minutes to save configuration file, please wait..........

9 W3 G/ L! o$ z8 ?! \( @& }' G" L
! ]1 N& P8 q  X. i8 g# Z
  Configuration file had been saved successfully
+ h, P6 {0 b4 w1 }6 x
  Note: The configuration file will take effect after being activated

( A- X4 w" B; A2 \
) ^( D' _8 W; ^4 q* c! S
Mar 13 2014 07:37:25-05:13 Huawei ARP/4/ARP_IPCONFLICT_TRAP:OID 16777216.50331648

2 O3 E* y7 @1 d; l+ c
.100663296.16777216.67108864.16777216.3674669056.83886080.419430400.2063597568.33
' W  I+ j$ h' Z+ O- X# z  v5 x$ _
554432.100663296 ARP detects IP conflict. (IP address=201.1.168.192, Local interf

' y2 O- K+ f7 X! l
ace=GigabitEthernet0/0/0, Local MAC=4437-e68c-b212, Local vlan=0, Local CE vlan=0

! U0 ~( Y; n* f; v* ^
, Receive interface=GigabitEthernet0/0/0, Receive MAC=1c1a-c00f-253f, Receive vla
7 B7 l8 T3 t* ^; {9 p# n
n=0, Receive CE vlan=0, IP conflict type=Remote IP conflict).

* ~! ]: N8 E7 E/ l2 `
7 ]$ R5 e  u; L! T& Y- M# X) m0 e4 _; M

接下来配置S5700交换机,GE1接口IP为1.1.1.2,属于vlan100,GE2接口属于vlan1,GE3接口属于vlan2,代码如下

[Huawei]vlan batch 2 4 6 8 100
Info: This operation may take a few seconds. Please wait for a moment...done.

5 y: C, J8 D' I% S% W* @: T  C% f
[Huawei]

' P0 I+ |+ d! k/ t. Q
Mar 13 2014 10:38:34-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.
- P- x8 c; i- s
25.191.3.1 configurations have been changed. The current change number is 4, the
+ S9 y0 t& Q5 p. Q: O- u/ L
change loop count is 0, and the maximum number of records is 4095.
3 \- H$ J6 t+ Y: ~2 a9 l7 C1 H# {
[Huawei]interface vlanif 100
8 `$ W# x! z  D" s3 u3 Y
[Huawei-Vlanif100]ip address 1.1.1.2 255.255.255.0

4 E. ^+ {! |# l" s
[Huawei-Vlanif100]

; H! H. I- d& j7 P! W' N
Mar 13 2014 10:40:14-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.

9 @; E/ s3 }! ]7 v( ~5 Y3 D: W
25.191.3.1 configurations have been changed. The current change number is 6, the
  T! [. ], J2 z/ |: N, C1 J8 ~+ |1 z% t
change loop count is 0, and the maximum number of records is 4095.
; s! \/ S7 M# m3 k3 k/ _0 o
[Huawei-Vlanif100]q
* Q- W& T$ b: r0 M! W4 Z
[Huawei]interface giga 0/0/1
& @' S$ H3 W# q# U6 B( R
[Huawei-GigabitEthernet0/0/1]port link-type access

/ N. {/ ?; M2 F$ ~( l# d: m5 I6 g
[Huawei-GigabitEthernet0/0/1]port default vlan 100

7 }$ j+ l6 F4 E* A/ Q5 l9 P
[Huawei-GigabitEthernet0/0/1]q

! q% b& ^" d7 k" ]! ?
[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1
) ?. ~! _. O; \' g5 j$ H* `
[Huawei]
7 l% o6 n) u9 L# J3 a7 x% Z0 C
Mar 13 2014 10:43:24-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.
5 N8 }9 y& B# j7 {2 `
25.191.3.1 configurations have been changed. The current change number is 9, the
& E- J' `1 ~1 j2 h2 Q3 n2 z
change loop count is 0, and the maximum number of records is 4095.

' k) F# G* C# l/ d2 n* p) N! }, f
[Huawei]interface vlanif 1

/ i" |7 S5 K9 `/ r1 [
[Huawei-Vlanif1]ip address 192.168.0.1 255.255.255.0

# |, E/ i" X9 D% ]7 E
[Huawei-Vlanif1]q

/ o& U* h1 ?& c' V
[Huawei]interface vlanif 2

4 W% s: _% K3 m' r/ q. m. |* a0 V
[Huawei-Vlanif2]ip address 192.168.2.1 255.255.255.0

3 o( V: U' k' R8 v" r& K
[Huawei-Vlanif2]q
! R! l3 Z$ \9 ^. s, J! t
[Huawei]interface giga 0/0/3

8 n- R* b5 l/ ]$ D. W5 v+ [
[Huawei-GigabitEthernet0/0/3]port link-type access
8 G% q# Q1 E) x
[Huawei-GigabitEthernet0/0/3]port default vlan 2
& c+ E$ e" L% T' v, G9 B
[Huawei-GigabitEthernet0/0/3]
" x2 Z( H9 w+ l: K+ S2 w! V
[Huawei]q

' t- G' m! _+ u& Z3 O! Y7 a$ i
save

8 B% L5 p8 @) Z! d. K2 t
The current configuration will be written to the device.
# o7 @( l6 G8 j
Are you sure to continue?[Y/N]y

( |& @$ w" m4 R. P$ d
Now saving the current configuration to the slot 0.
. p# f# }( `0 X9 g: Z
Mar 13 2014 11:02:44-08:00 Huawei %CFM/4/SAVE(l)[11]:The user chose Y when dec

( ]& Y' H1 ~8 N0 R% M' |  y
iding whether to save the configuration to the device.
2 v% `* y; L9 u' P, _; O$ o* D
Save the configuration successfully.

, A2 W1 \1 k2 H  h8 |; H
; `8 L4 s; W/ c; D( g5 z8 L
然后设置PC1和PC2的IP地址,先ping 1.1.1.1,如果没有问题再ping 192.168.1.3,192.168.1.111,202.99.192.66,一路ping下来是不是感觉有点小成就感,如果PC2无法ping通,那么就像昨天一样,在自己的真实路由器上做个静态路由指向192.168.2.0便可以了.需要的可以下载附件导出配置文件看.

. u% `! F* M0 l5 G' w
$ V  Z) D- s7 }% K. G% D9 m6 h3 ~. t* H6 S& i9 x; T
您需要登录后才可以回帖 登录 | 注册

本版积分规则

返回首页|Archiver|手机版|小黑屋|易陆发现技术论坛 ( 蜀ICP备2026014127号-1 )

GMT+8, 2026-6-12 01:53 , Processed in 0.015742 second(s), 22 queries .

Powered by Discuz! X5.0

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表