找回密码
 注册
查看: 1065|回复: 1

实验AR1200+S5700+S3700网络组网

[复制链接]

1

主题

0

回帖

12

积分

管理员

积分
12
QQ
发表于 2022-3-23 15:00:01 | 显示全部楼层 |阅读模式
AR1200+S5700+S3700访问外网的例子,其实也是我们公司实际的网络拓扑网,只是公司的还没有进行配置,AR2220做为路由访问外网,一台S5700是核心交换机,两台S3700做为接入层交换机使用,为每台S3700划分一个vlan,在本例中,一个是vlan 2,一个是vlan 4,只要这两个会了,再增加交换机也就没有问题了,希望对初学者有些帮助.网络拓扑图如下:0 E5 k( x* z5 B. v: I# a' c, v/ B9 M


0 P  |9 i0 b. k/ @+ P8 h
画图水平不行, 凑活着看就行,下面配置主路由器AR1200,'号后面是备注信息,配置如下:

, |' t3 @6 x! o% Y( Y. f
[Huawei]acl number 2000                5 _/ B" |( ~- k
[Huawei-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255   '做个acl,可以根据自己需要配置IP,' o6 I1 l5 H- `2 f" j4 Z7 k- u* X
[Huawei-acl-basic-2000]q
% @! x3 w9 I3 W( K' c[Huawei]vlan 100
% n9 J4 g1 W) n[Huawei-vlan100]q
! w# ~( \9 E+ Q& i, f/ r[Huawei]interface giga 0/0/06 M( ?/ L! N1 k
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.3 24  '配置外网IP地址,也就是联通呀,移动等运营商提供给你的IP址,24是掩码          3 S8 Z6 s; ^! z( t) N9 J  `
[Huawei-GigabitEthernet0/0/0]q! S5 y. ?6 `3 d9 L
[Huawei]interface giga 0/0/18 G- x; q, P: G* c0 E6 j
[Huawei-GigabitEthernet0/0/1]ip address 1.1.1.1 24   
. M0 `7 |  O0 ^7 L6 p# l[Huawei-GigabitEthernet0/0/1]q
, D- I& p9 f, Q3 B/ o; Z- P+ L[Huawei]ip route-static 0.0.0.0 0.0.0.0 192.168.1.1       '静态路由,使内网的所有外部访问都指向外网网关,网关是运营商提供的.- F* }& `# Y1 r
[Huawei]ip route-static 192.168.2.0 255.255.255.0 1.1.1.3  '静态路由,所有访问192.168.2.X的请求指向1.1.1.3
# m) l4 a5 a( S+ S5 q[Huawei]ip route-static 192.168.4.0 255.255.255.0 1.1.1.4  '静态路由,所有访问192.168.4.X的请求指向1.1.1.4
5 A7 p; U" |* ?& L4 R# d; B[Huawei]                                                                        '可以根据需要自己再增加' F6 K6 g# Y3 N/ m
<Huawei>
  o0 b! e+ ^0 _% K2 L刚开始搞不明白为什么路由器上的接口可以设置IP地址,交换机上的就不行,输入命令时经常搞错,所以遇到路由器就在接口上设置IP,交换机就在Vlanif接口上设置IP就行,也不知我的想法对不.
) f5 l2 W6 k" o% d- m& J) x' U
# F4 Q1 N# S" o8 O$ ^# m
接下来配置S5700核心交换机,配置如下:

[Huawei]undo info-center enable
. ?* q# E$ g& eInfo: Information center is disabled.  o3 J' S+ W  J4 T. z% u
[Huawei]vlan 100
- i$ ?1 H& ^3 D[Huawei-vlan100]q5 V( |9 y- V' Q7 b! ]0 U3 ?
[Huawei]interface vlanif 100
2 T; y- z# j0 U9 C* J7 M3 Q" ~[Huawei-Vlanif100]ip address 1.1.1.2 24
0 O! [  g# m2 z) G5 U8 ]/ Y4 v& f[Huawei-Vlanif100]q
$ X; h* x& L' f! e7 j* [; ^[Huawei]interface giga 0/0/22" J2 Q5 c' B! t$ M4 n  s9 J' V
[Huawei-GigabitEthernet0/0/22]port link-type trunk                      '交换机和交换机之间连接用trunk接口6 v4 b$ O: f. C0 `  C1 S
8 |% K% |) Q$ e# `
[Huawei-GigabitEthernet0/0/22]port trunk allow-pass vlan 100 2     '允许通过vlan100和vlan23 m" S! p  ?" G, ]
[Huawei-GigabitEthernet0/0/22]q8 l0 \6 d: U7 E: n" Y
[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1
1 [/ M1 o1 |# F& S2 l% Q[Huawei]interface giga 0/0/24# U: ?! p3 U2 k6 w
1 ^1 M8 C0 ^$ t$ l/ U/ s
[Huawei-GigabitEthernet0/0/24]port link-type access4 u+ ^, h2 v" V
[Huawei-GigabitEthernet0/0/24]port default vlan 100" \8 u' q  _8 ], I' m
[Huawei-GigabitEthernet0/0/24]q
  C1 k7 ?) k# o[Huawei]interface giga 0/0/23
! j/ q! W/ L7 R[Huawei-GigabitEthernet0/0/23]port link-type trunk                     '同上面22接口
% Q# p1 z6 Q. ^, i: @" D[Huawei-GigabitEthernet0/0/23]port trunk allow-pass vlan 100 4    '允许通过vlan100和vlan4
+ A: m1 ^: e& z. p  V  p" ~[Huawei-GigabitEthernet0/0/23]q% N8 x; v+ w' D2 G0 p% M* R$ O. g
4 e3 E& W) E2 i- o$ X& w) o4 m% p

4 O( C: p: D% d. c
8 ^' C8 A: ~# k$ T- T! u下面配置S3700交换机,属于vlan2
[Huawei]undo info-center enable  @5 u0 l8 m4 t
Info: Information center is disabled.
4 i1 X2 Q5 g; E) I6 `* k[Huawei]vlan 100$ j; _+ ~) Q0 L2 P1 ^! O$ X
[Huawei-vlan100]q
9 R( ]7 M& _$ r" n) V+ i0 V[Huawei]interface eth 0/0/22
9 e3 U+ |5 w/ s5 ~7 Z[Huawei-Ethernet0/0/22]ip address 1.1.1.3 24  '在这个地方出错了,不允许在接口上设置IP
6 ?* f$ E; K+ E' h  M                          ^
: r( z0 _. p- l) u9 |2 |Error: Unrecognized command found at '^' position.0 n4 b+ {/ F, O2 |. y
[Huawei-Ethernet0/0/22]port link-type trunk, w; P1 I/ v& g7 P6 A  l. z$ D
[Huawei-Ethernet0/0/22]port trunk allow-pass vlan 100 2# {# Y6 v% f5 @+ F. i. }0 H* U! ~
[Huawei-Ethernet0/0/22]q
# G% a' v7 h* z4 a[Huawei]interface vlanif 1000 D& C- H2 ^% p, ^
[Huawei-Vlanif100]ip address 1.1.1.3 24: O9 n. \8 _# x. ]/ P: c/ c
[Huawei-Vlanif100]q
) R3 t- ~& L/ m# k/ e7 _[Huawei]vlan 2
$ r% b, E3 S' R" v0 b( _9 Q7 m[Huawei-vlan2]q! e; I1 m" @2 Q4 e+ C$ i
[Huawei]interface vlanif 27 R$ P# \/ [) Y. E9 v% l
[Huawei-Vlanif2]ip address 192.168.2.1 24
' j% s1 s: J' D  J( M' A[Huawei-Vlanif2]q, x" O% [6 B  u9 D5 P2 X5 y
[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1; U$ t$ y; l: e4 l
[Huawei]interface eth 0/0/14 u! h- Z; U" S6 z
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 2% g% n  }. V1 b2 e& J1 l* M
[Huawei-Ethernet0/0/1]port hybrid pvid vlan 2
  {% w6 B. @7 ?2 x1 j5 N
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 100 26 y# b% ?* R# x4 V2 z4 b
[Huawei-Ethernet0/0/1]dis this         ' 查看一下接口信息
! m  f3 y/ h8 g- G6 F4 \#
1 q' y" B( U! r: P" G. y$ K+ zinterface Ethernet0/0/1& }3 b; A3 U& ~9 N5 t
port hybrid pvid vlan 2
9 `" G: X; v1 S+ c* _ port hybrid untagged vlan 2 100  z; x7 n$ E$ Z  `0 F
#
: I  N! ]0 Q' H' C7 Qreturn
1 P' ~  }- f/ f6 p' |
. J" z+ t/ N& k+ l
下面配置S3700-2交换机,属于vlan4

[Huawei]undo info-center enable
1 }; J5 ?7 _1 ~2 kInfo: Information center is disabled.
! B" ^1 S- o9 r8 Z[Huawei]vlan 100
; J6 p8 o; V  s2 S  f" M[Huawei-vlan100]q: N) z9 B6 z# Z
[Huawei]interface vlanif 1006 p6 t) V7 Z# ~% v# z
[Huawei-Vlanif100]ip address 1.1.1.4 24
( o0 \$ m! d2 ]0 g3 i[Huawei-Vlanif100]q
5 m6 ?4 c5 M) g" H. t$ m[Huawei]interface eth 0/0/22
1 G3 \# E4 G7 H[Huawei-Ethernet0/0/22]port link-type trunk9 R. _9 Q1 h, Q( w3 e2 `# q" X
[Huawei-Ethernet0/0/22]port trunk allow-pass vlan 100 4
7 U, Y: d. r0 h, L6 j[Huawei-Ethernet0/0/22]dis this( H# E, l0 `. A& u$ x$ e
#
" M. U' `! j3 E9 A& ointerface Ethernet0/0/22
9 z0 [1 t/ s# N! a port link-type trunk
) l& w1 W( e. M' ~3 q port trunk allow-pass vlan 4 100/ B  s  U7 \$ |" F; z7 W
#
3 H% u# z: q. x% T; C2 M$ Q& Rreturn
, [5 k2 f% T) T% `0 `: W[Huawei-Ethernet0/0/22]q6 X  A& f+ F' X! y6 q4 X
[Huawei]vlan 4
) j+ [, J5 S* b" _[Huawei-vlan4]q9 e! w9 C( c3 q
[Huawei]interface vlanif 49 r+ I0 d5 v) t
[Huawei-Vlanif4]ip address 192.168.4.1 247 u0 H: X5 {9 S- `$ U
[Huawei-Vlanif4]q- j( ~' v8 m# k* V
[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1
$ ~: K( u9 T2 o- w# ]' ~/ ~[Huawei]ping 192.168.4.1  r# [% v+ `9 ~# P6 K8 s
  PING 192.168.4.1: 56  data bytes, press CTRL_C to break& z: T! Z  u. i* m
    Reply from 192.168.4.1: bytes=56 Sequence=1 ttl=255 time=20 ms4 A+ j5 x  ?# j0 h; V4 B+ J2 @- m: B
    Reply from 192.168.4.1: bytes=56 Sequence=2 ttl=255 time=10 ms* F2 L; l% {9 Y: [5 k. i
    Reply from 192.168.4.1: bytes=56 Sequence=3 ttl=255 time=1 ms
) f( W$ x8 r2 x) p5 [, U' I    Reply from 192.168.4.1: bytes=56 Sequence=4 ttl=255 time=30 ms( n/ e. m4 c9 [; ?
    Reply from 192.168.4.1: bytes=56 Sequence=5 ttl=255 time=1 ms8 X  m9 c4 a( V" ]2 Y, `
  --- 192.168.4.1 ping statistics ---
( w. q+ C' |3 p; S4 b# X9 T    5 packet(s) transmitted) d" V0 i% R; k; w3 i0 N" I6 r
    5 packet(s) received
! ~; K2 s0 s4 o6 Y% e    0.00% packet loss
) N1 E1 H3 O  f  N: h    round-trip min/avg/max = 1/12/30 ms; m" O7 Q) h" o8 t% p: g# S
[Huawei]interface eth 0/0/1. K, H0 e3 D, U+ z$ t
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 100 4
8 B- l, q9 i' Q+ F6 [. J[Huawei-Ethernet0/0/1]port hybrid pvid vlan 49 I, y" {9 K5 H/ C6 ]
[Huawei-Ethernet0/0/1]q% T* {. x4 L7 b. M- f8 c

% D& e! z* W" L( A! C& g
好了,交换机和路由器的设置就完成了,把两个PC客户端配置好IP地址就可以试试效果了,但由于是模拟器的原因,在长间没有使用时,有时候会有ping不通的情况,在我这里两个都能ping通外网,vlan2和vlan4之间也能互通.在真实的设备上我们可以启用web界面和telnet,然后通过1.1.1.1,1.1.1.2,1.1.1.3这些地址来访问和管理路由器和交换机了,端口隔离,mac黑洞之类的配置可以在web界面上操作,谁让咱会的太少了.下面是前两个例子的地址,从简到稍难

4 c  U+ p: e, O4 c0 {, r9 f

1

主题

0

回帖

12

积分

管理员

积分
12
QQ
 楼主| 发表于 2022-3-23 15:00:02 | 显示全部楼层
首先配置AR2220,设置GE0接口IP为固定外网地址,设置GE1接口IP为1.1.1.1,然后做两条静态路由,创建vlan 100,红色文本是需要特别多看几眼的,代码如下:

[Huawei]vlan 100
8 K0 ?9 C8 |' n2 I2 u1 J7 E; D6 p
[Huawei-vlan100]q
- P2 e' U- }9 L2 v5 s
[Huawei]acl number 2000
( _( F, q( S6 Z0 l2 @
[Huawei-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255
( N9 g0 p( |- x& b* e8 U0 M
[Huawei-acl-basic-2000]q
" ^8 s( h- L& s' f7 y$ I" W5 j7 u
[Huawei]interface giga 0/0/0
( G" o6 q% J' ~, a* _
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.3 255.255.255.0
- t& `" U3 d/ T5 K
[Huawei-GigabitEthernet0/0/0]
6 r) L. C. J/ o" i# s) b5 K% f
Mar 13 2014 07:34:12-05:13 Huawei %IFNET/4/LINK_STATE(l)[1]:The line protocol

3 K+ ^1 g( W0 K# N
IP on the interface GigabitEthernet0/0/0 has entered the UP state.

7 v4 O5 J6 l% i4 ^/ V  V
[Huawei-GigabitEthernet0/0/0]q
( f6 Z9 h) j0 ~, O
[Huawei]interface giga 0/0/1

5 C' k4 ~# o# l1 J) u2 q3 ~- B5 E
[Huawei-GigabitEthernet0/0/1]ip address 1.1.1.1 255.255.255.0
7 o; Z2 E9 v; z' s
[Huawei-GigabitEthernet0/0/1]q
7 |5 {/ f# T, }% e7 @8 A$ n
[Huawei]ip route-static 0.0.0.0 0.0.0.0 192.168.1.1
* p& ^4 W4 [4 \
[Huawei]ip route-static 192.168.0.0 255.255.0.0 1.1.1.2
, G8 V9 B6 o8 G
[Huawei]q

0 R: P6 L. s7 S) k# I) C. r4 x$ h: r
save
0 T; `1 }: }2 s; z5 t
  The current configuration will be written to the device.
2 @2 K% T5 n* R. z8 h9 n( Z
  Are you sure to continue? (y/n)[n]:y

  E) f4 @5 n9 ]6 a  r4 V' x0 x8 |
  It will take several minutes to save configuration file, please wait..........

3 u! A: \5 ~8 X8 e: A5 k. z1 ]) n- `8 u! H9 }' \
& F3 H7 }8 u" ]! M8 Y+ R
  Configuration file had been saved successfully

) J1 ]6 t8 x% [% J0 s
  Note: The configuration file will take effect after being activated

+ @4 J2 b8 f1 W( [+ z2 Y) ]
! b6 F1 ]" P! q* L1 l  B
Mar 13 2014 07:37:25-05:13 Huawei ARP/4/ARP_IPCONFLICT_TRAP:OID 16777216.50331648

2 i: b) j4 k% Y- E: Y! s
.100663296.16777216.67108864.16777216.3674669056.83886080.419430400.2063597568.33
2 a. `( i, h2 |  ^9 U
554432.100663296 ARP detects IP conflict. (IP address=201.1.168.192, Local interf

+ e5 u$ q1 X7 s& A" K2 y' U
ace=GigabitEthernet0/0/0, Local MAC=4437-e68c-b212, Local vlan=0, Local CE vlan=0

; d6 g, K8 Q* q0 l' g
, Receive interface=GigabitEthernet0/0/0, Receive MAC=1c1a-c00f-253f, Receive vla

" B) l' ^* X: B, T* C3 J- x
n=0, Receive CE vlan=0, IP conflict type=Remote IP conflict).

) I* }  }% X( x) g
( R) D0 p' a. z3 u8 Z
0 r* i2 Y! C9 V! g  a( u0 n- L

接下来配置S5700交换机,GE1接口IP为1.1.1.2,属于vlan100,GE2接口属于vlan1,GE3接口属于vlan2,代码如下

[Huawei]vlan batch 2 4 6 8 100
Info: This operation may take a few seconds. Please wait for a moment...done.

, V; H/ k# l: D) n& {7 U
[Huawei]
" t# d9 W! Q6 O% K" B
Mar 13 2014 10:38:34-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.
% y( |5 N+ P% h) U5 A
25.191.3.1 configurations have been changed. The current change number is 4, the
& M) k4 y# e; ?2 }
change loop count is 0, and the maximum number of records is 4095.

3 X; Y- H8 \/ }. c' g
[Huawei]interface vlanif 100

5 }6 P, j  k; W9 v# Z# p2 x+ a
[Huawei-Vlanif100]ip address 1.1.1.2 255.255.255.0
/ z- U5 K5 d7 Q" a
[Huawei-Vlanif100]
3 K* E# V4 N5 J* C5 w( H3 q
Mar 13 2014 10:40:14-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.

& ]% A$ L1 ~1 P" V, Y/ b) y
25.191.3.1 configurations have been changed. The current change number is 6, the
. s/ H+ N1 s# I( l% N
change loop count is 0, and the maximum number of records is 4095.

6 x1 b5 d, q1 i3 u, w) a1 \9 Q
[Huawei-Vlanif100]q

' ~0 s' X. m9 R6 L8 |3 K
[Huawei]interface giga 0/0/1
& P* G& V- Z) Y6 h7 @
[Huawei-GigabitEthernet0/0/1]port link-type access
7 ~7 ]- E1 _3 h& n( ?
[Huawei-GigabitEthernet0/0/1]port default vlan 100

, o) B0 D7 n; O3 F; S
[Huawei-GigabitEthernet0/0/1]q

4 Q8 [! \* m  {5 S. f
[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1

- B6 s( v& ]; ~% I) q. {: D
[Huawei]

9 _$ w5 [$ M  R* N) p+ ?, s. I% n
Mar 13 2014 10:43:24-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.
, _, f7 I- q+ B( g8 c* V
25.191.3.1 configurations have been changed. The current change number is 9, the
* E3 Q6 `' O$ x7 X" b
change loop count is 0, and the maximum number of records is 4095.

7 m; d" y& o* N+ w3 Y# J' l9 l
[Huawei]interface vlanif 1

- @4 w& `* w3 H3 |7 c; D4 @4 Q1 k" i
[Huawei-Vlanif1]ip address 192.168.0.1 255.255.255.0
' j- D( Y. W: n8 ?4 c% w8 j* V
[Huawei-Vlanif1]q

* f1 E) }) A# T3 V. \. ~
[Huawei]interface vlanif 2
! B% y9 w9 G  q4 i. b
[Huawei-Vlanif2]ip address 192.168.2.1 255.255.255.0

0 z$ W) V4 w+ \! R8 p" _
[Huawei-Vlanif2]q

! I9 |+ s: U2 H# ]7 z; N
[Huawei]interface giga 0/0/3
& q: m+ j! P: k! l& ^
[Huawei-GigabitEthernet0/0/3]port link-type access
3 N- E5 v  i# _- d9 C* b9 m9 i
[Huawei-GigabitEthernet0/0/3]port default vlan 2

  U& s% k) k6 a" W2 [; t- C" {$ y
[Huawei-GigabitEthernet0/0/3]
& I/ X6 {* D$ ~2 K" q
[Huawei]q
- I: s$ V( K, v2 o) _1 n; c" c
save

9 |# U9 `$ r4 s2 u- `; x
The current configuration will be written to the device.

& ?% H& U9 |7 }" E$ w5 T
Are you sure to continue?[Y/N]y

6 o/ y9 t: W, `  J
Now saving the current configuration to the slot 0.

9 B) [% g4 y  E5 m* ~  G& `
Mar 13 2014 11:02:44-08:00 Huawei %CFM/4/SAVE(l)[11]:The user chose Y when dec

  g: e; X5 v* ?4 B2 o/ N/ k
iding whether to save the configuration to the device.

! o0 w8 R3 ^% M: o1 h
Save the configuration successfully.
7 h9 e- Z$ j8 E4 l$ W
! J; }" P: N# U" M2 Q' l

然后设置PC1和PC2的IP地址,先ping 1.1.1.1,如果没有问题再ping 192.168.1.3,192.168.1.111,202.99.192.66,一路ping下来是不是感觉有点小成就感,如果PC2无法ping通,那么就像昨天一样,在自己的真实路由器上做个静态路由指向192.168.2.0便可以了.需要的可以下载附件导出配置文件看.
  a7 M  W' I0 Q  O& Y
! X. }2 o7 i1 X+ F; C0 @
3 B/ B: I, X  Q
您需要登录后才可以回帖 登录 | 注册

本版积分规则

返回首页|Archiver|手机版|小黑屋|易陆发现技术论坛 ( 蜀ICP备2026014127号-1 )

GMT+8, 2026-6-12 03:05 , Processed in 0.018900 second(s), 22 queries .

Powered by Discuz! X5.0

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表