找回密码
 注册
查看: 1064|回复: 1

实验AR1200+S5700+S3700网络组网

[复制链接]

1

主题

0

回帖

12

积分

管理员

积分
12
QQ
发表于 2022-3-23 15:00:01 | 显示全部楼层 |阅读模式
AR1200+S5700+S3700访问外网的例子,其实也是我们公司实际的网络拓扑网,只是公司的还没有进行配置,AR2220做为路由访问外网,一台S5700是核心交换机,两台S3700做为接入层交换机使用,为每台S3700划分一个vlan,在本例中,一个是vlan 2,一个是vlan 4,只要这两个会了,再增加交换机也就没有问题了,希望对初学者有些帮助.网络拓扑图如下:
& ~$ ^4 \% M) R2 X; t3 v3 [

- z! ~7 L) u, c3 M
画图水平不行, 凑活着看就行,下面配置主路由器AR1200,'号后面是备注信息,配置如下:
4 x+ Y" y. k0 `7 O

[Huawei]acl number 2000               
# J  @% ?5 B3 ~2 z: _[Huawei-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255   '做个acl,可以根据自己需要配置IP,
. D' U4 Y6 ~* M[Huawei-acl-basic-2000]q. G5 j: q; |4 j" P. x" Q
[Huawei]vlan 100
( L3 k  i) \  ~% t  ?9 C3 d' G4 Y[Huawei-vlan100]q
2 f2 X$ w& K/ q4 L0 d1 X[Huawei]interface giga 0/0/0* ~0 Y, t$ E+ D7 M7 ]7 A% J; o+ V
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.3 24  '配置外网IP地址,也就是联通呀,移动等运营商提供给你的IP址,24是掩码          + ]$ c* O" d0 E  M, _
[Huawei-GigabitEthernet0/0/0]q- r4 M5 `; J; b% t2 ~+ x
[Huawei]interface giga 0/0/1
3 f  @" a) G5 c! }[Huawei-GigabitEthernet0/0/1]ip address 1.1.1.1 24   
  p  I$ F' m3 H  g7 x[Huawei-GigabitEthernet0/0/1]q! v* p- Q+ i9 s
[Huawei]ip route-static 0.0.0.0 0.0.0.0 192.168.1.1       '静态路由,使内网的所有外部访问都指向外网网关,网关是运营商提供的.
0 m- f2 e- h. Y9 ?+ v  d. ~[Huawei]ip route-static 192.168.2.0 255.255.255.0 1.1.1.3  '静态路由,所有访问192.168.2.X的请求指向1.1.1.3
9 I8 Q# q% O: _& }* ~[Huawei]ip route-static 192.168.4.0 255.255.255.0 1.1.1.4  '静态路由,所有访问192.168.4.X的请求指向1.1.1.4
0 @! h% {* W' U- g. p: G9 I( L. ?* o[Huawei]                                                                        '可以根据需要自己再增加$ j+ u- x% U) ]8 r- S  ?9 O  F+ S$ A
<Huawei>
& e5 z9 {$ u$ t3 O2 y2 f: e! F2 E刚开始搞不明白为什么路由器上的接口可以设置IP地址,交换机上的就不行,输入命令时经常搞错,所以遇到路由器就在接口上设置IP,交换机就在Vlanif接口上设置IP就行,也不知我的想法对不.5 J2 E$ u9 i8 h( p4 u6 L( x$ }

/ M4 g2 i) l6 r  N
接下来配置S5700核心交换机,配置如下:

[Huawei]undo info-center enable
0 v4 q; F, m" E) h6 DInfo: Information center is disabled.' u; V* ]! v2 E; R' a
[Huawei]vlan 100' K6 C2 V9 M$ m9 X1 f
[Huawei-vlan100]q
! I0 V" R& s0 Y3 q[Huawei]interface vlanif 100
( \2 w$ n& e: l; _[Huawei-Vlanif100]ip address 1.1.1.2 24& m. Q8 C9 N+ a2 t. Q# i5 X
[Huawei-Vlanif100]q
0 v! T/ }! l8 O, r/ U$ U, Q7 \8 ^) ^[Huawei]interface giga 0/0/22
) Q/ _& `' o7 P$ f4 h  t- d[Huawei-GigabitEthernet0/0/22]port link-type trunk                      '交换机和交换机之间连接用trunk接口! K) ]+ W6 P4 k
( T# n# t( f- l3 X. w# d$ @
[Huawei-GigabitEthernet0/0/22]port trunk allow-pass vlan 100 2     '允许通过vlan100和vlan2
" B9 H5 |! K& Z5 G& L: A8 a[Huawei-GigabitEthernet0/0/22]q
" w: y- L7 p# e/ R% b[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1' D% P( R9 ^/ z3 b
[Huawei]interface giga 0/0/24/ i7 @; j1 C" Y; T( q
& R8 j, |2 Y7 g' n7 k  A
[Huawei-GigabitEthernet0/0/24]port link-type access4 @8 t6 _7 \3 E$ G( Z0 L
[Huawei-GigabitEthernet0/0/24]port default vlan 100
& Q6 z0 x# |1 \, V- [[Huawei-GigabitEthernet0/0/24]q
  P+ @+ Z- |8 g" Q& R( f7 |& I[Huawei]interface giga 0/0/23( y' i, d1 J* {. z6 o9 t( V6 @3 S) _
[Huawei-GigabitEthernet0/0/23]port link-type trunk                     '同上面22接口. h* I! L- j2 @/ j$ v
[Huawei-GigabitEthernet0/0/23]port trunk allow-pass vlan 100 4    '允许通过vlan100和vlan4
9 Q5 c' Y3 z: E8 {) u( p9 a% g[Huawei-GigabitEthernet0/0/23]q, g0 V8 H# m5 S7 J" Y

- H. b# l( @1 z4 @4 E
+ {/ D% o" k, V+ ^, u. E
3 M6 @$ d2 {4 h( L0 j下面配置S3700交换机,属于vlan2
[Huawei]undo info-center enable. y: {0 j+ y& V' K9 N' t  k
Info: Information center is disabled.* i7 d+ z$ b5 E& D$ b. N
[Huawei]vlan 100: U9 w" r8 A1 H
[Huawei-vlan100]q/ A% |5 Y. ~  Y5 ^
[Huawei]interface eth 0/0/22
( U# y& J/ y8 P4 \3 N# _[Huawei-Ethernet0/0/22]ip address 1.1.1.3 24  '在这个地方出错了,不允许在接口上设置IP% [% |7 Q' W; l6 N
                          ^+ Z0 n+ ^2 l. p( y; ?* g
Error: Unrecognized command found at '^' position.
' b# ~3 T0 M3 k0 k& ^+ B[Huawei-Ethernet0/0/22]port link-type trunk0 V- v& }2 O3 ]/ p# H* x3 U
[Huawei-Ethernet0/0/22]port trunk allow-pass vlan 100 2( g/ m4 v. i, x; P( ~
[Huawei-Ethernet0/0/22]q; W( x/ e5 l: j( z
[Huawei]interface vlanif 100
* m' d" U' V0 v4 N8 S% O[Huawei-Vlanif100]ip address 1.1.1.3 24& {: w! \) w9 A+ D- h5 j
[Huawei-Vlanif100]q3 `8 @3 s' n/ v2 Y' ^5 U8 v. q$ N
[Huawei]vlan 2
7 D  q% ]" R4 o[Huawei-vlan2]q9 T  _$ P0 P1 a; V3 r& e
[Huawei]interface vlanif 2
" M+ j: V9 ?" D[Huawei-Vlanif2]ip address 192.168.2.1 249 c  X4 O& W. i9 M: @
[Huawei-Vlanif2]q0 B2 a. m! s9 A/ }3 x
[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1! q/ B( C: r: A9 s  Y- n- S
[Huawei]interface eth 0/0/11 t; I, z2 \$ K
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 2
" E- c- y- a2 q0 S
[Huawei-Ethernet0/0/1]port hybrid pvid vlan 2
" ?$ u  r/ b$ t; W' [
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 100 2
) a3 v/ p, ?7 s+ b3 ^- w& Q[Huawei-Ethernet0/0/1]dis this         ' 查看一下接口信息
0 m1 o" G2 G( K$ f# j. S- `#
2 g- t4 D5 n2 j+ ]: t. Qinterface Ethernet0/0/1
" q! K2 U% T; S% A' N, h; s port hybrid pvid vlan 2
0 j; n% I. }2 f9 t( s port hybrid untagged vlan 2 100
7 x% g+ C8 g* l) ~5 U#+ x! E2 f0 q* B, ~4 u
return
7 q3 G9 e* U4 H# @' u
" f1 d/ }5 t$ p* |3 R( ~/ n
下面配置S3700-2交换机,属于vlan4

[Huawei]undo info-center enable, V0 {. g: ]) W7 x2 D
Info: Information center is disabled.0 H) H9 K0 }: r! Z
[Huawei]vlan 100
  _- @5 b* j( S( M9 e" L[Huawei-vlan100]q
8 J: O2 R/ O- a2 q1 ^- S; T, }[Huawei]interface vlanif 100
5 }% ^% O+ t9 a* I6 s[Huawei-Vlanif100]ip address 1.1.1.4 24
6 |! @* L+ P" e4 w3 D2 x[Huawei-Vlanif100]q4 s, U& Q6 e, a+ [% p$ J
[Huawei]interface eth 0/0/22( _% w: Y$ d6 M9 j
[Huawei-Ethernet0/0/22]port link-type trunk; W+ r4 x8 \& F
[Huawei-Ethernet0/0/22]port trunk allow-pass vlan 100 4: Q/ f% b( K9 a
[Huawei-Ethernet0/0/22]dis this
9 S# B, d, p- q2 q8 w! Y#
6 g9 M5 M, e, Y: G* Rinterface Ethernet0/0/221 M7 h* g+ m& U1 w- }5 {
port link-type trunk8 {# J4 S% |2 Y9 p( s3 ~! g- y7 n$ a- g
port trunk allow-pass vlan 4 100% u: L6 B  q1 S# Q; d; \8 s, N( Z
#0 z! R( e8 ?) k+ {# Q" e( z
return3 W% L6 B/ L' D+ L' O
[Huawei-Ethernet0/0/22]q, j* Q3 O0 z  ]! @$ a! ~
[Huawei]vlan 4
8 B& T, U7 `* i4 D6 Z/ r1 ][Huawei-vlan4]q8 m  h' u" v1 \, G
[Huawei]interface vlanif 4
! [# c) i  w4 ^( u( y- U[Huawei-Vlanif4]ip address 192.168.4.1 24* ^: P3 J0 W( X( e
[Huawei-Vlanif4]q
3 W3 D5 _! K$ @6 J/ y, n[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1+ S' C  Q4 t8 F0 }# V" O" r2 |; `3 w8 ?
[Huawei]ping 192.168.4.19 w5 a( N4 E1 J! f9 R6 C
  PING 192.168.4.1: 56  data bytes, press CTRL_C to break
: c' e2 R# t) Q7 u/ [    Reply from 192.168.4.1: bytes=56 Sequence=1 ttl=255 time=20 ms) B" k4 }4 E# ^# o9 D# V: m
    Reply from 192.168.4.1: bytes=56 Sequence=2 ttl=255 time=10 ms
9 G; w3 ^2 a. z1 {6 Z; s% k    Reply from 192.168.4.1: bytes=56 Sequence=3 ttl=255 time=1 ms3 w. ]3 ~( E4 ^3 G2 p
    Reply from 192.168.4.1: bytes=56 Sequence=4 ttl=255 time=30 ms& j7 z6 o2 ]& b
    Reply from 192.168.4.1: bytes=56 Sequence=5 ttl=255 time=1 ms+ C: S# _( i5 M1 w9 t- Q  J1 I# x
  --- 192.168.4.1 ping statistics ---
& Y/ f4 d1 o- s& n) L    5 packet(s) transmitted+ q) X1 ?9 t8 V' ], g! u' N, b
    5 packet(s) received- o, \# L1 n" G
    0.00% packet loss' ?" v8 V; |3 Y$ Y7 |$ J) y+ m
    round-trip min/avg/max = 1/12/30 ms
3 ]& B; Q1 i, \- T[Huawei]interface eth 0/0/1
% \$ l4 {, x% v
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 100 4% E: y+ l/ U% \7 ?: n4 I9 o
[Huawei-Ethernet0/0/1]port hybrid pvid vlan 4# u* ]4 a/ p, ?4 v$ B
[Huawei-Ethernet0/0/1]q
  X  ]: v/ J. n) O, k
5 O3 d# L" v7 z( P9 q/ O2 S
好了,交换机和路由器的设置就完成了,把两个PC客户端配置好IP地址就可以试试效果了,但由于是模拟器的原因,在长间没有使用时,有时候会有ping不通的情况,在我这里两个都能ping通外网,vlan2和vlan4之间也能互通.在真实的设备上我们可以启用web界面和telnet,然后通过1.1.1.1,1.1.1.2,1.1.1.3这些地址来访问和管理路由器和交换机了,端口隔离,mac黑洞之类的配置可以在web界面上操作,谁让咱会的太少了.下面是前两个例子的地址,从简到稍难

8 I9 B4 v% E' c

1

主题

0

回帖

12

积分

管理员

积分
12
QQ
 楼主| 发表于 2022-3-23 15:00:02 | 显示全部楼层
首先配置AR2220,设置GE0接口IP为固定外网地址,设置GE1接口IP为1.1.1.1,然后做两条静态路由,创建vlan 100,红色文本是需要特别多看几眼的,代码如下:

[Huawei]vlan 100
" S6 Q3 o2 f' ?1 g$ e4 F$ j6 C
[Huawei-vlan100]q

3 }: ]6 J) u" j2 E. z
[Huawei]acl number 2000
8 T2 h3 `# r5 N8 }3 y( F
[Huawei-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255

& [+ k/ G6 b1 X! W; B
[Huawei-acl-basic-2000]q

& U" I+ |* F, z
[Huawei]interface giga 0/0/0
  ]( m8 o6 X) h
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.3 255.255.255.0

3 |% v; [1 @9 i) n. ^
[Huawei-GigabitEthernet0/0/0]

7 t, Q" e& C( ]
Mar 13 2014 07:34:12-05:13 Huawei %IFNET/4/LINK_STATE(l)[1]:The line protocol

7 a) T; V. a, G4 Q' T! e
IP on the interface GigabitEthernet0/0/0 has entered the UP state.
; V1 @( k# m9 T4 `! Y
[Huawei-GigabitEthernet0/0/0]q
; F# I3 R& F: U
[Huawei]interface giga 0/0/1

- X3 Z. D7 r1 O$ d7 q3 S" I& E3 D$ E
[Huawei-GigabitEthernet0/0/1]ip address 1.1.1.1 255.255.255.0
- x8 p8 Z8 _- `8 M1 A
[Huawei-GigabitEthernet0/0/1]q
; J0 [$ T( u. ?& N) |
[Huawei]ip route-static 0.0.0.0 0.0.0.0 192.168.1.1

+ u$ V0 ~1 q8 E3 w" i# `/ \7 e
[Huawei]ip route-static 192.168.0.0 255.255.0.0 1.1.1.2
4 \; f$ p9 {5 h9 A/ j* a7 d* v
[Huawei]q
# j8 ^) a6 y. R. C
save
5 t$ V* S( M# V* z; f! ]$ o0 i
  The current configuration will be written to the device.

% u: X5 l7 ~6 `" d" }/ |
  Are you sure to continue? (y/n)[n]:y

  u. L/ ?% f9 [3 z# [2 s
  It will take several minutes to save configuration file, please wait..........
* Y7 }  x, i4 R& O+ l: R- K" U
3 O1 h0 b- ?* |. ~

' s8 T, h! x! a) R; L8 b( m; A2 m  N- f
  Configuration file had been saved successfully

) W6 q1 o& y! ?9 m8 `; B
  Note: The configuration file will take effect after being activated
5 M$ q$ D( f. H0 A

% w4 e6 D$ z: s5 ?: a, U
Mar 13 2014 07:37:25-05:13 Huawei ARP/4/ARP_IPCONFLICT_TRAP:OID 16777216.50331648

" X6 c) J+ i0 Q7 J' Y
.100663296.16777216.67108864.16777216.3674669056.83886080.419430400.2063597568.33
  y; b- [* n8 V9 x0 Y) ]2 m+ Z
554432.100663296 ARP detects IP conflict. (IP address=201.1.168.192, Local interf
9 X/ f' V+ E4 D  @0 h
ace=GigabitEthernet0/0/0, Local MAC=4437-e68c-b212, Local vlan=0, Local CE vlan=0
1 P0 E" u! [7 @4 A) n/ z8 i5 Z+ O9 q
, Receive interface=GigabitEthernet0/0/0, Receive MAC=1c1a-c00f-253f, Receive vla

8 x6 m, G) ~! a9 u5 U, u" C/ {
n=0, Receive CE vlan=0, IP conflict type=Remote IP conflict).

+ R' R7 U+ J; v6 J7 j# ]: Z" D" m- j

2 T7 H1 S+ f' n/ z: X4 y0 Q0 m  {/ _: ?

接下来配置S5700交换机,GE1接口IP为1.1.1.2,属于vlan100,GE2接口属于vlan1,GE3接口属于vlan2,代码如下

[Huawei]vlan batch 2 4 6 8 100
Info: This operation may take a few seconds. Please wait for a moment...done.
% J* u0 C/ n1 u0 I2 C+ W
[Huawei]

/ y  k7 t- r$ ^4 H4 v' A
Mar 13 2014 10:38:34-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.

+ c! x+ ]& O7 n3 }7 ~3 k9 H
25.191.3.1 configurations have been changed. The current change number is 4, the

( ~% r4 p% N7 Y& W
change loop count is 0, and the maximum number of records is 4095.
! t9 l0 S- J* B9 W: _
[Huawei]interface vlanif 100
* p2 Y( K; q6 s& ?( o# C. m2 Q) q
[Huawei-Vlanif100]ip address 1.1.1.2 255.255.255.0
- S4 J, `: \1 G- |4 b+ z% a# Q/ |
[Huawei-Vlanif100]

+ L' }2 h' w% G% J
Mar 13 2014 10:40:14-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.
. M9 c8 L5 M) H/ b# C& q& b+ s
25.191.3.1 configurations have been changed. The current change number is 6, the

1 S, g( y+ Z8 x$ O1 H5 S. p, M
change loop count is 0, and the maximum number of records is 4095.
( }: r) w; ]  E0 f' ]& m+ r2 L$ H6 V
[Huawei-Vlanif100]q
- c$ L: C4 a! Y& @
[Huawei]interface giga 0/0/1

2 M( p3 ?0 P# ^4 ~3 r* {
[Huawei-GigabitEthernet0/0/1]port link-type access
% Q+ L5 a1 A: w
[Huawei-GigabitEthernet0/0/1]port default vlan 100
+ s3 ?; \/ i+ q% h& s) `) X
[Huawei-GigabitEthernet0/0/1]q

  _0 D# Q) u6 E. P8 v2 L2 o! n/ J3 D
[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1

( ]' t! h1 K/ H# a
[Huawei]

  f0 e2 \) i( y: h1 d9 g2 t  s
Mar 13 2014 10:43:24-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.
) Y4 b* d7 L9 j+ x7 e% u
25.191.3.1 configurations have been changed. The current change number is 9, the

2 E8 X" S% S' d% T3 e$ u
change loop count is 0, and the maximum number of records is 4095.

8 |9 V* Y! T* X7 Z# R. w
[Huawei]interface vlanif 1

% m3 d; c( z& X4 c1 U1 ?2 x" H$ L
[Huawei-Vlanif1]ip address 192.168.0.1 255.255.255.0

$ }& i' G9 {$ ]. l: e. _
[Huawei-Vlanif1]q
3 l4 C7 v4 Q! Q9 C( j
[Huawei]interface vlanif 2
: H; d( Y6 V- v# n" m
[Huawei-Vlanif2]ip address 192.168.2.1 255.255.255.0

1 l% X$ b! V# B
[Huawei-Vlanif2]q

) t/ m4 x" t0 G
[Huawei]interface giga 0/0/3

7 I2 u  |0 v# F  I3 R. D+ g
[Huawei-GigabitEthernet0/0/3]port link-type access

9 s( P$ B3 T, L+ v: F3 x, r
[Huawei-GigabitEthernet0/0/3]port default vlan 2
; d- r) v; P( g  O9 X3 \
[Huawei-GigabitEthernet0/0/3]
, K  y. M, p9 A& e2 f) ]( Q+ X
[Huawei]q
3 `  @. d/ t3 ~5 m! B
save
5 z5 J, m& }8 |  J9 \2 ?7 a
The current configuration will be written to the device.

. K9 i  k6 ~: v
Are you sure to continue?[Y/N]y
/ e2 H' v* E$ y  M* f
Now saving the current configuration to the slot 0.

/ `7 ^! ]" I, H0 ^% M
Mar 13 2014 11:02:44-08:00 Huawei %CFM/4/SAVE(l)[11]:The user chose Y when dec

7 m" W! R8 {3 c
iding whether to save the configuration to the device.

* n# w3 Z3 j+ _5 u" i4 W# q
Save the configuration successfully.

  d: |' Y  u% u4 F( U4 ~& g5 d% l% F- L0 K

然后设置PC1和PC2的IP地址,先ping 1.1.1.1,如果没有问题再ping 192.168.1.3,192.168.1.111,202.99.192.66,一路ping下来是不是感觉有点小成就感,如果PC2无法ping通,那么就像昨天一样,在自己的真实路由器上做个静态路由指向192.168.2.0便可以了.需要的可以下载附件导出配置文件看.
  ]/ B( D+ j% z  v! S. y  W) Z
# d! w# I% D+ Y: B
7 S+ _4 C0 A1 e7 V1 |; q. s
您需要登录后才可以回帖 登录 | 注册

本版积分规则

返回首页|Archiver|手机版|小黑屋|易陆发现技术论坛 ( 蜀ICP备2026014127号-1 )

GMT+8, 2026-6-12 03:02 , Processed in 0.020007 second(s), 22 queries .

Powered by Discuz! X5.0

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表