易陆发现互联网技术论坛

 找回密码
 开始注册
查看: 1053|回复: 1
收起左侧

实验AR1200+S5700+S3700网络组网

[复制链接]
发表于 2022-3-23 15:00:01 | 显示全部楼层 |阅读模式

马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。

您需要 登录 才可以下载或查看,没有账号?开始注册

x
AR1200+S5700+S3700访问外网的例子,其实也是我们公司实际的网络拓扑网,只是公司的还没有进行配置,AR2220做为路由访问外网,一台S5700是核心交换机,两台S3700做为接入层交换机使用,为每台S3700划分一个vlan,在本例中,一个是vlan 2,一个是vlan 4,只要这两个会了,再增加交换机也就没有问题了,希望对初学者有些帮助.网络拓扑图如下:
  B. d# x% ?( k6 k1 b2 J
/ ^# C: z/ f) G7 x0 I3 u
& m! B& x: H9 Q& W- \5 V
                               
登录/注册后可看大图
画图水平不行, 凑活着看就行,下面配置主路由器AR1200,'号后面是备注信息,配置如下:
/ D+ t! V) K( t% x

[Huawei]acl number 2000                ! W! z  W1 k; ^9 G
[Huawei-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255   '做个acl,可以根据自己需要配置IP,1 U' a1 t. {; w' }" M
[Huawei-acl-basic-2000]q
  g) L/ V+ e. W3 a[Huawei]vlan 100
4 l$ y% R1 l1 e  A. m[Huawei-vlan100]q, k: N1 g) t' i7 w* o
[Huawei]interface giga 0/0/0
. P( e4 ]# m9 `' t# t" z) ~[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.3 24  '配置外网IP地址,也就是联通呀,移动等运营商提供给你的IP址,24是掩码         
: G! k6 y' Q& W) G4 X. M[Huawei-GigabitEthernet0/0/0]q
& u+ L, r9 n. u: G[Huawei]interface giga 0/0/1
! _. T5 c6 q; _! f) B! Q) k8 L+ y' I[Huawei-GigabitEthernet0/0/1]ip address 1.1.1.1 24   
* L: O, S1 m4 ]" V& J% X6 ]* H[Huawei-GigabitEthernet0/0/1]q. P& I/ J0 X+ t0 r* O% Y
[Huawei]ip route-static 0.0.0.0 0.0.0.0 192.168.1.1       '静态路由,使内网的所有外部访问都指向外网网关,网关是运营商提供的.
8 w* m% `: o4 j! O3 Y[Huawei]ip route-static 192.168.2.0 255.255.255.0 1.1.1.3  '静态路由,所有访问192.168.2.X的请求指向1.1.1.39 ]( O  n9 J7 x- x
[Huawei]ip route-static 192.168.4.0 255.255.255.0 1.1.1.4  '静态路由,所有访问192.168.4.X的请求指向1.1.1.4% R& t' x( b; [4 g5 L0 W% ^
[Huawei]                                                                        '可以根据需要自己再增加
" ?  K# j* Z' l) O8 I: [# Q<Huawei>
' L# {7 Z2 j1 p: x! o2 {' C! A刚开始搞不明白为什么路由器上的接口可以设置IP地址,交换机上的就不行,输入命令时经常搞错,所以遇到路由器就在接口上设置IP,交换机就在Vlanif接口上设置IP就行,也不知我的想法对不.
4 ~( C9 e; u" i8 v. T, P; n
' R/ J/ H1 t- a, U& }
接下来配置S5700核心交换机,配置如下:

[Huawei]undo info-center enable* o$ e% ~, w4 S' W8 v
Info: Information center is disabled.1 |5 `5 k8 r. h7 T3 [
[Huawei]vlan 100
, e) b8 s0 U) M7 f[Huawei-vlan100]q. |# H6 g! P$ r* l8 s6 w
[Huawei]interface vlanif 100; |) [5 Y. _5 }) k6 F& C
[Huawei-Vlanif100]ip address 1.1.1.2 24" c% n3 Y' X* m
[Huawei-Vlanif100]q
; m4 S3 H8 J  M6 z. q7 M! [* T5 R[Huawei]interface giga 0/0/22
" s% z$ e4 f' i# a8 j1 j! d[Huawei-GigabitEthernet0/0/22]port link-type trunk                      '交换机和交换机之间连接用trunk接口
5 c% h4 C( n$ Y4 R" o+ z* Z8 K' U& [" d' D( L) T1 d6 Y
[Huawei-GigabitEthernet0/0/22]port trunk allow-pass vlan 100 2     '允许通过vlan100和vlan2+ F: @# y! o% c4 T- a& H% ~, ~- l
[Huawei-GigabitEthernet0/0/22]q+ |3 K$ H  A5 T) l& M. E
[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1' P* s0 b8 |5 l# d* b. ?- f) X) b
[Huawei]interface giga 0/0/24, B3 d' W3 r% n9 p  q$ C; O' L( a

, \5 F: W- g. d1 @6 x[Huawei-GigabitEthernet0/0/24]port link-type access+ q5 L, {7 i8 Q% g' G+ i$ m' s) S
[Huawei-GigabitEthernet0/0/24]port default vlan 100
: U# }! C& o  a4 l[Huawei-GigabitEthernet0/0/24]q3 j' w4 M7 ^, Y. P: ~
[Huawei]interface giga 0/0/23
7 K/ [* I; H& B[Huawei-GigabitEthernet0/0/23]port link-type trunk                     '同上面22接口
/ [5 |( V  j' N, x" @[Huawei-GigabitEthernet0/0/23]port trunk allow-pass vlan 100 4    '允许通过vlan100和vlan4
0 i9 j/ k0 L2 U* I, S! f[Huawei-GigabitEthernet0/0/23]q
1 {# h, N6 O& u3 _2 T% q) c. T0 i
. [4 q* m3 V' g7 W& h& L  b5 j# A6 o6 m. u7 r6 r3 ~2 m

% b+ Y* `& g- Z/ y  C下面配置S3700交换机,属于vlan2
[Huawei]undo info-center enable
8 U4 V( Q* K( j5 P/ vInfo: Information center is disabled.3 @- m2 l$ z8 ?3 L0 \  p7 z, Q
[Huawei]vlan 100
+ z) F& J) L7 m7 v; d. B% H[Huawei-vlan100]q
! ?# R  b- e: w1 x[Huawei]interface eth 0/0/224 N- j# q: W) q4 H
[Huawei-Ethernet0/0/22]ip address 1.1.1.3 24  '在这个地方出错了,不允许在接口上设置IP  \$ s/ `  c6 l- A7 l! ^4 T) y
                          ^! A+ J- c( k& Z  y$ s# O( K
Error: Unrecognized command found at '^' position.
& N* T+ L0 k' h$ c& t[Huawei-Ethernet0/0/22]port link-type trunk- {' {$ w7 X! o  f- M  E
[Huawei-Ethernet0/0/22]port trunk allow-pass vlan 100 2
, Y, q. L& u' i/ z[Huawei-Ethernet0/0/22]q( O, r0 G/ p9 @( r
[Huawei]interface vlanif 100
# f9 P7 L8 o6 n" ~. T7 E[Huawei-Vlanif100]ip address 1.1.1.3 24
' j1 I; y6 `5 ?' t[Huawei-Vlanif100]q
& S, Q0 {  x' k, _5 _% }[Huawei]vlan 2: Z# A% |, @% S+ A9 ~7 y' g; q- y
[Huawei-vlan2]q/ c  ]. y. @6 k; Z; |! Z
[Huawei]interface vlanif 22 X2 S% g. G8 }5 P) h% N& W; ]
[Huawei-Vlanif2]ip address 192.168.2.1 24) h* o$ W% r- V; Y: z" s# b1 ^
[Huawei-Vlanif2]q
1 D  K$ S2 I0 J[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1* k& v! _8 P4 _1 R0 I( E4 O
[Huawei]interface eth 0/0/1, P- `& ?0 {5 ]. h4 b5 P- U
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 2' O: E* h/ b' C2 t" B, F9 }# w
[Huawei-Ethernet0/0/1]port hybrid pvid vlan 2
) D/ L2 o) v) y" `- s1 W
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 100 2
& |6 j, W& x; ?2 O; J$ z- s7 t[Huawei-Ethernet0/0/1]dis this         ' 查看一下接口信息
, U% x4 S2 N! W9 d#
" m7 d2 {8 U% Y  P. N- k& S1 `! W8 t% binterface Ethernet0/0/10 V" {& H5 L- Q: N) ?* e
port hybrid pvid vlan 2
% p7 j1 }2 q4 S# i port hybrid untagged vlan 2 100
& y% G4 U4 p) A: n#& f) b: B$ [& p  ]5 z/ d/ k6 k* R
return
, n- Z" Q) }! A9 g5 y" d: q! R

  p$ r* B, B  q" @1 J/ j; h
下面配置S3700-2交换机,属于vlan4

[Huawei]undo info-center enable+ i6 B7 T& g  H
Info: Information center is disabled.
. R( n2 w  t5 c0 H" s$ _) n[Huawei]vlan 1009 ?9 o" s# \- R! X+ C7 O2 B
[Huawei-vlan100]q
8 `6 a- {7 l) F: `4 y5 y[Huawei]interface vlanif 100
. p5 ~! F$ x1 p5 S! ]9 ~  m- ~[Huawei-Vlanif100]ip address 1.1.1.4 24
+ P( y' I+ X' w: v8 c, S& T[Huawei-Vlanif100]q
2 Y# M/ Y. N  Q[Huawei]interface eth 0/0/22
0 h: F' a( t, o+ o/ o& y* l; q[Huawei-Ethernet0/0/22]port link-type trunk' a+ d6 b, x; H* l* v6 {
[Huawei-Ethernet0/0/22]port trunk allow-pass vlan 100 4+ Y$ `; E% W  D3 @/ N/ y
[Huawei-Ethernet0/0/22]dis this
# x1 D  {& O) Q2 V) k#
: g; H+ Q: \' z1 k+ e& @  q$ Qinterface Ethernet0/0/22
* `6 D9 P+ _+ Z3 g0 `+ H7 h, H& s port link-type trunk
9 C/ P6 y* I, l" E port trunk allow-pass vlan 4 100
- v. E" k1 T& A% B#/ g0 [0 A' g/ l& w/ L
return( m: R2 V- ^5 M$ Y; C
[Huawei-Ethernet0/0/22]q7 z, `' A4 M/ ]8 m* r
[Huawei]vlan 4
' J# f' c; @3 W: Q0 d[Huawei-vlan4]q
$ d' x3 j- L0 U% l" q
[Huawei]interface vlanif 4
: H" \9 T) b( y) e, S* V5 j1 Z4 c[Huawei-Vlanif4]ip address 192.168.4.1 24$ b& X1 X( C: y1 Y! x
[Huawei-Vlanif4]q  d7 j% v' ]+ K9 G' E8 `9 `& Y
[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1% s/ q6 j$ \, b! {0 i  H/ w2 V
[Huawei]ping 192.168.4.1
# c: @9 \' l* A5 j0 U* H  PING 192.168.4.1: 56  data bytes, press CTRL_C to break7 U! B4 R; W. h! N+ o1 u% y
    Reply from 192.168.4.1: bytes=56 Sequence=1 ttl=255 time=20 ms
: x1 k" u4 G0 T7 h! R, h) l: R    Reply from 192.168.4.1: bytes=56 Sequence=2 ttl=255 time=10 ms
% e2 l( S2 g* G1 t' u    Reply from 192.168.4.1: bytes=56 Sequence=3 ttl=255 time=1 ms
' [: u0 F5 }, Z. k    Reply from 192.168.4.1: bytes=56 Sequence=4 ttl=255 time=30 ms
# s6 m$ C5 q5 V3 ^    Reply from 192.168.4.1: bytes=56 Sequence=5 ttl=255 time=1 ms- Z4 ~8 v; B5 G, y2 M* r3 x" s
  --- 192.168.4.1 ping statistics ---
& ^: S. q& `; J# u6 B9 Q: r% g    5 packet(s) transmitted
9 L3 I5 M1 X' B- G6 V& T    5 packet(s) received) G+ x) k, K3 c( a4 [. A
    0.00% packet loss+ w. @" E+ m- z) ?% D
    round-trip min/avg/max = 1/12/30 ms
  ~4 a: F- [" M+ m" A  [[Huawei]interface eth 0/0/1
2 F+ O! l( x2 P7 }8 ]+ a* V1 P* s* \% n
[Huawei-Ethernet0/0/1]port hybrid untagged vlan 100 4
2 ?/ r# z4 i! L3 @5 j. ^( s8 D) X[Huawei-Ethernet0/0/1]port hybrid pvid vlan 4% U8 k' Z' P0 d% w' S' }
[Huawei-Ethernet0/0/1]q
1 F- J* e3 }$ x$ p
& Z4 q8 s: a) p* j% J
好了,交换机和路由器的设置就完成了,把两个PC客户端配置好IP地址就可以试试效果了,但由于是模拟器的原因,在长间没有使用时,有时候会有ping不通的情况,在我这里两个都能ping通外网,vlan2和vlan4之间也能互通.在真实的设备上我们可以启用web界面和telnet,然后通过1.1.1.1,1.1.1.2,1.1.1.3这些地址来访问和管理路由器和交换机了,端口隔离,mac黑洞之类的配置可以在web界面上操作,谁让咱会的太少了.下面是前两个例子的地址,从简到稍难
+ C8 _  E5 \5 Z- C
 楼主| 发表于 2022-3-23 15:00:02 | 显示全部楼层
首先配置AR2220,设置GE0接口IP为固定外网地址,设置GE1接口IP为1.1.1.1,然后做两条静态路由,创建vlan 100,红色文本是需要特别多看几眼的,代码如下:

[Huawei]vlan 100

( T. U3 ^; L7 g4 w% U
[Huawei-vlan100]q
% r0 X" i" e0 @6 c; z
[Huawei]acl number 2000

( a# Y2 j8 x3 V5 Q
[Huawei-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255

7 q" G3 M* Z2 q. J* L9 A! B5 q
[Huawei-acl-basic-2000]q
, a$ {2 a) D' ?: ~* o, h
[Huawei]interface giga 0/0/0

( ~/ h- Z. d3 O) O) i/ b8 _
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.3 255.255.255.0
0 m% _$ W5 I/ Q' d# H: ^6 M
[Huawei-GigabitEthernet0/0/0]

  e* E) H* O' r/ b
Mar 13 2014 07:34:12-05:13 Huawei %IFNET/4/LINK_STATE(l)[1]:The line protocol

: H$ a1 p) M. e. A3 ]
IP on the interface GigabitEthernet0/0/0 has entered the UP state.

6 l1 w, ]! L' u5 e! ~% h8 R/ o6 _
[Huawei-GigabitEthernet0/0/0]q
6 `' j0 m0 |, q; Y+ T) V2 W2 G
[Huawei]interface giga 0/0/1
1 l! [2 _& ~) ^, D+ M0 Z
[Huawei-GigabitEthernet0/0/1]ip address 1.1.1.1 255.255.255.0

! \. m0 K3 I4 ?. `8 @/ F9 H1 L9 Q
[Huawei-GigabitEthernet0/0/1]q
: h  E0 I3 U5 t  m7 t! k
[Huawei]ip route-static 0.0.0.0 0.0.0.0 192.168.1.1

  R  z, ^9 N+ y! P7 j$ X+ X( S
[Huawei]ip route-static 192.168.0.0 255.255.0.0 1.1.1.2

2 ^  b5 W- \" u4 E) G
[Huawei]q

/ t3 p" V1 b6 O! d3 v1 T, k
save
+ I( o& h7 S" t( g' B5 M- h$ d
  The current configuration will be written to the device.

2 M/ u! Z4 ~# x5 }6 @; w  W' R
  Are you sure to continue? (y/n)[n]:y

2 Z* y2 H, V; T: T
  It will take several minutes to save configuration file, please wait..........

6 z# i- Q. I0 h$ T& m' g3 ~3 P: ]8 o5 H+ O; `* v

3 O4 K7 c, w4 ~3 q6 a
  Configuration file had been saved successfully
& N8 o0 \( R  B9 m3 o
  Note: The configuration file will take effect after being activated

: L: t. C5 w; s. [' U
9 K: x. Y, J& s' Z, p  Z
Mar 13 2014 07:37:25-05:13 Huawei ARP/4/ARP_IPCONFLICT_TRAP:OID 16777216.50331648

1 q$ j) \5 n# x& E: P  x
.100663296.16777216.67108864.16777216.3674669056.83886080.419430400.2063597568.33
3 x5 d2 l; s. g' J5 j/ l
554432.100663296 ARP detects IP conflict. (IP address=201.1.168.192, Local interf
+ D( A8 l* }! K' N+ P* M+ i. m# N
ace=GigabitEthernet0/0/0, Local MAC=4437-e68c-b212, Local vlan=0, Local CE vlan=0
6 f# G" L. }0 V7 o4 o7 p. ]. d
, Receive interface=GigabitEthernet0/0/0, Receive MAC=1c1a-c00f-253f, Receive vla
. o* B9 l( H: }2 @* e9 i$ f
n=0, Receive CE vlan=0, IP conflict type=Remote IP conflict).
% k) X. x3 N( d, X

. p7 n6 z. ]2 i7 I+ Z' l
8 i; M3 a) M) e- u; K# D8 |

接下来配置S5700交换机,GE1接口IP为1.1.1.2,属于vlan100,GE2接口属于vlan1,GE3接口属于vlan2,代码如下

[Huawei]vlan batch 2 4 6 8 100
Info: This operation may take a few seconds. Please wait for a moment...done.
, i$ m2 T( |* @
[Huawei]

2 j# f  I$ e1 X: g3 B
Mar 13 2014 10:38:34-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.
) n$ a! V# E! g* j7 ~! _
25.191.3.1 configurations have been changed. The current change number is 4, the
, G* T; V8 S" h  @) H1 T
change loop count is 0, and the maximum number of records is 4095.
# Z7 c% U4 Q  k- v. ^
[Huawei]interface vlanif 100

: W3 U! U# z/ N2 U& ^* L
[Huawei-Vlanif100]ip address 1.1.1.2 255.255.255.0

9 A% p; a4 A; R3 A$ q2 n+ }9 o- r
[Huawei-Vlanif100]
3 d3 o% P% g# |
Mar 13 2014 10:40:14-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.

% y$ H$ Z3 s) v% O( H# T
25.191.3.1 configurations have been changed. The current change number is 6, the
& H7 j8 ]6 |; E$ O* I% G
change loop count is 0, and the maximum number of records is 4095.
! s, }6 M7 ]  _% }1 l* f: G
[Huawei-Vlanif100]q
/ t8 X% @) ?6 f4 T
[Huawei]interface giga 0/0/1

$ _; L1 I5 G  {% w4 G  ]
[Huawei-GigabitEthernet0/0/1]port link-type access

/ F7 x# s0 c7 g) N
[Huawei-GigabitEthernet0/0/1]port default vlan 100

3 ^4 M7 t7 I; Q$ q) R4 b0 E
[Huawei-GigabitEthernet0/0/1]q
5 V% d& q1 H4 V" Y  M
[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.1

  x3 w+ v0 p' o# E
[Huawei]
& E4 F% A% B! ]+ j4 v9 K7 b$ F
Mar 13 2014 10:43:24-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5.
7 m% _- n0 J1 P+ `
25.191.3.1 configurations have been changed. The current change number is 9, the

7 @, |* X  M/ }+ c; F5 j
change loop count is 0, and the maximum number of records is 4095.
0 ?! w" M4 R" P9 v: [3 p. O
[Huawei]interface vlanif 1

  w1 b6 {  \% b; Y1 Z# ~: r% }! {5 P
[Huawei-Vlanif1]ip address 192.168.0.1 255.255.255.0

* y( s+ L; A/ v" O
[Huawei-Vlanif1]q
- W& ~- ~* n& S2 I- o% r% H$ ~, Q
[Huawei]interface vlanif 2
- i6 _# N5 i$ w
[Huawei-Vlanif2]ip address 192.168.2.1 255.255.255.0

: s" j0 j+ l0 S% w
[Huawei-Vlanif2]q
/ D5 U  _. u% A* v7 j( X$ Q4 g
[Huawei]interface giga 0/0/3

: f; G& A$ T' O+ y8 J( T
[Huawei-GigabitEthernet0/0/3]port link-type access
% ?: p- M. p/ E
[Huawei-GigabitEthernet0/0/3]port default vlan 2
3 U$ S, w6 V4 G- ~( {2 i! \0 N7 a6 D7 ^
[Huawei-GigabitEthernet0/0/3]
+ L/ I5 a; D6 R$ x: o+ u6 P4 I: l* M- X
[Huawei]q

4 {$ I" f- g/ L/ {" F1 u- x
save

6 f  j7 R; v+ h/ M3 V
The current configuration will be written to the device.
2 X' a5 V1 z" F. B0 q
Are you sure to continue?[Y/N]y
+ V9 p/ G6 b; E: r- L8 s
Now saving the current configuration to the slot 0.

$ Y6 z5 P- G7 l
Mar 13 2014 11:02:44-08:00 Huawei %CFM/4/SAVE(l)[11]:The user chose Y when dec

, d  Z. Q4 _5 W5 W6 r
iding whether to save the configuration to the device.

4 ^& b8 m1 K  @/ i  h, [4 r& Y3 R
Save the configuration successfully.

9 a" G- \) p7 Q6 ?  c: b
+ p' A. H# u: W4 u% M' Y2 h$ |
然后设置PC1和PC2的IP地址,先ping 1.1.1.1,如果没有问题再ping 192.168.1.3,192.168.1.111,202.99.192.66,一路ping下来是不是感觉有点小成就感,如果PC2无法ping通,那么就像昨天一样,在自己的真实路由器上做个静态路由指向192.168.2.0便可以了.需要的可以下载附件导出配置文件看.

) b' ~" n" Z/ ?, U; [" V1 W' H% D9 g0 q+ `& D% Q4 p- v
) F( P& U& R& c
您需要登录后才可以回帖 登录 | 开始注册

本版积分规则

关闭

站长推荐上一条 /4 下一条

北京云银创陇科技有限公司以云计算运维,代码开发

QQ|返回首页|Archiver|小黑屋|易陆发现技术论坛 ( 蜀ICP备2026014127号-1 )点击这里给我发消息

GMT+8, 2026-4-8 21:41 , Processed in 0.052870 second(s), 21 queries .

Powered by Discuz! X3.4 Licensed

© 2012-2025 Discuz! Team.

快速回复 返回顶部 返回列表