华为策略路由配置实例Word格式.docx
《华为策略路由配置实例Word格式.docx》由会员分享,可在线阅读,更多相关《华为策略路由配置实例Word格式.docx(7页珍藏版)》请在冰豆网上搜索。
4、配置流行为,使满足不同规则的报文分别被重定向到10.1.20.1/24和10.1.30.1/24。
5、配置流策略,绑定上述流分类和流行为,并应用到接口GE2/0/1的入方向上,实现策略路由。
3、操作步骤
3.1、创建VLAN并配置各接口
#
在Switch上创建VLAN100和VLAN200。
<
HUAWEI>
system-view
[HUAWEI]
sysnameSwitch
[Switch]
vlanbatch100200
配置Switch上接口GE1/0/1、GE1/0/2和GE2/0/1的接口类型为Trunk,并加入VLAN100和VLAN200。
interfacegigabitethernet1/0/1
[Switch-GigabitEthernet1/0/1]
portlink-typetrunk
porttrunkallow-passvlan100200
quit
interfacegigabitethernet1/0/2
[Switch-GigabitEthernet1/0/2]
interfacegigabitethernet2/0/1
[Switch-GigabitEthernet2/0/1]
配置LSW与Switch对接的接口为Trunk类型接口,并加入VLAN100和VLAN200。
创建VLANIF100和VLANIF200,并配置各虚拟接口IP地址。
interfacevlanif100
[Switch-Vlanif100]
ipaddress10.1.20.224
interfacevlanif200
[Switch-Vlanif200]
ipaddress10.1.30.224
3.2、配置ACL规则
在Switch上创建编码为3001、3002的高级ACL,规则分别为允许IP优先级0、1、2、3和允许IP优先级4、5、6、7的报文通过。
acl3001
[Switch-acl-adv-3001]
rulepermitipprecedence0
rulepermitipprecedence1
rulepermitipprecedence2
rulepermitipprecedence3
acl3002
[Switch-acl-adv-3002]
rulepermitipprecedence4
rulepermitipprecedence5
rulepermitipprecedence6
rulepermitipprecedence7
3.3、配置流分类
在Switch上创建流分类c1、c2,匹配规则分别为ACL3001和ACL3002。
trafficclassifierc1operatorand
[Switch-classifier-c1]
if-matchacl3001
trafficclassifierc2operatorand
[Switch-classifier-c2]
if-matchacl3002
3.4、配置流行为
在Switch上创建流行为b1、b2,并分别指定重定向到网段10.1.20.1/24和10.1.30.1/24的动作。
trafficbehaviorb1
[Switch-behavior-b1]
redirectip-nexthop10.1.20.1
trafficbehaviorb2
[Switch-behavior-b2]
redirectip-nexthop10.1.30.1
3.5、配置流策略并应用到接口上
在Switch上创建流策略p1,将流分类和对应的流行为进行绑定。
trafficpolicyp1
[Switch-trafficpolicy-p1]
classifierc1behaviorb1
classifierc2behaviorb2
将流策略p1应用到接口GE2/0/1的入方向上。
traffic-policyp1inbound
return
3.6、验证配置结果
查看ACL规则的配置信息。
Switch>
displayacl3001
AdvancedACL3001,4rules
Acl'
sstepis5
rule5permitipprecedenceroutine(match-counter0)
rule10permitipprecedencepriority(match-counter0)
rule15permitipprecedenceimmediate(match-counter0)
rule20permitipprecedenceflash(match-counter0)
displayacl3002
AdvancedACL3002,4rules
rule5permitipprecedenceflash-override(match-counter0)
rule10permitipprecedencecritical(match-counter0)
rule15permitipprecedenceinternet(match-counter0)
rule20permitipprecedencenetwork(match-counter0)
查看流分类的配置信息。
displaytrafficclassifieruser-defined
UserDefinedClassifierInformation:
Classifier:
c1
Precedence:
5
Operator:
AND
Rule(s):
c2
10
Totalclassifiernumberis2
查看流策略的配置信息。
displaytrafficpolicyuser-definedp1
UserDefinedTrafficPolicyInformation:
Policy:
p1
Behavior:
b1
Redirect:
noforced
Redirectip-nexthop
10.1.20.1
b2
10.1.30.1
4、配置文件
Switch的配置文件
#
aclnumber3001
rule5permitipprecedenceroutine
rule10permitipprecedencepriority
rule15permitipprecedenceimmediate
rule20permitipprecedenceflash
aclnumber3002
rule5permitipprecedenceflash-override
rule10permitipprecedencecritical
rule15permitipprecedenceinternet
rule20permitipprecedencenetwork
trafficclassifierc1operatorandprecedence5
trafficclassifierc2operatorandprecedence10
trafficpolicyp1match-orderconfig
interfaceVlanif100
ipaddress10.1.20.2255.255.255.0
interfaceVlanif200
ipaddress10.1.30.2255.255.255.0
interfaceGigabitEthernet1/0/1
interfaceGigabitEthernet1/0/2
interfaceGigabitEthernet2/0/1