1、!version 12.4service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryptionhostname CEboot-start-markerboot-end-markerno aaa new-modelmemory-size iomem 5ip cefno ip domain lookupip sla monitor 1 type echo protocol ipIcmpEcho 172.16.2.1 source-interface FastE
2、thernet0/0ip sla monitor schedule 1 life forever start-time nowip sla monitor 2 type echo protocol ipIcmpEcho 172.31.2.1 source-interface FastEthernet2/0ip sla monitor schedule 2 life forever start-time nowtrack 1 rtr 1 reachability #将track与ip sla 关联起来,track根据ip sla的返回代码来断定链路UP/DOWNtrack 2 rtr 2 rea
3、chabilityinterface Loopback0 ip address 1.1.1.1 255.255.255.255 ip load-sharing per-packet ip nat inside ip virtual-reassembly no ip route-cache cef no ip route-cacheinterface FastEthernet0/0 description isp1 ip address 172.16.1.1 255.255.255.0 ip nat outside duplex auto speed autointerface Serial1/
4、0 no ip address shutdown serial restart-delay 0interface Serial1/1interface Serial1/2interface Serial1/3interface FastEthernet2/0 description isp2 ip address 172.31.1.1 255.255.255.0ip http serverno ip http secure-serverip route 0.0.0.0 0.0.0.0 FastEthernet0/0 172.16.1.2 track 1 #根据track reachabilit
5、y状态UP/DOWN默认路由ip route 0.0.0.0 0.0.0.0 FastEthernet2/0 172.31.1.2 track 2ip route 172.16.2.1 255.255.255.255 FastEthernet0/0 #首先解决IP SLA 检测目标的路由,而后默认路由才能UPip route 172.31.2.1 255.255.255.255 FastEthernet2/0ip nat inside source route-map isp1 interface FastEthernet0/0 overloadip nat inside source rou
6、te-map isp2 interface FastEthernet2/0 overload #通过使用route map来匹配数据包的路由出接口access-list 1 permit 1.1.1.1access-list 100 permit ip host 1.1.1.1 host 3.3.3.3 # 此ACL仅用于debug调试route-map isp2 permit 10 match ip address 1 match interface FastEthernet2/0route-map isp1 permit 10 match interface FastEthernet0/0
7、control-planeline con 0 logging synchronousline aux 0line vty 0 4 loginEndISP1 configurationISP1#sh run 955 byteshostname ISP1resource policy ip address 172.16.1.2 255.255.255.0 duplex half ip address 172.16.2.2 255.255.255.0ip route 3.3.3.3 255.255.255.255 Serial1/1no ip http serverlogging alarm in
8、formational stopbits 1ISP2 configurationISP2#sh runhostname ISP2 ip address 172.31.2.2 255.255.255.0 ip address 172.31.1.2 255.255.255.0ip route 3.3.3.3 255.255.255.255 Serial1/0Internet-server configurationInternet-server#sh run 1065 byteshostname Internet-server ip address 3.3.3.3 255.255.255.255
9、ip address 172.16.2.1 255.255.255.0 ip address 172.31.2.1 255.255.255.0ip route 172.16.0.0 255.255.0.0 Serial1/0ip route 172.31.0.0 255.255.0.0 Serial1/1Show信息Debug测试走F2/0的包,源IP被NAT成ISP2接口IP走F0/0的包,源IP被NAT成ISP1接口IPShutdown internet-server路由器的S1/0接口,测试IP SLA由于IP SLA monitor 1 检测目标ping不同,ISP1的默认路由DOWN掉,只剩下ISP2的默认路由IP SLA monitor 1 return code为timeout,track 1 reachability为down,因此ISP1默认路由DOWN掉
copyright@ 2008-2022 冰豆网网站版权所有
经营许可证编号:鄂ICP备2022015515号-1