1、第8章案例一故障配置V238.1.1 参考配置错误配置正确配置#sysname RT1#router id 10.10.10.1#ip unreachables enable#ip ttl-expires enable#acl number 3001 rule 0 permit ip source 69.1.1.1 0 destination 69.1.1.2 0#ike peer 123 pre-shared-key simple 123 remote-address 69.1.1.1#ipsec proposal 1#ipsec policy 1 1 isakmp security acl
2、 3001 ike-peer 123 proposal 1#interface Ethernet5/0 port link-mode route ospf authentication-mode md5 1 plain h3c ip address 10.2.1.9 255.255.255.252#interface Ethernet5/1 port link-mode routeospf authentication-mode md5 1 plain h3c ip address 69.1.1.1 255.255.255.252#interface LoopBack0 ip address
3、10.10.10.1 255.255.255.255#interface GigabitEthernet0/0 port link-mode route ip address 10.1.1.9 255.255.255.252#interface GigabitEthernet0/1 port link-mode route ospf authentication-mode md5 1 plain h3c ip address 10.2.1.1 255.255.255.252#interface Tunnel0 ip address 10.2.1.13 255.255.255.252 sourc
4、e 69.1.1.1 destination 69.1.1.2 keepalive 10 3 ipsec policy 1#bgp 65131 router-id 10.10.10.1 import-route ospf 10 undo synchronization group in internalpeer in connect-interface LoopBack0 peer 10.10.10.3 group in peer 10.10.10.4 group in peer 10.10.10.2 group in#ospf 1 area 0.0.0.0 authentication-mo
5、de md5 network 10.2.1.0 0.0.0.3 network 10.2.1.8 0.0.0.3 network 10.2.1.12 0.0.0.3 network 10.10.10.1 0.0.0.0#ospf 10 area 0.0.0.0 network 10.1.1.8 0.0.0.3# sysname RT2#router id 10.10.10.2#ip unreachables enable#ip ttl-expires enable#acl number 2001 rule 0 permit source 192.1.0.0 0.0.255.255 rule 5
6、 permit source 172.1.1.0 0.0.0.255#local-user rt2 password simple h3c service-type ppp#interface Ethernet5/0 port link-mode route ip address 10.3.1.6 255.255.255.252#interface Serial6/0 link-protocol ppp ppp authentication-mode chap ppp chap user rt2ppp mp Mp-group 0#interface Serial6/1 link-protoco
7、l ppp ppp authentication-mode chap ppp chap user rt2ppp mp Mp-group 0#interface Mp-group0 ip address 10.2.1.5 255.255.255.252ospf authentication-mode md5 1 plain h3c#interface LoopBack0 ip address 10.10.10.2 255.255.255.255#interface GigabitEthernet0/0 port link-mode route ip address 10.1.1.5 255.25
8、5.255.252#interface GigabitEthernet0/1 port link-mode route ip address 10.2.1.2 255.255.255.252 ospf authentication-mode md5 1 plain h3c#bgp 65131 router-id 10.10.10.2 import-route ospf 10 undo synchronization peer 10.3.1.5 as-number 65132 peer 10.3.1.5 route-policy 1 export group in internal peer i
9、n next-hop-localpeer in connect-interface LoopBack0 peer 10.10.10.3 group in peer 10.10.10.1 group in#ospf 1 area 0.0.0.0 authentication-mode md5 network 10.2.1.0 0.0.0.3 network 10.10.10.2 0.0.0.0 network 10.2.1.4 0.0.0.3#ospf 10 area 0.0.0.0 network 10.1.1.4 0.0.0.3#route-policy 1 permit node 10 i
10、f-match acl 2001# sysname RT3#router id 10.10.10.3#ip unreachables enable#ip ttl-expires enable#local-user rt3 password simple h3c service-type ppp#interface Serial6/0 link-protocol ppp ppp chap user rt3 ppp mp Mp-group 0#interface Serial6/1 link-protocol ppp ppp chap user rt3ppp mp Mp-group 0#inter
11、face Mp-group0 ip address 10.2.1.6 255.255.255.252ospf authentication-mode md5 1 plain h3c#interface LoopBack0 ip address 10.10.10.3 255.255.255.255#interface LoopBack10 ip address 172.1.2.254 255.255.255.255#interface LoopBack20 ip address 192.1.2.254 255.255.255.255#interface GigabitEthernet0/0 po
12、rt link-mode route ip address 10.2.1.10 255.255.255.252 ospf authentication-mode md5 1 plain h3c#bgp 65131 network 172.1.2.254 255.255.255.255 network 192.1.2.254 255.255.255.255 undo synchronization group in internal peer in connect-interface LoopBack0 peer 10.10.10.1 group in peer 10.10.10.2 group
13、 in peer 10.10.10.2 route-policy 10 import#ospf 1 area 0.0.0.0 authentication-mode md5 network 10.10.10.3 0.0.0.0 network 10.2.1.4 0.0.0.0 network 10.2.1.8 0.0.0.0#route-policy 10 permit node 10 if-match ip-prefix 10 apply local-preference 200# ip ip-prefix 10 index 10 permit 192.1.1.0 24#sysname RT
14、4# router id 10.10.10.4# ip unreachables enable#ip ttl-expires enable#acl number 3001 rule 0 permit ip source 69.1.1.2 0 destination 69.1.1.1 0#ike peer 123 pre-shared-key simple 123 remote-address 69.1.1.1 local-address 69.1.1.2#ipsec proposal 1#ipsec policy 1 1 isakmp security acl 3001 ike-peer 12
15、3 proposal 1#interface LoopBack0 ip address 10.10.10.4 255.255.255.255#interface LoopBack10 ip address 172.1.3.254 255.255.255.255#interface LoopBack20 ip address 192.1.3.254 255.255.255.255#interface GigabitEthernet0/0 port link-mode routeospf authentication-mode md5 1 plain h3c ip address 69.1.1.2
16、 255.255.255.252 #interface Tunnel0 ip address 10.2.1.14 255.255.255.252 source 69.1.1.2 destination 69.1.1.1 keepalive 10 3ipsec policy 1#bgp 65131 router-id 10.10.10.1network 172.1.3.254 255.255.255.255 network 192.1.3.254 255.255.255.255 undo synchronization group in internal peer in connect-inte
17、rface LoopBack0 peer 10.10.10.1 group in#ospf 1 area 0.0.0.0 network 10.10.10.4 0.0.0.0 network 10.2.1.12 0.0.0.3# # sysname RT5 # super password level 3 simple h3c# telnet server enable # ip unreachables enable #ip ttl-expires enable# interface LoopBack0 ip address 20.20.20.1 255.255.255.255 #inter
18、face LoopBack10 ip address 172.2.1.254 255.255.255.255 # interface LoopBack20 ip address 192.2.1.254 255.255.255.255# interface GigabitEthernet0/0 port link-mode route ip address 10.3.1.1 255.255.255.252# interface GigabitEthernet0/1 port link-mode route ip address 10.3.1.5 255.255.255.252# bgp 6513
19、2 router-id 20.20.20.1 network 172.2.1.254 255.255.255.255 network 192.2.1.254 255.255.255.255 undo synchronization peer 10.3.1.2 as-number 65131 peer 10.3.1.6 as-number 65131 # # sysname SW1# ip unreachables enable#vlan 1#vlan 10#vlan 101 to 102#stp enablestp region-configuration instance 1 vlan 10
20、1 instance 2 vlan 102 active region-configuration#interface Vlan-interface10 ip address 10.1.1.10 255.255.255.252#interface Vlan-interface101 ip address 172.1.1.1 255.255.255.0 vrrp vrid 1 virtual-ip 172.1.1.254#interface Vlan-interface102 ip address 192.1.1.1 255.255.255.0 vrrp vrid 2 virtual-ip 19
21、2.1.1.254#interface Ethernet1/0/1 port link-mode bridge port access vlan 10#interface Ethernet1/0/2 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102#interface Ethernet1/0/24 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102#ospf 10 area 0.0.
22、0.0 network 10.1.1.8 0.0.0.3 network 172.1.1.0 0.0.0.255 network 192.1.1.0 0.0.0.255#sysname SW2#ip unreachables enable#acl number 3000 rule 0 permit ip source 172.2.0.0 0.0.255.255#vlan 1#vlan 10#vlan 20#vlan 101 to 102#stp enablestp region-configuration instance 1 vlan 101 instance 2 vlan 102 acti
23、ve region-configuration#interface Vlan-interface10 ip address 10.1.1.6 255.255.255.252#interface Vlan-interface20 ip address 10.3.1.2 255.255.255.252#interface Vlan-interface101 ip address 172.1.1.1 255.255.255.0 vrrp vrid 1 virtual-ip 172.1.1.254 #interface Vlan-interface102 ip address 192.1.1.2 25
24、5.255.255.0 vrrp vrid 2 virtual-ip 192.1.1.254 #interface Ethernet1/0/1 port link-mode bridge port access vlan 10#interface Ethernet1/0/2 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102#interface Ethernet1/0/3 port link-mode bridge port access vlan 20#interface Etherne
25、t1/0/24 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102#bgp 65131 network 172.1.1.0 255.255.255.0 undo synchronization peer 10.3.1.1 as-number 65132#ospf 10 area 0.0.0.0 network 10.1.1.4 0.0.0.3 network 172.1.1.0 0.0.0.255 network 192.1.1.0 0.0.0.255#route-policy 1 per
26、mit node 10 if-match acl 3000#sysname SW3#vlan 1#vlan 101 to 102#stp enable stp region-configuration instance 1 vlan 101 instance 2 vlan 102 active region-configuration#interface Vlan-interface101 ip address 172.1.1.100 255.255.255.0#interface Vlan-interface102 ip address 192.1.1.100 255.255.255.0#i
27、nterface Ethernet1/0/1 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102#interface Ethernet1/0/2 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102#interface Ethernet1/0/11 port link-mode bridge port access vlan 101#interface Ethernet1/0/12 po
28、rt link-mode bridge port access vlan 102#ip route-static 172.0.0.0 255.0.0.0 172.1.1.254 ip route-static 192.0.0.0 255.0.0.0 192.1.1.254# sysname RT1#router id 10.10.10.1#ip unreachables enable#ip ttl-expires enable#acl number 3001 rule 0 permit ip source 69.1.1.1 0 destination 69.1.1.2 0#ike peer 1
29、23 pre-shared-key simple 123 remote-address 69.1.1.2 local-address 69.1.1.1#ipsec proposal 1#ipsec policy 1 1 isakmp security acl 3001 ike-peer 123 proposal 1#interface Ethernet5/0 port link-mode routeospf authentication-mode md5 1 plain h3c ip address 10.2.1.9 255.255.255.252#interface Ethernet5/1 port link-mode route ip address 69.1.1.1 255.255.255.252 ipsec policy 1#interface LoopBack0 ip address 10.10.10.1 255.255.255.255#interface GigabitEthernet0/0 port link-mode rout
copyright@ 2008-2022 冰豆网网站版权所有
经营许可证编号:鄂ICP备2022015515号-1