拓撲
配置
配置底層資訊:
AR1
[Huawei]sysname AR1 //修改主機名稱# 介面互通配置[AR1]int GigabitEthernet 0/0/0[AR1-GigabitEthernet0/0/0]ip address 10。1。12。1 24[AR1]int GigabitEthernet 0/0/1[AR1-GigabitEthernet0/0/1]ip address 10。1。13。1 24#當作外部通訊地址[AR1]interface LoopBack 0[AR1-LoopBack0]ip address 1。1。1。1 32
AR2
[Huawei]sysname AR2 //修改主機名#配置互聯地址[AR2]int GigabitEthernet 0/0/0 [AR2-GigabitEthernet0/0/0]ip address 10。1。12。2 24#配置主機閘道器地址[AR2]int GigabitEthernet 0/0/1[AR2-GigabitEthernet0/0/1]ip address 192。168。1。2 24
AR3
[Huawei]sysname AR3 //修改主機名//配置介面互聯地址[AR3]int GigabitEthernet 0/0/[AR3-GigabitEthernet0/0/0]ip address 10。1。13。3 24//配置閘道器地址[AR3]int GigabitEthernet 0/0/1[AR3-GigabitEthernet0/0/1]ip address 192。168。1。3 24
配置Easy ip:
AR2:
#寫一條Acl將需要NAT的地址抓出來[AR2]acl 2000[AR2-acl-basic-2000]rule 1 permit source 192。168。1。0 0。0。0。255#將NAT掛接到介面上[AR2]int GigabitEthernet 0/0/0[AR2-GigabitEthernet0/0/0]nat outbound 2000#寫一條通往出口路由的路由[AR2]ip route-static 0。0。0。0 0。0。0。0 10。1。12。1
AR3:
#配置同上[AR3]access-user[AR3]acl 2000[AR3-acl-basic-2000]rule 1 permit source 192。168。1。0 0。0。0。255[AR3]int GigabitEthernet 0/0/0[AR3-GigabitEthernet0/0/0]nat outbound 2000[AR3]ip route-static 0。0。0。0 0。0。0。0 10。1。13。1
搭建DHCP伺服器:
AR2:
[AR2]ip pool pc1 //建立全域性地址池[AR2-ip-pool-pc1]network 192。168。1。0 mask 24 //建立地址池範圍[AR2-ip-pool-pc1]gateway-list 192。168。1。2 192。168。1。3 //配置DHCP閘道器[AR2-ip-pool-pc1]lease day 0 hour 3 minute 30 //配置租期[AR2-ip-pool-pc1]dns-list 114。114。114。114 //配置DNS[AR2-ip-pool-pc1]excluded-ip-address 192。168。1。1 //排除地址//靜態繫結某個主機拿到固定地址[AR2-ip-pool-pc1]static-bind ip-address 192。168。1。100 mac-address 5489-98B9-1067 [AR2]dhcp enable //開啟DHCP服務[AR2]interface GigabitEthernet 0/0/1[AR2-GigabitEthernet0/0/1]dhcp select global //介面上應用全域性地址池
AR3
#AR3同理AR2[AR3]dhcp enable [AR3]ip pool pc2Info: It‘s successful to create an IP address pool。[AR3-ip-pool-pc2]network 192。168。1。0 mask 24[AR3-ip-pool-pc2]gateway-list 192。168。1。3[AR3-ip-pool-pc2]dns-list 114。114。114。114[AR3-ip-pool-pc2]lease day 0 hour 3 minute 30[AR3-ip-pool-pc2]int g0/0/0[AR3-GigabitEthernet0/0/0]dhcp select global
配置VRRP:
AR2:
[AR2]int GigabitEthernet 0/0/1//配置備份組和虛擬閘道器地址[AR2-GigabitEthernet0/0/1]vrrp vrid 1 virtual-ip 192。168。1。1 //配置優先順序,預設100[AR2-GigabitEthernet0/0/1]vrrp vrid 1 priority 150//配置搶佔延遲時間為20S[AR2-GigabitEthernet0/0/1]vrrp vrid 1 preempt-mode timer delay 20//檢測上行鏈路故障時,優先順序減少30[AR2-GigabitEthernet0/0/1]vrrp vrid 1 track interface GigabitEthernet 0/0/0 reduced 30
AR3:
//配置與AR2同理[AR3]int GigabitEthernet 0/0/1[AR3-GigabitEthernet0/0/1]vrrp vrid 1 virtual-ip 192。168。1。1[AR3-GigabitEthernet0/0/1]vrrp vrid 1 preempt-mode timer delay 20[AR3-GigabitEthernet0/0/1]vrrp vrid 1 track interface GigabitEthernet 0/0/0 reduced 30
鏈路聚合配置:
LSW1:
#使得VLAN可以透過交換機上去[LSW1]int GigabitEthernet 0/0/1[LSW1-GigabitEthernet0/0/1]port trunk allow-pass vlan all interface Eth-Trunk1 //建立埠聚合組mode lacp-static //配置聚合模式為LACPleast active-linknumber 4 //聚合成員最低閥值數量4,低於4個活動成員此介面會自動down(預設情況閥值數量為1) //將埠加入聚合組[LSW1-Eth-Trunk1]trunkport GigabitEthernet 0/0/3[LSW1-Eth-Trunk1]trunkport GigabitEthernet 0/0/4 #配置trunk[LSW1-Eth-Trunk1]port link-type trunk [LSW1-Eth-Trunk1]port trunk allow-pass vlan all
LSW2:
#配置和LSW1類似[LSW2]int GigabitEthernet 0/0/1[LSW2-GigabitEthernet0/0/1]port link-type trunk [LSW2-GigabitEthernet0/0/1]port trunk allow-pass vlan all [LSW2]int Eth-Trunk 1[LSW2-Eth-Trunk1]mode lacp-static [LSW2-Eth-Trunk1]least active-linknumber 4[LSW2-Eth-Trunk1]trunkport GigabitEthernet 0/0/3[LSW2-Eth-Trunk1]trunkport GigabitEthernet 0/0/4[LSW2-Eth-Trunk1]port link-type trunk [LSW2-Eth-Trunk1]port trunk allow-pass vlan all
配置驗證:
PC1:
其他一些功能性的測試,大家可以做下!!!