S5120-28P交换机GE 1/0/24连接MSR2600GE0/4接口,交换机的配置如下
interface gigabitethernet 1/0/24
port link-type trunk
port trunk permit vlan 1 3 4
vlan 3
port gigabitethernet 1/0/1 to gigabitethernet 1/0/12
vlan 4
port gigabitethernet 1/0/13 to gigabitethernet 1/0/23
交换机上未配置其它。
现在PC1连接S5120 GE1/0/1口,可以正确获取IP并走路由器的dialer12上网,但如果将路由器的GE0/2关闭,也就是断开了这条外网,PC1就上不了网了。也就是说路由器下所有网段都只能走策略路由上网,并没有实现各外网线路的备份,还要在路由器上做什么样的配置,才能实现各外网线路互为备份呢?
MSR2600的配置如下:
#
version 5.20, Release 2516P17
#
sysname H3C
#
clock timezone UTC add 08:00:00
#
domain default enable system
#
dns proxy enable
#
telnet server enable
#
dar p2p signature-file flash:/p2p_default.mtd
#
ndp enable
#
ntdp enable
#
qos carl 1 destination-ip-address range 192.168.2.2 to 192.168.2.254 per-address shared-bandwidth
qos carl 2 source-ip-address range 192.168.2.2 to 192.168.2.254 per-address shared-bandwidth
qos carl 3 destination-ip-address range 192.168.4.2 to 192.168.4.254 per-address shared-bandwidth
qos carl 4 source-ip-address range 192.168.4.2 to 192.168.4.254 per-address shared-bandwidth
qos carl 5 destination-ip-address range 192.168.8.2 to 192.168.8.254 per-address shared-bandwidth
qos carl 6 source-ip-address range 192.168.8.2 to 192.168.8.254 per-address shared-bandwidth
qos carl 7 destination-ip-address range 192.168.16.2 to 192.168.16.254 per-address shared-bandwidth
qos carl 8 source-ip-address range 192.168.16.2 to 192.168.16.254 per-address shared-bandwidth
#
cluster enable
#
port-security enable
#
password-recovery enable
#
acl number 3003
rule 0 permit ip source 192.168.2.0 0.0.0.255
acl number 3004
rule 0 permit ip source 192.168.4.0 0.0.0.255
acl number 3008
rule 0 permit ip source 192.168.8.0 0.0.0.255
acl number 3016
rule 0 permit ip source 192.168.16.0 0.0.0.255
#
vlan 1
#
connection-limit policy 19
connection-limit default action permit
connection-limit default amount upper-limit 100 lower-limit 99
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
dhcp server ip-pool vlan1 extended
network ip range 192.168.1.2 192.168.1.254
network mask 255.255.255.0
forbidden-ip 192.168.1.23
gateway-list 192.168.1.1
dns-list 202.96.64.68 202.96.69.38
#
dhcp server ip-pool vlan16 extended
network ip range 192.168.16.2 192.168.16.200
network mask 255.255.255.0
gateway-list 192.168.16.1
dns-list 202.96.64.68
#
dhcp server ip-pool vlan3 extended
network ip range 192.168.2.2 192.168.2.200
network mask 255.255.255.0
gateway-list 192.168.2.1
dns-list 202.96.64.68 202.96.69.38
#
dhcp server ip-pool vlan4 extended
network ip range 192.168.4.2 192.168.4.200
network mask 255.255.255.0
gateway-list 192.168.4.1
dns-list 202.96.64.68 202.96.69.38
#
dhcp server ip-pool vlan8 extended
network ip range 192.168.8.2 192.168.8.200
network mask 255.255.255.0
gateway-list 192.168.8.1
dns-list 202.96.64.68 202.96.69.38
#
policy-based-route CNC permit node 1
if-match acl 3003
apply output-interface Dialer12
policy-based-route CNC permit node 2
if-match acl 3004
apply output-interface Dialer13
policy-based-route CNC permit node 3
if-match acl 3008
apply output-interface Dialer10
policy-based-route CNC permit node 4
if-match acl 3016
apply output-interface Dialer11
#
user-group system
group-attribute allow-guest
#
local-user admin
password cipher $c$3$Q58BrJ76zoVGiUYjcVsGhI3MCYwuXa8T5ljM
authorization-attribute level 3
service-type telnet
service-type web
local-user 1234
password cipher $c$3$P0Xhf1w1RsVmdWCHuzKH/J4yWpZJTs3ms+5K
authorization-attribute level 3
service-type telnet terminal
service-type web
#
cwmp
undo cwmp enable
#
interface Aux0
async mode flow
link-protocol ppp
#
interface Cellular0/0
async mode protocol
link-protocol ppp
tcp mss 1024
#
interface Dialer10
nat outbound
link-protocol ppp
ppp chap user 123456
ppp chap password cipher $c$3$NlCAvWpbfDmglf8j03pabnI2lAJUxvxXiw==
ppp pap local-user 123456 password cipher $c$3$nSdTGqySqfD2E0jvz6frOAWhI55ratg5dg==
ppp ipcp dns admit-any
ppp ipcp dns request
mtu 1492
ip address ppp-negotiate
tcp mss 1024
dialer user username
dialer-group 10
dialer bundle 10
qos car inbound carl 5 cir 90000 cbs 5625000 ebs 0 green pass red discard
qos car outbound carl 6 cir 9000 cbs 562500 ebs 0 green pass red discard
#
interface Dialer11
nat outbound
link-protocol ppp
ppp chap user 123456
ppp chap password cipher $c$3$GPrOJgGJv4pIIyFmolBjZ/ikLAoioA6QfA==
ppp pap local-user 123456 password cipher $c$3$hARSFmuvtkW7TSaRWqEBdc6GexkIABfHvg==
ppp ipcp dns admit-any
ppp ipcp dns request
mtu 1492
ip address ppp-negotiate
tcp mss 1024
dialer user username
dialer-group 11
dialer bundle 11
qos car inbound carl 7 cir 90000 cbs 5625000 ebs 0 green pass red discard
qos car outbound carl 8 cir 9000 cbs 562500 ebs 0 green pass red discard
#
interface Dialer12
nat outbound
link-protocol ppp
ppp chap user 123456
ppp chap password cipher $c$3$TjVs71oFIG1HhP0UNQ0SH8NY79kf+TSutg==
ppp pap local-user 123456 password cipher $c$3$y82JE/MyLo2TS51dTez8c/rLSjT2qbdLTQ==
ppp ipcp dns admit-any
ppp ipcp dns request
mtu 1492
ip address ppp-negotiate
tcp mss 1024
dialer user username
dialer-group 12
dialer bundle 12
qos car inbound carl 1 cir 90000 cbs 5625000 ebs 0 green pass red discard
qos car outbound carl 2 cir 9000 cbs 562500 ebs 0 green pass red discard
#
interface Dialer13
nat outbound
link-protocol ppp
ppp chap user123456
ppp chap password cipher $c$3$xM07Y/IjPmqfTm8Mfu9h/SPLH1kl/wy+rw==
ppp pap local-user 123456 password cipher $c$3$IGDeupY1bBbIQvOd4JuMOqLGDoBTgkhOng==
ppp ipcp dns admit-any
ppp ipcp dns request
mtu 1492
ip address ppp-negotiate
tcp mss 1024
dialer user username
dialer-group 13
dialer bundle 13
qos car inbound carl 3 cir 90000 cbs 5625000 ebs 0 green pass red discard
qos car outbound carl 4 cir 9000 cbs 562500 ebs 0 green pass red discard
#
interface NULL0
#
interface Vlan-interface1
ip address 192.168.1.1 255.255.255.0
tcp mss 1024
dhcp server apply ip-pool vlan1
#
interface GigabitEthernet0/0
port link-mode route
nat outbound
pppoe-client dial-bundle-number 10
qos car inbound carl 5 cir 90000 cbs 5625000 ebs 0 green pass red discard
qos car outbound carl 6 cir 9000 cbs 562500 ebs 0 green pass red discard
#
interface GigabitEthernet0/1
port link-mode route
nat outbound
pppoe-client dial-bundle-number 11
qos car inbound carl 7 cir 90000 cbs 5625000 ebs 0 green pass red discard
qos car outbound carl 8 cir 9000 cbs 562500 ebs 0 green pass red discard
#
interface GigabitEthernet0/2
port link-mode route
nat outbound
pppoe-client dial-bundle-number 12
qos car inbound carl 1 cir 90000 cbs 5625000 ebs 0 green pass red discard
qos car outbound carl 2 cir 9000 cbs 562500 ebs 0 green pass red discard
#
interface GigabitEthernet0/3
port link-mode route
nat outbound
pppoe-client dial-bundle-number 13
qos car inbound carl 3 cir 90000 cbs 5625000 ebs 0 green pass red discard
qos car outbound carl 4 cir 9000 cbs 562500 ebs 0 green pass red discard
#
interface GigabitEthernet0/4
port link-mode route
#
interface GigabitEthernet0/4.3
vlan-type dot1q vid 3
ip address 192.168.2.1 255.255.255.0
dhcp server apply ip-pool vlan3
ip policy-based-route CNC
#
interface GigabitEthernet0/4.4
vlan-type dot1q vid 4
ip address 192.168.4.1 255.255.255.0
dhcp server apply ip-pool vlan4
ip policy-based-route CNC
#
interface GigabitEthernet0/5
port link-mode route
#
interface GigabitEthernet0/5.8
vlan-type dot1q vid 8
ip address 192.168.8.1 255.255.255.0
dhcp server apply ip-pool vlan8
ip policy-based-route CNC
#
interface GigabitEthernet0/5.16
vlan-type dot1q vid 16
ip address 192.168.16.1 255.255.255.0
dhcp server apply ip-pool vlan16
ip policy-based-route CNC
#
interface GigabitEthernet0/6
port link-mode bridge
#
interface GigabitEthernet0/7
port link-mode bridge
#
interface GigabitEthernet0/8
port link-mode bridge
#
interface GigabitEthernet0/9
port link-mode bridge
#
ip route-static 0.0.0.0 0.0.0.0 Dialer10
ip route-static 0.0.0.0 0.0.0.0 Dialer11
ip route-static 0.0.0.0 0.0.0.0 Dialer12
ip route-static 0.0.0.0 0.0.0.0 Dialer13
#
snmp-agent
snmp-agent local-engineid 800063A20350DA00467971
snmp-agent sys-info version all
#
dhcp enable
#
ntp-service unicast-server 202.112.29.82
#
nat connection-limit-policy 19
#
dialer-rule 10 ip permit
dialer-rule 11 ip permit
dialer-rule 12 ip permit
dialer-rule 13 ip permit
#
nms primary monitor-interface Dialer11
#
load xml-configuration
#
load tr069-configuration
#
user-interface tty 12
user-interface aux 0
user-interface vty 0 4
authentication-mode scheme
#
return
4条联通ADSL宽带分别连接MSR2600的GE0/0,GE0/1,GE0/2,GE0/3,通过配置子接口,划分4个IP段,192.168.2.0,192.168.4.0,192.168.8.0,192.168.16.0
设置策略路由使每个网段单走一条ADSL宽带上网
(0)
最佳答案
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论