核心上联两台路由器走不同出口宽带。下联全部trunk口。。
那么我在配置策略路由时,不同源地址的主机走不同的出口上外网。那么我最后的Qos是应用到哪个接口上?所有下联的trunk口?还是上联的那两个接路由器的端口?
帮忙看一下我下面的配置对不?我应用在上联的端口上。
另外有应用在全局上的吗?好像打不出命令。
# vlan 510
description fb1
# vlan 520
description fb2
# vlan 530
description fb3
# vlan 540
description fb4
# vlan 550
description fb5
# vlan 1000
description 7503E-to-MSR
# vlan 1001
description 7503E-to-ER
# interface Vlan-interface510
ip address 172.10.0.1 255.255.255.0
dhcp select relay
dhcp relay server-address 10.10.1.200
# interface Vlan-interface520
ip address 172.20.1.1 255.255.255.0
dhcp select relay
dhcp relay server-address 10.10.1.200
# interface Vlan-interface530
ip address 10.10.1.1 255.255.255.0
dhcp select relay
dhcp relay server-address 10.10.1.200
# interface Vlan-interface540
ip address 10.10.3.1 255.255.255.0
dhcp select relay
dhcp relay server-address 10.10.1.200
# interface Vlan-interface550
ip address 10.20.0.1 255.255.0.0
dhcp select relay
dhcp relay server-address 10.10.1.200
#interface Vlan-interface1000
ip address 192.168.1.2 255.255.255.0
# interface Vlan-interface1001
ip address 192.168.2.2 255.255.255.0
acl number 3100
rule 0 permit ip source 10.10.0.0 0.0.255.255
rule 5 permit ip source 10.20.0.0 0.0.255.255
# acl number 3200
rule 0 permit ip source 172.10.0.0 0.0.255.255
rule 5 permit ip source 172.20.0.0 0.0.255.255
# traffic classifier toER operator and
if-match acl 3200
# traffic classifier toMSR operator and
if-match acl 3100
# traffic behavior toER
redirect next-hop 192.168.1.1
# traffic behavior toMSR
redirect next-hop 192.168.2.1
# qos policy aaaa
classifier toMSR behavior toMSR
classifier toER behavior toER
# interface Ten-GigabitEthernet1/0/1
port link-mode bridge
port link-type trunk
port trunk permit vlan all
# interface Ten-GigabitEthernet1/0/2
port link-mode bridge
port link-type trunk
port trunk permit vlan all
#
……
#
interface Ten-GigabitEthernet1/0/23
port link-mode bridge
port access vlan 1000
qos apply policy aaaa inbound
#
interface Ten-GigabitEthernet1/0/24
port link-mode bridge
port access vlan 1001
qos apply policy aaaa inbound
#
ip route-static 0.0.0.0 0 192.168.1.1
(0)
看一下这样配行不行?
acl number 3000
rule 0 permit ip destination 10.10.0.0 0.0.255.255
rule 0 permit ip destination 10.20.0.0 0.0.255.255
rule 0 permit ip destination 172.10.0.0 0.0.255.255
rule 0 permit ip destination 172.20.0.0 0.0.255.255
acl number 3100
rule 0 permit ip source 10.10.0.0 0.0.255.255
rule 5 permit ip source 10.20.0.0 0.0.255.255
# acl number 3200
rule 0 permit ip source 172.10.0.0 0.0.255.255
rule 5 permit ip source 172.20.0.0 0.0.255.255
# traffic classifier 3000 operator and
if-match acl 3000
# traffic classifier toER operator and
if-match acl 3200
# traffic classifier toMSR operator and
if-match acl 3100
# traffic behavior 3000
# traffic behavior toER
redirect next-hop 192.168.1.1
# traffic behavior toMSR
redirect next-hop 192.168.2.1
# qos policy aaaa
classifier 3000 behavior 3000
classifier toMSR behavior toMSR
classifier toER behavior toER
# qos apply policy aaaa global inbound
# ip route-static 0.0.0.0 0 192.168.1.
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
我这样直接应用在上联口不对吗?怎么好像有效果呀。
另外,如果应用到下联口,会不会影响到三层路由vlan间相互通信转发?
怎么可能有效果,你匹配的是源ip,除非应用在上联口的outbound方向,你配置上联口的inbond不行的。
会的,所以你写acl的时候,写精细一点,哪些要重定向,不需要的那些会自动查路由表转发的。
可是我是所有内网vlan都需要互访。但又要两个大段分不同的出口上外网。怎么写配置?
写多一个cb对咯,if-match正常互访的源和目的ip,但是behavior不写动作。后面的cb对写if-match 所有源,不匹配目的ip,全部重定向。
流行为traffic behavior不是至少要写一个动作吗?不写动作那是要如何?留空?只命名?
对,behavior下面的具体动作不写就行了。
看一下这样配行不行? acl number 3000 rule 0 permit ip destination 10.10.0.0 0.0.255.255 rule 0 permit ip destination 10.20.0.0 0.0.255.255 rule 0 permit ip destination 172.10.0.0 0.0.255.255 rule 0 permit ip destination 172.20.0.0 0.0.255.255 acl number 3100 rule 0 permit ip source 10.10.0.0 0.0.255.255 rule 5 permit ip source 10.20.0.0 0.0.255.255 # acl number 3200 rule 0 permit ip source 172.10.0.0 0.0.255.255 rule 5 permit ip source 172.20.0.0 0.0.255.255 # traffic classifier 3000 operator and if-match acl 3000 # traffic classifier toER operator and if-match acl 3200 # traffic classifier toMSR operator and if-match acl 3100 # traffic behavior 3000 # traffic behavior toER redirect next-hop 192.168.1.1 # traffic behavior toMSR redirect next-hop 192.168.2.1 # qos policy aaaa classifier 3000 behavior 3000 classifier toMSR behavior toMSR classifier toER behavior toER # qos apply policy aaaa global inbound # ip route-static 0.0.0.0 0 192.168.1.1