H3C MSR 830 ge1接PC可以DHCP上网,接H3C S5500的24口上
不了网,本换机有4个VLAN都可以获取相应的地址,就是不能上网。
还有个问题,这样配置4个VLAN里的PC可以相互访问吗??不知道
是不是配置有问题,求解
下面是两台设备的配置
H3C 5500 的配置
[H3C]dis cu
#
version 5.20, Release 2222P12
#
sysname H3C
#
irf mac-address persistent timer
irf auto-update enable
undo irf link-delay
#
domain default enable system
#
undo ip http enable
#
password-recovery enable
#
vlan 1
#
vlan 10
#
vlan 20
#
vlan 30
#
vlan 40
#
vlan 100
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
dhcp server ip-pool 10
network 192.168.10.0 mask 255.255.255.0
gateway-list 192.168.10.254
dns-list 58.22.96.66 218.104.128.106
#
dhcp server ip-pool 20
network 192.168.20.0 mask 255.255.255.0
gateway-list 192.168.20.254
dns-list 58.22.96.66 218.104.128.106
#
dhcp server ip-pool 30
network 192.168.30.0 mask 255.255.255.0
gateway-list 192.168.30.254
dns-list 58.22.96.66 218.104.128.106
#
dhcp server ip-pool 40
network 192.168.40.0 mask 255.255.255.0
gateway-list 192.168.40.254
dns-list 58.22.96.66 218.104.128.106
#
user-group system
group-attribute allow-guest
#
local-user admin
password cipher $c$3$cPgkbebUcqfnpwmaK53Vudt92zDk6i5R
service-type ssh telnet terminal
#
interface NULL0
#
interface Vlan-interface1
ip address dhcp-alloc client-identifier mac Vlan-interface1
#
interface Vlan-interface10
ip address 192.168.10.254 255.255.255.0
#
interface Vlan-interface20
ip address 192.168.20.254 255.255.255.0
#
interface Vlan-interface30
ip address 192.168.30.254 255.255.255.0
#
interface Vlan-interface40
ip address 192.168.40.254 255.255.255.0
#
interface Vlan-interface100
ip address 192.168.2.50 255.255.255.0
#
interface GigabitEthernet1/0/1
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/2
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/3
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/4
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/5
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/6
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/7
port link-mode bridge
port access vlan 20
#
interface GigabitEthernet1/0/8
port link-mode bridge
port access vlan 20
#
interface GigabitEthernet1/0/9
port link-mode bridge
port access vlan 20
#
interface GigabitEthernet1/0/10
port link-mode bridge
port access vlan 20
#
interface GigabitEthernet1/0/11
port link-mode bridge
port access vlan 20
#
interface GigabitEthernet1/0/12
port link-mode bridge
port access vlan 20
#
interface GigabitEthernet1/0/13
port link-mode bridge
port access vlan 30
#
interface GigabitEthernet1/0/14
port link-mode bridge
port access vlan 30
#
interface GigabitEthernet1/0/15
port link-mode bridge
port access vlan 30
#
interface GigabitEthernet1/0/16
port link-mode bridge
port access vlan 30
#
interface GigabitEthernet1/0/17
port link-mode bridge
port access vlan 30
#
interface GigabitEthernet1/0/18
port link-mode bridge
port access vlan 30
#
interface GigabitEthernet1/0/19
port link-mode bridge
port access vlan 40
#
interface GigabitEthernet1/0/20
port link-mode bridge
port access vlan 40
#
interface GigabitEthernet1/0/21
port link-mode bridge
port access vlan 40
#
interface GigabitEthernet1/0/22
port link-mode bridge
port access vlan 40
#
interface GigabitEthernet1/0/23
port link-mode bridge
#
interface GigabitEthernet1/0/24
port link-mode bridge
#
interface GigabitEthernet1/0/25
port link-mode bridge
shutdown
#
interface GigabitEthernet1/0/26
port link-mode bridge
shutdown
#
interface GigabitEthernet1/0/27
port link-mode bridge
shutdown
#
interface GigabitEthernet1/0/28
port link-mode bridge
shutdown
#
ip route-static 0.0.0.0 0.0.0.0 192.168.2.1
#
dhcp enable
#
load xml-configuration
#
load tr069-configuration
#
user-interface aux 0
user-interface vty 0 4
user privilege level 3
user-interface vty 5 15
#
return
=======================================
MSR830的配置
[H3C]dis cu
#
version 5.20, Release 2514P04
#
sysname H3C
#
domain default enable system
#
password-recovery enable
#
acl number 3000
rule 1 permit ip source 192.0.0.0 0.255.255.255
rule 10 deny ip
#
vlan 1
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
dhcp server ip-pool 1
network 192.168.2.0 mask 255.255.255.0
gateway-list 192.168.2.1
dns-list 58.22.96.66
expired unlimited
#
user-group system
group-attribute allow-guest
#
interface Cellular0/0
async mode protocol
link-protocol ppp
#
interface NULL0
#
interface GigabitEthernet0/0
port link-mode route
description TO_waiwang-WAN
nat outbound 3000
ip address 192.168.199.16 255.255.255.0
#
interface GigabitEthernet0/1
port link-mode route
ip address 192.168.2.1 255.255.255.0
#
interface GigabitEthernet0/4
port link-mode route
#
interface GigabitEthernet0/2
port link-mode bridge
#
interface GigabitEthernet0/3
port link-mode bridge
#
ip route-static 0.0.0.0 0.0.0.0 192.168.199.1
#
dhcp server forbidden-ip 192.168.2.1
#
dhcp enable
#
load xml-configuration
#
load tr069-configuration
#
user-interface con 0
user-interface tty 13
user-interface vty 0 4
#
return
(1)
最佳答案
您好,请知:
看配置有以下几个问题:
1、路由器830与交换机5500的互联接口没有配置
建议将5500交换机的24口划分到VLAN100,配置如下:
int gi 1/0/24
port link-type access
port access vlan 100
quit
2、路由器没有路由指向到5500交换机的业务网段,需添加如下路由:
ip route-static 192.168.10.0 255.255.255.0 192.168.2.50
ip route-static 192.168.20.0 255.255.255.0 192.168.2.50
ip route-static 192.168.30.0 255.255.255.0 192.168.2.50
ip route-static 192.168.40.0 255.255.255.0 192.168.2.50
3、在路由器830的地址转换的ACL中,没有将5500交换机上的业务地址段加入进去,不然交换机上业务地址无法访问外网,整改如下:
acl number 3000
rule 2 permit ip source 192.168.10.0 0.0.0.255
rule 3 permit ip source 192.168.20.0 0.0.0.255
rule 4 permit ip source 192.168.30.0 0.0.0.255
rule 5 permit ip source 192.168.40.0 0.0.0.255
quit
(1)
非常感谢 可以了
s5500缺少如下配置
#
interface GigabitEthernet1/0/24
port link-mode bridge
port access vlan 100
#
(0)
你好 我加我这条命令了。还是不能上网
(0)
问题还没解决吗?
问题还没解决吗?
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
好的,望关注,感谢支持哈!