只有一台s5120当核心,下面全是傻瓜交换机。
交换机配置如下:
#
version 7.1.070, Release 6113
#
sysname H3C
#
clock timezone Beijing add 08:00:00
clock protocol none
#
telnet server enable
#
irf mac-address persistent timer
irf auto-update enable
undo irf link-delay
irf member 1 priority 1
#
dhcp enable
#
lldp global enable
#
password-recovery enable
#
vlan 1
#
vlan 10
#
vlan 20
#
vlan 30
#
vlan 40
#
vlan 50
#
vlan 60
#
vlan 70
#
vlan 80
#
vlan 90
#
vlan 100
#
vlan 200
#
stp global enable
#
dhcp server ip-pool 1
gateway-list 192.168.10.1
network 192.168.10.0 mask 255.255.255.0
dns-list 222.246.129.80 59.51.78.210
expired day 0 hour 2
#
dhcp server ip-pool 2
gateway-list 192.168.20.1
network 192.168.20.0 mask 255.255.255.0
dns-list 222.246.129.80 59.51.78.210
expired day 0 hour 2
#
dhcp server ip-pool 3
gateway-list 192.168.30.1
network 192.168.30.0 mask 255.255.255.0
dns-list 222.246.129.80 59.51.78.210
expired day 0 hour 2
#
dhcp server ip-pool 4
gateway-list 192.168.40.1
network 192.168.40.0 mask 255.255.255.0
dns-list 222.246.129.80 59.51.78.210
expired day 0 hour 2
#
dhcp server ip-pool 5
gateway-list 192.168.50.1
network 192.168.50.0 mask 255.255.255.0
dns-list 222.246.129.80 59.51.78.210
expired day 0 hour 2
#
dhcp server ip-pool 6
gateway-list 192.168.60.1
network 192.168.60.0 mask 255.255.255.0
dns-list 222.246.129.80 59.51.78.210
expired day 0 hour 2
#
dhcp server ip-pool 7
gateway-list 192.168.70.1
network 192.168.70.0 mask 255.255.255.0
dns-list 222.246.129.80 59.51.78.210
expired day 0 hour 2
forbidden-ip 192.168.70.251
forbidden-ip 192.168.70.252
forbidden-ip 192.168.70.253
forbidden-ip 192.168.70.254
#
dhcp server ip-pool 8
gateway-list 192.168.80.1
network 192.168.80.0 mask 255.255.255.0
dns-list 222.246.129.80 59.51.78.210
expired day 0 hour 2
#
dhcp server ip-pool 9
gateway-list 192.168.90.1
network 192.168.90.0 mask 255.255.255.0
dns-list 222.246.129.80 59.51.78.210
expired day 0 hour 2
#
dhcp server ip-pool 10
gateway-list 192.168.100.1
network 192.168.100.0 mask 255.255.255.0
dns-list 222.246.129.80
expired day 0 hour 2
#
interface NULL0
#
interface Vlan-interface1
#
interface Vlan-interface10
ip address 192.168.10.1 255.255.255.0
#
interface Vlan-interface20
ip address 192.168.20.1 255.255.255.0
#
interface Vlan-interface30
ip address 192.168.30.1 255.255.255.0
#
interface Vlan-interface40
ip address 192.168.40.1 255.255.255.0
#
interface Vlan-interface50
ip address 192.168.50.1 255.255.255.0
#
interface Vlan-interface60
ip address 192.168.60.1 255.255.255.0
#
interface Vlan-interface70
ip address 192.168.70.1 255.255.255.0
#
interface Vlan-interface80
ip address 192.168.80.1 255.255.255.0
#
interface Vlan-interface90
ip address 192.168.90.1 255.255.255.0
#
interface Vlan-interface100
ip address 192.168.100.1 255.255.255.0
#
interface Vlan-interface200
ip address 192.168.254.2 255.255.255.0
#
interface GigabitEthernet1/0/1
port access vlan 10
#
interface GigabitEthernet1/0/2
port access vlan 20
#
interface GigabitEthernet1/0/3
port access vlan 30
#
interface GigabitEthernet1/0/4
port access vlan 40
#
interface GigabitEthernet1/0/5
port access vlan 50
#
interface GigabitEthernet1/0/6
port access vlan 60
#
interface GigabitEthernet1/0/7
port access vlan 70
#
interface GigabitEthernet1/0/8
port access vlan 70
#
interface GigabitEthernet1/0/9
port access vlan 70
#
interface GigabitEthernet1/0/10
port access vlan 70
#
interface GigabitEthernet1/0/11
port access vlan 70
#
interface GigabitEthernet1/0/12
port access vlan 70
#
interface GigabitEthernet1/0/13
port access vlan 80
#
interface GigabitEthernet1/0/14
port access vlan 80
#
interface GigabitEthernet1/0/15
port access vlan 80
#
interface GigabitEthernet1/0/16
port access vlan 80
#
interface GigabitEthernet1/0/17
port access vlan 90
#
interface GigabitEthernet1/0/18
port access vlan 90
#
interface GigabitEthernet1/0/19
port access vlan 90
#
interface GigabitEthernet1/0/20
port access vlan 90
#
interface GigabitEthernet1/0/21
port access vlan 100
#
interface GigabitEthernet1/0/22
port access vlan 100
#
interface GigabitEthernet1/0/23
port access vlan 100
#
interface GigabitEthernet1/0/24
port access vlan 200
#
interface GigabitEthernet1/0/25
#
interface GigabitEthernet1/0/26
#
interface GigabitEthernet1/0/27
#
interface GigabitEthernet1/0/28
#
scheduler logfile size 16
#
line class aux
user-role network-admin
#
line class vty
user-role network-operator
#
line aux 0
user-role network-admin
#
line vty 0 4
authentication-mode scheme
user-role network-operator
#
line vty 5 63
user-role network-operator
#
ip route-static 0.0.0.0 0 192.168.254.254
#
radius scheme system
user-name-format without-domain
#
domain system
#
domain default enable system
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role
#
role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
user-group system
#
local-user ADMIN class manage
authorization-attribute user-role network-operator
#
local-user admin class manage
password hash $h$6$yG1dMrwANXZbFgaf$o3MQOtE c9cnUxakH0iOS0vpQ4GGQVB765a9tSy2GJtubNy0JzjzXzY25HOKo UUDKuiBb b0Dcjdh0VFQ5ZQg==
service-type telnet http
authorization-attribute user-role network-admin
#
local-user damin class manage
password hash $h$6$RdiNMxXWfMw rfzp$gCrmnit 4/4jtWwn9WWR/YBjZcCrgU5 UfWpXAtBltd/107rZub3OwQiHwpVtSEW5EEdxNq8d49dGOktpp14lQ==
service-type http https
authorization-attribute user-role level-3
authorization-attribute user-role network-operator
#
ip http enable
ip https enable
#
暂无评论