华为三层交换机配置命令
华为三层交换机配置命令
你的三层交换机是不是经常让你机器不好使,看看下面的三层交换机配置文章,一切问题都能解决。详细介绍实例讲解:全面的三层交换机配置比较全面的三层交换机配置实例,带命令解释哟!快来get吧!
三层交换机配置:
Enable //进入私有模式
Configure terminal //进入全局模式
service password-encryption //对密码进行加密
hostname Catalyst 3550-12T1 //给三层交换机定义名称
enable password 123456. //enable密码
Enable secret 654321 //enable的加密密码(应该是乱码而不是654321这样)
Ip subnet-zero //允许使用全0子网(默认都是打开的)
Ip name-server 172.16.8.1 172.16.8.2 //三层交换机名字Catalyst 3550-12T1对应的IP地址是172.16.8.1
Service dhcp //提供DHCP服务
ip routing //启用三层交换机上的路由模块
Exit
三层交换机配置:
Vtp mode server //定义VTP工作模式为sever模式
Vtp domain centervtp //定义VTP域的名称为centervtp
Vlan 2 name vlan2 //定义vlan并给vlan取名(如果不取名的话,vlan2的名字应该是vlan002)
Vlan 3 name vlan3
Vlan 4 name vlan4
Vlan 5 name vlan5
Vlan 6 name vlan6
Vlan 7 name vlan7
Vlan 8 name vlan8
Vlan 9 name vlan9
Exit
三层交换机配置:
interface Port-channel 1 //进入虚拟的以太通道组1
switchport trunk encapsulation dot1q //给这个接口的trunk封装为802.1Q的帧格式
switchport mode trunk //定义这个接口的工作模式为trunk
switchport trunk allowed vlan all //在这个trunk上允许所有的vlan通过
Interface gigabitethernet 0/1 //进入模块0上的吉比特以太口1
switchport trunk encapsulation dotlq //给这个接口的trunk封装为802.1Q的帧格式
switchport mode trunk //定义这个接口的工作模式为trunk
switchport trunk allowed vlan all //在这个trunk上允许所有的vlan通过
channel-group 1 mode on //把这个接口放到快速以太通道组1中
Interface gigabitethernet 0/2 //同上
switchport trunk encapsulation dotlq
switchport mode trunk
switchport trunk allowed vlan all
channel-group 1 mode on
三层交换机配置:
port-channel load-balance src-dst-ip //定义快速以太通道组的负载均衡方式(依*源和目的IP的`方式)
interface gigabitethernet 0/3 //进入模块0上的吉比特以太口3
switchport trunk encapsulation dotlq //给trunk封装为802.1Q
switchport mode trunk //定义这个接口的工作模式为trunk
switchport trunk allowed vlan all //允许所有vlan信息通过
interface gigabitethernet 0/4 //同上
switchport trunk encapsulation dotlq
switchport mode trunk
switchport trunk allowed vlan all
interface gigbitethernet 0/5 //同上
switchport trunk encapsulation dotlq
switchport mode trunk
switchport trunk allowed vlan all
interface gigbitethernet 0/6 //同上
switchport trunk encapsulation dotlq
switchport mode trunk
switchprot trunk allowed vlan all
三层交换机配置:
interface gigbitethernet 0/7 //进入模块0上的吉比特以太口7
Switchport mode access //定义这个接口的工作模式为访问模式
switchport access vlan 9 //定义这个接口可以访问哪个vlan(实际就是分配这个接口到vlan)
no shutdown
spanning-tree vlan 6-9 cost 1000 //在生成树中,vlan6-9的开销定义为10000
interface range gigabitethernet 0/8 – 10 //进入模块0上的吉比特以太口8,9,10
switchport mode access //定义这些接口的工作模式为访问模式
switchport access vlan 8 //把这些接口都分配到vlan8中
no shutdown
三层交换机配置:
spanning-tree portfast //在这些接口上使用portfast(使用portfast以后,在生成树的时候不参加运算,直接成为转发状态)
interface gigabitethernet 0/11 //进入模块0上的吉比特以太口11
switchport trunk encapsulation dotlq //给这个接口封装为802.1Q
switchport mode trunk //定义这个接口的工作模式为trunk
switchport trunk allowed vlan all //允许所有vlan信息通过
interface gigabitethernet 0/12 //同上
switchport trunk encapsulation dotlq
switchport mode trunk
switchport trunk allowed vlan all
interface vlan 1 //进入vlan1的逻辑接口(不是物理接口,用来给vlan做路由用)
ip address 172.16.1.7 255.255.255.0 //配置IP地址和子网掩码
no shutdown
三层交换机配置:
standby 1 ip 172.16.1.9 //开启了冗余热备份(HSRP),冗余热备份组1,虚拟路由器的IP地址为172.16.1.9
standby 1 priority 110 preempt //定义这个三层交换机在冗余热备份组1中的优先级为110,preempt是用来开启抢占模式
interface vlan 2 //同上
ip address 172.16.2.252 255.255.255.0
no shutdown
standby 2 ip 172.16.2.254
standby 2 priority 110 preempt
ip access-group 101 in //在入方向上使用扩展的访问控制列表101
interface vlan 3 //同上
ip address 172.16.3.252 255.255.255.0
no shutdown
三层交换机配置:
standby 3 ip 172.16.3.254
standby 3 priority 110 preempt
ip access-group 101 in
interface vlan 4 //同上
ip address 172.16.4.252 255.255.255.0
no shutdown
standby 4 ip 172.16.4.254
standby 4 priority 110 preempt
ip access-group 101 in
interface vlan 5
ip address 172.16.5.252 255.255.255.0
no shutdown
standby 5 ip 172.16.5.254
standby 5 priority 110 preempt
ip access-group 101 in
interface vlan 6
ip address 172.16.6.252 255.255.255.0
no shutdown
三层交换机配置:
standby 6 ip 172.16.6.254
standby 6 priority 100 preempt
interface vlan 7
ip address 172.16.7.252 255.255.255.0
no shutdown
standby 7 ip 172.16.7.254
standby 7 priority 100 preempt
interface vlan 8
ip address 172.16.8.252 255.255.255.0
no shutdown
standby 8 ip 172.16.8.254
standby 8 priority 100 preempt
interface vlan 9
ip address 172.16.9.252 255.255.255.0
no shutdown
三层交换机配置:
standby 9 ip 172.16.9.254
standby 9 priority 100 preempt
access-list 101 deny ip any 172.16.7.0 0.0.0.255 //扩展的访问控制列表101
access-list 101 permit ip any any
Interface vlan 1 //进入vlan1这个逻辑接口
Ip helper-address 172.16.8.1 //可以转发广播(helper-address的作用就是把广播转化为单播,然后发向172.16.8.1)
Interface vlan 2
Ip helper-address 172.16.8.1
Interface vlan 3
ip helper-address 172.16.8.1
interface vlan 4
ip helper-address 172.16.8.1
interface vlan 5
ip helper-address 172.16.8.1
interface vlan 6
ip helper-address 172.16.8.1
interface vlan 7
ip helper-address 172.16.8.1
interface vlan 9
ip helper-address 172.16.8.1
router rip //启用路由协议RIP
version 2 //使用的是RIPv2,如果没有这句,则是使用RIPv1
network 172.16.0.0 //宣告直连的网段
exit
三层交换机配置:
ip route 0.0.0.0 0.0.0.0 172.16.9.250 //缺省路由,所有在路由表中没有办法匹配的数据包,都发向下一跳地址为172.16.9.250这个路由器
line con 0
line aux 0
line vty 0 15 //telnet线路(路由器只有5个,是0-4)
password 12345678 //login密码
login
end
copy running-config startup-config 保存配置
;绛旓細1銆佸皢鐢佃剳鐢═ELNET鎴朇ONSOLE绾胯繛鎺涓夊眰浜ゆ崲鏈銆2銆佽緭鍏鏍稿績浜ゆ崲鏈鐨勭敤鎴峰悕銆佸瘑鐮佸苟鐧婚檰銆3銆佽繘鍏ヤ氦鎹㈡満鍚庯紙浠鍗庝负浜ゆ崲鏈轰负渚嬶級锛歴ystem-view锛堣繘鍏ョ郴缁閰嶇疆锛塿lan 10锛堝垱寤篤LAN锛塱nterface vlan 10锛堣繘鍏LAN锛塱p address 172.16.10.1 24锛堣缃甀P銆佹帺鐮侊級defaut getway 172.16.10.1锛堣缃綉鍏筹級quit...
绛旓細杩欎釜杈撳嚭淇℃伅鍛婅瘔鎴戜滑锛孷LAN 10鐨勬帴鍙f槸鈥淰lanif10鈥濓紝鍏禝P鍦板潃鏄192.168.10.1锛屽瓙缃戞帺鐮佹槸255.255.255.0銆傛澶栵紝璇鍛戒护杩樻彁渚涗簡鍏朵粬鏈夊叧VLAN 10鐨勮缁嗕俊鎭紝渚嬪VLAN绫诲瀷鍜岃矾鐢辨帴鍙g瓑銆傛讳箣锛屼互涓婁袱绉嶆柟娉曢兘鍙互鐢ㄦ潵鏌ョ湅鍗庝负浜ゆ崲鏈VLAN绔彛涓嬪搴旂殑IP鍦板潃銆備娇鐢ㄢ渄isplay ip interface brief鈥濆懡浠ゅ彲浠...
绛旓細涓銆佷簩灞備氦鎹㈡満鐨閰嶇疆锛氬湪涓や釜浜屽眰浜ゆ崲鏈轰笂鍒嗗埆鍒掑嚭涓LAN锛屽苟灏嗕簩灞備氦鎹㈡満涓婁笌涓夊眰浜ゆ崲鎴栬矾鐢卞櫒涓婄殑鎺ョ嚎璁剧疆涓篴ccess鎺ュ彛锛屽叿浣撻厤缃氨涓嶅湪杩欓噷鍋氳禈杩颁簡锛屽ぇ瀹跺彲浠ョ炕鎴戜箣鍓嶇殑妗堜緥鏌ョ湅銆備簩锛涓夊眰浜ゆ崲鏈鐨勯厤缃細1锛氶鍏堝湪涓夊眰浜ゆ崲涓婂垝鍑轰袱涓猇LAN锛屽苟杩涘叆VLAN涓哄叾閰嶇疆IP锛屾IP灏嗕綔涓轰笌浠栫浉杩濸C鐨勭綉鍏炽...
绛旓細鍦鍗庝负涓夊眰浜ゆ崲鏈5700浜ゆ崲鏈轰笂寮鍚疍HCP鏈嶅姟锛岀劧鍚閰嶇疆濂藉湴鍧姹犱负192.168.2.254缃戞锛屾帓闄ゆ帀192.168.2.200鍒192.168.2.199杩欎釜鑼冨洿鐨勬墍鏈塈P锛屽叿浣鍛戒护濡備笅锛歞hcp enable ip address 192.168.2.200 255.255.255.0 interface vlanif10 dhcp server excluded-ip - address 192.168.2.200 192....
绛旓細s3500鏄涓夊眰鐨浜ゆ崲鏈銆閰嶇疆ip锛<quidways3500>sys [quidways3500]interface vlan-interface 1 [quidways3500-vlan-interface1]ip address 192.168.0.1 255.255.255.0 绔彛涔熷彲浠ラ厤缃甶p鍦板潃锛屼絾鍜屼笂闈㈤厤缃殑鎰忎箟瀹屽叏涓嶄竴鏍凤紝绔彛涓嬬殑ip鍦板潃鍙緵绔彛鑷繁浣跨敤锛岃屽湪vlan-interface涓嬮厤缃殑ip鏄氦鎹㈡満鐨刬p...
绛旓細濡備笅鍥炬墍绀猴細7銆佸埄鐢╬ing鍛戒护瀵筆C涔嬮棿杩涜閫氫俊娴嬭瘯锛屽彲浠ing閫氱殑缁撴灉濡備笅鍥炬墍绀猴細娉ㄦ剰浜嬮」锛1銆侀厤缃甈C鏃朵竴瀹氳璁╁畠浠浜庝笉鍚孖P鍜岀綉鍏炽2銆閰嶇疆涓夊眰浜ゆ崲鏈鐨刅LAN锛岃璁╁畠浠殑VLAN涓篜C涔嬮棿鐨勭綉鍏筹紝鍒囪锛岃繖寰堥噸瑕併3銆佷笁灞備氦鎹㈡満涓瀹氳寮鍚矾鐢卞姛鑳斤紝鍛戒护鏄“ip routing"銆4銆侀厤缃笁灞備氦鎹㈡満涓瀹...
绛旓細int vlanif 50 dhcp server static-bind ip-address 192.168.50.100 mac-address 1234-1234-1234 1.2) ARP缁戝畾 user-bind static ip-address 192.168.50.100 mac-address 1234-1234-1234 杩欐牱閰嶇疆鍚庯紝璇AC鍦板潃姣忔閮藉彲浠ヨ幏鍙栧埌鎸囧畾鐨処P锛屼笖鍙湁璇ユ寚瀹氱殑IP鍦板潃鎵嶅彲浠ヨ仈缃戙涓夊眰浜ゆ崲鏈涓婇厤缃甀P-...
绛旓細[Access-Ethernet0/4/1]port trunk permit vlan 2 to 3 (娉ㄦ剰鍗庝负鐨勪负allowd杩欓噷涓簆ermit)STP鐨勯棶棰 H3C鏈変簺浜ゆ崲鏈哄瀷鍙稴TP鏄叧闂殑锛屽彲浠ラ氳繃displaystp brief鏌ョ湅锛屽鏋滄墦寮浜嗙殑璇濓紝鍙互鍦ㄦ帴鍙d笅鍚敤杈圭紭绔彛鍔熻兘銆俿tpedged-port enable 2.涓夊眰浜ゆ崲鏈鍒濆鍖(閰嶇疆VLAN浠ュ強VLAN鎺ュ彛锛屾帴鍙e垝鍒)鍒涘缓瀵瑰簲...
绛旓細鍦鍗庝负涓夊眰浜ゆ崲鏈涓婅繘琛孷LAN闂磋矾鐢辩殑閰嶇疆锛屼富瑕佸氨鏄垱寤篤LAN锛岀鍙e垝鍒嗭紝涓夊眰VLAN鎺ュ彛鍦板潃閰嶇疆锛岄潤鎬佽矾鐢辨垨鏄疪IP鍗忚閰嶇疆銆傞潤鎬佽矾鐢遍厤缃繃绋嬶細PCA:ip address:10.1.1.2/24 gw:10.1.1.1/24(VLAN2璺敱鎺ュ彛IP鍦板潃)PCB:ip address:10.1.2.2/24 gw:10.1.2.1/24(VLAN3璺敱鎺ュ彛IP鍦板潃)PCC:ip ...
绛旓細妤间富锛屼綘濂藉搱 鑴氭湰閰嶇疆濡備笅 璺敱鍣細sys sysname GateWay interface g0/0 des TO_CoreSwitch-G0/24 ip add 192.168.1.1 29 quit ip route-static 192.168.10.0 24 192.168.1.2 ip route-static 192.168.20.0 24 192.168.1.2 鏍稿績浜ゆ崲鏈 sys sysname CoreSwitch vlan batch 10 20 100...