ÎÄÕÂÁбí
 
2008-01-24 9:52
¸ÄÍ·»»Ã棬Çë·ÃÎÊUbuntu¸ßµØ
 
2007-04-02 16:57

Login authentication

Password:

<S5600>

%Oct 26 13:15:22:079 2006 S5600 SHELL/5/LOGIN:- 1 - VTY(172.29.22.24) in unit1 l

oginsuper

Password:

User privilege level is 3, and only those commands can be used

whose level is equal or less than this.

Privilege note: 0-VISIT, 1-MONITOR, 2-SYSTEM, 3-MANAGE

<S5600>dis cur

#

sysname S5600

#

super password level 3 simple *****

#

vfs check check-method fix

#

radius scheme system

#

domain system

#

vlan 1

#

vlan 51

description Lan1

#

vlan 52

description Lab2

#

vlan 53

#

vlan 54

#

vlan 55

#

vlan 56

#

vlan 57

#

vlan 58

#

vlan 59

#

vlan 60

#

vlan 61

#

vlan 62

#

vlan 88

#

interface Vlan-interface51

ip address 172.29.51.254 255.255.255.0

#

interface Vlan-interface52

ip address 172.29.52.254 255.255.255.0

#

interface Vlan-interface53

ip address 172.29.53.254 255.255.255.0

#

interface Vlan-interface54

ip address 172.29.54.254 255.255.255.0

#

interface Vlan-interface55

ip address 172.29.55.254 255.255.255.0

#

interface Vlan-interface56

ip address 172.29.56.254 255.255.255.0

#

interface Vlan-interface57

ip address 172.29.57.254 255.255.255.0

#

interface Vlan-interface58

ip address 172.29.58.254 255.255.255.0

#

interface Vlan-interface59

ip address 172.29.21.254 255.255.255.0

#

interface Vlan-interface60

ip address 172.29.22.254 255.255.255.0

#

interface Vlan-interface61

ip address 172.29.61.1 255.255.255.0

#

interface Vlan-interface62

ip address 172.29.10.254 255.255.255.0

#

interface Vlan-interface88

ip address 172.169.88.2 255.255.255.252

#

interface Aux1/0/0

#

interface GigabitEthernet1/0/1

port access vlan 51

#

interface GigabitEthernet1/0/2

port access vlan 52

#

interface GigabitEthernet1/0/3

port access vlan 53

#

interface GigabitEthernet1/0/4

port access vlan 54

#

interface GigabitEthernet1/0/5

port access vlan 55

#

interface GigabitEthernet1/0/6

port access vlan 56

#

interface GigabitEthernet1/0/7

port access vlan 57

#

interface GigabitEthernet1/0/8

port access vlan 58

#

interface GigabitEthernet1/0/9

port access vlan 59

#

interface GigabitEthernet1/0/10

port access vlan 60

#

interface GigabitEthernet1/0/11

port access vlan 61

#

interface GigabitEthernet1/0/12

port link-type trunk

port trunk permit vlan 1 60 62

#

interface GigabitEthernet1/0/13

port access vlan 51

#

interface GigabitEthernet1/0/14

port access vlan 52

#

interface GigabitEthernet1/0/15

port access vlan 51

#

interface GigabitEthernet1/0/16

port access vlan 51

#

interface GigabitEthernet1/0/17

port link-type trunk

port trunk permit vlan 1 60 62

#

interface GigabitEthernet1/0/18

port link-type trunk

port trunk permit vlan 1 60 62

#

interface GigabitEthernet1/0/19

#

interface GigabitEthernet1/0/20

#

interface GigabitEthernet1/0/21

#

interface GigabitEthernet1/0/22

#

interface GigabitEthernet1/0/23

shutdown

port access vlan 88

#

interface GigabitEthernet1/0/24

shutdown

port access vlan 88

#

interface GigabitEthernet1/0/25

shutdown

#

interface GigabitEthernet1/0/26

port access vlan 88

#

interface GigabitEthernet1/0/27

shutdown

#

interface GigabitEthernet1/0/28

port access vlan 88

#

interface Cascade1/2/1

#

interface Cascade1/2/2

#

interface NULL0

#

ip route-static 0.0.0.0 0.0.0.0 172.169.88.1 preference 60

ip route-static 172.29.62.0 255.255.255.0 172.29.61.2 preference 60

ip route-static 172.29.63.0 255.255.255.0 172.29.61.2 preference 60

ip route-static 172.29.64.0 255.255.255.0 172.29.61.2 preference 60

ip route-static 172.29.65.0 255.255.255.0 172.29.61.2 preference 60

ip route-static 172.29.66.0 255.255.255.0 172.29.61.2 preference 60

ip route-static 172.29.67.0 255.255.255.0 172.29.61.2 preference 60

ip route-static 172.29.68.0 255.255.255.0 172.29.61.2 preference 60

#

snmp-agent

snmp-agent local-engineid 800007DB00E0FC7DAD966877

snmp-agent community read *****

snmp-agent sys-info version v2c v3

#

user-interface aux 0 7

user-interface vty 0 4

set authentication password simple huawei

#

return

<S5600>

 
2007-04-02 16:50

Ò»£®ÖÐÐĽ»»»µÄVLANÅäÖÃ

£¨1£©¼¤»îvlan·ÓÉ

Switch1#config t

Switch1(config)#ip routing

£¨2£©´´½¨Èý¸öVLAN

Switch1#

Switch1#vlan database

Switch1(vlan)#vlan 2

Switch1(vlan)#vlan 3

Switch1(vlan)#vlan 10

Switch1(vlan)#exit

£¨3£©¸øVLAN·ÖÅäIP

Switch1#config t

Switch1(config)#config vlan2

Switch1(config-if)#ip address 192.168.2.1 255.255.255.0

Switch1(config-if)#no shutdown

Switch1#config t

Switch1(config)#config vlan3

Switch1(config-if)#ip address 192.168.3.1 255.255.255.0

Switch1(config-if)#no shutdown

Switch1#config t

Switch1(config)#config vlan10

Switch1(config-if)#ip address 192.168.10.1 255.255.255.0

Switch1(config-if)#no shutdown

£¨4£©ÅäVTP

Switch1#

Switch1#config t

Switch1(config)#vtp domain china_mobile

Switch1(config)#vtp mode server

Switch1(config)#end

£¨5£©ÅäTrunk

Switch1#

Switch1#config t

Switch1(config)#interface gigabitethernet0/1

Switch1(config-if)#switchport trunk encapsulation isl

Switch1(config-if)#switchport mode trunk

Switch1(config-if)#end

£¨6£©¸øÖÐÐĽ»»»»úͨÍù·ÓÉÆ÷µÄ½Ó¿ÚÅäIP

Switch1#

Switch1#config t

Switch1(config)#interface fastethernet0/1

Switch1(config-if)#no switchport

Switch1(config-if)#ip address 200.1.1.1 255.255.255.0

Switch1(config-if)#no shutdown

£¨7£©¸øÖÐÐĽ»»»»úÅäÖÃȱʡ·ÓÉ

Switch1#

Switch1#config t

Switch(config)#ip route 0.0.0.0 0.0.0.0 200.1.1.2

£¨8£©°ÑVLANºÅ·ÖÅ䏸IP½Ó¿Ú

Switch1#

Switch1#config t

Switch1(config)#interface fastethernet0/2

Switch1(config-if)#switchport mode access

Switch1(config-if)#switchport access vlan2

Switch1(config-if)#spanning-tree portfast

¡­ ¡­

Switch1#

Switch1#config t

Switch1(config)#interface fastethernet0/13

Switch1(config-if)#switchport mode access

Switch1(config-if)#switchport access vlan3

Switch1(config-if)#spanning-tree portfast

(ÆäËüͬ)

£¨9£©Åä·ÃÎÊ¿ØÖÆÁбíACL½ûVLAN3×ÓÍøµÄ¿Í»§»ú·ÃÎÊ·þÎñÆ÷

Switch1#

Switch1#config t

Switch1(config)#access-list 1 deny 192.168.3.0 0.0.0.255

Switch1(config)#access-list 1 permit any

Switch1(config)#interface fastethernet0/13 £¨´Ë½Ó¿Ú½Ó·þÎñÆ÷£©

Switch1(config-if)#ip access-group 1 out

£¨10£©¼ì²éÉÏÊöÅäÖÃ

Switch1#show vlan

Switch1#show ip route

Switch1#show interface gigabitethernet0/1 switchport

Switch1#show run

Switch1#show vtp status

£¨11£©´æÅäÖÃ

Switch1#copy running-config startup-config

¶þ£®ÔÚ½ÓÈë²ã½»»»»úSwith2ÉÏVLANµÄÅäÖÃ

(1)ÅäTRUNK

Switch2#

Swtich2#config t

Switch2(config)#interface gigabitethernet0/1

Switch2(config-if)#switchport trunk encapsulation isl

Switch2(config-if)#switchport mode trunk

Switch2(config-if)#end

Switch2#

Swtich2#config t

Switch2(config)#interface gigabitethernet0/2

Switch2(config-if)#switchport trunk encapsulation isl

Switch2(config-if)#switchport mode trunk

Switch2(config-if)#end

(2)ÅäVTP

Switch2#

Switch2#config t

Switch2(config)#vtp mode client

Switch2(config)#vtp domain china_mobile

Switch2(config)#end

(3)¸ø½Ó¿Ú·ÖÅäVLANºÅ

Switch2#

Switch2#config t

Switch2(config)#interface fastethernet0/1

Switch2(config-if)#switchport mode access

Switch2(config-if)#switchport access vlan2

Switch2(config-if)#spanning-tree portfast

¡­ ¡­

(ÆäËü¶Ë¿ÚÅäÖÃͬ)

(4)´æÅäÖÃ

Switch2#copy running-config startup-config

(ÆäËü½»»»»úͬ)

С½á£º

¶ÔÓÚÆóÒµ¼¶µÄÓ¦ÓÃÀ´Ëµ£¬¾ÖÓòÍøÄÚµÄÒµÎñÁ÷Á¿ÀàÐÍÆðÀ´Ô½¶à£¬¶ÔÍøÂçµÄÕûÌåÐÔÄÜÒ²¾ÍÌá³öÁ˹¶¿ÌµÄÒªÇó¡£ÎÒÃÇÖ»ÓÐÉè¼Æ³ö¼¼ÊõÓÅÔ½µÄÍøÂç²ÅÄÜÊÊÓ¦ÕâÖÖÒªÇó¡£Ë¼¿ÆCATALYST 3550 -24 EMIÔÚQoSÉÏÐÔÄܳ¬Èº£¬Äܰ´ÒµÎñÀàÐͽøÐзÖÀ࣬ÒÔ½øÐÐÓÅÏȼ¶·þÎñ£¬Ê¹¹Ø¼üÐÔÒµÎñ£¬´ø¿íÃô¸ÐÐÔÒµÎñÓÅÏÈת·¢¡£¶øÈý²ã½»»»¹¦ÄܸüÊÇÄÜÍêÃÀʤÈε±½ñÆóÒµ¾ÖÓòÍøÔ½À´Ô½ÆÕ±éµÄÔÚ½»»»»·¾³Öв¿ÊðÈý²ã½»»»µÄÐèÇó¡£±¾°¸Àý¾Í˵Ã÷ÁËCATALYST 3550 -24 EMIµÄÈý²ã½»»»¹¦ÄܺܺõØÊ¤ÈÎÁËÕâÖÖÐèÇó¡£

 
2007-04-02 16:46

ÍøÂç»·¾³£ºÒ»Ì¨3550EMI½»»»»ú£¬»®·ÖÈý¸övlan£¬vlan2Ϊ·þÎñÆ÷ËùÔÚÍøÂ磬ÃûΪserver£¬IPµØÖ·¶ÎΪ192.168.2.0£¬×ÓÍøÑÚÂ룺255.255.255.0£¬Íø¹Ø£º192.168.2.1£¬Óò·þÎñÆ÷Ϊwindows 2000 advance server£¬Í¬Ê±¼æ×÷DNS·þÎñÆ÷£¬IPµØÖ·Îª192.168.2.10£¬vlan3Ϊ¿Í»§»ú1ËùÔÚÍøÂ磬IPµØÖ·¶ÎΪ192.168.3.0£¬×ÓÍøÑÚÂ룺255.255.255.0£¬Íø¹Ø£º192.168.3.1ÃüÃûΪwork01£¬vlan4Ϊ¿Í»§»ú2ËùÔÚÍøÂ磬ÃüÃûΪwork02£¬IPµØÖ·¶ÎΪ 192.168.4.0£¬×ÓÍøÑÚÂ룺255.255.255.0£¬Íø¹Ø£º192.168.4.1£¬3550×÷DHCP·þÎñÆ÷,¶Ë¿Ú1-8»®µ½VLAN 2£¬¶Ë¿Ú9-16»®·Öµ½VLAN 3£¬¶Ë¿Ú17-24»®·Öµ½VLAN 4£®DHCP·þÎñÆ÷ʵÏÖ¹¦ÄÜ£º¸÷VLAN±£Áô2-10µÄIPµØÖ·²»·ÖÅäÖã¬ÀýÈ磺192.168.2.0µÄÍø¶Î£¬±£Áô192.168.2.2ÖÁ 192.168.2.10µÄIPµØÖ·¶Î²»·ÖÅ䣮

°²È«ÒªÇó£º

VLAN 3ºÍVLAN 4 ²»ÔÊÐí»¥Ïà·ÃÎÊ,µ«¶¼¿ÉÒÔ·ÃÎÊ·þÎñÆ÷ËùÔÚµÄVLAN 2,ĬÈÏ·ÃÎÊ¿ØÖÆÁбíµÄ¹æÔòÊǾܾøËùÓаü£®

ÅäÖÃÃüÁî¼°²½ÖèÈçÏ£º

µÚÒ»²½:´´½¨VLAN£º

Switch>en

Switch#Vlan Database

Switch(Vlan)>Vlan 2 Name server

Switch(Vlan)>Vlan 3 Name work01

Switch(vlan)>Vlan 4 Name work02

µÚ¶þ²½£ºÉèÖÃVLAN IPµØÖ·£º

Switch#Config T

Switch(Config)>Int Vlan 2

Switch(Config-vlan)Ip Address 192.168.2.1 255.255.255.0

Switch(Config-vlan)No Shut

Switch(Config-vlan)>Int Vlan 3

Switch(Config-vlan)Ip Address 192.168.3.1 255.255.255.0

Switch(Config-vlan)No Shut

Switch(Config-vlan)>Int Vlan 4

Switch(Config-vlan)Ip Address 192.168.4.1 255.255.255.0

Switch(Config-vlan)No Shut

Switch(Config-vlan)Exit

/*×¢Òâ:ÓÉÓÚ´ËʱûÓн«¶Ë¿Ú·ÖÅäÖõ½VLAN2,3,4,ËùÒÔ¸÷VLAN»áDOWNµô,´ý½«¶Ë¿Ú·ÖÅäµ½¸÷VLANºó,VLAN»áÆðÀ´*/

µÚÈý²½£ºÉèÖö˿ÚÈ«¾Ö²ÎÊý

Switch(Config)Interface Range Fa 0/1 - 24

Switch(Config-if-range)Switchport Mode Access

Switch(Config-if-range)Spanning-tree Portfast

µÚËIJ½:½«¶Ë¿ÚÌí¼Óµ½VLAN2,3,4ÖÐ

/*½«¶Ë¿Ú1-8Ìí¼Óµ½VLAN 2*/

Switch(Config)Interface Range Fa 0/1 - 8

Switch(Config-if-range)Switchport Access Vlan 2

/*½«¶Ë¿Ú9-16Ìí¼Óµ½VLAN 3*/

Switch(Config)Interface Range Fa 0/9 - 16

Switch(Config-if-range)Switchport Access Vlan 3

/*½«¶Ë¿Ú17-24Ìí¼Óµ½VLAN 4*/

Switch(Config)Interface Range Fa 0/17 - 24

Switch(Config-if-range)Switchport Access Vlan 4

Switch(Config-if-range)Exit

/*¾­¹ýÕâÒ»²½ºó,¸÷VLAN»áÆðÀ´*/

µÚÎå²½£ºÅäÖÃ3550×÷ΪDHCP·þÎñÆ÷

/*VLAN 2¿ÉÓõØÖ·³ØºÍÏàÓ¦²ÎÊýµÄÅäÖÃ,Óм¸¸öVLANÒªÉ輸¸öµØÖ·³Ø*/

Switch(Config)Ip Dhcp Pool Test01

/*ÉèÖÿɷÖÅäµÄ×ÓÍø*/

Switch(Config-pool)Network 192.168.2.0 255.255.255.0

/*ÉèÖÃDNS·þÎñÆ÷*/

Switch(Config-pool)Dns-server 192.168.2.10

/*ÉèÖøÃ×ÓÍøµÄÍø¹Ø*/

Switch(Config-pool)Default-router 192.168.2.1

/*ÅäÖÃVLAN 3ËùÓõĵØÖ·³ØºÍÏàÓ¦²ÎÊý*/

Switch(Config)Ip Dhcp Pool Test02

Switch(Config-pool)Network 192.168.3.0 255.255.255.0

Switch(Config-pool)Dns-server 192.168.2.10

Switch(Config-pool)Default-router 192.168.3.1

/*ÅäÖÃVLAN 4ËùÓõĵØÖ·³ØºÍÏàÓ¦²ÎÊý*/

Switch(Config)Ip Dhcp Pool Test03

Switch(Config-pool)Network 192.168.4.0 255.255.255.0

Switch(Config-pool)Dns-server 192.168.2.10

Switch(Config-pool)Default-router 192.168.4.1

µÚÁù²½£ºÉèÖÃDHCP±£Áô²»·ÖÅäµÄµØÖ·

Switch(Config)Ip Dhcp Excluded-address 192.168.2.2 192.168.2.10

Switch(Config)Ip Dhcp Excluded-address 192.168.3.2 192.168.3.10

Switch(Config)Ip Dhcp Excluded-address 192.168.4.2 192.168.4.10

µÚÆß²½£ºÆôÓ÷ÓÉ

/*·ÓÉÆôÓú󣬸÷VLAN¼äÖ÷»ú¿É»¥Ïà·ÃÎÊ*/

Switch(Config)Ip Routing

µÚ°Ë²½£ºÅäÖ÷ÃÎÊ¿ØÖÆÁбí

Switch(Config)access-list 103 permit ip 192.168.2.0 0.0.0.255 192.168.3.0 0.0.0.255

Switch(Config)access-list 103 permit ip 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255

Switch(Config)access-list 103 permit udp any any eq bootpc

Switch(Config)access-list 103 permit udp any any eq tftp

Switch(Config)access-list 103 permit udp any eq bootpc any

Switch(Config)access-list 103 permit udp any eq tftp any

Switch(Config)access-list 104 permit ip 192.168.2.0 0.0.0.255 192.168.4.0 0.0.0.255

Switch(Config)access-list 104 permit ip 192.168.4.0 0.0.0.255 192.168.2.0 0.0.0.255

Switch(Config)access-list 104 permit udp any eq tftp any

Switch(Config)access-list 104 permit udp any eq bootpc any

Switch(Config)access-list 104 permit udp any eq bootpc any

Switch(Config)access-list 104 permit udp any eq tftp any

µÚ¾Å²½£ºÓ¦Ó÷ÃÎÊ¿ØÖÆÁбí

/*½«·ÃÎÊ¿ØÖÆÁбíÓ¦Óõ½VLAN 3ºÍVLAN 4,VLAN 2²»ÐèÒª*/

Switch(Config)Int Vlan 3

Switch(Config-vlan)ip access-group 103 out

Switch(Config-vlan)Int Vlan 4

Switch(Config-vlan)ip access-group 104 out

µÚÊ®²½£º½áÊø²¢±£´æÅäÖÃ

Switch(Config-vlan)End

Switch#Copy Run Start

 
2007-04-02 16:42

T¿Í»§¶Ë ¶Ë¿Ú·¶Î§

̰À·ABC ¿ÉÒÔÊÖ¹¤ÉèÖÃ

BitComet ûÓй«¿ª

BitTorrent Plus ¿ÉÒÔÊÖ¹¤ÉèÖÃ

BitTorrent 6881¡«6889

±ÈÌØ¾«ÁéBit Spirit 16881

½ûÖ¹BTÅäÖÃ:

¶¨ÒåÓû§×Ô¶¨ÒåÁ÷Ä£°å£º

[Quidway]flow-template user-defined ip-protocol bt-flag

¶¨Òå¸ß¼¶·ÃÎÊÁÐ±í£º

[Quidway]acl num 3000

[Quidway-acl-adv-3000]rule 0 deny tcp bt-flag

[Quidway-acl-adv-3000]rule 1 deny udp bt-flag

ÔÚ½Ó¿ÚÏÂÅäÖöÔBTÁ÷½øÐнûÖ¹£º

[Quidway-Ethernet2/1/1]flow-template user-defined

[Quidway-Ethernet2/1/1]packet-filter inbound ip-group 3000

Ŀǰ֧³Ö¶ÔBT½øÐÐÏÞÖÆµÄÉ豸ÓÐ:

8505/8508/8512

eudemon500/1000

ne20

secpath1800f

 
2007-04-02 16:39

1. ipµØÖ··ÖÀà

ipµØÖ··ÖÎªÍøÂçµØÖ·ºÍÖ÷»úµØÖ·¶þ¸ö²¿·Ö£¬aÀàµØÖ·Ç°8Î»ÎªÍøÂçµØÖ·£¬ºó24λΪÖ÷»úµØÖ·£¬bÀàµØÖ·16Î»ÎªÍøÂçµØÖ·£¬ºó16λΪÖ÷»úµØÖ·£¬cÀàµØÖ·Ç°24Î»ÎªÍøÂçµØÖ·£¬ºó8λΪÖ÷»úµØÖ·£¬ÍøÂçµØÖ··¶Î§ÈçϱíËùʾ£º

ÖÖÀà ÍøÂçµØÖ··¶Î§

a¡¡ 1.0.0.0 µ½126.0.0.0ÓÐЧ 0.0.0.0 ºÍ127.0.0.0±£Áô

b 128.1.0.0µ½191.254.0.0ÓÐЧ 128.0.0.0ºÍ191.255.0.0±£Áô

c 192.0.1.0 µ½223.255.254.0ÓÐЧ 192.0.0.0ºÍ223.255.255.0±£Áô

d 224.0.0.0µ½239.255.255.255ÓÃÓÚ¶àµã¹ã²¥

e 240.0.0.0µ½255.255.255.254±£Áô 255.255.255.255ÓÃÓڹ㲥

2. ·ÖÅä½Ó¿ÚipµØÖ·

ÈÎÎñ ÃüÁî

½Ó¿ÚÉèÖÃ interface type slot/number

Ϊ½Ó¿ÚÉèÖÃipµØÖ· ip address ip-address mask

ÑÚÂ꣨mask£©ÓÃÓÚʶ±ðipµØÖ·ÖеÄÍøÂçµØÖ·Î»Êý£¬ipµØÖ·£¨ip-address£©ºÍÑÚÂ루mask£©ÏàÓë¼´µÃµ½ÍøÂçµØÖ·¡£

3. ʹÓÿɱ䳤µÄ×ÓÍøÑÚÂë

ͨ¹ýʹÓÿɱ䳤µÄ×ÓÍøÑÚÂë¿ÉÒÔÈÃλÓÚ²»Í¬½Ó¿ÚµÄÍ¬Ò»ÍøÂç±àºÅµÄÍøÂçʹÓò»Í¬µÄÑÚÂ룬ÕâÑù¿ÉÒÔ½ÚÊ¡ipµØÖ·£¬³ä·ÖÀûÓÃÓÐЧµÄipµØÖ·¿Õ¼ä¡£

ÈçÏÂͼËùʾ£º

router1 ºÍrouter2µÄe0¶Ë¿Ú¾ùʹÓÃÁËcÀàµØÖ·192.1.0.0×÷ÎªÍøÂçµØÖ·£¬router1µÄe0µÄÍøÂçµØÖ·Îª192.1.0.128,ÑÚÂëΪ 255.255.255.192, router2µÄe0µÄÍøÂçµØÖ·Îª192.1.0.64,ÑÚÂëΪ255.255.255.192£¬ÕâÑù¾Í½«Ò»¸öcÀàÍøÂçµØÖ··ÖÅ䏸Á˶þ¸öÍø£¬¼È»®·ÖÁ˶þ¸ö×ÓÍø£¬Æðµ½Á˽ÚÔ¼µØÖ·µÄ×÷Óá£

4. ʹÓÃÍøÂçµØÖ··­Ò루nat£©

nat£¨network address translation£©Æðµ½½«ÄÚ²¿Ë½ÓеØÖ··­Òë³ÉÍⲿºÏ·¨µÄÈ«¾ÖµØÖ·µÄ¹¦ÄÜ£¬ËüʹµÃ²»¾ßÓкϷ¨ipµØÖ·µÄÓû§¿ÉÒÔͨ¹ýnat·ÃÎʵ½Íⲿinternet.

µ±½¨Á¢ÄÚ²¿ÍøµÄʱºò,½¨ÒéʹÓÃÒÔϵØÖ·×éÓÃÓÚÖ÷»ú,ÕâЩµØÖ·ÊÇÓÉnetwork working group(rfc 1918)±£ÁôÓÃÓÚ˽ÓÐÍøÂçµØÖ··ÖÅäµÄ.

l class a:10.1.1.1 to 10.254.254.254

l class b:172.16.1.1 to 172.31.254.254

l class c:192.168.1.1 to 192.168.254.254

ÃüÁîÃèÊöÈçÏ£º

ÈÎÎñ ÃüÁî

¶¨ÒåÒ»¸ö±ê×¼·ÃÎÊÁбí access-list access-list-number permit source [source-wildcard]

¶¨ÒåÒ»¸öÈ«¾ÖµØÖ·³Ø ip nat pool name start-ip end-ip {netmask netmask | prefix-length prefix-length} [type rotary]

½¨Á¢¶¯Ì¬µØÖ··­Òë ip nat inside source {list {access-list-number | name} pool name [overload] | static local-ip global-ip}

Ö¸¶¨ÄÚ²¿ºÍÍⲿ¶Ë¿Ú ip nat {inside | outside}

·ÓÉÆ÷µÄethernet 0¶Ë¿ÚΪinside¶Ë¿Ú£¬¼´´Ë¶Ë¿ÚÁ¬½ÓÄÚ²¿ÍøÂ磬²¢ÇҴ˶˿ÚËùÁ¬½ÓµÄÍøÂçÓ¦¸Ã±»·­Ò룬serial 0¶Ë¿ÚΪoutside¶Ë¿Ú£¬ÆäÓµÓкϷ¨ipµØÖ·£¨ÓÉnic»ò·þÎñÌṩÉÌËù·ÖÅäµÄºÏ·¨µÄipµØÖ·£©,À´×ÔÍøÂç10.1.1.0/24µÄÖ÷»ú½«´ÓipµØÖ·³Ø c2501ÖÐÑ¡ÔñÒ»¸öµØÖ·×÷Ϊ×Ô¼ºµÄºÏ·¨µØÖ·£¬¾­ÓÉserial 0¿Ú·ÃÎÊinternet¡£ÃüÁîip nat inside source list 2 pool c2501 overloadÖеIJÎÊýoverload£¬½«ÔÊÐí¶à¸öÄÚ²¿µØÖ·Ê¹ÓÃÏàͬµÄÈ«¾ÖµØÖ·£¨Ò»¸öºÏ·¨ipµØÖ·£¬ËüÊÇÓÉnic»ò·þÎñÌṩÉÌËù·ÖÅäµÄµØÖ·£©¡£ÃüÁî ip nat pool c2501 202.96.38.1 202.96.38.62 netmask 255.255.255.192¶¨ÒåÁËÈ«¾ÖµØÖ·µÄ·¶Î§¡£

ÉèÖÃÈçÏ£º

ip nat pool c2501 202.96.38.1 202.96.38.62 netmask 255.255.255.192

interface ethernet 0

ip address 10.1.1.1 255.255.255.0

ip nat inside

!

interface serial 0

ip address 202.200.10.5 255.255.255.252

ip nat outside

!

ip route 0.0.0.0 0.0.0.0 serial 0

access-list 2 permit 10.0.0.0 0.0.0.255

! dynamic nat

!

ip nat inside source list 2 pool c2501 overload

line console 0

exec-timeout 0 0

!

line vty 0 4

end

Èý²ã½»»»»úÅäÖÃʵÀý¼°ËµÃ÷

Õâ¸ö²»Ïñ·ÓÉÆ÷ÄǸö£¬ÄǸöÊÇshow run³öÀ´µÄ£¬Õâ¸ö¾ÍÊÇ×Ô¼ºÖ±½ÓдµÄÁË¡££¬Ê¹ÓÃÔÚ»ã¾Û²ãµÄÈý²ã½»»»»úµÄÅäÖá£

Enable //½øÈë˽ÓÐģʽ

Configure terminal //½øÈëÈ«¾Öģʽ

service password-encryption //¶ÔÃÜÂë½øÐмÓÃÜ

hostname Catalyst 3550-12T1 //¸øÈý²ã½»»»»ú¶¨ÒåÃû³Æ

enable password 123456. //enableÃÜÂë

Enable secret 654321 //enableµÄ¼ÓÃÜÃÜÂ루Ӧ¸ÃÊÇÂÒÂë¶ø²»ÊÇ654321ÕâÑù£©

Ip subnet-zero //ÔÊÐíʹÓÃÈ«0×ÓÍø£¨Ä¬È϶¼ÊÇ´ò¿ªµÄ£©

Ip name-server 172.16.8.1 172.16.8.2 //Èý²ã½»»»»úÃû×ÖCatalyst 3550-12T1¶ÔÓ¦µÄIPµØÖ·ÊÇ172.16.8.1

Service dhcp //ÌṩDHCP·þÎñ

ip routing //ÆôÓÃÈý²ã½»»»»úÉϵÄ·ÓÉÄ£¿é

Exit

Vtp mode server //¶¨ÒåVTP¹¤×÷ģʽΪseverģʽ

Vtp domain centervtp //¶¨ÒåVTPÓòµÄÃû³ÆÎªcentervtp

Vlan 2 name vlan2 //¶¨Òåvlan²¢¸øvlanÈ¡Ãû£¨Èç¹û²»È¡ÃûµÄ»°£¬vlan2µÄÃû×ÖÓ¦¸ÃÊÇvlan002£©

Vlan 3 name vlan3

Vlan 4 name vlan4

Vlan 5 name vlan5

Vlan 6 name vlan6

Vlan 7 name vlan7

Vlan 8 name vlan8

Vlan 9 name vlan9

Exit

interface Port-channel 1 //½øÈëÐéÄâµÄÒÔ̫ͨµÀ×é1

Interface gigabitethernet 0/1 //½øÈëÄ£¿é0Éϵļª±ÈÌØÒÔÌ«¿Ú1

channel-group 1 mode on //°ÑÕâ¸ö½Ó¿Ú·Åµ½¿ìËÙÒÔ̫ͨµÀ×é1ÖÐ

Interface gigabitethernet 0/2 //ͬÉÏ

channel-group 1 mode on

port-channel load-balance src-dst-ip //¶¨Òå¿ìËÙÒÔ̫ͨµÀ×éµÄ¸ºÔؾùºâ·½Ê½£¨ÒÀ¿¿Ô´ºÍÄ¿µÄIPµÄ·½Ê½£©

interface gigabitethernet 0/3 //½øÈëÄ£¿é0Éϵļª±ÈÌØÒÔÌ«¿Ú3< trunk ¸øtrunk·âװΪ802.1Q

< all >

interface gigabitethernet 0/4 //ͬÉÏ<>

interface gigbitethernet 0/5 //ͬÉÏ<>

interface gigbitethernet 0/6 //ͬÉÏ< trunk

interface gigbitethernet 0/7 //½øÈëÄ£¿é0Éϵļª±ÈÌØÒÔÌ«¿Ú7

no shutdown

spanning-tree vlan 6-9 cost 1000 //ÔÚÉú³ÉÊ÷ÖУ¬vlan6-9µÄ¿ªÏú¶¨ÒåΪ10000

interface range gigabitethernet 0/8 ¨C 10 //½øÈëÄ£¿é0Éϵļª±ÈÌØÒÔÌ«¿Ú8,9,10

no shutdown

spanning-tree portfast //ÔÚÕâЩ½Ó¿ÚÉÏʹÓÃportfast£¨Ê¹ÓÃportfastÒÔºó£¬ÔÚÉú³ÉÊ÷µÄʱºò²»²Î¼ÓÔËË㣬ֱ½Ó³ÉΪת·¢×´Ì¬£©

interface gigabitethernet 0/11 //½øÈëÄ£¿é0Éϵļª±ÈÌØÒÔÌ«¿Ú11< ¸øÕâ¸ö½Ó¿Ú·âװΪ802.1Q

interface gigabitethernet 0/12 //ͬÉÏ<>

interface vlan 1 //½øÈëvlan1µÄÂß¼­½Ó¿Ú£¨²»ÊÇÎïÀí½Ó¿Ú£¬ÓÃÀ´¸øvlan×ö·ÓÉÓã©

ip address 172.16.1.7 255.255.255.0 //ÅäÖÃIPµØÖ·ºÍ×ÓÍøÑÚÂë

no shutdown

standby 1 ip 172.16.1.9 //¿ªÆôÁËÈßÓàÈȱ¸·Ý£¨HSRP£©£¬ÈßÓàÈȱ¸·Ý×é1£¬ÐéÄâ·ÓÉÆ÷µÄIPµØÖ·Îª172.16.1.9

standby 1 priority 110 preempt //¶¨ÒåÕâ¸öÈý²ã½»»»»úÔÚÈßÓàÈȱ¸·Ý×é1ÖеÄÓÅÏȼ¶Îª110£¬preemptÊÇÓÃÀ´¿ªÆôÇÀռģʽ

interface vlan 2 //ͬÉÏ

ip address 172.16.2.252 255.255.255.0

no shutdown

standby 2 ip 172.16.2.254

standby 2 priority 110 preempt

ip access-group 101 in //ÔÚÈë·½ÏòÉÏʹÓÃÀ©Õ¹µÄ·ÃÎÊ¿ØÖÆÁбí101

interface vlan 3 //ͬÉÏ

ip address 172.16.3.252 255.255.255.0

no shutdown

standby 3 ip 172.16.3.254

standby 3 priority 110 preempt

ip access-group 101 in

interface vlan 4 //ͬÉÏ

ip address 172.16.4.252 255.255.255.0

no shutdown

standby 4 ip 172.16.4.254

standby 4 priority 110 preempt

ip access-group 101 in

interface vlan 5

ip address 172.16.5.252 255.255.255.0

no shutdown

standby 5 ip 172.16.5.254

standby 5 priority 110 preempt

ip access-group 101 in

interface vlan 6

ip address 172.16.6.252 255.255.255.0

no shutdown

standby 6 ip 172.16.6.254

standby 6 priority 100 preempt

interface vlan 7

ip address 172.16.7.252 255.255.255.0

no shutdown

standby 7 ip 172.16.7.254

standby 7 priority 100 preempt

interface vlan 8

ip address 172.16.8.252 255.255.255.0

no shutdown

standby 8 ip 172.16.8.254

standby 8 priority 100 preempt

interface vlan 9

ip address 172.16.9.252 255.255.255.0

no shutdown

standby 9 ip 172.16.9.254

standby 9 priority 100 preempt

access-list 101 deny ip any 172.16.7.0 0.0.0.255 //À©Õ¹µÄ·ÃÎÊ¿ØÖÆÁбí101

access-list 101 permit ip any any

Interface vlan 1 //½øÈëvlan1Õâ¸öÂß¼­½Ó¿Ú

Ip helper-address 172.16.8.1 //¿ÉÒÔת·¢¹ã²¥£¨helper£­addressµÄ×÷ÓþÍÊǰѹ㲥ת»¯Îªµ¥²¥£¬È»ºó·¢Ïò172.16.8.1£©

Interface vlan 2

Ip helper-address 172.16.8.1

Interface vlan 3

ip helper-address 172.16.8.1

interface vlan 4

ip helper-address 172.16.8.1

interface vlan 5

ip helper-address 172.16.8.1

interface vlan 6

ip helper-address 172.16.8.1

interface vlan 7

ip helper-address 172.16.8.1

interface vlan 9

ip helper-address 172.16.8.1

router rip //ÆôÓ÷ÓÉЭÒéRIP

version 2 //ʹÓõÄÊÇRIPv2£¬Èç¹ûûÓÐÕâ¾ä£¬ÔòÊÇʹÓÃRIPv1

network 172.16.0.0 //Ðû¸æÖ±Á¬µÄÍø¶Î

exit

ip route 0.0.0.0 0.0.0.0 172.16.9.250 //ȱʡ·ÓÉ£¬ËùÓÐÔÚ·ÓɱíÖÐûÓа취ƥÅäµÄÊý¾Ý°ü£¬¶¼·¢ÏòÏÂÒ»ÌøµØÖ·Îª172.16.9.250Õâ¸ö·ÓÉÆ÷

line con 0

line aux 0

line vty 0 15 //telnetÏß·£¨Â·ÓÉÆ÷Ö»ÓÐ5¸ö£¬ÊÇ0-4£©

password 12345678 //loginÃÜÂë

login

end

copy running-config startup-config ±£´æÅäÖÃ

 
2007-03-29 5:36
¡ºÅäÖû·¾³²ÎÊý¡»



1. ½»»»»úE0/1ºÍE0/2ÊôÓÚvlan10



2. ½»»»»úE0/3ÊôÓÚvlan20



3. ½»»»»úE0/4ºÍE0/5ÊôÓÚvlan30



4. ½»»»»úE0/23Á¬½ÓServer1



5. ½»»»»úE0/24Á¬½ÓServer2



6. Server1ºÍServer2·ÖÊôÓÚvlan40ºÍvlan50



7. PCºÍServer¶¼ÔÚÍ¬Ò»Íø¶Î



8. E0/10Á¬½ÓBASÉ豸£¬ÊôÓÚvlan60



¡º×éÍøÐèÇó¡»



1. ÀûÓöþ²ã½»»»»ú¶Ë¿ÚµÄhybridÊôÐÔÁé»îʵÏÖvlanÖ®¼äµÄÁé»î»¥·Ã£»



2. Vlan10¡¢vlan20ºÍvlan30µÄPC¾ù¿ÉÒÔ·ÃÎÊServer 1£»



3. vlan 10¡¢20ÒÔ¼°vlan30µÄ4¶Ë¿ÚµÄPC¿ÉÒÔ·ÃÎÊServer 2£»



4. vlan 10ÖеÄ2¶Ë¿ÚµÄPC¿ÉÒÔ·ÃÎÊvlan 30µÄPC£»



5. vlan 20µÄPC¿ÉÒÔ·ÃÎÊvlan 30µÄ5¶Ë¿ÚµÄPC£»



6. vlan10µÄPC·ÃÎÊÍâÍøÐèÒª½«vlanÐÅÏ¢Ë͵½BAS£¬¶øvlan20ºÍvlan30Ôò²»ÐèÒª¡£



2 Êý¾ÝÅäÖò½Öè

¡º¶Ë¿ÚhybridÊôÐÔÅäÖÃÁ÷³Ì¡»



hybrid ÊôÐÔÊÇÒ»ÖÖ»ìÔÓģʽ£¬ÊµÏÖÁËÔÚÒ»¸öuntagged¶Ë¿ÚÔÊÐí±¨ÎÄÒÔtaggedÐÎʽËͳö½»»»»ú¡£Í¬Ê±¿ÉÒÔÀûÓÃhybridÊôÐÔ¶¨Òå·ÖÊôÓÚ²»Í¬µÄvlanµÄ ¶Ë¿ÚÖ®¼äµÄ»¥·Ã£¬ÕâÊÇaccessºÍtrunk¶Ë¿ÚËù²»ÄÜʵÏֵġ£ÔÚһ̨½»»»»úÉϲ»ÔÊÐítrunk¶Ë¿ÚºÍhybrid¶Ë¿Úͬʱ´æÔÚ¡£



1. ÏÈ´´½¨ÒµÎñÐèÒªµÄvlan



[SwitchA]vlan 10



[SwitchA]vlan 20



[SwitchA]vlan 30



[SwitchA]vlan 40



[SwitchA]vlan 50



2. ÿ¸ö¶Ë¿Ú£¬¶¼ÅäÖÃΪ hybrid״̬



[SwitchA]interface Ethernet 0/1



[SwitchA-Ethernet0/1]port link-type hybrid



3. ÉèÖö˿ڵÄpvidµÈÓڸö˿ÚËùÊôµÄvlan



[Switch-Ethernet0/1]port hybrid pvid vlan 10



4. ½«Ï£Íû¿ÉÒÔ»¥Í¨µÄ¶Ë¿ÚµÄpvid vlan£¬ÉèÖÃΪuntagged vlan£¬ÕâÑù´Ó¸Ã¶Ë¿Ú·¢³öµÄ¹ã²¥Ö¡¾Í¿ÉÒÔµ½´ï±¾¶Ë¿Ú



[Switch-Ethernet0/1]port hybrid vlan 10 40 50 60 untagged







ʵ¼ÊÉÏ£¬ÕâÖÖÅäÖÃÊÇͨ¹ý hybrid ¶Ë¿ÚµÄ pvid À´Î¨Ò»µÄ±íʾһ¸ö¶Ë¿Ú£¬½ÓÊÕ¶Ë¿Úͨ¹ýÊÇ·ñ½« vlan ÉèÖÃΪ untagged vlan£¬À´¿ØÖÆÊÇ·ñÓë pvid vlan Ϊ ¸Ã vlan µÄ¶Ë¿Ú»¥Í¨¡£



5. ÒÔϸ÷¶Ë¿ÚÀàËÆ£º



[Switch-Ethernet0/1]int e0/2



[Switch-Ethernet0/2]port link-type hybrid



[Switch-Ethernet0/2]port hybrid pvid vlan 10



[Switch-Ethernet0/2]port hybrid vlan 10 30 40 50 60 untagged







[Switch-Ethernet0/2]int e0/3



[Switch-Ethernet0/3]port link-type hybrid



[Switch-Ethernet0/3]port hybrid pvid vlan 20



[Switch-Ethernet0/3]port hybrid vlan 20 30 40 50 60 untagged



[Switch-Ethernet0/3]int e0/4



[Switch-Ethernet0/4]port link-type hybrid



[Switch-Ethernet0/4]port hybrid pvid vlan 30



[Switch-Ethernet0/4]port hybrid vlan 10 30 40 50 60 untagged







[Switch-Ethernet0/4]int e0/5



[Switch-Ethernet0/5]port link-type hybrid



[Switch-Ethernet0/5]port hybrid pvid vlan 30



[Switch-Ethernet0/5]port hybrid vlan 10 20 30 40 60 untagged







[Switch-Ethernet0/5]int e0/23



[Switch-Ethernet0/23]port link-type hybrid



[Switch-Ethernet0/23]port hybrid pvid vlan 40



[Switch-Ethernet0/23]port hybrid vlan 10 20 30 40 untagged







[Switch-Ethernet0/24]int e0/24



[Switch-Ethernet0/24]port link-type hybrid



[Switch-Ethernet0/24]port hybrid pvid vlan 50



[Switch-Ethernet0/24]port hybrid vlan 10 20 30 50 untagged







6. ÔÚÉÏÐпÚE0/10ÉÏÔÊÐívlan10ÒÔtaggedÐÎʽËͳö£¬ÆäËüΪuntagged



[SwitchA]interface Ethernet 0/10



[SwitchA-Ethernet0/10]port link-type hybrid



[SwitchA-Ethernet0/10]port hybrid pvid vlan 60



[SwitchA-Ethernet0/10]port hybrid vlan 10 tagged



[SwitchA-Ethernet0/10]port hybrid vlan 20 30 untagged



±¾ÀýÖÐÐèÇó±È½Ï¸´ÔÓ£¬Ò»°ãÈËÔ±ºÜÄÑ×öµ½Ò»´ÎÐÔÔÚÒ»¸ö¶Ë¿ÚÉÏÖ¸¶¨ÄÄЩvlanÔÊÐíͨ¹ý£¬¿ÉÒÔ¸ù¾ÝÐèÇóÖðÌõÅäÖ㬽»»»»úÖ§³ÖÔÚ¶Ë¿ÚÉ϶à´ÎÉèÖá£



SϵÁн»»»»úʵÏÖ²»Í¬VLANÖ®¼ä»¥·ÃµÄÅäÖÃ



Ò»¡¢×éÍøÐèÇó£º



½»»»»úÅäÖÃÁË4¸öVLAN£¬·Ö±ðΪVLAN1£¬VLAN2£¬VLAN3£¬VLAN4£¬ÒªÇóVLAN1¿ÉÒÔÓëVLAN2£¬3£¬4»¥·Ã£¬µ«ÊÇVLAN2£¬3£¬4Ö®¼ä²»ÄÜ»¥·Ã£¬ÓÃHybrid¶Ë¿ÚÊôÐÔʵÏִ˹¦ÄÜ¡£



¶þ¡¢×éÍøÍ¼£º



ÎÞ



Èý¡¢ÅäÖò½Ö裺



1. ´´½¨VLAN2



[Quidway]vlan 2



2. ´´½¨VLAN3



[Quidway-vlan2]vlan 3



3. ´´½¨VLAN4



[Quidway-vlan3]vlan 4



4. ½øÈë¶Ë¿ÚEthernet1/0/1



[Quidway-vlan4] interface Ethernet1/0/1



5. ½«¶Ë¿ÚÉèÖÃΪhybridģʽ



[Quidway-Ethernet1/0/1]port link-type hybrid



6. ÉèÖö˿ÚpvidΪ1



[Quidway-Ethernet1/0/1]port hybrid pvid vlan 1



7. ÔÊÐíVLAN1£¬2£¬3£¬4²»´ò±êǩͨ¹ý



[Quidway-Ethernet1/0/1]port hybrid vlan 1 to 4 untagged



8. ½øÈë¶Ë¿ÚEthernet1/0/2



[Quidway-Ethernet1/0/1]interface Ethernet1/0/2



9. ½«¶Ë¿ÚÉèÖÃΪhybridģʽ



[Quidway-Ethernet1/0/2]port link-type hybrid



10. ÉèÖö˿ÚpvidΪ2



[Quidway-Ethernet1/0/2]port hybrid pvid vlan 2



11. ÔÊÐíVLAN1£¬2²»´ò±êǩͨ¹ý



[Quidway-Ethernet1/0/2]port hybrid vlan 1 to 2 untagged



12. ½øÈë¶Ë¿ÚEthernet1/0/3



[Quidway-Ethernet1/0/2]interface Ethernet1/0/3



13. ½«¶Ë¿ÚÉèÖÃΪhybridģʽ



[Quidway-Ethernet1/0/3]port link-type hybrid



14. ÉèÖö˿ÚpvidΪ3



[Quidway-Ethernet1/0/3]port hybrid pvid vlan 3



15. ÔÊÐíVLAN1£¬3²»´ò±êǩͨ¹ý



[Quidway-Ethernet1/0/3]port hybrid vlan 1 3 untagged



16. ½øÈë¶Ë¿ÚEthernet1/0/4



[Quidway-Ethernet1/0/3]interface Ethernet1/0/4



17. ½«¶Ë¿ÚÉèÖÃΪhybridģʽ



[Quidway-Ethernet1/0/4]port link-type hybrid



18. ÉèÖö˿ÚpvidΪ4



[Quidway-Ethernet1/0/4]port hybrid pvid vlan 4



19. ÔÊÐíVLAN1£¬4²»´ò±êǩͨ¹ý



[Quidway-Ethernet1/0/4]port hybrid vlan 1 4 untagged



ËÄ¡¢ÅäÖùؼüµã£º



1. ÀûÓý»»»»úÒÔÌ«Íø¶Ë¿ÚµÄHybridÌØÐÔ£¬¿ÉÒÔʵÏÖPVLANµÄ¹¦ÄÜ¡£



2. ²ÉÓÃHybridÊôÐÔʵÏÖµÄPVLAN¹¦ÄܺÍPVLANµÄ¹¤×÷»úÖÆ´æÔڽϴó²îÒ죬ÉÏÊöÇé¿öÖ»ÊÊÓÃÓÚÍøÂçÁ÷Á¿£¬ÍøÂçÓû§½ÏÉÙµÄÓ¦Óá£

S3000-EIϵÁн»»»»úʵÏÖ²»Í¬VLANÖ®¼ä»¥·ÃµÄÅäÖÃ



Ò»¡¢×éÍø£º



S3026C½»»»»úÅäÖÃÁË4¸öVLAN£¬·Ö±ðΪVLAN1£¬VLAN2£¬VLAN3£¬VLAN4£¬ÒªÇóVLAN1¿ÉÒÔÓëVLAN2£¬3£¬4»¥·Ã£¬µ«ÊÇVLAN2£¬3£¬4Ö®¼ä²»ÄÜ»¥·Ã£¬ÓÃPVLANʵÏִ˹¦ÄÜ¡£



¶þ¡¢×éÍøÍ¼£º



ÎÞ



Èý¡¢ÅäÖò½Ö裺



1. ½øÈëVLAN1



[Switch] vlan 1



2. ÉèÖÃVLAN1ÀàÐÍΪisolate-user-vlan



[Switch-vlan1] isolate-user-vlan enable



3. ´´½¨£¨½øÈ룩½øÈëVLAN2



[Switch-vlan1] vlan 2



4. ½«¶Ë¿ÚE0/2¼ÓÈëVLAN2



[Switch-vlan2] port ethernet0/2



5. ´´½¨£¨½øÈ룩½øÈëVLAN3



[Switch-vlan2] vlan 3



6. ½«¶Ë¿ÚE0/3¼ÓÈëVLAN3



[Switch-vlan3] port ethernet0/3



7. ´´½¨£¨½øÈ룩½øÈëVLAN4



[Switch-vlan3] vlan 4



8. ½«¶Ë¿ÚE0/4¼ÓÈëVLAN4



[Switch-vlan4] port ethernet0/4



9. Í˳öµ½ÏµÍ³ÊÓͼ



[Switch-vlan4] quit



10. ÅäÖÃisolate-user-vlanºÍSecondary VLAN¼äµÄÓ³Éä¹ØÏµ



[Switch] isolate-user-vlan 1 secondary 2 to 4



ËÄ¡¢ÅäÖùؼüµã£º



1. ĿǰSϵÁн»»»»úS2403H¡¢S2026Z-SI ¡¢S2026C-SIÓëS3000ϵÁж¼Ö§³ÖPVLAN£¬´Ë´¦½öÒÔS3026CΪÀý£¬ÆäËû½»»»»úÅäÖÃÏàͬ£»



2. isolate-user-vlan²»ÄܺÍTrunk¶Ë¿ÚͬʱÅäÖ㬼´Èç¹û½»»»»úÉÏÅäÖÃÁËisolate-user-vlan£¬¾Í²»ÄÜÅäÖÃTrunk¶Ë¿Ú£»Èç¹ûÅäÖÃÁËTrunk¶Ë¿Ú£¬¾Í²»ÄÜÅäÖÃisolate-user-vlan£»



isolate-user-vlan¼ò½é

isolate -user-vlanÊÇ»ªÎª¹«Ë¾ÏµÁÐÒÔÌ«Íø½»»»»úµÄÒ»¸öÌØÐÔ£¬Í¨¹ý¸ÃÌØÐÔ¿ÉʵÏÖÍøÂçÖÐVLAN×ÊÔ´µÄ½ÚÔ¼¡£isolate-user-vlan²ÉÓöþ²ã VLAN½á¹¹£¬ÔÚһ̨ÒÔÌ«Íø½»»»»úÉÏÉèÖÃisolate-user-vlanºÍSecondary VLANÁ½ÀàVLAN¡£Ò»¸öisolate-user-vlanºÍ¶à¸öSecondary VLAN¶ÔÓ¦£¬isolate-user-vlan°üº¬Ëù¶ÔÓ¦µÄËùÓÐSecondary VLANÖаüº¬µÄ¶Ë¿ÚºÍÉÏÐж˿ڣ¬ÕâÑù¶ÔÉϲ㽻»»»úÀ´Ëµ£¬Ö»Ðëʶ±ðϲ㽻»»»úÖеÄisolate-user-vlan£¬¶ø²»±Ø¹ØÐÄisolate- user-vlanÖаüº¬µÄSecondary VLAN£¬¼ò»¯ÁËÍøÂçÅäÖ㬽ÚÊ¡ÁËVLAN×ÊÔ´¡£Í¬Ê±£¬Óû§¿ÉÒÔ²ÉÓÃisolate-user-vlanʵÏÖ¶þ²ã±¨ÎĵĸôÀ룬¼´ÎªÃ¿¸öÓû§·ÖÅäÒ»¸ö Secondary VLAN£¬Ã¿¸öSecondary VLANÖÐÖ»°üº¬¸ÃÓû§Á¬½ÓµÄ¶Ë¿ÚºÍÉÏÐж˿ڣ»Èç¹ûÏ£ÍûʵÏÖÓû§Ö®¼ä¶þ²ã±¨ÎĵĻ¥Í¨£¬Ö»Òª½«ÕâЩÓû§Á¬½ÓµÄ¶Ë¿Ú»®Èëͬһ¸öSecondary VLANÖм´¿É¡£

2.2 isolate-user-vlanÅäÖÃ

isolate-user-vlanÅäÖðüÀ¨£º

l ÅäÖÃisolate-user-vlan

l ÅäÖÃSecondary VLAN

l ÉèÖÃisolate-user-vlanºÍSecondary VLAN¼äµÄÓ³Éä¹ØÏµ

ÒÔÉÏÈÎÎñ¶¼ÊDZØÑ¡µÄ£¬Ò»µ©ÆôÓÃisolate-user-vlan¾Í±ØÐëÅäÖá£

2.2.1 ÅäÖÃisolate-user-vlan

¿ÉÒÔʹÓÃÏÂÃæµÄÃüÁîΪһ¸öÒÔÌ«Íø½»»»»ú´´½¨Ò»¸öisolate-user-vlan£¬²¢ÇÒÏò´Ëisolate-user-vlanÖÐÌí¼Ó¶Ë¿Ú¡£

ÇëÔÚϵͳÊÓͼϽøÐд´½¨VLANµÄÅäÖã¬ÔÚVLANÊÓͼϽøÐÐÉèÖÃVLANÀàÐÍΪisolate-user-vlan¼°¸ø¸ÃVLANÌí¼Ó¶Ë¿ÚµÄÅäÖá£

±í2-1 ÅäÖÃisolate-user-vlan

*×÷ ÃüÁî

´´½¨VLAN vlan vlan-id

ÉèÖÃVLANÀàÐÍΪisolate-user-vlan isolate-user-vlan enable

È¡ÏûVLANΪisolate-user-vlanµÄÉèÖà undo isolate-user-vlan enable

Ïòisolate-user-vlanÖÐÌí¼Ó¶Ë¿Ú port interface-list



Ò» ̨ÒÔÌ«Íø½»»»»ú¿ÉÒÔÓжà¸öisolate-user-vlan£¬¿ÉÒÔΪÿ¸öisolate-user-vlanÖ¸¶¨¶à¸ö¶Ë¿Ú¡£isolate-user- vlan²»ÄܺÍTrunk¶Ë¿ÚͬʱÅäÖ㬼´Èç¹ûÒÔÌ«Íø½»»»»úÉÏÅäÖÃÁËisolate-user-vlan£¬¾Í²»ÄÜÅäÖÃTrunk¶Ë¿Ú£»Èç¹ûÅäÖÃÁË Trunk¶Ë¿Ú£¬¾Í²»ÄÜÅäÖÃisolate-user-vlan¡£´ËÍ⣬ÉÏÐж˿ڱØÐëÌí¼Óµ½ÁËisolate-user-vlanÖС£

2.2.2 ÅäÖÃSecondary VLAN

¿ÉÒÔʹÓÃÏÂÃæµÄÃüÁîÀ´´´½¨Secondary VLAN£¬²¢ÎªSecondary VLANÖ¸¶¨¶Ë¿Ú¡£

ÇëÔÚϵͳÊÓͼϽøÐÐÏÂÁÐÅäÖá£

±í2-2 ÅäÖÃSecondary VLAN

*×÷ ÃüÁî

´´½¨Secondary VLAN vlan vlan-id

ÏòSecondary VLANÖÐÌí¼Ó¶Ë¿Ú port interface-list



¿ÉÒÔÏòÿһ¸öSecondary VLANÖÐÌí¼Ó¶à¸ö¶Ë¿Ú£¨·ÇÉÏÐж˿ڣ©¡£

2.2.3 ÅäÖÃisolate-user-vlanºÍSecondary VLAN¼äµÄÓ³Éä¹ØÏµ

¿ÉÒÔʹÓÃÏÂÃæµÄÃüÁîÀ´½¨Á¢isolate-user-vlanºÍSecondary VLANÖ®¼äµÄÓ³Éä¹ØÏµ¡£

ÇëÔÚϵͳÊÓͼϽøÐÐÏÂÁÐÅäÖá£

±í2-3 ÅäÖÃisolate-user-vlanºÍSecondary VLAN¼äµÄÓ³Éä¹ØÏµ

*×÷ ÃüÁî

Åä ÖÃisolate-user-vlanºÍSecondary VLAN¼äµÄÓ³Éä¹ØÏµ isolate-user-vlan isolate-user-vlan_num secondary secondary_vlan_numlist [ to secondary_vlan_numlist ]

È¡ÏûÅäÖÃisolate-user-vlanºÍSecondary VLAN¼äµÄÓ³Éä¹ØÏµ undo isolate-user-vlan isolate-user-vlan_num [secondary secondary_vlan_numlist [ to secondary_vlan_numlist ]



ÐèҪעÒâµÄÊÇ£¬Ö´ÐиÃÃüÁîǰ£¬isolate-user-vlanºÍSecondary VLANÖж¼±ØÐëÒѾ­°üº¬Á˶˿ڡ£×î¶à¿ÉÒÔÏòÒ»¸öisolate-user-vlanÖÐÓ³Éä30¸öSecondary VLAN¡£

½¨Á¢Ó³Éä¹ØÏµºó£¬Ïòisolate-user-vlanºÍSecondary VLANÖÐÌí¼ÓºÍɾ³ý¶Ë¿ÚÒÔ¼°É¾³ýVLANµÄ*×÷±»ÏµÍ³½ûÖ¹¡£Ö»ÓÐÔÚ½â³ýÁËÓ³Éä¹ØÏµºó²Å¿ÉÒÔÖ´ÐС£

undo isolate-user-vlanÃüÁîÈç¹û²»´ø²ÎÊýsecondary secondary_vlan_numlistµÄ»°£¬¾Í½â³ýËùÓÐSecondary VLANºÍÖ¸¶¨isolate-user-vlanµÄÓ³Éä¹ØÏµ£»Èç¹û´øÓиòÎÊýµÄ»°¾Í½â³ý²ÎÊýÖ¸¶¨µÄSecondary VLANºÍÖ¸¶¨isolate-user-vlanµÄÓ³Éä¹ØÏµ¡£

2.3 isolate-user-vlanÏÔʾºÍµ÷ÊÔ

ÔÚÍê³ÉÉÏÊöÅäÖúó£¬ÔÚËùÓÐÊÓͼ?´ÐÐdisplayÃüÁî¿ÉÒÔÏÔʾÅäÖúóisolate-user-vlanµÄÔËÐÐÇé¿ö£¬Í¨¹ý²é¿´ÏÔʾÐÅÏ¢ÑéÖ¤ÅäÖõÄЧ¹û¡£

±í2-4 isolate-user-vlanµÄÏÔʾÓëµ÷ÊÔ

*×÷ ÃüÁî

ÏÔʾisolate-user-vlanºÍSecondary VLANµÄÓ³Éä¹ØÏµ display isolate-user-vlan [isolate-user-vlan_num | secondary_vlan_numlist ]

ÏÔʾVLANÐÅÏ¢ display vlan [ vlan-id ]



2.4 isolate-user-vlanµäÐÍÅäÖþÙÀý

1. ×éÍøÐèÇó

Switch AÌ«Íø½»»»»úϽÓSwitch B¡¢Switch CÒÔÌ«Íø½»»»»ú¡£Switch BÉϵÄVLAN5Ϊisolate-user-vlan£¬°üº¬ÉÏÐж˿ÚEthernet 1/1ºÍÁ½¸öSecondary VLAN£ºVLAN2ºÍVLAN3£¬VLAN3°üº¬¶Ë¿ÚEthernet 0/1£¬VLAN2°üº¬¶Ë¿ÚEthernet 0/2£»Switch CÉϵÄVLAN6Ϊisolate-user-vlan£¬°üº¬ÉÏÐж˿ÚEthernet 1/1ºÍÁ½¸öSecondary VLAN£ºVLAN3ºÍVLAN4£¬VLAN3°üº¬¶Ë¿ÚEthernet 0/3£¬VLAN4°üº¬¶Ë¿ÚEthernet 0/4¡£´ÓSwitch A ¿´£¬Ï½ӵÄSwitch B¡¢Switch C¶¼Ö»ÓÐÒ»¸öVLAN£ºVLAN 5 ºÍVLAN 6¡£

2. ×éÍøÍ¼



ͼ2-1 isolate-user-vlanÅäÖÃ×éÍøÍ¼

3. ÅäÖò½Öè

ÏÂÃæÖ»ÁгöSwitch BºÍSwitch CµÄÅäÖùý³Ì¡£

ÅäÖÃSwitch B£º

# ÅäÖÃisolate-user-vlan¡£

[Quidway] vlan 5

[Quidway-vlan5] isolate-user-vlan enable

[Quidway-vlan5] port ethernet 1/1

# ÅäÖÃSecondary VLAN¡£

[Quidway-vlan5] vlan 3

[Quidway-vlan3] port ethernet 0/1

[Quidway-vlan3] quit

[Quidway] vlan 2

[Quidway-vlan2] port ethernet 0/2

[Quidway-vlan2] quit

# ÅäÖÃisolate-user-vlanºÍSecondary VLAN¼äµÄÓ³Éä¹ØÏµ¡£

[Quidway] isolate-user-vlan 5 secondary 2 to 3

ÅäÖÃSwitch C£º

# ÅäÖÃisolate-user-vlan¡£

[Quidway] vlan 6

[Quidway-vlan6] isolate-user-vlan enable

[Quidway-vlan6] port ethernet 1/1

# ÅäÖÃSecondary VLAN¡£

[Quidway] vlan 3

[Quidway-vlan3] port ethernet 0/3

[Quidway-vlan3] quit

[Quidway] vlan 4

[Quidway-vlan4] port ethernet 0/4

[Quidway-vlan4] quit

# ÅäÖÃisolate-user-vlanºÍSecondary VLAN¼äµÄÓ³Éä¹ØÏµ¡£

[Quidway] isolate-user-vlan 6 secondary 3 to 4
 
2007-03-29 0:11

µÚÒ»²½£¬ÔÚ×÷Ϊ·þÎñÆ÷µÄ΢»úÉϰ²×°Á½¿éÍø¿¨£¬Áª½Óµ½ISPµÄÍø¿¨È¡Ãû"ÍâÍø¿¨"£¬Áª½Óµ½¾ÖÓòÍøµÄÍø¿¨È¡Ãû"ÄÚÍø¿¨"£»

¡¡¡¡µÚ¶þ²½£¬ÔÚ"ÍâÍø¿¨"ÉÏÅäÖÃIPµØÖ·ºÍ×ÓÍøÑÚÂ루ÓÉISPÌṩ£©£¬ÈçIPÊÇ10.32.101.11,×ÓÍøÑÚÂëÊÇ255.255.255.0(±íʾ¾ÖÓòÍø¹æÄ£Ð¡ÓÚ256̨);ÆäËü¶¼°´ISPµÄÒªÇóÉèÖá£×¢Ò⣺ÏÂÃæµÄ²Ù×÷Êǹؼü£º

¡¡¡¡1¡¢ÔÚWindows 2000²Ù×÷ϵͳÖУ¬Ë«»÷"ÍâÍø¿¨"Á¬½ÓÊôÐÔ£¬Ñ¡"¹²Ïí"±êÇ©£¬Ñ¡ÖÐ"ÆôÓôËÁ¬½ÓµÄInternetÁ¬½Ó¹²Ïí"Ïî¡£

¡¡¡¡2¡¢ÔÚ£×indows 98²Ù×÷ϵͳÖУ¬µãÉèÖ㬿ØÖÆÃæ°å£¬Ë«»÷InternetÑ¡Ïµã"Á¬½Ó"±êÇ©£¬µ¥»÷"¾ÖÓòÍøÉèÖÃ"ϵÄ"¹²Ïí"Ñ¡ÏѡÖÐ"ÆôÓôËÁ¬½ÓµÄInternetÁ¬½Ó¹²Ïí"Ïî¡£

¡¡¡¡µÚÈý²½£¬"ÄÚÍø¿¨"IPµØÖ·ÉèΪ£º192.168.0.1¡£

¡¡¡¡µÚËIJ½£¬¾ÖÓòÍøÖÐÆäËü¿Í»§»úÍø¿¨¾²Ì¬ÉèÖÃΪ192.168.0.2µ½192.168.0.253Ö®¼äµÄÈκÎIPµØÖ·£¬Íø¹Ø¡¢DNS¾ùÉèΪ192.168.0.1£¨¼´·þÎñÆ÷"ÄÚÍø¿¨"µÄIPµØÖ·£©£¬ÕÕ´ËÉèÖ㬼´¿É¹²ÏíÒ»ÌõÏß·Á¬ÉÏInternet£¬ºÜ¼òµ¥°É¡£

 
2007-03-29 0:01

ÎÊ:±¾¹«Ë¾¼ÆËã»úÊýÁ¿²»¶à£¬´ó¸ÅÓÐ50̨×óÓÒ£¬×ܹ²·ÖÁ½¸ö²¿ÃÅ¡£Ò»¸öÊÇÅàѵ²¿Ò»¸öÊǹ¤³Ì²¿¡£ÍøÂç½á¹¹ÒªÇóÕâÁ½¸ö²¿ÃŵļÆËã»ú·ÖÊôÓÚ²»Í¬µÄ×ÓÍø£¬ÕâÑùÔÚ¹ÜÀíºÍ°²È«·½Ãæ¶¼ÓÐËù±£ÕÏ£¬È»¶øÁ½¸ö×ÓÍøÖ®¼äÓÖÒªÇóÄܹ»»¥Á¬£¬Ò²¾ÍÊÇ˵ÔÚ¹¤³Ì²¿µÄ¼ÆËã»ú¿ÉÒÔ·ÃÎʵ½Åàѵ²¿£¬ÏàÓ¦µÄÅàѵ²¿ÃŵļÆËã»úÒ²¿ÉÒÔ·ÃÎʵ½¹¤³Ì²¿ÖеÄÍøÂçÉ豸¡£ÓÉÓÚ¹«Ë¾¾­·ÑÓÐÏÞûÓйºÂò·ÓÉÆ÷»òÈý²ã½»»»»ú£¬ÓÐûÓа취Äܹ»ÊµÏÖÕâ¸öÒªÇóÄØ£¿ÂíÉϾÍҪʵʩÁË£¡¼±£¡Ð»Ð»ÁË£¡

¡¡¡¡´ð:Õâ¸öÏÖÏó±È½ÏÆÕ±é£¬ÌرðÊÇÔÚÓлú·¿µÄ¹«Ë¾ÖУ¬»ú·¿Ö÷ÒªÓÃÓÚÅàѵʹÓã¬ÕâÑùΪÁËÌá¸ß°²È«»ú·¿ÖмÆËã»úÉèÖõÄIPµØÖ·ËùÔÚ×ÓÍøºÍ°ì¹«ÊÒÖеÄIPµØÖ·×ÓÍø²»Í¬¡£È»¶øÊµ¼ÊÖÐÓÖÏ£Íû»ú·¿ºÍ°ì¹«ÊÒ¿ÉÒÔ»¥Á¬£¬ÕâÖÖÏÖÏóºÍÉÏÃæÍøÓÑÌá³öµÄÎÊÌâÊÇÒ»ÑùµÄ¡£

¡¡¡¡ÈçºÎ½â¾öÕâ¸öÎÊÌâÄØ£¿Ê×ÏÈÒª½éÉÜÏÂʹÓ÷ÓÉÆ÷»òÈý²ã½»»»»úʵÏÖ¸ÃÒªÇóµÄ·½·¨£¬Èç¹û¹«Ë¾Óо­·ÑµÄ»°¿ÉÒÔ¹ºÂòһ̨·Óɽ»»»É豸£¬ÕâÑùΪÕâ¸öÉ豸Á½¸öÒÔÌ«Íø¶Ë¿ÚÉèÖò»Í¬µÄIPµØÖ·£¬ÀýÈç192.168.1.254ºÍ10.91.30.254¡£È»ºó½«10.91.30.0Íø¶ÎµÄ¼ÆËã»ú½ÓÈë 10.91.30.254½Ó¿Ú£¬½«192.168.1.0Íø¶Î¼ÆËã»úÁ¬½Óµ½192.168.1.254½Ó¿ÚÉÏ¡£ÓÉÓÚĬÈÏÇé¿öÏ·ÓÉÆ÷ºÍÈý²ã½»»»»ú¶¼¾ß±¸¶Ë¿ÚºÍÍøÂçʶ±ðµÄ¹¦ÄÜ£¬ËùÒÔ²»ÐèÒªÅäÖÃÈκηÓÉÁ½¸ö½Ó¿Ú¾Í¿ÉÒÔ»¥ÏàPINGͨÁË£¬·ÃÎÊÆð¹²Ïí×ÊÔ´À´Ò²Ã»ÓÐһ˿ÎÊÌâ¡£

¡¡¡¡µ±È»Èç¹û¹«Ë¾Ã»ÓзÑÓùºÂò·Óɽ»»»É豸µÄ»°£¬ÕýÈçÉÏÃæÍøÓÑËùÎʵÄÒ»Ñù£¬ÈçºÎ½â¾öÄØ£¿Æäʵ¿ÉÒÔʹÓüÆËã»ú×ÔÐн¨Á¢Â·Óɵķ½·¨£¬Ò²¾ÍÊÇ˵ÕÒµ½Ò»Ì¨ÅäÖÃÖеȵļÆËã»ú£¬°²×°Á½¸öÍø¿¨²¢Ìí¼Ó·Óɼ°Ô¶³Ì²¦ºÅ·ÃÎÊ×é¼þ£¬½Ó×ÅÅäÖ÷Óɼ°Ô¶³Ì²¦ºÅ·ÃÎÊ£¬ÈÃÕą̂¼ÆËã»úÆðµ½Â·Óɹ¦ÄÜ£¬³äµ±Â·ÓÉÆ÷µÄ½ÇÉ«¡£Ò»¸öÍø¿¨½ÓÒ»¸öÍø¶Î£¬´Ó¶øÊµÏÖÁËÍøÓѵÄÒªÇó¡£ÏÂÃæ¾ÍÇë¸úËæ±ÊÕßÒ»ÆðÒ»²½²½µÄÉèÖ÷Óɼ°Ô¶³Ì²¦ºÅ·ÃÎÊ¡£Êµ¼Ê»·¾³ÖбÊÕßÊÇÔÚwindows server 2003ÏÂÅäÖø÷þÎñ£¬µ±È»windows 2000 serverÖеÄÅäÖ÷½·¨Ò²ÊÇÀàËÆµÄ¡£

¡¡¡¡»·¾³ÃèÊö£º¹«Ë¾ÒªÇóÁ½¸öÍøÂ磬һ¸öÊÇ10.91.30.*£¬Ò»¸öÊÇ192.168.0.*£¬ÒªÇóÈÃÕâÁ½¸öÍøÂ绥Á¬£¬Ê¹ÓÃһ̨¼ÆËã»ú³äµ±Â·ÓÉÆ÷½ÇÉ«¡£

¡¡¡¡µÚÒ»²½£ºÕÒµ½Á½¿éÍø¿¨ºÍһ̨¼ÆËã»ú£¬È»ºó½ÓÔÚÆäPCI²å²ÛÖС£°²×°windows 2003²Ù×÷ϵͳ£¬Íø¿¨µÄÇý¶¯³ÌÐò»á×Ô¶¯°²×°¡£°²×°Íê±Ïºó»áÔÚ¡°ÍøÉÏÁÚ¾Ó¡ª>ÊôÐÔ¡ª>±¾µØÁ¬½Ó¡±¿´µ½³öÏÖÁË¡°±¾µØÁ¬½Ó¡±ºÍ¡°±¾µØÁ¬½Ó2¡±£¬±íÃ÷Íø¿¨°²×°¼°¹¤×÷Õý³£¡££¨Èçͼ1£©

ͼ1 µã»÷¿´´óͼ

¡¡¡¡µÚ¶þ²½£ºË«»÷¡°±¾µØÁ¬½Ó¡±Í¼±ê£¬È»ºóµã¡°ÊôÐÔ¡±°´Å¥¡£ÔÚ³£¹æ±êÇ©ÖÐË«»÷internetЭÒ飨TCP/IP£©£¬ÉèÖñ¾µØÁ¬½Ó1¶ÔÓ¦µÄIPµØÖ·µÈÐÅÏ¢¡£ÆäÖÐIPµØÖ·ÉèÖÃΪ192.168.0.1£¬×ÓÍøÑÚÂëΪ255.255.255.0£¬Ä¬ÈÏÍø¹Ø¿Õ×Ų»ÌDNS·þÎñÆ÷Ò²ÊÇ192.168.0.1¡££¨Èçͼ 2£©

ͼ2

¡¡¡¡µÚÈý²½£º½Ó×ÅÅäÖá°±¾µØÁ¬½Ó2¡±µÄÊôÐÔ£¬Ë«»÷¡°±¾µØÁ¬½Ó2¡±Í¼±ê£¬È»ºóµã¡°ÊôÐÔ¡±°´Å¥¡£ÔÚ³£¹æ±êÇ©ÖÐË«»÷internetЭÒ飨TCP/IP£©£¬ÉèÖñ¾µØÁ¬½Ó2¶ÔÓ¦µÄIPµØÖ·µÈÐÅÏ¢¡£ÆäÖÐIPµØÖ·ÉèÖÃΪ10.91.30.45£¬×ÓÍøÑÚÂëΪ255.255.255.0£¬Íø¹ØÈÔÈ»¿Õ×Ų»Ìî¡£DNSµØÖ·Ò²Îª 10.91.30.45¡£

¡¡¡¡Ð¡Ìáʾ£ºÓÉÓÚ±ÊÕßËùÔÚ¹«Ë¾10.91.30.*Íø¶ÎµÄ10.91.30.1ºÍ10.91.30.254 ÊÇÁíÍâÁ½Ì¨ÌṩÊý¾Ý¿â·þÎñµÄ·þÎñÆ÷£¬ËùÒÔÕą̂·ÓÉ·þÎñÆ÷Íø¿¨2Ö»ÄÜÉèÖÃIPµØÖ·Îª10.91.30.45ÁË¡£µ±È»¶ÔÓÚ´ó¶àÊýÇé¿öÀ´ËµÈç¹ûÒª»¥Á¬Á½¸öÍø¶Î×îºÃ»¹ÊÇʹÓÃ10.91.30.1ÒÔ¼°10.91.30.254ÕâÑùµÄÐÎʽ¡£

¡¡¡¡µÚËIJ½£ºÈ»ºóÎÒÃDzéѯÅäÖÃÊÇ·ñÕýÈ·£¬Í¨¹ýÈÎÎñÀ¸µÄ¡°¿ªÊ¼->ÔËÐÐ->ÊäÈëCMD¡±£¬½øÈëÃüÁîÐÐģʽ£¬È»ºóÊäÈëipconfig¡£Äã»á¿´µ½¸Õ²ÅÅäÖõÄËùÓÐÐÅÏ¢£¬°üÀ¨Íø¿¨1ºÍÍø¿¨2µÄÍøÂç²ÎÊý¡££¨Èçͼ3£©

ͼ3 µã»÷¿´´óͼ

¡¡¡¡µÚÎå²½£ºÕâʱ½«Á¬½Ó192.168.0.*µÄÍøÏß½Óµ½Íø¿¨1ÉÏ£¬½«Á¬½Ó10.91.30.*µÄÍøÏß½Óµ½Íø¿¨2ÉÏ£¬ÎÒÃÇͨ¹ýpingÕâÁ½¸öÍø¶Î¼ÆËã»úµÄ IPÀ´²éѯÁ¬½ÓÇé¿ö£¬Èç¹ûÔڳ䵱·ÓÉÆ÷ÄÇ̨¼ÆËã»úÉÏpingÁ½¸öÍø¶ÎµÄ¼ÆËã»ú¶¼Í¨µÄ»°¾Í±íÃ÷Ïß·Á¬½ÓûÓÐÎÊÌ⣬ÎÒÃÇ¿ÉÒÔ¼ÌÐøÏÂÃæµÄ²Ù×÷ÁË¡££¨Èçͼ4£©

ͼ4 µã»÷¿´´óͼ

¡¡¡¡µÚÁù²½£ºÔÚwindows2003ÖÐͨ¹ýÈÎÎñÀ¸µÄ¡°¿ªÊ¼->ÔËÐÐ->¹ÜÀí¹¤¾ß->·ÓɺÍÔ¶³Ì·ÃÎÊ¡±À´½øÒ»²½ÅäÖᣣ¨Èçͼ5£©

ͼ5 µã»÷¿´´óͼ

¡¡¡¡µÚÆß²½£º¿ÉÄÜÄã»á·¢ÏÖ·ÓɺÍÔ¶³Ì·ÃÎÊÖС°±¾µØ¡±¼ÆËã»úµÄͼ±êÊǺìÉ«µÄ£¬Ò²¾ÍÊÇ˵ûÓÐÆôÓûòÕßÅäÖᣣ¨Èçͼ6£©ÕâÊÇÒòΪ·þÎñÔÚµ·¹í£¬ÎÒÃÇͨ¹ý¡°¿ªÊ¼- >ÔËÐÐ->ÊäÈëservices.msc¡±½øÈë·þÎñÉèÖô°¿Ú£¬Äã»á·¢ÏÖÔ­À´routing and remote access·þÎñ±»½ûÓÃÁË¡££¨Èçͼ7£©½«ÆäÉèÖÃΪ×Ô¶¯Æô¶¯ºó¾ÍÄܽâ¾öÉÏÃæµÄÎÊÌâ¡££¨Èçͼ9£©

ͼ6 µã»÷¿´´óͼ

ͼ7

ͼ8

¡¡¡¡µÚ°Ë²½£ºÔÙ´ÎÀ´µ½¡°Â·ÓɺÍÔ¶³Ì·ÃÎÊ¡±ÉèÖô°¿Ú£¬ÔÚ¡°softer±¾µØ¡±ÉϵãÊó±êÓÒ¼ü£¬Ñ¡Ôñ¡°ÅäÖò¢ÆôÓ÷ÓɺÍÔ¶³Ì·ÃÎÊ¡±¡£¿ªÊ¼ÉèÖ÷ÓɺÍÔ¶³Ì·ÃÎÊ¡££¨Èçͼ9£©

ͼ9 µã»÷¿´´óͼ

¡¡¡¡µÚ¾Å²½£ºÊ×ÏȳöÏÖ»¶Ó­Ê¹Ó÷ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñÆ÷°²×°Ïòµ¼¡£ÎÒÃǵ㡰ÏÂÒ»²½¡±¼ÌÐø¡££¨Èçͼ10£©

ͼ10

¡¡¡¡µÚÊ®²½£ºÔÚÅäÖô°¿ÚÖÐÎÒÃÇÑ¡Ôñ¡°Á½¸öרÓÃÍøÂçÖ®¼äµÄ°²È«Á¬½Ó¡±¡£È»ºóµã¡°ÏÂÒ»²½¡±¼ÌÐø¡££¨Èçͼ11£©

ͼ11

¡¡¡¡µÚʮһ²½£ºÏµÍ³½«×Ô¶¯ÆôÓ÷ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ¡££¨Èçͼ12£©

ͼ12

¡¡¡¡µÚÊ®¶þ²½£ºÆôÓöøÎÒÃǾͿÉÒÔÔÚ192.168.0.*ÍøÂçÖеļÆËã»úpingͨ10.91.30.*ÍøÂçÖеļÆËã»úÁË£¬·ÃÎʹ²Ïí×ÊԴҲûÓÐÈκÎÎÊÌâ¡££¨Èçͼ13£©

ͼ13 µã»÷¿´´óͼ

¡¡¡¡Ð¡Ìáʾ£ºÊµ¼ÊÉϵ±»¥Á¬Á½¸öÍøÂçʱ¿ÉÒÔ²»ÔÚ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñÖÐÆôÓö¯Ì¬Â·ÓÉ·¢ÏÖЭÒ飬ÒòΪ×é¼þ»á×Ô¶¯ÕÒµ½Ö±Á¬µÄÁ½¸öÍøÂç¡£µ±»¥Á¬ÍøÂç¶à»òÕßÍøÂçÌøÔ¾µã±È½Ï¶àµÄʱºò¾ÍÐèÒªÔÚ·ÓɺÍÔ¶³Ì·ÃÎÊÖÐÆôÓÃÏàÓ¦µÄ¶¯Ì¬Â·ÓÉЭÒéÁË£¬ÀýÈçripµÈ¡£

¡¡¡¡µ±È»ÎÒÃÇÔÚ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñÆ÷°²×°Ïòµ¼³öÏÖÅäÖô°¿Úʱ²»Ñ¡Ôñ¡°Á½¸öרÓÃÍøÂçÖ®¼äµÄ°²È«Á¬½Ó¡±Ò²ÊÇ¿ÉÒԵģ¬ÀýÈçÑ¡Ôñ¡°×Ô¶¨ÒåÅäÖᱡ££¨Èçͼ14£©È»¶ø¹´Ñ¡LAN·Óɼ´¿É¡££¨Èçͼ15£©Õâ¸ö·½·¨ºÍÉÏÃæÌáµ½µÄ·½·¨Ð§¹ûÊÇÒ»ÑùµÄ£¬Á½¸öÍøÂ绥·Ã¶¼ÊÇûÓÐÎÊÌâµÄ¡£ÁíÍâÔÚÉèÖÃÍø¿¨ÍøÂç²ÎÊýʱ¿ÉÒÔ½«Íø¹ØµØÖ·ÉèÖÃΪ×Ô¼º£¬Í¬Ñù²»Ó°ÏìʹÓá£ÀýÈç±¾µØÁ¬½Ó´¦µÄĬÈÏÍø¹ØÒ²Ìîд192.168.0.1¡£

ͼ14

ͼ15

×ܽ᣺

¡¡¡¡Â·ÓɺÍÔ¶³Ì²¦ºÅ·ÃÎÊʹÓõķ¶Î§»¹ÊÇÏ൱¹ã·ºµÄ£¬¿ÉÒÔ»¥Á¬Á½¸öÍø¶Î»òÕßÈý¸öÍø¶Î£¬¿ÉÒÔÆôÓÃNAT¹¦Äܱ£»¤ÄÚÍø¼ÆËã»úµÄ°²È«£¬Ò²¿ÉÒÔÉèÖÃVPN±£Ö¤ÆóÒµ¶à×Ó²¿ÃŰ²È«Á¬½Ó¡£¸ÐÐËȤµÄ¶ÁÕß¿ÉÒÔ×ÔÐÐÑо¿£¬ÎÒÃÇIT168·þÎñÆ÷ƵµÀÒ²»á×öÏà¹ØµÄºóÐø±¨µÀ¡£

 
2007-03-28 23:32

»ªÎª6500ϵÁÐ×÷ΪÆóÒµ¼¶ºËÐĽ»»»»úʹÓÃÔÚÏîĿʵʩÖл¹ÊǾ­³£»áÓöµ½µÄ£¬´Ë´Î½èǰ½×¶ÎÒ»ÏîÄ¿ÖÐÅäÖûªÎª-3Com 6506ºËÐĽ»»»»ú£¬Ïò´ó¼Ò¹²ÏíһϸÃÅäÖ㬲¢Å䱸עÊÍÎÄ×Ö¡£ÎªÁ˱ÜÃâ²úÉúÇÖȨÎÊÌ⣬ÅäÖÃÖÐÒþÈ¥Á˸ÿͻ§É豸µÄÕæÊµÃû³Æ¡£

¼òµ¥ÃèÊöһϻ·¾³£º

¾ÖÓòÍø»·¾³£¬ºÜ¼òµ¥£¬²ÉÓÃCore-Access½á¹¹£¬ºËÐÄÉ豸6506ÓëÁíһ̨3500ϵÁкËÐĽ»»»»úÅäÖóÉΪVRRPÈÈÈßÓà×飬ÌṩºËÐĽ»»»¹¦ÄÜ¡£µ×ϽÓÈë½»»»»ú²ÉÓÃ3000ϵÁпìËÙÒÔÌ«Íø½»»»»úÒÔTrunk·½Ê½ÉÏÁªºËÐĽ»»»»ú£¬ÌṩÁ´Â·ÈßÓ༰Éú³ÉÊ÷¹¦ÄÜ¡£Ê¹ÓÃVlan»®·Ö¹¦ÄÜ×ÓÍø£¬ÌṩÈý²ã·ÓÉ¡£ AAAÈÏÖ¤¼°·ÃÎÊ¿ØÖÆÔÚ¸ÃÅäÖÃÎļþÖÐÔÝʱûÓнøÐйý¶àÉèÖá£

¸öÈËÄÜÁ¦ÓÐÏÞ£¬Èç¹û×¢ÊÍÖÐÓв»Çå³þ»ò´íÎóµÄµØ·½£¬ÍûÖ¸Õý£¬Ð»Ð»¡£

dis cur

#

sysname HuaweiOfLeonhart {²»±ã͸¶Óû§É豸Ãû³Æ}

#

super password level 3 simple huawei {ÅäÖÃÇл»µÍ¼¶±ðÓû§µ½¸ß¼¶±ðÓû§µÄÃÜÂë}

#

radius scheme system {Ö¸¶¨µ±Ç°ISPÓòÒýÓõÄRADIUS·þÎñÆ÷×é¡£´Ë´¦RADIUS·þÎñÆ÷×éÃûΪ¡°system¡±}

server-type huawei {ÅäÖÃÖ¸¶¨Óû§µÄ·þÎñÀàÐÍ}

primary authentication 127.0.0.1 1645 {ÅäÖÃÖ÷RADIUSÈÏÖ¤/ÊÚȨµÄIPµØÖ·ºÍ¶Ë¿ÚºÅ,Ŀǰ»·¾³Ã»ÓÐAAA·þÎñÆ÷}

primary accounting 127.0.0.1 1646 {ÅäÖÃÖ÷RADIUS¼Æ·Ñ·þÎñÆ÷µÄIPµØÖ·ºÍ¶Ë¿ÚºÅ}

user-name-format without-domain {ÅäÖ÷¢Ë͸øRADIUS·þÎñÆ÷µÄÓû§Ãû¸ñʽ¡£Ö¸¶¨·¢Ë͸øRADIUS·þÎñÆ÷µÄÓû§Ãû²»´øÓòÃû}

domain system {´´½¨Ò»¸öISPÓò£¬È±Ê¡Çé¿öÏ£¬ÏµÍ³ÖÐÒÑ´´½¨ÁËÒ»¸öÃûΪ¡°system¡±µÄISPÓò¡£ISPÓò¼´ISPÓû§Èº£¬Ò»¸öISPÓò¼´ÊÇÓÉͬÊôÓÚÒ»¸ö ISPµÄÓû§¹¹³ÉµÄÓû§Èº¡£ÒýÈëISPÓòµÄÉèÖÃÊÇΪÁËÖ§³Ö¶àISPµÄÓ¦Óû·¾³£ºÔÚÕâÖÖ»·¾³ÖУ¬Í¬Ò»¸ö½ÓÈëÉ豸½ÓÈëµÄÓпÉÄÜÊDz»Í¬ISPµÄÓû§¡£ÓÉÓÚ¸÷ ISPÓû§µÄÓû§ÊôÐÔ£¨ÀýÈçÓû§Ãû¼°ÃÜÂë¹¹³É¡¢·þÎñÀàÐÍ/ȨÏ޵ȣ©ÓпÉÄܸ÷²»Ïàͬ£¬Òò´ËÓбØÒªÍ¨¹ýÉèÖÃISPÓòµÄ·½·¨°ÑËüÃÇÇø±ð¿ª¡£ÔÚISPÓòÊÓͼÏ£¬¿ÉÒÔΪÿ¸öISPÓòÅäÖðüÀ¨AAA²ßÂÔ£¨Ê¹ÓõÄRADIUS·þÎñÆ÷×éµÈ£©ÔÚÄÚµÄÒ»ÕûÌ×µ¥¶ÀµÄISPÓòÊôÐÔ¡£¶ÔÓÚ½»»»»úÀ´Ëµ£¬Ã¿¸ö½ÓÈëÓû§¶¼ÊôÓÚÒ»¸öISP Óò¡£ÏµÍ³ÖÐ×î¶à¿ÉÒÔÅäÖÃ16¸öISPÓò¡£}

radius-scheme system

access-limit disable {±íʾ²»¶Ôµ±Ç°ISPÓò¿ÉÈÝÄɵĽÓÈëÓû§Êý×÷ÏÞÖÆ}

state active {Ö¸¶¨µ±Ç°ISPÓò/µ±Ç°Óû§´¦Óڻ״̬£¬¼´ÏµÍ³ÔÊÐí¸ÃÓòϵÄÓû§/µ±Ç°Óû§ÇëÇóÍøÂç·þÎñ}

idle-cut disable {ÅäÖõ±Ç°ISPÓòϵÄÓû§Ä£°å,±íʾ½ûÖ¹Óû§ÆôÓÃÏÐÖÃÇжϹ¦ÄÜ}

self-service-url disable

messenger time disable

domain default enable system

#

local-server nas-ip 127.0.0.1 key huawei {ÅäÖñ¾»úRADIUS·þÎñÆ÷µÄÏà¹Ø²ÎÊý£¬nas-ipÓÃÀ´ÅäÖýÓÈë·þÎñÆ÷µÄIPµØÖ·£¬keyÓÃÀ´ÅäÖõǼÓû§µÄÃÜÂë}

#

temperature-limit 0 20 80

temperature-limit 1 10 80

temperature-limit 3 10 80

#

monitor slot 1 disable

monitor slot 3 disable

#

link-aggregation group 1 mode manual {½«Ò»×é¶Ë¿ÚÅäÖÃΪ»ã¾Û¶Ë¿Ú£¬ÅäÖúóϵͳ»á×Ô¶¯ÎªÕâ×é¾ÛºÏ¶Ë¿Ú·ÖÅäÒ»¸ö×éºÅ¡£modeÓÃÀ´´´½¨ÊÖ¹¤»ò¾²Ì¬¾ÛºÏ×飬Ŀǰ»·¾³Îªmanual£ºÊÖ¹¤¾ÛºÏ×é}

#

vrrp ping-enable {ÅäÖñ¸·Ý×éµÄÐéÄâIPµØÖ·¿ÉÒÔ±»pingͨ£¬¿ªÆô¸ÃÃüÁîºó±ãÓÚµ÷ÊÔÈ·ÈϿͻ§»úÓëÐéÄâÍø¹ØµÄÁ¬Í¨ÐÔ,¸öÈËÇ¿ÁÒ½¨Ò鿪Æô¸Ã¹¦ÄÜ}

#

stp instance 0 root primary {ÅäÖÃÉú³ÉÊ÷ʵÀý²¢½«´ËºËÐĽ»»»»úÉèΪÉú³ÉÊ÷¸ù}

stp TC-protection enable

stp enable

#

vlan 1 {´´½¨vlan}

#

vlan 13

#

vlan 14

#

vlan 15

#

vlan 16

#

vlan 17

#

vlan 18

#

vlan 19

#

vlan 20

#

vlan 21

#

vlan 30

#

interface Vlan-interface13 {ÅäÖÃvlanÂß¼­½Ó¿Ú}

ip address 192.168.13.240 255.255.255.0 {ÅäÖÃvlanʵ¼ÊIPµØÖ·}

vrrp vrid 13 virtual-ip 192.168.13.254 {ÅäÖÃvrrpÐéÄâIPµØÖ·}

vrrp vrid 13 priority 110 {ÅäÖÃvrrpÓÅÏȼ¶£¬ÓÅÏȼ¶¸ßµÄ³ÉΪActiveÉ豸}

#

interface Vlan-interface14

ip address 192.168.14.253 255.255.255.0

vrrp vrid 14 virtual-ip 192.168.14.254

vrrp vrid 14 priority 110

#

interface Vlan-interface15

ip address 192.168.15.253 255.255.255.0

vrrp vrid 15 virtual-ip 192.168.15.254

vrrp vrid 15 priority 110

#

interface Vlan-interface16

ip address 192.168.16.253 255.255.255.0

vrrp vrid 16 virtual-ip 192.168.16.254

vrrp vrid 16 priority 110

#

interface Vlan-interface17

ip address 192.168.17.253 255.255.255.0

vrrp vrid 17 virtual-ip 192.168.17.254

vrrp vrid 17 priority 110

#

interface Vlan-interface18

ip address 192.168.18.253 255.255.255.0

vrrp vrid 18 virtual-ip 192.168.18.254

vrrp vrid 18 priority 110

#

interface Vlan-interface19

ip address 192.168.19.253 255.255.255.0

vrrp vrid 19 virtual-ip 192.168.19.254

vrrp vrid 19 priority 110

#

interface Vlan-interface20

ip address 192.168.20.253 255.255.255.0

vrrp vrid 20 virtual-ip 192.168.20.254

vrrp vrid 20 priority 110

#

interface Vlan-interface21

ip address 192.168.21.253 255.255.255.0

vrrp vrid 21 virtual-ip 192.168.21.254

vrrp vrid 21 priority 110

#

interface Vlan-interface30

ip address 192.168.30.253 255.255.255.0

vrrp vrid 30 virtual-ip 192.168.30.254

vrrp vrid 30 priority 110

#

interface Aux0/0/0

#

interface M-Ethernet0/0/0

#

interface GigabitEthernet1/0/1 {ǧÕ׿ìËÙÒÔÌ«¶Ë¿Ú}

#

interface GigabitEthernet1/0/2

#

interface GigabitEthernet1/0/3

#

interface GigabitEthernet1/0/4

#

interface GigabitEthernet1/0/5

#

interface GigabitEthernet1/0/6

#

interface GigabitEthernet1/0/7

#

interface GigabitEthernet1/0/8

#

interface GigabitEthernet3/0/1

port access vlan 20 {ÅäÖö˿ڴÓÊôµÄvlan}

#

interface GigabitEthernet3/0/2

port access vlan 13

#

interface GigabitEthernet3/0/3

port access vlan 13

#

interface GigabitEthernet3/0/4

port access vlan 13

#

interface GigabitEthernet3/0/5

port access vlan 13

#

interface GigabitEthernet3/0/6

port access vlan 13

#

interface GigabitEthernet3/0/7

port access vlan 13

#

interface GigabitEthernet3/0/8

port access vlan 13

#

interface GigabitEthernet3/0/9

port access vlan 13

#

interface GigabitEthernet3/0/10

port access vlan 13

#

interface GigabitEthernet3/0/11

port link-type trunk {ÅäÖÃÒÔÌ«Íø¶Ë¿ÚµÄÁ´Â·ÀàÐÍ£¬ÓÉÓÚ´Ë´¦¸Ã¶Ë¿ÚΪ¶þ¼¶½ÓÈë½»»»»úµÄÉÏÁª¶Ë¿Ú£¬¿ªÆôΪTrunk¶Ë¿Ú}

port trunk permit vlan all {½«Trunk¶Ë¿Ú¼ÓÈëµ½Ö¸¶¨µÄVLAN£¬´Ë´¦ÎªÔÊÐíËùÓÐvlanͨ¹ýTrunk¸ÉµÀ}

#

interface GigabitEthernet3/0/12

port link-type trunk

port trunk permit vlan all

#

interface GigabitEthernet3/0/13

port link-type trunk

port trunk permit vlan all

#

interface GigabitEthernet3/0/14

port link-type trunk

port trunk permit vlan all

#

interface GigabitEthernet3/0/15

port link-type trunk

port trunk permit vlan all

#

interface GigabitEthernet3/0/16

port link-type trunk

port trunk permit vlan all

#

interface GigabitEthernet3/0/17

#

interface GigabitEthernet3/0/18

#

interface GigabitEthernet3/0/19

duplex full {ÅäÖö˿ÚΪȫ˫¹¤}

speed 100 {ÊÖ¹¤ÅäÖøö˿ÚΪ°ÙÕ×ËÙÂÊ}

port link-type trunk

port trunk permit vlan all

port link-aggregation group 1 {½«ÒÔÌ«Íø¶Ë¿Ú¼ÓÈëÊÖ¹¤»ò¾²Ì¬»ã¾Û×飬´Ë´¦¸ù¾ÝÇ°ÃæµÄÅäÖüÓÈëÊÖ¹¤¾ÛºÏ×é1}

#

interface GigabitEthernet3/0/20

duplex full

speed 100

port link-type trunk

port trunk permit vlan all

port link-aggregation group 1

#

interface NULL0

#

user-interface aux 0 {ÅäÖÃConsoleÓû§µÇ¼}

set authentication password simple huawei {ÅäÖñ¾µØÑéÖ¤µÄ¿ÚÁ¿ÉÒÔÒÔÃ÷ÎÄsimple·½Ê½£¬»òÊÇÃÜÎÄ·½Ê½cipher}

user-interface vty 0 4 {ÅäÖÃVTYÓû§µÇ¼}

set authentication password simple huawei {´ÓAUXÓû§½çÃæµÇ¼ºó¿ÉÒÔ·ÃÎʵÄÃüÁî¼¶±ðΪ3¼¶£¬´ÓVTYÓû§½çÃæµÇ¼ºó¿ÉÒÔ·ÃÎʵÄÃüÁî¼¶±ðΪ0¼¶}

 
   
 
 
ÎÄÕ´浵
 
     
 
×îÐÂÎÄÕÂÆÀÂÛ
  

дµÄÒ»¶ÑÀ¬»ø£¬»¹Ã°³ä¸ßÊÖ£¬
 

ÄãºÃ£¬ÇëÎÊÄãÖªµÀ °Ù¶È¿Õ¼ä²©¿ÍµÄMetaWeblog APIÂð£¿
 
 
 
   
°ïÖúÖÐÐÄ | ¿Õ¼ä¿Í·þ | Í¶ËßÖÐÐÄ | ¿Õ¼äЭÒé
©2012 Baidu