拓扑图:
网络情况如下:
用户 1 网络:172.16.1.0/24
用户 2 网络: 192.168.1.0/24
至出口 1 网络:172.16.100.0/24
至出口 2 网络:192.168.100.0/24
实现功能:用户 1 通过互联网出口 1,用户 2 通过互联网出口 2。
功能实现:在三层交换台机上配置默认路由,将数据包丢向 192.168.100.253,再利用策略路由,凡是用户 2 网络 IP192.168.1.0/24 的地址都丢向 172.16.100.253。
配置步骤:
说明:这里接口的配置等操作就不在写了。
1、首先建立默认路由,将所有的数据包都丢往出口 2 的下一节点 192.168.100.253
[H3C5500] ip route-static 0.0.0.0 0.0.0.0 192.168.100.253
2、配置流分类 1,对象为 172.16.1.0/24 的数据
[H3C5500]acl number 3001
[H3C5500-acl-adv-3001] rule 0 permit ip source 172.16.1.0 0.0.0.255
[H3C5500] quit
[H3C5500] traffic classifier 1
[H3C5500-classifier-1] if-match acl 3001
[H3C5500-classifier-1] quit
3、配置刚才定义的流分类的行为,定义如果匹配就下一跳至出口 1 即 172.16.100.253
[H3C5500] traffic behavior 1
[H3C5500-behavior-1] redirect next-hop 172.16.100.253
[H3C5500-behavior-1] quit
4、将刚才设置的应用至 QOS 策略中,定义 policy 1
[H3C5500] qos policy 1
[H3C5500-qospolicy-1] classifier 1 behavior 1
[H3C5500-qospolicy-1] quit
5、在接口上应用定义的 QOS 策略 policy 1
[H3C5500] interface GigabitEthernet 1/0/15
[H3C5500-GigabitEthernet1/0/15] qos apply policy 1 inbound
[H3C5500-GigabitEthernet1/0/15] quit
至此,配置已完成。
配置文件(略过一些接口配置信息):
version 5.20, Release 2102P02
sysname H3C5500
domain default enable system
telnet server enable
vlan 1
vlan 100 to 103
traffic classifier 1 operator and
if-match acl 3001traffic behavior 1
redirect next-hop 172.16.100.253qos policy 1
classifier 1 behavior 1dhcp server ip-pool 1
network 192.168.1.0 mask 255.255.255.0
gateway-list 192.168.1.254
dns-list 221.228.255.1dhcp server ip-pool 2
network 172.16.1.0 mask 255.255.255.0
gateway-list 172.16.1.254
dns-list 221.228.255.1local-user huawei
password cipher .]@USE=B,53Q=^Q`M<1!!
service-type telnet terminal
level 3acl number 3001
rule 0 permit ip source 172.16.1.0 0.0.0.255interface NULL0
interface Vlan-interface1
ip address 192.168.0.254 255.255.255.0interface Vlan-interface100
ip address 192.168.100.254 255.255.255.0interface Vlan-interface101
ip address 192.168.1.254 255.255.255.0interface Vlan-interface102
ip address 172.16.100.254 255.255.255.0interface Vlan-interface103
ip address 172.16.1.254 255.255.255.0interface GigabitEthernet1/0/1
port link-type access
port access vlan 100
speed 1000
duplex fullinterface GigabitEthernet1/0/2
port link-type access
port access vlan 102
speed 1000
duplex fullinterface GigabitEthernet1/0/15
port link-type trunk
port trunk permit vlan 1 101 103
speed 1000
duplex full
qos apply policy 1 inboundinterface GigabitEthernet1/0/16
port link-type trunk
port trunk permit vlan 1 101 103
speed 1000
duplex full
qos apply policy 1 inboundip route-static 0.0.0.0 0.0.0.0 192.168.100.253
dhcp enable
load xml-configuration
user-interface aux 0
authentication-mode scheme
user-interface vty 0 4
authentication-mode scheme
user privilege level 3
return
欢迎来到这里!
我们正在构建一个小众社区,大家在这里相互信任,以平等 • 自由 • 奔放的价值观进行分享交流。最终,希望大家能够找到与自己志同道合的伙伴,共同成长。
注册 关于