柔中带刚,刚中带柔,淫荡中富含柔和,刚猛中荡漾风骚,无坚不摧,无孔不入!
全部博文(1669)
分类: 系统运维
2017-06-14 15:49:34
CE12800系列产品V100R005C10或更高版本。
如所示为某数据中心网络,客户希望构建一个稳定的大二层网络。要求双归接入保证可靠性,同时链路之间进行负载分担提高链路利用率。汇聚层部署VS划分不同的分区,提高机柜的利用率。同时为了满足服务器业务的安全性,在汇聚层旁挂防火墙(SeGW)提供安全防护功能。
本示例中,交换机以CE12804为例,安全网关设备以USG9520为例。
设备名称 |
接口 |
IP地址 |
虚拟IP地址 |
|
---|---|---|---|---|
SwitchA |
管理网口 |
10.1.1.1/24 |
- |
|
SwitchB |
管理网口 |
10.1.1.2/24 |
- |
|
SwitchC |
VS1 |
管理网口 |
10.2.1.1/24 |
- |
VLANIF11 |
10.4.1.1/24 |
10.4.1.111 |
||
VLANIF20 |
10.5.1.1/24 |
10.5.1.111 |
||
VS2 |
管理网口 |
10.3.1.1/24 |
- |
|
VLANIF30 |
10.6.1.1/24 |
10.6.1.111 |
||
VLANIF200 |
10.8.1.1/24 |
- |
||
VLANIF300 |
10.11.1.1/24 |
- |
||
SwitchD |
VS3 |
管理网口 |
10.2.1.2/24 |
- |
VLANIF11 |
10.4.1.2/24 |
10.4.1.111 |
||
VLANIF20 |
10.5.1.2/24 |
10.5.1.111 |
||
VS4 |
管理网口 |
10.3.1.2/24 |
- |
|
VLANIF30 |
10.6.1.2/24 |
10.6.1.111 |
||
VLANIF210 |
10.9.1.1/24 |
- |
||
VLANIF300 |
10.11.1.2/24 |
- |
||
SwitchE |
VLANIF200 |
10.8.1.2/24 |
- |
|
VLANIF400 |
10.12.1.1/24 |
- |
||
SwitchF |
VLANIF210 |
10.9.1.2/24 |
- |
|
VLANIF400 |
10.12.1.2/24 |
- |
||
SeGW A |
GigabitEthernet 3/0/0 |
10.10.0.1/24 |
- |
|
上行接口浮动IP |
10.6.1.3/24 |
- |
||
下行接口浮动IP |
10.5.1.3/24 |
- |
||
SeGW B |
GigabitEthernet 3/0/0 |
10.10.0.2/24 |
- |
|
上行接口浮动IP |
10.6.1.3/24 |
- |
||
下行接口浮动IP |
10.5.1.3/24 |
- |
||
服务器所在网段 |
- |
10.20.20.0/24 |
- |
采用如下的思路配置:
在SwitchC和SwitchD上配置划分VS。
在SwitchA和SwitchB之间、VS1和VS3之间、VS2和VS4之间配置M-LAG,并配置VRPP备份组分别作为用户侧网关和防火墙的下一跳。
配置安全网关设备采用路由模式接入,并启用双机热备功能,采用主备备份方式工作,增强网络的健壮性。
在汇聚层和核心层交换机上使能OSPF。
这里以SwitchC为例,SwitchD的配置与SwitchC类似,不再赘述。
执行命令display dfs-group,查看M-LAG的相关信息。
# 查看DFS Group编号为1的M-LAG信息。(这里以SwitchA和SwitchB组成的M-LAG为例,VS1和VS3、VS2和VS4类似)
[~SwitchA] display dfs-group 1 m-lag * : Local node
Heart beat state : OK Node 1 *
Dfs-Group ID : 1
Priority : 150
Address : ip address 10.1.1.1
State : Master Causation : -
System ID : 0025-9e95-7c31
SysName : SwitchA
Version :
Device Type : CE12800
Node 2
Dfs-Group ID : 1
Priority : 120
Address : ip address 10.1.1.2
State : Backup Causation : -
System ID : 0025-9e95-7c11
SysName : SwitchB
Version :
Device Type : CE12800
# 查看SwitchA上的M-LAG信息。
[~SwitchA] display dfs-group 1 node 1 m-lag brief * - Local node
M-Lag ID Interface Port State Status
1 Eth-Trunk 10 Up active(*)-active
2 Eth-Trunk 20 Up active(*)-active
通过以上显示信息可以看到,“Heart beat state”的状态是“OK”,表明心跳状态正常;SwitchA作为Node 1,优先级为150,“State”的状态是“Master”;SwitchB作为Node 2,优先级为120,“State”的状态是“Backup”。同时“Causation”的状态是“-”,Node 1的“Port State”状态为“Up”,Node 2的“Port State”状态为“Up”,且Node 1和Node 2的M-LAG状态均为“active”,表明M-LAG的配置正确。
在VS1和VS3上分别执行display vrrp命令,可以看到VS1和VS3在备份组中的状态均为Master。
switch virtual-system vs1 display vrrp verbose Vlanif11 | Virtual Router 1 State : Master Virtual IP : 10.4.1.111 Master IP : 10.4.1.1 PriorityRun : 100 PriorityConfig : 100 MasterPriority : 100 Preempt : YES Delay Time : 0s Remain : -- TimerRun : 1s TimerConfig : 1s Auth Type : NONE Virtual MAC : 0000-5e00-0101 Check TTL : YES Config Type : Normal Create Time : 2015-03-20 11:39:18 Last Change Time : 2015-03-25 11:38:58 Vlanif20 | Virtual Router 2 State : Master Virtual IP : 10.5.1.111 Master IP : 10.5.1.1 PriorityRun : 100 PriorityConfig : 100 MasterPriority : 100 Preempt : YES Delay Time : 0s Remain : -- TimerRun : 1s TimerConfig : 1s Auth Type : NONE Virtual MAC : 0000-5e00-0101 Check TTL : YES Config Type : Normal Create Time : 2015-03-20 11:39:18 Last Change Time : 2015-03-25 11:38:58
switch virtual-system vs3 display vrrp verbose Vlanif11 | Virtual Router 1 State : Master Virtual IP : 10.4.1.111 Master IP : 10.4.1.2 PriorityRun : 100 PriorityConfig : 100 MasterPriority : 100 Preempt : YES Delay Time : 0s Remain : -- TimerRun : 1s TimerConfig : 1s Auth Type : NONE Virtual MAC : 0000-5e00-0101 Check TTL : YES Config Type : Normal Create Time : 2015-03-20 11:39:18 Last Change Time : 2015-03-25 11:38:58 Vlanif20 | Virtual Router 2 State : Master Virtual IP : 10.5.1.111 Master IP : 10.5.1.2 PriorityRun : 100 PriorityConfig : 100 MasterPriority : 100 Preempt : YES Delay Time : 0s Remain : -- TimerRun : 1s TimerConfig : 1s Auth Type : NONE Virtual MAC : 0000-5e00-0101 Check TTL : YES Config Type : Normal Create Time : 2015-03-20 11:39:18 Last Change Time : 2015-03-25 11:38:58
在VS2和VS4上分别执行display vrrp命令,可以看到VS2和VS4在备份组中的状态均为Master。
switch virtual-system vs2 display vrrp verbose Vlanif30 | Virtual Router 1 State : Master Virtual IP : 10.6.1.111 Master IP : 10.6.1.1 PriorityRun : 100 PriorityConfig : 100 MasterPriority : 100 Preempt : YES Delay Time : 0s Remain : -- TimerRun : 1s TimerConfig : 1s Auth Type : NONE Virtual MAC : 0000-5e00-0102 Check TTL : YES Config Type : Normal Create Time : 2015-03-20 11:39:18 Last Change Time : 2015-03-25 11:38:58
switch virtual-system vs4 display vrrp verbose Vlanif30 | Virtual Router 1 State : Master Virtual IP : 10.6.1.111 Master IP : 10.6.1.2 PriorityRun : 100 PriorityConfig : 100 MasterPriority : 100 Preempt : YES Delay Time : 0s Remain : -- TimerRun : 1s TimerConfig : 1s Auth Type : NONE Virtual MAC : 0000-5e00-0102 Check TTL : YES Config Type : Normal Create Time : 2015-03-20 11:39:18 Last Change Time : 2015-03-25 11:38:58
在SeGW A上执行display hrp state命令,检查当前HRP的状态,显示以下信息表示HRP建立成功。
HRP_M[SeGWA] display hrp state Role: active, peer: active Running priority: 51008, peer: 51008 Core state: normal, peer: normal Backup channel usage: 0% Stable time: 0 days, 18 hours, 41 minutes
SwitchA的配置文件
# sysname SwitchA # dfs-group 1 priority 150 source ip 10.1.1.1 m-lag up-delay 30 # vlan batch 11 # stp v-stp enable stp mode rstp # interface MEth0/0/0 ip address 10.1.1.1 255.255.255.0 # interface Eth-Trunk0 mode lacp-static peer-link 1 # interface Eth-Trunk10 port default vlan 11 mode lacp-dynamic dfs-group 1 m-lag 1 lacp m-lag priority 10 lacp m-lag system-id 00e0-fc00-0000 # interface Eth-Trunk20 port link-type trunk port trunk allow-pass vlan 11 mode lacp-static dfs-group 1 m-lag 2 lacp m-lag priority 10 lacp m-lag system-id 00e0-fc00-0000 # interface 10GE1/0/1 eth-trunk 10 # interface 10GE1/0/4 eth-trunk 0 # interface 10GE1/0/5 eth-trunk 0 # interface 10GE1/0/6 eth-trunk 20 # interface 10GE1/0/7 eth-trunk 20 # return
SwitchB的配置文件
# sysname SwitchB # dfs-group 1 priority 120 source ip 10.1.1.2 m-lag up-delay 30 # vlan batch 11 # stp v-stp enable stp mode rstp # interface MEth0/0/0 ip address 10.1.1.2 255.255.255.0 # interface Eth-Trunk0 mode lacp-static peer-link 1 # interface Eth-Trunk10 port default vlan 11 mode lacp-dynamic dfs-group 1 m-lag 1 lacp m-lag priority 10 lacp m-lag system-id 00e0-fc00-0000 # interface Eth-Trunk20 port link-type trunk port trunk allow-pass vlan 11 mode lacp-static dfs-group 1 m-lag 2 lacp m-lag priority 10 lacp m-lag system-id 00e0-fc00-0000 # interface 10GE1/0/1 eth-trunk 10 # interface 10GE1/0/4 eth-trunk 0 # interface 10GE1/0/5 eth-trunk 0 # interface 10GE1/0/6 eth-trunk 20 # interface 10GE1/0/7 eth-trunk 20 # return
SwitchC的配置文件
# sysname SwitchC # admin virtual-system vs1 port-mode group resource u4route upper-limit 60000 resource m4route upper-limit 1000 resource u6route upper-limit 16000 resource m6route upper-limit 100 resource vlan upper-limit 4063 resource mpls enable resource trill enable resource mcast enable resource vpn-instance upper-limit 4096 resource cpu weight 5 resource memory ratio-threshold 100 assign interface 10GE1/0/0 assign interface 10GE1/0/1 assign interface 10GE1/0/2 assign interface 10GE1/0/3 assign interface 10GE1/0/4 assign interface 10GE1/0/5 assign interface 10GE1/0/6 assign interface 10GE1/0/7 assign interface 10GE1/0/8 assign interface 10GE1/0/9 assign interface 10GE1/0/10 assign interface 10GE1/0/11 assign interface 10GE1/0/12 assign interface 10GE1/0/13 assign interface 10GE1/0/14 assign interface 10GE1/0/15 assign interface 10GE1/0/16 assign interface 10GE1/0/17 assign interface 10GE1/0/18 assign interface 10GE1/0/19 assign interface 10GE1/0/20 assign interface 10GE1/0/21 assign interface 10GE1/0/22 assign interface 10GE1/0/23 virtual-system vs2 port-mode group resource u4route upper-limit 60000 resource m4route upper-limit 1000 resource u6route upper-limit 16000 resource m6route upper-limit 100 resource vlan upper-limit 4063 resource mpls enable resource trill enable resource mcast enable resource vpn-instance upper-limit 4096 resource cpu weight 5 resource memory ratio-threshold 100 assign interface 10GE1/0/24 assign interface 10GE1/0/25 assign interface 10GE1/0/26 assign interface 10GE1/0/27 assign interface 10GE1/0/28 assign interface 10GE1/0/29 assign interface 10GE1/0/30 assign interface 10GE1/0/31 assign interface 10GE1/0/32 assign interface 10GE1/0/33 assign interface 10GE1/0/34 assign interface 10GE1/0/35 assign interface 10GE1/0/36 assign interface 10GE1/0/37 assign interface 10GE1/0/38 assign interface 10GE1/0/39 assign interface 10GE1/0/40 assign interface 10GE1/0/41 assign interface 10GE1/0/42 assign interface 10GE1/0/43 assign interface 10GE1/0/44 assign interface 10GE1/0/45 assign interface 10GE1/0/46 assign interface 10GE1/0/47 # return
SwitchD的配置文件
# sysname SwitchD # admin virtual-system vs3 port-mode group resource u4route upper-limit 60000 resource m4route upper-limit 1000 resource u6route upper-limit 16000 resource m6route upper-limit 100 resource vlan upper-limit 4063 resource mpls enable resource trill enable resource mcast enable resource vpn-instance upper-limit 4096 resource cpu weight 5 resource memory ratio-threshold 100 assign interface 10GE1/0/0 assign interface 10GE1/0/1 assign interface 10GE1/0/2 assign interface 10GE1/0/3 assign interface 10GE1/0/4 assign interface 10GE1/0/5 assign interface 10GE1/0/6 assign interface 10GE1/0/7 assign interface 10GE1/0/8 assign interface 10GE1/0/9 assign interface 10GE1/0/10 assign interface 10GE1/0/11 assign interface 10GE1/0/12 assign interface 10GE1/0/13 assign interface 10GE1/0/14 assign interface 10GE1/0/15 assign interface 10GE1/0/16 assign interface 10GE1/0/17 assign interface 10GE1/0/18 assign interface 10GE1/0/19 assign interface 10GE1/0/20 assign interface 10GE1/0/21 assign interface 10GE1/0/22 assign interface 10GE1/0/23 virtual-system vs4 port-mode group resource u4route upper-limit 60000 resource m4route upper-limit 1000 resource u6route upper-limit 16000 resource m6route upper-limit 100 resource vlan upper-limit 4063 resource mpls enable resource trill enable resource mcast enable resource vpn-instance upper-limit 4096 resource cpu weight 5 resource memory ratio-threshold 100 assign interface 10GE1/0/24 assign interface 10GE1/0/25 assign interface 10GE1/0/26 assign interface 10GE1/0/27 assign interface 10GE1/0/28 assign interface 10GE1/0/29 assign interface 10GE1/0/30 assign interface 10GE1/0/31 assign interface 10GE1/0/32 assign interface 10GE1/0/33 assign interface 10GE1/0/34 assign interface 10GE1/0/35 assign interface 10GE1/0/36 assign interface 10GE1/0/37 assign interface 10GE1/0/38 assign interface 10GE1/0/39 assign interface 10GE1/0/40 assign interface 10GE1/0/41 assign interface 10GE1/0/42 assign interface 10GE1/0/43 assign interface 10GE1/0/44 assign interface 10GE1/0/45 assign interface 10GE1/0/46 assign interface 10GE1/0/47 # return
VS1的配置文件
# sysname vs1 # dfs-group 1 priority 150 source ip 10.2.1.1 m-lag up-delay 30 # vlan batch 11 20 # stp v-stp enable stp mode rstp # interface Vlanif11 ip address 10.4.1.1 255.255.255.0 vrrp vrid 1 virtual-ip 10.4.1.111 # interface Vlanif20 ip address 10.5.1.1 255.255.255.0 vrrp vrid 2 virtual-ip 10.5.1.111 # interface MEth0/0/0 ip address 10.2.1.1 255.255.255.0 # interface Eth-Trunk0 mode lacp-static peer-link 1 # interface Eth-Trunk30 port link-type trunk port trunk allow-pass vlan 11 mode lacp-static dfs-group 1 m-lag 1 lacp m-lag priority 10 lacp m-lag system-id 00e0-fc00-0001 # interface Eth-Trunk40 port link-type trunk port trunk allow-pass vlan 20 mode lacp-static dfs-group 1 m-lag 2 lacp m-lag priority 10 lacp m-lag system-id 00e0-fc00-0001 # interface Eth-Trunk50 port link-type trunk port trunk allow-pass vlan 20 mode lacp-static dfs-group 1 m-lag 3 lacp m-lag priority 10 lacp m-lag system-id 00e0-fc00-0001 # interface 10GE1/0/1 eth-trunk 30 # interface 10GE1/0/2 eth-trunk 30 # interface 10GE1/0/3 eth-trunk 0 # interface 10GE1/0/4 eth-trunk 0 # interface 10GE1/0/5 eth-trunk 40 # interface 10GE1/0/6 eth-trunk 50 # ip route-static 0.0.0.0 0.0.0.0 10.5.1.3 # return
VS2的配置文件
# sysname vs2 # dfs-group 1 priority 150 source ip 10.3.1.1 m-lag up-delay 30 # vlan batch 30 200 300 # stp v-stp enable stp mode rstp # interface Vlanif30 ip address 10.6.1.1 255.255.255.0 vrrp vrid 1 virtual-ip 10.6.1.111 # interface Vlanif200 ip address 10.8.1.1 255.255.255.0 # interface Vlanif300 ip address 10.11.1.1 255.255.255.0 # interface MEth0/0/0 ip address 10.3.1.1 255.255.255.0 # interface Eth-Trunk0 mode lacp-static peer-link 1 # interface Eth-Trunk60 port link-type trunk port trunk allow-pass vlan 30 mode lacp-static dfs-group 1 m-lag 2 lacp m-lag priority 10 lacp m-lag system-id 00e0-fc00-0002 # interface Eth-Trunk70 port link-type trunk port trunk allow-pass vlan 30 mode lacp-static dfs-group 1 m-lag 3 lacp m-lag priority 10 lacp m-lag system-id 00e0-fc00-0002 # interface 10GE1/0/31 port link-type trunk port trunk allow-pass vlan 200 # interface 10GE1/0/32 eth-trunk 0 # interface 10GE1/0/33 eth-trunk 0 # interface 10GE1/0/34 eth-trunk 60 # interface 10GE1/0/35 eth-trunk 70 # ip route-static 10.20.20.0 255.255.255.0 10.6.1.3 # ospf 1 area 0.0.0.0 network 10.3.1.0 0.0.0.255 network 10.6.1.0 0.0.0.255 network 10.8.1.0 0.0.0.255 network 10.11.1.0 0.0.0.255 # return
VS3的配置文件
# sysname vs3 # dfs-group 1 priority 120 source ip 10.2.1.2 m-lag up-delay 30 # vlan batch 11 20 # stp v-stp enable stp mode rstp # interface Vlanif11 ip address 10.4.1.2 255.255.255.0 vrrp vrid 1 virtual-ip 10.4.1.111 # interface Vlanif20 ip address 10.5.1.2 255.255.255.0 vrrp vrid 2 virtual-ip 10.5.1.111 # interface MEth0/0/0 ip address 10.2.1.2 255.255.255.0 # interface Eth-Trunk0 mode lacp-static peer-link 1 # interface Eth-Trunk30 port link-type trunk port trunk allow-pass vlan 11 mode lacp-static dfs-group 1 m-lag 1 lacp m-lag priority 10 lacp m-lag system-id 00e0-fc00-0001 # interface Eth-Trunk40 port link-type trunk port trunk allow-pass vlan 20 mode lacp-static dfs-group 1 m-lag 2 lacp m-lag priority 10 lacp m-lag system-id 00e0-fc00-0001 # interface Eth-Trunk50 port link-type trunk port trunk allow-pass vlan 20 mode lacp-static dfs-group 1 m-lag 3 lacp m-lag priority 10 lacp m-lag system-id 00e0-fc00-0001 # interface 10GE1/0/1 eth-trunk 30 # interface 10GE1/0/2 eth-trunk 30 # interface 10GE1/0/3 eth-trunk 0 # interface 10GE1/0/4 eth-trunk 0 # interface 10GE1/0/5 eth-trunk 40 # interface 10GE1/0/6 eth-trunk 50 # ip route-static 0.0.0.0 0.0.0.0 10.5.1.3 # return
VS4的配置文件
# sysname vs4 # dfs-group 1 priority 120 source ip 10.3.1.2 m-lag up-delay 30 # vlan batch 30 210 300 # stp v-stp enable stp mode rstp # interface Vlanif30 ip address 10.6.1.2 255.255.255.0 vrrp vrid 1 virtual-ip 10.6.1.111 # interface Vlanif210 ip address 10.9.1.1 255.255.255.0 # interface Vlanif300 ip address 10.11.1.2 255.255.255.0 # interface MEth0/0/0 ip address 10.3.1.2 255.255.255.0 # interface Eth-Trunk0 mode lacp-static peer-link 1 # interface Eth-Trunk60 port link-type trunk port trunk allow-pass vlan 30 mode lacp-static dfs-group 1 m-lag 2 lacp m-lag priority 10 lacp m-lag system-id 00e0-fc00-0002 # interface Eth-Trunk70 port link-type trunk port trunk allow-pass vlan 30 mode lacp-static dfs-group 1 m-lag 3 lacp m-lag priority 10 lacp m-lag system-id 00e0-fc00-0002 # interface 10GE1/0/31 port link-type trunk port trunk allow-pass vlan 210 # interface 10GE1/0/32 eth-trunk 0 # interface 10GE1/0/33 eth-trunk 0 # interface 10GE1/0/34 eth-trunk 60 # interface 10GE1/0/35 eth-trunk 70 # ip route-static 10.20.20.0 255.255.255.0 10.6.1.3 # ospf 1 area 0.0.0.0 network 10.3.1.0 0.0.0.255 network 10.6.1.0 0.0.0.255 network 10.9.1.0 0.0.0.255 network 10.11.1.0 0.0.0.255 # return
SwitchE的配置文件
# sysname SwitchE # vlan batch 200 400 # interface Vlanif200 ip address 10.8.1.2 255.255.255.0 # interface Vlanif400 ip address 10.12.1.1 255.255.255.0 # interface 10GE1/0/1 port link-type trunk port trunk allow-pass vlan 200 # interface 10GE1/0/2 port link-type trunk port trunk allow-pass vlan 400 # ospf 1 area 0.0.0.0 network 10.8.1.0 0.0.0.255 network 10.12.1.0 0.0.0.255 # return
SwitchF的配置文件
# sysname SwitchF # vlan batch 210 400 # interface Vlanif210 ip address 10.9.1.2 255.255.255.0 # interface Vlanif400 ip address 10.12.1.2 255.255.255.0 # interface 10GE1/0/1 port link-type trunk port trunk allow-pass vlan 210 # interface 10GE1/0/2 port link-type trunk port trunk allow-pass vlan 400 # ospf 1 area 0.0.0.0 network 10.9.1.0 0.0.0.255 network 10.12.1.0 0.0.0.255 # return