sysname h3c-1F
interface Vlan-interface1
ip address 192.168.1.2 24
description wangguanpingtai
quit
clock timezone GMT add 8
ntp-service unicast-server 202.120.2.101
ip route-static 0.0.0.0 0.0.0.0 192.168.1.1
回程静态路由
Ip route-static 192.168.0.0 255.255.0.0
super password level 3 cipher 67742665
super authentication-mode local scheme
配置telnet和web 账号和密码
telnet server enable
local-user admin
password cipher 67742665
service-type telnet terminal ssh level 3
quit
user-interface vty 0 4
authentication-mode scheme
protocol inbound telnet
screen-length 30
history-command max-size 30
idle-timeout 10
quit
设置console口令
user-interface aux 0
authentication-mode password
set authentication password cipher 67742665
user privilege level 3
idle-timeout 5
配置VLAN接口IP
interface vlan-interface 1
ip address 192.168.1.1 255.255.255.0
undo shutdown
interface vlan-interface 2
ip address 192.168.2.1 255.255.255.0
undo shutdown
quit
snmp-agent community read public
snmp-agent community write H3C
snmp-agent sys-info version all
snmp-agent trap enable
端口组配置
port-group manual 1
group-member Ethernet 0/1 to Ethernet 0/24
link-aggregation group 1 mode manual
interface GigabitEthernet3/0/1
port link-type trunk
port trunk permit vlan all
port link-aggregation group 1
description TO_jiaohuanji_h3c3100 _g0/3
interface GigabitEthernet3/0/2
port link-type trunk
port trunk permit vlan all
port link-aggregation group 1
description TO_jiaohuanji_h3c3100 _g0/3
quit
interface GigabitEthernet1/1/3
port link-type trunk
port trunk permit vlan all
quit
动态VLAN (在trunk端口上开启gvrp)
gvrp
GigabitEthernet1/1/3
gvrp
quit
端口隔离
interface GigabitEthernet 1/0/1
port-isolate enable
quit
interface GigabitEthernet 1/0/2
port-isolate enable
quit
interface GigabitEthernet 1/0/3
port-isolate enable
ACL VLAN之间不能互通 (VLAN2与VLAN3不能互通)
acl number 3000
rule 0 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule 1 permit ip
Interface vlan-interface 2
packet-filter inbound ip-group 3000
stacking ip-pool 129.10.1.15 3 255.255.255.0
stacking enable
quit
display stacking
fabric-port GigabitEthernet 1/1/1 enable
fabric-port GigabitEthernet 1/1/2 enable
change self-unit to 1
set unit 1 name unit 1
sysname fabric
irf-fabric authentication-mode simple hello
fabric-port GigabitEthernet 1/1/1 enable
fabric-port GigabitEthernet 1/1/2 enable
change self-unit to 2
set unit 2 name unit 2
sysname fabric
irf-fabric authentication-mode simple hello
display ftm information
display irf-fabric
ospf
area 0
network 192.168.1.0 0.0.0.255
ospf
import-route rip
rip
import-route ospf
stp生成树
stp enable 开启stp功能
stp root primary 设置此交换机为主根
stp root secondary 设置此交换机为备根
stp bpdu-protection BPDU保护功能
interface Ethernet 0/1
stp root-protection 根保护 配置在主副根交换机所有端口
stp edged-port enable 边缘端口 建议同时配置BPDU保护 提高STP收敛速度
stp loop-protection 环路保护
DHCP(全局DHCP)
dhcp server ip-pool vlan2
network 192.168.2.0 mask 255.255.255.0
gateway-list 192.168.2.1
dns-list 192.168.4.5
quit
dhcp server forbidden-ip 192.168.2.1
dhcp server ip-pool vlan3
network 192.168.3.0 mask 255.255.255.0
gateway-list 192.168.3.1
dns-list 192.168.4.5
quit
dhcp server forbidden-ip 192.168.3.1
interface vlan-interface 2
dhcp select global
quit
interface vlan-interface 3
dhcp select global
quit
NAT地址转换
acl number 2001
rule 5 permit source 192.168.10.0 0.0.0.255
rule 10 permit source 192.168.20.0 0.0.0.255
rule 15 permit source 192.168.30.0 0.0.0.255
rule 20 permit source 192.168.40.0 0.0.0.255
rule 25 permit source 192.168.50.0 0.0.0.255
rule 30 deny
nat address-group 1 1.1.1.3 1.1.1.3
interface GigabitEthernet0/0/1
ip address 1.1.1.2 255.255.255.248
nat outbound 2001 address-group 1
端口映射
nat server protocol tcp global 123.1.1.2 inside 192.168.4.5
nat server protocol tcp global 123.1.1.3 inside 192.168.4.6
设置服务器IP,MAC和端口绑定
Am user-bind ip-address 192.168.4.5 mac-address 00e0-fcab-cd11 interface e0/4
Am user-bind ip-address 192.168.4.6 mac-address 0000-0cab-cd12 interface e0/5