这篇是下半部分,主要就是配置的MA主柜的配置
MA主柜设备图
依然是从下到上
倒数第一台为核心交换机。H3C_S6800,48x10G+4x40G
倒数第二台为原先专线入口路由器,目前已停用
倒数第三台为私网专用交换机,目前弃用
倒数第四为新专线路由器且为SDN业务路由
倒数第五为ACG网关,目前未使用
倒数第六为业务机房核心交换机
倒数第一个交换机配置(不显示前段)
#配置VLAN 1(default), 2-7, 9-10, 14, 22, 28, 78, 81, 91, 111, 323, 330, 335, 833, 903, 1016
#配置下联交换机40G聚合
-----------
int Bridge-Aggregation 3
link-agg mode dyn
quit
int range ten 1/0/1 to ten 1/0/4
default
port link-agg group 3
quit
int Bridge-Aggregation 3
port link-type hybrid
port hybrid vlan 4 10 28 81 91 111 833 1016 tagged
port hybrid vlan 1 untagged
quit
#配置5号接口到总部
-----------
int ten 1/0/5
port link-ty hy
port hybrid vlan 4 6 10 81 91 330 1016 tagged
port hybrid vlan 1 untagged
quit
#配置20G端口到上联交换机
-----------
int Bridge-Aggregation 2
link-agg mode dyn
quit
int range ten 1/0/43 to ten 1/0/44
default
port link-agg group 2
quit
int Bridge-Aggregation 2
port link-ty hy
port hy vlan 2 to 7 9 to 10 14 22 28 78 81 91 323 330 tagged
port hybrid vlan 335 833 903 1016 tagged
port hybrid vlan 1 untagged
quit
#配置到服务器的20G带宽
-----------
int range ten 1/0/33 to ten 1/0/34
default
port link-ty hy
port hy pvid vlan 1
port hy vlan 1 untag
quit
#配置VLAN 1
-----------
int vlan 1
ip add 172.16.83.208 22
undo shut
quit
#保存配置文件
-----------
save force
下面配置上层的机房业务交换机
#配置VLAN1(default), 2, 4-6, 10, 12, 14, 22, 28, 80-81, 91, 98, 323, 330, 833, 903, 1014-1017
#配置链路聚合到20G上联
-----------
int Bridge-Aggregation 2
link-agg mode dyn
quit
int range ten 1/0/51 to ten 1/0/52
default
port link-agg group 2
quit
int Bridge-Aggregation 2
port link-type hybrid
port hybrid vlan 4 6 10 28 80 to 81 91 98 323 330 833 tagged
port hybrid vlan 903 1016 tagged
port hybrid vlan 1 untagged
quit
#配置专线路由器的链路聚合
-----------
int range gi 1/0/25 to gi 1/0/28
default
int Bridge-Aggregation 3
description zhuanxian
port link-type hybrid
port hybrid vlan 28 98 330 833 903 tagged
port hybrid vlan 1 untagged
link-aggregation mode dynamic
quit
#配置IP-SAN的链路聚合
-----------
int range gi 1/0/33 to gi 1/0/36
default
int Bridge-Aggregation 1
port link-ty acc
port acc vlan 1016
link-agg mode dyn
quit
#配置VLAN 1
-----------
int vlan 1
ip add 172.16.83.206 22
undo shut
#保存配置文件
-----------
save force
配置MikroTik业务路由器
#配置桥
-----------
/interface bridge
add dhcp-snooping=yes name=URM1
#配置链路聚合为LACP
-----------
/interface bonding
add lacp-rate=1sec mode=802.3ad name=LAN-LACP slaves=\
ether8,ether7,ether6,ether5
#配置VLAN
-----------
/interface vlan
add interface=LAN-LACP name=VLAN1 vlan-id=1
add comment=TR069 interface=LAN-LACP name=VLAN28 vlan-id=28
add interface=LAN-LACP name=VLAN93 vlan-id=93
add comment=WLAN_URM1 interface=LAN-LACP name=VLAN330 vlan-id=330
add interface=LAN-LACP name=VLAN833 vlan-id=833
add comment=CONN interface=LAN-LACP name=VLAN903 vlan-id=903
#配置地址池
-----------
/ip pool
add name=VLAN330 ranges=192.168.154.50-192.168.154.150
add name=TR069 ranges=10.18.1.0-10.18.5.255
#配置DHCP服务器
-----------
/ip dhcp-server
add address-pool=VLAN330 interface=VLAN330 name=VLAN330
add address-pool=TR069 interface=VLAN28 name=TR069
#配置IP地址
-----------
/ip address
add address=192.168.154.1/24 interface=VLAN330 network=192.168.154.0
add address=172.31.255.2/26 interface=VLAN903 network=172.31.255.0
add address=10.18.0.1/16 interface=VLAN28 network=10.18.0.0
add address=172.30.0.2/16 interface=VLAN833 network=172.30.0.0
#DHCP服务器的配置文件
-----------
/ip dhcp-server network
add address=10.18.0.0/16 dns-server=10.18.0.250 gateway=10.18.0.1 netmask=16
add address=192.168.154.0/24 dns-server=218.4.4.4,218.2.2.2 gateway=\
192.168.154.1 netmask=24
#配置DHCP服务器的DNS服务器
-----------
/ip dns
set servers=218.4.4.4,218.2.2.2
#配置NAT以及MASQUERADE
-----------
/ip firewall nat
add action=masquerade chain=srcnat
add action=src-nat chain=srcnat src-address=192.168.154.0/24 to-addresses=\
xxx.xxx.xxx.xxx
#配置路由
-----------
/ip route
add disabled=no dst-address=0.0.0.0/0 gateway=xxx.xxx.xxx.xxx routing-table=main \
suppress-hw-offload=no
add disabled=no dst-address=172.16.80.0/22 gateway=172.31.255.3 routing-table=\
main suppress-hw-offload=no
add disabled=no dst-address=10.16.0.0/16 gateway=172.31.255.3 routing-table=\
main suppress-hw-offload=no
add disabled=no dst-address=192.168.212.0/24 gateway=172.31.255.3 \
routing-table=main suppress-hw-offload=no
MA主柜配置完毕,实机配置请勿直接使用(并不能保证你的接法和我的接法是否是一致的,或者说你的设备硬件版本号与我的硬件版本号是否一致的)
评论