实验名称:华为设备stp 、vrrp的实力应用
实验目的:1.熟练地应用stp、vrrp的应用及配置
2.了解环路以及解决方案
3.使全网互通
实验思路:首先把拓扑图分为三个部分
1.配置相同vlan相通,相同网段看交换,先配置交换机,左右两边各有三个交换机.
2.所有会有环路,就要用到stp ,把sw2,3配置为根网桥,所有交换流量都要通过他俩: 配置命令:stp root primary
3. 其他两个交换机配置stp,实现负载均衡,以及备份链路
[sw]stp region-configuration 进入stp 域模式
[sw-mst-region]region-name haha 定义域名称
[sw-mst-region]revision-level 2 修订级别 2 默认是0
[sw-mst-region]instance 1 vlan 10 配置vlan 和实列1映射关系
[sw-mst-region]instance 2 vlan 20 配置vlan 和实列2映射关系
[sw-mst-region]active region-configuration 激活域配置
[sw]stp instance 1 priority 4096 定义映射1为root设备
[sw]stp instance 2 priority 8192 定义映射2为备root设备
交换机与交换机之间用trunk链接
2. 在配置第二部分,不同网段用路由。
三个路由器都要使用的情况下,要实现冗余,就用vrrp协议配置优先级
配置命令:
R1
vrrp vrid 10 virtual-ip 192.168.10.250 创建虚拟网关
vrrp vrid 10 priority 150 配置优先级为150,默认100
vrrp vrid10 interface gi 0/0/2 reduce 100
配置链路跟踪,当interface gi0/0/2 端口为down时,优先级减100
R2
vrrp vrid 10 virtual-ip 192.168.10.250
vrrp vrid 10 priority 100
R3
vrrp vrid 10 virtual-ip 192.168.10.250
vrrp vrid 10 priority 80
3.配置第三部分
交换机端口开启
R4
配置ip interface gi0/0/0 0/0/1
配置步骤:
设备 ip 网关 子网掩码
pc1 192.168.10.1 192.168.10.250 255.255.255.0
pc2 192.168.20.1 192.168.20.250 255.255.255.0
pc3 192.168.10.2 192.168.10.250 255.255.255.0
pc4 192.168.20.2 192.168.20.250 255.255.255.0
服务器 192.168.30.1 192.168.30.254 255.255.255.0
R1-0/0/0 192.168.10.254 255.255.255.0
R1-0/0/1 192.168.20.254 255.255.255.0
R1-0/0/2 192.168.100.1 255.255.255.0
R1-虚拟ip 192.168.10.250
R1-虚拟ip 192.168.20.250
R2-0/0/0 192.168.10.253 255.255.255.0
R2-0/0/1 192.168.20.253 255.255.255.0
R2-0/0/2 192.168.100.1 255.255.255.0
R2-虚拟ip 192.168.10.250
R2-虚拟ip 192.168.20.250
R3-0/0/0 192.168.10.252 255.255.255.0
R3-0/0/1 192.168.20.252 255.255.255.0
R3-0/0/2 192.168.100.1 255.255.255.0
R3-虚拟ip 192.168.10.250
192.168.20.250
R4-0/0/0 192.168.100.2 255.255.255.0
R4-0/0/1 192.168.30.254 255.255.255.0
第一部分
sw4
interface gi0/0/1 :port link-tyde access 端口1加入vlan 10
port default vlan 10
interface gi0/0/2 :port link-tyde trunk 设置为trunk链路
port trunk allow-pass vlan all
interface gi0/0/3 :port link-tyde trunk 设置为trunk链路
port trunk allow-pass vlan all
[sw4]stp region-configuration 创建stp
[sw4-mst-region]region-name haha stp 名称为 haha
[sw4-mst-region]instance 1 vlan 10 vlan 10加入 1组
[sw4-mst-region]instance 2 vlan 20 vlan 20加入 2组
[sw4-mst-region]active region-configuration 开启配置
[sw4]stp instance 1 priority 4096 1组设置优先级为 4096 (stp优先级只能为为4096的倍数)
[sw4]stp instance 2 priority 8192 2组设置优先级为 8192
sw5
interface gi0/0/1 :port link-tyde access 加入vlan 20
port default vlan 20
interface gi0/0/2 :port link-tyde trunk 设置为trunk链路
port trunk allow-pass vlan all
interface gi0/0/3 :port link-tyde trunk 设置为trunk链路
port trunk allow-pass vlan all
[sw5]stp region-configuration
[sw5-mst-region]region-name haha 创建stp,以及名称 haha
[sw5-mst-region]instance 1 vlan 10 vlan10 加入1组
[sw5-mst-region]instance 2 vlan 20 vlan20 加入2组
[sw5-mst-region]active region-configuration 开启配置
[sw5]stp instance 1 priority 8192 配置优先级 1组为8192
[sw5]stp instance 2 priority 4096 配置优先级 2组为 4096
sw2
interface gi0/0/1 :port link-tyde trunk 配置为trunk链路
port trunk allow-pass vlan all
interface gi0/0/2 :port link-tyde trunk 配置为trunk链路
port trunk allow-pass vlan all
interface gi0/0/3 :port link-tyde access 加入vlan10
port default vlan 10
interface gi0/0/4 :port link-tyde access 加入vlan10
port default vlan 10
interface gi0/0/5 :port link-tyde access 加入vlan10
port default vlan 10
interface gi0/0/6 :port link-tyde trunk 配置为trunk链路
port trunk allow-pass vlan all
sw2:stp root primary 设置为root 根交换机
sw6
interface gi0/0/1 :port link-tyde access 加入vlan10
port default vlan 10
interface gi0/0/2 :port link-tyde trunk 配置为trunk链路
port trunk allow-pass vlan all
interface gi0/0/3 :port link-tyde trunk 配置为trunk链路
port trunk allow-pass vlan all
[sw6]stp region-configuration 创建stp 以及名称 haha
[sw6-mst-region]region-name haha
[sw6-mst-region]instance 1 vlan 10 vlan10加入 1组
[sw6-mst-region]instance 2 vlan 20 vlan20加入 2组
[sw6-mst-region]active region-configuration 开启配置
[sw6]stp instance 1 priority 4096 配置优先级 组1 为4096
[sw6]stp instance 2 priority 8192 组2 为8192
sw7
interface gi0/0/1 :port link-tyde access 加入vlan 20
port default vlan 20
interface gi0/0/2 :port link-tyde trunk 配置trunk链路
port trunk allow-pass vlan all
interface gi0/0/3 :port link-tyde trunk 配置trunk链路
port trunk allow-pass vlan all
[sw7]stp region-configuration 创建stp 以及名称 haha
[sw7-mst-region]region-name haha
[sw7-mst-region]instance 1 vlan 10 vlan10 加入1组
[sw7-mst-region]instance 2 vlan 20 vlan20加入2组
[sw7-mst-region]active region-configuration 开启配置
[sw7]stp instance 1 priority 8192 配置优先级 1组8192
[sw7]stp instance 2 priority 4096 2组4096
sw3
interface gi0/0/1 :port link-tyde trunk 配置trunk链路
port trunk allow-pass vlan all
interface gi0/0/2 :port link-tyde trunk 配置trunk链路
port trunk allow-pass vlan all
interface gi0/0/3 :port link-tyde access 加入vlan20
port default vlan 20
interface gi0/0/4 :port link-tyde access 加入vlan20
port default vlan 20
interface gi0/0/5 :port link-tyde access 加入vlan20
port default vlan 20
interface gi0/0/6 :port link-tyde trunk 配置trunk链路
port trunk allow-pass vlan all
sw3:stp root primary 配置为root 根交换机
验证:
pc1 ping pc3
pc2 ping pc4
第二部分
R1
interface gi 0/0/0 :ip addess 192.168.10.254 255.255.255.0 配置ip
vrrp vrid 10 virtual-ip 192.168.10.250 创建vrrp,虚拟ip (三个路由器都加入组vrrp vrid10 ,他们都是为虚拟ip服务
vrrp vrid 10 priority 150 优先级为150 当其中一个路由器坏了另外一个路由器就会启用)
vrrp vrid 10 track interface GigabitEthernet0/0/2 reduced 100 配置跟踪链路,当0/0/2口为down时,优先级下降100,变为50
interface gi 0/0/1 :ip addess 192.168.20.252 255.255.255.0
vrrp vrid 20 virtual-ip 192.168.20.250 创建vrrp vlan20的
vrrp vrid 10 priority 80 优先级为80
interface gi 0/0/2 :ip addess 192.168.100.1 255.255.255.0
ospf 1 router-id 1.1.1.1 配置路由协议ospf
area 0.0.0.0
network 192.168.10.0 0.0.0.255
network 192.168.20.0 0.0.0.255 宣告网段
area 0.0.0.30
network 192.168.100.0 0.0.0.255
R2
interface gi 0/0/0 :ip addess 192.168.10.253 255.255.255.0 配置ip
vrrp vrid 10 virtual-ip 192.168.10.250 创建vrrp,配置虚拟ip
vrrp vrid 10 priority 100 配置优先级
vrrp vrid 10 track interface GigabitEthernet0/0/2 reduced 50 配置跟踪链路
interface gi 0/0/1 :ip addess 192.168.20.253 255.255.255.0
vrrp vrid 20 virtual-ip 192.168.20.250
vrrp vrid 10 priority 100
vrrp vrid 20 track interface GigabitEthernet0/0/2 reduced 50
interface gi 0/0/2 :ip addess 192.168.100.1 255.255.255.0
ospf 1 router-id 2.2.2.2
area 0.0.0.0
network 192.168.10.0 0.0.0.255
network 192.168.20.0 0.0.0.255
area 0.0.0.30
network 192.168.100.0 0.0.0.255
R3
interface gi 0/0/0 :ip addess 192.168.10.252 255.255.255.0
vrrp vrid 10 virtual-ip 192.168.10.250
vrrp vrid 10 priority 80
interface gi 0/0/1 :ip addess 192.168.20.252 255.255.255.0
vrrp vrid 20 virtual-ip 192.168.20.250
vrrp vrid 20 priority 150
vrrp vrid 20 track interface GigabitEthernet0/0/2 reduced 100
interface gi 0/0/2 :ip addess 192.168.100.1 255.255.255.0
ospf 1 router-id 3.3.3.3
area 0.0.0.0
network 192.168.10.0 0.0.0.255
network 192.168.20.0 0.0.0.255
area 0.0.0.30
network 192.168.100.0 0.0.0.255
验证vlan与vlan之间
pc1 ping pc2、pc4
第三部分
sw1不用配置,端口默认开启
R4
interface gi0/0/0 :ip addess 192.168.100.2 255.255.255.0
interface gi0/0/1 :ip addess 192.168.30.254 255.255.255.0
ospf 1 router-id 4.4.4.4
area 0.0.0.30
network 192.168.30.0 0.0.0.255
network 192.168.100.0 0.0.0.255
验证全网通
pc1 ping 服务器