华为三层交换机基于ip地址的限速

[H3C]dis cur
#
 version 5.20, Release 2202
#
 sysname H3C
#
 clock timezone beijing add 13:01:45
#
 super password level 3 cipher :Aa.-B3\6E@ZY#9\EO)311!!
#
 irf mac-address persistent timer
 irf auto-update enable
 undo irf link-delay
#
 domain default enable system
#
 telnet server enable
#
 undo ip ttl-expires
#
acl number 2000 match-order auto
#
vlan 1
#
vlan 1000 to 1010
#
radius scheme system
 server-type extended
 primary authentication 127.0.0.1 1645
 primary accounting 127.0.0.1 1646
 user-name-format without-domain
#
domain system
 access-limit disable
 state active
 idle-cut disable
 self-service-url disable
#
traffic classifier ban-gong operator and
 if-match any
traffic classifier bi-sai operator and
 if-match any
traffic classifier zhang-xin-da operator and
 if-match any
#
traffic behavior ban-gong
 car cir 20480 cbs 4000 ebs 4000 green pass red discard yellow pass
traffic behavior bi-sai
 car cir 40960 cbs 4000 ebs 4000 green pass red discard yellow pass
traffic behavior zhang-xin-da
 car cir 3072 cbs 4000 ebs 4000 green pass red discard yellow pass
#
qos policy bi-sai-upload
 classifier bi-sai behavior bi-sai
qos policy ban-gong-out
 classifier ban-gong behavior ban-gong
qos policy zhang-xin-da-out
 classifier zhang-xin-da behavior zhang-xin-da
#
user-group system
#
interface NULL0
#
interface LoopBack0
 ip address 119.255.3.49 255.255.255.255
#
interface Vlan-interface1000
 description connet-li-gong
 ip address 10.2.59.66 255.255.255.252
 ospf cost 30
#
interface Vlan-interface1001
 description connect-to-kecai
 ip address 10.2.59.70 255.255.255.252
#
interface Vlan-interface1003
#
interface Vlan-interface1004
 ip address 192.168.116.1 255.255.255.252
#
interface Vlan-interface1005
 ip address 192.168.117.1 255.255.255.252
#
interface Vlan-interface1007
 ip address 192.168.104.1 255.255.255.252
#
interface Vlan-interface1008
 ip address 192.168.103.1 255.255.255.252
#
interface Vlan-interface1009
 ip address 192.168.105.1 255.255.255.252
#
interface Vlan-interface1010
 ip address 192.168.106.1 255.255.255.252
#
interface GigabitEthernet1/0/1
 description connect-to-ligong
 port access vlan 1000
#
interface GigabitEthernet1/0/2
 description connect-to-kecai
 port access vlan 1001
#
interface GigabitEthernet1/0/3
 port access vlan 1003
#
interface GigabitEthernet1/0/4
#
interface GigabitEthernet1/0/5
 description zhang-xin-da
 port access vlan 1004
 qos apply policy zhang-xin-da-out inbound
 qos apply policy zhang-xin-da-out outbound
#
interface GigabitEthernet1/0/6
 description zhang-xin-da
 port access vlan 1005
 qos apply policy zhang-xin-da-out inbound
 qos apply policy zhang-xin-da-out outbound
#
interface GigabitEthernet1/0/7
 description ban-gong
 port access vlan 1007
 qos apply policy ban-gong-out inbound
 qos apply policy ban-gong-out outbound
#
interface GigabitEthernet1/0/8
 description ban-gong
 port access vlan 1008
#
interface GigabitEthernet1/0/9
 description bi-sai
 port access vlan 1009
 qos apply policy bi-sai-upload inbound
 qos apply policy bi-sai-upload outbound
#
interface GigabitEthernet1/0/10
 description bi-sai
 port access vlan 1010
 qos apply policy bi-sai-upload inbound
 qos apply policy bi-sai-upload outbound

 shutdown
#
bgp 23844
 import-route direct route-policy first_test
 import-route static route-policy first_test
 undo synchronization
 group edge internal
 peer edge password cipher 'E'9D=OF"='Q=^Q`MAF4<1!!
 peer edge next-hop-local
 peer edge connect-interface LoopBack0
 peer 203.86.64.16 group edge
#
ospf 17 router-id 119.255.3.49
 area 0.0.0.1
  network 10.2.59.66 0.0.0.0
  network 119.255.3.49 0.0.0.0
  network 10.2.59.70 0.0.0.0
#
route-policy first_test permit node 2
 if-match ip-prefix deny_private
#
nqa entry admin test
 type icmp-echo
  destination ip 192.168.116.2
  frequency 100
  reaction 1 checked-element probe-fail threshold-type consecutive 2 action-type
 trigger-only
#
nqa entry admin1 test
 type icmp-echo
  destination ip 192.168.117.2
  frequency 100
  reaction 2 checked-element probe-fail threshold-type consecutive 2 action-type
 trigger-only
#
nqa entry weisheng test
 type icmp-echo
  destination ip 192.168.105.2
  frequency 100
  reaction 3 checked-element probe-fail threshold-type consecutive 2 action-type
 trigger-only
#
nqa entry weisheng1 test
 type icmp-echo
  destination ip 192.168.106.2
  frequency 100
  reaction 4 checked-element probe-fail threshold-type consecutive 2 action-type
 trigger-only
#
 ip ip-prefix deny_private index 9 permit 203.86.66.32 27 greater-equal 27 less-
equal 32
 ip ip-prefix deny_private index 11 permit 118.102.28.0 25 greater-equal 25 less
-equal 32
 ip ip-prefix deny_private index 13 permit 203.86.66.128 25 greater-equal 25 les
s-equal 32
 ip ip-prefix deny_private index 14 permit 119.255.3.48 29 greater-equal 29 less
-equal 32
 ip ip-prefix deny_private index 20 deny 0.0.0.0 0 less-equal 32
#
 ip route-static 118.102.28.64 255.255.255.192 192.168.105.2 track 3
 ip route-static 118.102.28.64 255.255.255.192 192.168.106.2 track 4
 ip route-static 203.86.66.32 255.255.255.224 192.168.116.2 track 1
 ip route-static 203.86.66.32 255.255.255.224 192.168.117.2 track 2
 ip route-static 203.86.66.128 255.255.255.128 192.168.104.2
#
 snmp-agent
 snmp-agent local-engineid 800063A203000FE2E9B528
 snmp-agent community read pop-nortel
 snmp-agent sys-info version all
#
 track 1 nqa entry admin test reaction 1
 track 2 nqa entry admin1 test reaction 2
 track 3 nqa entry weisheng test reaction 3
 track 4 nqa entry weisheng1 test reaction 4
#
 nqa schedule admin test start-time now lifetime forever
 nqa schedule admin1 test start-time now lifetime forever
 nqa schedule weisheng test start-time now lifetime forever
 nqa schedule weisheng1 test start-time now lifetime forever
#
user-interface aux 0 8
user-interface vty 0 4
 set authentication password cipher E!GR*G<E.T/Q=^Q`MAF4<1!!
#
return
[H3C]

你可能感兴趣的:(职场,休闲,qos,三层,限速)