½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎª NE5000E)ÅäÖù淶V1.4-20110709 - ͼÎÄ

½­ËÕµçÐųÇÓòÍø³ö¿Ú·ÓÉÆ÷ (»ªÎªNE5000E) É豸ÅäÖù淶

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

2011Äê7ÔÂ

Confidential

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

°æ±¾¸üÐÂ˵Ã÷

V1.0°æ±¾ÎªÎĵµ¶¨¸å°æ£¬ºóÆÚµÄ°æ±¾ÎªÐÞ¶©°æ£¬°æ±¾µÄÐòºÅΪ¡¶½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶VX.X-YYYYMMDD¡·£¬ÐÞ¶©ËµÃ÷ÌîдÔÚ¡°Ö÷Òª¸üÐÂÄÚÈÝ¡±ÖС£

ÏîÄ¿±àºÅ °æ±¾ºÅ V1.4 V1.3 V1.2 V1.1 V1.02 V1.01 V1.0 ±àÖÆÈË/ʱ¼ä Àî¾²/20110709 Àî¾²/20100801 Àî¾²/20100525 Àî¾²/20100425 Àî¾²/20100417 Àî¾²/20100322 Áõ½ðÅô/20091222 ÉóºËÈË/ʱ¼ä Êø¶°/20110709 Êø¶°/20100801 Êø¶°/20100525 Êø¶°/20100425 Êø¶°/20100417 Êø¶°/20100322 Êø¶°/20091222 Îĵµ±àºÅ Q3-WL-43 Ö÷Òª¸üÐÂÄÚÈÝ °´ÕÕ¼¯ÍŹ淶£¬¸üв¿·ÖÄÚÈÝ ¸üÐÂMTU²¿·ÖÄÚÈÝ ¸üÐÂISIS ĬÈÏ·ÓÉÏ·¢Óë½ÓÊÕ²ßÂÔ ¸üÐÂMTU,ISIS²¿·ÖÄÚÈÝ RR£¬²¿·Ö°²È«¼Ó¹Ì²ßÂÔ BFD,ISISЭÒé,BGPÊôÐÔ ¶¨¸å ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾ µÚ1Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

Ŀ ¼

µÚ1ÕÂ 1.1 1.2 µÚ2ÕÂ 2.1 2.1.1 2.1.2 2.2 2.2.1 2.2.2

¸ÅÊö ....................................................................................................................................... 1 ÊõÓïºÍËõдÓï±í ................................................................................................................... 1 ÍøÂç½á¹¹ËµÃ÷ ....................................................................................................................... 3 IP³ÇÓòÍøÍøÂçÉ豸ÃüÃû¼°Á´Â·ÃèÊö¹æ·¶.......................................................................... 5 É豸ÃüÃû¹æ·¶ ....................................................................................................................... 5

ÊÊÓ÷¶Î§ .......................................................................................................................... 5 É豸ÃüÃû¹æ·¶¸ñʽ .......................................................................................................... 5

¶Ë¿ÚÃèÊö¹æ·¶ ....................................................................................................................... 9

»·»Ø½Ó¿ÚÃèÊö .................................................................................................................. 9 ÍøÂç¶Ë¿ÚÃèÊö¹æ·¶ ........................................................................................................ 10

ÊÊÓ÷¶Î§ ............................................................................................................................ 10 ¶Ë¿ÚÃèÊö°üº¬ÏÂÃæ¼¸²¿·Ö ................................................................................................. 10

2.2.2.1 2.2.2.2

2.2.3 2.2.4 µÚ3ÕÂ 3.1 3.1.1 3.1.2 3.1.3

Óû§¶Ë¿Ú ........................................................................................................................ 11 ¿ÕÏж˿ÚÃèÊö ................................................................................................................ 11

³ö¿Ú·ÓÉÆ÷NE5000EÅäÖù淶 ..................................................................................... 12 ϵͳ»ù±¾ÅäÖù淶 ............................................................................................................. 12

É豸Ãû³ÆÅäÖà ................................................................................................................ 12 BannerÅäÖà ................................................................................................................... 12 É豸×ÔÉíʱ¼ä¼°NTP .................................................................................................... 13

Ê±ÇøÅäÖà ............................................................................................................................ 13 ϵͳ±¾µØÊ±¼ä ..................................................................................................................... 13

3.1.3.1 3.1.3.2 3.1.3.3 NTPÏûÏ¢Ô´µØÖ· ...................................................................................................................... 14 3.1.3.4 NTPЭÒé¼ÓÃÜ .......................................................................................................................... 14 3.1.3.5 SNTP½ø³Ì¹Ø±Õ ....................................................................................................................... 15 3.1.3.6

ÅäÖ÷¶Àý ............................................................................................................................ 15

3.1.4 TelnetÅäÖÃ ..................................................................................................................... 16

Á¬½ÓÊýÏÞÖÆ......................................................................................................................... 16 ¿ÕÏÐʱ¼ä ............................................................................................................................ 16

3.1.4.1 3.1.4.2

3.1.4.3 TELNET·ÃÎÊ¿ØÖÆÁбí ........................................................................................................... 17 3.1.4.4

ÅäÖ÷¶Àý ............................................................................................................................ 17

3.1.5 AAAÅäÖÃ ........................................................................................................................ 18

3.1.5.1 AAA·þÎñÆ÷IPµØÖ·ºÍ¶Ë¿ÚºÅ ................................................................................................ 18 3.1.5.2 AAAÏûÏ¢Êý¾Ý°üÔ´µØÖ· .......................................................................................................... 18

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ2Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

3.1.5.3 3.1.5.4 3.1.5.5 3.1.5.6 3.1.5.7

ÈÏ֤ģʽ ............................................................................................................................ 18 ÊÚȨģʽ ............................................................................................................................ 19 Éó¼ÆÄ£Ê½ ............................................................................................................................ 19 ±¾µØÓû§ÕʺŠ..................................................................................................................... 19 ÅäÖ÷¶Àý ............................................................................................................................ 20

3.1.6 3.2 3.2.1 3.2.2 3.2.3

ϵͳ¸ß¿É¿¿ÐÔÅäÖà ........................................................................................................ 21

¶Ë¿ÚÅäÖù淶 ..................................................................................................................... 21

MTUÖµÉè¼Æ ................................................................................................................... 21 Loopback½Ó¿ÚÅäÖà ....................................................................................................... 23 GE½Ó¿ÚÅäÖà .................................................................................................................. 23

½Ó¿ÚÃèÊö ............................................................................................................................ 23

3.2.3.1

3.2.3.2 MTUÖµ ..................................................................................................................................... 24 3.2.3.3 3.2.3.4 3.2.3.5 3.2.3.6

¹Ø±ÕGE¶Ë¿ÚЭÉÌ .............................................................................................................. 24 ¹Ø±Õ´æÔÚ·çÏյݲȫ©¶´ ................................................................................................. 25 ½Ó¿ÚÕðµ´½ûÖ¹ ..................................................................................................................... 25 ÅäÖ÷¶Àý ............................................................................................................................ 25

3.2.4 GE×Ó½Ó¿Ú½Ó¿ÚÅäÖÃ ...................................................................................................... 26

ÃüÃû¹æ·¶ ............................................................................................................................ 26 ½Ó¿ÚÃèÊö ............................................................................................................................ 26

3.2.4.1 3.2.4.2

3.2.4.3 dot1q·â×°¸ñʽ ....................................................................................................................... 26 3.2.4.4

ÅäÖ÷¶Àý ............................................................................................................................ 26

3.2.5 POS½Ó¿ÚÅäÖÃ ................................................................................................................ 27

½Ó¿ÚÃèÊö ............................................................................................................................ 27

3.2.5.1

3.2.5.2 MTUÖµ ..................................................................................................................................... 27 3.2.5.3 POS·â×°¡¢Ö¡µÈ ...................................................................................................................... 27 3.2.5.4 POSÁ´Â·Í¬²½Ê±ÖÓ .................................................................................................................. 28 3.2.5.5 ÅäÖ÷¶Àý ............................................................................................................................ 28

3.2.6 3.3 3.3.1 3.3.2 3.3.3

¶Ë¿Ú¾µÏñÅäÖà ................................................................................................................ 29

·ÓÉЭÒéÅäÖù淶 ............................................................................................................. 29

³ÇÓòÍøÂ·Óɼܹ¹¸ÅÊö .................................................................................................... 29 ·ÓÉÓÅÏȼ¶/¹ÜÀí¾àÀë ................................................................................................... 30 ¾²Ì¬Â·ÓÉÅäÖà ................................................................................................................ 31

¾²Ì¬Â·ÓÉÓÅÏȼ¶ ................................................................................................................. 31 ¾²Ì¬Â·ÓÉÅäÖ÷½Ê½ ............................................................................................................. 31 ºÚ¶´Â·ÓÉÅäÖà ..................................................................................................................... 31 ¸¡¶¯¾²Ì¬Â·ÓÉÅäÖà ............................................................................................................. 32 ¾²Ì¬Â·Óɱê¼ÇºÍÃèÊö ......................................................................................................... 32 ÅäÖ÷¶Àý ............................................................................................................................ 33

µÚ3Ò³

3.3.3.1 3.3.3.2 3.3.3.3 3.3.3.4 3.3.3.5 3.3.3.6

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

3.3.4 ISIS ÅäÖÃ ....................................................................................................................... 33

¸ÅÊö .................................................................................................................................... 33

3.3.4.1

3.3.4.2 ISIS ʵÀýÃû ............................................................................................................................ 33 3.3.4.3 ISIS NET ID ............................................................................................................................ 34 3.3.4.4 ISIS·ÓÉÆ÷ÀàÐÍ ..................................................................................................................... 34 3.3.4.5 ISIS Cost-style ........................................................................................................................ 34 3.3.4.6 ISISЭÒé½Ó¿ÚÀàÐÍ.................................................................................................................. 35 3.3.4.7 ISIS ¸ºÔؾùºâÌõÄ¿................................................................................................................. 35 3.3.4.8 ISIS ·ÓÉЭÒéÓÅÏȼ¶ ............................................................................................................. 35 3.3.4.9 ISIS ÖØ·Ö²¼Â·ÓÉ .................................................................................................................... 35 3.3.4.10 3.3.4.11 3.3.4.12 3.3.4.13 3.3.4.14 3.3.4.15 3.3.4.16 3.3.4.17 3.3.4.18 3.3.4.19 3.3.4.20 3.3.4.21

ISISÁÚ¾Ó¼ÓÃÜ .................................................................................................................... 36 ISIS½Ó¿ÚÐû¸æ .................................................................................................................... 36 ISIS costÖµ¹æ»® ................................................................................................................ 36 ISIS LSP×î´óÓÐЧʱ¼ä ..................................................................................................... 37 ¹Ø±ÕISIS hello ±¨ÎÄÌî³ä ................................................................................................. 38 ISIS LSP MTU .................................................................................................................... 38 ISIS LSPˢмä¸ôʱ¼ä ..................................................................................................... 38 ISIS¶¯Ì¬Ö÷»úÃû ................................................................................................................ 38 ISIS OVERBITλ ............................................................................................................... 39 ISISȱʡ·ÓÉ .................................................................................................................... 39 ISIS logÁھӱ仯ÐÅÏ¢ ...................................................................................................... 39 ÅäÖ÷¶Àý ............................................................................................................................ 39

3.3.5 BGPÅäÖÃ ........................................................................................................................ 40

¸ÅÊö .................................................................................................................................... 41 ×ÔÖÎϵͳ ............................................................................................................................ 41 ³ÇÓòÍøBGP ²¿Êð²ßÂÔ....................................................................................................... 41

3.3.5.1 3.3.5.2 3.3.5.3

3.3.5.4 BGP router-idÅäÖà ................................................................................................................. 42 3.3.5.5 BGP logÁھӱ仯ÐÅÏ¢ ........................................................................................................... 42 3.3.5.6

¹Ø±ÕBGPͬ²½ºÍ×Ô¶¯»ã×Ü ................................................................................................ 42

3.3.5.7 BGPÁÚ¾ÓMD5¼ÓÃÜ ................................................................................................................ 43 3.3.5.8 BGPʱ¼ä²ÎÊý .......................................................................................................................... 43 3.3.5.9 BGP community ÊôÐԹ滮 .................................................................................................... 43 3.3.5.10 3.3.5.11 3.3.5.12

163 BGP ·ÓɲßÂÔ ............................................................................................................ 43 CN2 BGP·ÓɲßÂÔ ............................................................................................................ 44 ÅäÖ÷¶Àý ............................................................................................................................ 44

3.3.6 RRÅäÖÃ .......................................................................................................................... 46

¸ÅÊö .................................................................................................................................... 47 ¹¦ÄÜÉè¼Æ ............................................................................................................................ 48 ÊÕ·¢Â·ÓɲßÂÔ ..................................................................................................................... 48

3.3.6.1 3.3.6.2 3.3.6.3

3.3.6.4 BGP Peer group̟̞ ............................................................................................................. 49

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ4Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

3.3.6.5

ÅäÖ÷¶Àý ............................................................................................................................ 49

3.3.7 3.3.8 3.3.9

ĬÈÏ·ÓɹÜÀí ................................................................................................................ 51 ¸ºÔؾùºâÅäÖà ................................................................................................................ 51 ²ßÂÔ·ÓÉÅäÖà ................................................................................................................ 52

¸ÅÊö .................................................................................................................................... 52 ²ßÂÔ·ÓɲßÂÔ£¨²Î¿¼£© ..................................................................................................... 52

3.3.9.1 3.3.9.2

3.4 MPLS±êÇ©ÅäÖù淶 ............................................................................................................... 53 3.4.1

MPLSÈ«¾ÖÅäÖà .............................................................................................................. 53

È«¾Ö¿ªÆôMPLS¹¦ÄÜ ......................................................................................................... 53

3.4.1.1

3.4.1.2 MPLS router-id ........................................................................................................................ 54 3.4.1.3

ÅäÖ÷¶Àý ............................................................................................................................ 55

3.4.2 LDPЭÒéÅäÖà ................................................................................................................ 55

3.4.2.1 LDPЭÒé¼ÓÃÜ .......................................................................................................................... 55 3.4.2.2 LDP±êÇ©·¢²¼ºÍ¹ÜÀí .............................................................................................................. 55 3.4.2.3 LDPЭÒéʱ¼ä²ÎÊý .................................................................................................................. 57 3.4.2.4 LDPÁÚ¾Ó¹ýÂË .......................................................................................................................... 57 3.4.2.5

ÅäÖ÷¶Àý ............................................................................................................................ 59

3.5 3.5.1

Íø¹ÜÅäÖà ............................................................................................................................. 59

SNMP¹ÜÀí´úÀíÅäÖà ..................................................................................................... 59

È«¾Ö¿ªÆôSNMP½ø³Ì......................................................................................................... 59

3.5.1.1

3.5.1.2 SNMP°æ±¾ ............................................................................................................................... 60 3.5.1.3 RO CommunityÖµ .................................................................................................................. 60 3.5.1.4 RW CommunityÖµ .................................................................................................................. 61 3.5.1.5 SNMP·ÃÎÊ¿ØÖÆÁбí ............................................................................................................... 61 3.5.1.6 IfindexË÷ÒýÒ»ÖÂÐÔ................................................................................................................. 61 3.5.1.7 ÅäÖ÷¶Àý ............................................................................................................................ 62

3.5.2 ¹ÊÕϹÜÀíÅäÖà ................................................................................................................ 62

3.5.2.1 SNMP TRAPÐÅÏ¢ÄÚÈÝ ............................................................................................................ 62 3.5.2.2 SNMP TRAP ·þÎñÆ÷µØÖ· ....................................................................................................... 63 3.5.2.3 SNMP TRAPÏûÏ¢Ô´µØÖ· ........................................................................................................ 63 3.5.2.4 SYSLOG·þÎñÆ÷µØÖ· ............................................................................................................... 63 3.5.2.5 SYSLOGÐÅÏ¢¼¶±ð ................................................................................................................... 63 3.5.2.6 SYSLOGÏûÏ¢Ô´µØÖ· ............................................................................................................... 64 3.5.2.7

ÅäÖ÷¶Àý ............................................................................................................................ 64

3.5.3 FlowÅäÖÃ ....................................................................................................................... 65

ÅäÖ÷¶Àý ............................................................................................................................ 66

3.5.3.1

3.6 QOSÅäÖù淶 ......................................................................................................................... 66 3.6.1

QoS·ÖÀàºÍ±ê¼Ç ............................................................................................................ 66

µÚ5Ò³

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

3.6.2 3.6.3 3.6.4 3.6.5 3.6.6 3.7 3.7.1 3.7.2 3.7.3 3.7.4

Ô¤Áô´ø¿í¹ÜÀí ................................................................................................................ 67 Á÷Á¿ÏÞËÙºÍÕûÐÎ ............................................................................................................ 67 ¶ÓÁе÷¶È ........................................................................................................................ 68 ÓµÈû±ÜÃâ ........................................................................................................................ 68 ÓëCN2ÍøµÄQoS¶Ô½Ó .................................................................. ´íÎó£¡Î´¶¨ÒåÊéÇ©¡£

×é²¥ÅäÖù淶 ..................................................................................................................... 73

×é²¥¸ÅÊö ........................................................................................................................ 73 ×é²¥ÅäÖà ........................................................................................................................ 74 ×é²¥RPÅäÖÃ.................................................................................................................. 75 ×é²¥MSDPÅäÖà ............................................................................................................ 76

3.8 BFDÅäÖù淶 .......................................................................................................................... 77 3.8.1 3.8.2 3.8.3 3.8.4 3.8.5 3.9 3.9.1 3.9.2

BFD¸ÅÊö ........................................................................................................................ 77 ¾²Ì¬BFD»á»°ºÍ½Ó¿Ú״̬Áª¶¯ ................................................................................... 78 ¾²Ì¬Â·ÓÉÅäÖÃBFD ........................................................................................................ 79 ISISЭÒéÅäÖÃBFD ........................................................................................................ 79 BGPЭÒéÅäÖÃBFD ........................................................................................................ 80

°²È«²ßÂÔÅäÖÃÍÆ¹ã ............................................................................................................. 81

Ô´µØÖ·ºÏ·¨ÐÔ¼ì²â ........................................................................................................ 81 ³ÇÓòÍøÉ豸°²È«¼Ó¹Ì²ßÂÔ ............................................................................................ 82

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾ µÚ6Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

µÚ1Õ ¸ÅÊö

Ϊ±£Ö¤³ÇÓòÍøµÄÔËÐÐÖÊÁ¿£¬±ØÐëÔÚÉ豸ÄÜÁ¦¡¢ÍøÂçÉè¼Æ¡¢ÍøÂçÅäÖá¢Î¬»¤Á÷³Ì¡¢Ö§³ÅϵͳµÈ»·½ÚÓèÒÔ±£ÕÏ¡£ÍøÂçÅäÖÃÖ÷ÒªÊÇָͨ¹ýÔÚÉ豸ÉÏʵʩ¾ßÌåÅäÖù淶£¬¿ªÆôÉ豸¿ØÖƲãÃæºÍת·¢²ãÃæµÄ¹¦ÄÜ£¬ÊµÏÖÍøÂçµÄ»¥Í¨£¬±£Ö¤ÍøÂç¾ß±¸Ô¤ÆÚµÄÒµÎñ³ÐÔØÄÜÁ¦¡£Í¬ÑùµÄÎïÀíÍøÂçÔÚ²»Í¬µÄÅäÖÃÏÂËùÌṩµÄÒµÎñ³ÐÔØÄÜÁ¦¿ÉÄܲî¾àÉõÔ¶£¬´ËÍ⣬ÓÉÓÚÍøÂç¹æÄ£²»¶ÏÀ©´ó£¬Éè±¸ÌØÐÔ²»¶Ï±ä»¯£¬ÅäÖù¤×÷ÕýÈÕÒæ±äµÃ¸´ÔÓ£¬È«ÍøÅäÖ÷¢Éú´íÎóµÄ¸ÅÂÊÒ²ÔÚÔö¼Ó£¬Òò´ËºÜÓбØÒª¶Ô³ÇÓòÍøÍøÂçÉ豸µÄÍøÂçÅäÖÃÓèÒԹ淶¡£

±¾¿ÎÌâÉæ¼°µÄ¶ÔÏó¾ÍÊdzÇÓòÍøÍøÂçÉ豸ÅäÖõÄÏà¹Ø¹æ·¶±ê×¼£¬Ä¿µÄÊÇΪ³ÇÓòÍøÎ¬»¤ÈËÔ±ÌṩʵÓÃά»¤¹¤¾ß¡£¿¼Âǵ½³ÇÓòÍøÍøÂçÉ豸ά»¤·Ö¹¤Ã÷È·£¬ÅäÖù淶°´·Ö²á½øÐбàд£¬±¾ÆªÖ»Õë¶Ô³ÇÓòÍøºËÐIJã·ÓÉÆ÷Éè±¸ÖÆ¶¨Ïà¹ØÅäÖù淶¡£

±¾ÎÄÖ÷ÒªÄÚÈݰ²ÅÅÈçÏ£º

1. ½éÉܳÇÓòÍøÓÅ»¯Ä¿±êÍøÂç½á¹¹ÒÔ¼°Â·ÓÉÆ÷ÔÚ³ÇÓòÍøÖеŦÄܶ¨Î»£» 2. ´ÓÍøÂçÅäÖ÷½Ãæ²ûÊöÅäÖÃ˵Ã÷ÒÔ¼°¹æ·¶ÒªÇ󣬲¢¸ø³öÖ÷Á÷·ÓÉÆ÷ÐͺÅÉ豸µÄÅäÖÃʾÀý¡£Õë¶Ô·ÓÉÆ÷É豸£¬ÍøÂçÅäÖÃÖ÷Òª°üÀ¨ÏµÍ³»ù±¾ÅäÖᢶ˿ÚÅäÖᢰ²È«ÅäÖá¢Íø¹ÜÅäÖõȡ£

3. Ìá³öÎĵµÎ¬»¤ºÍÖ´ÐеĹÜÀíÒªÇó¡£

1.1 ÊõÓïºÍËõдÓï±í

±¾ÎÄÖн«Ê¹ÓÃÏÂÁÐÊõÓïºÍËõд£¬³ý·ÇÎÄÖÐÌØ±ð˵Ã÷£¬·ñÔòÒâÒåÈçÏ£»¶ÔÓÚϱíÖÐδ˵Ã÷µÄÊõÓïºÍËõд£¬Ó¦×öÒµ½ç±ê×¼»ò¹ßÀýÀí½â¡£

AAA ACL AS BGP CAR CE CR ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

Autentication Authorization and Accounting ÈÏÖ¤¡¢ÊÚȨÓë¼Æ·Ñ Access Control List ·ÃÎÊ¿ØÖÆÁбí Autonomous System ×ÔÖÎϵͳ Boarder Gateway Protocol ±ß½çÍø¹ØÐ­Òé Committed Access Rate ³Ðŵ·ÃÎÊËÙÂÊ Customer Edge ¿Í»§±ßÔµÉ豸 Core Router ºËÐÄ·ÓÉÆ÷ µÚ1Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

DDoS DiffServ DSCP FRR GE GR HA HDLC H-QOS IP ISIS LDP LSP LSR MP-BGP MIB MPLS NSF NSR NTP OAM OSPF PE POS PPP QoS RR RSVP SDH SNMP SR TCP TE ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

Distributed Deny of Service ·Ö²¼Ê½¾Ü¾ø·þÎñ¹¥»÷ Differentiated Services ²î·Ö·þÎñ Differentiated Service Code Point ²î·Ö·þÎñ´úÂëµã Fast Re-route ¿ìËÙÖØÂ·ÓÉ Gigabyte Ethernet ǧÕ×ÒÔÌ«Íø Graceful Restart ƽ»¬ÖØÆô¶¯ High Availability ¸ß¿ÉÓÃÐÔ High Data Link Control ¸ß¼¶Êý¾ÝÁ´Â·¿ØÖÆ Hierarchical Quality of Servie Internet Protocol »¥ÁªÍøÐ­Òé Inter System to Inter System Öмäϵͳµ½Öмäϵͳ Label Distribution Protocol ±ê¼Ç·Ö·¢Ð­Òé Label Switching Path ±ê¼Çת·¢Â·¾¶ Label Switch Router ±ê¼Ç½»»»Â·ÓÉÆ÷ Multi-protocol Boarder Gate Protocol ¶àЭÒé±ß½çÍø¹ØÐ­Òé Management Information Base ¹ÜÀíÐÅÏ¢¿â Multiple Protocol Label Switching ¶àЭÒé±êÇ©½»»» Non stop Fowarding ²»¼ä¶Ïת·¢ Non stop Routing ²»¼ä¶Ï·ÓÉ Network Time Protocol Operation Administration and Maintenance ²Ù×÷ά»¤¹ÜÀí Open Shortest Path First Provider Edge ÔËÓªÉ̱ßÔµÉ豸 Packet over SDH SDH·â×°Êý¾Ý°ü Point to Point Protocol µãµ½µãЭÒé Quality of Service ·þÎñÖÊÁ¿ Route Reflector ·ÓÉ·´ÉäÆ÷ Resource Reservation Protocol ×ÊÔ´Ô¤ÁôЭÒé SymMetric Digital Hierarchy ͬ²½Êý×ÖÐòÁÐ Simple Network Management Protocol ¼òµ¥ÍøÂç¹ÜÀíЭÒé Service Router ÒµÎñ·ÓÉÆ÷ Transfer Control Protocol ´«Êä¿ØÖÆÐ­Òé Traffic Engineering Á÷Á¿¹¤³Ì µÚ2Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

UDP uRPF VPLS VPN VRF VRRP ÉÏÐÐÁ÷Á¿ ÏÂÐÐÁ÷Á¿ ¡­¡­ User Data Protocol Óû§Êý¾Ý±¨Ð­Òé Reverse Path Fowarding ·´Ïò·¾¶×ª·¢ Virtual Private LAN Service ÐéÄâרÓþÖÓòÍøÒµÎñ Virtual Private NetworkÐéÄâרÓÃÍø Virtual Routing and Forwarding ÐéÄâ·ÓÉת·¢ÊµÀý Virtual Routing Redundancy Protocol ÐéÄâ·ÓÉÈßÓàЭÒé Óû§·¢³öµÄÁ÷Á¿ Óû§ÊÕµ½µÄÁ÷Á¿ ¡­¡­

1.2 ÍøÂç½á¹¹ËµÃ÷ ¾­¹ý³ÇÓòÍø¸ÄÔìÀ©Èݺó£¬Ä¿±êÍøÂç½á¹¹ÈçÏÂͼËùʾ¡£IP ³ÇÓòÍø°üÀ¨³ÇÓò¹Ç¸ÉÍøºÍ¿í´ø½ÓÈëÍø£¬ÆäÖгÇÓò¹Ç¸ÉÍøÊÇÒµÎñ½ÓÈë¿ØÖÆµã£¨°üÀ¨BRAS ºÍSR£©¼°¿ØÖƵãÒÔÉϵijÇÓòÍøºËÐÄ·ÓÉÆ÷×é³ÉµÄÈý²ã·ÓÉÍøÂ磬»®·ÖΪºËÐIJãºÍÒµÎñ½ÓÈë¿ØÖÆ²ãÁ½²ã¡£ÒµÎñ½ÓÈë¿ØÖÆ²ã³Ð½Ó¿í´ø½ÓÈëÍøºÍ³ÇÓò¹Ç¸ÉÍø£¬¸ºÔðʵÏÖ¼¯ÖеÄÒµÎñÌṩºÍ¿ØÖÆ£¬BRAS ºÍSR ×÷ΪҵÎñ½ÓÈë¿ØÖÆ²ã×é³É²¿·Ö£¬ÊÇIP ³ÇÓòÍøÊµÏÖ¡°Óû§¿Éʶ±ð¡¢ÒµÎñ¿ÉÇø·Ö¡¢ÖÊÁ¿¿É¿ØÖÆ¡¢ÍøÂç¿É¹ÜÀí¡±µÄתÐÍÄ¿±êµÄÖØÒª»·½Ú¡£

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ3Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾ µÚ4Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

µÚ2Õ IP³ÇÓòÍøÍøÂçÉ豸ÃüÃû¼°Á´Â·ÃèÊö¹æ·¶

2.1 É豸ÃüÃû¹æ·¶

2.1.1 ÊÊÓ÷¶Î§

±¾²¿·Ö¹æ¶¨µÄIP³ÇÓòÍøÉ豸ÃüÃû¹æ·¶£¬ÊÊÓÃÓÚIP³ÇÓòÍøÄÚÒÔÏÂÉ豸£º ? ³ö¿ÚºËÐÄ·ÓÉÆ÷ ? »ã¾Û·ÓÉÆ÷ ? ·ÓÉ·´ÉäÆ÷ ? BRAS ? SR ? »ã¾Û½»»»»ú ? Ô°Çø½»»»»ú ? Â¥µÀ½»»»»ú ? DSLAM 2.1.2 É豸ÃüÃû¹æ·¶¸ñʽ ³ÇÊÐËõд ×Ö·û <6 ±ØÑ¡ ½ÚµãËõд ×Ö·û <8 ±ØÑ¡ É豸ÊôÐÔ ×Ö·û ¡Ü3 ±ØÑ¡ ÍøÂç(ÒµÎñ)ÀàÐÍ ×Ö·û ¡Ü4 ±ØÑ¡ É豸ÐͺŠ×Ö·û ¡Ü7 ¿ÉÑ¡ É豸ÐòºÅ Êý×Ö 3 ¿ÉÑ¡ | ·ûºÅ ×Ö·ûÊý Ñ¡Ïî - ×Ö·û 1 ±ØÑ¡ - ×Ö·û 1 ±ØÑ¡ . ×Ö·û 1 ±ØÑ¡ . ×Ö·û 1 ±ØÑ¡ - ×Ö·û 1 ¿ÉÑ¡ ? ×Öĸ´óС¸÷ÊÐÐèÒª²ÉÓÃͳһ±ê×¼£¬È«²¿´óд¡£ ? Á½¶Ë¡¢Öм䲻´øÈκοոñ¡£

? ³ÇÊбêʶ£¬È¡³ÇÊÐÃû³ÆÆ´ÒôµÄÊ××Öĸ´óдÈ磺ÄϾ©NJ¡¢ÑγÇYC¡£ ? ½Úµã±êʶ£¬È¡½ÚµãÃû³ÆÆ´ÒôµÄÊ××Öĸ´óд£¬ÈçÁ½½ÚµãµÄÊ××ÖĸÓÐÖØµþ£¬Ôò

ȡƴÒô²»ÏàͬµÄÓÃȫƴ£ºÈ¥·ÖÁ½ÖÖÇé¿ö£¬µ±ºóÒ»¸ö×Ö²»Í¬Ê±ÔòºóÒ»¸öȡȫƴ£¬µ±Ç°Ò»¸ö×Ö²»Í¬Ê±Ôòǰһ¸öȡȫƴ£¬È纺ÖÐÃÅ£¨HanZM£©ºÍºóÔ×ÃÅ£¨HouZM£©¡£

? »ªÎªÉ豸Ãû³Æ×î¶à×Ö·ûÊý£º

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ5Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

NE5000E¡¢ME60¡¢5200G¡¢NE80E×î¶à30¸ö×Ö·û£» ? ½¼ÊÐÇø½Úµã±êʶǰͳһÔö¼Ó½¼ÊÐÇøÃû³ÆÆ´ÒôµÄÊ××Öĸ£º

½­Äþ£ºNJJN ÆÒ¿Ú£ºNJPK ÁùºÏ£ºNJLH

? É豸ÊôÐÔ±êʶ£¬¹æ¶¨ÈçÏ£º

³ö¿Ú·ÓÉÆ÷£ºCR£¬ÈçºËÐÄ·ÓÉÆ÷¼æ×ö³ö¿Ú·ÓÉÆ÷ÔòÓÃCR »ã¾Û·ÓÉÆ÷£ºBR BRASÉ豸£ºBAS ÒµÎñ·ÓÉÆ÷£ºSR ·ÓÉ·´ÉäÆ÷£ºRR »ã¾Û½»»»»ú£ºBSW Ô°Çø½»»»»ú£ºASW Â¥µÀ½»»»»ú£ºLSW DslamÉ豸£ºDSL WLAN ACÉ豸£ºAC WLAN APÉ豸£ºAP ºÚ¶´É豸£ºHD DNSÉ豸£ºDNS

? É豸ÐòºÅ£¬È¡°¢À­²®Êý×Ö£¬´Ó1¿ªÊ¼¡£Í¬½ÚµãµÄÏàͬÊôÐÔµÄÉ豸¼äÒÔÉ豸

ÐòºÅÇø±ð¡£

? ÍøÂçÀàÐÍ£ºMAN (³ÇÓòÍø)£¬M2N£¨µÚ2Æ½ÃæÉ豸£© IDC£¨IDC£© NGN (NGN) ITV(IPTV) DCN

? É豸ÐͺţºÉ豸ÐͺűàÂë¡£

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾ µÚ6Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

É豸 CISCO CRS-1/MC CISCO 12X16 CISCO 12816 CISCO 6509 CISCO 7609 CISCO 7513 CISCO 2948 CISCO 3550 ALCATEL7750 FOUNDRY 8000 FOUNDRY 4000 SE800 SE1200 »ªÎªNE5000E »ªÎªNE80 »ªÎªNE40 ÖÐÐË T64G É豸ÐͺűàÂë CRS C12X16 C12816 C6509 C7609 C7513 C2948 C3550 AC7750 F8000 F4000 SE800 SE1200 NE5000E NE80 NE40 T64G µÚ7Ò³

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

ÖÐÐË T40G ÖÐÐË980X ÖÐÐË9210 Juniper E320 Juniper ERX1440 Juniper T1600 »ªÎª MA5200G »ªÎª5200F »ªÎª5200 »ªÎª5100 »ªÎª530X »ªÎª560X »ªÎª8505 »ªÎª8508 »ªÎª3026 »ªÎª2403X »ªÎª6506R »ªÎª6503 T40G ZTE980X ZTE9210 E320 ERX1440 T1600 MA5200G MA5200F MA5200 MA5100 MA530X MA560X S8505 S8508 S3026 S2403X S6506R S6503 ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾ µÚ8Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

±´¶û 730X ÖÐÐË8220

BL730X ZTE8220 ? ×Ô¶¨Òå×ֶΣ¬¿ÉÒÔ¼ÓÈëÍøÂç×ÓÀàÐͼ°É豸ÐͺŵÈÄÚÈÝ¡£ Àý×Ó£º

ʾÀý1£º³ÇÓòÍø³ö¿Ú·ÓÉÆ÷£¬ÄϾ©£¬Óθ©Î÷½Ö£¬µÚһ̨³ö¿Ú·ÓÉÆ÷£¬ÃüÃûΪ NJ-YFXJ-CR.MAN.CRS-1 ʾÀý2£º³ÇÓòÍø»ã¾Û·ÓÉÆ÷£¬ÄϾ©£¬ººÖÐÃÅ£¬µÚһ̨»ã¾Û·ÓÉÆ÷£¬ÃüÃûΪ NJ-HanZM-BR.MAN.C12816-1 ʾÀý3£º³ÇÓòÍøÒµÎñ·ÓÉÆ÷£¬ÄϾ©½­Äþ£¬ÌÀɽ£¬µÚһ̨ҵÎñ·ÓÉÆ÷£¬ÃüÃûΪ NJJN-TS-SR.MAN.C12816-1 ʾÀý4£º³ÇÓòÍø»ã¾Û½»»»»ú£¬ÄϾ©£¬Ð½ֿڣ¬µÚһ̨»ã¾Û½»»»»ú£¬ÃüÃûΪ NJ-XJK-BS.MAN.S8505-1 ʾÀý5£º³ÇÓòÍø½ÓÈë½»»»»ú£¬ÄϾ©£¬ºóÔ×ÃÅ£¬µÚһ̨½ÓÈë½»»»»ú£¬ÃüÃûΪNJ-HouZM-AS.MAN.T64G-1 ʾÀý6£ºIPTV·ÓÉÆ÷£¬ÄϾ©£¬ººÖÐÃÅ£¬µÚһ̨»ã¾Û·ÓÉÆ÷£¬ÃüÃûΪ NJ-HanZM-BR.ITV.C7609-1

2.2 ¶Ë¿ÚÃèÊö¹æ·¶ 2.2.1 »·»Ø½Ó¿ÚÃèÊö | ·ûºÅ ×Ö·ûÊý Ñ¡Ïî For ×Ö·û 3 ±ØÑ¡ - ×Ö·û 1 ±ØÑ¡ ¹¦ÄÜÃèÊö ×Ö·û´® ¡Ü30 ±ØÑ¡ ˵Ã÷£º For£º¹Ì¶¨×Ö·û´®¡£

¹¦ÄÜÃèÊö£ºÃèÊö¸Ãloopback¶Ë¿ÚÌØÊ⹦ÄÜ£¬ÎªÓÐÒâÒåµÄÓ¢ÎÄ×Ö·û´®¡£È磺Management¡¢Multicast¡¢VPN¡¢Global Routing¡¢BGP Load balanceµÈ¡£

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ9Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

interface Loopback0 description For-Management ip address 202.97.36.86 255.255.255.255 2.2.2 ÍøÂç¶Ë¿ÚÃèÊö¹æ·¶

2.2.2.1 ÊÊÓ÷¶Î§

±¾²¿·ÖÊÊÓÃÓÚ³ÇÓòÍøÉ豸µÄ»¥Á¬½Ó¿ÚÃèÊö¡£ »ªÎª£ºNE5000E½Ó¿ÚÃèÊö×î¶à242¸ö×Ö·û£¬NE80×î¶à80¸ö×Ö·û£¬ME60×î¶à64¸ö×Ö·û£¬5200G×î¶à80¸ö×Ö·û£» 2.2.2.2 ¶Ë¿ÚÃèÊö°üº¬ÏÂÃæ¼¸²¿·Ö | ·ûºÅ ×Ö·ûÊý Ñ¡Ïî uT:(ÉÏÐÐ)pT:(ƽÐÐ)dT:(ÏÂÐÐ) ×Ö·û 3 ±ØÑ¡ ¶Ô¶ËÉ豸Ãû³Æ ×Ö·û ¡Ü20 ±ØÑ¡ (Á´Â·´«Êä±àºÅ) ×Ö·û ¡Ü15 ±ØÑ¡ ¶Ô¶Ë¶Ë¿ÚÀàÐÍ ×Ö·û ¡Ü10 ±ØÑ¡ ¶Ô¶Ë¶Ë¿Ú±êÖ¾ Êý×Ö/×Ö·û ¡Ü8 ¿ÉÑ¡ £¨VR£© ×Ö·û ¡Ü10 ¿ÉÑ¡ : ×Ö·û 1 ±ØÑ¡ ¡°¶Ô¶Ë¶Ë¿ÚÀàÐÍ¡±Òª¸ù¾Ý¶Ô¶Ë²»Í¬É豸ÀàÐͽøÐÐÇø·Ö¹æ·¶£¬ ¡°¶Ô¶Ë¶Ë¿Ú±êÖ¾¡±±íʾÁ´Â·¶Ô¶ËÉ豸¶ÔÓ¦¶Ë¿ÚµÄ¾ßÌå±êÖ¾¹æ·¶£¬ ¡°(Á´Â·´«Êä±àºÅ)¡±±íʾÁ´Â·µÄ´«ÊäºÅ,Èç¹ûͬ»ú·¿ÄÚÉ豸»¥Á¬ÎÞ´«Êä±àºÅ,ÔòΪ(Local)¡£µ÷²âÆÚ¼äµÄÁ´Â·ÃèÊö×îºóÔö¼Ó¡°::PROCESSING¡±£¬µ÷²âÍê³É¼ÓÒµÎñºóÈ¡Ïû¡°::PROCESSING¡±¡£ ¶Ë¿ÚÀàÐÍÈçÏÂ±í£º

¶Ë¿ÚÀàÐÍ POS(2.5G) POS(10G) POS(40G) ÒÔÌ«(GE) ÒÔÌ«(10GE) ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

¶Ë¿ÚÃèÊö OC48POS*/*/* 10GPOS*/*/* 40GPOS*/*/* GE*/*/* 10GE*/*/* µÚ10Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

Àý×Ó£º

uT:NJ-YFXJ-CR.MAN.CRS-1:(Local)10GE0/0/1/0(VOD£©::PROCESSING 2.2.3 Óû§¶Ë¿Ú

¶ÔÓÚÁ¬½ÓÓû§µÄ½Ó¿Ú»ò×Ó½Ó¿Ú£¬×îÇ°ÃæÎªÌí¼Ó±¾µØ×¨Ïߺţ¬Èç¹ûÊdz¤Í¾VPNµç·£¬ÐèÒªÌí¼Ó±¾µØ½ÓÈëµç·ºÅ£¨±ÈÈçÄϾ©CTVPN52127A£©¡£ÁíÍ⣬½¨ÒéÌí¼ÓÓû§Ãû³ÆµÈÈçÏÂÐÅÏ¢¡£ ¸ñʽ£º רÏߺŠToÓû§±êʶ | ·ûºÅ ×Ö·ûÊý Ñ¡Ïî ±¾µØ×¨ÏߺŻòÕß½ÓÈëµç·ºÅ ¿Õ¸ñ ×Ö·û ¸ù¾Ýʵ¼ÊÇé¿ö ±ØÑ¡ To ¿Õ¸ñ Óû§±êʶ ¿Õ¸ñ ·ÖÅä´ø¿í ×Ö·û ¡Ü20 ±ØÑ¡ ×Ö·û 1 ±ØÑ¡ ×Ö·û ¡Ü5 ±ØÑ¡ ×Ö·û ×Ö·û ×Ö·û 1 2 1 ±ØÑ¡ ±ØÑ¡ ±ØÑ¡ ˵Ã÷£º ? ±¾µØ×¨ÏߺŻòÕß½ÓÈëµç·ºÅ£¬±ÈÈ磺IPCYW1248693 ? To:¹Ì¶¨×Ö·û´®£» ? Óû§±êʶ£ºÓÐÒâÒåµÄººÓïÆ´ÒôºÍÓïÒô×é³ÉµÄ×Ö·û´®£¬Óû§Ãû.Óû§ÐÔÖÊ£¬ÆäÖÐÓû§ÃûΪСд£¬Óû§ÐÔÖʼûÏÂ±í¹æ²ÎÕÕÏÂ±í½øÐй涨¡£ ¹«Ë¾ ֤ȯ ÒøÐÐ ÍÅÌå Õþ¸® Íø°É ÖÐСѧ ´óѧ CORP SECU BANK COMM GOVE NETB SCHO UNIV ʾÀý1£º IPCYW2517649 To DaJinTouZi.CORP 3M ±íʾÓû§Îª´ó½ðͶ×ʹ«Ë¾£¬Ê¹ÓÃ3M´ø¿í¡£

2.2.4 ¿ÕÏж˿ÚÃèÊö

¹æ·¶ÒªÇóÉ豸ÉϵÄËùÓпÕÏÐδÓõĶ˿Úͳһshutdown£¬±ãÓÚÍø¹Ü¼à¿Ø¡£

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾ µÚ11Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

µÚ3Õ ³ö¿Ú·ÓÉÆ÷NE5000EÅäÖù淶

3.1 ϵͳ»ù±¾ÅäÖù淶

3.1.1 É豸Ãû³ÆÅäÖÃ

ÅäÖÃ˵Ã÷£º

¹æ·¶É豸ÃüÃû£¬Î¨Ò»ÐÔ±êʶ³ÇÓòÍøÖеÄÿ̨É豸£¬ÓÃÓÚ¶Ô³ÇÓòÍøµÄÿ̨É豸½øÐÐÇø·Ö£¬·½±ãÉ豸¹ÜÀí£¬Ìá¸ß¿É¶ÁÐԺͿɹÜÀíÐÔ¡£ ¹æ·¶ÒªÇó£º É豸Ãû³ÆÒªÇó·ûºÏµÚ¶þÕÂÖС°IP³ÇÓòÍøÍøÂçÉ豸ÃüÃû¼°Á´Â·ÃèÊö¹æ·¶¡±Öй涨¡£ ÅäÖù淶£º # sysname YC-836-CR.MAN.NE5000E-1 ÅäÖÃ×¢Òâϸ½Ú£º ¿ÉÒÔ¸ù¾ÝÐèÒªÌí¼ÓÉ豸ÐͺÅÔÚ.MANºó¡£ ¸î½Ó¹ý¶ÉÆÚ¼äÐÂÉ豸¼ÓN£¬ÈçYC-836-CR.MAN.NE5000E-N1£¬¸î½ÓºóÓ¦¼°Ê±½«Nɾ³ý¡£ 3.1.2 BannerÅäÖà ÅäÖÃ˵Ã÷£º ͳһBannerÓïÑÔ£¬ÒÔÊ¡Íø±ê׼ΪÖ÷¡£ ¹æ·¶ÒªÇó£º ËùÓгö¿Ú·ÓÉÆ÷ÅäÖÃͳһµÄBannerÐÅÏ¢£¬µÇ½ʱÌáʾ£º WARNING!!! Authorised access only, all of your done will be recorded! disconnect IMMEDIATELY if you are not an authorised user! ÅäÖù淶£º

[Quidway] header login information % WARNING!!! Authorised access only, all of your done will be recorded! disconnect IMMEDIATELY if you are not an authorised user!% ÅäÖÃÑéÖ¤£º

µÇ½·ÓÉÆ÷ʱӦ¿´µ½bannerÌáʾ¡£ ÅäÖÃ×¢Òâϸ½Ú£º

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ12Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

BannerÓïÑÔÓ¦Æðµ½ÌáʾºÍ¾¯¸æ·ÇÊÚȨ·ÃÎÊÕßµÄ×÷Óã¬ÑϽûÔÚBannerÖгöÏÖÈκαíʾ»¶Ó­µÄ×ÖÑù¡£

3.1.3 É豸×ÔÉíʱ¼ä¼°NTP

NTPʵÏÖÍøÂçÉ豸ʱ¼äͬ²½¹¦ÄÜ£¬Óëʱ¼äÓйصÄÓ¦Óã¬ÀýÈçLogÐÅÏ¢£¬»ùÓÚʱ¼äÏÞÖÆ´ø¿íµÈ£¬¶¼ÐèÒª»ùÓÚÕýÈ·µÄʱ¼ä¡£

3.1.3.1 Ê±ÇøÅäÖà ÅäÖÃ˵Ã÷£º ͳһÉ豸µÄÊ±ÇøÅäÖᣠ¹æ·¶ÒªÇó£º ÅäÖÃÏµÍ³Ê±ÇøÎªGMT+8£¬±±¾©Ê±Çø¡£ ÅäÖù淶£º clock timezone BeiJing minus 08:00:00 #ÔÚÓû§Ä£Ê½ÏÂÅäÖà ÅäÖÃÑéÖ¤£º display clock ÅäÖÃ×¢Òâϸ½Ú£º Òò±±¾©´¦ÓÚ+8Ê±Çø£¬Ê±¼äÆ«ÒÆÁ¿Ôö¼ÓÁË8£»ÄÇôÔÚÅäÖÃʱ£¬¾ÍÊÇÔÚϵͳĬÈϵÄUTCÊ±ÇøµÄ»ù´¡ÉÏ£¬¼õÈ¥Æ«ÒÆÁ¿8 £¬²ÅÄܵõ½Ô¤ÆÚµÄBeiJingÊ±Çø¡£ 3.1.3.2 ϵͳ±¾µØÊ±¼ä ÅäÖÃ˵Ã÷£º ʹÓÃNTPЭÒéͬ²½ÍøÂçÉÏËùÓÐÉ豸µÄʱ¼ä£¬±£Ö¤ÍøÂçÉ豸µÃµ½ÕýÈ·µÄʱ¼ä¡£ ¹æ·¶ÒªÇó£º

¹Ç¸ÉÉ豸ÄϾ©C1, ÄϾ©C4 ×÷Ϊ½­ËÕÊ¡ÄÚ³ÇÓòÍø³ö¿Ú·ÓÉÆ÷µÄNTP SERVER£» ³ÇÓòÍøÅäÖÃÖ÷ºÍ±¸Á½×éNTP·þÎñÆ÷£¬²¢·ÖΪÁ½¼¶½á¹¹£º

³ÇÓòÍø³ö¿Ú×÷ΪNTP CLIENT£¬ÅäÖÃÓë202.97.32.192 , 202.97.32.187ͬ²½Ê±ÖÓ£»³ÇÓòÍø³ö¿Ú×öΪNTP SERVER£¬ÅäÖÃNTP ËùÔÚÖ÷ʱÖÓ²ãÊýΪĬÈÏ£¬³ö¿ÚÒÔÏÂÉ豸ÔòÅäÖÃÏò³ö¿Ú·ÓÉÆ÷½øÐÐʱÖÓͬ²½¡£

ÅäÖÃÏÖÍøÉ豸NTPЭÒé°æ±¾ÎªV3¡£

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ13Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

Ö¸¶¨±¾µØ·¢³öNTPÏûÏ¢µÄ½Ó¿Ú¡£ ÅäÖù淶£º

ntp-service source-interface LoopBack0 ntp-service unicast-server 202.97.32.192 preference #Ö÷Ó÷þÎñÆ÷£¬ÄϾ©C1 ntp-service unicast-server 202.97.32.187 #±¸Ó÷þÎñÆ÷, ÄϾ©C4 ntp-service refclock-master 8 #×÷Ϊ³ÇÓòÍøÄÚBRAS/SRµÄntp server£¬È¡Ä¬ÈϲãÊýΪ8 ÅäÖÃÑéÖ¤£º

display ntp-service status display ntp-service session ÅäÖÃ×¢Òâϸ½Ú£º »ªÎªNE·ÓÉÆ÷ĬÈÏNTPЭÒé°æ±¾ºÅΪV3£¬²»ÐèÌØ±ðÅäÖð汾ÐÅÏ¢¡£ ÅäÖÃÏÞÖÆNTP PEERµÄ¿ØÖÆÁбíͳһȡֵΪ2579¡£ 3.1.3.3 NTPÏûÏ¢Ô´µØÖ· ÅäÖÃ˵Ã÷£º Ö¸¶¨±¾µØ·¢³öNTPÏûÏ¢µÄ½Ó¿Ú¡£ ¹æ·¶ÒªÇó£º ³ÇÓòÍøºËÐIJ㡢ҵÎñ¿ØÖƲãÉ豸µÄʹÓÃLoopback0 µØÖ·×÷ΪNTPÏûÏ¢Ô´µØÖ·¡£ ÅäÖù淶£º ntp-service source-interface loopback 0 ÅäÖÃÑéÖ¤£º display current | i ntp-service ÅäÖÃ×¢Òâϸ½Ú£º ÎÞ¡£ 3.1.3.4 NTPЭÒé¼ÓÃÜ ÅäÖÃ˵Ã÷£º

ÅäÖÃNTPЭÒé¼ÓÃÜ£¬·ÀֹαÔìNTPÔ´ÒýÆðÉ豸ʱ¼ä´íÎó¡£ ¹æ·¶ÒªÇó£º

Òò²¿·ÖÉ豸²»Ö§³ÖNTPЭÒé¼ÓÃÜ£¬ÎªÁËÈ«ÍøÍ³Ò»¹æ·¶£¬ÏÖ½×¶ÎNTPЭÒé¾ù²»Ê¹ÓÃʹÓüÓÃÜ¡£

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ14Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

ÅäÖù淶£¨²Î¿¼£©£º

ntp-service authentication enable ntp-service authentication-keyid 11 authentication-mode md5 ¡°xxx¡± #key ntp-service reliable authentication-keyid 11 ÅäÖÃÑéÖ¤£º display clock display ntp-service status display ntp-service session ÅäÖÃ×¢Òâϸ½Ú£º ÎÞ¡£

3.1.3.5 SNTP½ø³Ì¹Ø±Õ ÅäÖÃ˵Ã÷£º SNTPÊÇNTPЭÒéµÄµÄÒ»¸ö¸Äд±¾£¬Ïà±ÈNTPЭÒéʵÏÖ¸ü¼òµ¥£¬µ«¾«È·¶ÈÒªµÍ£¬²»ÄÜͬʱÓë¶à¸öServerͬ²½Ê±¼ä¡£¹Ø±ÕSNTPЭÒ飬¿É·ÀÖ¹»ùÓÚSNTP©¶´µÄ¹¥»÷¡£

¹æ·¶ÒªÇó£º ³ö¿Ú·ÓÉÆ÷ÅäÖÃʹÓÃNTPЭÒéͬ²½Ê±¼ä£¬¶ø²»ÊÇʹÓÃSNTPЭÒé¡£ÒÑÅäÖÃÁËʹÓÃSNTPЭÒéͬ²½Ê±¼äµÄ£¬Ó¦¸ü¸ÄSNTPЭÒéΪNTPЭÒé¡£ ÅäÖù淶£º NE5000EĬÈϹرÕSNTP½ø³Ì£¬²»ÐèÒªÌØ±ðÅäÖᣠÅäÖÃÑéÖ¤£º ÎÞ¡£ ÅäÖÃ×¢Òâϸ½Ú£º ÎÞ¡£ 3.1.3.6 ÅäÖ÷¶Àý clock timezone BeiJing minus 08:00:00 #Ê±ÇøÉèÖã¨Óû§ÊÓͼ£© ntp-service source-interface LoopBack0 ntp-service unicast-server 202.97.32.192 preference #Ö÷Ó÷þÎñÆ÷,ÄϾ©C1 ntp-service unicast-server 202.97.32.187 #±¸Ó÷þÎñÆ÷,ÄϾ©C4 ntp-service refclock-master 8 #³ÇÓòÍø³ö¿Ú·ÓÉÆ÷£¬×÷Ϊ³ÇÓòÍøÄÚBRAS/SRµÄntp server£¬ÌṩʱÖÓ·þÎñ ÅäÖÃacl£¬ÏÞÖÆpeer µÄ·ÃÎÊ acl 2579 acl number 2579 description this acl is used ntp peer rule 10 permit source 202.97.32.192 0 rule 15 permit source 202.97.32.187 0 rule 20 permit source 61.177.248.0 255.255.255.0 ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ15Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

rule 100 deny ntp-service access peer 2579 3.1.4 TelnetÅäÖÃ

3.1.4.1 Á¬½ÓÊýÏÞÖÆ ÅäÖÃ˵Ã÷£º

¶ÔͬʱԶ³ÌµÇ½µ½É豸ÉϵÄsessionÊý½øÐÐÏÞÖÆ£¬¿ÉÒÔ·ÀÖ¹´óÁ¿µÄsessionÁ¬½ÓÕ¼Óùý¶àϵͳ×ÊÔ´£¬Í¬Ê±±ãÓÚ¼¯ÖÐÔËά£¬±£Ö¤¹ÊÕÏÆÚ¼äµÄÕý³£´¦Àí¡£ ¹æ·¶ÒªÇó£º ÅäÖóö¿Ú·ÓÉÆ÷Telnet×î´óÁ¬½ÓÊýÏÞÖÆÎª5¸ö£¨7750ÉèÖÃΪ7£©¡£ ÅäÖù淶£º user-interface maximum-vty 5 ÅäÖÃÑéÖ¤£º display user-interface maximum-vty ÅäÖÃ×¢Òâϸ½Ú£º »ªÎª¼°CISCOÉ豸 VTYÁ¬½ÓÊýÏÞ֯ĬÈÏΪ5¡£ 3.1.4.2 ¿ÕÏÐʱ¼ä ÅäÖÃ˵Ã÷£º ÉèÖÃÁËTelnet³¬Ê±¹¦ÄÜ£¬µ±¿ÕÏÐʱ¼ä³¬¹ýÉ趨ֵºó£¬TelnetÏ̶߳Ͽª£¬·Àֹδ±»ÊÚȨµÄÈËÔ±ÔÚ²Ù×÷Ô±À뿪ºó½øÐзǷ¨²Ù×÷¡£ ¹æ·¶ÒªÇó£º ¶ÔVTY, Console,AUXµÇ¼³¬Ê±ÉèÖýøÐÐÅäÖã¬ÉèÖÿÕÏÐʱ¼äΪ10·ÖÖÓ¡£ ÅäÖù淶£º

user-interface console 0 idle-timeout 10 0 user-interface aux 0 idle-timeout 10 0 user-interface vty 0 9 idle-timeout 10 0 ÅäÖÃÑéÖ¤£º ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ16Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

disp curr | b user-interface ÅäÖÃ×¢Òâϸ½Ú£º »ªÎªÉ豸ĬÈϳ¬Ê±Ê±¼ä¼´Îª10·ÖÖÓ£¬ÅäÖúóÒ²²»»áÏÔʾÅäÖᣠ3.1.4.3 TELNET·ÃÎÊ¿ØÖÆÁбí ÅäÖÃ˵Ã÷£º

ÏÞÖÆTelnetµÇÂ¼ÍøÂçµÄÔ´µØÖ·£¬´Ó¶øÔöÇ¿É豸µÄ°²È«ÐÔ£¬×î´óÏÞ¶È·ÀÖ¹·Ç·¨µÇ½³¢ÊÔ¡£

¹æ·¶ÒªÇó£º ÅäÖÃTelnetÔ´µØÖ·ÏÞÖÆ£¬°üº¬Ê¡¹«Ë¾µØÖ·ºÍ×îС»¯µÄµØÊÐÍø¹ÜÖÐÐÄά»¤IPÍø¶Î¡£ Telnet·ÃÎÊ¿ØÖÆÁбíÌõÄ¿´Ó10¿ªÊ¼£¬ÌõÄ¿µÄ¼ä¸ô²½³¤Îª5£¬ÔÚ·ÃÎÊ¿ØÖÆÁбíµÄ×îºóÏÔʾÅäÖÃÒ»Ìõdeny source anyÓï¾ä¡£ ÅäÖù淶£º acl number 2577 description this acl is used telnet rule 10 permit source *.*.*.* *.*.*.* rule 15 permit source *.*.*.* *.*.*.* rule 3000 deny any ÅäÖÃÑéÖ¤£º disp acl 2577 disp curr | b user-interface ÅäÖÃ×¢Òâϸ½Ú£º »ªÎªÉ豸Telnet ACLͳһʹÓñàºÅ2577¡£ 3.1.4.4 ÅäÖ÷¶Àý ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾ µÚ17Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

acl number 2577 description this acl is used telnet

rule 10 permit source 61.155.48.0 0.0.0.255 rule 15 permit source 61.177.248.0 0.0.1.255 rule 20 permit source 202.102.15.200 0

rule 25 permit source 202.102.37.64 0.0.0.31 rule 3000 deny any

user-interface vty 0 4

acl 2577 inbound #ÉèÖÃVTY¿ÚµÇ¼¿ØÖÆÁбíΪ2577

disp acl 2577

disp curr | b user-interface

×¢Ò⣺

ÐÞ¸ÄACLʱ£¬ÏÈɾ³ýVTYÏÂaclµÄÓ¦ÓÃ,Èçundo acl inbound£¬¶ø²»ÊÇundo acl xxx inbound£¬ÔÙÖØÐÂÓ¦ÓÃеÄacl¡£

3.1.5 AAAÅäÖÃ

3.1.5.1 AAA·þÎñÆ÷IPµØÖ·ºÍ¶Ë¿ÚºÅ ÅäÖÃ˵Ã÷£º

ÅäÖÃAAA·þÎñÆ÷IPµØÖ·£¬Tacacs+ЭÒéÖ§³ÖʹÓÃMD5Ëã·¨À´¼ÓÃܽ»»¥µÄTacacs+±¨ÎÄ£¬Í¨ÐÅË«·½Í¨¹ýÉèÖüÓÃÜÃÜÔ¿À´ÑéÖ¤±¨ÎĵĺϷ¨ÐÔ¡£Ö»ÓÐÔÚÃÜÔ¿Ò»ÖµÄÇé¿öÏ£¬Ë«·½²ÅÄܱ˴˽ÓÊÕ¶Ô·½·¢À´µÄ±¨ÎIJ¢×÷³öÏìÓ¦¡£

¹æ·¶ÒªÇó£º

¸ù¾ÝAAAÈÏÖ¤·þÎñÆ÷µÄÀàÐÍÖ¸¶¨²ÉÓÃTacacs+ÈÏÖ¤£»

Àý£ºÖ¸¶¨Tacacs+·þÎñÆ÷µØÖ·Îª£º221.231.148.6£¬ÈÏÖ¤ÃÜԿΪXXX¡£²¢Ôö¼Ó±¸ÓÃTacacs+·þÎñÆ÷µØÖ·61.177.64.146£¬ÈÏÖ¤ÃÜԿΪXXX¡£

3.1.5.2 AAAÏûÏ¢Êý¾Ý°üÔ´µØÖ· ÅäÖÃ˵Ã÷£º

ÅäÖÃAAAÏûÏ¢Êý¾Ý°üÔ´µØÖ·¡£ ¹æ·¶ÒªÇó£º

Ö¸¶¨³ö¿Ú·ÓÉÆ÷AAAÏûÏ¢Êý¾Ý°üÔ´µØÖ·ÎªLoopback0½Ó¿ÚµØÖ·¡£ 3.1.5.3 ÈÏ֤ģʽ ÅäÖÃ˵Ã÷£º

AAAµÄÈÏÖ¤×é¼þ¸ºÔðÌṩʶ±ð£¨ÈÏÖ¤£©Óû§µÄ·½·¨¡£¿ÉÄܰüÀ¨µÇ¼·ÃÎÊ£¬ÒÔ¼°

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ18Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

ÆäËûÀàÐ͵ķÃÎÊ¡£Ê¹ÓÃAAAÈÏ֤ʱ£¬¶¨ÒåÁËÒ»¸öºÍ¸ü¶àµÄÈÏÖ¤·½·¨£¬¹©Â·ÓÉÆ÷ÔÚÈÏÖ¤Ò»¸öÓû§Ê±Ê¹Óá£

¹æ·¶ÒªÇó£º

ÅäÖÃÈÏÖ¤·½Ê½Ë³ÐòΪÊ×ÏÈÑ¡ÓÃTacacs+·þÎñÆ÷£¬Æä´ÎÑ¡Óñ¾µØÓû§ÐÅÏ¢½øÐÐÈÏÖ¤¡£

ÅäÖÃ×¢Òâϸ½Ú£º

²»Í¬³§¼ÒAAAÈÏÖ¤µÄ˳Ðò²îÒì½Ï´ó£¬ÐèҪעÒâ¡£ 3.1.5.4 ÊÚȨģʽ ÅäÖÃ˵Ã÷£º

Óû§ÈÏÖ¤³É¹¦Íê³ÉÖ®ºó£¬AAAÊÚȨÓÃÀ´ÏÞÖÆÒ»¸öÓû§ÄÜÖ´ÐÐʲôÐÐΪ»òÕßÒ»¸öÓû§ÄÜ·ÃÎÊʲô·þÎñ¡£ÅäÖÃÓÉÏÈTACACS·þÎñÆ÷ÊÚȨ£¬ºó±¾µØÓû§ÊÚȨ¡£Óû§·Ö3¸öµÈ¼¶£º

1¼¶Ö»¾ßÓÐÒ»°ãµÄ²é¿´È¨ÏÞ£¬²»¾ßÓв鿴ÅäÖÃȨÏÞ£» 2¼¶¾ßÓÐ1¼¶µÄ²é¿´È¨ÏÞ¡¢ÅäÖýӿÚȨÏÞ£» 3¼¶È«²¿²Ù×÷ȨÏÞ¡£ ¹æ·¶ÒªÇó£º

ÅäÖÃÓÉÊ×ÏÈTACACS·þÎñÆ÷ÊÚȨ£¬Æä´Î±¾µØÓû§ÊÚȨ£¬Óû§·Ö3¸öµÈ¼¶¡£ 3.1.5.5 Éó¼ÆÄ£Ê½ ÅäÖÃ˵Ã÷£º

AAAÉ󼯹¦ÄܸºÔð¶ÔÈÏÖ¤ºÍÊÚȨÐÐΪʼþ±£³Ö¼Ç¼¡£AAAµÄÉ󼯹¦Äܱ£³ÖʼþµÄÈÕÖ¾¼Ç¼¡£É󼯹¦ÄÜÒªÇóÓÐһ̨ÍⲿAAA°²È«·þÎñÆ÷À´´æ´¢Êµ¼ÊµÄ¼ÇÕʼǼ¡£

¹æ·¶ÒªÇó£º

ÅäÖÃTacacs+·þÎñÆ÷¶ÔµÇ½É豸µÄÓû§½øÐÐÉ󼯼Ǽ¡£ 3.1.5.6 ±¾µØÓû§ÕʺŠÅäÖÃ˵Ã÷£º

ÅäÖñ¾µØÓû§Õʺţ¬×÷ΪAAA·þÎñÆ÷Á¬½Óʧ°ÜʱµÄÓ¦¼±µÇ½Óá£ÅäÖñ¾µØÓû§ÕʺÅadmin£¬ÉèÖÃ×î¸ßȨÏÞ£¬Ê¹ÓÃÊ¡¹«Ë¾Í³Ò»Ö¸¶¨µÄÃÜÂ롣·ÓÉÆ÷µÄCONSOLE¿Ú½öÔÊÐí±¾µØÕʺÅÈÏÖ¤£¬²»Ê¹ÓÃAAA·þÎñÆ÷ÈÏÖ¤¡£

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ19Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

¹æ·¶ÒªÇó£º

ÉèÖÃ×î¸ßȨÏ޵ı¾µØÕ˺ţ¬ÓÃÓÚÓ¦¼±µÇ½¡£ 3.1.5.7 ÅäÖ÷¶Àý

#ÅäÖÃHWTACACS·þÎñÆ÷Ä£°åtongyirenzheng£¬Ô´µØÖ·ÎªÉ豸LOOPBACK0µØÖ·£¬ÃÜԿΪXXX£¬Óû§Ãû¸ñʽÖв»°üÀ¨ÓòÃû¡£

hwtacacs-server template tongyirenzheng hwtacacs-server authentication 221.231.148.6

hwtacacs-server authentication 61.177.64.146 secondary hwtacacs-server authorization 221.231.148.6

hwtacacs-server authorization 61.177.64.146 secondary hwtacacs-server accounting 221.231.148.6

hwtacacs-server accounting 61.177.64.146 secondary hwtacacs-server source-ip *.*.*.* hwtacacs-server shared-key xxx

undo hwtacacs-server user-name domain-included

aaa #½øÈëAAAÊÓͼ

#ÅäÖÃÈÏÖ¤·½°¸hwtacacs£¬ÈÏ֤ģʽÏȲÉÓÃtac·þÎñÆ÷ÈÏÖ¤£¬ºó²ÉÓñ¾µØÈÏÖ¤¡£ authentication-scheme hwtacacs

authentication-mode hwtacacs local

#ÅäÖÃÊÚȨ·½°¸hwtacacs£¬ÏȲÉÓÃtac·þÎñÆ÷ÊÚȨ£¬ºó²ÉÓñ¾µØÓû§ÊÚȨ¡£ authorization-scheme hwtacacs

authorization-mode hwtacacs local

#ÅäÖüƷѷ½°¸hwtacacs£¬Ê¹ÓÃtac·þÎñÆ÷½øÐмƷѡ£ accounting-scheme hwtacacs accounting-mode hwtacacs

#ÅäÖüǼ·½°¸hwtacacs£¬Óë¼Ç¼·½·¨¹ØÁªµÄhwtacacs·þÎñÆ÷Ä£°åµÄÃû³ÆÎªÉÏÃæÅäÖõÄhwtacacs¡£×¢Ò⣺ÔÚʹÓÃrecording-mode hwtacacsÃüÁîǰ£¬hwtacacs·þÎñÆ÷Ä£°å±ØÐëÒѾ­´´½¨Íê³É¡£

recording-scheme hwtacacs

recording-mode hwtacacs tongyirenzheng

#ÉèÖÃϵͳʼþµÄ¼Ç¼²ßÂÔ£¬Ä¿Ç°Ö§³Ö¶ÔrebootÃüÁîµ¼ÖµÄʼþ½øÐмǼ¡£ system recording-scheme hwtacacs

#ÉèÖöÔÓÚ·ÓÉÆ÷×öΪ¿Í»§¶Ë½øÐеIJÙ×÷µÄ¼Ç¼²ßÂÔ£¬Ä¿Ç°Ö§³Ö¶ÔTelnet¿Í»§¶ËµÄ¼Ç¼¡£ÃüÁîÖÐÒýÓõļǼ·½°¸Ãû³Æ±ØÐëÊÇÒѾ­´´½¨Íê³ÉµÄ¼Ç¼·½°¸¡£ outbound recording-scheme hwtacacs

#ÉèÖÃÓû§ÔÚ·ÓÉÆ÷ÉÏËùÖ´ÐеÄÃüÁîµÄ¼Ç¼²ßÂÔ£¬ÅäÖøÃÃüÁîºó£¬¿ÉÒÔ¶ÔÉ豸Çé¿ö½øÐмǼ£¬¶Ô¼à¿ØºÍ¹ÊÕÏ´¦ÀíÓÐÒ»¶¨µÄ°ïÖú¡£ cmd recording-scheme hwtacacs

#ÅäÖÃȱʡÓòdefaul£¬ÓòµÄÈÏÖ¤·½°¸¡¢¼Æ·Ñ·½°¸¡¢ÊÚȨ·½°¸Ãû³Æ¶¼Îªhwtacacs¡£

domain default

authentication-scheme hwtacacs authorization-scheme hwtacacs accounting-scheme hwtacacs hwtacacs-server tongyirenzheng

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ20Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

#¹æ·¶±¾µØlevel 3 µÄÕʺÅ: local-user admin password cipher admin local-user admin level 3 local-user admin service-type terminal telnet user-interface con 0 authentication-mode password //con¿Ú£¬±¾µØÈÏ֤ģʽ set authentication password cipher XXX //¿É¸ù¾ÝÊ¡NOCͳһ¹æ»® ¼ì²é: display authentication-scheme hwtacacs display authentication-scheme hwtacacs display authorization-scheme hwtacacs display hwtacacs-server template tongyirenzheng display domain default display local-user 3.1.6 ϵͳ¸ß¿É¿¿ÐÔÅäÖà ÅäÖÃ˵Ã÷£º ÅäÖÃϵͳÒýÇæÈßÓàģʽ¡£ ¹æ·¶ÒªÇó£º ´ò¿ª×Ô¶¯Çл»£¬ÒªÇó²ÉÓÃ×îÓÅÇл»·½Ê½¡£ ÅäÖù淶£º »ªÎªNE·ÓÉÆ÷Á½¿éÒýÇæÖ®¼äµÄ±¸·Ý»úÖÆÊÇϵͳ×Ô¶¯µÄ£¬ÔÚMasterÒýÇæ¹ÊÕϵÄÇé¿öÏ£¬Slave»áÁ¢¿Ì×Ô¶¯½«×Ô¼ºÇл»ÎªMasterÒýÇæ£¬ÎÞÐèÃüÁîÅäÖᣠÅäÖÃÑéÖ¤£º display device #ÏÔʾ2¿éMPUΪ1¸öΪMaster״̬£¬Ò»¸öΪSlave״̬ display switchover state #ÏÔʾ±¸·Ý״̬£¬µ±×´Ì¬Îª¡°Info:HA FSM State, Realtime and routine backup.¡±Ê±¼´±íʾ¿ÉÒÔ½øÐÐÖ÷±¸Çл»£¬µ±×´Ì¬ÎªÖ÷±¸ÒýÇæÕýÔÚͬ²½Ê±£¬Çл»¿ÉÄÜ»áÓÐÎÊÌâ ÅäÖÃ×¢Òâϸ½Ú£º ÎÞ¡£

3.2 ¶Ë¿ÚÅäÖù淶

3.2.1 MTUÖµÉè¼Æ

³ÇÓòÍøÂ·ÓÉÐÍÉ豸¶Ë¿ÚMTUµÄÉèÖÃÖ÷ÒªÊܶà¸ö·½ÃæÒòËØÓ°Ï죺

? IP³ÇÓòÍøÄÚ²¿Í³Ò»IP MTUÖµ(MPLS MTUËæIP MTU×Ô¶¯µ÷Õû)£»¶Ô³§¼Ò¡¢

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ21Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

»úÐÍ¡¢°å¿¨ÀàÐÍ¡¢¶Ë¿ÚÀàÐͶ¼Í³Ò»£»

? L3 Protocol MTUÖµ¾¡¿ÉÄÜÈ¡´óÖµ£¬ÒÔ¼Ó¿ìЭÒéÊÕÁ²£»

? IGP·ÓÉЭÒéÁÚ¾Ó¹ØÏµµÄ½¨Á¢£¬ÐèÒªÁ½²àÉ豸¶Ë¿ÚMTUÖµ±£³ÖÒ»Ö£» ? ½ÓÈëÍøµÄÒÔÌ«»¯£¬Öն˲àMTU¾ù²»³¬¹ý1500£»

? ÓëÍⲿÁ¬½Ó¶Ë¿ÚµÄMTUÖµÐèÓë¶Ô¶ËÉ豸ЭÉ̱£³ÖÒ»Ö£¬¾¡¿ÉÄÜÈ¡´óÖµ¡£ ? PIM JoinÏûÏ¢ÒÔ¶Ë¿ÚMTUΪ»ù×¼£¬½øÐÐJoin Êý¾Ý°ü·ÖƬ£» ? ISISЭÒéLSPÊý¾Ý°üĬÈÏ×î´óֵΪ1497£»

¹æ·¶IP³ÇÓòÍøÂ·ÓÉÐÍÉ豸µÄËùÓл¥Á¬¶Ë¿Ú£¬GE/10GEÒÔÌ«Íø¿ÚIP MTUͳһȡֵΪ1600×Ö½Ú£»POS¿ÚIP MTUͳһȡֵΪ4470×Ö½Ú¡£ ΪËõ¶ÌIGPÁÚ¾Ó½¨Á¢Ê±¼ä£¬IGPЭÒéÅäÖÃÈ«²¿È¡Ïû¶Ô½Ó¿ÚMTUµÄ¼ì²é¡£ ¸÷³§¼ÒÉ豸µÄÉ豸¶Ë¿ÚÅäÖÃÏÂMTU¾ßÌ庬ÒåÓÐËù²»Í¬£¬¾ßÌå¼ûÏÂ±í£º ÐòºÅ 1 2 3 4 5 6 1 2 3 4 6 7 8 Juniper TX °¢ÀÊ SR7750 EX ˼¿Æ RedBack SEϵÁÐ CRS-1ϵÁÐ »ªÎª NEϵÁР˼¿Æ É豸³§ÉÌ É豸ÀàÐÍ GSR/76/65ϵÁÐ ¶Ë¿ÚÀàÐÍ Ethernet POS Ethernet POS Ethernet POS Ethernet POS Ethernet POS Ethernet Ethernet POS MTUÖµº¬Òå IP MTU IP MTU IP MTU IP MTU IP MTU IP MTU IP MTU+14 IP MTU+4 IP MTU£«14 IP MTU£«2 IP MTU£«18 IP MTU£«14 IP MTU£«4 ȱʡֵ 1500 4470 1500 4470 1500 4470 1514 4474 1514 9208 1518 1514 4474 ½¨ÒéÖµ 1600 4470 1600 4470 1600 4470 1614 4474 1614 4472 1622 1614 4474 ¡¾1¡¿ Juniper EϵÁÐBrasÉ豸ͨ³£ÓÃ×ӽӿڵķ½Ê½»¥Á¬ÉϲãÉ豸£¬×Ó½Ó¿ÚÏÂIP MTU=Ö÷½Ó¿Ú MTU

-22 ,Òò´Ë½¨ÒéÖ÷½Ó¿ÚMTUȡֵΪ1622¡£

EϵÁÐÉ豸IP MTUÖµÊǸù¾Ý¶þ²ãMTU²ãÖµ×Ô¶¯¼ÆËã¶øÀ´£¬Èý²ãMTUµÈÓÚ¶þ²ãMTU¼õ22;

¡¾2¡¿ SR 7750 ÒÔÌ«¶Ë¿ÚΪaccess ģʽ£¬Ä¬ÈÏMTU Ϊ1514£¬Èô·â×°dot1Q £¬ÔòÐè¼Ó4×Ö½ÚΪ

1518×Ö½Ú£»ÈôΪnetworkģʽ£¬ÔòĬÈÏΪ1514×Ö½Ú;

SR 7750 POS¶Ë¿ÚΪnetwotkģʽʱĬÈÏΪ9208×Ö½Ú¡£

¡¾3¡¿ ¶ÔÓÚiTVƽ̨¡¢È«ÇòÑÛÆ½Ì¨¡¢½»»»BACµÈ·ÇMPLS½ÓÈ룬½¨Òéͳһ½Ó¿ÚIP MTUΪ1500¡£

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ22Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

3.2.2 Loopback½Ó¿ÚÅäÖÃ

ÅäÖÃ˵Ã÷£º

ÅäÖÃLoopbackµØÖ·£¬Ìṩһ¸öÓÀÔ¶upµÄIPµØÖ·£¬ÓÃÓÚ¸÷ÖÖ·ÓÉЭÒéÁھӵĽ¨Á¢¡¢Ô¶³ÌµÇ¼¡¢É豸¹ÜÀíµÈ¡£Í¬Ê±£¬BGPºÍMP-BGP·ÓÉÆ÷ÉϵÄloopbackµØÖ·£¬ÓÃ×÷¸Ã·ÓÉÆ÷·¢²¼µÄBGP»òMP-BGP·ÓɵÄÏÂÒ»ÌøµØÖ·¡£

¹æ·¶ÒªÇó£º

³ÇÓò¹Ç¸ÉÍø³ö¿Ú·ÓÉÆ÷ÅäÖÃÒ»¸öloopback 0µØÖ·£¬ÑÚÂë±ØÐëΪ32λ¡£ Loopback½Ó¿ÚÐèÌí¼Ó¶Ë¿ÚÃèÊö£¬¶Ë¿ÚÃèÊöÒªÇó·ûºÏµÚ¶þÕÂÖÐIP³ÇÓòÍøÍøÂçÉ豸ÃüÃû¼°Á´Â·ÃèÊö¹æ·¶Öй涨¡£ ²âÊÔʹÓÃloopback´Ó500¿ªÊ¼±àºÅ,²¢Ã÷È·±ê×¢ÏàÓ¦µÄ²âÊÔÓÃ;£¬±ãÓÚ²éѯºÍɾ³ý¡£ ÅäÖù淶£º interface LoopBack0 ip address *.*.*.* 255.255.255.255 description For-Management ÅäÖÃÑéÖ¤£º disp inter loopback 0 ÅäÖÃ×¢Òâϸ½Ú£º ÎÞ 3.2.3 GE½Ó¿ÚÅäÖà 3.2.3.1 ½Ó¿ÚÃèÊö ÅäÖÃ˵Ã÷£º ÅäÖýӿÚÃèÊö£¬Ã÷È·±êʶÁ´Â·Á¬½Ó·½Ïò£¬ÓÃÓÚ¶Ô³ÇÓòÍøµÄÿ̨É豸½øÐÐÇø·Ö£¬·½±ãÉ豸¹ÜÀí£¬Ìá¸ß¿É¶ÁÐԺͿɹÜÀíÐÔ¡£

¹æ·¶ÒªÇó£º

¶ÔÓÚ¶þÈý²ã½Ó¿Ú²»·ÖµÄÉ豸£¬£¨»ªÎª£¬CISCO¡¢Juniper£©£º

¶Ë¿ÚÃèÊöÒªÇó·ûºÏµÚ¶þÕÂÖС°IP³ÇÓòÍøÍøÂçÉ豸ÃüÃû¼°Á´Â·ÃèÊö¹æ·¶¡±Öй涨¡£ ¶ÔÓÚ¶þÈý²ã½Ó¿Ú·ÖÀëµÄÉ豸£¬£¨7750¡¢SE800£©£º

ÅäÖöþ²ã½Ó¶Ë¿ÚµÄÃèÊö·ûºÏµÚ¶þÕÂÖС°IP³ÇÓòÍøÍøÂçÉ豸ÃüÃû¼°Á´Â·ÃèÊö¹æ·¶¡±Öй涨¡£²¢×¢Òâ¶Ë¿ÚÃèÊöÖеĶԶ˶˿ÚÓ¦Çø±ð²»Í¬É豸¡£

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ23Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

ÃüÃûÈý²ã½Ó¿Úʱ£¬²ÉÓÃÓëJuniperÀàËÆµÄÃû³Æ, ±ÈÈçso-1/1/3,ge-2/0/0£¬Ãû³ÆÖв»´ø¿Õ¸ñ¡£

ÅäÖÃÈý²ã½Ó¿ÚµÄÃèÊöºÍÏàÓ¦µÄ¶þ²ã½Ó¿ÚÃèÊöÒ»Ö£¬ÉÏÐÐÁ´Â·ÃèÊöǰ׺ʹÓá°uT:¡±£¬ÏÂÐÐÁ´Â·ÃèÊöǰ׺ʹÓá°dT:¡±£¬ºáÁ¬Á´Â·Ç°×ºÊ¹Óá°pT:¡±¡£

δʹÓõĶ˿ÚÐèÒªShutdown£¬²¢É¾³ý¶Ë¿ÚÃèÊö¡¢IPµØÖ·¡¢×Ó½Ó¿ÚµÈÅäÖᣠ3.2.3.2 MTUÖµ ÅäÖÃ˵Ã÷£º

ÅäÖýӿڵÄ×î´ó´«Êäµ¥Ôª(MTU)Öµ¡£µ±Á½¶ËµÄmtuÖµ²»Ò»ÖÂʱ±íÏÖΪ£ºµ±PINGС°üʱÕý³££¬²»»á¶ª°ü£¬µ«ÊÇPING´ó°üʱ»áÃ÷ÏÔ¶ª°ü£¬¶øÇÒÓ°ÏìIGPЭÒéÕý³£½¨Á¢ÁÚ¾Ó¹ØÏµ¡£

¹æ·¶ÒªÇó£º

Cisco CRS-1£¬Juniper TX£¬°¢ÀÉSR 7750 É豸¶Ë¿ÚMTUΪIP MTU +14£¬¼´È¡ÖµÎª£º1614¡£

Cisco GSR£¬»ªÎªÉ豸¶Ë¿ÚMTUȡֵΪ£º1600¡£ Juniper EϵÁÐBrasÉ豸¶Ë¿ÚMTUΪIP MTU +22 £¬¼´È¡ÖµÎª£º1622. ÅäÖÃ×¢Òâϸ½Ú

¶Ë¿ÚÐèshutdown/undoshutdownºó£¬¸ü¸ÄºóµÄMTUÖµ²Å»áÉúЧ¡£

²»Í¬É豸¶Ë¿ÚÏÂMTUÅäÖÃÃüÁÄÜ´æÔÚ²îÒ죬Àý£º»ªÎªÉ豸¶Ë¿ÚÏÂÅäÖÃMTUÃüÁîµÄĬÈϼ´Îª3²ãMTU,¶øCisco CRSÉ豸¶Ë¿ÚÅäÖÃMTUÃüÁîΪ2²ãMTU£¬ÆäÊýÖµÐè-14×Ö½Ú²ÅΪIP MTUÖµ£¬Òò´ËÅäÖö˿ÚMTUֵʱ£¬Ðè×¢ÒⲻͬÉ豸µÄÅäÖÃÏÂMTUÅäÖÃÃüÁîµÄ¹¦ÄܲîÒì¡£

3.2.3.3 ¹Ø±ÕGE¶Ë¿ÚЭÉÌ ÅäÖÃ˵Ã÷£º

¶Ë¿ÚЭÉ̹¦ÄÜÔÊÐíÒ»¸öÉ豸ÏòÁ´Â·Ô¶¶ËµÄÉ豸ͨ¸æ×Ô¼ºËùÔËÐеŤ×÷·½Ê½£¬²¢ÇÒÕì²âÔ¶¶Ëͨ¸æµÄÏàÓ¦µÄÔËÐз½Ê½¡£Ò»ÌõÁ´Â·Á½¶ËµÄ¶Ë¿Ú±ØÐëÊÇͬÑùµÄÅäÖã¬Èç¹ûǧÕ×Á´Â·Á½¶ËµÄÅäÖò»Ò»Ö£¬¶Ë¿Ú״̬½«²»up»ò²»Îȶ¨¡£

¹æ·¶ÒªÇó£º

¹Ø±ÕGE¶Ë¿ÚµÄ×Ô¶¯Ð­É̹¦ÄÜ£¬·ÀֹЭÉ̲»Ò»Öµ¼Ö¶˿ڲ»ÄÜup¡£ ÅäÖÃ×¢Òâϸ½Ú£º

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ24Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

ȱʡÇé¿öÏ£¬GEµç¿ÚΪ×Ô¶¯Ð­ÉÌ£¬¿ÉÐÞ¸ÄЭÉÌģʽ¡£ 3.2.3.4 ¹Ø±Õ´æÔÚ·çÏյݲȫ©¶´ ÅäÖÃ˵Ã÷£º

¹Ø±ÕGE¶Ë¿Ú¿ÉÄÜ´æÔÚ·çÏյݲȫ©¶´¡£

ICMP Redirect£º¿ÉÒÔ֪ͨÖ÷»úÐÞ¸ÄÆä·¢ËÍÊý¾ÝµÄÏÂÒ»ÌøIP£¬¸ü¸ÄÖ÷»úµÄ·ÓÉ£¬´æÔÚDOS¹¥»÷µÄ·çÏÕ¡£

Direct Broadcast£ºÔÊÐíÏò¸ÃÍø¶ÎϵÄËùÓÐÉ豸·¢Ë͹㲥°üÎÄ£¬Ôì³É´óÁ¿µÄÁ÷Á¿¡£ Proxy ARP£ºÔÊÐí½Ó¿Ú´úÀí²éѯARPµØÖ·£¬½«×Ô¼ºµÄMACµØÖ·×öΪӦ´ð£¬´æÔÚARPÆÛÆ­°²È«ÎÊÌâ¡£ ¹æ·¶ÒªÇó£º ¹Ø±ÕICMP Redirect¡¢Direct Broadcast¡¢Proxy ARP¡£ 3.2.3.5 ½Ó¿ÚÕðµ´½ûÖ¹ ÅäÖÃ˵Ã÷£º Ϊ±ÜÃâ½Ó¿Ú·´¸´UP/DOWNÔì³Éϵͳ·ÓÉÕðµ´£¬µ¼Ö¶ÔÍøÂçÎȶ¨ÐÔµÄÓ°Ï죬½Ó¿Ú¿ªÆôÕðµ´½ûÖ¹¹¦ÄÜ¡£½öÔÚÖ÷½Ó¿ÚÆôÓ㬲»ÔÚ×Ó½Ó¿ÚÆôÓᣠËùÓÐGEºÍPOS½Ó¿Ú¶¼¿ªÆôdamping¡£ HWĬÈÏÖµ£º half-life:54s, resume:750, suppress:2000, max-suppress:6000 ¹æ·¶ÒªÇó£º ¿ªÆô½Ó¿ÚÕðµ´½ûÖ¹¹¦ÄÜ£¬Ê¹ÓÃĬÈÏÖµ¡£ 3.2.3.6 ÅäÖ÷¶Àý interface GigabitEthernet1/0/0 undo negotiation auto #GEµç¿Ú mtu 1600 #×¢ÒâÓë¶Ô¶Ë±£³ÖÒ»Ö description pT: NJ-HZM-BAS.MAN.SE800-1::( )GE1/0/0 ip address X.X.X.X X.X.X.X undo icmp redirect send undo arp-proxy enable #ĬÈÏÐÐΪ control-flap #¶Ë¿ÚÆôÓÃÕðµ´½ûÖ¹ set flow-stat interval 30 #Á÷Á¿Í³¼ÆÊ±¼ä¼ä¸ôΪ30Ãë¡£ ¼ì²é£º disp inter gi1/0/0 ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾ µÚ25Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

3.2.4 GE×Ó½Ó¿Ú½Ó¿ÚÅäÖÃ

3.2.4.1 ÃüÃû¹æ·¶

»ªÎª¡¢CiscoΪ¹Ì¶¨¡°Ö÷½Ó¿ÚÃû¡±+¡°.¡±+¡°Êý×Ö±àºÅ¡±µÄ¸ñʽ¡£

°¢ÀÊ7750µÄ×Ó½Ó¿ÚÃüÃû¹æ·¶×ñ´Ó¡°-¡±Ö®ºó×Ö¶ÎÓë¹ØÁªsapÏàͬµÄÔ­Ôò£¬¾ßÌå¾ÙÀýÈçÏÂ±í£º

Ö÷½Ó¿ÚÀàÐÍ ×Ó½Ó¿ÚÃüÃû¾ÙÀý(dot1q) ×Ó½Ó¿ÚÃüÃû¾ÙÀý(qinq) FE¿Ú fe-2/1/1:100 fe-2/1/1:100.1001 GE¿Ú ge-1/1/1:200 ge-1/1/1:200.2001 LAG¿Ú lag-1:300 lag-1:300.3001 3.2.4.2 ½Ó¿ÚÃèÊö ÅäÖÃ˵Ã÷£º ³ö¿Ú·ÓÉÆ÷µÄGE×Ó½Ó¿ÚΪÁ¬½Óµ½BAS²»Í¬VRʹÓã¬×Ó½Ó¿ÚÃèÊöÖÐÓ¦ÄÜÌåÏÖÁ¬½Ó¶Ô¶ËVRµÄÏà¹Ø±ØÒªÐÅÏ¢¡£ ¹æ·¶ÒªÇó£º ¸ñʽ£º½Ó¿ÚÃèÊö+(VRÃû³Æ)¡£ 3.2.4.3 dot1q·â×°¸ñʽ ÅäÖÃ˵Ã÷£º ³ö¿ÚGE×Ó½Ó¿Ú·âװΪdot1q¸ñʽ£¬ÓÃÓÚÓëÏÂÁªBAS¾ßÌåVRͨÐÅ¡£ ¹æ·¶ÒªÇó£º GE×Ó½Ó¿Ú·âװΪdot1q¸ñʽ¡£×Ó½Ó¿ÚIDʹÓÃVLANºÅ¡£ 3.2.4.4 ÅäÖ÷¶Àý interface GigabitEthernet1/0/0 undo negotiation auto #GEµç¿Ú mtu 1600 #×¢ÒâÓë¶Ô¶Ë±£³ÖÒ»Ö description pT: NJ-HZM-BAS.MAN.SE800-1::( )GE1/0/0 ip address X.X.X.X X.X.X.X undo icmp redirect send undo arp-proxy enable #ĬÈÏÐÐΪ control-flap #¶Ë¿ÚÆôÓÃÕðµ´½ûÖ¹ set flow-stat interval 30 #Á÷Á¿Í³¼ÆÊ±¼ä¼ä¸ôΪ30Ãë¡£ interface GigabitEthernetX/X/X.192 description pT: NJ-HZM-BAS.MAN.SE800-1::( )GE1/0/0(vrVPDN_LAC) ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾ µÚ26Ò³ ½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

¼ì²éÃüÁ display inter gi X/X/X display inter gi X/X/X.192 vlan-type dot1q 192 ip address X.X.X.X X.X.X.X 3.2.5 POS½Ó¿ÚÅäÖÃ

3.2.5.1 ½Ó¿ÚÃèÊö ÅäÖÃ˵Ã÷£º

ÅäÖýӿÚÃèÊö£¬Î¨Ò»ÐÔ±êʶ³ÇÓòÍøÖеÄÿ̨É豸£¬ÓÃÓÚ¶Ô³ÇÓòÍøµÄÿ̨É豸½øÐÐÇø·Ö£¬·½±ãÉ豸¹ÜÀí£¬Ìá¸ß¿É¶ÁÐԺͿɹÜÀíÐÔ¡£

¹æ·¶ÒªÇó£º

ÒªÇóÅäÖÃÈý²ã½Ó¿ÚµÄÃèÊöºÍÏàÓ¦µÄ¶þ²ã½Ó¿ÚÃèÊöÒ»Ö£¬·ûºÏµÚ¶þÕ¹淶¡£ δʹÓõĶ˿ÚÐèÒªSHUTDOWN£¬²¢É¾³ý¶Ë¿ÚÃèÊö¡¢IPµØÖ·¡¢×Ó½Ó¿ÚµÈÅäÖᣠ3.2.5.2 MTUÖµ ÅäÖÃ˵Ã÷£º

ÅäÖýӿڵÄ×î´ó´«Êäµ¥Ôª(MTU)Öµ¡£µ±Á½¶ËµÄMTUÖµ²»Ò»ÖÂʱ¶¯Ì¬Â·ÓÉЭÒé²»ÄÜÕý³£½¨Á¢ÁÚ¾Ó¹ØÏµ¡£µ±PINGС°üʱÕý³££¬²»»á¶ª°ü£¬µ«ÊÇPING´ó°üʱ»áÃ÷ÏÔ¶ª°ü¡£

¹æ·¶ÒªÇó£º

Cisco CRS-1£¬Juniper TX É豸¶Ë¿ÚMTUΪIP MTU +4£¬Ä¬ÈÏÖµ¼´Îª4474£¬ÎÞÐèÅäÖᣠCisco GSR£¬»ªÎªÉ豸¶Ë¿ÚÏÂMTUĬÈÏֵΪ4470£¬ÎÞÐèÅäÖᣠ°¢ÀÉSR 7750É豸¶Ë¿ÚMTUΪIP MTU +2£¬¼´È¡ÖµÎª£º4472¡£ 3.2.5.3 POS·â×°¡¢Ö¡µÈ ÅäÖÃ˵Ã÷£º

POS¼´Packet Over SONET/SDH£¬Ê¹ÓÃSDHÌṩµÄ¸ßËÙ´«ÊäͨµÀÖ±½Ó´«ËÍIP·Ö×飬SONET/SDHÊǵã¶ÔµãµÄÎïÀí²ãµÄЭÒ飬IPÊÇÍøÂç²ãµÄЭÒé¡£¸ù¾ÝOSIÆß²ãÄ£ÐÍ£¬¶þÕßÖ®¼ä»¹ÐèÒªÒ»¸öÁ´Â·²ãЭÒ飬¿ÉÅäÖòÉÓÃPPP»òHDLC×÷ΪÁ´Â·²ãµÄЭ

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ27Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

Òé¡£

ÅäÖÃPOSµÄÎïÀí²ãÖ¡¸ñʽ²ÉÓùú¼Ê±ê×¼SDH£¬²»Ê¹Óñ±ÃÀ±ê×¼SONET¡£ ÅäÖÃPOS½Ó¿ÚµÄÏß·¼ÓÂ빦ÄÜ£¬±ãÓÚ½ÓÊܶËÌáÈ¡Ïß·ʱÖÓ£¬Èç¹ûÒ»¶ËÅäÖÃÁËÏß·¼ÓÈŶøÁíÒ»·½Ã»ÓУ¬Ôò²»ÄÜ»¥Í¨¡£

ÅäÖÃPOS½Ó¿ÚÁ½¶ËµÄCRCÖµ±ØÐëÒ»Ö£¬·ñÔò²»ÄÜ»¥Í¨¡£

ÅäÖÃPOSµÄÁ´Â·²ãÖ¡¸ñʽʹÓùú¼Ê±ê×¼PPP£¬²»Ê¹ÓÃHDLC·â×°¡£ ¹æ·¶ÒªÇó£º

ÅäÖÃPOS½Ó¿Ú·âװΪPPP£» ÅäÖÃPOSµÄÖ¡¸ñʽΪSDH£» ÅäÖÃCRCÉèÖÃΪ32λ£» ¿ªÆôPOS scramble¼ÓÈÅ£» ¹Ø±ÕICMP RedirectÌØÐÔ£» 3.2.5.4 POSÁ´Â·Í¬²½Ê±ÖÓ ÅäÖÃ˵Ã÷£º

ÅäÖÃPOSÁ´Â·Í¬²½Ê±ÖÓ£¬Óë´«Ê以ÁªÊ±ÖÓÓ¦¸úËæ´«ÊäʱÖÓ£¬ÓëÆäËû·ÓÉÆ÷±³¿¿±³ÂãÏËÖ±Á¬½Óʱ£¬»¥Á¬Ë«·½¶¼ÉèÖÃΪÖ÷ʱÖÓ£¬·ÀÖ¹³öÏÖʱÖÓ»·¡£Ö÷ʱÖÓÊÇʹÓÃÄÚ²¿Ê±ÖÓÐźÅÅж¨ÊÕµ½µÄÊý¾Ý룬´ÓʱÖÓÊÇʹÓôÓÊÕµ½µÄÊý¾ÝÁ÷ÖÐÌáÈ¡¶Ô¶ËʱÖÓÐźÅÀ´Åж¨ÊÕµ½µÄÊý¾Ýλ¡£

CISCO¡¢JUNIPER¡¢Alcatel-Lucent POS¶Ë¿ÚĬÈÏΪ´ÓʱÖÓ£¬»ªÎªÄ¬ÈÏΪÖ÷ʱÖÓ¡£ ¹æ·¶ÒªÇó£º Óë´«Ê以ÁªÊ±ÖÓ¸úËæ´«ÊäʱÖÓ£¬¼´Â·ÓÉÆ÷ÅäÖÃΪ´ÓʱÖÓ¡£

ÈçΪWDM»òÓëÆäËû·ÓÉÆ÷±³¿¿±³ÂãÏËÖ±Á¬½Óʱ£¬»¥Á¬Ë«·½¾ùÉèÖÃΪÖ÷ʱÖÓ¡£ 3.2.5.5 ÅäÖ÷¶Àý

interface pos 1/0/0 description pT:NJ-YFXJ-CR.MAN.CRS-1:( )10GPOS0/5/3/0 mtu 4470 #ĬÈÏÖµ link-protocol ppp #ĬÈÏÖµ frame-format sdh #ĬÈÏÖµ scramble #ĬÈÏÖµ clock master #ĬÈÏΪMaster set flow-stat interval 30 control-flap undo icmp redirect send ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾ µÚ28Ò³ ½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

¼ì²é£º display inter pos 1/0/0 3.2.6 ¶Ë¿Ú¾µÏñÅäÖÃ

ÅäÖÃ˵Ã÷£º

ÉèÖÃÒ»¸ö¶Ë¿Ú×÷Ϊ¾µÏñ¶Ë¿Ú£¬½«Á÷¾­Ò»¸ö»ò¼¸¸öÖ¸¶¨¶Ë¿ÚµÄËùÓÐÊý¾ÝÖ¡¿½±´µ½Õâ¸ö¾µÏñ¶Ë¿ÚÉÏÀ´¡£

¹æ·¶ÒªÇó£º ÔÚÓбØÒªÊ±ÅäÖö˿ھµÏñ¹¦ÄÜ¡£ ÅäÖù淶£º observe-port interface gigabitethernet3/0/2 interface gi 1/0/0 port-mirroring to observe-port 1 inbound ÅäÖÃÑéÖ¤£º disp curr | i observe-port disp curr int gi 1/0/0 ÅäÖÃ×¢Òâϸ½Ú£º ÎÞ¡£ 3.3 ·ÓÉЭÒéÅäÖù淶 3.3.1 ³ÇÓòÍøÂ·Óɼܹ¹¸ÅÊö ½­ËÕµçÐÅÏÂÊô³ÇÓòÍø¸÷×Ô¹¹³Éµ¥¶ÀASÓò£¬³ÇÓòÍøÂ·Óɼܹ¹·ÖΪÓû§Â·ÓÉÉú³É£¨custom routing£©¡¢IGP¡¢BGP¡¢MP-BGP·ÓÉ4¸ö²¿·Ö¡£ Óû§Â·ÓÉÉú³É£ºÖ¸ÔÚ³ÇÓòÍøÒµÎñ½ÓÈë¿ØÖÆµã£¨BRASºÍSR£©ÉÏÅäÖÃÉú³É»ò¶¯Ì¬Ñ§Ï°Óû§Â·ÓɵÄʵÏÖ·½Ê½ºÍ¹ý³Ì£» IGP£ºÔËÐÐÔÚ³ÇÓòÍøºËÐIJãºÍÒµÎñ½ÓÈë¿ØÖÆ²ã£¬ÔÚ³ÇÓòÍøÈý²ãÉ豸֮¼ä³ÐÔØºÍ½»»»Â·ÓÉÐÅÏ¢£º³ÇÓòÍøASÓòÄÚÉ豸½Ó¿Ú£¨°üÀ¨loopback½Ó¿Ú£©µØÖ·Â·ÓÉ¡£

BGP£º

IBGP-ÔËÐÐÔÚ³ÇÓòÍøºËÐIJãºÍÒµÎñ½ÓÈë¿ØÖÆ²ã£¬³ÐÔØ³ÇÓòÍøÄÚIPV4Óû§Â·ÓÉ£» EBGP-ÔËÐÐÔÚ³ÇÓòÍø³ö¿Ú·ÓÉÆ÷Óë163¡¢CN2¹Ç¸ÉÍøÂ·ÓÉÆ÷Ö®¼ä£¬ÊµÏÖ³ÇÓòÍøÏò¹Ç¸ÉÍø·¢²¼³ÇÓòÍøÄڵķÓÉ£¬²¢´Ó¹Ç¸ÉÍø½ÓÊÕȱʡºÍÍøÍâ·ÓÉ¡£

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ29Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

MP-BGP£ºÔËÐÐÔÚSR£¨¼´PE£©Ö®¼ä£¬ÓÃÓÚ³ÐÔØ³ÇÓòÍø×ÔÖÎÓòÄںͿçÓòMPLS VPNv4Óû§Â·ÓÉ¡£

3.3.2 ·ÓÉÓÅÏȼ¶/¹ÜÀí¾àÀë

ÅäÖÃ˵Ã÷£º

¶Ô·ÓÉÓÅÏȼ¶/¹ÜÀí¾àÀëµÄ¶¨ÒåÊÇΪÁËÉ豸ÔÚ½ÓÊÕµ½Ïàͬ·ÓÉÌõĿʱºò½øÐÐѡ·£¬ÔÚ·ÓÉÌõÄ¿ÏàͬµÄÇé¿öÏ£¬ÓÅÏȼ¶ÊýֵСµÄ·Óɽ«±»Ñ¡Ôñ¡£

¹æ·¶ÒªÇó£º Â·ÓÉÓÅÏȼ¶±ðµÄÉ趨°´ÕÕÏÂÃæ¹æ·¶¡£ Route type Direct attached ÆÕͨ¾²Ì¬ EBGP OSPF internal IS-IS External ISIS ºÚ¶´Â·ÓÉ IBGP ¸¡¶¯¾²Ì¬ Route Preference/AD 0 [1] 1»ò5 [2] 20 110 10 115 [3] 15 25 150 180 200 210

ÅäÖÃ×¢Òâϸ½Ú£º ÉϱíΪ·ÓÉÓÅÏȼ¶±ðµÄÍÆ¼öÉ趨ֵ£¬ÔÚʵ¼ÊÉ趨ʱ°´ÒÔÏÂ˳Ðò¼´¿É£º ÆÕͨ¾²Ì¬->EBGP->OSPF->ISIS->ºÚ¶´¾²Ì¬->IBGP->¸¡¶¯¾²Ì¬¡£

[1][2]

£ºÒ»°ã²»¿É¸ü¸Ä¡£

£ºÖ®ËùÒÔûÓÐͳһ£¬ÊÇÒòΪ£º

¾²Ì¬Â·ÓÉȱʡֵ£ºCisco 1£»Juniper 5£»Alcatel 5£»»ªÎª£º60

°´ÉÏÊöµ÷Õû£¬1»ò5¶Ô·ÓÉÑ¡Ôñ¶¼²»»á²úÉúʵÖÊÐÔµÄÓ°Ï죬¹Ê³ý»ªÎªÉ豸ÐèÒª½«¾²Ì¬Â·ÓɵÄ

ȱʡÓÅÏȼ¶ÐÞ¸ÄΪ1Í⣬ÆäËû³§¼ÒÉ豸±£³Öȱʡֵ¼´¿É¡£

[3]

£ºÒòCisco·ÓÉÆ÷²»Çø·ÖIS-IS L1/L2¡¢Internal/External·ÓɵÄÓÅÏȼ¶/¹ÜÀí¾àÀ룬¹ÊÖ»Äܽ«Æä

IS-IS·ÓɹÜÀí¾àÀë/ÓÅÏȼ¶Í³Ò»ÉèΪ115¡£

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ30Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

3.3.3 ¾²Ì¬Â·ÓÉÅäÖÃ

3.3.3.1 ¾²Ì¬Â·ÓÉÓÅÏȼ¶ ÅäÖÃ˵Ã÷£º

¸ü¸Ä¾²Ì¬Â·ÓɵÄЭÒéÓÅÏȼ¶/¹ÜÀí¾àÀë¡£ ¹æ·¶ÒªÇó£º

ÆÕͨ¾²Ì¬Â·ÓÉÓÅÏȼ¶/¹ÜÀí¾àÀëÅäÖÃΪ1¡£CISCOºÍAlcatelÎÞ·¨ÓÃÒ»ÌõÃüÁîÐÞ¸ÄËùÓо²Ì¬Â·ÓɵÄȱʡÓÅÏȼ¶£¨Ö»ÄÜÖðÌõÐÞ¸ÄÿÌõ¾²Ì¬Â·ÓÉ£©¡£JuniperºÍ»ªÎª¿ÉÒÔÓÃÒ»ÌõÃüÁîÐÞÓÐËùÓо²Ì¬Â·ÓɵÄȱʡÓÅÏȼ¶¡£

ÅäÖÃ×¢Òâϸ½Ú£º

¾²Ì¬Â·ÓÉÓÅÏȼ¶È±Ê¡Öµ£ºCisco 1£»Juniper 5£»Alcatel 5£»»ªÎª£º60¡£ »ªÎªÉ豸ʹÓÃÒ»ÌõÃüÁîÐÞ¸ÄËùÓо²Ì¬Â·ÓɵÄÓÅÏȼ¶£¬Ö»Õë¶ÔÐÂÔöµÄ¾²Ì¬ÉúЧ£¬¶øÐÞ¸ÄǰÒÑ´æÔڵľ²Ì¬Â·ÓɵÄÓÅÏȼ¶±ðÒÀÈ»ÐèÖðÌõÊÖ¶¯µ÷Õû¡£ 3.3.3.2 ¾²Ì¬Â·ÓÉÅäÖ÷½Ê½ ÅäÖÃ˵Ã÷£º

Ö¸¶¨³ö¿Ú·ÓÉÆ÷Éϵľ²Ì¬Â·ÓÉÅäÖ÷½Ê½£» ¹æ·¶ÒªÇó£º

³ö¿Ú·ÓÉÆ÷Óë²»ÔËÐзÓÉЭÒéµÄBRASÖ®¼ä¾²Ì¬Â·ÓÉÅäÖ÷½·¨¸ù¾Ý³ö¿Ú·ÓÉÆ÷µÄ²»Í¬¶øÓÐËùÇø±ð£º

? CISCO¡¢»ªÎª¾²Ì¬Â·ÓɲÉÓõü´ú·½Ê½£¬°ó¶¨ÏÂÒ»ÌøÎª¶Ô¶ËÉ豸Loopback0

µØÖ·£¬¶Ô¶ËÉ豸µÄLoopback0µØÖ·²ÉÓÃͬʱ°ó¶¨ÏÂÒ»ÌøIP µØÖ·ºÍ³ö½Ó¿ÚµÄ¾²Ì¬Â·ÓÉ·½Ê½¡£

? 7750¾²Ì¬Â·ÓÉÖ»°ó¶¨ÏÂÒ»ÌøIP µØÖ·¡£

? Juniper-TX POS¶Ë¿Ú¾²Ì¬Â·ÓÉÖ»°ó¶¨³ö½Ó¿Ú£¬²»°ó¶¨ÏÂÒ»ÌøIPµØÖ·¡£GE

¶Ë¿Ú¾²Ì¬Â·ÓÉÖ»°ó¶¨IP µØÖ·£¬²¢Ìí¼ÓNO-RESOLVE²ÎÊý¡£ ¹æ·¶ÒªÇó£º

¾²Ì¬Â·Óɰ󶨽ӿںÍÏÂÒ»ÌøIPµØÖ·¡£ 3.3.3.3 ºÚ¶´Â·ÓÉÅäÖà ÅäÖÃ˵Ã÷£º

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ31Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

ÔÚ³ö¿Ú·ÓÉÆ÷ÉÏÅäÖóÇÓòÍøÍø¶ÎµÄÖ¸ÏòNULL0µÄºÚ¶´Â·ÓÉ£¬ÓÃÓÚBGPЭÒ齫³ÇÓòÍøÍø¶ÎÐû¸æ¸ø¹Ç¸É£¬ÅäÖÃÓÅÏȼ¶Îª180£¬²¢Ôö¼ÓTAG 901±ê¼Ç¡£

³ö¿Ú·ÓÉÆ÷ÉϵijÇÓòÍøÍø¶ÎºÚ¶´Â·ÓÉÑϽû×¢Èëµ½ISISÖС£

³ÇÓòÍøÁ½Ì¨³ö¿Ú·ÓÉÆ÷ÉÏÅäÖõĺڶ´Â·ÓÉÔ­ÔòÉϱØÐëÍêÈ«Ïàͬ£¬ÒÔ±ÜÃâ´Ó¹Ç¸É·µ»ØµÄÁ÷Á¿²»¾ùºâ¼°uRPF´íÎó¡£

¹æ·¶ÒªÇó£º

ºÚ¶´Â·ÓÉÅäÖÃÓÅÏȼ¶Îª180£¬Ôö¼ÓTAG 901±ê¼Ç£¬ÑϽû×¢Èëµ½ISISÖС£ ÅäÖÃ×¢Òâϸ½Ú£º

ÅäÖÃǰÐè×ÐϸÅŲé³ÇÓòÍøºËÐÄÉÏÊÕµ½µÄBR/BRAS/SR»ã×Ü·¢À´µÄIBGP·ÓÉÊÇ·ñºÍ±¾»úͨ¹ý¾²Ì¬Ö¸Ïònull 0 + network·¢²¼µÄÍø¶ÎÖдæÔÚ×ÓÍøÑÚÂ볤¶ÈÏàͬµÄ·ÓÉÌõÄ¿£¬Õë¶ÔÕâÖÖÌØÀý£¬ºËÐÄÉÏÐèÈ¡ÏûÕë¶Ô¸Ã·ÓÉnetwork µÄ¾²Ì¬·¢²¼Óï¾ä£¬·ñÔò»áÔì³ÉºËÐÄÉϵÄÕë¶Ô¸ÃÌõĿ·ÓɵÄÁ÷Á¿¶ªÆú¡£

3.3.3.4 ¸¡¶¯¾²Ì¬Â·ÓÉÅäÖà ÅäÖÃ˵Ã÷£º

³ö¿ÚºËÐÄÉÏÅäÖöàÌõÖ¸Ïò¹Ç¸ÉÉ豸µÄ¾²Ì¬Ä¬ÈÏ·ÓÉ£¬±ÜÃâ³ö¿ÚºËÐĺ͹ǸÉÉ豸֮¼äµÄBGP»á»°³öÏÖ¹ÊÕÏʱ¶øÒýÆðÁ÷Á¿ÎÞ·¨×ª·¢µÄÏÖÏó¡£

ÏÂÁ¬»ã¾ÛBR£¬BRAS/SRÉ豸ÉÏÅäÖöàÌõÖ¸Ïò³ÇÓòÍøºËÐĵľ²Ì¬Ä¬ÈÏ·ÓÉ£¬±ÜÃâ±¾¶ËºÍºËÐÄÖ®¼äµÄISIS/BGP»á»°³öÏÖ¹ÊÕÏʱ¶øÒýÆðÁ÷Á¿ÎÞ·¨×ª·¢µÄÏÖÏó¡£

¹æ·¶ÒªÇó£º

³ö¿ÚºËÐÄÉÏÅäÖöàÌõ¾²Ì¬Ä¬ÈÏ·ÓÉ£¬°ó¶¨¹Ç¸ÉÉ豸»¥Á¬Á´Â·½Ó¿ÚºÍÏÂÒ»ÌøµØÖ·£¬Í¬Ê±½«Â·ÓÉÓÅÏȼ¶/¹ÜÀí¾àÀëÉèÖÃΪ210£¬¼ÓTAG 210,ÑϽû×¢ÈëISISÖС£

»ã¾ÛBR,BRAS/SRÉ豸ÅäÖöàÌõ¾²Ì¬Ä¬ÈÏ·ÓÉ£¬°ó¶¨ºÍºËÐÄ»¥Á¬Á´Â·½Ó¿ÚºÍÏÂÒ»ÌøµØÖ·£¬Í¬Ê±½«Â·ÓÉÓÅÏȼ¶/¹ÜÀí¾àÀëÉèÖÃΪ210£¬¼ÓTAG 210,ÑϽû×¢ÈëISISÖС£

3.3.3.5 ¾²Ì¬Â·Óɱê¼ÇºÍÃèÊö ÅäÖÃ˵Ã÷£º

³ö¿Ú·ÓÉÆ÷Éϵľ²Ì¬Â·ÓÉÅäÖã¬ÔÚ·ÓÉÖØ·Ö·¢×ö±ê¼Ç£¬¸ù¾ÝÐèÒª¿ÉÒÔ¼ÓtagºÍÃèÊö¡£ÔöÇ¿¿É¶ÁÐÔ£¬·½±ã²ßÂÔʹÓú͹ÜÀí¡£

Tag 901ÓÃÓÚºÚ¶´¾²Ì¬Â·ÓÉ£» TAG 210 ÓÃÓÚ¸¡¶¯¾²Ì¬Ä¬ÈÏ·ÓÉ¡£

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ32Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

¹æ·¶ÒªÇó£º

ºÚ¶´¾²Ì¬Â·ÓÉÉèÖÃTAGֵΪ901£¬¸¡¶¯¾²Ì¬Â·ÓÉÉèÖÃTAG 210,ÆäËü¸ù¾ÝÐèÒªÉèÖÃTAGÖµ¡£

3.3.3.6 ÅäÖ÷¶Àý

#Õë¶ÔBRASÒµÎñµÄ¾²Ì¬Â·Óɵü´úÅäÖ÷¶Àý

ip route-static default-preference 1 #È«¾ÖÒ»ÌõÃüÁîÐ޸ľ²Ì¬Â·ÓɵÄĬÈÏÓÅÏȼ¶Îª1 #

ip route-static 1.1.1.1 255.255.255.255 gi1/0/0 192.168.1.2 #ÅäÖóÇÓòÍø³ö¿Ú·ÓÉÆ÷µ½BRAS Loopback0µÄ¾²Ì¬Â·ÓÉ£¬Â·ÓÉÊýºÍÁ´Â·ÊýÏàͬ #

ip route-static 172.16.0.0 255.255.0.0 1.1.1.1 #°ó¶¨BRAS IP POOLµÄÏÂÒ»ÌøIPµØÖ·ÎªBRAS Loopback0µØÖ· #

ip route-static 192.168.0.0 255.255.255.0 null0 preference 180 tag 901 #ºÚ¶´Â·ÓɼÓtag 901£¬Í¨¹ýBGP¹ã²¥¸ø¹Ç¸ÉÉ豸¡£

ip route-static 0.0.0.0 0.0.0.0 Pos2/0/0 61.177.249.229 preference 210 tag 210 #¸¡¶¯¾²Ì¬Â·ÓÉ

3.3.4 ISIS ÅäÖÃ

3.3.4.1 ¸ÅÊö

½­ËÕµçÐÅÏÂÊô³ÇÓòÍøÊ¹ÓÃISISΪIGPЭÒ飬IGPÔËÐÐÔÚ³ÇÓòÍøºËÐIJãºÍÒµÎñ½ÓÈë¿ØÖÆ²ã¡£ISIS º­¸ÇÍøÂçÖÐËùÓкËÐÄÉ豸ºÍ»ã¾ÛÉ豸µÄLoopback ¶Ë¿ÚºÍÁ´Â·¶Ë¿Ú£»ºËÐÄ·ÓÉÆ÷µÄÉÏÁª½Ó¿ÚºÍÉ豸µÄLoopback ¶Ë¿ÚÉèÖÃΪPassiveģʽ¡£ISIS·ÓÉЭÒéÖ»³ÐÔØÉ豸֮¼äµÄ»¥Á¬Á´Â·ºÍloopbackµØÖ·µÄÖ÷»ú·ÓÉ£¬²»³ÐÔØÓû§µÄ·ÓÉ¡£³ÇÓòÍø³ö¿Ú·ÓÉÆ÷ISIS½ø³ÌʼÖÕÏ·¢Ä¬ÈÏ·ÓÉ¡£ISISЭÒéÌṩµÄÊÇÒµÎñ½ÓÈë¿ØÖÆ²ã¼°ÆäÒÔÉÏÉ豸֮¼äµÄ¿É´ïÐÔ£¬ÎªIBGPÌṩIGP·Óɿɴ

3.3.4.2 ISIS ʵÀýÃû ÅäÖÃ˵Ã÷£º

ͬһ³ÇÓòÍøISISʵÀýÃû³Æ±£³Öͳһ£¬µ¥»ú²»ÔËÐжà¸öISISʵÀý£¬ISISʵÀýÃû³ÆÈ¡µØÊÐÃû³ÆÈ«Æ´£¬Àý£ºÑïÖݽڵãISISʵÀýÃûyangzhou¡£

ISISʵÀýÐèÓÃÊý×Ö±êʶ£¬¾ù¶¨Îª100¡£ ¹æ·¶ÒªÇó£º

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ33Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

ͬһ³ÇÓòÍøISISʵÀýÃû³Æ±£³Öͳһ£¬µ¥»ú²»ÔËÐжà¸öISISʵÀý¡£

[1]

£ºÏÖÍø»·¾³ÖУ¬´ó²¿·Ö»ªÎªÂ·ÓÉÆ÷ÔËÐÐISISµÄʵÀý±êʶ¶¼²ÉÓÃĬÈϵÄ1£¬µ±Ðèɾ³ý¶Ë¿Úisis

µÄÅäÖÃʱ£¬ÈÝÒײúÉúÎó²Ù×÷£ºundo isis £¬½á¹ûµ¼Ö¸Ą̃É豸µÄisis ½ø³Ì±»Çå³ý¡£Îª¹æ±ÜÈç´ËÎó²Ù×÷ËùÒýÆðµÄ·çÏÕ£¬isisʵÀý²ÉÓÃÊý×Ö±êʶÐè²»ÉèÖÃΪ1¡£

3.3.4.3 ISIS NET ID ÅäÖÃ˵Ã÷£º

ÅäÖÃISIS net id£¬Î¨Ò»±êʶ×ÔÖÎϵͳÖеÄһ̨ISIS·ÓÉÆ÷¡£ ¹æ·¶ÒªÇó£º

ÔËÐж¯Ì¬Â·ÓÉЭÒéµÄcontextÅäÖÃISIS net id£¬net idµØÖ·²ÉÓÃArea ID + System ID + NSELµØÖ··½Ê½¡£

ÆäÖУ¬XX.YYYY.ZZZZΪArea ID£¬ÆäÖÐXX¹Ì¶¨Îª86£¬YYYY±¨¸÷³ÇÓòÍøË½ÓÐ5λASºÅµÄºó4룬ZZZZΪ¸÷µØÊÐµç»°ÇøºÅ£¬²»×ãËÄλµÄÇ°Ãæ²¹Áã¡£Àý£ºÑγdzÇÓòÍøË½ÓÐASºÅΪ64522£¬ÇøºÅΪ0515£¬ÄÇôÑγdzÇÓòÍøISIS NET IDΪ£º86.4522.0515¡£

System IDΪ6룬¸ñʽΪAAAA.AAAA.AAAA£¬²ÉÓóÇÓòÍøÉ豸loopback0µÄIPµØÖ·£¬ÒÔ×ó¼Ó0µÄ·½Ê½½«Ã¿Ò»½Ú²¹Æë3룬ÔÙ´Ó×óÖÁÓÒÈýµÈ·ÖÍê³É¸ñʽת»»¡£±ÈÈç61.177.248.2ת»»ºóΪ0611.7724.8002¡£NSEL¹Ì¶¨Îª00¡£

3.3.4.4 ISIS·ÓÉÆ÷ÀàÐÍ ÅäÖÃ˵Ã÷£º ISISµÄ·ÓÉÆ÷ÀàÐͿɷÖΪlevel-1ºÍlevel-2Á½ÖÖ£¬level-1ÓÃÓÚ´«µÝÓòÄÚ·ÓÉ¡¢level-2Óû§´«µÝÓò¼ä·ÓÉ¡£

¹æ·¶ÒªÇó£º

ͬһ¸ö³ÇÓòÍøÔËÐÐͬһ¸öISISЭÒ飬½­ËÕµçÐųÇÓòÍøÊ¹ÓÃISIS Level-1£¬¹Ø±Õ·ÓÉÆ÷ISIS Level-2¹¦ÄÜ¡£

3.3.4.5 ISIS Cost-style ÅäÖÃ˵Ã÷£º

ISISЭÒécost-style·ÖΪnarrowºÍwideÁ½ÖÖ·½Ê½£¬narrow·½Ê½ÊÇÀÏʽcostÀàÐÍ£¬costÖµÖ»ÄÜ´Ó0¡ª63£¬²»Ö§³ÖMPLS TE¡£wide·½Ê½Ê±ISIS cost¿ÉÒÔ´Ó0 ¡ª

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ34Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

16,777,215 ¡£²»Í¬cost-styleµÄISIS¶ÔµÈÌå²»Äܽ¨Á¢ÁÚ¾Ó¡£

¹æ·¶ÒªÇó£º

ÅäÖÃISIS cost-styleµÄÀàÐÍΪwide¡£

ÔËÐÐISISЭÒéµÄ¶Ë¿ÚĬÈÏ·ÓÉÆ÷ÀàÐÍΪlevel -1£¬costֵΪ100000¡£ 3.3.4.6 ISISЭÒé½Ó¿ÚÀàÐÍ ÅäÖÃ˵Ã÷£º

ÔÚʹÓÃ30λÑÚÂëµÄ¹ã²¥ÀàÐͽӿÚÏ£¬ÅäÖÃISISÍøÂçÀàÐÍΪµãµ½µã

point-to-point£¬²»·¢Ë͹㲥°ü£¬¼õÉÙLSP·ººé¡£Á´Â·Á½¶ËµÄIS-IS½Ó¿ÚµÄÍøÂçÀàÐͱØÐëÒ»Ö£¬·ñÔòË«·½²»¿ÉÒÔ½¨Á¢ÆðÁÚ¾Ó¹ØÏµ¡£

ISISЭÒéĬÈÏÒÔÌ«Íø½Ó¿ÚÀàÐÍÊǹ㲥ÀàÐÍ¡£ ¹æ·¶ÒªÇó£º

³ÇÓòÍøÄÚ»¥Á¬ÓÃPOS----±£³ÖΪPoint-To-Point²»±ä

³ÇÓòÍøÄÚ»¥ÁªÓÃGE/10GE --- Ç¿ÖÆ¸ü¸ÄΪPoint-To-Point(ÈôÉ豸²»Ö§³Ö£¬ÈçÖÐÐËÉ豸£¬ÒÀ¾É²ÉÓÃBroadcastģʽ) Loopback ---- Passive½øISISÓòÄÚ

ÆäËû¶Ë¿Ú-----ÈçÃ÷È·Ðèͨ¹ýIGP¿É´ïµÄ¶Ë¿Ú£¬ÔòÐèpassive½øISISÓòÄÚ£¬ÖîÈ磺ÉÏÁ¬¹Ç¸ÉÉ豸¶Ë¿Ú£¬ÉÏÁ¬CN2É豸¶Ë¿Ú¡£ 3.3.4.7 ISIS ¸ºÔؾùºâÌõÄ¿ ÅäÖÃ˵Ã÷£º ÅäÖÃISIS¸ºÔؾùºâÌõÄ¿£¬ÊµÏÖÁ÷Á¿µÄ¸ºÔؾùºâ¡£ ¹æ·¶ÒªÇó£º

°´Ê¡¹«Ë¾Í³Ò»¹æ·¶ÒªÇó£¬ÅäÖÃISIS¸ºÔؾùºâÊý²»ÉÙÓÚ8Ìõ¡£ 3.3.4.8 ISIS ·ÓÉЭÒéÓÅÏȼ¶ ÅäÖÃ˵Ã÷£º

¸ü¸ÄISISЭÒé·ÓÉЭÒéÓÅÏȼ¶/¹ÜÀí¾àÀë ¹æ·¶ÒªÇó£º

ͳһISIS·ÓÉЭÒéÓÅÏȼ¶/¹ÜÀí¾àÀëΪ115£¬»ªÎªÄ¬ÈÏΪ15¡£ 3.3.4.9 ISIS ÖØ·Ö²¼Â·ÓÉ

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ35Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

ÅäÖÃ˵Ã÷£º

ÅäÖý«ÆäËûЭÒéÖØ·Ö²¼µ½ISISЭÒé¡£ ¹æ·¶ÒªÇó£º

ISISЭÒé²»³ÐÔØÓû§Â·ÓÉ£¬½öΪBGPЭÒéÌṩµ×²ãIGP¿É´ï£¬Ô­ÔòÉϲ»½«ÆäËû·ÓÉЭÒé×¢Èë½øISIS£¬ÈçÐèÒªÔòÓÃrouter-policy¹ýÂË×¢Èë¡£

3.3.4.10 ISISÁÚ¾Ó¼ÓÃÜ ÅäÖÃ˵Ã÷£º

ÅäÖÃISISÁÚ¾Ó¼ÓÃÜ£¬¶ÔISISÁÚ¾ÓÖ®¼äµÄЭÒ鱨ÎĽøÐмÓÃܺÍУÑé¡£ ¹æ·¶ÒªÇó£º

¿¼Âǵ½³ÇÓòÍøÃæÏòÓû§µÄ¶Ë¿Ú¹Ø±ÕÁËISIS´¦Àí£¬ÇÒ½­ËÕ³ÇÓòÍøÈ¡ÏûBR£¬ÊµÊ©±âƽ»¯ºó£¬³ö¿Ú·ÓÉÆ÷µÄISISÁÚ¾ÓÊý½«½Ï¶à£¬Îª¼õÉÙISISÁÚ¾Ó¼ÓÃÜÕ¼ÓÃÌ«¶àCPU×ÊÔ´£¬½¨Òé½­ËÕ³ÇÓòÍø²»¿ªÆôISISÁÚ¾Ó¼ÓÃܹ¦ÄÜ¡£

3.3.4.11 ISIS½Ó¿ÚÐû¸æ ÅäÖÃ˵Ã÷£º

ÅäÖÃÐèÐû¸æµ½ISISЭÒéÖеĽӿڣ¬ÅäÖÃloopback½Ó¿ÚºÍ»¥Á¬½Ó¿ÚΪISIS½Ó¿Ú£¬½Ó¿ÚµØÖ·Â·ÓÉ×Ô¶¯·¢²¼µ½ISIS£¬Óû§½ÓÈë½Ó¿ÚÒ»Âɲ»¿ÉÅäÖÃΪISIS½Ó¿Ú¡£

¹æ·¶ÒªÇó£º

ÅäÖÃloopback½Ó¿ÚºÍÉÏÁ¬½Ó¿ÚΪISIS½Ó¿Ú£¬²ÉÓÃPASSIVEģʽ£¬½Ó¿ÚµØÖ·Â·ÓÉ×Ô¶¯·¢²¼µ½ISIS¡£Óû§½ÓÈë½Ó¿ÚÒ»Âɲ»¿ÉÅäÖÃΪISIS½Ó¿Ú¡£

3.3.4.12 ISIS costÖµ¹æ»® ÅäÖÃ˵Ã÷£º

Ö¸¶¨ÔËÐÐISIS½Ó¿ÚµÄcostÖµ£¬²»Ê¹ÓÃISIS×Ô¶¯¼ÆËãµÄ½Ó¿ÚcostÖµ¡£½¨ÒéͳһÉè¼ÆcostÉ趨¹æ·¶À´É趨Á´Â·µÄcost£¬»ùÓÚ½Ó¿ÚÊÖ¹¤Ö¸¶¨ISIS costÖµ£¬Ê¹ÓÃIGPµÄcostÀ´Òýµ¼Á÷Á¿¡£

¹æ·¶ÒªÇó£º

½Ó¿ÚĬÈÏÉèÖÃΪLevel -1 ÍøÂçÀàÐÍ£¬costֵΪ100000¡£

³ÇÓòÍøÊÕÈ¡¹úÄÚ·ÓÉ»ò¹ú¼Ê·Óɺó£¬Í¨¹ý²ã´Î»¯µÄcostÖµ½«¿ÉÄܲúÉúµÄ´©Í¸Á÷Á¿±£³ÖÔÚ³ö¿ÚÉ豸¼ä´©Í¸£¬±ÜÃâÔÚ³ÇÓòÍøÄÚ²¿ºá´©Á÷Á¿¡£

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ36Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

Ò»°ãÉ豸˫ÉÏÁ¬µÄÁ´Â·Ê¹ÓÃͬÑùµÄ´ø¿íÁ´Â·£¬ËùÒÔ°´ÍøÂç²ã´Î·ÖÅäMETRICÖµ£¬½¨ÒéISIS metricÉ趨°´ÕÕÏÂÃæ¹æ·¶Ö´ÐС£

Á´Â·¹¦ÄÜ ³ö¿Ú·ÓÉÆ÷Ö®¼äÁ´Â· »ã¾Û·ÓÉÆ÷ÖÁ³ö¿Ú·ÓÉÆ÷ SR/BRASÖÁ³ö¿Ú·ÓÉÆ÷ SR/BRASÖÁ»ã¾Û·ÓÉÆ÷ »ã¾Û·ÓÉÆ÷Ö®¼äÁ´Â· SR/BRASÖ®¼äÁ´Â· LOOPBACK PASSIVEµÄ½Ó¿Ú ±¸Óà ±£ÁôÁ´Â· ISIS costÖµÉè¼Æ 50 100 100 100 100 100 100 100 140 200

ÅäÖÃ×¢Òâϸ½Ú£º ÈçÓбØÒª£¬»¹Ðè¸ù¾ÝÁ´Â·³ÐÔØµÄÒµÎñÀàÐͽøÐÐCostÖµµÄ»®·Ö£¬ÈçÁ´Â·³ÐÔØµÄÖ÷ÓÃÒµÎñΪ¿í´øÒµÎñ£¬Í¬Ê±×÷ΪITVÒµÎñµÄ±¸ÓÃÁ´Â·£¬Ôò¸ÃÁ´Â·µÄcostֵѡȡΪ100£»ÈçÁ´Â·³ÐÔØµÄÓÃÒµÎñΪITVÒµÎñ£¬Í¬Ê±×÷Ϊ¿í´øÒµÎñµÄ±¸ÓÃÁ´Â·£¬Ôò¸ÃÁ´Â·µÄcostֵѡȡΪ140¡£ ±¸×¢£º±£ÁôÁ´Â·£¨´ý²ð³ý£©½¨ÒéSHUTDOWN½Ó¿Ú»òÈ¡Ïû½Ó¿ÚISISЭÒ飬±ÜÃâÍø¹ÜÎ󱨡£

3.3.4.13 ISIS LSP×î´óÓÐЧʱ¼ä ÅäÖÃ˵Ã÷£º ·ÓÉÆ÷Éú³ÉϵͳLSPʱ£¬»áÔÚLSPÖÐÌîд´ËLSPµÄ×î´óÓÐЧʱ¼ä¡£Èç¹û·ÓÉÆ÷һֱûÓÐÊÕµ½¸üеÄLSP£¬ÔÚ´ËLSPµÄÓÐЧʱ¼äÒѼõÉÙµ½0ºó£¬Èô»¹Î´ÊÕµ½Ë¢ÐµÄLSP£¬Ôò½«¸ÃLSPɾ³ý¡£

CRSĬÈÏΪ1200s£¬»ªÎªÄ¬ÈÏΪ1200s£¬°¢ÀÉĬÈÏΪ1200s£¬JuniperĬÈÏ1200s¡£ ¹æ·¶ÒªÇó£º

ÉèÖÃΪ65500s£¬ÓëLSPË¢ÐÂʱ¼ä±£³ÖÆ¥Åä¡£

¡¾1¡¿CRSÉèÖÃΪ65535,»áÔÚ3.8ÒÔϰ汾»á´¥·¢BUG,½¨ÒéÉèÖÃÉÔСһµãµÄÊýÖµ£¬ÖîÈ磺65500.

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ37Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

3.3.4.14 ¹Ø±ÕISIS hello ±¨ÎÄÌî³ä ÅäÖÃ˵Ã÷£º

ÔÚÁÚ½Ó¹ØÏµµÄ½¨Á¢¹ý³ÌÖУ¬IS-ISÐèÒª¼ì²éÁ´Â·Á½¶ËµÄMTU´óСÊÇ·ñÒ»Ö¡£È±Ê¡Çé¿öÏ£¬IS-ISЭÒ齫Hello±¨ÎÄÌî³äÖÁMTU´óС¡£¿ÉÒÔͨ¹ýÃüÁî¼ò»¯Hello±¨ÎĵÄÊÕ·¢²Ù×÷£¬¼õС¶ÔÍøÂç´ø¿íµÄÀË·Ñ¡£

¹æ·¶ÒªÇó£º

¹Ø±Õhello ±¨ÎÄÌî³ä£¬¼õÉÙÁ´Â·´ø¿íÕ¼Óã¬Í¬Ê±Ê¹IGP²»¼ì²é½Ó¿ÚMTU¡£ 3.3.4.15 ISIS LSP MTU ÅäÖÃ˵Ã÷£º

ISIS LSP MTU¾ö¶¨ÁËIS·¢³öLSPµÄ×î´ó³¤¶È£¬±ØÐëСÓÚÈ«ÍøËùÓÐISµÄ½Ó¿ÚCLNS MTU¡£

¹æ·¶ÒªÇó£º

LSP MTUͳһÉèÖÃΪ1497£¨Cisco¡¢»ªÎª¡¢Juniper³§¼ÒÉ豸ĬÈÏÊýÖµ£©¡£ 3.3.4.16 ISIS LSPˢмä¸ôʱ¼ä ÅäÖÃ˵Ã÷£º

ISIS·ÓÉÆ÷ÖÜÆÚµÄ·¢ËÍLSP¸øÆäËüISIS·ÓÉÆ÷£¬Ê¹Õû¸öISISÇøÓòµÄLSP±£³Öͬ²½¡£

CRSȱʡΪ900s£¬»ªÎªÈ±Ê¡Îª900s£¬°¢ÀÉȱʡΪ600s£¬JuniperȱʡΪLSP×î´óÓÐЧʱ¼ä-317 ¹æ·¶ÒªÇó£º ÉèÖÃΪ32768s£¬JuniperΪ¼ÆËãÖµ¡£¼õÉÙË¢ÐÂÕ¼ÓÃÁ´Â·´ø¿í¡£ 3.3.4.17 ISIS¶¯Ì¬Ö÷»úÃû ÅäÖÃ˵Ã÷£º

ISISµÄLSP±¨ÎÄЯ´øISIS·ÓÉÆ÷Ö÷»úÃû£¬ÆäËüISIS·ÓÉÆ÷Äܶ¯Ì¬½âÎö·ÓÉÆ÷Ãû³Æ¡£

CISCOȱʡÊÇ¿ªÆô£¬»ªÎªÈ±Ê¡Êǹرա£ ¹æ·¶ÒªÇó£º

ÅäÖÿªÆôISIS¶¯Ì¬Ö÷»úÃû¡£

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ38Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

3.3.4.18 ISIS OVERBITλ ÅäÖÃ˵Ã÷£º

ÔÚ·ÓÉÆ÷ÖØÆðʱ£¬ÉèÖÃISIS ¹ýÔØ±êʶλÖÃλ£¬Ê¹ISISÁ÷Á¿²»ÔÚ¸ÃÉ豸ºá´©¡£ ¹æ·¶ÒªÇó£º

ÅäÖÃÔÚ·ÓÉÆ÷ÖØÆôµÄ15ÃëÄÚÉèÖÃISIS OVERBITλ¡£ 3.3.4.19 ISISȱʡ·ÓÉ ÅäÖÃ˵Ã÷£º

³ÇÓòÍø³ö¿Ú·ÓÉÆ÷ÏòÕû¸öÇøÓòÇ¿ÖÆÏ·¢ISISĬÈÏ·ÓÉÒýµ¼³ÇÓòÍøÄÚÓû§µÄÉÏÐÐÁ÷Á¿£¬Í¨¹ýISIS µÄĬÈÏ·ÓÉÀ´´ïµ½³ÇÓòÍøÓû§ÉÏÐÐÁ÷Á¿µÄ¸ºÔؾùºâ¡£ ¹æ·¶ÒªÇó£º

ÅäÖÃISIS×ÜÊÇÏ·¢Ä¬ÈÏ·ÓÉ¡£Í¬Ê±¼ÓTAG 115£¬²¢Ó¦ÓòßÂÔ¹ýÂ˵ô³ýºËÐÄÍâÆäËûÉ豸·¢Ë͵ÄĬÈÏ·ÓɽøÈëIP·ÓÉ±í¡£

3.3.4.20 ISIS logÁھӱ仯ÐÅÏ¢ ÅäÖÃ˵Ã÷£º

ÅäÖÃISIS logÁھӱ仯ÐÅÏ¢£¬¼Ç¼ISISÁھӱ仯¡£ ¹æ·¶ÒªÇó£º

¸ù¾ÝÊ¡¹«Ë¾Í³Ò»¹æ·¶£¬ÅäÖÃISIS log Áھӱ仯ÐÅÏ¢¹¦ÄÜ¡£ 3.3.4.21 ÅäÖ÷¶Àý

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾ µÚ39Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

1£©»ù±¾ÅäÖà isis 100 #ÅäÖÃISISʵÀýID

set-overload on-startup wait-for-bgp 15 #·ÓÉÆ÷ÖØÆô»òÕß³öÏÖ¹ÊÕÏʱ£¬¹ýÔØ±ê־λÔÚÅäÖõÄʱ¼äÄÚ½«±£³Ö±»ÖÃλ״̬£¬¸ù¾ÝBGPÊÕÁ²µÄ״̬£¬ÉèÖÃϵͳ±£³Ö¹ýÔØ±ê־λʱ³¤Îª15s¡£

is-name YC-833-CR.MAN.NE5000E-1 #ÅäÖö¯Ì¬Ö÷»úÃû network-entity xx.xxxx.xxxx.xxxx.00 #ÅäÖÃNET ID

log-peer-change #´ò¿ªIS-ISÁÚ½Ó״̬±ä»¯µÄÊä³ö¿ª¹Ø cost-style wide #ÅäÖýӿڿªÏúÀàÐÍΪwide

circuit-cost 100000 level-1 #È«¾ÖÏÂÅäÖÃÓÐIS-IS½Ó¿ÚµÄĬÈÏ¿ªÏúֵΪ100000,ÍøÂçÀàÐÍΪlevel-1

is-level level-1 #ÅäÖ÷ÓÉÆ÷ÀàÐÍ

maximum load-balancing 16 #ÅäÖøºÔؾùºâÊýΪ16

preference 115 #ÅäÖÃЭÒéÓÅÏȼ¶£¬Ä¬ÈÏΪ15 timer lsp-max-age 65500 #ÉèÖÃΪ65500£¬±¾»úÓÐЧ timer lsp-refresh 32768 #ÉèÖÃΪ32768£¬±¾»úÓÐЧ

timer spf 5 50 200 #·ÓɼÆËã×î´óÑÓ³Ùʱ¼äȱʡֵÊÇ5Ãë,³õ´Î·ÓɼÆËãµÄÑÓ³Ùʱ¼äΪ50ms£¬Á½´Î·ÓɼÆËãÖ®¼äµÄµÝÔöÑÓ³Ùʱ¼äΪ200ms¡£

is-snmp-traps enable #ʹÄÜIS-ISÏòÍø¹Ü·¢ËÍTrap±¨ÎĵŦÄÜ

2£©ºËÐÄISIS½ÓÊÕ·ÓɲßÂÔ

ip ip-prefix ipDefault index 10 permit 0.0.0.0 0

route-policy rpFromISIS permit node 10 if-match tag 115

route-policy rpFromISIS deny node 15 if-match ip-prefix ipDefault

route-policy rpFromISIS permit node 20

isis 100

default-route-advertise always level-1 tag 115 //ʼÖÕÏ·¢Ä¬ÈÏ£¬²¢¼Ótag 115 filter-policy route-policy rpFromISIS import //¹ýÂ˵ôÏÂÁ¬BRAS/SRÉ豸Îó·¢³öµÄĬÈϽøÈë·Óɱí

3£©ÔËÐÐISISЭÒé¶Ë¿ÚÅäÖÃ

interface ge-1/1 #ÅäÖýӿÚÐû¸æ isis enable 100 isis circuit-level level-1

isis cost 100 level-1 #ÅäÖÃcostÖµ

isis small-hello #ÓÃÀ´ÉèÖýӿڷ¢ËͲ»¼ÓÈëÌî³ä×ֶεÄСÐÍHello±¨ÎÄ control-flap

set flow-stat interval 30 undo icmp redirect send

mtu 1600 #ÉèÖÃIP MTUΪ1600 isis circuit-type p2p #ÉèÖö˿ÚÀàÐÍΪP2P

interface pos0/0/0 #ÅäÖýӿÚÐû¸æ

isis enable 100

isis circuit-level level-1 isis cost 100 level-1

isis silent #½Ó¿ÚÉèÖÃΪpassive״̬

3.3.5 BGPÅäÖÃ

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ40Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

3.3.5.1 ¸ÅÊö

EBGPÔËÐÐÔÚ³ÇÓòÍø³ö¿Ú·ÓÉÆ÷Óë163¡¢CN2¹Ç¸ÉÍøÂ·ÓÉÆ÷Ö®¼ä£¬ÊµÏÖ³ÇÓòÍøÏò¹Ç¸ÉÍø·¢²¼³ÇÓòÍøÄڵķÓÉ£¬²¢´Ó¹Ç¸ÉÍø½ÓÊÕȱʡºÍÍøÍâ·ÓÉ¡£

IBGPÔËÐÐÔÚ³ÇÓòÍøºËÐIJãºÍÒµÎñ½ÓÈë¿ØÖÆ²ã£¬³ÐÔØÓû§Â·ÓÉ¡£ 3.3.5.2 ×ÔÖÎϵͳ

½­ËÕµçÐÅËùÊô³ÇÓòÍøÉϲ¼ÊðµÄBGP²ÉÓÃ˽ÓÐ×ÔÖÎϵͳºÅ£¬³ÇÓòÍøÏò163Ðû¸æµÄÍø¶ÎûÓдøcommunity£¬163É豸½«½ÓÊյijÇÓòÍøÂ·ÓÉÉèÖÃcommunity¡£¸÷³ÇÓòÍøASºÅÈçÏ£º ½­ËÕÊ¡Íø¸÷³ÇÓòÍøºÍcommunityÉè¼Æ ³ÇÓòÍø/IDC ÄϾ©³ÇÓòÍø ÎÞÎý³ÇÓòÍø »´°²³ÇÓòÍø ËÞǨ³ÇÓòÍø ÑγdzÇÓòÍø Ì©ÖݳÇÓòÍø Õò½­³ÇÓòÍø ÄÏͨ³ÇÓòÍø ÐìÖݳÇÓòÍø ÑïÖݳÇÓòÍø ³£ÖݳÇÓòÍø Á¬ÔƸ۳ÇÓòÍø ËÕÖݳÇÓòÍø AS±àºÅ 64660 64662 64669 64672 64522 64519 64664 64518 64668 64665 64663 64671 64513 163ÉèÖÃCommunity 4134:111,4134:3025,4134:3250,4134:64660,64660:10661 4134:111,4134:3025,4134:3250,4134:64662,64662:10661 4134:111,4134:3025,4134:3250,4134:64669,64669:10661 4134:111,4134:3025,4134:3250,4134:64672,64672:10661 4134:111,4134:3025,4134:3250,4134:64522,64522:10661 4134:111,4134:3025,4134:3250,4134:64519,64519:10661 4134:111,4134:3025,4134:3250,4134:64664,64664:10661 4134:111,4134:3025,4134:3250,4134:64518,64518:10661 4134:111,4134:3025,4134:3250,4134:64668,64668:10661 4134:111,4134:3025,4134:3250,4134:64665,64665:10661 4134:111,4134:3025,4134:3250,4134:64663,64663:10661 4134:111,4134:3025,4134:3250,4134:64671,64671:10661 4134:111,4134:3025,4134:3250,4134:64513,64513:10661 3.3.5.3 ³ÇÓòÍøBGP ²¿Êð²ßÂÔ ¹Ø±ÕBGP×Ô¶¯Â·ÓÉ»ã×ÜÌØÐÔ¡£ ¹Ø±ÕIGPÓëBGPµÄͬ²½¡£ ¿ªÆôBGP DAMPING£¬±ÜÃâ·ÓÉÒÖÖÆ¶ÔÒµÎñµÄÓ°Ïì¡£ ¹Ø±Õ bgp always-compare-med

Ðû¸æ¸ø163µÄ³ÇÓòÍøÂ·ÓÉЯ´øMEDÊôÐÔ£¬ÉèÖÃMED=0¡£ ³ÇÓòÍøÒÔORIGIN IGPµÄ·½Ê½¶ÔÍâ·¢²¼Â·ÓÉ¡£

Ã÷È·ÅäÖÃBGP router-idΪLoopback 0µØÖ·¡£

¸ù¾ÝÐèҪȷ¶¨BGP MultihopµÄTTLÖµ£¬¶Ô´ó²¿·ÖÇé¿ö£¬ÅäÖÃEBGP MultihopΪ255£¬ÒÔ¼°BGP TTL Security¼ì²â¡£

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ41Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

Ã÷È·ÅäÖÃÐÂʽcommunity¸ñʽ¡£ ¼Ç¼BGPÁھӱ仯¡£

BGP²ÉÓÃÃÜÂ뽨Á¢ÁÚ¾Ó¹ØÏµ£¨EBGPÃÜÂ룺µç»°ÇøºÅ_AS£©¡£ EBGPºÍIBGP¸ºÔؾùºâÊýÄ¿²»Ð¡ÓÚ8¡£

ÅäÖÃBGP³ö·½Ïò·ÓɹýÂË£¬Ðû¸æ¸øÊ¡ÍøÂ·Óɾ¡Á¿ºÏ²¢£¬²ÉÓÃPREFIXºÍNETWORKÐû¸æ¡£

ʹÓÃLoopbackµØÖ·Óë¹Ç¸ÉºËÐĽ¨Á¢EBGP¹ØÏµ£¬²»Ê¹Óýӿڽ¨Á¢¹ØÏµ£¬ÆôÓÃEBGP TTL¼ì²â¡£

BGP TIMER ²ÎÊýkeepaliveºÍHoldtime¶¨Ê±Æ÷ͳһΪ60sÓë180s¡£

3.3.5.4 BGP router-idÅäÖà ÅäÖÃ˵Ã÷£º

ÅäÖÃBGP router-id£¬Î¨Ò»±êʶ×ÔÖÎϵͳÖеÄһ̨BGP·ÓÉÆ÷¡£ ¹æ·¶ÒªÇó£º

ÅäÖÃBGP router-idµØÖ·Îªloopback0½Ó¿ÚµÄIPµØÖ·£¬²»Ê¹ÓÃBGPЭÒé×Ô¶¯Ñ¡¾ÙµÄrouter-id¡£

3.3.5.5 BGP logÁھӱ仯ÐÅÏ¢ ÅäÖÃ˵Ã÷£º

ÅäÖÃBGP logÁھӱ仯ÐÅÏ¢£¬¼Ç¼BGPÁھӱ仯¡£ ¹æ·¶ÒªÇó£º

ÅäÖÃBGP log Áھӱ仯ÐÅÏ¢¡£ ÅäÖù淶£º

NE5000EĬÈÏÖ§³ÖBGP logÁھӱ仯ÐÅÏ¢£¬²»ÐèÌØ±ðÅäÖᣠÅäÖÃ×¢Òâϸ½Ú£º ÎÞ¡£

3.3.5.6 ¹Ø±ÕBGPͬ²½ºÍ×Ô¶¯»ã×Ü ÅäÖÃ˵Ã÷£º

ÅäÖÃBGPЭÒéµÄͬ²½ºÍ×Ô¶¯»ã×ܹ¦ÄÜ¡£ ¹æ·¶ÒªÇó£º

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ42Ò³

½­ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶

ÔÚ³ÇÓòÍøËùÓÐÔËÐÐBGPЭÒéµÄÉ豸ÉϹرÕBGPͬ²½ºÍ×Ô¶¯»ã×ܹ¦ÄÜ¡£ 3.3.5.7 BGPÁÚ¾ÓMD5¼ÓÃÜ ÅäÖÃ˵Ã÷£º

ÅäÖÃBGPÁÚ¾Ó¼ÓÃÜ¡£ ¹æ·¶ÒªÇó£º

BGPÁÚ¾Ó¾ù²ÉÓÃMD5¼ÓÃÜ£¬ÃÜԿΪ£ºµç»°ÇøºÅ_ASºÅ£¬ÓëCN2µÄÃÜÔ¿°´CN2¹æ·¶Ö´ÐС£

3.3.5.8 BGPʱ¼ä²ÎÊý ÅäÖÃ˵Ã÷£º

ÅäÖÃBGPЭÒéµÄKeepaliveºÍHoldtime¶¨Ê±Æ÷£¬Ò»¸öBGP¶ÔµÈÌåÿ¸ôKeepaliveʱ¼äÏòÁÚ¾Ó·¢ËÍÒ»¸ö´æ»î±¨ÎÄ£¬Èç¹ûHoldtimeʱ¼äÄÚûÓбص½ÁÚ¾Ó·¢Ë͵Ĵæ»î±¨ÎÄ£¬¾ÍÈÏΪÕâ¸öÁÚ¾ÓÒÑËÀÍö£¬´Ó¶ø½áÊø»á»°¡£ ¹æ·¶ÒªÇó£º

µ÷½ÚBGP keepaliveʱ¼äΪ60s,holdtimeʱ¼äΪ180s¡£ ÅäÖù淶£º

NE5000E BGP keepaliveʱ¼ä£¬holdtimeʱ¼äĬÈÏ·Ö±ðΪ60sºÍ180s£¬ÏÖÓÐÅäÖÃÎÞÐèÐ޸ġ£

ÅäÖÃ×¢Òâϸ½Ú£º ÎÞ¡£ 3.3.5.9 BGP community ÊôÐԹ滮 ÅäÖÃ˵Ã÷£º

ÅäÖÃBGPЯ´øµÄcommunityÊôÐÔ£¬ÓÃÓÚ·ÓÉ¿ØÖÆ¡£163É豸ÒѶԽÓÊյijÇÓòÍøÂ·ÓÉÉèÖÃcommunity¡£

¹æ·¶ÒªÇó£º

163É豸ÒѶԽÓÊյijÇÓòÍøÂ·ÓÉÉèÖÃcommunity£¬³ö¿Ú·ÓÉÆ÷²»ÓÃÉèÖᣠ3.3.5.10 163 BGP ·ÓɲßÂÔ ÅäÖÃ˵Ã÷£º

ÅäÖóÇÓòÍøÓë163Ö®¼äµÄBGP ·ÓɲßÂÔ

ÖйúµçÐŽ­ËÕ·Ö¹«Ë¾

µÚ43Ò³

ÁªÏµ¿Í·þ£º779662525#qq.com(#Ìæ»»Îª@)