½ËÕµçÐųÇÓòÍø³ö¿Ú·ÓÉÆ÷ (»ªÎªNE5000E) É豸ÅäÖù淶
ÖйúµçÐŽËÕ·Ö¹«Ë¾
2011Äê7ÔÂ
Confidential
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
°æ±¾¸üÐÂ˵Ã÷
V1.0°æ±¾ÎªÎĵµ¶¨¸å°æ£¬ºóÆÚµÄ°æ±¾ÎªÐÞ¶©°æ£¬°æ±¾µÄÐòºÅΪ¡¶½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶VX.X-YYYYMMDD¡·£¬ÐÞ¶©ËµÃ÷ÌîдÔÚ¡°Ö÷Òª¸üÐÂÄÚÈÝ¡±ÖС£
ÏîÄ¿±àºÅ °æ±¾ºÅ V1.4 V1.3 V1.2 V1.1 V1.02 V1.01 V1.0 ±àÖÆÈË/ʱ¼ä Àî¾²/20110709 Àî¾²/20100801 Àî¾²/20100525 Àî¾²/20100425 Àî¾²/20100417 Àî¾²/20100322 Áõ½ðÅô/20091222 ÉóºËÈË/ʱ¼ä Êø¶°/20110709 Êø¶°/20100801 Êø¶°/20100525 Êø¶°/20100425 Êø¶°/20100417 Êø¶°/20100322 Êø¶°/20091222 Îĵµ±àºÅ Q3-WL-43 Ö÷Òª¸üÐÂÄÚÈÝ °´ÕÕ¼¯ÍŹ淶£¬¸üв¿·ÖÄÚÈÝ ¸üÐÂMTU²¿·ÖÄÚÈÝ ¸üÐÂISIS ĬÈÏ·ÓÉÏ·¢Óë½ÓÊÕ²ßÂÔ ¸üÐÂMTU,ISIS²¿·ÖÄÚÈÝ RR£¬²¿·Ö°²È«¼Ó¹Ì²ßÂÔ BFD,ISISÐÒé,BGPÊôÐÔ ¶¨¸å ÖйúµçÐŽËÕ·Ö¹«Ë¾ µÚ1Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
Ŀ ¼
µÚ1ÕÂ 1.1 1.2 µÚ2ÕÂ 2.1 2.1.1 2.1.2 2.2 2.2.1 2.2.2
¸ÅÊö ....................................................................................................................................... 1 ÊõÓïºÍËõдÓï±í ................................................................................................................... 1 ÍøÂç½á¹¹ËµÃ÷ ....................................................................................................................... 3 IP³ÇÓòÍøÍøÂçÉ豸ÃüÃû¼°Á´Â·ÃèÊö¹æ·¶.......................................................................... 5 É豸ÃüÃû¹æ·¶ ....................................................................................................................... 5
ÊÊÓ÷¶Î§ .......................................................................................................................... 5 É豸ÃüÃû¹æ·¶¸ñʽ .......................................................................................................... 5
¶Ë¿ÚÃèÊö¹æ·¶ ....................................................................................................................... 9
»·»Ø½Ó¿ÚÃèÊö .................................................................................................................. 9 ÍøÂç¶Ë¿ÚÃèÊö¹æ·¶ ........................................................................................................ 10
ÊÊÓ÷¶Î§ ............................................................................................................................ 10 ¶Ë¿ÚÃèÊö°üº¬ÏÂÃæ¼¸²¿·Ö ................................................................................................. 10
2.2.2.1 2.2.2.2
2.2.3 2.2.4 µÚ3ÕÂ 3.1 3.1.1 3.1.2 3.1.3
Óû§¶Ë¿Ú ........................................................................................................................ 11 ¿ÕÏж˿ÚÃèÊö ................................................................................................................ 11
³ö¿Ú·ÓÉÆ÷NE5000EÅäÖù淶 ..................................................................................... 12 ϵͳ»ù±¾ÅäÖù淶 ............................................................................................................. 12
É豸Ãû³ÆÅäÖà ................................................................................................................ 12 BannerÅäÖà ................................................................................................................... 12 É豸×ÔÉíʱ¼ä¼°NTP .................................................................................................... 13
Ê±ÇøÅäÖà ............................................................................................................................ 13 ϵͳ±¾µØÊ±¼ä ..................................................................................................................... 13
3.1.3.1 3.1.3.2 3.1.3.3 NTPÏûÏ¢Ô´µØÖ· ...................................................................................................................... 14 3.1.3.4 NTPÐÒé¼ÓÃÜ .......................................................................................................................... 14 3.1.3.5 SNTP½ø³Ì¹Ø±Õ ....................................................................................................................... 15 3.1.3.6
ÅäÖ÷¶Àý ............................................................................................................................ 15
3.1.4 TelnetÅäÖÃ ..................................................................................................................... 16
Á¬½ÓÊýÏÞÖÆ......................................................................................................................... 16 ¿ÕÏÐʱ¼ä ............................................................................................................................ 16
3.1.4.1 3.1.4.2
3.1.4.3 TELNET·ÃÎÊ¿ØÖÆÁбí ........................................................................................................... 17 3.1.4.4
ÅäÖ÷¶Àý ............................................................................................................................ 17
3.1.5 AAAÅäÖÃ ........................................................................................................................ 18
3.1.5.1 AAA·þÎñÆ÷IPµØÖ·ºÍ¶Ë¿ÚºÅ ................................................................................................ 18 3.1.5.2 AAAÏûÏ¢Êý¾Ý°üÔ´µØÖ· .......................................................................................................... 18
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ2Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
3.1.5.3 3.1.5.4 3.1.5.5 3.1.5.6 3.1.5.7
ÈÏ֤ģʽ ............................................................................................................................ 18 ÊÚȨģʽ ............................................................................................................................ 19 Éó¼ÆÄ£Ê½ ............................................................................................................................ 19 ±¾µØÓû§ÕʺŠ..................................................................................................................... 19 ÅäÖ÷¶Àý ............................................................................................................................ 20
3.1.6 3.2 3.2.1 3.2.2 3.2.3
ϵͳ¸ß¿É¿¿ÐÔÅäÖà ........................................................................................................ 21
¶Ë¿ÚÅäÖù淶 ..................................................................................................................... 21
MTUÖµÉè¼Æ ................................................................................................................... 21 Loopback½Ó¿ÚÅäÖà ....................................................................................................... 23 GE½Ó¿ÚÅäÖà .................................................................................................................. 23
½Ó¿ÚÃèÊö ............................................................................................................................ 23
3.2.3.1
3.2.3.2 MTUÖµ ..................................................................................................................................... 24 3.2.3.3 3.2.3.4 3.2.3.5 3.2.3.6
¹Ø±ÕGE¶Ë¿ÚÐÉÌ .............................................................................................................. 24 ¹Ø±Õ´æÔÚ·çÏյݲȫ©¶´ ................................................................................................. 25 ½Ó¿ÚÕðµ´½ûÖ¹ ..................................................................................................................... 25 ÅäÖ÷¶Àý ............................................................................................................................ 25
3.2.4 GE×Ó½Ó¿Ú½Ó¿ÚÅäÖÃ ...................................................................................................... 26
ÃüÃû¹æ·¶ ............................................................................................................................ 26 ½Ó¿ÚÃèÊö ............................................................................................................................ 26
3.2.4.1 3.2.4.2
3.2.4.3 dot1q·â×°¸ñʽ ....................................................................................................................... 26 3.2.4.4
ÅäÖ÷¶Àý ............................................................................................................................ 26
3.2.5 POS½Ó¿ÚÅäÖÃ ................................................................................................................ 27
½Ó¿ÚÃèÊö ............................................................................................................................ 27
3.2.5.1
3.2.5.2 MTUÖµ ..................................................................................................................................... 27 3.2.5.3 POS·â×°¡¢Ö¡µÈ ...................................................................................................................... 27 3.2.5.4 POSÁ´Â·Í¬²½Ê±ÖÓ .................................................................................................................. 28 3.2.5.5 ÅäÖ÷¶Àý ............................................................................................................................ 28
3.2.6 3.3 3.3.1 3.3.2 3.3.3
¶Ë¿Ú¾µÏñÅäÖà ................................................................................................................ 29
·ÓÉÐÒéÅäÖù淶 ............................................................................................................. 29
³ÇÓòÍøÂ·Óɼܹ¹¸ÅÊö .................................................................................................... 29 ·ÓÉÓÅÏȼ¶/¹ÜÀí¾àÀë ................................................................................................... 30 ¾²Ì¬Â·ÓÉÅäÖà ................................................................................................................ 31
¾²Ì¬Â·ÓÉÓÅÏȼ¶ ................................................................................................................. 31 ¾²Ì¬Â·ÓÉÅäÖ÷½Ê½ ............................................................................................................. 31 ºÚ¶´Â·ÓÉÅäÖà ..................................................................................................................... 31 ¸¡¶¯¾²Ì¬Â·ÓÉÅäÖà ............................................................................................................. 32 ¾²Ì¬Â·Óɱê¼ÇºÍÃèÊö ......................................................................................................... 32 ÅäÖ÷¶Àý ............................................................................................................................ 33
µÚ3Ò³
3.3.3.1 3.3.3.2 3.3.3.3 3.3.3.4 3.3.3.5 3.3.3.6
ÖйúµçÐŽËÕ·Ö¹«Ë¾
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
3.3.4 ISIS ÅäÖÃ ....................................................................................................................... 33
¸ÅÊö .................................................................................................................................... 33
3.3.4.1
3.3.4.2 ISIS ʵÀýÃû ............................................................................................................................ 33 3.3.4.3 ISIS NET ID ............................................................................................................................ 34 3.3.4.4 ISIS·ÓÉÆ÷ÀàÐÍ ..................................................................................................................... 34 3.3.4.5 ISIS Cost-style ........................................................................................................................ 34 3.3.4.6 ISISÐÒé½Ó¿ÚÀàÐÍ.................................................................................................................. 35 3.3.4.7 ISIS ¸ºÔؾùºâÌõÄ¿................................................................................................................. 35 3.3.4.8 ISIS ·ÓÉÐÒéÓÅÏȼ¶ ............................................................................................................. 35 3.3.4.9 ISIS ÖØ·Ö²¼Â·ÓÉ .................................................................................................................... 35 3.3.4.10 3.3.4.11 3.3.4.12 3.3.4.13 3.3.4.14 3.3.4.15 3.3.4.16 3.3.4.17 3.3.4.18 3.3.4.19 3.3.4.20 3.3.4.21
ISISÁÚ¾Ó¼ÓÃÜ .................................................................................................................... 36 ISIS½Ó¿ÚÐû¸æ .................................................................................................................... 36 ISIS costÖµ¹æ»® ................................................................................................................ 36 ISIS LSP×î´óÓÐЧʱ¼ä ..................................................................................................... 37 ¹Ø±ÕISIS hello ±¨ÎÄÌî³ä ................................................................................................. 38 ISIS LSP MTU .................................................................................................................... 38 ISIS LSPˢмä¸ôʱ¼ä ..................................................................................................... 38 ISIS¶¯Ì¬Ö÷»úÃû ................................................................................................................ 38 ISIS OVERBITλ ............................................................................................................... 39 ISISȱʡ·ÓÉ .................................................................................................................... 39 ISIS logÁھӱ仯ÐÅÏ¢ ...................................................................................................... 39 ÅäÖ÷¶Àý ............................................................................................................................ 39
3.3.5 BGPÅäÖÃ ........................................................................................................................ 40
¸ÅÊö .................................................................................................................................... 41 ×ÔÖÎϵͳ ............................................................................................................................ 41 ³ÇÓòÍøBGP ²¿Êð²ßÂÔ....................................................................................................... 41
3.3.5.1 3.3.5.2 3.3.5.3
3.3.5.4 BGP router-idÅäÖà ................................................................................................................. 42 3.3.5.5 BGP logÁھӱ仯ÐÅÏ¢ ........................................................................................................... 42 3.3.5.6
¹Ø±ÕBGPͬ²½ºÍ×Ô¶¯»ã×Ü ................................................................................................ 42
3.3.5.7 BGPÁÚ¾ÓMD5¼ÓÃÜ ................................................................................................................ 43 3.3.5.8 BGPʱ¼ä²ÎÊý .......................................................................................................................... 43 3.3.5.9 BGP community ÊôÐԹ滮 .................................................................................................... 43 3.3.5.10 3.3.5.11 3.3.5.12
163 BGP ·ÓɲßÂÔ ............................................................................................................ 43 CN2 BGP·ÓɲßÂÔ ............................................................................................................ 44 ÅäÖ÷¶Àý ............................................................................................................................ 44
3.3.6 RRÅäÖÃ .......................................................................................................................... 46
¸ÅÊö .................................................................................................................................... 47 ¹¦ÄÜÉè¼Æ ............................................................................................................................ 48 ÊÕ·¢Â·ÓɲßÂÔ ..................................................................................................................... 48
3.3.6.1 3.3.6.2 3.3.6.3
3.3.6.4 BGP Peer group̟̞ ............................................................................................................. 49
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ4Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
3.3.6.5
ÅäÖ÷¶Àý ............................................................................................................................ 49
3.3.7 3.3.8 3.3.9
ĬÈÏ·ÓɹÜÀí ................................................................................................................ 51 ¸ºÔؾùºâÅäÖà ................................................................................................................ 51 ²ßÂÔ·ÓÉÅäÖà ................................................................................................................ 52
¸ÅÊö .................................................................................................................................... 52 ²ßÂÔ·ÓɲßÂÔ£¨²Î¿¼£© ..................................................................................................... 52
3.3.9.1 3.3.9.2
3.4 MPLS±êÇ©ÅäÖù淶 ............................................................................................................... 53 3.4.1
MPLSÈ«¾ÖÅäÖà .............................................................................................................. 53
È«¾Ö¿ªÆôMPLS¹¦ÄÜ ......................................................................................................... 53
3.4.1.1
3.4.1.2 MPLS router-id ........................................................................................................................ 54 3.4.1.3
ÅäÖ÷¶Àý ............................................................................................................................ 55
3.4.2 LDPÐÒéÅäÖà ................................................................................................................ 55
3.4.2.1 LDPÐÒé¼ÓÃÜ .......................................................................................................................... 55 3.4.2.2 LDP±êÇ©·¢²¼ºÍ¹ÜÀí .............................................................................................................. 55 3.4.2.3 LDPÐÒéʱ¼ä²ÎÊý .................................................................................................................. 57 3.4.2.4 LDPÁÚ¾Ó¹ýÂË .......................................................................................................................... 57 3.4.2.5
ÅäÖ÷¶Àý ............................................................................................................................ 59
3.5 3.5.1
Íø¹ÜÅäÖà ............................................................................................................................. 59
SNMP¹ÜÀí´úÀíÅäÖà ..................................................................................................... 59
È«¾Ö¿ªÆôSNMP½ø³Ì......................................................................................................... 59
3.5.1.1
3.5.1.2 SNMP°æ±¾ ............................................................................................................................... 60 3.5.1.3 RO CommunityÖµ .................................................................................................................. 60 3.5.1.4 RW CommunityÖµ .................................................................................................................. 61 3.5.1.5 SNMP·ÃÎÊ¿ØÖÆÁбí ............................................................................................................... 61 3.5.1.6 IfindexË÷ÒýÒ»ÖÂÐÔ................................................................................................................. 61 3.5.1.7 ÅäÖ÷¶Àý ............................................................................................................................ 62
3.5.2 ¹ÊÕϹÜÀíÅäÖà ................................................................................................................ 62
3.5.2.1 SNMP TRAPÐÅÏ¢ÄÚÈÝ ............................................................................................................ 62 3.5.2.2 SNMP TRAP ·þÎñÆ÷µØÖ· ....................................................................................................... 63 3.5.2.3 SNMP TRAPÏûÏ¢Ô´µØÖ· ........................................................................................................ 63 3.5.2.4 SYSLOG·þÎñÆ÷µØÖ· ............................................................................................................... 63 3.5.2.5 SYSLOGÐÅÏ¢¼¶±ð ................................................................................................................... 63 3.5.2.6 SYSLOGÏûÏ¢Ô´µØÖ· ............................................................................................................... 64 3.5.2.7
ÅäÖ÷¶Àý ............................................................................................................................ 64
3.5.3 FlowÅäÖÃ ....................................................................................................................... 65
ÅäÖ÷¶Àý ............................................................................................................................ 66
3.5.3.1
3.6 QOSÅäÖù淶 ......................................................................................................................... 66 3.6.1
QoS·ÖÀàºÍ±ê¼Ç ............................................................................................................ 66
µÚ5Ò³
ÖйúµçÐŽËÕ·Ö¹«Ë¾
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
3.6.2 3.6.3 3.6.4 3.6.5 3.6.6 3.7 3.7.1 3.7.2 3.7.3 3.7.4
Ô¤Áô´ø¿í¹ÜÀí ................................................................................................................ 67 Á÷Á¿ÏÞËÙºÍÕûÐÎ ............................................................................................................ 67 ¶ÓÁе÷¶È ........................................................................................................................ 68 ÓµÈû±ÜÃâ ........................................................................................................................ 68 ÓëCN2ÍøµÄQoS¶Ô½Ó .................................................................. ´íÎó£¡Î´¶¨ÒåÊéÇ©¡£
×é²¥ÅäÖù淶 ..................................................................................................................... 73
×é²¥¸ÅÊö ........................................................................................................................ 73 ×é²¥ÅäÖà ........................................................................................................................ 74 ×é²¥RPÅäÖÃ.................................................................................................................. 75 ×é²¥MSDPÅäÖà ............................................................................................................ 76
3.8 BFDÅäÖù淶 .......................................................................................................................... 77 3.8.1 3.8.2 3.8.3 3.8.4 3.8.5 3.9 3.9.1 3.9.2
BFD¸ÅÊö ........................................................................................................................ 77 ¾²Ì¬BFD»á»°ºÍ½Ó¿Ú״̬Áª¶¯ ................................................................................... 78 ¾²Ì¬Â·ÓÉÅäÖÃBFD ........................................................................................................ 79 ISISÐÒéÅäÖÃBFD ........................................................................................................ 79 BGPÐÒéÅäÖÃBFD ........................................................................................................ 80
°²È«²ßÂÔÅäÖÃÍÆ¹ã ............................................................................................................. 81
Ô´µØÖ·ºÏ·¨ÐÔ¼ì²â ........................................................................................................ 81 ³ÇÓòÍøÉ豸°²È«¼Ó¹Ì²ßÂÔ ............................................................................................ 82
ÖйúµçÐŽËÕ·Ö¹«Ë¾ µÚ6Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
µÚ1Õ ¸ÅÊö
Ϊ±£Ö¤³ÇÓòÍøµÄÔËÐÐÖÊÁ¿£¬±ØÐëÔÚÉ豸ÄÜÁ¦¡¢ÍøÂçÉè¼Æ¡¢ÍøÂçÅäÖá¢Î¬»¤Á÷³Ì¡¢Ö§³ÅϵͳµÈ»·½ÚÓèÒÔ±£ÕÏ¡£ÍøÂçÅäÖÃÖ÷ÒªÊÇָͨ¹ýÔÚÉ豸ÉÏʵʩ¾ßÌåÅäÖù淶£¬¿ªÆôÉ豸¿ØÖƲãÃæºÍת·¢²ãÃæµÄ¹¦ÄÜ£¬ÊµÏÖÍøÂçµÄ»¥Í¨£¬±£Ö¤ÍøÂç¾ß±¸Ô¤ÆÚµÄÒµÎñ³ÐÔØÄÜÁ¦¡£Í¬ÑùµÄÎïÀíÍøÂçÔÚ²»Í¬µÄÅäÖÃÏÂËùÌṩµÄÒµÎñ³ÐÔØÄÜÁ¦¿ÉÄܲî¾àÉõÔ¶£¬´ËÍ⣬ÓÉÓÚÍøÂç¹æÄ£²»¶ÏÀ©´ó£¬Éè±¸ÌØÐÔ²»¶Ï±ä»¯£¬ÅäÖù¤×÷ÕýÈÕÒæ±äµÃ¸´ÔÓ£¬È«ÍøÅäÖ÷¢Éú´íÎóµÄ¸ÅÂÊÒ²ÔÚÔö¼Ó£¬Òò´ËºÜÓбØÒª¶Ô³ÇÓòÍøÍøÂçÉ豸µÄÍøÂçÅäÖÃÓèÒԹ淶¡£
±¾¿ÎÌâÉæ¼°µÄ¶ÔÏó¾ÍÊdzÇÓòÍøÍøÂçÉ豸ÅäÖõÄÏà¹Ø¹æ·¶±ê×¼£¬Ä¿µÄÊÇΪ³ÇÓòÍøÎ¬»¤ÈËÔ±ÌṩʵÓÃά»¤¹¤¾ß¡£¿¼Âǵ½³ÇÓòÍøÍøÂçÉ豸ά»¤·Ö¹¤Ã÷È·£¬ÅäÖù淶°´·Ö²á½øÐбàд£¬±¾ÆªÖ»Õë¶Ô³ÇÓòÍøºËÐIJã·ÓÉÆ÷Éè±¸ÖÆ¶¨Ïà¹ØÅäÖù淶¡£
±¾ÎÄÖ÷ÒªÄÚÈݰ²ÅÅÈçÏ£º
1. ½éÉܳÇÓòÍøÓÅ»¯Ä¿±êÍøÂç½á¹¹ÒÔ¼°Â·ÓÉÆ÷ÔÚ³ÇÓòÍøÖеŦÄܶ¨Î»£» 2. ´ÓÍøÂçÅäÖ÷½Ãæ²ûÊöÅäÖÃ˵Ã÷ÒÔ¼°¹æ·¶ÒªÇ󣬲¢¸ø³öÖ÷Á÷·ÓÉÆ÷ÐͺÅÉ豸µÄÅäÖÃʾÀý¡£Õë¶Ô·ÓÉÆ÷É豸£¬ÍøÂçÅäÖÃÖ÷Òª°üÀ¨ÏµÍ³»ù±¾ÅäÖᢶ˿ÚÅäÖᢰ²È«ÅäÖá¢Íø¹ÜÅäÖõȡ£
3. Ìá³öÎĵµÎ¬»¤ºÍÖ´ÐеĹÜÀíÒªÇó¡£
1.1 ÊõÓïºÍËõдÓï±í
±¾ÎÄÖн«Ê¹ÓÃÏÂÁÐÊõÓïºÍËõд£¬³ý·ÇÎÄÖÐÌØ±ð˵Ã÷£¬·ñÔòÒâÒåÈçÏ£»¶ÔÓÚϱíÖÐδ˵Ã÷µÄÊõÓïºÍËõд£¬Ó¦×öÒµ½ç±ê×¼»ò¹ßÀýÀí½â¡£
AAA ACL AS BGP CAR CE CR ÖйúµçÐŽËÕ·Ö¹«Ë¾
Autentication Authorization and Accounting ÈÏÖ¤¡¢ÊÚȨÓë¼Æ·Ñ Access Control List ·ÃÎÊ¿ØÖÆÁбí Autonomous System ×ÔÖÎϵͳ Boarder Gateway Protocol ±ß½çÍø¹ØÐÒé Committed Access Rate ³Ðŵ·ÃÎÊËÙÂÊ Customer Edge ¿Í»§±ßÔµÉ豸 Core Router ºËÐÄ·ÓÉÆ÷ µÚ1Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
DDoS DiffServ DSCP FRR GE GR HA HDLC H-QOS IP ISIS LDP LSP LSR MP-BGP MIB MPLS NSF NSR NTP OAM OSPF PE POS PPP QoS RR RSVP SDH SNMP SR TCP TE ÖйúµçÐŽËÕ·Ö¹«Ë¾
Distributed Deny of Service ·Ö²¼Ê½¾Ü¾ø·þÎñ¹¥»÷ Differentiated Services ²î·Ö·þÎñ Differentiated Service Code Point ²î·Ö·þÎñ´úÂëµã Fast Re-route ¿ìËÙÖØÂ·ÓÉ Gigabyte Ethernet ǧÕ×ÒÔÌ«Íø Graceful Restart ƽ»¬ÖØÆô¶¯ High Availability ¸ß¿ÉÓÃÐÔ High Data Link Control ¸ß¼¶Êý¾ÝÁ´Â·¿ØÖÆ Hierarchical Quality of Servie Internet Protocol »¥ÁªÍøÐÒé Inter System to Inter System Öмäϵͳµ½Öмäϵͳ Label Distribution Protocol ±ê¼Ç·Ö·¢ÐÒé Label Switching Path ±ê¼Çת·¢Â·¾¶ Label Switch Router ±ê¼Ç½»»»Â·ÓÉÆ÷ Multi-protocol Boarder Gate Protocol ¶àÐÒé±ß½çÍø¹ØÐÒé Management Information Base ¹ÜÀíÐÅÏ¢¿â Multiple Protocol Label Switching ¶àÐÒé±êÇ©½»»» Non stop Fowarding ²»¼ä¶Ïת·¢ Non stop Routing ²»¼ä¶Ï·ÓÉ Network Time Protocol Operation Administration and Maintenance ²Ù×÷ά»¤¹ÜÀí Open Shortest Path First Provider Edge ÔËÓªÉ̱ßÔµÉ豸 Packet over SDH SDH·â×°Êý¾Ý°ü Point to Point Protocol µãµ½µãÐÒé Quality of Service ·þÎñÖÊÁ¿ Route Reflector ·ÓÉ·´ÉäÆ÷ Resource Reservation Protocol ×ÊÔ´Ô¤ÁôÐÒé SymMetric Digital Hierarchy ͬ²½Êý×ÖÐòÁÐ Simple Network Management Protocol ¼òµ¥ÍøÂç¹ÜÀíÐÒé Service Router ÒµÎñ·ÓÉÆ÷ Transfer Control Protocol ´«Êä¿ØÖÆÐÒé Traffic Engineering Á÷Á¿¹¤³Ì µÚ2Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
UDP uRPF VPLS VPN VRF VRRP ÉÏÐÐÁ÷Á¿ ÏÂÐÐÁ÷Á¿ ¡¡ User Data Protocol Óû§Êý¾Ý±¨ÐÒé Reverse Path Fowarding ·´Ïò·¾¶×ª·¢ Virtual Private LAN Service ÐéÄâרÓþÖÓòÍøÒµÎñ Virtual Private NetworkÐéÄâרÓÃÍø Virtual Routing and Forwarding ÐéÄâ·ÓÉת·¢ÊµÀý Virtual Routing Redundancy Protocol ÐéÄâ·ÓÉÈßÓàÐÒé Óû§·¢³öµÄÁ÷Á¿ Óû§ÊÕµ½µÄÁ÷Á¿ ¡¡
1.2 ÍøÂç½á¹¹ËµÃ÷ ¾¹ý³ÇÓòÍø¸ÄÔìÀ©Èݺó£¬Ä¿±êÍøÂç½á¹¹ÈçÏÂͼËùʾ¡£IP ³ÇÓòÍø°üÀ¨³ÇÓò¹Ç¸ÉÍøºÍ¿í´ø½ÓÈëÍø£¬ÆäÖгÇÓò¹Ç¸ÉÍøÊÇÒµÎñ½ÓÈë¿ØÖÆµã£¨°üÀ¨BRAS ºÍSR£©¼°¿ØÖƵãÒÔÉϵijÇÓòÍøºËÐÄ·ÓÉÆ÷×é³ÉµÄÈý²ã·ÓÉÍøÂ磬»®·ÖΪºËÐIJãºÍÒµÎñ½ÓÈë¿ØÖÆ²ãÁ½²ã¡£ÒµÎñ½ÓÈë¿ØÖÆ²ã³Ð½Ó¿í´ø½ÓÈëÍøºÍ³ÇÓò¹Ç¸ÉÍø£¬¸ºÔðʵÏÖ¼¯ÖеÄÒµÎñÌṩºÍ¿ØÖÆ£¬BRAS ºÍSR ×÷ΪҵÎñ½ÓÈë¿ØÖÆ²ã×é³É²¿·Ö£¬ÊÇIP ³ÇÓòÍøÊµÏÖ¡°Óû§¿Éʶ±ð¡¢ÒµÎñ¿ÉÇø·Ö¡¢ÖÊÁ¿¿É¿ØÖÆ¡¢ÍøÂç¿É¹ÜÀí¡±µÄתÐÍÄ¿±êµÄÖØÒª»·½Ú¡£
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ3Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
ÖйúµçÐŽËÕ·Ö¹«Ë¾ µÚ4Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
µÚ2Õ IP³ÇÓòÍøÍøÂçÉ豸ÃüÃû¼°Á´Â·ÃèÊö¹æ·¶
2.1 É豸ÃüÃû¹æ·¶
2.1.1 ÊÊÓ÷¶Î§
±¾²¿·Ö¹æ¶¨µÄIP³ÇÓòÍøÉ豸ÃüÃû¹æ·¶£¬ÊÊÓÃÓÚIP³ÇÓòÍøÄÚÒÔÏÂÉ豸£º ? ³ö¿ÚºËÐÄ·ÓÉÆ÷ ? »ã¾Û·ÓÉÆ÷ ? ·ÓÉ·´ÉäÆ÷ ? BRAS ? SR ? »ã¾Û½»»»»ú ? Ô°Çø½»»»»ú ? Â¥µÀ½»»»»ú ? DSLAM 2.1.2 É豸ÃüÃû¹æ·¶¸ñʽ ³ÇÊÐËõд ×Ö·û <6 ±ØÑ¡ ½ÚµãËõд ×Ö·û <8 ±ØÑ¡ É豸ÊôÐÔ ×Ö·û ¡Ü3 ±ØÑ¡ ÍøÂç(ÒµÎñ)ÀàÐÍ ×Ö·û ¡Ü4 ±ØÑ¡ É豸ÐͺŠ×Ö·û ¡Ü7 ¿ÉÑ¡ É豸ÐòºÅ Êý×Ö 3 ¿ÉÑ¡ | ·ûºÅ ×Ö·ûÊý Ñ¡Ïî - ×Ö·û 1 ±ØÑ¡ - ×Ö·û 1 ±ØÑ¡ . ×Ö·û 1 ±ØÑ¡ . ×Ö·û 1 ±ØÑ¡ - ×Ö·û 1 ¿ÉÑ¡ ? ×Öĸ´óС¸÷ÊÐÐèÒª²ÉÓÃͳһ±ê×¼£¬È«²¿´óд¡£ ? Á½¶Ë¡¢Öм䲻´øÈκοոñ¡£
? ³ÇÊбêʶ£¬È¡³ÇÊÐÃû³ÆÆ´ÒôµÄÊ××Öĸ´óдÈ磺ÄϾ©NJ¡¢ÑγÇYC¡£ ? ½Úµã±êʶ£¬È¡½ÚµãÃû³ÆÆ´ÒôµÄÊ××Öĸ´óд£¬ÈçÁ½½ÚµãµÄÊ××ÖĸÓÐÖØµþ£¬Ôò
ȡƴÒô²»ÏàͬµÄÓÃȫƴ£ºÈ¥·ÖÁ½ÖÖÇé¿ö£¬µ±ºóÒ»¸ö×Ö²»Í¬Ê±ÔòºóÒ»¸öȡȫƴ£¬µ±Ç°Ò»¸ö×Ö²»Í¬Ê±Ôòǰһ¸öȡȫƴ£¬È纺ÖÐÃÅ£¨HanZM£©ºÍºóÔ×ÃÅ£¨HouZM£©¡£
? »ªÎªÉ豸Ãû³Æ×î¶à×Ö·ûÊý£º
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ5Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
NE5000E¡¢ME60¡¢5200G¡¢NE80E×î¶à30¸ö×Ö·û£» ? ½¼ÊÐÇø½Úµã±êʶǰͳһÔö¼Ó½¼ÊÐÇøÃû³ÆÆ´ÒôµÄÊ××Öĸ£º
½Äþ£ºNJJN ÆÒ¿Ú£ºNJPK ÁùºÏ£ºNJLH
? É豸ÊôÐÔ±êʶ£¬¹æ¶¨ÈçÏ£º
³ö¿Ú·ÓÉÆ÷£ºCR£¬ÈçºËÐÄ·ÓÉÆ÷¼æ×ö³ö¿Ú·ÓÉÆ÷ÔòÓÃCR »ã¾Û·ÓÉÆ÷£ºBR BRASÉ豸£ºBAS ÒµÎñ·ÓÉÆ÷£ºSR ·ÓÉ·´ÉäÆ÷£ºRR »ã¾Û½»»»»ú£ºBSW Ô°Çø½»»»»ú£ºASW Â¥µÀ½»»»»ú£ºLSW DslamÉ豸£ºDSL WLAN ACÉ豸£ºAC WLAN APÉ豸£ºAP ºÚ¶´É豸£ºHD DNSÉ豸£ºDNS
? É豸ÐòºÅ£¬È¡°¢À²®Êý×Ö£¬´Ó1¿ªÊ¼¡£Í¬½ÚµãµÄÏàͬÊôÐÔµÄÉ豸¼äÒÔÉ豸
ÐòºÅÇø±ð¡£
? ÍøÂçÀàÐÍ£ºMAN (³ÇÓòÍø)£¬M2N£¨µÚ2Æ½ÃæÉ豸£© IDC£¨IDC£© NGN (NGN) ITV(IPTV) DCN
? É豸ÐͺţºÉ豸ÐͺűàÂë¡£
ÖйúµçÐŽËÕ·Ö¹«Ë¾ µÚ6Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
É豸 CISCO CRS-1/MC CISCO 12X16 CISCO 12816 CISCO 6509 CISCO 7609 CISCO 7513 CISCO 2948 CISCO 3550 ALCATEL7750 FOUNDRY 8000 FOUNDRY 4000 SE800 SE1200 »ªÎªNE5000E »ªÎªNE80 »ªÎªNE40 ÖÐÐË T64G É豸ÐͺűàÂë CRS C12X16 C12816 C6509 C7609 C7513 C2948 C3550 AC7750 F8000 F4000 SE800 SE1200 NE5000E NE80 NE40 T64G µÚ7Ò³
ÖйúµçÐŽËÕ·Ö¹«Ë¾
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
ÖÐÐË T40G ÖÐÐË980X ÖÐÐË9210 Juniper E320 Juniper ERX1440 Juniper T1600 »ªÎª MA5200G »ªÎª5200F »ªÎª5200 »ªÎª5100 »ªÎª530X »ªÎª560X »ªÎª8505 »ªÎª8508 »ªÎª3026 »ªÎª2403X »ªÎª6506R »ªÎª6503 T40G ZTE980X ZTE9210 E320 ERX1440 T1600 MA5200G MA5200F MA5200 MA5100 MA530X MA560X S8505 S8508 S3026 S2403X S6506R S6503 ÖйúµçÐŽËÕ·Ö¹«Ë¾ µÚ8Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
±´¶û 730X ÖÐÐË8220
BL730X ZTE8220 ? ×Ô¶¨Òå×ֶΣ¬¿ÉÒÔ¼ÓÈëÍøÂç×ÓÀàÐͼ°É豸ÐͺŵÈÄÚÈÝ¡£ Àý×Ó£º
ʾÀý1£º³ÇÓòÍø³ö¿Ú·ÓÉÆ÷£¬ÄϾ©£¬Óθ©Î÷½Ö£¬µÚһ̨³ö¿Ú·ÓÉÆ÷£¬ÃüÃûΪ NJ-YFXJ-CR.MAN.CRS-1 ʾÀý2£º³ÇÓòÍø»ã¾Û·ÓÉÆ÷£¬ÄϾ©£¬ººÖÐÃÅ£¬µÚһ̨»ã¾Û·ÓÉÆ÷£¬ÃüÃûΪ NJ-HanZM-BR.MAN.C12816-1 ʾÀý3£º³ÇÓòÍøÒµÎñ·ÓÉÆ÷£¬ÄϾ©½Äþ£¬ÌÀɽ£¬µÚһ̨ҵÎñ·ÓÉÆ÷£¬ÃüÃûΪ NJJN-TS-SR.MAN.C12816-1 ʾÀý4£º³ÇÓòÍø»ã¾Û½»»»»ú£¬ÄϾ©£¬Ð½ֿڣ¬µÚһ̨»ã¾Û½»»»»ú£¬ÃüÃûΪ NJ-XJK-BS.MAN.S8505-1 ʾÀý5£º³ÇÓòÍø½ÓÈë½»»»»ú£¬ÄϾ©£¬ºóÔ×ÃÅ£¬µÚһ̨½ÓÈë½»»»»ú£¬ÃüÃûΪNJ-HouZM-AS.MAN.T64G-1 ʾÀý6£ºIPTV·ÓÉÆ÷£¬ÄϾ©£¬ººÖÐÃÅ£¬µÚһ̨»ã¾Û·ÓÉÆ÷£¬ÃüÃûΪ NJ-HanZM-BR.ITV.C7609-1
2.2 ¶Ë¿ÚÃèÊö¹æ·¶ 2.2.1 »·»Ø½Ó¿ÚÃèÊö | ·ûºÅ ×Ö·ûÊý Ñ¡Ïî For ×Ö·û 3 ±ØÑ¡ - ×Ö·û 1 ±ØÑ¡ ¹¦ÄÜÃèÊö ×Ö·û´® ¡Ü30 ±ØÑ¡ ˵Ã÷£º For£º¹Ì¶¨×Ö·û´®¡£
¹¦ÄÜÃèÊö£ºÃèÊö¸Ãloopback¶Ë¿ÚÌØÊ⹦ÄÜ£¬ÎªÓÐÒâÒåµÄÓ¢ÎÄ×Ö·û´®¡£È磺Management¡¢Multicast¡¢VPN¡¢Global Routing¡¢BGP Load balanceµÈ¡£
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ9Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
interface Loopback0 description For-Management ip address 202.97.36.86 255.255.255.255 2.2.2 ÍøÂç¶Ë¿ÚÃèÊö¹æ·¶
2.2.2.1 ÊÊÓ÷¶Î§
±¾²¿·ÖÊÊÓÃÓÚ³ÇÓòÍøÉ豸µÄ»¥Á¬½Ó¿ÚÃèÊö¡£ »ªÎª£ºNE5000E½Ó¿ÚÃèÊö×î¶à242¸ö×Ö·û£¬NE80×î¶à80¸ö×Ö·û£¬ME60×î¶à64¸ö×Ö·û£¬5200G×î¶à80¸ö×Ö·û£» 2.2.2.2 ¶Ë¿ÚÃèÊö°üº¬ÏÂÃæ¼¸²¿·Ö | ·ûºÅ ×Ö·ûÊý Ñ¡Ïî uT:(ÉÏÐÐ)pT:(ƽÐÐ)dT:(ÏÂÐÐ) ×Ö·û 3 ±ØÑ¡ ¶Ô¶ËÉ豸Ãû³Æ ×Ö·û ¡Ü20 ±ØÑ¡ (Á´Â·´«Êä±àºÅ) ×Ö·û ¡Ü15 ±ØÑ¡ ¶Ô¶Ë¶Ë¿ÚÀàÐÍ ×Ö·û ¡Ü10 ±ØÑ¡ ¶Ô¶Ë¶Ë¿Ú±êÖ¾ Êý×Ö/×Ö·û ¡Ü8 ¿ÉÑ¡ £¨VR£© ×Ö·û ¡Ü10 ¿ÉÑ¡ : ×Ö·û 1 ±ØÑ¡ ¡°¶Ô¶Ë¶Ë¿ÚÀàÐÍ¡±Òª¸ù¾Ý¶Ô¶Ë²»Í¬É豸ÀàÐͽøÐÐÇø·Ö¹æ·¶£¬ ¡°¶Ô¶Ë¶Ë¿Ú±êÖ¾¡±±íʾÁ´Â·¶Ô¶ËÉ豸¶ÔÓ¦¶Ë¿ÚµÄ¾ßÌå±êÖ¾¹æ·¶£¬ ¡°(Á´Â·´«Êä±àºÅ)¡±±íʾÁ´Â·µÄ´«ÊäºÅ,Èç¹ûͬ»ú·¿ÄÚÉ豸»¥Á¬ÎÞ´«Êä±àºÅ,ÔòΪ(Local)¡£µ÷²âÆÚ¼äµÄÁ´Â·ÃèÊö×îºóÔö¼Ó¡°::PROCESSING¡±£¬µ÷²âÍê³É¼ÓÒµÎñºóÈ¡Ïû¡°::PROCESSING¡±¡£ ¶Ë¿ÚÀàÐÍÈçÏÂ±í£º
¶Ë¿ÚÀàÐÍ POS(2.5G) POS(10G) POS(40G) ÒÔÌ«(GE) ÒÔÌ«(10GE) ÖйúµçÐŽËÕ·Ö¹«Ë¾
¶Ë¿ÚÃèÊö OC48POS*/*/* 10GPOS*/*/* 40GPOS*/*/* GE*/*/* 10GE*/*/* µÚ10Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
Àý×Ó£º
uT:NJ-YFXJ-CR.MAN.CRS-1:(Local)10GE0/0/1/0(VOD£©::PROCESSING 2.2.3 Óû§¶Ë¿Ú
¶ÔÓÚÁ¬½ÓÓû§µÄ½Ó¿Ú»ò×Ó½Ó¿Ú£¬×îÇ°ÃæÎªÌí¼Ó±¾µØ×¨Ïߺţ¬Èç¹ûÊdz¤Í¾VPNµç·£¬ÐèÒªÌí¼Ó±¾µØ½ÓÈëµç·ºÅ£¨±ÈÈçÄϾ©CTVPN52127A£©¡£ÁíÍ⣬½¨ÒéÌí¼ÓÓû§Ãû³ÆµÈÈçÏÂÐÅÏ¢¡£ ¸ñʽ£º רÏߺŠToÓû§±êʶ | ·ûºÅ ×Ö·ûÊý Ñ¡Ïî ±¾µØ×¨ÏߺŻòÕß½ÓÈëµç·ºÅ ¿Õ¸ñ ×Ö·û ¸ù¾Ýʵ¼ÊÇé¿ö ±ØÑ¡ To ¿Õ¸ñ Óû§±êʶ ¿Õ¸ñ ·ÖÅä´ø¿í ×Ö·û ¡Ü20 ±ØÑ¡ ×Ö·û 1 ±ØÑ¡ ×Ö·û ¡Ü5 ±ØÑ¡ ×Ö·û ×Ö·û ×Ö·û 1 2 1 ±ØÑ¡ ±ØÑ¡ ±ØÑ¡ ˵Ã÷£º ? ±¾µØ×¨ÏߺŻòÕß½ÓÈëµç·ºÅ£¬±ÈÈ磺IPCYW1248693 ? To:¹Ì¶¨×Ö·û´®£» ? Óû§±êʶ£ºÓÐÒâÒåµÄººÓïÆ´ÒôºÍÓïÒô×é³ÉµÄ×Ö·û´®£¬Óû§Ãû.Óû§ÐÔÖÊ£¬ÆäÖÐÓû§ÃûΪСд£¬Óû§ÐÔÖʼûÏÂ±í¹æ²ÎÕÕÏÂ±í½øÐй涨¡£ ¹«Ë¾ ֤ȯ ÒøÐÐ ÍÅÌå Õþ¸® Íø°É ÖÐСѧ ´óѧ CORP SECU BANK COMM GOVE NETB SCHO UNIV ʾÀý1£º IPCYW2517649 To DaJinTouZi.CORP 3M ±íʾÓû§Îª´ó½ðͶ×ʹ«Ë¾£¬Ê¹ÓÃ3M´ø¿í¡£
2.2.4 ¿ÕÏж˿ÚÃèÊö
¹æ·¶ÒªÇóÉ豸ÉϵÄËùÓпÕÏÐδÓõĶ˿Úͳһshutdown£¬±ãÓÚÍø¹Ü¼à¿Ø¡£
ÖйúµçÐŽËÕ·Ö¹«Ë¾ µÚ11Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
µÚ3Õ ³ö¿Ú·ÓÉÆ÷NE5000EÅäÖù淶
3.1 ϵͳ»ù±¾ÅäÖù淶
3.1.1 É豸Ãû³ÆÅäÖÃ
ÅäÖÃ˵Ã÷£º
¹æ·¶É豸ÃüÃû£¬Î¨Ò»ÐÔ±êʶ³ÇÓòÍøÖеÄÿ̨É豸£¬ÓÃÓÚ¶Ô³ÇÓòÍøµÄÿ̨É豸½øÐÐÇø·Ö£¬·½±ãÉ豸¹ÜÀí£¬Ìá¸ß¿É¶ÁÐԺͿɹÜÀíÐÔ¡£ ¹æ·¶ÒªÇó£º É豸Ãû³ÆÒªÇó·ûºÏµÚ¶þÕÂÖС°IP³ÇÓòÍøÍøÂçÉ豸ÃüÃû¼°Á´Â·ÃèÊö¹æ·¶¡±Öй涨¡£ ÅäÖù淶£º # sysname YC-836-CR.MAN.NE5000E-1 ÅäÖÃ×¢Òâϸ½Ú£º ¿ÉÒÔ¸ù¾ÝÐèÒªÌí¼ÓÉ豸ÐͺÅÔÚ.MANºó¡£ ¸î½Ó¹ý¶ÉÆÚ¼äÐÂÉ豸¼ÓN£¬ÈçYC-836-CR.MAN.NE5000E-N1£¬¸î½ÓºóÓ¦¼°Ê±½«Nɾ³ý¡£ 3.1.2 BannerÅäÖà ÅäÖÃ˵Ã÷£º ͳһBannerÓïÑÔ£¬ÒÔÊ¡Íø±ê׼ΪÖ÷¡£ ¹æ·¶ÒªÇó£º ËùÓгö¿Ú·ÓÉÆ÷ÅäÖÃͳһµÄBannerÐÅÏ¢£¬µÇ½ʱÌáʾ£º WARNING!!! Authorised access only, all of your done will be recorded! disconnect IMMEDIATELY if you are not an authorised user! ÅäÖù淶£º
[Quidway] header login information % WARNING!!! Authorised access only, all of your done will be recorded! disconnect IMMEDIATELY if you are not an authorised user!% ÅäÖÃÑéÖ¤£º
µÇ½·ÓÉÆ÷ʱӦ¿´µ½bannerÌáʾ¡£ ÅäÖÃ×¢Òâϸ½Ú£º
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ12Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
BannerÓïÑÔÓ¦Æðµ½ÌáʾºÍ¾¯¸æ·ÇÊÚȨ·ÃÎÊÕßµÄ×÷Óã¬ÑϽûÔÚBannerÖгöÏÖÈκαíʾ»¶ÓµÄ×ÖÑù¡£
3.1.3 É豸×ÔÉíʱ¼ä¼°NTP
NTPʵÏÖÍøÂçÉ豸ʱ¼äͬ²½¹¦ÄÜ£¬Óëʱ¼äÓйصÄÓ¦Óã¬ÀýÈçLogÐÅÏ¢£¬»ùÓÚʱ¼äÏÞÖÆ´ø¿íµÈ£¬¶¼ÐèÒª»ùÓÚÕýÈ·µÄʱ¼ä¡£
3.1.3.1 Ê±ÇøÅäÖà ÅäÖÃ˵Ã÷£º ͳһÉ豸µÄÊ±ÇøÅäÖᣠ¹æ·¶ÒªÇó£º ÅäÖÃÏµÍ³Ê±ÇøÎªGMT+8£¬±±¾©Ê±Çø¡£ ÅäÖù淶£º
¹Ç¸ÉÉ豸ÄϾ©C1, ÄϾ©C4 ×÷Ϊ½ËÕÊ¡ÄÚ³ÇÓòÍø³ö¿Ú·ÓÉÆ÷µÄNTP SERVER£» ³ÇÓòÍøÅäÖÃÖ÷ºÍ±¸Á½×éNTP·þÎñÆ÷£¬²¢·ÖΪÁ½¼¶½á¹¹£º
³ÇÓòÍø³ö¿Ú×÷ΪNTP CLIENT£¬ÅäÖÃÓë202.97.32.192 , 202.97.32.187ͬ²½Ê±ÖÓ£»³ÇÓòÍø³ö¿Ú×öΪNTP SERVER£¬ÅäÖÃNTP ËùÔÚÖ÷ʱÖÓ²ãÊýΪĬÈÏ£¬³ö¿ÚÒÔÏÂÉ豸ÔòÅäÖÃÏò³ö¿Ú·ÓÉÆ÷½øÐÐʱÖÓͬ²½¡£
ÅäÖÃÏÖÍøÉ豸NTPÐÒé°æ±¾ÎªV3¡£
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ13Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
Ö¸¶¨±¾µØ·¢³öNTPÏûÏ¢µÄ½Ó¿Ú¡£ ÅäÖù淶£º
ntp-service source-interface LoopBack0 ntp-service unicast-server 202.97.32.192 preference #Ö÷Ó÷þÎñÆ÷£¬ÄϾ©C1 ntp-service unicast-server 202.97.32.187 #±¸Ó÷þÎñÆ÷, ÄϾ©C4 ntp-service refclock-master 8 #×÷Ϊ³ÇÓòÍøÄÚBRAS/SRµÄntp server£¬È¡Ä¬ÈϲãÊýΪ8 ÅäÖÃÑéÖ¤£º
display ntp-service status display ntp-service session ÅäÖÃ×¢Òâϸ½Ú£º »ªÎªNE·ÓÉÆ÷ĬÈÏNTPÐÒé°æ±¾ºÅΪV3£¬²»ÐèÌØ±ðÅäÖð汾ÐÅÏ¢¡£ ÅäÖÃÏÞÖÆNTP PEERµÄ¿ØÖÆÁбíͳһȡֵΪ2579¡£ 3.1.3.3 NTPÏûÏ¢Ô´µØÖ· ÅäÖÃ˵Ã÷£º Ö¸¶¨±¾µØ·¢³öNTPÏûÏ¢µÄ½Ó¿Ú¡£ ¹æ·¶ÒªÇó£º ³ÇÓòÍøºËÐIJ㡢ҵÎñ¿ØÖƲãÉ豸µÄʹÓÃLoopback0 µØÖ·×÷ΪNTPÏûÏ¢Ô´µØÖ·¡£ ÅäÖù淶£º ntp-service source-interface loopback 0 ÅäÖÃÑéÖ¤£º display current | i ntp-service ÅäÖÃ×¢Òâϸ½Ú£º ÎÞ¡£ 3.1.3.4 NTPÐÒé¼ÓÃÜ ÅäÖÃ˵Ã÷£º
ÅäÖÃNTPÐÒé¼ÓÃÜ£¬·ÀֹαÔìNTPÔ´ÒýÆðÉ豸ʱ¼ä´íÎó¡£ ¹æ·¶ÒªÇó£º
Òò²¿·ÖÉ豸²»Ö§³ÖNTPÐÒé¼ÓÃÜ£¬ÎªÁËÈ«ÍøÍ³Ò»¹æ·¶£¬ÏÖ½×¶ÎNTPÐÒé¾ù²»Ê¹ÓÃʹÓüÓÃÜ¡£
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ14Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
ÅäÖù淶£¨²Î¿¼£©£º
ntp-service authentication enable ntp-service authentication-keyid 11 authentication-mode md5 ¡°xxx¡± #key ntp-service reliable authentication-keyid 11 ÅäÖÃÑéÖ¤£º display clock display ntp-service status display ntp-service session ÅäÖÃ×¢Òâϸ½Ú£º ÎÞ¡£
3.1.3.5 SNTP½ø³Ì¹Ø±Õ ÅäÖÃ˵Ã÷£º SNTPÊÇNTPÐÒéµÄµÄÒ»¸ö¸Äд±¾£¬Ïà±ÈNTPÐÒéʵÏÖ¸ü¼òµ¥£¬µ«¾«È·¶ÈÒªµÍ£¬²»ÄÜͬʱÓë¶à¸öServerͬ²½Ê±¼ä¡£¹Ø±ÕSNTPÐÒ飬¿É·ÀÖ¹»ùÓÚSNTP©¶´µÄ¹¥»÷¡£
¹æ·¶ÒªÇó£º ³ö¿Ú·ÓÉÆ÷ÅäÖÃʹÓÃNTPÐÒéͬ²½Ê±¼ä£¬¶ø²»ÊÇʹÓÃSNTPÐÒé¡£ÒÑÅäÖÃÁËʹÓÃSNTPÐÒéͬ²½Ê±¼äµÄ£¬Ó¦¸ü¸ÄSNTPÐÒéΪNTPÐÒé¡£ ÅäÖù淶£º NE5000EĬÈϹرÕSNTP½ø³Ì£¬²»ÐèÒªÌØ±ðÅäÖᣠÅäÖÃÑéÖ¤£º ÎÞ¡£ ÅäÖÃ×¢Òâϸ½Ú£º ÎÞ¡£ 3.1.3.6 ÅäÖ÷¶Àý clock timezone BeiJing minus 08:00:00 #Ê±ÇøÉèÖã¨Óû§ÊÓͼ£© ntp-service source-interface LoopBack0 ntp-service unicast-server 202.97.32.192 preference #Ö÷Ó÷þÎñÆ÷,ÄϾ©C1 ntp-service unicast-server 202.97.32.187 #±¸Ó÷þÎñÆ÷,ÄϾ©C4 ntp-service refclock-master 8 #³ÇÓòÍø³ö¿Ú·ÓÉÆ÷£¬×÷Ϊ³ÇÓòÍøÄÚBRAS/SRµÄntp server£¬ÌṩʱÖÓ·þÎñ ÅäÖÃacl£¬ÏÞÖÆpeer µÄ·ÃÎÊ acl 2579 acl number 2579 description this acl is used ntp peer rule 10 permit source 202.97.32.192 0 rule 15 permit source 202.97.32.187 0 rule 20 permit source 61.177.248.0 255.255.255.0 ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ15Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
rule 100 deny ntp-service access peer 2579 3.1.4 TelnetÅäÖÃ
3.1.4.1 Á¬½ÓÊýÏÞÖÆ ÅäÖÃ˵Ã÷£º
¶ÔͬʱԶ³ÌµÇ½µ½É豸ÉϵÄsessionÊý½øÐÐÏÞÖÆ£¬¿ÉÒÔ·ÀÖ¹´óÁ¿µÄsessionÁ¬½ÓÕ¼Óùý¶àϵͳ×ÊÔ´£¬Í¬Ê±±ãÓÚ¼¯ÖÐÔËά£¬±£Ö¤¹ÊÕÏÆÚ¼äµÄÕý³£´¦Àí¡£ ¹æ·¶ÒªÇó£º ÅäÖóö¿Ú·ÓÉÆ÷Telnet×î´óÁ¬½ÓÊýÏÞÖÆÎª5¸ö£¨7750ÉèÖÃΪ7£©¡£ ÅäÖù淶£º user-interface maximum-vty 5 ÅäÖÃÑéÖ¤£º display user-interface maximum-vty ÅäÖÃ×¢Òâϸ½Ú£º »ªÎª¼°CISCOÉ豸 VTYÁ¬½ÓÊýÏÞ֯ĬÈÏΪ5¡£ 3.1.4.2 ¿ÕÏÐʱ¼ä ÅäÖÃ˵Ã÷£º ÉèÖÃÁËTelnet³¬Ê±¹¦ÄÜ£¬µ±¿ÕÏÐʱ¼ä³¬¹ýÉ趨ֵºó£¬TelnetÏ̶߳Ͽª£¬·Àֹδ±»ÊÚȨµÄÈËÔ±ÔÚ²Ù×÷Ô±À뿪ºó½øÐзǷ¨²Ù×÷¡£ ¹æ·¶ÒªÇó£º ¶ÔVTY, Console,AUXµÇ¼³¬Ê±ÉèÖýøÐÐÅäÖã¬ÉèÖÿÕÏÐʱ¼äΪ10·ÖÖÓ¡£ ÅäÖù淶£º
user-interface console 0 idle-timeout 10 0 user-interface aux 0 idle-timeout 10 0 user-interface vty 0 9 idle-timeout 10 0 ÅäÖÃÑéÖ¤£º ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ16Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
disp curr | b user-interface ÅäÖÃ×¢Òâϸ½Ú£º »ªÎªÉ豸ĬÈϳ¬Ê±Ê±¼ä¼´Îª10·ÖÖÓ£¬ÅäÖúóÒ²²»»áÏÔʾÅäÖᣠ3.1.4.3 TELNET·ÃÎÊ¿ØÖÆÁбí ÅäÖÃ˵Ã÷£º
ÏÞÖÆTelnetµÇÂ¼ÍøÂçµÄÔ´µØÖ·£¬´Ó¶øÔöÇ¿É豸µÄ°²È«ÐÔ£¬×î´óÏÞ¶È·ÀÖ¹·Ç·¨µÇ½³¢ÊÔ¡£
¹æ·¶ÒªÇó£º ÅäÖÃTelnetÔ´µØÖ·ÏÞÖÆ£¬°üº¬Ê¡¹«Ë¾µØÖ·ºÍ×îС»¯µÄµØÊÐÍø¹ÜÖÐÐÄά»¤IPÍø¶Î¡£ Telnet·ÃÎÊ¿ØÖÆÁбíÌõÄ¿´Ó10¿ªÊ¼£¬ÌõÄ¿µÄ¼ä¸ô²½³¤Îª5£¬ÔÚ·ÃÎÊ¿ØÖÆÁбíµÄ×îºóÏÔʾÅäÖÃÒ»Ìõdeny source anyÓï¾ä¡£ ÅäÖù淶£º acl number 2577 description this acl is used telnet rule 10 permit source *.*.*.* *.*.*.* rule 15 permit source *.*.*.* *.*.*.* rule 3000 deny any ÅäÖÃÑéÖ¤£º disp acl 2577 disp curr | b user-interface ÅäÖÃ×¢Òâϸ½Ú£º »ªÎªÉ豸Telnet ACLͳһʹÓñàºÅ2577¡£ 3.1.4.4 ÅäÖ÷¶Àý ÖйúµçÐŽËÕ·Ö¹«Ë¾ µÚ17Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
acl number 2577 description this acl is used telnet
rule 10 permit source 61.155.48.0 0.0.0.255 rule 15 permit source 61.177.248.0 0.0.1.255 rule 20 permit source 202.102.15.200 0
rule 25 permit source 202.102.37.64 0.0.0.31 rule 3000 deny any
user-interface vty 0 4
acl 2577 inbound #ÉèÖÃVTY¿ÚµÇ¼¿ØÖÆÁбíΪ2577
disp acl 2577
disp curr | b user-interface
×¢Ò⣺
ÐÞ¸ÄACLʱ£¬ÏÈɾ³ýVTYÏÂaclµÄÓ¦ÓÃ,Èçundo acl inbound£¬¶ø²»ÊÇundo acl xxx inbound£¬ÔÙÖØÐÂÓ¦ÓÃеÄacl¡£
3.1.5 AAAÅäÖÃ
3.1.5.1 AAA·þÎñÆ÷IPµØÖ·ºÍ¶Ë¿ÚºÅ ÅäÖÃ˵Ã÷£º
ÅäÖÃAAA·þÎñÆ÷IPµØÖ·£¬Tacacs+ÐÒéÖ§³ÖʹÓÃMD5Ëã·¨À´¼ÓÃܽ»»¥µÄTacacs+±¨ÎÄ£¬Í¨ÐÅË«·½Í¨¹ýÉèÖüÓÃÜÃÜÔ¿À´ÑéÖ¤±¨ÎĵĺϷ¨ÐÔ¡£Ö»ÓÐÔÚÃÜÔ¿Ò»ÖµÄÇé¿öÏ£¬Ë«·½²ÅÄܱ˴˽ÓÊÕ¶Ô·½·¢À´µÄ±¨ÎIJ¢×÷³öÏìÓ¦¡£
¹æ·¶ÒªÇó£º
¸ù¾ÝAAAÈÏÖ¤·þÎñÆ÷µÄÀàÐÍÖ¸¶¨²ÉÓÃTacacs+ÈÏÖ¤£»
Àý£ºÖ¸¶¨Tacacs+·þÎñÆ÷µØÖ·Îª£º221.231.148.6£¬ÈÏÖ¤ÃÜԿΪXXX¡£²¢Ôö¼Ó±¸ÓÃTacacs+·þÎñÆ÷µØÖ·61.177.64.146£¬ÈÏÖ¤ÃÜԿΪXXX¡£
3.1.5.2 AAAÏûÏ¢Êý¾Ý°üÔ´µØÖ· ÅäÖÃ˵Ã÷£º
ÅäÖÃAAAÏûÏ¢Êý¾Ý°üÔ´µØÖ·¡£ ¹æ·¶ÒªÇó£º
Ö¸¶¨³ö¿Ú·ÓÉÆ÷AAAÏûÏ¢Êý¾Ý°üÔ´µØÖ·ÎªLoopback0½Ó¿ÚµØÖ·¡£ 3.1.5.3 ÈÏ֤ģʽ ÅäÖÃ˵Ã÷£º
AAAµÄÈÏÖ¤×é¼þ¸ºÔðÌṩʶ±ð£¨ÈÏÖ¤£©Óû§µÄ·½·¨¡£¿ÉÄܰüÀ¨µÇ¼·ÃÎÊ£¬ÒÔ¼°
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ18Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
ÆäËûÀàÐ͵ķÃÎÊ¡£Ê¹ÓÃAAAÈÏ֤ʱ£¬¶¨ÒåÁËÒ»¸öºÍ¸ü¶àµÄÈÏÖ¤·½·¨£¬¹©Â·ÓÉÆ÷ÔÚÈÏÖ¤Ò»¸öÓû§Ê±Ê¹Óá£
¹æ·¶ÒªÇó£º
ÅäÖÃÈÏÖ¤·½Ê½Ë³ÐòΪÊ×ÏÈÑ¡ÓÃTacacs+·þÎñÆ÷£¬Æä´ÎÑ¡Óñ¾µØÓû§ÐÅÏ¢½øÐÐÈÏÖ¤¡£
ÅäÖÃ×¢Òâϸ½Ú£º
²»Í¬³§¼ÒAAAÈÏÖ¤µÄ˳Ðò²îÒì½Ï´ó£¬ÐèҪעÒâ¡£ 3.1.5.4 ÊÚȨģʽ ÅäÖÃ˵Ã÷£º
Óû§ÈÏÖ¤³É¹¦Íê³ÉÖ®ºó£¬AAAÊÚȨÓÃÀ´ÏÞÖÆÒ»¸öÓû§ÄÜÖ´ÐÐʲôÐÐΪ»òÕßÒ»¸öÓû§ÄÜ·ÃÎÊʲô·þÎñ¡£ÅäÖÃÓÉÏÈTACACS·þÎñÆ÷ÊÚȨ£¬ºó±¾µØÓû§ÊÚȨ¡£Óû§·Ö3¸öµÈ¼¶£º
1¼¶Ö»¾ßÓÐÒ»°ãµÄ²é¿´È¨ÏÞ£¬²»¾ßÓв鿴ÅäÖÃȨÏÞ£» 2¼¶¾ßÓÐ1¼¶µÄ²é¿´È¨ÏÞ¡¢ÅäÖýӿÚȨÏÞ£» 3¼¶È«²¿²Ù×÷ȨÏÞ¡£ ¹æ·¶ÒªÇó£º
ÅäÖÃÓÉÊ×ÏÈTACACS·þÎñÆ÷ÊÚȨ£¬Æä´Î±¾µØÓû§ÊÚȨ£¬Óû§·Ö3¸öµÈ¼¶¡£ 3.1.5.5 Éó¼ÆÄ£Ê½ ÅäÖÃ˵Ã÷£º
AAAÉ󼯹¦ÄܸºÔð¶ÔÈÏÖ¤ºÍÊÚȨÐÐΪʼþ±£³Ö¼Ç¼¡£AAAµÄÉ󼯹¦Äܱ£³ÖʼþµÄÈÕÖ¾¼Ç¼¡£É󼯹¦ÄÜÒªÇóÓÐһ̨ÍⲿAAA°²È«·þÎñÆ÷À´´æ´¢Êµ¼ÊµÄ¼ÇÕʼǼ¡£
¹æ·¶ÒªÇó£º
ÅäÖÃTacacs+·þÎñÆ÷¶ÔµÇ½É豸µÄÓû§½øÐÐÉ󼯼Ǽ¡£ 3.1.5.6 ±¾µØÓû§ÕʺŠÅäÖÃ˵Ã÷£º
ÅäÖñ¾µØÓû§Õʺţ¬×÷ΪAAA·þÎñÆ÷Á¬½Óʧ°ÜʱµÄÓ¦¼±µÇ½Óá£ÅäÖñ¾µØÓû§ÕʺÅadmin£¬ÉèÖÃ×î¸ßȨÏÞ£¬Ê¹ÓÃÊ¡¹«Ë¾Í³Ò»Ö¸¶¨µÄÃÜÂ롣·ÓÉÆ÷µÄCONSOLE¿Ú½öÔÊÐí±¾µØÕʺÅÈÏÖ¤£¬²»Ê¹ÓÃAAA·þÎñÆ÷ÈÏÖ¤¡£
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ19Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
¹æ·¶ÒªÇó£º
ÉèÖÃ×î¸ßȨÏ޵ı¾µØÕ˺ţ¬ÓÃÓÚÓ¦¼±µÇ½¡£ 3.1.5.7 ÅäÖ÷¶Àý
#ÅäÖÃHWTACACS·þÎñÆ÷Ä£°åtongyirenzheng£¬Ô´µØÖ·ÎªÉ豸LOOPBACK0µØÖ·£¬ÃÜԿΪXXX£¬Óû§Ãû¸ñʽÖв»°üÀ¨ÓòÃû¡£
hwtacacs-server template tongyirenzheng hwtacacs-server authentication 221.231.148.6
hwtacacs-server authentication 61.177.64.146 secondary hwtacacs-server authorization 221.231.148.6
hwtacacs-server authorization 61.177.64.146 secondary hwtacacs-server accounting 221.231.148.6
hwtacacs-server accounting 61.177.64.146 secondary hwtacacs-server source-ip *.*.*.* hwtacacs-server shared-key xxx
undo hwtacacs-server user-name domain-included
aaa #½øÈëAAAÊÓͼ
#ÅäÖÃÈÏÖ¤·½°¸hwtacacs£¬ÈÏ֤ģʽÏȲÉÓÃtac·þÎñÆ÷ÈÏÖ¤£¬ºó²ÉÓñ¾µØÈÏÖ¤¡£ authentication-scheme hwtacacs
authentication-mode hwtacacs local
#ÅäÖÃÊÚȨ·½°¸hwtacacs£¬ÏȲÉÓÃtac·þÎñÆ÷ÊÚȨ£¬ºó²ÉÓñ¾µØÓû§ÊÚȨ¡£ authorization-scheme hwtacacs
authorization-mode hwtacacs local
#ÅäÖüƷѷ½°¸hwtacacs£¬Ê¹ÓÃtac·þÎñÆ÷½øÐмƷѡ£ accounting-scheme hwtacacs accounting-mode hwtacacs
#ÅäÖüǼ·½°¸hwtacacs£¬Óë¼Ç¼·½·¨¹ØÁªµÄhwtacacs·þÎñÆ÷Ä£°åµÄÃû³ÆÎªÉÏÃæÅäÖõÄhwtacacs¡£×¢Ò⣺ÔÚʹÓÃrecording-mode hwtacacsÃüÁîǰ£¬hwtacacs·þÎñÆ÷Ä£°å±ØÐëÒѾ´´½¨Íê³É¡£
recording-scheme hwtacacs
recording-mode hwtacacs tongyirenzheng
#ÉèÖÃϵͳʼþµÄ¼Ç¼²ßÂÔ£¬Ä¿Ç°Ö§³Ö¶ÔrebootÃüÁîµ¼ÖµÄʼþ½øÐмǼ¡£ system recording-scheme hwtacacs
#ÉèÖöÔÓÚ·ÓÉÆ÷×öΪ¿Í»§¶Ë½øÐеIJÙ×÷µÄ¼Ç¼²ßÂÔ£¬Ä¿Ç°Ö§³Ö¶ÔTelnet¿Í»§¶ËµÄ¼Ç¼¡£ÃüÁîÖÐÒýÓõļǼ·½°¸Ãû³Æ±ØÐëÊÇÒѾ´´½¨Íê³ÉµÄ¼Ç¼·½°¸¡£ outbound recording-scheme hwtacacs
#ÉèÖÃÓû§ÔÚ·ÓÉÆ÷ÉÏËùÖ´ÐеÄÃüÁîµÄ¼Ç¼²ßÂÔ£¬ÅäÖøÃÃüÁîºó£¬¿ÉÒÔ¶ÔÉ豸Çé¿ö½øÐмǼ£¬¶Ô¼à¿ØºÍ¹ÊÕÏ´¦ÀíÓÐÒ»¶¨µÄ°ïÖú¡£ cmd recording-scheme hwtacacs
#ÅäÖÃȱʡÓòdefaul£¬ÓòµÄÈÏÖ¤·½°¸¡¢¼Æ·Ñ·½°¸¡¢ÊÚȨ·½°¸Ãû³Æ¶¼Îªhwtacacs¡£
domain default
authentication-scheme hwtacacs authorization-scheme hwtacacs accounting-scheme hwtacacs hwtacacs-server tongyirenzheng
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ20Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
#¹æ·¶±¾µØlevel 3 µÄÕʺÅ: local-user admin password cipher admin local-user admin level 3 local-user admin service-type terminal telnet user-interface con 0 authentication-mode password //con¿Ú£¬±¾µØÈÏ֤ģʽ set authentication password cipher XXX //¿É¸ù¾ÝÊ¡NOCͳһ¹æ»® ¼ì²é: display authentication-scheme hwtacacs display authentication-scheme hwtacacs display authorization-scheme hwtacacs display hwtacacs-server template tongyirenzheng display domain default display local-user 3.1.6 ϵͳ¸ß¿É¿¿ÐÔÅäÖà ÅäÖÃ˵Ã÷£º ÅäÖÃϵͳÒýÇæÈßÓàģʽ¡£ ¹æ·¶ÒªÇó£º ´ò¿ª×Ô¶¯Çл»£¬ÒªÇó²ÉÓÃ×îÓÅÇл»·½Ê½¡£ ÅäÖù淶£º »ªÎªNE·ÓÉÆ÷Á½¿éÒýÇæÖ®¼äµÄ±¸·Ý»úÖÆÊÇϵͳ×Ô¶¯µÄ£¬ÔÚMasterÒýÇæ¹ÊÕϵÄÇé¿öÏ£¬Slave»áÁ¢¿Ì×Ô¶¯½«×Ô¼ºÇл»ÎªMasterÒýÇæ£¬ÎÞÐèÃüÁîÅäÖᣠÅäÖÃÑéÖ¤£º display device #ÏÔʾ2¿éMPUΪ1¸öΪMaster״̬£¬Ò»¸öΪSlave״̬ display switchover state #ÏÔʾ±¸·Ý״̬£¬µ±×´Ì¬Îª¡°Info:HA FSM State, Realtime and routine backup.¡±Ê±¼´±íʾ¿ÉÒÔ½øÐÐÖ÷±¸Çл»£¬µ±×´Ì¬ÎªÖ÷±¸ÒýÇæÕýÔÚͬ²½Ê±£¬Çл»¿ÉÄÜ»áÓÐÎÊÌâ ÅäÖÃ×¢Òâϸ½Ú£º ÎÞ¡£
3.2 ¶Ë¿ÚÅäÖù淶
3.2.1 MTUÖµÉè¼Æ
³ÇÓòÍøÂ·ÓÉÐÍÉ豸¶Ë¿ÚMTUµÄÉèÖÃÖ÷ÒªÊܶà¸ö·½ÃæÒòËØÓ°Ï죺
? IP³ÇÓòÍøÄÚ²¿Í³Ò»IP MTUÖµ(MPLS MTUËæIP MTU×Ô¶¯µ÷Õû)£»¶Ô³§¼Ò¡¢
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ21Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
»úÐÍ¡¢°å¿¨ÀàÐÍ¡¢¶Ë¿ÚÀàÐͶ¼Í³Ò»£»
? L3 Protocol MTUÖµ¾¡¿ÉÄÜÈ¡´óÖµ£¬ÒÔ¼Ó¿ìÐÒéÊÕÁ²£»
? IGP·ÓÉÐÒéÁÚ¾Ó¹ØÏµµÄ½¨Á¢£¬ÐèÒªÁ½²àÉ豸¶Ë¿ÚMTUÖµ±£³ÖÒ»Ö£» ? ½ÓÈëÍøµÄÒÔÌ«»¯£¬Öն˲àMTU¾ù²»³¬¹ý1500£»
? ÓëÍⲿÁ¬½Ó¶Ë¿ÚµÄMTUÖµÐèÓë¶Ô¶ËÉ豸ÐÉ̱£³ÖÒ»Ö£¬¾¡¿ÉÄÜÈ¡´óÖµ¡£ ? PIM JoinÏûÏ¢ÒÔ¶Ë¿ÚMTUΪ»ù×¼£¬½øÐÐJoin Êý¾Ý°ü·ÖƬ£» ? ISISÐÒéLSPÊý¾Ý°üĬÈÏ×î´óֵΪ1497£»
¹æ·¶IP³ÇÓòÍøÂ·ÓÉÐÍÉ豸µÄËùÓл¥Á¬¶Ë¿Ú£¬GE/10GEÒÔÌ«Íø¿ÚIP MTUͳһȡֵΪ1600×Ö½Ú£»POS¿ÚIP MTUͳһȡֵΪ4470×Ö½Ú¡£ ΪËõ¶ÌIGPÁÚ¾Ó½¨Á¢Ê±¼ä£¬IGPÐÒéÅäÖÃÈ«²¿È¡Ïû¶Ô½Ó¿ÚMTUµÄ¼ì²é¡£ ¸÷³§¼ÒÉ豸µÄÉ豸¶Ë¿ÚÅäÖÃÏÂMTU¾ßÌ庬ÒåÓÐËù²»Í¬£¬¾ßÌå¼ûÏÂ±í£º ÐòºÅ 1 2 3 4 5 6 1 2 3 4 6 7 8 Juniper TX °¢ÀÊ SR7750 EX ˼¿Æ RedBack SEϵÁÐ CRS-1ϵÁÐ »ªÎª NEϵÁР˼¿Æ É豸³§ÉÌ É豸ÀàÐÍ GSR/76/65ϵÁÐ ¶Ë¿ÚÀàÐÍ Ethernet POS Ethernet POS Ethernet POS Ethernet POS Ethernet POS Ethernet Ethernet POS MTUÖµº¬Òå IP MTU IP MTU IP MTU IP MTU IP MTU IP MTU IP MTU+14 IP MTU+4 IP MTU£«14 IP MTU£«2 IP MTU£«18 IP MTU£«14 IP MTU£«4 ȱʡֵ 1500 4470 1500 4470 1500 4470 1514 4474 1514 9208 1518 1514 4474 ½¨ÒéÖµ 1600 4470 1600 4470 1600 4470 1614 4474 1614 4472 1622 1614 4474 ¡¾1¡¿ Juniper EϵÁÐBrasÉ豸ͨ³£ÓÃ×ӽӿڵķ½Ê½»¥Á¬ÉϲãÉ豸£¬×Ó½Ó¿ÚÏÂIP MTU=Ö÷½Ó¿Ú MTU
-22 ,Òò´Ë½¨ÒéÖ÷½Ó¿ÚMTUȡֵΪ1622¡£
EϵÁÐÉ豸IP MTUÖµÊǸù¾Ý¶þ²ãMTU²ãÖµ×Ô¶¯¼ÆËã¶øÀ´£¬Èý²ãMTUµÈÓÚ¶þ²ãMTU¼õ22;
¡¾2¡¿ SR 7750 ÒÔÌ«¶Ë¿ÚΪaccess ģʽ£¬Ä¬ÈÏMTU Ϊ1514£¬Èô·â×°dot1Q £¬ÔòÐè¼Ó4×Ö½ÚΪ
1518×Ö½Ú£»ÈôΪnetworkģʽ£¬ÔòĬÈÏΪ1514×Ö½Ú;
SR 7750 POS¶Ë¿ÚΪnetwotkģʽʱĬÈÏΪ9208×Ö½Ú¡£
¡¾3¡¿ ¶ÔÓÚiTVƽ̨¡¢È«ÇòÑÛÆ½Ì¨¡¢½»»»BACµÈ·ÇMPLS½ÓÈ룬½¨Òéͳһ½Ó¿ÚIP MTUΪ1500¡£
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ22Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
3.2.2 Loopback½Ó¿ÚÅäÖÃ
ÅäÖÃ˵Ã÷£º
ÅäÖÃLoopbackµØÖ·£¬Ìṩһ¸öÓÀÔ¶upµÄIPµØÖ·£¬ÓÃÓÚ¸÷ÖÖ·ÓÉÐÒéÁھӵĽ¨Á¢¡¢Ô¶³ÌµÇ¼¡¢É豸¹ÜÀíµÈ¡£Í¬Ê±£¬BGPºÍMP-BGP·ÓÉÆ÷ÉϵÄloopbackµØÖ·£¬ÓÃ×÷¸Ã·ÓÉÆ÷·¢²¼µÄBGP»òMP-BGP·ÓɵÄÏÂÒ»ÌøµØÖ·¡£
¹æ·¶ÒªÇó£º
³ÇÓò¹Ç¸ÉÍø³ö¿Ú·ÓÉÆ÷ÅäÖÃÒ»¸öloopback 0µØÖ·£¬ÑÚÂë±ØÐëΪ32λ¡£ Loopback½Ó¿ÚÐèÌí¼Ó¶Ë¿ÚÃèÊö£¬¶Ë¿ÚÃèÊöÒªÇó·ûºÏµÚ¶þÕÂÖÐIP³ÇÓòÍøÍøÂçÉ豸ÃüÃû¼°Á´Â·ÃèÊö¹æ·¶Öй涨¡£ ²âÊÔʹÓÃloopback´Ó500¿ªÊ¼±àºÅ,²¢Ã÷È·±ê×¢ÏàÓ¦µÄ²âÊÔÓÃ;£¬±ãÓÚ²éѯºÍɾ³ý¡£ ÅäÖù淶£º interface LoopBack0 ip address *.*.*.* 255.255.255.255 description For-Management ÅäÖÃÑéÖ¤£º disp inter loopback 0 ÅäÖÃ×¢Òâϸ½Ú£º ÎÞ 3.2.3 GE½Ó¿ÚÅäÖà 3.2.3.1 ½Ó¿ÚÃèÊö ÅäÖÃ˵Ã÷£º ÅäÖýӿÚÃèÊö£¬Ã÷È·±êʶÁ´Â·Á¬½Ó·½Ïò£¬ÓÃÓÚ¶Ô³ÇÓòÍøµÄÿ̨É豸½øÐÐÇø·Ö£¬·½±ãÉ豸¹ÜÀí£¬Ìá¸ß¿É¶ÁÐԺͿɹÜÀíÐÔ¡£
¹æ·¶ÒªÇó£º
¶ÔÓÚ¶þÈý²ã½Ó¿Ú²»·ÖµÄÉ豸£¬£¨»ªÎª£¬CISCO¡¢Juniper£©£º
¶Ë¿ÚÃèÊöÒªÇó·ûºÏµÚ¶þÕÂÖС°IP³ÇÓòÍøÍøÂçÉ豸ÃüÃû¼°Á´Â·ÃèÊö¹æ·¶¡±Öй涨¡£ ¶ÔÓÚ¶þÈý²ã½Ó¿Ú·ÖÀëµÄÉ豸£¬£¨7750¡¢SE800£©£º
ÅäÖöþ²ã½Ó¶Ë¿ÚµÄÃèÊö·ûºÏµÚ¶þÕÂÖС°IP³ÇÓòÍøÍøÂçÉ豸ÃüÃû¼°Á´Â·ÃèÊö¹æ·¶¡±Öй涨¡£²¢×¢Òâ¶Ë¿ÚÃèÊöÖеĶԶ˶˿ÚÓ¦Çø±ð²»Í¬É豸¡£
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ23Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
ÃüÃûÈý²ã½Ó¿Úʱ£¬²ÉÓÃÓëJuniperÀàËÆµÄÃû³Æ, ±ÈÈçso-1/1/3,ge-2/0/0£¬Ãû³ÆÖв»´ø¿Õ¸ñ¡£
ÅäÖÃÈý²ã½Ó¿ÚµÄÃèÊöºÍÏàÓ¦µÄ¶þ²ã½Ó¿ÚÃèÊöÒ»Ö£¬ÉÏÐÐÁ´Â·ÃèÊöǰ׺ʹÓá°uT:¡±£¬ÏÂÐÐÁ´Â·ÃèÊöǰ׺ʹÓá°dT:¡±£¬ºáÁ¬Á´Â·Ç°×ºÊ¹Óá°pT:¡±¡£
δʹÓõĶ˿ÚÐèÒªShutdown£¬²¢É¾³ý¶Ë¿ÚÃèÊö¡¢IPµØÖ·¡¢×Ó½Ó¿ÚµÈÅäÖᣠ3.2.3.2 MTUÖµ ÅäÖÃ˵Ã÷£º
ÅäÖýӿڵÄ×î´ó´«Êäµ¥Ôª(MTU)Öµ¡£µ±Á½¶ËµÄmtuÖµ²»Ò»ÖÂʱ±íÏÖΪ£ºµ±PINGС°üʱÕý³££¬²»»á¶ª°ü£¬µ«ÊÇPING´ó°üʱ»áÃ÷ÏÔ¶ª°ü£¬¶øÇÒÓ°ÏìIGPÐÒéÕý³£½¨Á¢ÁÚ¾Ó¹ØÏµ¡£
¹æ·¶ÒªÇó£º
Cisco CRS-1£¬Juniper TX£¬°¢ÀÉSR 7750 É豸¶Ë¿ÚMTUΪIP MTU +14£¬¼´È¡ÖµÎª£º1614¡£
Cisco GSR£¬»ªÎªÉ豸¶Ë¿ÚMTUȡֵΪ£º1600¡£ Juniper EϵÁÐBrasÉ豸¶Ë¿ÚMTUΪIP MTU +22 £¬¼´È¡ÖµÎª£º1622. ÅäÖÃ×¢Òâϸ½Ú
¶Ë¿ÚÐèshutdown/undoshutdownºó£¬¸ü¸ÄºóµÄMTUÖµ²Å»áÉúЧ¡£
²»Í¬É豸¶Ë¿ÚÏÂMTUÅäÖÃÃüÁÄÜ´æÔÚ²îÒ죬Àý£º»ªÎªÉ豸¶Ë¿ÚÏÂÅäÖÃMTUÃüÁîµÄĬÈϼ´Îª3²ãMTU,¶øCisco CRSÉ豸¶Ë¿ÚÅäÖÃMTUÃüÁîΪ2²ãMTU£¬ÆäÊýÖµÐè-14×Ö½Ú²ÅΪIP MTUÖµ£¬Òò´ËÅäÖö˿ÚMTUֵʱ£¬Ðè×¢ÒⲻͬÉ豸µÄÅäÖÃÏÂMTUÅäÖÃÃüÁîµÄ¹¦ÄܲîÒì¡£
3.2.3.3 ¹Ø±ÕGE¶Ë¿ÚÐÉÌ ÅäÖÃ˵Ã÷£º
¶Ë¿ÚÐÉ̹¦ÄÜÔÊÐíÒ»¸öÉ豸ÏòÁ´Â·Ô¶¶ËµÄÉ豸ͨ¸æ×Ô¼ºËùÔËÐеŤ×÷·½Ê½£¬²¢ÇÒÕì²âÔ¶¶Ëͨ¸æµÄÏàÓ¦µÄÔËÐз½Ê½¡£Ò»ÌõÁ´Â·Á½¶ËµÄ¶Ë¿Ú±ØÐëÊÇͬÑùµÄÅäÖã¬Èç¹ûǧÕ×Á´Â·Á½¶ËµÄÅäÖò»Ò»Ö£¬¶Ë¿Ú״̬½«²»up»ò²»Îȶ¨¡£
¹æ·¶ÒªÇó£º
¹Ø±ÕGE¶Ë¿ÚµÄ×Ô¶¯ÐÉ̹¦ÄÜ£¬·ÀÖ¹ÐÉ̲»Ò»Öµ¼Ö¶˿ڲ»ÄÜup¡£ ÅäÖÃ×¢Òâϸ½Ú£º
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ24Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
ȱʡÇé¿öÏ£¬GEµç¿ÚΪ×Ô¶¯ÐÉÌ£¬¿ÉÐÞ¸ÄÐÉÌģʽ¡£ 3.2.3.4 ¹Ø±Õ´æÔÚ·çÏյݲȫ©¶´ ÅäÖÃ˵Ã÷£º
¹Ø±ÕGE¶Ë¿Ú¿ÉÄÜ´æÔÚ·çÏյݲȫ©¶´¡£
ICMP Redirect£º¿ÉÒÔ֪ͨÖ÷»úÐÞ¸ÄÆä·¢ËÍÊý¾ÝµÄÏÂÒ»ÌøIP£¬¸ü¸ÄÖ÷»úµÄ·ÓÉ£¬´æÔÚDOS¹¥»÷µÄ·çÏÕ¡£
Direct Broadcast£ºÔÊÐíÏò¸ÃÍø¶ÎϵÄËùÓÐÉ豸·¢Ë͹㲥°üÎÄ£¬Ôì³É´óÁ¿µÄÁ÷Á¿¡£ Proxy ARP£ºÔÊÐí½Ó¿Ú´úÀí²éѯARPµØÖ·£¬½«×Ô¼ºµÄMACµØÖ·×öΪӦ´ð£¬´æÔÚARPÆÛư²È«ÎÊÌâ¡£ ¹æ·¶ÒªÇó£º ¹Ø±ÕICMP Redirect¡¢Direct Broadcast¡¢Proxy ARP¡£ 3.2.3.5 ½Ó¿ÚÕðµ´½ûÖ¹ ÅäÖÃ˵Ã÷£º Ϊ±ÜÃâ½Ó¿Ú·´¸´UP/DOWNÔì³Éϵͳ·ÓÉÕðµ´£¬µ¼Ö¶ÔÍøÂçÎȶ¨ÐÔµÄÓ°Ï죬½Ó¿Ú¿ªÆôÕðµ´½ûÖ¹¹¦ÄÜ¡£½öÔÚÖ÷½Ó¿ÚÆôÓ㬲»ÔÚ×Ó½Ó¿ÚÆôÓᣠËùÓÐGEºÍPOS½Ó¿Ú¶¼¿ªÆôdamping¡£ HWĬÈÏÖµ£º half-life:54s, resume:750, suppress:2000, max-suppress:6000 ¹æ·¶ÒªÇó£º ¿ªÆô½Ó¿ÚÕðµ´½ûÖ¹¹¦ÄÜ£¬Ê¹ÓÃĬÈÏÖµ¡£ 3.2.3.6 ÅäÖ÷¶Àý interface GigabitEthernet1/0/0 undo negotiation auto #GEµç¿Ú mtu 1600 #×¢ÒâÓë¶Ô¶Ë±£³ÖÒ»Ö description pT: NJ-HZM-BAS.MAN.SE800-1::( )GE1/0/0 ip address X.X.X.X X.X.X.X undo icmp redirect send undo arp-proxy enable #ĬÈÏÐÐΪ control-flap #¶Ë¿ÚÆôÓÃÕðµ´½ûÖ¹ set flow-stat interval 30 #Á÷Á¿Í³¼ÆÊ±¼ä¼ä¸ôΪ30Ãë¡£ ¼ì²é£º disp inter gi1/0/0 ÖйúµçÐŽËÕ·Ö¹«Ë¾ µÚ25Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
3.2.4 GE×Ó½Ó¿Ú½Ó¿ÚÅäÖÃ
3.2.4.1 ÃüÃû¹æ·¶
»ªÎª¡¢CiscoΪ¹Ì¶¨¡°Ö÷½Ó¿ÚÃû¡±+¡°.¡±+¡°Êý×Ö±àºÅ¡±µÄ¸ñʽ¡£
°¢ÀÊ7750µÄ×Ó½Ó¿ÚÃüÃû¹æ·¶×ñ´Ó¡°-¡±Ö®ºó×Ö¶ÎÓë¹ØÁªsapÏàͬµÄÔÔò£¬¾ßÌå¾ÙÀýÈçÏÂ±í£º
Ö÷½Ó¿ÚÀàÐÍ ×Ó½Ó¿ÚÃüÃû¾ÙÀý(dot1q) ×Ó½Ó¿ÚÃüÃû¾ÙÀý(qinq) FE¿Ú fe-2/1/1:100 fe-2/1/1:100.1001 GE¿Ú ge-1/1/1:200 ge-1/1/1:200.2001 LAG¿Ú lag-1:300 lag-1:300.3001 3.2.4.2 ½Ó¿ÚÃèÊö ÅäÖÃ˵Ã÷£º ³ö¿Ú·ÓÉÆ÷µÄGE×Ó½Ó¿ÚΪÁ¬½Óµ½BAS²»Í¬VRʹÓã¬×Ó½Ó¿ÚÃèÊöÖÐÓ¦ÄÜÌåÏÖÁ¬½Ó¶Ô¶ËVRµÄÏà¹Ø±ØÒªÐÅÏ¢¡£ ¹æ·¶ÒªÇó£º ¸ñʽ£º½Ó¿ÚÃèÊö+(VRÃû³Æ)¡£ 3.2.4.3 dot1q·â×°¸ñʽ ÅäÖÃ˵Ã÷£º ³ö¿ÚGE×Ó½Ó¿Ú·âװΪdot1q¸ñʽ£¬ÓÃÓÚÓëÏÂÁªBAS¾ßÌåVRͨÐÅ¡£ ¹æ·¶ÒªÇó£º GE×Ó½Ó¿Ú·âװΪdot1q¸ñʽ¡£×Ó½Ó¿ÚIDʹÓÃVLANºÅ¡£ 3.2.4.4 ÅäÖ÷¶Àý interface GigabitEthernet1/0/0 undo negotiation auto #GEµç¿Ú mtu 1600 #×¢ÒâÓë¶Ô¶Ë±£³ÖÒ»Ö description pT: NJ-HZM-BAS.MAN.SE800-1::( )GE1/0/0 ip address X.X.X.X X.X.X.X undo icmp redirect send undo arp-proxy enable #ĬÈÏÐÐΪ control-flap #¶Ë¿ÚÆôÓÃÕðµ´½ûÖ¹ set flow-stat interval 30 #Á÷Á¿Í³¼ÆÊ±¼ä¼ä¸ôΪ30Ãë¡£ interface GigabitEthernetX/X/X.192 description pT: NJ-HZM-BAS.MAN.SE800-1::( )GE1/0/0(vrVPDN_LAC) ÖйúµçÐŽËÕ·Ö¹«Ë¾ µÚ26Ò³ ½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
¼ì²éÃüÁ display inter gi X/X/X display inter gi X/X/X.192 vlan-type dot1q 192 ip address X.X.X.X X.X.X.X 3.2.5 POS½Ó¿ÚÅäÖÃ
3.2.5.1 ½Ó¿ÚÃèÊö ÅäÖÃ˵Ã÷£º
ÅäÖýӿÚÃèÊö£¬Î¨Ò»ÐÔ±êʶ³ÇÓòÍøÖеÄÿ̨É豸£¬ÓÃÓÚ¶Ô³ÇÓòÍøµÄÿ̨É豸½øÐÐÇø·Ö£¬·½±ãÉ豸¹ÜÀí£¬Ìá¸ß¿É¶ÁÐԺͿɹÜÀíÐÔ¡£
¹æ·¶ÒªÇó£º
ÒªÇóÅäÖÃÈý²ã½Ó¿ÚµÄÃèÊöºÍÏàÓ¦µÄ¶þ²ã½Ó¿ÚÃèÊöÒ»Ö£¬·ûºÏµÚ¶þÕ¹淶¡£ δʹÓõĶ˿ÚÐèÒªSHUTDOWN£¬²¢É¾³ý¶Ë¿ÚÃèÊö¡¢IPµØÖ·¡¢×Ó½Ó¿ÚµÈÅäÖᣠ3.2.5.2 MTUÖµ ÅäÖÃ˵Ã÷£º
ÅäÖýӿڵÄ×î´ó´«Êäµ¥Ôª(MTU)Öµ¡£µ±Á½¶ËµÄMTUÖµ²»Ò»ÖÂʱ¶¯Ì¬Â·ÓÉÐÒé²»ÄÜÕý³£½¨Á¢ÁÚ¾Ó¹ØÏµ¡£µ±PINGС°üʱÕý³££¬²»»á¶ª°ü£¬µ«ÊÇPING´ó°üʱ»áÃ÷ÏÔ¶ª°ü¡£
¹æ·¶ÒªÇó£º
Cisco CRS-1£¬Juniper TX É豸¶Ë¿ÚMTUΪIP MTU +4£¬Ä¬ÈÏÖµ¼´Îª4474£¬ÎÞÐèÅäÖᣠCisco GSR£¬»ªÎªÉ豸¶Ë¿ÚÏÂMTUĬÈÏֵΪ4470£¬ÎÞÐèÅäÖᣠ°¢ÀÉSR 7750É豸¶Ë¿ÚMTUΪIP MTU +2£¬¼´È¡ÖµÎª£º4472¡£ 3.2.5.3 POS·â×°¡¢Ö¡µÈ ÅäÖÃ˵Ã÷£º
POS¼´Packet Over SONET/SDH£¬Ê¹ÓÃSDHÌṩµÄ¸ßËÙ´«ÊäͨµÀÖ±½Ó´«ËÍIP·Ö×飬SONET/SDHÊǵã¶ÔµãµÄÎïÀí²ãµÄÐÒ飬IPÊÇÍøÂç²ãµÄÐÒé¡£¸ù¾ÝOSIÆß²ãÄ£ÐÍ£¬¶þÕßÖ®¼ä»¹ÐèÒªÒ»¸öÁ´Â·²ãÐÒ飬¿ÉÅäÖòÉÓÃPPP»òHDLC×÷ΪÁ´Â·²ãµÄÐ
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ27Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
Òé¡£
ÅäÖÃPOSµÄÎïÀí²ãÖ¡¸ñʽ²ÉÓùú¼Ê±ê×¼SDH£¬²»Ê¹Óñ±ÃÀ±ê×¼SONET¡£ ÅäÖÃPOS½Ó¿ÚµÄÏß·¼ÓÂ빦ÄÜ£¬±ãÓÚ½ÓÊܶËÌáÈ¡Ïß·ʱÖÓ£¬Èç¹ûÒ»¶ËÅäÖÃÁËÏß·¼ÓÈŶøÁíÒ»·½Ã»ÓУ¬Ôò²»ÄÜ»¥Í¨¡£
ÅäÖÃPOS½Ó¿ÚÁ½¶ËµÄCRCÖµ±ØÐëÒ»Ö£¬·ñÔò²»ÄÜ»¥Í¨¡£
ÅäÖÃPOSµÄÁ´Â·²ãÖ¡¸ñʽʹÓùú¼Ê±ê×¼PPP£¬²»Ê¹ÓÃHDLC·â×°¡£ ¹æ·¶ÒªÇó£º
ÅäÖÃPOS½Ó¿Ú·âװΪPPP£» ÅäÖÃPOSµÄÖ¡¸ñʽΪSDH£» ÅäÖÃCRCÉèÖÃΪ32λ£» ¿ªÆôPOS scramble¼ÓÈÅ£» ¹Ø±ÕICMP RedirectÌØÐÔ£» 3.2.5.4 POSÁ´Â·Í¬²½Ê±ÖÓ ÅäÖÃ˵Ã÷£º
ÅäÖÃPOSÁ´Â·Í¬²½Ê±ÖÓ£¬Óë´«Ê以ÁªÊ±ÖÓÓ¦¸úËæ´«ÊäʱÖÓ£¬ÓëÆäËû·ÓÉÆ÷±³¿¿±³ÂãÏËÖ±Á¬½Óʱ£¬»¥Á¬Ë«·½¶¼ÉèÖÃΪÖ÷ʱÖÓ£¬·ÀÖ¹³öÏÖʱÖÓ»·¡£Ö÷ʱÖÓÊÇʹÓÃÄÚ²¿Ê±ÖÓÐźÅÅж¨ÊÕµ½µÄÊý¾Ý룬´ÓʱÖÓÊÇʹÓôÓÊÕµ½µÄÊý¾ÝÁ÷ÖÐÌáÈ¡¶Ô¶ËʱÖÓÐźÅÀ´Åж¨ÊÕµ½µÄÊý¾Ýλ¡£
CISCO¡¢JUNIPER¡¢Alcatel-Lucent POS¶Ë¿ÚĬÈÏΪ´ÓʱÖÓ£¬»ªÎªÄ¬ÈÏΪÖ÷ʱÖÓ¡£ ¹æ·¶ÒªÇó£º Óë´«Ê以ÁªÊ±ÖÓ¸úËæ´«ÊäʱÖÓ£¬¼´Â·ÓÉÆ÷ÅäÖÃΪ´ÓʱÖÓ¡£
ÈçΪWDM»òÓëÆäËû·ÓÉÆ÷±³¿¿±³ÂãÏËÖ±Á¬½Óʱ£¬»¥Á¬Ë«·½¾ùÉèÖÃΪÖ÷ʱÖÓ¡£ 3.2.5.5 ÅäÖ÷¶Àý
interface pos 1/0/0 description pT:NJ-YFXJ-CR.MAN.CRS-1:( )10GPOS0/5/3/0 mtu 4470 #ĬÈÏÖµ link-protocol ppp #ĬÈÏÖµ frame-format sdh #ĬÈÏÖµ scramble #ĬÈÏÖµ clock master #ĬÈÏΪMaster set flow-stat interval 30 control-flap undo icmp redirect send ÖйúµçÐŽËÕ·Ö¹«Ë¾ µÚ28Ò³ ½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
¼ì²é£º display inter pos 1/0/0 3.2.6 ¶Ë¿Ú¾µÏñÅäÖÃ
ÅäÖÃ˵Ã÷£º
ÉèÖÃÒ»¸ö¶Ë¿Ú×÷Ϊ¾µÏñ¶Ë¿Ú£¬½«Á÷¾Ò»¸ö»ò¼¸¸öÖ¸¶¨¶Ë¿ÚµÄËùÓÐÊý¾ÝÖ¡¿½±´µ½Õâ¸ö¾µÏñ¶Ë¿ÚÉÏÀ´¡£
¹æ·¶ÒªÇó£º ÔÚÓбØÒªÊ±ÅäÖö˿ھµÏñ¹¦ÄÜ¡£ ÅäÖù淶£º observe-port interface gigabitethernet3/0/2 interface gi 1/0/0 port-mirroring to observe-port 1 inbound ÅäÖÃÑéÖ¤£º disp curr | i observe-port disp curr int gi 1/0/0 ÅäÖÃ×¢Òâϸ½Ú£º ÎÞ¡£ 3.3 ·ÓÉÐÒéÅäÖù淶 3.3.1 ³ÇÓòÍøÂ·Óɼܹ¹¸ÅÊö ½ËÕµçÐÅÏÂÊô³ÇÓòÍø¸÷×Ô¹¹³Éµ¥¶ÀASÓò£¬³ÇÓòÍøÂ·Óɼܹ¹·ÖΪÓû§Â·ÓÉÉú³É£¨custom routing£©¡¢IGP¡¢BGP¡¢MP-BGP·ÓÉ4¸ö²¿·Ö¡£ Óû§Â·ÓÉÉú³É£ºÖ¸ÔÚ³ÇÓòÍøÒµÎñ½ÓÈë¿ØÖÆµã£¨BRASºÍSR£©ÉÏÅäÖÃÉú³É»ò¶¯Ì¬Ñ§Ï°Óû§Â·ÓɵÄʵÏÖ·½Ê½ºÍ¹ý³Ì£» IGP£ºÔËÐÐÔÚ³ÇÓòÍøºËÐIJãºÍÒµÎñ½ÓÈë¿ØÖÆ²ã£¬ÔÚ³ÇÓòÍøÈý²ãÉ豸֮¼ä³ÐÔØºÍ½»»»Â·ÓÉÐÅÏ¢£º³ÇÓòÍøASÓòÄÚÉ豸½Ó¿Ú£¨°üÀ¨loopback½Ó¿Ú£©µØÖ·Â·ÓÉ¡£
BGP£º
IBGP-ÔËÐÐÔÚ³ÇÓòÍøºËÐIJãºÍÒµÎñ½ÓÈë¿ØÖÆ²ã£¬³ÐÔØ³ÇÓòÍøÄÚIPV4Óû§Â·ÓÉ£» EBGP-ÔËÐÐÔÚ³ÇÓòÍø³ö¿Ú·ÓÉÆ÷Óë163¡¢CN2¹Ç¸ÉÍøÂ·ÓÉÆ÷Ö®¼ä£¬ÊµÏÖ³ÇÓòÍøÏò¹Ç¸ÉÍø·¢²¼³ÇÓòÍøÄڵķÓÉ£¬²¢´Ó¹Ç¸ÉÍø½ÓÊÕȱʡºÍÍøÍâ·ÓÉ¡£
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ29Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
MP-BGP£ºÔËÐÐÔÚSR£¨¼´PE£©Ö®¼ä£¬ÓÃÓÚ³ÐÔØ³ÇÓòÍø×ÔÖÎÓòÄںͿçÓòMPLS VPNv4Óû§Â·ÓÉ¡£
3.3.2 ·ÓÉÓÅÏȼ¶/¹ÜÀí¾àÀë
ÅäÖÃ˵Ã÷£º
¶Ô·ÓÉÓÅÏȼ¶/¹ÜÀí¾àÀëµÄ¶¨ÒåÊÇΪÁËÉ豸ÔÚ½ÓÊÕµ½Ïàͬ·ÓÉÌõĿʱºò½øÐÐѡ·£¬ÔÚ·ÓÉÌõÄ¿ÏàͬµÄÇé¿öÏ£¬ÓÅÏȼ¶ÊýֵСµÄ·Óɽ«±»Ñ¡Ôñ¡£
¹æ·¶ÒªÇó£º Â·ÓÉÓÅÏȼ¶±ðµÄÉ趨°´ÕÕÏÂÃæ¹æ·¶¡£ Route type Direct attached ÆÕͨ¾²Ì¬ EBGP OSPF internal IS-IS External ISIS ºÚ¶´Â·ÓÉ IBGP ¸¡¶¯¾²Ì¬ Route Preference/AD 0 [1] 1»ò5 [2] 20 110 10 115 [3] 15 25 150 180 200 210
ÅäÖÃ×¢Òâϸ½Ú£º ÉϱíΪ·ÓÉÓÅÏȼ¶±ðµÄÍÆ¼öÉ趨ֵ£¬ÔÚʵ¼ÊÉ趨ʱ°´ÒÔÏÂ˳Ðò¼´¿É£º ÆÕͨ¾²Ì¬->EBGP->OSPF->ISIS->ºÚ¶´¾²Ì¬->IBGP->¸¡¶¯¾²Ì¬¡£
[1][2]
£ºÒ»°ã²»¿É¸ü¸Ä¡£
£ºÖ®ËùÒÔûÓÐͳһ£¬ÊÇÒòΪ£º
¾²Ì¬Â·ÓÉȱʡֵ£ºCisco 1£»Juniper 5£»Alcatel 5£»»ªÎª£º60
°´ÉÏÊöµ÷Õû£¬1»ò5¶Ô·ÓÉÑ¡Ôñ¶¼²»»á²úÉúʵÖÊÐÔµÄÓ°Ï죬¹Ê³ý»ªÎªÉ豸ÐèÒª½«¾²Ì¬Â·ÓɵÄ
ȱʡÓÅÏȼ¶ÐÞ¸ÄΪ1Í⣬ÆäËû³§¼ÒÉ豸±£³Öȱʡֵ¼´¿É¡£
[3]
£ºÒòCisco·ÓÉÆ÷²»Çø·ÖIS-IS L1/L2¡¢Internal/External·ÓɵÄÓÅÏȼ¶/¹ÜÀí¾àÀ룬¹ÊÖ»Äܽ«Æä
IS-IS·ÓɹÜÀí¾àÀë/ÓÅÏȼ¶Í³Ò»ÉèΪ115¡£
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ30Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
3.3.3 ¾²Ì¬Â·ÓÉÅäÖÃ
3.3.3.1 ¾²Ì¬Â·ÓÉÓÅÏȼ¶ ÅäÖÃ˵Ã÷£º
¸ü¸Ä¾²Ì¬Â·ÓɵÄÐÒéÓÅÏȼ¶/¹ÜÀí¾àÀë¡£ ¹æ·¶ÒªÇó£º
ÆÕͨ¾²Ì¬Â·ÓÉÓÅÏȼ¶/¹ÜÀí¾àÀëÅäÖÃΪ1¡£CISCOºÍAlcatelÎÞ·¨ÓÃÒ»ÌõÃüÁîÐÞ¸ÄËùÓо²Ì¬Â·ÓɵÄȱʡÓÅÏȼ¶£¨Ö»ÄÜÖðÌõÐÞ¸ÄÿÌõ¾²Ì¬Â·ÓÉ£©¡£JuniperºÍ»ªÎª¿ÉÒÔÓÃÒ»ÌõÃüÁîÐÞÓÐËùÓо²Ì¬Â·ÓɵÄȱʡÓÅÏȼ¶¡£
ÅäÖÃ×¢Òâϸ½Ú£º
¾²Ì¬Â·ÓÉÓÅÏȼ¶È±Ê¡Öµ£ºCisco 1£»Juniper 5£»Alcatel 5£»»ªÎª£º60¡£ »ªÎªÉ豸ʹÓÃÒ»ÌõÃüÁîÐÞ¸ÄËùÓо²Ì¬Â·ÓɵÄÓÅÏȼ¶£¬Ö»Õë¶ÔÐÂÔöµÄ¾²Ì¬ÉúЧ£¬¶øÐÞ¸ÄǰÒÑ´æÔڵľ²Ì¬Â·ÓɵÄÓÅÏȼ¶±ðÒÀÈ»ÐèÖðÌõÊÖ¶¯µ÷Õû¡£ 3.3.3.2 ¾²Ì¬Â·ÓÉÅäÖ÷½Ê½ ÅäÖÃ˵Ã÷£º
Ö¸¶¨³ö¿Ú·ÓÉÆ÷Éϵľ²Ì¬Â·ÓÉÅäÖ÷½Ê½£» ¹æ·¶ÒªÇó£º
³ö¿Ú·ÓÉÆ÷Óë²»ÔËÐзÓÉÐÒéµÄBRASÖ®¼ä¾²Ì¬Â·ÓÉÅäÖ÷½·¨¸ù¾Ý³ö¿Ú·ÓÉÆ÷µÄ²»Í¬¶øÓÐËùÇø±ð£º
? CISCO¡¢»ªÎª¾²Ì¬Â·ÓɲÉÓõü´ú·½Ê½£¬°ó¶¨ÏÂÒ»ÌøÎª¶Ô¶ËÉ豸Loopback0
µØÖ·£¬¶Ô¶ËÉ豸µÄLoopback0µØÖ·²ÉÓÃͬʱ°ó¶¨ÏÂÒ»ÌøIP µØÖ·ºÍ³ö½Ó¿ÚµÄ¾²Ì¬Â·ÓÉ·½Ê½¡£
? 7750¾²Ì¬Â·ÓÉÖ»°ó¶¨ÏÂÒ»ÌøIP µØÖ·¡£
? Juniper-TX POS¶Ë¿Ú¾²Ì¬Â·ÓÉÖ»°ó¶¨³ö½Ó¿Ú£¬²»°ó¶¨ÏÂÒ»ÌøIPµØÖ·¡£GE
¶Ë¿Ú¾²Ì¬Â·ÓÉÖ»°ó¶¨IP µØÖ·£¬²¢Ìí¼ÓNO-RESOLVE²ÎÊý¡£ ¹æ·¶ÒªÇó£º
¾²Ì¬Â·Óɰ󶨽ӿںÍÏÂÒ»ÌøIPµØÖ·¡£ 3.3.3.3 ºÚ¶´Â·ÓÉÅäÖà ÅäÖÃ˵Ã÷£º
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ31Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
ÔÚ³ö¿Ú·ÓÉÆ÷ÉÏÅäÖóÇÓòÍøÍø¶ÎµÄÖ¸ÏòNULL0µÄºÚ¶´Â·ÓÉ£¬ÓÃÓÚBGPÐÒ齫³ÇÓòÍøÍø¶ÎÐû¸æ¸ø¹Ç¸É£¬ÅäÖÃÓÅÏȼ¶Îª180£¬²¢Ôö¼ÓTAG 901±ê¼Ç¡£
³ö¿Ú·ÓÉÆ÷ÉϵijÇÓòÍøÍø¶ÎºÚ¶´Â·ÓÉÑϽû×¢Èëµ½ISISÖС£
³ÇÓòÍøÁ½Ì¨³ö¿Ú·ÓÉÆ÷ÉÏÅäÖõĺڶ´Â·ÓÉÔÔòÉϱØÐëÍêÈ«Ïàͬ£¬ÒÔ±ÜÃâ´Ó¹Ç¸É·µ»ØµÄÁ÷Á¿²»¾ùºâ¼°uRPF´íÎó¡£
¹æ·¶ÒªÇó£º
ºÚ¶´Â·ÓÉÅäÖÃÓÅÏȼ¶Îª180£¬Ôö¼ÓTAG 901±ê¼Ç£¬ÑϽû×¢Èëµ½ISISÖС£ ÅäÖÃ×¢Òâϸ½Ú£º
ÅäÖÃǰÐè×ÐϸÅŲé³ÇÓòÍøºËÐÄÉÏÊÕµ½µÄBR/BRAS/SR»ã×Ü·¢À´µÄIBGP·ÓÉÊÇ·ñºÍ±¾»úͨ¹ý¾²Ì¬Ö¸Ïònull 0 + network·¢²¼µÄÍø¶ÎÖдæÔÚ×ÓÍøÑÚÂ볤¶ÈÏàͬµÄ·ÓÉÌõÄ¿£¬Õë¶ÔÕâÖÖÌØÀý£¬ºËÐÄÉÏÐèÈ¡ÏûÕë¶Ô¸Ã·ÓÉnetwork µÄ¾²Ì¬·¢²¼Óï¾ä£¬·ñÔò»áÔì³ÉºËÐÄÉϵÄÕë¶Ô¸ÃÌõĿ·ÓɵÄÁ÷Á¿¶ªÆú¡£
3.3.3.4 ¸¡¶¯¾²Ì¬Â·ÓÉÅäÖà ÅäÖÃ˵Ã÷£º
³ö¿ÚºËÐÄÉÏÅäÖöàÌõÖ¸Ïò¹Ç¸ÉÉ豸µÄ¾²Ì¬Ä¬ÈÏ·ÓÉ£¬±ÜÃâ³ö¿ÚºËÐĺ͹ǸÉÉ豸֮¼äµÄBGP»á»°³öÏÖ¹ÊÕÏʱ¶øÒýÆðÁ÷Á¿ÎÞ·¨×ª·¢µÄÏÖÏó¡£
ÏÂÁ¬»ã¾ÛBR£¬BRAS/SRÉ豸ÉÏÅäÖöàÌõÖ¸Ïò³ÇÓòÍøºËÐĵľ²Ì¬Ä¬ÈÏ·ÓÉ£¬±ÜÃâ±¾¶ËºÍºËÐÄÖ®¼äµÄISIS/BGP»á»°³öÏÖ¹ÊÕÏʱ¶øÒýÆðÁ÷Á¿ÎÞ·¨×ª·¢µÄÏÖÏó¡£
¹æ·¶ÒªÇó£º
³ö¿ÚºËÐÄÉÏÅäÖöàÌõ¾²Ì¬Ä¬ÈÏ·ÓÉ£¬°ó¶¨¹Ç¸ÉÉ豸»¥Á¬Á´Â·½Ó¿ÚºÍÏÂÒ»ÌøµØÖ·£¬Í¬Ê±½«Â·ÓÉÓÅÏȼ¶/¹ÜÀí¾àÀëÉèÖÃΪ210£¬¼ÓTAG 210,ÑϽû×¢ÈëISISÖС£
»ã¾ÛBR,BRAS/SRÉ豸ÅäÖöàÌõ¾²Ì¬Ä¬ÈÏ·ÓÉ£¬°ó¶¨ºÍºËÐÄ»¥Á¬Á´Â·½Ó¿ÚºÍÏÂÒ»ÌøµØÖ·£¬Í¬Ê±½«Â·ÓÉÓÅÏȼ¶/¹ÜÀí¾àÀëÉèÖÃΪ210£¬¼ÓTAG 210,ÑϽû×¢ÈëISISÖС£
3.3.3.5 ¾²Ì¬Â·Óɱê¼ÇºÍÃèÊö ÅäÖÃ˵Ã÷£º
³ö¿Ú·ÓÉÆ÷Éϵľ²Ì¬Â·ÓÉÅäÖã¬ÔÚ·ÓÉÖØ·Ö·¢×ö±ê¼Ç£¬¸ù¾ÝÐèÒª¿ÉÒÔ¼ÓtagºÍÃèÊö¡£ÔöÇ¿¿É¶ÁÐÔ£¬·½±ã²ßÂÔʹÓú͹ÜÀí¡£
Tag 901ÓÃÓÚºÚ¶´¾²Ì¬Â·ÓÉ£» TAG 210 ÓÃÓÚ¸¡¶¯¾²Ì¬Ä¬ÈÏ·ÓÉ¡£
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ32Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
¹æ·¶ÒªÇó£º
ºÚ¶´¾²Ì¬Â·ÓÉÉèÖÃTAGֵΪ901£¬¸¡¶¯¾²Ì¬Â·ÓÉÉèÖÃTAG 210,ÆäËü¸ù¾ÝÐèÒªÉèÖÃTAGÖµ¡£
3.3.3.6 ÅäÖ÷¶Àý
#Õë¶ÔBRASÒµÎñµÄ¾²Ì¬Â·Óɵü´úÅäÖ÷¶Àý
ip route-static default-preference 1 #È«¾ÖÒ»ÌõÃüÁîÐ޸ľ²Ì¬Â·ÓɵÄĬÈÏÓÅÏȼ¶Îª1 #
ip route-static 1.1.1.1 255.255.255.255 gi1/0/0 192.168.1.2 #ÅäÖóÇÓòÍø³ö¿Ú·ÓÉÆ÷µ½BRAS Loopback0µÄ¾²Ì¬Â·ÓÉ£¬Â·ÓÉÊýºÍÁ´Â·ÊýÏàͬ #
ip route-static 172.16.0.0 255.255.0.0 1.1.1.1 #°ó¶¨BRAS IP POOLµÄÏÂÒ»ÌøIPµØÖ·ÎªBRAS Loopback0µØÖ· #
ip route-static 192.168.0.0 255.255.255.0 null0 preference 180 tag 901 #ºÚ¶´Â·ÓɼÓtag 901£¬Í¨¹ýBGP¹ã²¥¸ø¹Ç¸ÉÉ豸¡£
ip route-static 0.0.0.0 0.0.0.0 Pos2/0/0 61.177.249.229 preference 210 tag 210 #¸¡¶¯¾²Ì¬Â·ÓÉ
3.3.4 ISIS ÅäÖÃ
3.3.4.1 ¸ÅÊö
½ËÕµçÐÅÏÂÊô³ÇÓòÍøÊ¹ÓÃISISΪIGPÐÒ飬IGPÔËÐÐÔÚ³ÇÓòÍøºËÐIJãºÍÒµÎñ½ÓÈë¿ØÖÆ²ã¡£ISIS º¸ÇÍøÂçÖÐËùÓкËÐÄÉ豸ºÍ»ã¾ÛÉ豸µÄLoopback ¶Ë¿ÚºÍÁ´Â·¶Ë¿Ú£»ºËÐÄ·ÓÉÆ÷µÄÉÏÁª½Ó¿ÚºÍÉ豸µÄLoopback ¶Ë¿ÚÉèÖÃΪPassiveģʽ¡£ISIS·ÓÉÐÒéÖ»³ÐÔØÉ豸֮¼äµÄ»¥Á¬Á´Â·ºÍloopbackµØÖ·µÄÖ÷»ú·ÓÉ£¬²»³ÐÔØÓû§µÄ·ÓÉ¡£³ÇÓòÍø³ö¿Ú·ÓÉÆ÷ISIS½ø³ÌʼÖÕÏ·¢Ä¬ÈÏ·ÓÉ¡£ISISÐÒéÌṩµÄÊÇÒµÎñ½ÓÈë¿ØÖÆ²ã¼°ÆäÒÔÉÏÉ豸֮¼äµÄ¿É´ïÐÔ£¬ÎªIBGPÌṩIGP·Óɿɴ
3.3.4.2 ISIS ʵÀýÃû ÅäÖÃ˵Ã÷£º
ͬһ³ÇÓòÍøISISʵÀýÃû³Æ±£³Öͳһ£¬µ¥»ú²»ÔËÐжà¸öISISʵÀý£¬ISISʵÀýÃû³ÆÈ¡µØÊÐÃû³ÆÈ«Æ´£¬Àý£ºÑïÖݽڵãISISʵÀýÃûyangzhou¡£
ISISʵÀýÐèÓÃÊý×Ö±êʶ£¬¾ù¶¨Îª100¡£ ¹æ·¶ÒªÇó£º
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ33Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
ͬһ³ÇÓòÍøISISʵÀýÃû³Æ±£³Öͳһ£¬µ¥»ú²»ÔËÐжà¸öISISʵÀý¡£
[1]
£ºÏÖÍø»·¾³ÖУ¬´ó²¿·Ö»ªÎªÂ·ÓÉÆ÷ÔËÐÐISISµÄʵÀý±êʶ¶¼²ÉÓÃĬÈϵÄ1£¬µ±Ðèɾ³ý¶Ë¿Úisis
µÄÅäÖÃʱ£¬ÈÝÒײúÉúÎó²Ù×÷£ºundo isis £¬½á¹ûµ¼Ö¸Ą̃É豸µÄisis ½ø³Ì±»Çå³ý¡£Îª¹æ±ÜÈç´ËÎó²Ù×÷ËùÒýÆðµÄ·çÏÕ£¬isisʵÀý²ÉÓÃÊý×Ö±êʶÐè²»ÉèÖÃΪ1¡£
3.3.4.3 ISIS NET ID ÅäÖÃ˵Ã÷£º
ÅäÖÃISIS net id£¬Î¨Ò»±êʶ×ÔÖÎϵͳÖеÄһ̨ISIS·ÓÉÆ÷¡£ ¹æ·¶ÒªÇó£º
ÔËÐж¯Ì¬Â·ÓÉÐÒéµÄcontextÅäÖÃISIS net id£¬net idµØÖ·²ÉÓÃArea ID + System ID + NSELµØÖ··½Ê½¡£
ÆäÖУ¬XX.YYYY.ZZZZΪArea ID£¬ÆäÖÐXX¹Ì¶¨Îª86£¬YYYY±¨¸÷³ÇÓòÍøË½ÓÐ5λASºÅµÄºó4룬ZZZZΪ¸÷µØÊÐµç»°ÇøºÅ£¬²»×ãËÄλµÄÇ°Ãæ²¹Áã¡£Àý£ºÑγdzÇÓòÍøË½ÓÐASºÅΪ64522£¬ÇøºÅΪ0515£¬ÄÇôÑγdzÇÓòÍøISIS NET IDΪ£º86.4522.0515¡£
System IDΪ6룬¸ñʽΪAAAA.AAAA.AAAA£¬²ÉÓóÇÓòÍøÉ豸loopback0µÄIPµØÖ·£¬ÒÔ×ó¼Ó0µÄ·½Ê½½«Ã¿Ò»½Ú²¹Æë3룬ÔÙ´Ó×óÖÁÓÒÈýµÈ·ÖÍê³É¸ñʽת»»¡£±ÈÈç61.177.248.2ת»»ºóΪ0611.7724.8002¡£NSEL¹Ì¶¨Îª00¡£
3.3.4.4 ISIS·ÓÉÆ÷ÀàÐÍ ÅäÖÃ˵Ã÷£º ISISµÄ·ÓÉÆ÷ÀàÐͿɷÖΪlevel-1ºÍlevel-2Á½ÖÖ£¬level-1ÓÃÓÚ´«µÝÓòÄÚ·ÓÉ¡¢level-2Óû§´«µÝÓò¼ä·ÓÉ¡£
¹æ·¶ÒªÇó£º
ͬһ¸ö³ÇÓòÍøÔËÐÐͬһ¸öISISÐÒ飬½ËÕµçÐųÇÓòÍøÊ¹ÓÃISIS Level-1£¬¹Ø±Õ·ÓÉÆ÷ISIS Level-2¹¦ÄÜ¡£
3.3.4.5 ISIS Cost-style ÅäÖÃ˵Ã÷£º
ISISÐÒécost-style·ÖΪnarrowºÍwideÁ½ÖÖ·½Ê½£¬narrow·½Ê½ÊÇÀÏʽcostÀàÐÍ£¬costÖµÖ»ÄÜ´Ó0¡ª63£¬²»Ö§³ÖMPLS TE¡£wide·½Ê½Ê±ISIS cost¿ÉÒÔ´Ó0 ¡ª
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ34Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
16,777,215 ¡£²»Í¬cost-styleµÄISIS¶ÔµÈÌå²»Äܽ¨Á¢ÁÚ¾Ó¡£
¹æ·¶ÒªÇó£º
ÅäÖÃISIS cost-styleµÄÀàÐÍΪwide¡£
ÔËÐÐISISÐÒéµÄ¶Ë¿ÚĬÈÏ·ÓÉÆ÷ÀàÐÍΪlevel -1£¬costֵΪ100000¡£ 3.3.4.6 ISISÐÒé½Ó¿ÚÀàÐÍ ÅäÖÃ˵Ã÷£º
ÔÚʹÓÃ30λÑÚÂëµÄ¹ã²¥ÀàÐͽӿÚÏ£¬ÅäÖÃISISÍøÂçÀàÐÍΪµãµ½µã
point-to-point£¬²»·¢Ë͹㲥°ü£¬¼õÉÙLSP·ººé¡£Á´Â·Á½¶ËµÄIS-IS½Ó¿ÚµÄÍøÂçÀàÐͱØÐëÒ»Ö£¬·ñÔòË«·½²»¿ÉÒÔ½¨Á¢ÆðÁÚ¾Ó¹ØÏµ¡£
ISISÐÒéĬÈÏÒÔÌ«Íø½Ó¿ÚÀàÐÍÊǹ㲥ÀàÐÍ¡£ ¹æ·¶ÒªÇó£º
³ÇÓòÍøÄÚ»¥Á¬ÓÃPOS----±£³ÖΪPoint-To-Point²»±ä
³ÇÓòÍøÄÚ»¥ÁªÓÃGE/10GE --- Ç¿ÖÆ¸ü¸ÄΪPoint-To-Point(ÈôÉ豸²»Ö§³Ö£¬ÈçÖÐÐËÉ豸£¬ÒÀ¾É²ÉÓÃBroadcastģʽ) Loopback ---- Passive½øISISÓòÄÚ
ÆäËû¶Ë¿Ú-----ÈçÃ÷È·Ðèͨ¹ýIGP¿É´ïµÄ¶Ë¿Ú£¬ÔòÐèpassive½øISISÓòÄÚ£¬ÖîÈ磺ÉÏÁ¬¹Ç¸ÉÉ豸¶Ë¿Ú£¬ÉÏÁ¬CN2É豸¶Ë¿Ú¡£ 3.3.4.7 ISIS ¸ºÔؾùºâÌõÄ¿ ÅäÖÃ˵Ã÷£º ÅäÖÃISIS¸ºÔؾùºâÌõÄ¿£¬ÊµÏÖÁ÷Á¿µÄ¸ºÔؾùºâ¡£ ¹æ·¶ÒªÇó£º
°´Ê¡¹«Ë¾Í³Ò»¹æ·¶ÒªÇó£¬ÅäÖÃISIS¸ºÔؾùºâÊý²»ÉÙÓÚ8Ìõ¡£ 3.3.4.8 ISIS ·ÓÉÐÒéÓÅÏȼ¶ ÅäÖÃ˵Ã÷£º
¸ü¸ÄISISÐÒé·ÓÉÐÒéÓÅÏȼ¶/¹ÜÀí¾àÀë ¹æ·¶ÒªÇó£º
ͳһISIS·ÓÉÐÒéÓÅÏȼ¶/¹ÜÀí¾àÀëΪ115£¬»ªÎªÄ¬ÈÏΪ15¡£ 3.3.4.9 ISIS ÖØ·Ö²¼Â·ÓÉ
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ35Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
ÅäÖÃ˵Ã÷£º
ÅäÖý«ÆäËûÐÒéÖØ·Ö²¼µ½ISISÐÒé¡£ ¹æ·¶ÒªÇó£º
ISISÐÒé²»³ÐÔØÓû§Â·ÓÉ£¬½öΪBGPÐÒéÌṩµ×²ãIGP¿É´ï£¬ÔÔòÉϲ»½«ÆäËû·ÓÉÐÒé×¢Èë½øISIS£¬ÈçÐèÒªÔòÓÃrouter-policy¹ýÂË×¢Èë¡£
3.3.4.10 ISISÁÚ¾Ó¼ÓÃÜ ÅäÖÃ˵Ã÷£º
ÅäÖÃISISÁÚ¾Ó¼ÓÃÜ£¬¶ÔISISÁÚ¾ÓÖ®¼äµÄÐÒ鱨ÎĽøÐмÓÃܺÍУÑé¡£ ¹æ·¶ÒªÇó£º
¿¼Âǵ½³ÇÓòÍøÃæÏòÓû§µÄ¶Ë¿Ú¹Ø±ÕÁËISIS´¦Àí£¬ÇÒ½ËÕ³ÇÓòÍøÈ¡ÏûBR£¬ÊµÊ©±âƽ»¯ºó£¬³ö¿Ú·ÓÉÆ÷µÄISISÁÚ¾ÓÊý½«½Ï¶à£¬Îª¼õÉÙISISÁÚ¾Ó¼ÓÃÜÕ¼ÓÃÌ«¶àCPU×ÊÔ´£¬½¨Òé½ËÕ³ÇÓòÍø²»¿ªÆôISISÁÚ¾Ó¼ÓÃܹ¦ÄÜ¡£
3.3.4.11 ISIS½Ó¿ÚÐû¸æ ÅäÖÃ˵Ã÷£º
ÅäÖÃÐèÐû¸æµ½ISISÐÒéÖеĽӿڣ¬ÅäÖÃloopback½Ó¿ÚºÍ»¥Á¬½Ó¿ÚΪISIS½Ó¿Ú£¬½Ó¿ÚµØÖ·Â·ÓÉ×Ô¶¯·¢²¼µ½ISIS£¬Óû§½ÓÈë½Ó¿ÚÒ»Âɲ»¿ÉÅäÖÃΪISIS½Ó¿Ú¡£
¹æ·¶ÒªÇó£º
ÅäÖÃloopback½Ó¿ÚºÍÉÏÁ¬½Ó¿ÚΪISIS½Ó¿Ú£¬²ÉÓÃPASSIVEģʽ£¬½Ó¿ÚµØÖ·Â·ÓÉ×Ô¶¯·¢²¼µ½ISIS¡£Óû§½ÓÈë½Ó¿ÚÒ»Âɲ»¿ÉÅäÖÃΪISIS½Ó¿Ú¡£
3.3.4.12 ISIS costÖµ¹æ»® ÅäÖÃ˵Ã÷£º
Ö¸¶¨ÔËÐÐISIS½Ó¿ÚµÄcostÖµ£¬²»Ê¹ÓÃISIS×Ô¶¯¼ÆËãµÄ½Ó¿ÚcostÖµ¡£½¨ÒéͳһÉè¼ÆcostÉ趨¹æ·¶À´É趨Á´Â·µÄcost£¬»ùÓÚ½Ó¿ÚÊÖ¹¤Ö¸¶¨ISIS costÖµ£¬Ê¹ÓÃIGPµÄcostÀ´Òýµ¼Á÷Á¿¡£
¹æ·¶ÒªÇó£º
½Ó¿ÚĬÈÏÉèÖÃΪLevel -1 ÍøÂçÀàÐÍ£¬costֵΪ100000¡£
³ÇÓòÍøÊÕÈ¡¹úÄÚ·ÓÉ»ò¹ú¼Ê·Óɺó£¬Í¨¹ý²ã´Î»¯µÄcostÖµ½«¿ÉÄܲúÉúµÄ´©Í¸Á÷Á¿±£³ÖÔÚ³ö¿ÚÉ豸¼ä´©Í¸£¬±ÜÃâÔÚ³ÇÓòÍøÄÚ²¿ºá´©Á÷Á¿¡£
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ36Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
Ò»°ãÉ豸˫ÉÏÁ¬µÄÁ´Â·Ê¹ÓÃͬÑùµÄ´ø¿íÁ´Â·£¬ËùÒÔ°´ÍøÂç²ã´Î·ÖÅäMETRICÖµ£¬½¨ÒéISIS metricÉ趨°´ÕÕÏÂÃæ¹æ·¶Ö´ÐС£
Á´Â·¹¦ÄÜ ³ö¿Ú·ÓÉÆ÷Ö®¼äÁ´Â· »ã¾Û·ÓÉÆ÷ÖÁ³ö¿Ú·ÓÉÆ÷ SR/BRASÖÁ³ö¿Ú·ÓÉÆ÷ SR/BRASÖÁ»ã¾Û·ÓÉÆ÷ »ã¾Û·ÓÉÆ÷Ö®¼äÁ´Â· SR/BRASÖ®¼äÁ´Â· LOOPBACK PASSIVEµÄ½Ó¿Ú ±¸Óà ±£ÁôÁ´Â· ISIS costÖµÉè¼Æ 50 100 100 100 100 100 100 100 140 200
ÅäÖÃ×¢Òâϸ½Ú£º ÈçÓбØÒª£¬»¹Ðè¸ù¾ÝÁ´Â·³ÐÔØµÄÒµÎñÀàÐͽøÐÐCostÖµµÄ»®·Ö£¬ÈçÁ´Â·³ÐÔØµÄÖ÷ÓÃÒµÎñΪ¿í´øÒµÎñ£¬Í¬Ê±×÷ΪITVÒµÎñµÄ±¸ÓÃÁ´Â·£¬Ôò¸ÃÁ´Â·µÄcostֵѡȡΪ100£»ÈçÁ´Â·³ÐÔØµÄÓÃÒµÎñΪITVÒµÎñ£¬Í¬Ê±×÷Ϊ¿í´øÒµÎñµÄ±¸ÓÃÁ´Â·£¬Ôò¸ÃÁ´Â·µÄcostֵѡȡΪ140¡£ ±¸×¢£º±£ÁôÁ´Â·£¨´ý²ð³ý£©½¨ÒéSHUTDOWN½Ó¿Ú»òÈ¡Ïû½Ó¿ÚISISÐÒ飬±ÜÃâÍø¹ÜÎ󱨡£
3.3.4.13 ISIS LSP×î´óÓÐЧʱ¼ä ÅäÖÃ˵Ã÷£º ·ÓÉÆ÷Éú³ÉϵͳLSPʱ£¬»áÔÚLSPÖÐÌîд´ËLSPµÄ×î´óÓÐЧʱ¼ä¡£Èç¹û·ÓÉÆ÷һֱûÓÐÊÕµ½¸üеÄLSP£¬ÔÚ´ËLSPµÄÓÐЧʱ¼äÒѼõÉÙµ½0ºó£¬Èô»¹Î´ÊÕµ½Ë¢ÐµÄLSP£¬Ôò½«¸ÃLSPɾ³ý¡£
CRSĬÈÏΪ1200s£¬»ªÎªÄ¬ÈÏΪ1200s£¬°¢ÀÉĬÈÏΪ1200s£¬JuniperĬÈÏ1200s¡£ ¹æ·¶ÒªÇó£º
ÉèÖÃΪ65500s£¬ÓëLSPË¢ÐÂʱ¼ä±£³ÖÆ¥Åä¡£
¡¾1¡¿CRSÉèÖÃΪ65535,»áÔÚ3.8ÒÔϰ汾»á´¥·¢BUG,½¨ÒéÉèÖÃÉÔСһµãµÄÊýÖµ£¬ÖîÈ磺65500.
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ37Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
3.3.4.14 ¹Ø±ÕISIS hello ±¨ÎÄÌî³ä ÅäÖÃ˵Ã÷£º
ÔÚÁÚ½Ó¹ØÏµµÄ½¨Á¢¹ý³ÌÖУ¬IS-ISÐèÒª¼ì²éÁ´Â·Á½¶ËµÄMTU´óСÊÇ·ñÒ»Ö¡£È±Ê¡Çé¿öÏ£¬IS-ISÐÒ齫Hello±¨ÎÄÌî³äÖÁMTU´óС¡£¿ÉÒÔͨ¹ýÃüÁî¼ò»¯Hello±¨ÎĵÄÊÕ·¢²Ù×÷£¬¼õС¶ÔÍøÂç´ø¿íµÄÀË·Ñ¡£
¹æ·¶ÒªÇó£º
¹Ø±Õhello ±¨ÎÄÌî³ä£¬¼õÉÙÁ´Â·´ø¿íÕ¼Óã¬Í¬Ê±Ê¹IGP²»¼ì²é½Ó¿ÚMTU¡£ 3.3.4.15 ISIS LSP MTU ÅäÖÃ˵Ã÷£º
ISIS LSP MTU¾ö¶¨ÁËIS·¢³öLSPµÄ×î´ó³¤¶È£¬±ØÐëСÓÚÈ«ÍøËùÓÐISµÄ½Ó¿ÚCLNS MTU¡£
¹æ·¶ÒªÇó£º
LSP MTUͳһÉèÖÃΪ1497£¨Cisco¡¢»ªÎª¡¢Juniper³§¼ÒÉ豸ĬÈÏÊýÖµ£©¡£ 3.3.4.16 ISIS LSPˢмä¸ôʱ¼ä ÅäÖÃ˵Ã÷£º
ISIS·ÓÉÆ÷ÖÜÆÚµÄ·¢ËÍLSP¸øÆäËüISIS·ÓÉÆ÷£¬Ê¹Õû¸öISISÇøÓòµÄLSP±£³Öͬ²½¡£
CRSȱʡΪ900s£¬»ªÎªÈ±Ê¡Îª900s£¬°¢ÀÉȱʡΪ600s£¬JuniperȱʡΪLSP×î´óÓÐЧʱ¼ä-317 ¹æ·¶ÒªÇó£º ÉèÖÃΪ32768s£¬JuniperΪ¼ÆËãÖµ¡£¼õÉÙË¢ÐÂÕ¼ÓÃÁ´Â·´ø¿í¡£ 3.3.4.17 ISIS¶¯Ì¬Ö÷»úÃû ÅäÖÃ˵Ã÷£º
ISISµÄLSP±¨ÎÄЯ´øISIS·ÓÉÆ÷Ö÷»úÃû£¬ÆäËüISIS·ÓÉÆ÷Äܶ¯Ì¬½âÎö·ÓÉÆ÷Ãû³Æ¡£
CISCOȱʡÊÇ¿ªÆô£¬»ªÎªÈ±Ê¡Êǹرա£ ¹æ·¶ÒªÇó£º
ÅäÖÿªÆôISIS¶¯Ì¬Ö÷»úÃû¡£
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ38Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
3.3.4.18 ISIS OVERBITλ ÅäÖÃ˵Ã÷£º
ÔÚ·ÓÉÆ÷ÖØÆðʱ£¬ÉèÖÃISIS ¹ýÔØ±êʶλÖÃλ£¬Ê¹ISISÁ÷Á¿²»ÔÚ¸ÃÉ豸ºá´©¡£ ¹æ·¶ÒªÇó£º
ÅäÖÃÔÚ·ÓÉÆ÷ÖØÆôµÄ15ÃëÄÚÉèÖÃISIS OVERBITλ¡£ 3.3.4.19 ISISȱʡ·ÓÉ ÅäÖÃ˵Ã÷£º
³ÇÓòÍø³ö¿Ú·ÓÉÆ÷ÏòÕû¸öÇøÓòÇ¿ÖÆÏ·¢ISISĬÈÏ·ÓÉÒýµ¼³ÇÓòÍøÄÚÓû§µÄÉÏÐÐÁ÷Á¿£¬Í¨¹ýISIS µÄĬÈÏ·ÓÉÀ´´ïµ½³ÇÓòÍøÓû§ÉÏÐÐÁ÷Á¿µÄ¸ºÔؾùºâ¡£ ¹æ·¶ÒªÇó£º
ÅäÖÃISIS×ÜÊÇÏ·¢Ä¬ÈÏ·ÓÉ¡£Í¬Ê±¼ÓTAG 115£¬²¢Ó¦ÓòßÂÔ¹ýÂ˵ô³ýºËÐÄÍâÆäËûÉ豸·¢Ë͵ÄĬÈÏ·ÓɽøÈëIP·ÓÉ±í¡£
3.3.4.20 ISIS logÁھӱ仯ÐÅÏ¢ ÅäÖÃ˵Ã÷£º
ÅäÖÃISIS logÁھӱ仯ÐÅÏ¢£¬¼Ç¼ISISÁھӱ仯¡£ ¹æ·¶ÒªÇó£º
¸ù¾ÝÊ¡¹«Ë¾Í³Ò»¹æ·¶£¬ÅäÖÃISIS log Áھӱ仯ÐÅÏ¢¹¦ÄÜ¡£ 3.3.4.21 ÅäÖ÷¶Àý
ÖйúµçÐŽËÕ·Ö¹«Ë¾ µÚ39Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
1£©»ù±¾ÅäÖà isis 100 #ÅäÖÃISISʵÀýID
set-overload on-startup wait-for-bgp 15 #·ÓÉÆ÷ÖØÆô»òÕß³öÏÖ¹ÊÕÏʱ£¬¹ýÔØ±ê־λÔÚÅäÖõÄʱ¼äÄÚ½«±£³Ö±»ÖÃλ״̬£¬¸ù¾ÝBGPÊÕÁ²µÄ״̬£¬ÉèÖÃϵͳ±£³Ö¹ýÔØ±ê־λʱ³¤Îª15s¡£
is-name YC-833-CR.MAN.NE5000E-1 #ÅäÖö¯Ì¬Ö÷»úÃû network-entity xx.xxxx.xxxx.xxxx.00 #ÅäÖÃNET ID
log-peer-change #´ò¿ªIS-ISÁÚ½Ó״̬±ä»¯µÄÊä³ö¿ª¹Ø cost-style wide #ÅäÖýӿڿªÏúÀàÐÍΪwide
circuit-cost 100000 level-1 #È«¾ÖÏÂÅäÖÃÓÐIS-IS½Ó¿ÚµÄĬÈÏ¿ªÏúֵΪ100000,ÍøÂçÀàÐÍΪlevel-1
is-level level-1 #ÅäÖ÷ÓÉÆ÷ÀàÐÍ
maximum load-balancing 16 #ÅäÖøºÔؾùºâÊýΪ16
preference 115 #ÅäÖÃÐÒéÓÅÏȼ¶£¬Ä¬ÈÏΪ15 timer lsp-max-age 65500 #ÉèÖÃΪ65500£¬±¾»úÓÐЧ timer lsp-refresh 32768 #ÉèÖÃΪ32768£¬±¾»úÓÐЧ
timer spf 5 50 200 #·ÓɼÆËã×î´óÑÓ³Ùʱ¼äȱʡֵÊÇ5Ãë,³õ´Î·ÓɼÆËãµÄÑÓ³Ùʱ¼äΪ50ms£¬Á½´Î·ÓɼÆËãÖ®¼äµÄµÝÔöÑÓ³Ùʱ¼äΪ200ms¡£
is-snmp-traps enable #ʹÄÜIS-ISÏòÍø¹Ü·¢ËÍTrap±¨ÎĵŦÄÜ
2£©ºËÐÄISIS½ÓÊÕ·ÓɲßÂÔ
ip ip-prefix ipDefault index 10 permit 0.0.0.0 0
route-policy rpFromISIS permit node 10 if-match tag 115
route-policy rpFromISIS deny node 15 if-match ip-prefix ipDefault
route-policy rpFromISIS permit node 20
isis 100
default-route-advertise always level-1 tag 115 //ʼÖÕÏ·¢Ä¬ÈÏ£¬²¢¼Ótag 115 filter-policy route-policy rpFromISIS import //¹ýÂ˵ôÏÂÁ¬BRAS/SRÉ豸Îó·¢³öµÄĬÈϽøÈë·Óɱí
3£©ÔËÐÐISISÐÒé¶Ë¿ÚÅäÖÃ
interface ge-1/1 #ÅäÖýӿÚÐû¸æ isis enable 100 isis circuit-level level-1
isis cost 100 level-1 #ÅäÖÃcostÖµ
isis small-hello #ÓÃÀ´ÉèÖýӿڷ¢ËͲ»¼ÓÈëÌî³ä×ֶεÄСÐÍHello±¨ÎÄ control-flap
set flow-stat interval 30 undo icmp redirect send
mtu 1600 #ÉèÖÃIP MTUΪ1600 isis circuit-type p2p #ÉèÖö˿ÚÀàÐÍΪP2P
interface pos0/0/0 #ÅäÖýӿÚÐû¸æ
isis enable 100
isis circuit-level level-1 isis cost 100 level-1
isis silent #½Ó¿ÚÉèÖÃΪpassive״̬
3.3.5 BGPÅäÖÃ
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ40Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
3.3.5.1 ¸ÅÊö
EBGPÔËÐÐÔÚ³ÇÓòÍø³ö¿Ú·ÓÉÆ÷Óë163¡¢CN2¹Ç¸ÉÍøÂ·ÓÉÆ÷Ö®¼ä£¬ÊµÏÖ³ÇÓòÍøÏò¹Ç¸ÉÍø·¢²¼³ÇÓòÍøÄڵķÓÉ£¬²¢´Ó¹Ç¸ÉÍø½ÓÊÕȱʡºÍÍøÍâ·ÓÉ¡£
IBGPÔËÐÐÔÚ³ÇÓòÍøºËÐIJãºÍÒµÎñ½ÓÈë¿ØÖÆ²ã£¬³ÐÔØÓû§Â·ÓÉ¡£ 3.3.5.2 ×ÔÖÎϵͳ
½ËÕµçÐÅËùÊô³ÇÓòÍøÉϲ¼ÊðµÄBGP²ÉÓÃ˽ÓÐ×ÔÖÎϵͳºÅ£¬³ÇÓòÍøÏò163Ðû¸æµÄÍø¶ÎûÓдøcommunity£¬163É豸½«½ÓÊյijÇÓòÍøÂ·ÓÉÉèÖÃcommunity¡£¸÷³ÇÓòÍøASºÅÈçÏ£º ½ËÕÊ¡Íø¸÷³ÇÓòÍøºÍcommunityÉè¼Æ ³ÇÓòÍø/IDC ÄϾ©³ÇÓòÍø ÎÞÎý³ÇÓòÍø »´°²³ÇÓòÍø ËÞǨ³ÇÓòÍø ÑγdzÇÓòÍø Ì©ÖݳÇÓòÍø Õò½³ÇÓòÍø ÄÏͨ³ÇÓòÍø ÐìÖݳÇÓòÍø ÑïÖݳÇÓòÍø ³£ÖݳÇÓòÍø Á¬ÔƸ۳ÇÓòÍø ËÕÖݳÇÓòÍø AS±àºÅ 64660 64662 64669 64672 64522 64519 64664 64518 64668 64665 64663 64671 64513 163ÉèÖÃCommunity 4134:111,4134:3025,4134:3250,4134:64660,64660:10661 4134:111,4134:3025,4134:3250,4134:64662,64662:10661 4134:111,4134:3025,4134:3250,4134:64669,64669:10661 4134:111,4134:3025,4134:3250,4134:64672,64672:10661 4134:111,4134:3025,4134:3250,4134:64522,64522:10661 4134:111,4134:3025,4134:3250,4134:64519,64519:10661 4134:111,4134:3025,4134:3250,4134:64664,64664:10661 4134:111,4134:3025,4134:3250,4134:64518,64518:10661 4134:111,4134:3025,4134:3250,4134:64668,64668:10661 4134:111,4134:3025,4134:3250,4134:64665,64665:10661 4134:111,4134:3025,4134:3250,4134:64663,64663:10661 4134:111,4134:3025,4134:3250,4134:64671,64671:10661 4134:111,4134:3025,4134:3250,4134:64513,64513:10661 3.3.5.3 ³ÇÓòÍøBGP ²¿Êð²ßÂÔ ¹Ø±ÕBGP×Ô¶¯Â·ÓÉ»ã×ÜÌØÐÔ¡£ ¹Ø±ÕIGPÓëBGPµÄͬ²½¡£ ¿ªÆôBGP DAMPING£¬±ÜÃâ·ÓÉÒÖÖÆ¶ÔÒµÎñµÄÓ°Ïì¡£ ¹Ø±Õ bgp always-compare-med
Ðû¸æ¸ø163µÄ³ÇÓòÍøÂ·ÓÉЯ´øMEDÊôÐÔ£¬ÉèÖÃMED=0¡£ ³ÇÓòÍøÒÔORIGIN IGPµÄ·½Ê½¶ÔÍâ·¢²¼Â·ÓÉ¡£
Ã÷È·ÅäÖÃBGP router-idΪLoopback 0µØÖ·¡£
¸ù¾ÝÐèҪȷ¶¨BGP MultihopµÄTTLÖµ£¬¶Ô´ó²¿·ÖÇé¿ö£¬ÅäÖÃEBGP MultihopΪ255£¬ÒÔ¼°BGP TTL Security¼ì²â¡£
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ41Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
Ã÷È·ÅäÖÃÐÂʽcommunity¸ñʽ¡£ ¼Ç¼BGPÁھӱ仯¡£
BGP²ÉÓÃÃÜÂ뽨Á¢ÁÚ¾Ó¹ØÏµ£¨EBGPÃÜÂ룺µç»°ÇøºÅ_AS£©¡£ EBGPºÍIBGP¸ºÔؾùºâÊýÄ¿²»Ð¡ÓÚ8¡£
ÅäÖÃBGP³ö·½Ïò·ÓɹýÂË£¬Ðû¸æ¸øÊ¡ÍøÂ·Óɾ¡Á¿ºÏ²¢£¬²ÉÓÃPREFIXºÍNETWORKÐû¸æ¡£
ʹÓÃLoopbackµØÖ·Óë¹Ç¸ÉºËÐĽ¨Á¢EBGP¹ØÏµ£¬²»Ê¹Óýӿڽ¨Á¢¹ØÏµ£¬ÆôÓÃEBGP TTL¼ì²â¡£
BGP TIMER ²ÎÊýkeepaliveºÍHoldtime¶¨Ê±Æ÷ͳһΪ60sÓë180s¡£
3.3.5.4 BGP router-idÅäÖà ÅäÖÃ˵Ã÷£º
ÅäÖÃBGP router-id£¬Î¨Ò»±êʶ×ÔÖÎϵͳÖеÄһ̨BGP·ÓÉÆ÷¡£ ¹æ·¶ÒªÇó£º
ÅäÖÃBGP router-idµØÖ·Îªloopback0½Ó¿ÚµÄIPµØÖ·£¬²»Ê¹ÓÃBGPÐÒé×Ô¶¯Ñ¡¾ÙµÄrouter-id¡£
3.3.5.5 BGP logÁھӱ仯ÐÅÏ¢ ÅäÖÃ˵Ã÷£º
ÅäÖÃBGP logÁھӱ仯ÐÅÏ¢£¬¼Ç¼BGPÁھӱ仯¡£ ¹æ·¶ÒªÇó£º
ÅäÖÃBGP log Áھӱ仯ÐÅÏ¢¡£ ÅäÖù淶£º
NE5000EĬÈÏÖ§³ÖBGP logÁھӱ仯ÐÅÏ¢£¬²»ÐèÌØ±ðÅäÖᣠÅäÖÃ×¢Òâϸ½Ú£º ÎÞ¡£
3.3.5.6 ¹Ø±ÕBGPͬ²½ºÍ×Ô¶¯»ã×Ü ÅäÖÃ˵Ã÷£º
ÅäÖÃBGPÐÒéµÄͬ²½ºÍ×Ô¶¯»ã×ܹ¦ÄÜ¡£ ¹æ·¶ÒªÇó£º
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ42Ò³
½ËÕµçÐųÇÓòÍøCR·ÓÉÆ÷(»ªÎªNE5000E) ÅäÖù淶
ÔÚ³ÇÓòÍøËùÓÐÔËÐÐBGPÐÒéµÄÉ豸ÉϹرÕBGPͬ²½ºÍ×Ô¶¯»ã×ܹ¦ÄÜ¡£ 3.3.5.7 BGPÁÚ¾ÓMD5¼ÓÃÜ ÅäÖÃ˵Ã÷£º
ÅäÖÃBGPÁÚ¾Ó¼ÓÃÜ¡£ ¹æ·¶ÒªÇó£º
BGPÁÚ¾Ó¾ù²ÉÓÃMD5¼ÓÃÜ£¬ÃÜԿΪ£ºµç»°ÇøºÅ_ASºÅ£¬ÓëCN2µÄÃÜÔ¿°´CN2¹æ·¶Ö´ÐС£
3.3.5.8 BGPʱ¼ä²ÎÊý ÅäÖÃ˵Ã÷£º
ÅäÖÃBGPÐÒéµÄKeepaliveºÍHoldtime¶¨Ê±Æ÷£¬Ò»¸öBGP¶ÔµÈÌåÿ¸ôKeepaliveʱ¼äÏòÁÚ¾Ó·¢ËÍÒ»¸ö´æ»î±¨ÎÄ£¬Èç¹ûHoldtimeʱ¼äÄÚûÓбص½ÁÚ¾Ó·¢Ë͵Ĵæ»î±¨ÎÄ£¬¾ÍÈÏΪÕâ¸öÁÚ¾ÓÒÑËÀÍö£¬´Ó¶ø½áÊø»á»°¡£ ¹æ·¶ÒªÇó£º
µ÷½ÚBGP keepaliveʱ¼äΪ60s,holdtimeʱ¼äΪ180s¡£ ÅäÖù淶£º
NE5000E BGP keepaliveʱ¼ä£¬holdtimeʱ¼äĬÈÏ·Ö±ðΪ60sºÍ180s£¬ÏÖÓÐÅäÖÃÎÞÐèÐ޸ġ£
ÅäÖÃ×¢Òâϸ½Ú£º ÎÞ¡£ 3.3.5.9 BGP community ÊôÐԹ滮 ÅäÖÃ˵Ã÷£º
ÅäÖÃBGPЯ´øµÄcommunityÊôÐÔ£¬ÓÃÓÚ·ÓÉ¿ØÖÆ¡£163É豸ÒѶԽÓÊյijÇÓòÍøÂ·ÓÉÉèÖÃcommunity¡£
¹æ·¶ÒªÇó£º
163É豸ÒѶԽÓÊյijÇÓòÍøÂ·ÓÉÉèÖÃcommunity£¬³ö¿Ú·ÓÉÆ÷²»ÓÃÉèÖᣠ3.3.5.10 163 BGP ·ÓɲßÂÔ ÅäÖÃ˵Ã÷£º
ÅäÖóÇÓòÍøÓë163Ö®¼äµÄBGP ·ÓɲßÂÔ
ÖйúµçÐŽËÕ·Ö¹«Ë¾
µÚ43Ò³