×¢²á | µÇ¼ Íü¼ÇÃÜÂ룿 51ctoÊ×Ò³ | ²©¿Í | ÂÛ̳ | ÕÐÆ¸
ÈȵãÎÄÕ ×ÓÓò²¿ÊðExchange·þÎñÆ÷Ïê..
¡¡°ïÖú

ÍøÂçÉ豸Ö÷±¸ÅäÖÃϵÁÐ3:»ªÎª·À»ðǽ(·ÓÉģʽ£©


2008-04-18 19:57:00
¡¡±êÇ©£ºÍøÂç ·À»ðǽ¡¡¡¡¡¡[ÍÆË͵½¼¼ÊõȦ]

×Ô´ÓÍÆ¼öÖ÷±¸ÅäÖÃϵÁÐÒÔÀ´£¬Ðí¶àÍøÓÑÒ»ÆðÓëÎÒ¹µÍ¨ÅäÖõķ½·¨¡£ÕâÁ½ÌìÖÕÓÚÓÐʱ¼äÁË£¬¾ö¶¨¼ÌÐøÍÆ³ö»ªÎªµÄ¡£¹²·ÖÁ½²¿·Ö£¬Â·ÓÉģʽÓë͸Ã÷ģʽ£¡  
Ë«»úÈȱ¸£¬Ëùν˫»úÈȱ¸ÆäʵÊÇË«»ú״̬±¸·Ý£¬µ±Á½Ì¨·À»ðǽ£¬ÔÚÈ·¶¨Ö÷´Ó·À»ðǽºó£¬ÓÉÖ÷·À»ðǽ½øÐÐÒµÎñµÄת·¢£¬¶ø´Ó·À»ðǽ´¦ÓÚ¼à¿Ø×´Ì¬£¬Í¬Ê±Ö÷·À»ðǽ»á¶¨Ê±Ïò´Ó·À»ðǽ·¢ËÍ״̬ÐÅÏ¢ºÍÐèÒª±¸·ÝµÄÐÅÏ¢£¬µ±Ö÷·À»ðǽ³öÏÖ¹ÊÕϺ󣬴ӷÀ»ðǽ»á¼°Ê±½ÓÌæÖ÷·À»ðǽÉϵÄÒµÎñÔËÐС£×´Ì¬±¸·Ý×îÖ÷ÒªµÄÓŵ㣬ÊÇ¿ÉÒÔ±£»¤µ±Ç°ÒµÎñ²»»áÖжÏ.
ʵÏÖË«»úÈȱ¸µÄ»ù±¾²½Ö裺
£¨1£©ÔÚ½Ó¿ÚÉÏÅäÖÃVRRP£¨ÐéÄâ·ÓÉÆ÷ÈßÓàЭÒ飩±¸·Ý×飬À´·¢ÏÖ·À»ðǽµÄ¹ÊÕÏÇé¿ö£»
£¨2£©½«VRRP±¸·Ý×é¼ÓÈëµ½VGMP£¨ VRRP×é¹ÜÀíЭÒ飩ÖУ¬ÒÔʵÏÖ¶ÔVRRP¹ÜÀí×éµÄͳһ¹ÜÀí£»
£¨3£©Ê¹ÄÜHRP£¨»ªÎªÈßÓàЭÒ飩£¬ÊµÏÖË«»úÇé¿öϵÄÐÅÏ¢±¸·Ý¡£
 
 
 
 
Éè¼ÆË¼Â·£º
1¡¢Æäʵ¾ÍÊǸö¿Ú×ÖÐÍÍøÂ磬Ö÷±¸É豸¼äÆðTRUNK£¬ ½»»»»úÓë·À»ðǽ»¥ÁªÎªaccess¿Ú£¬
2¡¢½»»»»úÓë·À»ðǽ»¥ÎªVRRP£¬AºÍB½»»»¸¡¶¯IP192.168.0.3£¬·À»ðǽ¸¡¶¯IPΪ192.168.0.6
CºÍD½»»»»ú¸¡¶¯IP192.168.1.3£¬·À»ðǽ¸¡¶¯IPΪ192.168.1.6
3¡¢Á½¸ö·À»ðǽ¼äͨ¹ýÒ»¸öÍø¿Ú×÷Ð¾Ìø£¬HRP
4¡¢ÉÏÃæºÍÏÂÃæµÄÁ½×é½»»»»úÅäÖ÷½·¨Ò»Ñù¡£±¾ÎÄÖ»ÁгöÉÏÃæµÄ¡£¡£
 
 
 
ÅäÖ㺽»»»»ú£¬´Ë´¦¾Í²»ÅäÖÃTRUNKºÍACCESS¿ÚµÄ·½·¨ÁË¡£
Èý²ãA
interface Vlan-interface803
description To_Eudemon500A
ip address 192.168.0.1 255.255.255.248
vrrp vrid 4 virtual-ip 192.168.0.3
vrrp vrid 4 priority 120
Èý²ãB
interface Vlan-interface803
description To_Eudemon500B
ip address 192.168.0.2 255.255.255.248
vrrp vrid 4 virtual-ip 192.168.0.3
 
 
·À»ðǽ£º
1,eudemon 500AÅäÖãº
sysname FW-E500-A

super password level 3 ciper huawei                
                       
                                                 
                         
web-manager enable                                 
                          
web-manager security enable  

acl number 3000                                    
                           
description permit-all                             
                          
rule permit ip  
                                                   
                 
firewall zone trust
set priority 85
add int g1/0/0
 
firewall zone untrust
set priority 5
add int g1/0/1
 
firewall zone hrp
set priority 30
add int g4/0/1

int g1/0/0
de to_switch_A
ip address 192.168.0.4 255.255.255.248
vrrp vrid 10 virtual-ip 192.168.0.6
vrrp vrid 10 pri 120
int g1/0/1
de to_switch_C
ip address 192.168.1.4 255.255.255.248
vrrp vrid 15 virtual-ip 192.168.1.6
vrrp vrid 15 pri 120
int g4/0/1
de HA_to_E500-B
ip address 192.168.3.1 255.255.255.0
vrrp vrid 20 virtual-ip 192.168.1.3
vrrp vrid 20 pri 120
vrrp group 1
add interface ethernet4/0/1 vrrp vrid 30 data
transfer-only
add interface ethernet1/0/0 vrrp vrid 10 data
add interface ethernet1/0/1 vrrp vrid 20 data
vrrp-group pri 105
vrrp-group preempt
vrrp-group enable

hrp enable
hrp interface g4/0/1

fire intzone trust local
pack 3000 in
pack 3000 out
fire intzone untrust local
pack 3000 in
pack 3000 out
fire intzone trust untrust
 
aaa                                                
                           
local-user huawei password simple huawei           
                          
local-user huawei service-type web telnet ssh
local-user huawei level 0                          
                                                   
               
 

                                                   

user-interface vty 0 4                             
                                                   
                                     
authentication-mode aaa                            
                          
user privilege level 0 
 
 
 
2¡¢eudemon 500BÅäÖÃ
 
sysname FW-E500-B

super password level 3 ciper huawei                      
                 
                                                         
                   
web-manager enable                                       
                    
web-manager security enable  

acl number 3000                                          
                     
description permit-all                                   
                    
rule permit ip  
                                                         
           
firewall zone trust
set priority 85
add int g1/0/0
 
firewall zone untrust
set priority 5
add int g1/0/1
 
firewall zone hrp
set priority 30
add int g4/0/1

int g1/0/0
de to_switch-B
ip address 192.168.0.5 255.255.255.248
vrrp vrid 10 virtual-ip 192.168.0.6
int g1/0/1
de to_switCh-D
ip address 192.168.1.5 255.255.255.248
vrrp vrid 15 virtual-ip 192.168.1.6
int g4/0/1
de HA_to_FW-E500-B
ip address 192.168.3.2 255.255.255.0
vrrp vrid 20 virtual-ip 192.168.3.3
vrrp group 1
add interface ethernet4/0/1 vrrp vrid 30 data transfer-
only
add interface ethernet1/0/0 vrrp vrid 10 data
add interface ethernet1/0/1 vrrp vrid 20 data
vrrp-group preempt
vrrp-group enable

hrp enable
hrp interface g4/0/1

fire intzone trust local
pack 3000 in
pack 3000 out
fire intzone untrust local
pack 3000 in
pack 3000 out
fire intzone trust untrust
pack 3002 in
pack 3001 out

aaa                                                      
                     
local-user huawei password simple huawei                 
                    
local-user huawei service-type web telnet ssh
local-user huawei level 0                                
                                                         
   

                                                    
user-interface vty 0 4                                   
                                                         
                         
authentication-mode aaa                                  
                    
user privilege level 0 
 
 
 
 
 
 
1.    Ë«»úÈȱ¸µÄ×¢Òâµã
£¨1£©¶ÔÓÚË«»úÈȱ¸Ä¿Ç°Ö»Ö§³ÖÁ½Ì¨ÉèÖýøÐб¸·Ý£¬²»Ö§³Ö¶ą̀É豸½øÐб¸·Ý¡£µ«¶ÔÓÚֻʹÓÃVRRPµÄ×éÍø¿ÉÒÔÖ§³Ö¶ą̀É豸½øÐÐÈßÓ౸·Ý£»
 
£¨2£©ÓÉÓÚË«»úÈȱ¸ÖоßÓб¸·Ý»úÖÆ¿ÉÒÔ±¸·Ý¶¯Ì¬ÐÅÏ¢ºÍÃüÁÒò´ËÒªÇó½øÐÐË«»úÈȱ¸µÄÁ½Ì¨É豸°å¿¨µÄλÖã¬ÒÔ¼°½Ó¿Ú¿¨µÄÀàÐͶ¼ÒªÇóÏàͬ£¬·ñÔò»á³öÏÖÖ÷·À»ðǽ±¸·Ý¹ýÈ¥µÄÐÅÏ¢£¬Óë´Ó·À»ðǽ¸ù±¾¾ÍÎÞ·¨½øÐдîÅäʹÓã¬Èç³öÏÖÖ÷±¸×´Ì¬Çл»¾Í»áµ¼ÖÂÒµÎñ³öÎÊÌâ¡£
 
£¨3£©½øÐÐË«»úÈȱ¸µÄÁ½Ì¨·À»ðǽÖеÄÅäÖÃÎļþ×îºÃΪ³õʼÅäÖûò±£Ö¤Á½Ì¨É豸ÅäÖÃÏàͬ£¬ÒÔÃâÓÉÓÚÏÈǰµÄÅäÖöøµ¼ÖÂÒµÎñÎÊÌâ¡£
 
±¾Îijö×Ô ¡°Ð¡ÏÀÌÆÔÚ·É¡± ²©¿Í£¬http://xiaoxia.blog.51cto.com/23357/6




    ÎÄÕÂÆÀÂÛ
 
 

·¢±íÆÀÂÛ

êÇ   ³Æ£º
ÑéÖ¤Â룺 ¡¡µã»÷ͼƬ¿ÉË¢ÐÂÑéÖ¤Âë¡¡¡¡²©¿Í¹ý2¼¶£¬ÎÞÐèÌîдÑéÖ¤Âë
ÄÚ   ÈÝ£º