8.1.1 参考配置
错误配置 第8章 H3CTE故障排除综合案例一 ip address 10.2.1.9 255.255.255.252 # interface Ethernet5/1 port link-mode route ospf authentication-mode md5 1 plain h3c ip address 69.1.1.1 255.255.255.252 # interface LoopBack0 ip address 10.10.10.1 255.255.255.255 # interface GigabitEthernet0/0 port link-mode route ip address 10.1.1.9 255.255.255.252 # interface GigabitEthernet0/1 port link-mode route ospf authentication-mode md5 1 plain h3c ip address 10.2.1.1 255.255.255.252 # interface Tunnel0 ip address 10.2.1.13 255.255.255.252 source 69.1.1.1 destination 69.1.1.2 keepalive 10 3 ipsec policy 1 # bgp 65131 router-id 10.10.10.1 import-route ospf 10 undo synchronization - 2 - ip address 10.2.1.9 255.255.255.252 # interface Ethernet5/1 port link-mode route ip address 69.1.1.1 255.255.255.252 ipsec policy 1 # interface LoopBack0 ip address 10.10.10.1 255.255.255.255 # interface GigabitEthernet0/0 port link-mode route ip address 10.1.1.9 255.255.255.252 # interface GigabitEthernet0/1 port link-mode route ospf authentication-mode md5 1 plain h3c ip address 10.2.1.1 255.255.255.252 # interface Tunnel0 ip address 10.2.1.13 255.255.255.252 ospf authentication-mode md5 1 plain h3c source 69.1.1.1 destination 69.1.1.2 keepalive 10 3 # bgp 65131 router-id 10.10.10.1 import-route ospf 10 undo synchronization 第8章 H3CTE故障排除综合案例一 group in internal peer in connect-interface LoopBack0 peer 10.10.10.3 group in peer 10.10.10.4 group in peer 10.10.10.2 group in # ospf 1 area 0.0.0.0 authentication-mode md5 network 10.2.1.0 0.0.0.3 network 10.2.1.8 0.0.0.3 network 10.2.1.12 0.0.0.3 network 10.10.10.1 0.0.0.0 # ospf 10 area 0.0.0.0 network 10.1.1.8 0.0.0.3 group in internal peer in reflect-client peer in connect-interface LoopBack0 peer 10.10.10.3 group in peer 10.10.10.4 group in peer 10.10.10.2 group in # ospf 1 area 0.0.0.0 authentication-mode md5 network 10.2.1.0 0.0.0.3 network 10.2.1.8 0.0.0.3 network 10.2.1.12 0.0.0.3 network 10.10.10.1 0.0.0.0 # ospf 10 default-route-advertise always area 0.0.0.0 network 10.1.1.8 0.0.0.3 # # local-user rt2 password simple h3c service-type ppp # interface Ethernet5/0 port link-mode route ip address 10.3.1.6 255.255.255.252 # interface Serial6/0 link-protocol ppp ppp authentication-mode chap ppp chap user rt2 ppp mp Mp-group 0 # interface Serial6/1 link-protocol ppp ppp authentication-mode chap ppp chap user rt2 ppp mp Mp-group 0 # interface Mp-group0 ip address 10.2.1.5 255.255.255.252 ospf authentication-mode md5 1 plain h3c # interface LoopBack0 ip address 10.10.10.2 255.255.255.255 # interface GigabitEthernet0/0 port link-mode route ip address 10.1.1.5 255.255.255.252 - 4 - # local-user rt2 password simple h3c service-type ppp # interface Ethernet5/0 port link-mode route ip address 10.3.1.6 255.255.255.252 # interface Serial6/0 link-protocol ppp ppp authentication-mode chap ppp chap user rt3 ppp mp Mp-group 0 # interface Serial6/1 link-protocol ppp ppp authentication-mode chap ppp chap user rt3 ppp mp Mp-group 0 # interface Mp-group0 ip address 10.2.1.5 255.255.255.252 ospf authentication-mode md5 1 plain h3c ospf cost 1 # interface LoopBack0 ip address 10.10.10.2 255.255.255.255 # interface GigabitEthernet0/0 port link-mode route ip address 10.1.1.5 255.255.255.252 第8章 H3CTE故障排除综合案例一 # interface GigabitEthernet0/1 port link-mode route ip address 10.2.1.2 255.255.255.252 ospf authentication-mode md5 1 plain h3c # bgp 65131 router-id 10.10.10.2 import-route ospf 10 undo synchronization peer 10.3.1.5 as-number 65132 peer 10.3.1.5 route-policy 1 export group in internal peer in next-hop-local peer in connect-interface LoopBack0 peer 10.10.10.3 group in peer 10.10.10.1 group in # ospf 1 area 0.0.0.0 authentication-mode md5 network 10.2.1.0 0.0.0.3 network 10.10.10.2 0.0.0.0 network 10.2.1.4 0.0.0.3 # ospf 10 area 0.0.0.0 network 10.1.1.4 0.0.0.3 # route-policy 1 permit node 10 - 5 - # interface GigabitEthernet0/1 port link-mode route ip address 10.2.1.2 255.255.255.252 ospf authentication-mode md5 1 plain h3c # bgp 65131 router-id 10.10.10.2 import-route ospf 10 undo synchronization peer 10.3.1.5 as-number 65132 peer 10.3.1.5 route-policy 1 export group in internal peer in next-hop-local peer in reflect-client peer in connect-interface LoopBack0 peer 10.10.10.3 group in peer 10.10.10.1 group in # ospf 1 area 0.0.0.0 authentication-mode md5 network 10.2.1.0 0.0.0.3 network 10.10.10.2 0.0.0.0 network 10.2.1.4 0.0.0.3 # ospf 10 default-route-advertise always area 0.0.0.0 network 10.1.1.4 0.0.0.3 # route-policy 1 permit node 10 第8章 H3CTE故障排除综合案例一 if-match acl 2001 # if-match acl 2001 # # interface LoopBack0 ip address 10.10.10.3 255.255.255.255 # interface LoopBack10 ip address 172.1.2.254 255.255.255.255 # interface LoopBack20 ip address 192.1.2.254 255.255.255.255 # interface GigabitEthernet0/0 port link-mode route ip address 10.2.1.10 255.255.255.252 ospf authentication-mode md5 1 plain h3c # bgp 65131 network 172.1.2.254 255.255.255.255 network 192.1.2.254 255.255.255.255 undo synchronization group in internal peer in connect-interface LoopBack0 peer 10.10.10.1 group in peer 10.10.10.2 group in peer 10.10.10.2 route-policy 10 import # ospf 1 area 0.0.0.0 authentication-mode md5 network 10.10.10.3 0.0.0.0 network 10.2.1.4 0.0.0.0 network 10.2.1.8 0.0.0.0 # - 7 - # interface LoopBack0 ip address 10.10.10.3 255.255.255.255 # interface LoopBack10 ip address 172.1.2.254 255.255.255.255 # interface LoopBack20 ip address 192.1.2.254 255.255.255.255 # interface GigabitEthernet0/0 port link-mode route ip address 10.2.1.10 255.255.255.252 ospf authentication-mode md5 1 plain h3c # bgp 65131 network 172.1.2.254 255.255.255.255 network 192.1.2.254 255.255.255.255 undo synchronization group in internal peer in connect-interface LoopBack0 peer 10.10.10.1 group in peer 10.10.10.2 group in peer 10.10.10.2 route-policy 10 import # ospf 1 area 0.0.0.0 authentication-mode md5 network 10.10.10.3 0.0.0.0 network 10.2.1.8 0.0.0.3 network 10.2.1.4 0.0.0.3 # 第8章 H3CTE故障排除综合案例一 route-policy 10 permit node 10 if-match ip-prefix 10 apply local-preference 200 # ip ip-prefix 10 index 10 permit 192.1.1.0 24 # route-policy 10 permit node 10 if-match ip-prefix 10 apply local-preference 200 route-policy 10 permit node 20 apply local-preference 50 # ip ip-prefix 10 index 10 permit 172.1.1.0 24 # proposal 1 # interface LoopBack0 ip address 10.10.10.4 255.255.255.255 # interface LoopBack10 ip address 172.1.3.254 255.255.255.255 # interface LoopBack20 ip address 192.1.3.254 255.255.255.255 # interface GigabitEthernet0/0 port link-mode route ospf authentication-mode md5 1 plain h3c ip address 69.1.1.2 255.255.255.252 # interface Tunnel0 ip address 10.2.1.14 255.255.255.252 source 69.1.1.2 destination 69.1.1.1 keepalive 10 3 ipsec policy 1 # bgp 65131 router-id 10.10.10.1 network 172.1.3.254 255.255.255.255 network 192.1.3.254 255.255.255.255 undo synchronization group in internal peer in connect-interface LoopBack0 - 9 - proposal 1 # interface LoopBack0 ip address 10.10.10.4 255.255.255.255 # interface LoopBack10 ip address 172.1.3.254 255.255.255.255 # interface LoopBack20 ip address 192.1.3.254 255.255.255.255 # interface GigabitEthernet0/0 port link-mode route ip address 69.1.1.2 255.255.255.252 ipsec policy 1 # interface Tunnel0 ip address 10.2.1.14 255.255.255.252 source 69.1.1.2 destination 69.1.1.1 keepalive 10 3 ospf authentication-mode md5 1 plain h3c # bgp 65131 router-id 10.10.10.4 network 172.1.3.254 255.255.255.255 network 192.1.3.254 255.255.255.255 undo synchronization group in internal peer in connect-interface LoopBack0 第8章 H3CTE故障排除综合案例一 peer 10.10.10.1 group in # ospf 1 area 0.0.0.0 network 10.10.10.4 0.0.0.0 network 10.2.1.12 0.0.0.3 # peer 10.10.10.1 group in # ospf 1 area 0.0.0.0 network 10.10.10.4 0.0.0.0 network 10.2.1.12 0.0.0.3 # interface GigabitEthernet0/1 port link-mode route ip address 10.3.1.5 255.255.255.252 # bgp 65132 router-id 20.20.20.1 network 172.2.1.254 255.255.255.255 network 192.2.1.254 255.255.255.255 undo synchronization peer 10.3.1.2 as-number 65131 peer 10.3.1.6 as-number 65131 # interface GigabitEthernet0/1 port link-mode route ip address 10.3.1.5 255.255.255.252 # bgp 65132 router-id 20.20.20.1 network 172.2.1.254 255.255.255.255 network 192.2.1.254 255.255.255.255 undo synchronization peer 10.3.1.2 as-number 65131 peer 10.3.1.6 as-number 65131 # # interface Vlan-interface10 ip address 10.1.1.10 255.255.255.252 # interface Vlan-interface101 ip address 172.1.1.1 255.255.255.0 vrrp vrid 1 virtual-ip 172.1.1.254 # interface Vlan-interface102 ip address 192.1.1.1 255.255.255.0 vrrp vrid 2 virtual-ip 192.1.1.254 # interface Ethernet1/0/1 port link-mode bridge port access vlan 10 # interface Ethernet1/0/2 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102 # interface Ethernet1/0/24 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102 # ospf 10 area 0.0.0.0 - 12 - # interface Vlan-interface10 ip address 10.1.1.10 255.255.255.252 # interface Vlan-interface101 ip address 172.1.1.1 255.255.255.0 vrrp vrid 1 virtual-ip 172.1.1.254 # interface Vlan-interface102 ip address 192.1.1.1 255.255.255.0 vrrp vrid 2 virtual-ip 192.1.1.254 vrrp vrid 2 priority 105 vrrp vrid 2 track interface Vlan-interface10 # interface Ethernet1/0/1 port link-mode bridge port access vlan 10 # interface Ethernet1/0/2 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102 # interface Ethernet1/0/24 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102 # ospf 10 silent-interface vlan-interface101 silent-interface vlan-interface102 area 0.0.0.0 第8章 H3CTE故障排除综合案例一 network 10.1.1.8 0.0.0.3 network 172.1.1.0 0.0.0.255 network 192.1.1.0 0.0.0.255 network 10.1.1.8 0.0.0.3 network 172.1.1.0 0.0.0.255 network 192.1.1.0 0.0.0.255 # interface Vlan-interface20 ip address 10.3.1.2 255.255.255.252 # interface Vlan-interface101 ip address 172.1.1.1 255.255.255.0 vrrp vrid 1 virtual-ip 172.1.1.254 # interface Vlan-interface102 ip address 192.1.1.2 255.255.255.0 vrrp vrid 2 virtual-ip 192.1.1.254 # interface Ethernet1/0/1 port link-mode bridge port access vlan 10 # interface Ethernet1/0/2 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102 # interface Ethernet1/0/3 port link-mode bridge port access vlan 20 # interface Ethernet1/0/24 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102 # bgp 65131 - 14 - interface Vlan-interface20 ip address 10.3.1.2 255.255.255.252 # interface Vlan-interface101 ip address 172.1.1.2 255.255.255.0 vrrp vrid 1 virtual-ip 172.1.1.254 vrrp vrid 1 priority 105 vrrp vrid 1 track interface Vlan-interface10 # interface Vlan-interface102 ip address 192.1.1.2 255.255.255.0 vrrp vrid 2 virtual-ip 192.1.1.254 # interface Ethernet1/0/1 port link-mode bridge port access vlan 10 # interface Ethernet1/0/2 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102 # interface Ethernet1/0/3 port link-mode bridge port access vlan 20 # interface Ethernet1/0/24 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102 # bgp 65131 第8章 H3CTE故障排除综合案例一 network 172.1.1.0 255.255.255.0 undo synchronization peer 10.3.1.1 as-number 65132 # ospf 10 area 0.0.0.0 network 10.1.1.4 0.0.0.3 network 172.1.1.0 0.0.0.255 network 192.1.1.0 0.0.0.255 # route-policy 1 permit node 10 if-match acl 3000 network 172.1.1.0 255.255.255.0 undo synchronization peer 10.3.1.1 as-number 65132 peer 10.3.1.1 route-policy 1 import # ospf 10 silent-interface vlan-interface101 silent-interface vlan-interface102 area 0.0.0.0 network 10.1.1.4 0.0.0.3 network 172.1.1.0 0.0.0.255 network 192.1.1.0 0.0.0.255 # route-policy 1 permit node 10 if-match acl 3000 # # interface Vlan-interface102 ip address 192.1.1.100 255.255.255.0 # interface Ethernet1/0/1 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102 # interface Ethernet1/0/2 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102 # interface Ethernet1/0/11 port link-mode bridge port access vlan 101 # interface Ethernet1/0/12 port link-mode bridge port access vlan 102 # ip route-static 172.0.0.0 255.0.0.0 172.1.1.254 ip route-static 192.0.0.0 255.0.0.0 # interface Vlan-interface102 ip address 192.1.1.100 255.255.255.0 # interface Ethernet1/0/1 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102 # interface Ethernet1/0/2 port link-mode bridge port link-type trunk port trunk permit vlan 1 101 to 102 # interface Ethernet1/0/11 port link-mode bridge port access vlan 101 # interface Ethernet1/0/12 port link-mode bridge port access vlan 102 # ip route-static 172.0.0.0 255.0.0.0 172.1.1.254 ip route-static 192.0.0.0 255.0.0.0 192.1.1.254 # 192.1.1.254 # - 16 - 第8章 H3CTE故障排除综合案例一 - 17 - 因篇幅问题不能全部显示,请点此查看更多更全内容