所有配置均基于HCL配置。

基于PBR,不改变现有拓扑的方式进行防火墙旁挂的引流。

拓扑图

描述

1、MSR36-20_1的Loopback0 口为1.1.1.1 用来模拟Internet。

2、整个网络采用OSPF动态路由协议来实现互联互通。

3、MSR36-20_5的Loopback 0 口5.5.5.5用来模拟局域内网。

4、S5820V2-54QS-GE_2为核心交换机。

5、两台F1060设备用来当做防火墙,一主一备。

6、防火墙旁挂网络,不中断现有的网络路由。

问题

1、在交换机新增两个vlan 100 200。

2、需要注意vlan 100 用来当做防火墙的Trust,vlan 200当做防火墙的Untrust。

3、交换机需要关闭快速转发功能。

4、所有设备开启ip unreachables  enable、ip ttl-expires  enable方便tracert查看现象。

配置

MSR36-20_5

接口IP配置 略

ospf 1 router-id 5.5.5.5
 area 0.0.0.0
  network 5.5.5.5 0.0.0.0
  network 192.168.10.10 0.0.0.0

ip unreachables enable
ip ttl-expires enable

S5820V2-54QS-GE_2

ospf 1 router-id 2.2.2.2
 area 0.0.0.0
  network 2.2.2.2 0.0.0.0
  network 192.168.10.254 0.0.0.0
  network 192.168.100.254 0.0.0.0
 area 0.0.0.1
  network 12.1.1.2 0.0.0.0
  network 192.168.200.254 0.0.0.0
#
 ip unreachables enable
 ip ttl-expires enable

 undo ip fast-forwarding load-sharing

policy-based-route from_10 permit node 10
 if-match acl 2000
 apply next-hop 192.168.100.253
#
policy-based-route from_1 permit node 10
 if-match acl 2001
 apply next-hop 192.168.200.253
#
interface Bridge-Aggregation1
 port link-type trunk
 port trunk permit vlan 1 100 200
#
interface Bridge-Aggregation2
 port link-type trunk
 port trunk permit vlan 1 100 200
 

interface LoopBack0
 description ospf-id
 ip address 2.2.2.2 255.255.255.255
#
interface Vlan-interface10
 description Trust
 ip address 192.168.10.254 255.255.255.0
 ip policy-based-route from_10
#
interface Vlan-interface12
 description Internet
 ip address 12.1.1.2 255.255.255.0
 ip policy-based-route from_1
#
interface Vlan-interface100
 ip address 192.168.100.254 255.255.255.0
#
interface Vlan-interface200
 ip address 192.168.200.254 255.255.255.0
 

interface GigabitEthernet1/0/1
 port link-mode bridge
 port access vlan 12
 combo enable fiber
#
interface GigabitEthernet1/0/2
 port link-mode bridge
 port access vlan 10
 combo enable fiber
#
interface GigabitEthernet1/0/3
 port link-mode bridge
 port link-type trunk
 port trunk permit vlan 1 100 200
 combo enable fiber
 port link-aggregation group 1
#
interface GigabitEthernet1/0/4
 port link-mode bridge
 port link-type trunk
 port trunk permit vlan 1 100 200
 combo enable fiber
 port link-aggregation group 1
#
interface GigabitEthernet1/0/5
 port link-mode bridge
 port link-type trunk
 port trunk permit vlan 1 100 200
 combo enable fiber
 port link-aggregation group 2
#
interface GigabitEthernet1/0/6
 port link-mode bridge
 port link-type trunk
 port trunk permit vlan 1 100 200
 combo enable fiber
 port link-aggregation group 2
#
acl basic 2000
 rule 0 permit source 192.168.10.0 0.0.0.255
 rule 5 permit source 5.5.5.5 0
#
acl basic 2001
 rule 0 permit source 1.1.1.1 0

MSR36-20_1

ospf 1 router-id 11.11.11.11
 import-route direct route-policy DIRECT
 area 0.0.0.1
  network 11.11.11.11 0.0.0.0
  network 12.1.1.1 0.0.0.0
#
 ip unreachables enable
 ip ttl-expires enable
#
route-policy DIRECT permit node 10
 if-match ip address prefix-list DIRICT
#
 ip prefix-list DIRICT index 10 permit 1.1.1.1 32

F1060

主备配置差不多,配置了remote-backup group后备用会同步配置(除接口配置、路由等)。

ospf 1 router-id 6.6.6.6
 area 0.0.0.0
  network 6.6.6.6 0.0.0.0
  network 192.168.100.251 0.0.0.0
 area 0.0.0.1
  network 192.168.200.251 0.0.0.0
#
 ip unreachables enable
 ip ttl-expires enable
#
interface Bridge-Aggregation1
 port link-type trunk
 port trunk permit vlan 1 100 200
#
interface NULL0
#
interface LoopBack0
 ip address 6.6.6.6 255.255.255.255
#
interface Vlan-interface100
 ip address 192.168.100.251 255.255.255.0
 vrrp vrid 1 virtual-ip 192.168.100.253 active
 vrrp vrid 1 priority 110
 vrrp vrid 1 preempt-mode delay 30
#
interface Vlan-interface200
 ip address 192.168.200.251 255.255.255.0
 vrrp vrid 1 virtual-ip 192.168.200.253 active
 vrrp vrid 1 priority 110
 vrrp vrid 1 preempt-mode delay 30
#
interface GigabitEthernet1/0/1
 port link-mode route
 combo enable copper
 ip address 192.168.0.1 255.255.255.0
#
interface GigabitEthernet1/0/23
 port link-mode route
 combo enable copper
 ip address 10.254.254.1 255.255.255.252
#
interface GigabitEthernet1/0/3
 port link-mode bridge
 port link-type trunk
 port trunk permit vlan 1 100 200
 combo enable copper
 port link-aggregation group 1
#
interface GigabitEthernet1/0/4
 port link-mode bridge
 port link-type trunk
 port trunk permit vlan 1 100 200
 combo enable copper
 port link-aggregation group 1
#
security-zone name Trust
 import interface Vlan-interface100
#
security-zone name DMZ
 import interface GigabitEthernet1/0/23
#
security-zone name Untrust
 import interface Vlan-interface200
#
security-policy ip
 rule 0 name OSPF
  action pass
  source-zone trust
  source-zone untrust
  source-zone Local
  destination-zone trust
  destination-zone untrust
  destination-zone Local
  service vrrp
  service ospf
  service ping
 rule 1 name Internet
  action pass
  source-zone Trust
  destination-zone Untrust
 rule 2 name Untrust_Trust
  action pass
  source-zone Untrust
  destination-zone Trust
  service ping
#
remote-backup group
 data-channel interface GigabitEthernet1/0/23
 configuration sync-check interval 1
 delay-time 1
 adjust-cost ospf enable absolute 65535
 local-ip 10.254.254.1
 remote-ip 10.254.254.2
 device-role primary


测试

MSR36-20_1

MSR36-20_5

Logo

腾讯云面向开发者汇聚海量精品云计算使用和开发经验,营造开放的云计算技术生态圈。

更多推荐