网络调优,部署内网备份冗余和负载分担---实验
2023-12-22 15:36:38
目录
网络调优,部署内网备份冗余和负载分担---实验
拓扑

需求
- 主机获取IP地址,访问WEB服务器,WEB服务器网关在SW5上
- SW5作为VLAN10,VLAN20的主网关,作为VLAN30,VLAN40的备网关;
- SW6作为VLAN30,VLAN40的主网关,作为VLAN10,VLAN20的备网关;
- SW5上的vlanif 地址为192.168.xx.251,虚拟网关为192.168.xx.254
- SW6上的vlanif 地址为192.168.xx.252,虚拟网关为192.168.xx.254
- SW5作为VLAN10,VLAN20,vlan88的主根,作为VLAN30,VLAN40,vlan66的备根;
- SW6作为VLAN30,VLAN40,vlan66的主根,作为VLAN10,VLAN20,vlan88的备根;
配置步骤:
- SW5和SW6中创建vlan88
- 所有的接入层交换机和SW5的互联的接口配置trunk
- SW5配置vlanif的管理地址,XX.251
- 配置VRRP主备网关,配置WEB服务器网关
- 配置SW5为DHCP中继
- 配置MSTP
配置命令:
第一步:SW5的基础配置:
[SW5]vlan batch 10 20 30 40 66 88
[SW5]port-group group-member g0/0/1 to g0/0/4 g0/0/20
[SW5-port-group]port link-type trunk
[SW5-port-group]port trunk allow-pass vlan all
第二步: 配置SW5的dhcp中继
[SW5]dhcp enable
[SW5]int vlan 10
[SW5-Vlanif10]ip add 192.168.10.251 24
[SW5-Vlanif10]dhcp select relay
[SW5-Vlanif10]dhcp relay server-ip 192.168.66.1
[SW5-Vlanif10]int vlan 20
[SW5-Vlanif20]ip add 192.168.20.251 24
[SW5-Vlanif20]dhcp select relay
[SW5-Vlanif20]dhcp relay server-ip 192.168.66.1
[SW5-Vlanif20]int vlan 30
[SW5-Vlanif30]ip add 192.168.30.251 24
[SW5-Vlanif30]dhcp select relay
[SW5-Vlanif30]dhcp relay server-ip 192.168.66.1
[SW5-Vlanif30]int vlan 40
[SW5-Vlanif40]ip add 192.168.40.251 24
[SW5-Vlanif40]dhcp select relay
[SW5-Vlanif40]dhcp relay server-ip 192.168.66.1
[SW5-Vlanif40]quit
[SW5]int vlan 66
[SW5-Vlanif66]ip address 192.168.66.253 24
[SW5-Vlanif66]int vlan 88
[SW5-Vlanif88]ip add 192.168.88.254 24
第三步:所有的交换机中都配置MSTP
1) 在所有的交换机中复制粘贴,不要手写命令,不要手写命令
stp region-configuration
region-name ntd2304
instance 1 vlan 10 20
instance 2 vlan 30 40
active region-configuration
2)在SW5中配置主根和备根
把SW5做成实例1(vlan10和vlan20)的主根
把SW5做成实例2(vlan30和vlan40)的备根
把SW5做成实例0(其余所有vlan)的主根
[SW5]stp instance 1 priority 4096
[SW5]stp instance 2 priority 8192
[SW5]stp instance 0 priority 4096
3)在SW6中配置主根和备根
把SW6做成实例1(vlan10和vlan20)的备根
把SW6做成实例2(vlan30和vlan40)的主根
把SW6做成实例0(其余所有vlan)的备根
[SW6]stp instance 1 priority 8192
[SW6]stp instance 2 priority 4096
[SW6]stp instance 0 priority 8192
第四步:配置VVRP
1)SW5配置VRRP-成为vlan10和vlan20的master
SW5配置VRRP-成为vlan30和vlan40的backup
[SW5-Vlanif10]vrrp vrid 10 virtual-ip 192.168.10.254
[SW5-Vlanif10]vrrp vrid 10 priority 160
[SW5-Vlanif10]int vlan 20
[SW5-Vlanif20]vrrp vrid 20 virtual-ip 192.168.20.254
[SW5-Vlanif20]vrrp vrid 20 priority 160
[SW5-Vlanif20]int vlan 30
[SW5-Vlanif30]vrrp vrid 30 virtual-ip 192.168.30.254
[SW5-Vlanif30]int vlan 40
[SW5-Vlanif40]vrrp vrid 40 virtual-ip 192.168.40.254
备注:如果写错:删除
[SW5-Vlanif20]int vlan 30
[SW5-Vlanif30]undo vrrp vird 40
2)SW6配置VRRP-成为vlan30和vlan40的master
SW6配置VRRP-成为vlan10和vlan20的backup
[SW6]int vlan 10
[SW6-Vlanif10]vrrp vrid 10 virtual-ip 192.168.10.254
[SW6-Vlanif10]int vlan 20
[SW6-Vlanif20]vrrp vrid 20 virtual-ip 192.168.20.254
[SW6-Vlanif20]int vlan 30
[SW6-Vlanif30]vrrp vrid 30 virtual-ip 192.168.30.254
[SW6-Vlanif30]vrrp vrid 30 priority 160
[SW6-Vlanif30]int vlan 40
[SW6-Vlanif40]vrrp vrid 40 virtual-ip 192.168.40.254
[SW6-Vlanif40]vrrp vrid 40 priority 160
备注:在SW6中配置vlan88的管理IP地址
[SW6]vlan 88
[SW6-vlan88]quit
[SW6]int vlan 88
[SW6-Vlanif88]ip address 192.168.88.6 24
备注:
配置完MSTP和VRRP后, 主机可以正常获取IP地址吗?
如果不能,为什么???
如何排错?
请思考:
2个小坑,辛苦各位填满
为什么呢?
因为SW5 和DHCP不能互通,三层有直连路由,但是不能互通,那么我们去查二层
1)抓包-分析
2)display port vlan 查看端口的状态和允许通过的vlan
通过抓包分析,发现SW5的5条链路,都无法发包,
使用display port vlan 发现 SW5的5条链路都没有做trunk ,都没有允许vlan通过
解决方案:给SW1/SW2/SW3/SW4的g0/0/11接口配置trunk ,允许vlan通过
给SW6的g0/0/20 接口配置trunk ,允许vlan通过
[SW6]int g0/0/20
[SW6-G0/0/20]port link-type trunk
[SW6-G0/0/20]port trunk allow-pass vlan all
[SW4]int g0/0/11
[SW4-G0/0/11]port link-type trunk
[SW4-G0/0/11]port trunk allow-pass vlan all
[SW3]int g0/0/11
[SW3-G0/0/11]port link-type trunk
[SW3-G0/0/11]port trunk allow-pass vlan all
[SW2]int g0/0/11
[SW2-G0/0/11]port link-type trunk
[SW2-G0/0/11]port trunk allow-pass vlan all
[SW1]int g0/0/11
[SW1-G0/0/11]port link-type trunk
[SW1-G0/0/11]port trunk allow-pass vlan all
备注:PC可以访问server服务器吗?
PC 能ping 通192.168.88.1
1)确认sw5 配置了vlanif88的IP地址
[SW5-Vlanif66]int vlan 88
[SW5-Vlanif88]ip add 192.168.88.254 24
2)确认sw6创建了vlan88 ,并配置了vlanif 88的IP地址
[SW6]vlan 88
[SW6-vlan88]quit
[SW6]int vlan 88
[SW6-Vlanif88]ip address 192.168.88.6 24
3)确认SW5的g0/0/8口,改为了access 并且加入了vlan88
[SW5]int g0/0/8
[SW5-GigabitEthernet0/0/8]port lin
[SW5-GigabitEthernet0/0/8]port link-type access
[SW5-GigabitEthernet0/0/8]port default vlan 88
文章来源:https://blog.csdn.net/weixin_72194028/article/details/135152248
本文来自互联网用户投稿,该文观点仅代表作者本人,不代表本站立场。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。 如若内容造成侵权/违法违规/事实不符,请联系我的编程经验分享网邮箱:veading@qq.com进行投诉反馈,一经查实,立即删除!
本文来自互联网用户投稿,该文观点仅代表作者本人,不代表本站立场。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。 如若内容造成侵权/违法违规/事实不符,请联系我的编程经验分享网邮箱:veading@qq.com进行投诉反馈,一经查实,立即删除!