网络调优,部署内网备份冗余和负载分担---实验

发布时间:2023年12月22日

目录

网络调优,部署内网备份冗余和负载分担---实验

拓扑

需求

配置步骤:

配置命令:


网络调优,部署内网备份冗余和负载分担---实验

拓扑

需求

  • 主机获取IP地址,访问WEB服务器,WEB服务器网关在SW5上
  • SW5作为VLAN10,VLAN20的主网关,作为VLAN30,VLAN40的备网关;
  • SW6作为VLAN30,VLAN40的主网关,作为VLAN10,VLAN20的备网关;
  • SW5上的vlanif 地址为192.168.xx.251,虚拟网关为192.168.xx.254
  • SW6上的vlanif 地址为192.168.xx.252,虚拟网关为192.168.xx.254
  • SW5作为VLAN10,VLAN20,vlan88的主根,作为VLAN30,VLAN40,vlan66的备根;
  • SW6作为VLAN30,VLAN40,vlan66的主根,作为VLAN10,VLAN20,vlan88的备根;

配置步骤:

  • SW5和SW6中创建vlan88
  • 所有的接入层交换机和SW5的互联的接口配置trunk
  • SW5配置vlanif的管理地址,XX.251
  • 配置VRRP主备网关,配置WEB服务器网关
  • 配置SW5为DHCP中继
  • 配置MSTP

配置命令:

 第一步:SW5的基础配置: 
[SW5]vlan batch 10 20 30 40 66 88
[SW5]port-group group-member g0/0/1 to g0/0/4 g0/0/20
[SW5-port-group]port link-type trunk
[SW5-port-group]port trunk allow-pass vlan all


 第二步: 配置SW5的dhcp中继 
[SW5]dhcp enable 
[SW5]int vlan 10
[SW5-Vlanif10]ip add 192.168.10.251 24
[SW5-Vlanif10]dhcp select relay 
[SW5-Vlanif10]dhcp relay server-ip 192.168.66.1

[SW5-Vlanif10]int vlan 20
[SW5-Vlanif20]ip add 192.168.20.251 24
[SW5-Vlanif20]dhcp select relay
[SW5-Vlanif20]dhcp relay server-ip 192.168.66.1

[SW5-Vlanif20]int vlan 30
[SW5-Vlanif30]ip add 192.168.30.251 24
[SW5-Vlanif30]dhcp select relay
[SW5-Vlanif30]dhcp relay server-ip 192.168.66.1

[SW5-Vlanif30]int vlan 40
[SW5-Vlanif40]ip add 192.168.40.251 24
[SW5-Vlanif40]dhcp select relay
[SW5-Vlanif40]dhcp relay server-ip 192.168.66.1
[SW5-Vlanif40]quit

[SW5]int vlan 66
[SW5-Vlanif66]ip address 192.168.66.253 24

[SW5-Vlanif66]int vlan 88
[SW5-Vlanif88]ip add 192.168.88.254 24


 第三步:所有的交换机中都配置MSTP 
 1) 在所有的交换机中复制粘贴,不要手写命令,不要手写命令 
stp region-configuration
  region-name ntd2304
  instance 1 vlan 10 20
  instance 2 vlan 30 40
  active region-configuration

 2)在SW5中配置主根和备根 
把SW5做成实例1(vlan10和vlan20)的主根
把SW5做成实例2(vlan30和vlan40)的备根
把SW5做成实例0(其余所有vlan)的主根

[SW5]stp instance 1  priority 4096
[SW5]stp instance 2  priority 8192
[SW5]stp instance 0  priority 4096

 3)在SW6中配置主根和备根 
把SW6做成实例1(vlan10和vlan20)的备根
把SW6做成实例2(vlan30和vlan40)的主根
把SW6做成实例0(其余所有vlan)的备根

[SW6]stp instance 1 priority 8192
[SW6]stp instance 2 priority 4096  
[SW6]stp instance 0 priority 8192

 第四步:配置VVRP 

 1)SW5配置VRRP-成为vlan10和vlan20的master 
   SW5配置VRRP-成为vlan30和vlan40的backup

[SW5-Vlanif10]vrrp vrid 10 virtual-ip 192.168.10.254 
[SW5-Vlanif10]vrrp vrid 10 priority 160

[SW5-Vlanif10]int vlan 20
[SW5-Vlanif20]vrrp vrid 20 virtual-ip 192.168.20.254
[SW5-Vlanif20]vrrp vrid 20 priority 160

[SW5-Vlanif20]int vlan 30
[SW5-Vlanif30]vrrp vrid 30 virtual-ip 192.168.30.254

[SW5-Vlanif30]int vlan 40
[SW5-Vlanif40]vrrp vrid 40 virtual-ip 192.168.40.254


 备注:如果写错:删除
[SW5-Vlanif20]int vlan 30
[SW5-Vlanif30]undo  vrrp vird 40 

 2)SW6配置VRRP-成为vlan30和vlan40的master
   SW6配置VRRP-成为vlan10和vlan20的backup 

[SW6]int vlan 10
[SW6-Vlanif10]vrrp vrid 10 virtual-ip 192.168.10.254

[SW6-Vlanif10]int vlan 20
[SW6-Vlanif20]vrrp vrid 20 virtual-ip 192.168.20.254

[SW6-Vlanif20]int vlan 30
[SW6-Vlanif30]vrrp vrid 30 virtual-ip 192.168.30.254
[SW6-Vlanif30]vrrp vrid 30 priority 160

[SW6-Vlanif30]int vlan 40
[SW6-Vlanif40]vrrp vrid 40 virtual-ip 192.168.40.254
[SW6-Vlanif40]vrrp vrid 40 priority 160

备注:在SW6中配置vlan88的管理IP地址
[SW6]vlan 88
[SW6-vlan88]quit
[SW6]int vlan 88
[SW6-Vlanif88]ip address 192.168.88.6 24

 
 备注:
配置完MSTP和VRRP后, 主机可以正常获取IP地址吗?
如果不能,为什么???
如何排错?
请思考:
 2个小坑,辛苦各位填满

为什么呢? 
因为SW5 和DHCP不能互通,三层有直连路由,但是不能互通,那么我们去查二层
1)抓包-分析
2)display  port vlan   查看端口的状态和允许通过的vlan

通过抓包分析,发现SW5的5条链路,都无法发包,
使用display  port vlan 发现 SW5的5条链路都没有做trunk ,都没有允许vlan通过


解决方案:给SW1/SW2/SW3/SW4的g0/0/11接口配置trunk ,允许vlan通过
        给SW6的g0/0/20 接口配置trunk ,允许vlan通过

[SW6]int g0/0/20
[SW6-G0/0/20]port link-type trunk
[SW6-G0/0/20]port trunk allow-pass vlan all

[SW4]int g0/0/11
[SW4-G0/0/11]port link-type trunk
[SW4-G0/0/11]port trunk allow-pass vlan all


[SW3]int g0/0/11
[SW3-G0/0/11]port link-type trunk
[SW3-G0/0/11]port trunk allow-pass vlan all


[SW2]int g0/0/11
[SW2-G0/0/11]port link-type trunk
[SW2-G0/0/11]port trunk allow-pass vlan all


[SW1]int g0/0/11
[SW1-G0/0/11]port link-type trunk
[SW1-G0/0/11]port trunk allow-pass vlan all


备注:PC可以访问server服务器吗?

PC  能ping  通192.168.88.1


1)确认sw5 配置了vlanif88的IP地址
[SW5-Vlanif66]int vlan 88
[SW5-Vlanif88]ip add 192.168.88.254 24


2)确认sw6创建了vlan88 ,并配置了vlanif 88的IP地址
[SW6]vlan 88
[SW6-vlan88]quit
[SW6]int vlan 88
[SW6-Vlanif88]ip address 192.168.88.6 24

3)确认SW5的g0/0/8口,改为了access 并且加入了vlan88
[SW5]int g0/0/8
[SW5-GigabitEthernet0/0/8]port lin  
[SW5-GigabitEthernet0/0/8]port link-type access
[SW5-GigabitEthernet0/0/8]port default vlan 88
文章来源:https://blog.csdn.net/weixin_72194028/article/details/135152248
本文来自互联网用户投稿,该文观点仅代表作者本人,不代表本站立场。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。