2026.8.6双击热备旁挂组网实验

发布时间:2026/8/9 2:18:08
2026.8.6双击热备旁挂组网实验 LSW3 VLAN配置 [sw3]vlan batch 2 3 [sw3]interface GigabitEthernet 0/0/3 [sw3-GigabitEthernet0/0/3]port link-type trunk [sw3-GigabitEthernet0/0/3]port trunk allow-pass vlan 2 3 [sw3]interface GigabitEthernet 0/0/4 [sw3-GigabitEthernet0/0/4]port link-type trunk [sw3-GigabitEthernet0/0/4]port trunk allow-pass vlan 2 3 STP配置 [sw3]stp region-configuration [sw3-mst-region]region-name aa [sw3-mst-region]instance 1 vlan 2 [sw3-mst-region]instance 2 vlan 3 [sw3-mst-region]active region-configuration [sw3]stp instance 1 root primary [sw3]stp instance 2 root secondary VRRP配置 [sw3]interface Vlanif 2 [sw3-Vlanif2]ip address 192.168.2.1 24 [sw3-Vlanif2]vrrp vrid 1 virtual-ip 192.168.2.254 [sw3-Vlanif2]vrrp vrid 1 priority 120 [sw3-Vlanif2]vrrp vrid 1 preempt-mode timer delay 20 [sw3-Vlanif2]vrrp vrid 1 track interface GigabitEthernet 0/0/1 reduced 15 [sw3-Vlanif2]vrrp vrid 1 track interface GigabitEthernet 0/0/2 reduced 15 [sw3]interface Vlanif 3 [sw3-Vlanif3]ip address 192.168.3.1 24 [sw3-Vlanif3]vrrp vrid 1 virtual-ip 192.168.3.254LSW4 VLAN配置 [sw4]vlan batch 2 3 [sw4-GigabitEthernet0/0/3]port link-type trunk [sw4-GigabitEthernet0/0/3]port trunk allow-pass vlan 2 3 [sw4]interface GigabitEthernet 0/0/4 [sw4-GigabitEthernet0/0/4]port link-type trunk [sw4-GigabitEthernet0/0/4]port trunk allow-pass vlan 2 3 STP配置 [sw4]stp region-configuration [sw4-mst-region]region-name aa [sw4-mst-region]instance 1 vlan 2 [sw4-mst-region]instance 2 vlan 3 [sw4-mst-region]active region-configuration [sw4]stp instance 1 root secondary [sw4]stp instance 2 root primary VRRP配置 [sw4]interface Vlanif 2 [sw4-Vlanif2]ip address 192.168.2.2 24 [sw4-Vlanif2]vrrp vrid 1 virtual-ip 192.168.2.254 [sw4]interface Vlanif 3 [sw4-Vlanif3]ip address 192.168.3.2 24 [sw4-Vlanif3]vrrp vrid 1 virtual-ip 192.168.3.254 [sw4-Vlanif3]vrrp vrid 1 priority 120 [sw4-Vlanif3]vrrp vrid 1 preempt-mode timer delay 20 [sw4-Vlanif3]vrrp vrid 1 track interface GigabitEthernet 0/0/1 reduced 15 [sw4-Vlanif3]vrrp vrid 1 track interface GigabitEthernet 0/0/2 reduced 15LSW5 VLAN配置 [sw5]vlan batch 2 3 [sw5]interface GigabitEthernet 0/0/3 [sw5-GigabitEthernet0/0/3]port link-type access [sw5-GigabitEthernet0/0/3]port default vlan 2 [sw5]interface GigabitEthernet 0/0/4 [sw5-GigabitEthernet0/0/4]port link-type access [sw5-GigabitEthernet0/0/4]port default vlan 3 [sw5]interface GigabitEthernet 0/0/1 [sw5-GigabitEthernet0/0/1]port link-type trunk [sw5-GigabitEthernet0/0/1]port trunk allow-pass vlan 2 3 [sw5]interface GigabitEthernet 0/0/2 [sw5-GigabitEthernet0/0/2]port link-type trunk [sw5-GigabitEthernet0/0/2]port trunk allow-pass vlan 2 3 STP配置 [sw5]stp region-configuration [sw5-mst-region]region-name aa [sw5-mst-region]instance 1 vlan 2 [sw5-mst-region]instance 2 vlan 3 [sw5-mst-region]active region-configurationLSW3 VLAN配置 [sw3]vlan batch 103 203 [sw3]interface GigabitEthernet 0/0/1 [sw3-GigabitEthernet0/0/1]port link-type access [sw3-GigabitEthernet0/0/1]port default vlan 103 [sw3-GigabitEthernet0/0/1]undo stp enable [sw3]interface GigabitEthernet 0/0/2 [sw3-GigabitEthernet0/0/2]port link-type access [sw3-GigabitEthernet0/0/2]port default vlan 203 [sw3-GigabitEthernet0/0/2]undo stp enable VRRP配置 [sw3]interface Vlanif 103 [sw3-Vlanif103]ip address 10.10.3.3 24 [sw3]interface Vlanif 203 [sw3-Vlanif203]ip address 10.20.3.3 24 OSPF配置 [sw3]ospf 1 router-id 3.3.3.3 [sw3-ospf-1]area 0 [sw3-ospf-1-area-0.0.0.0]network 10.10.3.3 0.0.0.0 [sw3-ospf-1-area-0.0.0.0]network 10.20.3.3 0.0.0.0LSW4 VLAN配置 [sw4]vlan batch 104 204 [sw4]interface GigabitEthernet 0/0/1 [sw4-GigabitEthernet0/0/1]port link-type access [sw4-GigabitEthernet0/0/1]port default vlan 204 [sw4-GigabitEthernet0/0/1]undo stp enable [sw4]interface GigabitEthernet 0/0/2 [sw4-GigabitEthernet0/0/2]port link-type access [sw4-GigabitEthernet0/0/2]port default vlan 104 [sw4-GigabitEthernet0/0/2]undo stp enable VRRP配置 [sw4]interface Vlanif 104 [sw4-Vlanif104]ip address 10.10.4.4 24 [sw4]interface Vlanif 204 [sw4-Vlanif204]ip address 10.20.4.4 24 OSPF配置 [sw4]ospf 1 router-id 4.4.4.4 [sw4-ospf-1]area 0 [sw4-ospf-1-area-0.0.0.0]network 10.10.4.4 0.0.0.0 [sw4-ospf-1-area-0.0.0.0]network 10.20.4.4 0.0.0.0LSW1 VRF标签 [sw1]ip vpn-instance VRF [sw1-vpn-instance-VRF]route-distinguisher 100:1 [sw1-vpn-instance-VRF-af-ipv4]vpn-target 100:1 both VLAN配置 [sw1]vlan batch 102 103 104 [sw1]interface GigabitEthernet 0/0/5 [sw1-GigabitEthernet0/0/5]port link-type access [sw1-GigabitEthernet0/0/5]port default vlan 103 [sw1-GigabitEthernet0/0/5]undo stp enable [sw1]interface GigabitEthernet 0/0/6 [sw1-GigabitEthernet0/0/6]port link-type access [sw1-GigabitEthernet0/0/6]port default vlan 104 [sw1-GigabitEthernet0/0/6]undo stp enable [sw1]interface GigabitEthernet 0/0/4 [sw1-GigabitEthernet0/0/4]port link-type trunk [sw1-GigabitEthernet0/0/4]port trunk allow-pass vlan 102 [sw1-GigabitEthernet0/0/4]undo stp enable [sw1-GigabitEthernet0/0/4]undo port trunk allow-pass vlan 1 VRRP配置 [sw1]interface Vlanif 102 [sw1-Vlanif102]ip binding vpn-instance VRF [sw1-Vlanif102]ip address 10.10.2.1 24 [sw1]interface Vlanif 103 [sw1-Vlanif103]ip binding vpn-instance VRF [sw1-Vlanif103]ip address 10.10.3.1 24 [sw1]interface Vlanif 104 [sw1-Vlanif104]ip binding vpn-instance VRF [sw1-Vlanif104]ip address 10.10.4.1 24 OSPF配置 [sw1]ospf 1 router-id 1.1.1.1 vpn-instance VRF [sw1-ospf-1]area 0 [sw1-ospf-1-area-0.0.0.0]network 10.10.2.1 0.0.0.0 [sw1-ospf-1-area-0.0.0.0]network 10.10.3.1 0.0.0.0 [sw1-ospf-1-area-0.0.0.0]network 10.10.4.1 0.0.0.0LSW2 VRF标签 [sw2]ip vpn-instance VRF [sw2-vpn-instance-VRF]route-distinguisher 100:1 [sw2-vpn-instance-VRF-af-ipv4]vpn-target 100:1 both VLAN配置 [sw2]vlan batch 102 203 204 [sw2]interface GigabitEthernet 0/0/5 [sw2-GigabitEthernet0/0/5]port link-type access [sw2-GigabitEthernet0/0/5]port default vlan 204 [sw2-GigabitEthernet0/0/5]undo stp enable [sw2]interface GigabitEthernet 0/0/6 [sw2-GigabitEthernet0/0/6]port link-type access [sw2-GigabitEthernet0/0/6]port default vlan 203 [sw2-GigabitEthernet0/0/6]undo stp enable [sw2]interface GigabitEthernet 0/0/4 [sw2-GigabitEthernet0/0/4]port link-type trunk [sw2-GigabitEthernet0/0/4]port trunk allow-pass vlan 102 [sw2-GigabitEthernet0/0/4]undo stp enable [sw2-GigabitEthernet0/0/4]undo port trunk allow-pass vlan 1 VRRP配置 [sw2]interface Vlanif 102 [sw2-Vlanif102]ip binding vpn-instance VRF [sw2-Vlanif102]ip address 10.10.2.2 24 [sw2]interface Vlanif 203 [sw2-Vlanif203]ip binding vpn-instance VRF [sw2-Vlanif203]ip address 10.20.3.2 24 [sw2]interface Vlanif 204 [sw2-Vlanif204]ip binding vpn-instance VRF [sw2-Vlanif204]ip address 10.20.4.2 24 OSPF配置 [sw2]ospf 1 router-id 2.2.2.2 vpn-instance VRF [sw2-ospf-1]area 0 [sw2-ospf-1-area-0.0.0.0]network 10.10.2.2 0.0.0.0 [sw2-ospf-1-area-0.0.0.0]network 10.10.3.2 0.0.0.0 [sw2-ospf-1-area-0.0.0.0]network 10.10.4.2 0.0.0.0修改开销值 [sw3]interface Vlanif 203 [sw3-Vlanif203]ospf cost 5 [sw4]interface Vlanif 104 [sw4-Vlanif104]ospf cost 5 [sw3]ip ip-prefix aa permit 192.168.3.0 24 [sw3]ip ip-prefix bb permit 192.168.2.0 24 [sw3]route-policy aa permit node 10 [sw3-route-policy]apply cost 5 [sw3-route-policy]if-match ip-prefix aa [sw3]route-policy aa permit node 20 [sw3-route-policy]if-match ip-prefix bb [sw4]ip ip-prefix aa permit 192.168.2.0 24 [sw4]ip ip-prefix bb permit 192.168.3.0 24 [sw4]route-policy aa permit node 10 [sw4-route-policy]if-match ip-prefix aa [sw4-route-policy]apply cost 5 [sw4]route-policy aa permit node 20 [sw4-route-policy]if-match ip-prefix bb [sw4]ospf 1 [sw4-ospf-1]import-route direct route-policy aa[sw1]vlan batch 401 402 [sw1]interface GigabitEthernet 0/0/3 [sw1-GigabitEthernet0/0/3]port link-type trunk [sw1-GigabitEthernet0/0/3]port trunk allow-pass vlan 401 402 [sw1]interface GigabitEthernet 0/0/4 [sw1-GigabitEthernet0/0/4]port link-type trunk [sw1-GigabitEthernet0/0/4]port trunk allow-pass vlan 401 402 [sw1]interface Vlanif 401 [sw1-Vlanif401]ip binding vpn-instance VRF [sw1-Vlanif401]ip address 10.40.1.1 24 [sw1-Vlanif401]vrrp vrid 1 virtual-ip 10.40.1.100 [sw1-Vlanif401]vrrp vrid 1 priority 120 [sw1-Vlanif401]vrrp vrid 1 preempt-mode timer delay 60 [sw1-Vlanif401]vrrp vrid 1 track interface GigabitEthernet 0/0/3 reduced 30 [sw1]interface Vlanif 402 [sw1-Vlanif402]ip binding vpn-instance VRF [sw1-Vlanif402]ip address 10.40.2.1 24 [sw1-Vlanif402]vrrp vrid 2 virtual-ip 10.40.2.100[sw2]vlan batch 401 402 [sw2]interface GigabitEthernet 0/0/3 [sw2-GigabitEthernet0/0/3]port link-type trunk [sw2-GigabitEthernet0/0/3]port trunk allow-pass vlan 401 402 [sw2]interface GigabitEthernet 0/0/4 [sw2-GigabitEthernet0/0/4]port link-type trunk [sw2-GigabitEthernet0/0/4]port trunk allow-pass vlan 401 402 [sw2]interface Vlanif 401 [sw2-Vlanif401]ip binding vpn-instance VRF [sw2-Vlanif401]ip address 10.40.1.2 24 [sw2-Vlanif401]vrrp vrid 1 virtual-ip 10.40.1.100 [sw2]interface Vlanif 402 [sw2-Vlanif402]ip binding vpn-instance VRF [sw2-Vlanif402]ip address 10.40.2.2 24 [sw2-Vlanif402]vrrp vrid 2 priority 120 [sw2-Vlanif402]vrrp vrid 2 preempt-mode timer delay 60 [sw2-Vlanif402]vrrp vrid 2 track interface GigabitEthernet 0/0/3 reduced 30[FW1]vlan batch 401 to 404 [FW1]interface GigabitEthernet 1/0/0 [FW1-GigabitEthernet1/0/0]ip address 10.10.10.1 30 [FW1]interface GigabitEthernet 1/0/2.401 [FW1-GigabitEthernet1/0/2.401]ip address 10.40.1.10 24 [FW1-GigabitEthernet1/0/2.401]vlan-type dot1q 401 [FW1]interface GigabitEthernet 1/0/2.402 [FW1-GigabitEthernet1/0/2.402]ip address 10.40.2.10 24 [FW1-GigabitEthernet1/0/2.402]vlan-type dot1q 402 [FW1]interface GigabitEthernet 1/0/3.403 [FW1-GigabitEthernet1/0/3.403]ip address 10.40.3.10 24 [FW1-GigabitEthernet1/0/3.403]vlan-type dot1q 403 [FW1]interface GigabitEthernet 1/0/3.404 [FW1-GigabitEthernet1/0/3.404]ip address 10.40.4.10 24 [FW1-GigabitEthernet1/0/3.404]vlan-type dot1q 404 [FW1]firewall zone trust [FW1-zone-trust]add interface GigabitEthernet 1/0/2.401 [FW1-zone-trust]add interface GigabitEthernet 1/0/2.402 [FW1]firewall zone untrust [FW1-zone-untrust]add interface GigabitEthernet 1/0/3.403 [FW1-zone-untrust]add interface GigabitEthernet 1/0/3.404 [FW1]firewall zone dmz [FW1-zone-dmz]add interface GigabitEthernet 1/0/0 [FW1]interface GigabitEthernet 1/0/2.401 [FW1-GigabitEthernet1/0/2.401]vrrp vrid 5 virtual-ip 10.40.1.200 active [FW1]interface GigabitEthernet 1/0/2.402 [FW1-GigabitEthernet1/0/2.402]vrrp vrid 6 virtual-ip 10.40.2.200 standby [FW1]interface GigabitEthernet 1/0/3.403 [FW1-GigabitEthernet1/0/3.403]vrrp vrid 7 virtual-ip 10.40.3.200 active [FW1]interface GigabitEthernet 1/0/3.404 [FW1-GigabitEthernet1/0/3.404]vrrp vrid 8 virtual-ip 10.40.4.200 standby [FW1]hrp mirror session enable [FW1]hrp interface GigabitEthernet 1/0/0 remote 10.10.10.2 [FW1]hrp enable HRP_S[FW1]ip route-static 0.0.0.0 0 10.40.3.100 HRP_S[FW1]ip route-static 0.0.0.0 0 10.40.4.100 preference 70 HRP_M[FW1]ip route-static 192.168.0.0 16 10.40.1.100 HRP_M[FW1]ip route-static 192.168.0.0 16 10.40.2.100 preference 70[FW2]vlan batch 401 to 404 [FW2]interface GigabitEthernet 1/0/0 [FW2-GigabitEthernet1/0/0]ip address 10.10.10.2 30 [FW2]interface GigabitEthernet 1/0/2.401 [FW2-GigabitEthernet1/0/2.401]ip address 10.40.1.20 24 [FW2-GigabitEthernet1/0/2.401]vlan-type dot1q 401 [FW2]interface GigabitEthernet 1/0/2.402 [FW2-GigabitEthernet1/0/2.402]ip address 10.40.2.20 24 [FW2-GigabitEthernet1/0/2.402]vlan-type dot1q 402 [FW2]interface GigabitEthernet 1/0/3.403 [FW2-GigabitEthernet1/0/3.403]ip address 10.40.3.20 24 [FW2-GigabitEthernet1/0/3.403]vlan-type dot1q 403 [FW2]interface GigabitEthernet 1/0/3.404 [FW2-GigabitEthernet1/0/3.404]ip address 10.40.4.20 24 [FW2-GigabitEthernet1/0/3.404]vlan-type dot1q 404 [FW2]firewall zone trust [FW2-zone-trust]add interface GigabitEthernet 1/0/2.401 [FW2-zone-trust]add interface GigabitEthernet 1/0/2.402 [FW2]firewall zone untrust [FW2-zone-untrust]add interface GigabitEthernet 1/0/3.403 [FW2-zone-untrust]add interface GigabitEthernet 1/0/3.404 [FW2]firewall zone dmz [FW2-zone-dmz]add interface GigabitEthernet 1/0/0 [FW2]interface GigabitEthernet 1/0/2.401 [FW2-GigabitEthernet1/0/2.401]vrrp vrid 5 virtual-ip 10.40.1.200 standby [FW2]interface GigabitEthernet 1/0/2.402 [FW2-GigabitEthernet1/0/2.402]vrrp vrid 6 virtual-ip 10.40.2.200 active [FW2]interface GigabitEthernet 1/0/3.403 [FW2-GigabitEthernet1/0/3.403]vrrp vrid 7 virtual-ip 10.40.3.200 standby [FW2]interface GigabitEthernet 1/0/3.404 [FW2-GigabitEthernet1/0/3.404]vrrp vrid 8 virtual-ip 10.40.4.200 active [FW2]hrp mirror session enable 、 [FW2]hrp interface GigabitEthernet 1/0/0 remote 10.10.10.1 [FW2]hrp enable HRP_S[FW2]ip route-static 0.0.0.0 0 10.40.4.100 HRP_S[FW2]ip route-static 0.0.0.0 0 10.40.3.100 preference 70 HRP_S[FW2]ip route-static 192.168.0.0 16 10.40.2.100 HRP_S[FW2]ip route-static 192.168.0.0 16 10.40.1.100 preference 70HRP_M[FW1]security-policy (B) HRP_M[FW1-policy-security]rule name trust_to_untrust (B) HRP_M[FW1-policy-security-rule-trust_to_untrust]source-zone trust (B) HRP_M[FW1-policy-security-rule-trust_to_untrust]destination-zone untrust (B) HRP_M[FW1-policy-security-rule-trust_to_untrust]source-address 192.168.0.0 16 (B) HRP_M[FW1-policy-security-rule-trust_to_untrust]action permit (B)[sw1]interface GigabitEthernet 0/0/1 [sw1-GigabitEthernet0/0/1]port link-type trunk [sw1-GigabitEthernet0/0/1]port trunk allow-pass vlan 403 404 [sw1]interface GigabitEthernet 0/0/2 [sw1-GigabitEthernet0/0/2]port link-type trunk [sw1-GigabitEthernet0/0/2]port trunk allow-pass vlan 403 404 [sw1]interface Vlanif 403 [sw1-Vlanif403]ip address 10.40.3.1 24 [sw1-Vlanif403]vrrp vrid 3 virtual-ip 10.40.3.100 [sw1-Vlanif403]vrrp vrid 3 priority 120 [sw1-Vlanif403]vrrp vrid 3 preempt-mode timer delay 60 [sw1-Vlanif403]vrrp vrid 3 track interface GigabitEthernet 0/0/1 reduced 30 [sw1]interface Vlanif 404 [sw1-Vlanif404]ip address 10.40.4.1 24 [sw1-Vlanif404]vrrp vrid 4 virtual-ip 10.40.4.100[sw2]vlan batch 403 404 [sw2]interface GigabitEthernet 0/0/1 [sw2-GigabitEthernet0/0/1]port link-type trunk [sw2-GigabitEthernet0/0/1]port trunk allow-pass vlan 403 404 [sw2]interface GigabitEthernet 0/0/2 [sw2-GigabitEthernet0/0/2]port link-type trunk [sw2-GigabitEthernet0/0/2]port trunk allow-pass vlan 403 404 [sw2]interface Vlanif 403 [sw2-Vlanif403]ip address 10.40.3.2 24 [sw2-Vlanif403]vrrp vrid 3 virtual-ip 10.40.3.100 [sw2]interface Vlanif 404 [sw2-Vlanif404]ip address 10.40.4.2 24 [sw2-Vlanif404]vrrp vrid 4 virtual-ip 10.40.4.100 [sw2-Vlanif404]vrrp vrid 4 priority 120 [sw2-Vlanif404]vrrp vrid 4 preempt-mode timer delay 60 [sw2-Vlanif404]vrrp vrid 4 track interface GigabitEthernet 0/0/1 reduced 30[sw1]ip route-static vpn-instance VRF 0.0.0.0 0 10.40.1.200 [sw1]ip route-static vpn-instance VRF 0.0.0.0 0 10.40.2.200 preference 70 [sw2]ip route-static vpn-instance VRF 0.0.0.0 0 10.40.2.200 [sw2]ip route-static vpn-instance VRF 0.0.0.0 0 10.40.1.200 preference 70 [sw1]ip route-static 192.168.0.0 16 10.40.3.200 [sw1]ip route-static 192.168.0.0 16 10.40.4.200 preference 70 [sw2]ip route-static 192.168.0.0 16 10.40.4.200 [sw2]ip route-static 192.168.0.0 16 10.40.3.200 preference 70