H3C交换机常用配置

news/2024/11/8 17:03:02/

零 修订记录

序号修订内容修订时间
1新增20210422

一 摘要

本文主要介绍H3C 交换机常用配置

二 环境信息

(一)机器信息

机器型号机器名称用途
LS-6860-54HFA3_1F_DC_openstack_test_jieru_train-irf_b02&b03接入层,用于接入openstack 集群

三 常用配置

(一)A3_1F_DC_openstack_test_jieru_train-irf_b02&b03

使用两台LS-6860-54HF,配置堆叠,两台交换机对应端口做端口聚合

3.1.1 修改交换机时间

<A3_1F_DC_openstack_test_jieru_train-irf_b02&b03>display clock
22:10:06.169 UTC Fri 01/07/2011
<A3_1F_DC_openstack_test_jieru_train-irf_b02&b03><A3_1F_DC_openstack_test_jieru_train-irf_b02&b03>system-view
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]clock protocol none#关闭protocol ,缺省情况下,默认开启,由缺省MDC获取系统时间
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]clock timezone beijing add 8
<A3_1F_DC_openstack_test_jieru_train-irf_b02&b03>clock datetime 14:20:30 2021/4/22
<A3_1F_DC_openstack_test_jieru_train-irf_b02&b03>display clock
14:20:34.266 beijing Thu 04/22/2021
Time Zone : beijing add 08:00:00

3.1.2 备份配置文件


<A3_1F_DC_openstack_test_jieru_train-irf_b02&b03>save
The current configuration will be written to the device. Are you sure? [Y/N]:y
Please input the file name(*.cfg)[flash:/startup.cfg]
(To leave the existing filename unchanged, press the enter key):
flash:/startup.cfg exists, overwrite? [Y/N]:y
Validating file. Please wait...
Saved the current configuration to mainboard device successfully.
Slot 2:
Save next configuration file successfully.

3.1.3 配置堆叠

堆叠配置信息:
堆叠口
te1/0/47 te1/0/48
te2/0/47 te2/0/48
堆叠检测口
te1/0/46 te2/0/46

3.1.4 常看UP 接口信息

<A3_1F_DC_openstack_test_jieru_train-irf_b02&b03>display interface brief | include UP
InLoop0              UP   UP(s)    --
NULL0                UP   UP(s)    --
REG0                 UP   --       --
Vlan1                UP   UP       --
Vlan81               UP   UP       10.3.181.251
Vlan140              UP   UP       10.3.140.1
Vlan141              UP   UP       10.3.141.1
Vlan142              UP   UP       10.3.142.1
Vlan143              UP   UP       10.3.143.1
Vlan144              UP   UP       10.3.144.1
Vlan145              UP   UP       10.3.145.1
Vlan146              UP   UP       10.3.146.1
Vlan147              UP   UP       10.3.147.1
Vlan148              UP   UP       10.3.148.1
Vlan149              UP   UP       10.3.149.1
Vlan1000             UP   UP       1.1.1.2         bfd
BAGG1                UP   20G(a)  F(a)   T    1    ithi
BAGG7                UP   10G(a)  F(a)   A    140
BAGG8                UP   20G(a)  F(a)   A    140
BAGG9                UP   10G(a)  F(a)   A    140
BAGG25               UP   10G(a)  F(a)   T    1

3.1.5 查看链路聚合详细信息

<A3_1F_DC_openstack_test_jieru_train-irf_b02&b03>dis link-aggregation verbose

3.1.6 配置链路聚合(trunk)

检查是否已配置过该链路聚合

[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]dis link-aggregation verbose | include 25XGE1/0/8            255      1        15       0xffff, 6c92-bff6-2a71 {ACDEF}XGE2/0/8            255      2        15       0xffff, 6c92-bff6-2a71 {ACDEF}
Aggregate Interface: Bridge-Aggregation25XGE1/0/25(R)        S        32768    7        4                      {ACDEFG}XGE2/0/25           U        32768    8        4                      {ACG}XGE1/0/25           32768    0        0        0x8000, 0000-0000-0000 {DEF}XGE2/0/25           32768    0        0        0x8000, 0000-0000-0000 {DEF}
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]dis link-aggregation verbose | include 31
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]interface Bridge-Aggregation 31
//创建端口聚合31
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation31]quit
//退出 端口聚合31
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]interface te1/0/31
//进入 te1/0/31 端口
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Ten-GigabitEthernet1/0/31]port link-aggregation group 31
// 将该端口加入 端口聚合31
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Ten-GigabitEthernet1/0/31]quit
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]interface te2/0/31
//进入 te2/0/31 端口
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Ten-GigabitEthernet2/0/31]port link-aggregation group 31
// 将该端口加入 端口聚合31[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Ten-GigabitEthernet2/0/31]quit
//再次 进入端口聚合31
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]interface Bridge-Aggregation 31
//配置为trunk
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation31]port link-type trunk
Configuring Ten-GigabitEthernet1/0/31 done.
Configuring Ten-GigabitEthernet2/0/31 done.
//取消vlan 1
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation31]undo port trunk permit vlan 1
Configuring Ten-GigabitEthernet1/0/31 done.
Configuring Ten-GigabitEthernet2/0/31 done.
// permit vlan 140 149
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation31]port trunk permit vlan 140 to 149
Configuring Ten-GigabitEthernet1/0/31 done.
Configuring Ten-GigabitEthernet2/0/31 done.
// 配置动态链路聚合
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation31]link-aggregation mode dynamic
// 查看整体配置
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation31]display this
#
interface Bridge-Aggregation31port link-type trunkundo port trunk permit vlan 1port trunk permit vlan 140 to 149link-aggregation mode dynamic
#
return
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation31]

3.1.7 修改链路聚合配置

比如将trunk 配置改为access 等配置
首先清空原配置,然后配置新配置。
当前配置

[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]interface Bridge-Aggregation 32
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation32]display this
#
interface Bridge-Aggregation32port link-type trunkundo port trunk permit vlan 1port trunk permit vlan 140 to 149link-aggregation mode dynamic
#
return
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation32]

恢复默认配置

[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation32]default
This command will restore the default settings. Continue? [Y/N]:y
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation32]display this
#
interface Bridge-Aggregation32
#
return
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation32]

添加access vlan 141
添加动态链路聚合

[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation32]port access vlan 141
Configuring Ten-GigabitEthernet1/0/32 done.
Configuring Ten-GigabitEthernet2/0/32 done.
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation32]link-aggregation mode dynamic
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation32]display this
#
interface Bridge-Aggregation32port access vlan 141link-aggregation mode dynamic
#
return
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation32]

3.1.8 配置链路聚合(access)

检查是否已配置过该链路聚合

[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]dis link-aggregation verbose | include 1
Aggregate Interface: Bridge-Aggregation1XGE1/0/45(R)     S       32768    1XGE2/0/45        S       32768    1
System ID: 0x8000, 1451-7e9e-a59a

可见 Bridge-Aggregation1 名称用了, 但实际用的是45port

[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]interface Bridge-Aggregation 1111
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation1111]quit
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]interface te1/0/1
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Ten-GigabitEthernet1/0/1]port link-aggregation group 1111
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Ten-GigabitEthernet1/0/1]quit
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]interface te2/0/1
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Ten-GigabitEthernet2/0/1]port link-aggregation group 1111
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Ten-GigabitEthernet2/0/1]quit
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]interface Bridge-Aggregation 1111
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation1111]port access vlan 140
Configuring Ten-GigabitEthernet1/0/1 done.
Configuring Ten-GigabitEthernet2/0/1 done.
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation1111]link-aggregation mode dynamic
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation1111]display this
#
interface Bridge-Aggregation1111port access vlan 140link-aggregation mode dynamic
#
return
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Bridge-Aggregation1111]

3.1.9 端口从链路聚合里删除

[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]interface te2/0/25
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Ten-GigabitEthernet2/0/25]display this
#
interface Ten-GigabitEthernet2/0/25port link-mode bridgeport link-type trunkundo port trunk permit vlan 1port trunk permit vlan 140 to 149port link-aggregation group 25
#
return
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Ten-GigabitEthernet2/0/25]undo port link-aggregation group
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Ten-GigabitEthernet2/0/25]display this
#
interface Ten-GigabitEthernet2/0/25port link-mode bridgeport link-type trunkundo port trunk permit vlan 1port trunk permit vlan 140 to 149
#
return
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Ten-GigabitEthernet2/0/25]

3.1.10 vlan 网络隔离

通过acl 实现vlan 网络隔离


<A3_1F_DC_openstack_test_jieru_train-irf_b02&b03>system-view
System View: return to User View with Ctrl+Z.
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]acl advanced 3001
// 新建acl
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-acl-ipv4-adv-3001]rule 1 deny ip source 10.3.143.0 0.0.0.255 destination 10.3.14
5.0 0.0.0.255//配置规则 禁止访问10.3.145.0/24
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-acl-ipv4-adv-3001]rule 2 deny ip source 10.3.143.0 0.0.0.255 destination 10.3.14
6.0 0.0.0.255//配置规则 禁止访问10.3.146.0/24
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-acl-ipv4-adv-3001]rule 20 permit ip//允许其他ip
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-acl-ipv4-adv-3001]exit
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]interface Vlan-interface 143
//进入vlan 143
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Vlan-interface143]display this
#
interface Vlan-interface143ip address 10.3.143.1 255.255.255.0
#
return
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Vlan-interface143]packet-filter 3001 inbound// vlan 143 inbound 方向下发acl
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Vlan-interface143]display this
#
interface Vlan-interface143ip address 10.3.143.1 255.255.255.0packet-filter 3001 inbound
#
return
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-Vlan-interface143]exit
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]display acl 3001
Advanced IPv4 ACL 3001, 3 rules,
ACL's step is 5, start ID is 0rule 1 deny ip source 10.3.143.0 0.0.0.255 destination 10.3.145.0 0.0.0.255rule 2 deny ip source 10.3.143.0 0.0.0.255 destination 10.3.146.0 0.0.0.255rule 20 permit ip[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]

通过配置counting,检测acl 是否生效

[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]acl advanced 3001
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-acl-ipv4-adv-3001]display this
#
acl advanced 3001rule 1 deny ip source 10.3.143.0 0.0.0.255 destination 10.3.145.0 0.0.0.255rule 2 deny ip source 10.3.143.0 0.0.0.255 destination 10.3.146.0 0.0.0.255rule 20 permit ip
#
return
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-acl-ipv4-adv-3001]undo rule 1
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-acl-ipv4-adv-3001]undo rule 2
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-acl-ipv4-adv-3001]undo rule 20
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-acl-ipv4-adv-3001]display this
#
acl advanced 3001
#
return
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-acl-ipv4-adv-3001]rule 1 deny ip source 10.3.143.0 0.0.0.255 destination 10.3.14
5.0 0.0.0.255 counting
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-acl-ipv4-adv-3001]rule 2 deny ip source 10.3.143.0 0.0.0.255 destination 10.3.14
6.0 0.0.0.255 counting
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-acl-ipv4-adv-3001]rule 20 permit ip counting
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-acl-ipv4-adv-3001]display this
#
acl advanced 3001rule 1 deny ip source 10.3.143.0 0.0.0.255 destination 10.3.145.0 0.0.0.255 countingrule 2 deny ip source 10.3.143.0 0.0.0.255 destination 10.3.146.0 0.0.0.255 countingrule 20 permit ip counting
#
return
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03-acl-ipv4-adv-3001]
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]dis packet-filter statistics interface Vlan-interface 143 inbound
Interface: Vlan-interface143Inbound policy:IPv4 ACL 3001rule 1 deny ip source 10.3.143.0 0.0.0.255 destination 10.3.145.0 0.0.0.255 counting (14 packets)rule 2 deny ip source 10.3.143.0 0.0.0.255 destination 10.3.146.0 0.0.0.255 counting (21 packets)rule 20 permit ip counting (63 packets)[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]

3.1.11 开启snmp

一般用zabbix 监控交换机时需要,开启snmp

A3_1F_DC_openstack_test_jieru_train-irf_b02&b03>system-view
System View: return to User View with Ctrl+Z.
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]snmp-agent
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]snmp-agent community read public
[A3_1F_DC_openstack_test_jieru_train-irf_b02&b03]snmp-agent sys-info version all

http://www.ppmy.cn/news/119346.html

相关文章

怎样选择(FC-SAN)光纤通道(存储)交换机

怎样选择&#xff08;FC-SAN&#xff09;光纤通道&#xff08;存储&#xff09;交换机 由于光纤通道交换机是构造存储区域网络 SAN 的核心构件&#xff0c;所以选择最合适的交换机是至关重要的。只有正确选择对存储区域网络最合适的光纤交换机才能提高企业信息管理的效率&#…

H3C交换机配置常用命令

1.配置文件相关命令 [Quidway]display current-configuration //显示当前生效的配置 [Quidway]display saved-configuration //显示flash中配置文件&#xff0c;即下次上电启动时所用的配置文件 <Quidway>reset saved-configuration //…

Brocade 300 光纤交换机的配置

一、上架 1、新到光纤交换机上架 注意网线口和管理口标志有区别 2、连线 二、基本配置 1、配置IP、修改用户密码 a.新的光纤交换机默认ip为&#xff1a;10.77.77.77&#xff0c;需直连配置ip b.登录机器配置ip&#xff0c;用户名&#xff1a;admin&#xff0c;密码默认…

H3C交换机配置SSH

一般连接交换机可以使用telnet协议&#xff0c;虽然Telnet较为简单实用也很方便&#xff0c;并不怎么安全。原因在于Telnet是一个明文传送协议&#xff0c;它将用户的所有内容&#xff0c;包括用户名和密码都明文在互联网上传送&#xff0c;具有一定的安全隐患&#xff0c;因此…

FAQ-华为交换机与H3C交换机对接主意事项

华为交换机和H3C 交换机对接经常会遇到各种不同的问题&#xff0c;经常出现的问题有STP、端口双工速率、链路聚合等几个方面。 解决方案 华为交换机和H3C交换机对接注意事项主要集中在以下三个方面&#xff1a; 1、生成树协议对接 华为S交换机与H3C交换机对接生成树协议时&…

H3C交换机常用配置命令

一.用户配置: <H3C>system-view [H3C]super password H3C 设置用户分级密码 [H3C]undo super password 删除用户分级密码 [H3C]localuser bigheap 123456 1 Web网管用户设置,1&#xff08;缺省&#xff09;为管理级用户,缺省admin,admin [H3C]undo loca…

华三交换机配置入门

前段时间接手了一个研究交换机的机会&#xff0c;然后写出来一个简单的操作文档&#xff0c;这个只是一个例子&#xff0c;其他的交换机原理相同&#xff0c;跟大家分享一下。 产品介绍&#xff1a; H3C&#xff08;华三&#xff09;S5028提供24个10/100/1000Base-T自协商的以…

H3C_交换机_Vlan配置

奶奶说&#xff0c;没事不要和小学生比爹。 一、实验环境 HCL v2.1.2win7操作系统 二、拓扑结构 三、模拟环境 一般用于企业网络或者需要对局域网进行逻辑区域划分的网络。不同vlan间一般情况是不能相互访问的&#xff0c;这样就可以减少广播和提高网络安全性。 四、介绍 …