|
楼主 |
发表于 2007-12-28 15:55:43
|
显示全部楼层
刚给用户做的catalyst 4506双机热备配置,经测试ACL、standby均工作正常。。该配置是主交换机配置,从交换机各VLAN的IP配置不同外(应与主交换机各VLAN的IP在同一网段),其它均相同。
Current configuration : 4307 bytes
!
version 12.2
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
service compress-config
!
hostname 4506-1
!
enable secret 5 $1$f6uA$uOeBnswuinoLFBNsxSP561
!
ip subnet-zero
no ip domain-lookup
!
!
no file verify auto
!
spanning-tree mode pvst
spanning-tree extend system-id
spanning-tree vlan 1-1005 priority 24576
power redundancy-mode redundant
!
!
vlan access-map vlan_map 10
action forward
match ip address server_acl
vlan access-map vlan_map 20
action drop
match ip address vlan_acl
vlan access-map vlan_map 30
action forward
vlan filter vlan_map vlan-list 30-31,33-34,37,39,100-101,200,311
vlan internal allocation policy ascending
!
interface Port-channel1
switchport
switchport trunk encapsulation dot1q
!
interface GigabitEthernet1/1
switchport trunk encapsulation dot1q
channel-group 1 mode on
!
interface GigabitEthernet1/2
switchport trunk encapsulation dot1q
channel-group 1 mode on
!
interface GigabitEthernet2/1
switchport trunk encapsulation dot1q
!
interface GigabitEthernet2/2
switchport access vlan 37
spanning-tree portfast
!
interface GigabitEthernet2/3
switchport trunk encapsulation dot1q
!
interface GigabitEthernet2/4
switchport access vlan 33
spanning-tree portfast
!
interface GigabitEthernet2/5
switchport trunk encapsulation dot1q
!
interface GigabitEthernet2/6
switchport access vlan 34
spanning-tree portfast
!
interface GigabitEthernet3/1
switchport trunk encapsulation dot1q
!
interface GigabitEthernet3/2
switchport trunk encapsulation dot1q
interface GigabitEthernet3/3
switchport access vlan 311
spanning-tree portfast
!
interface GigabitEthernet3/4
switchport trunk encapsulation dot1q
!
interface GigabitEthernet3/5
switchport access vlan 31
spanning-tree portfast
!
interface GigabitEthernet3/6
switchport access vlan 101
spanning-tree portfast
!
interface GigabitEthernet4/1
switchport trunk encapsulation dot1q
!
interface GigabitEthernet4/2
switchport access vlan 39
spanning-tree portfast
!
interface GigabitEthernet4/3
switchport trunk encapsulation dot1q
!
interface GigabitEthernet4/4
switchport access vlan 101
spanning-tree portfast
!
interface GigabitEthernet4/5
switchport trunk encapsulation dot1q
!
interface GigabitEthernet4/6
switchport access vlan 30
spanning-tree portfast
!
interface GigabitEthernet6/1
!
interface GigabitEthernet6/2
!
interface GigabitEthernet6/3
!
interface GigabitEthernet6/4
!
interface GigabitEthernet6/5
interface GigabitEthernet6/6
!
interface GigabitEthernet6/7
!
interface GigabitEthernet6/8
!
interface GigabitEthernet6/9
!
interface GigabitEthernet6/10
!
interface GigabitEthernet6/11
!
interface GigabitEthernet6/12
!
interface GigabitEthernet6/13
!
interface GigabitEthernet6/14
!
interface GigabitEthernet6/15
!
interface GigabitEthernet6/16
!
interface GigabitEthernet6/17
!
interface GigabitEthernet6/18
!
interface GigabitEthernet6/19
!
interface GigabitEthernet6/20
!
interface GigabitEthernet6/21
!
interface GigabitEthernet6/22
!
interface GigabitEthernet6/23
!
interface GigabitEthernet6/24
!
interface Vlan1
no ip address
!
interface Vlan30
ip address 192.168.30.252 255.255.255.0
standby ip 192.168.30.254
standby priority 110
standby preempt
!
interface Vlan31
ip address 192.168.31.252 255.255.255.0
standby ip 192.168.31.254
standby priority 110
standby preempt
!
interface Vlan33
ip address 192.168.33.252 255.255.255.0
standby ip 192.168.33.254
standby priority 110
standby preempt
!
interface Vlan34
ip address 192.168.34.252 255.255.255.0
standby ip 192.168.34.254
standby priority 110
standby preempt
!
interface Vlan37
ip address 192.168.37.252 255.255.255.0
standby ip 192.168.37.254
standby priority 110
standby preempt
!
interface Vlan39
ip address 192.168.39.252 255.255.255.0
standby ip 192.168.39.254
standby priority 110
standby preempt
!
interface Vlan100
ip address 192.168.100.252 255.255.255.0
standby ip 192.168.100.254
standby priority 110
standby preempt
!
interface Vlan101
ip address 192.168.101.252 255.255.255.0
standby ip 192.168.101.254
standby priority 110
standby preempt
!
interface Vlan200
ip address 192.168.200.252 255.255.255.0
standby ip 192.168.200.254
standby priority 110
standby preempt
!
interface Vlan311
ip address 192.168.11.252 255.255.255.0
standby ip 192.168.11.254
standby priority 110
standby preempt
!
no ip http server
!
!
ip access-list extended server_acl
permit ip 192.168.0.0 0.0.255.255 host 192.168.101.250
ip access-list extended vlan_acl
permit ip 192.168.30.0 0.0.0.255 192.168.33.0 0.0.0.255
permit ip 192.168.30.0 0.0.0.255 192.168.101.0 0.0.0.255
permit ip 192.168.30.0 0.0.0.255 192.168.31.0 0.0.0.255
permit ip 192.168.30.0 0.0.0.255 192.168.34.0 0.0.0.255
permit ip 192.168.30.0 0.0.0.255 192.168.37.0 0.0.0.255
permit ip 192.168.30.0 0.0.0.255 192.168.39.0 0.0.0.255
permit ip 192.168.30.0 0.0.0.255 192.168.11.0 0.0.0.255
permit ip 192.168.30.0 0.0.0.255 192.168.100.0 0.0.0.255
permit ip 192.168.30.0 0.0.0.255 192.168.200.0 0.0.0.255
permit ip 192.168.31.0 0.0.0.255 192.168.33.0 0.0.0.255
permit ip 192.168.31.0 0.0.0.255 192.168.34.0 0.0.0.255
permit ip 192.168.31.0 0.0.0.255 192.168.37.0 0.0.0.255
permit ip 192.168.31.0 0.0.0.255 192.168.39.0 0.0.0.255
permit ip 192.168.31.0 0.0.0.255 192.168.11.0 0.0.0.255
permit ip 192.168.31.0 0.0.0.255 192.168.100.0 0.0.0.255
permit ip 192.168.31.0 0.0.0.255 192.168.101.0 0.0.0.255
permit ip 192.168.31.0 0.0.0.255 192.168.200.0 0.0.0.255
permit ip 192.168.33.0 0.0.0.255 192.168.34.0 0.0.0.255
permit ip 192.168.33.0 0.0.0.255 192.168.37.0 0.0.0.255
permit ip 192.168.33.0 0.0.0.255 192.168.39.0 0.0.0.255
permit ip 192.168.33.0 0.0.0.255 192.168.11.0 0.0.0.255
permit ip 192.168.33.0 0.0.0.255 192.168.100.0 0.0.0.255
permit ip 192.168.33.0 0.0.0.255 192.168.101.0 0.0.0.255
permit ip 192.168.33.0 0.0.0.255 192.168.200.0 0.0.0.255
permit ip 192.168.34.0 0.0.0.255 192.168.37.0 0.0.0.255
permit ip 192.168.34.0 0.0.0.255 192.168.39.0 0.0.0.255
permit ip 192.168.34.0 0.0.0.255 192.168.11.0 0.0.0.255
permit ip 192.168.34.0 0.0.0.255 192.168.100.0 0.0.0.255
permit ip 192.168.34.0 0.0.0.255 192.168.101.0 0.0.0.255
permit ip 192.168.34.0 0.0.0.255 192.168.200.0 0.0.0.255
permit ip 192.168.37.0 0.0.0.255 192.168.39.0 0.0.0.255
permit ip 192.168.37.0 0.0.0.255 192.168.11.0 0.0.0.255
permit ip 192.168.37.0 0.0.0.255 192.168.100.0 0.0.0.255
permit ip 192.168.37.0 0.0.0.255 192.168.101.0 0.0.0.255
permit ip 192.168.37.0 0.0.0.255 192.168.200.0 0.0.0.255
permit ip 192.168.39.0 0.0.0.255 192.168.11.0 0.0.0.255
permit ip 192.168.39.0 0.0.0.255 192.168.100.0 0.0.0.255
permit ip 192.168.39.0 0.0.0.255 192.168.101.0 0.0.0.255
permit ip 192.168.39.0 0.0.0.255 192.168.200.0 0.0.0.255
permit ip 192.168.11.0 0.0.0.255 192.168.100.0 0.0.0.255
permit ip 192.168.11.0 0.0.0.255 192.168.101.0 0.0.0.255
permit ip 192.168.11.0 0.0.0.255 192.168.200.0 0.0.0.255
permit ip 192.168.100.0 0.0.0.255 192.168.101.0 0.0.0.255
permit ip 192.168.100.0 0.0.0.255 192.168.200.0 0.0.0.255
permit ip 192.168.101.0 0.0.0.255 192.168.200.0 0.0.0.255
!
!
!
line con 0
stopbits 1
line vty 0 4
password %$&&&*(&(
login
line vty 5 15
password %$&&&*(&(
login
!
end
4506-1#show standby brief
P indicates configured to preempt.
|
Interface Grp Prio P State Active addr Standby addr Group addr
Vl30 0 110 P Active local unknown 192.168.30.254
Vl31 0 110 P Active local unknown 192.168.31.254
Vl33 0 110 P Active local unknown 192.168.33.254
Vl34 0 110 P Active local unknown 192.168.34.254
Vl37 0 110 P Active local unknown 192.168.37.254
Vl39 0 110 P Active local unknown 192.168.39.254
Vl100 0 110 P Active local unknown 192.168.100.254
Vl101 0 110 P Active local unknown 192.168.101.254
Vl200 0 110 P Active local unknown 192.168.200.254
Vl311 0 110 P Active local unknown 192.168.11.254
4506-1#
4506-1#show vtp status
VTP Version : 2
Configuration Revision : 10
Maximum VLANs supported locally : 1005
Number of existing VLANs : 15
VTP Operating Mode : Server
VTP Domain Name : domainnet
VTP Pruning Mode : Enable
VTP V2 Mode : Enable
VTP Traps Generation : Disabled
MD5 digest : 0x46 0xDB 0x03 0x38 0x8D 0xBC 0x92 0x8F
Configuration last modified by 0.0.0.0 at 12-13-05 20:53:52
Local updater ID is 192.168.30.252 on interface Vl30 (lowest numbered VLAN inter
face found)
4506-1#
|
|
|