2台核心交换机irf配置:
<HX_A>dis cu
<HX_A>dis current-configuration
version 7.1.075, Alpha 7571
sysname HX_A
irf mac-address persistent timer
irf auto-update enable
undo irf link-delay
irf member 1 priority 32
irf member 2 priority 1
dhcp enable
lldp global enable
system-working-mode standard
xbar load-single
password-recovery enable
lpu-type f-series
vlan 1
vlan 10 to 15
irf-port 1/1
port group interface Ten-GigabitEthernet1/0/50
port group interface Ten-GigabitEthernet1/0/51
irf-port 2/2
port group interface Ten-GigabitEthernet2/0/50
port group interface Ten-GigabitEthernet2/0/51
dhcp server ip-pool vlan10
gateway-list 192.168.10.1
network 192.168.10.0 mask 255.255.255.0
dns-list 8.8.8.8 1.1.1.1
dhcp server ip-pool vlan11
gateway-list 192.168.11.1
network 192.168.11.0 mask 255.255.255.0
dns-list 1.1.1.1 2.2.2.2
interface Bridge-Aggregation1
interface Bridge-Aggregation2
port link-type trunk
port trunk permit vlan all
link-aggregation mode dynamic
mad enable
interface Route-Aggregation22
ip address 192.168.1.2 255.255.255.0
link-aggregation mode dynamic
interface NULL0
interface Vlan-interface10
ip address 192.168.10.1 255.255.255.0
dhcp server apply ip-pool vlan10
interface Vlan-interface11
ip address 192.168.11.1 255.255.255.0
dhcp server apply ip-pool vlan11
interface Vlan-interface15
ip address 192.168.100.254 255.255.255.0
interface FortyGigE1/0/53
port link-mode bridge
interface FortyGigE1/0/54
port link-mode bridge
interface FortyGigE2/0/53
port link-mode bridge
interface FortyGigE2/0/54
port link-mode bridge
interface GigabitEthernet1/0/1
port link-mode route
combo enable copper
port link-aggregation group 22
interface GigabitEthernet2/0/1
port link-mode route
combo enable copper
port link-aggregation group 22
interface GigabitEthernet1/0/2
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/3
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/4
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/5
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/6
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/7
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/8
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/9
port link-mode bridge
port link-type trunk
port trunk permit vlan all
combo enable copper
port link-aggregation group 2
interface GigabitEthernet1/0/10
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/11
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/12
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/13
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/14
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/15
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/16
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/17
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/18
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/19
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/20
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/21
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/22
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/23
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/24
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/25
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/26
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/27
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/28
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/29
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/30
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/31
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/32
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/33
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/34
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/35
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/36
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/37
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/38
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/39
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/40
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/41
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/42
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/43
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/44
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/45
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/46
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/47
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/48
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/2
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/3
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/4
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/5
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/6
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/7
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/8
port link-mode bridge
port link-type trunk
port trunk permit vlan all
combo enable copper
port link-aggregation group 2
interface GigabitEthernet2/0/9
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/10
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/11
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/12
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/13
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/14
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/15
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/16
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/17
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/18
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/19
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/20
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/21
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/22
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/23
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/24
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/25
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/26
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/27
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/28
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/29
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/30
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/31
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/32
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/33
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/34
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/35
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/36
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/37
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/38
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/39
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/40
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/41
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/42
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/43
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/44
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/45
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/46
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/47
port link-mode bridge
combo enable copper
interface GigabitEthernet2/0/48
port link-mode bridge
combo enable copper
interface M-GigabitEthernet0/0/0
interface Ten-GigabitEthernet1/0/49
port link-mode bridge
combo enable fiber
interface Ten-GigabitEthernet1/0/52
port link-mode bridge
combo enable fiber
interface Ten-GigabitEthernet2/0/49
port link-mode bridge
combo enable fiber
interface Ten-GigabitEthernet2/0/52
port link-mode bridge
combo enable fiber
interface Ten-GigabitEthernet1/0/50
combo enable fiber
interface Ten-GigabitEthernet1/0/51
combo enable fiber
interface Ten-GigabitEthernet2/0/50
combo enable fiber
interface Ten-GigabitEthernet2/0/51
combo enable fiber
scheduler logfile size 16
line class aux
user-role network-operator
line class console
user-role network-admin
line class tty
user-role network-operator
line class vty
user-role network-operator
line aux 0 1
user-role network-operator
line con 0 1
user-role network-admin
line vty 0 63
user-role network-operator
ip route-static 0.0.0.0 0 192.168.1.1
undo info-center enable
radius scheme system
user-name-format without-domain
domain system
domain default enable system
role name level-0
description Predefined level-0 role
role name level-1
description Predefined level-1 role
role name level-2
description Predefined level-2 role
role name level-3
description Predefined level-3 role
role name level-4
description Predefined level-4 role
role name level-5
description Predefined level-5 role
role name level-6
description Predefined level-6 role
role name level-7
description Predefined level-7 role
role name level-8
description Predefined level-8 role
role name level-9
description Predefined level-9 role
role name level-10
description Predefined level-10 role
role name level-11
description Predefined level-11 role
role name level-12
description Predefined level-12 role
role name level-13
description Predefined level-13 role
role name level-14
description Predefined level-14 role
user-group system
return
汇聚交换机配置:
HX>dis current-configuration
version 7.1.075, Alpha 7571
sysname HX
telnet server enable
irf mac-address persistent timer
irf auto-update enable
undo irf link-delay
irf member 1 priority 1
dhcp enable
lldp global enable
system-working-mode standard
xbar load-single
password-recovery enable
lpu-type f-series
vlan 1
vlan 10 to 15
interface Bridge-Aggregation1
port link-type trunk
port trunk permit vlan all
interface Bridge-Aggregation2
port link-type trunk
port trunk permit vlan all
link-aggregation mode dynamic
mad enable
interface NULL0
interface Vlan-interface10
interface Vlan-interface11
interface Vlan-interface15
ip address 192.168.100.250 255.255.255.0
interface FortyGigE1/0/53
port link-mode bridge
interface FortyGigE1/0/54
port link-mode bridge
interface GigabitEthernet1/0/1
port link-mode bridge
port link-type trunk
port trunk permit vlan all
combo enable copper
interface GigabitEthernet1/0/2
port link-mode bridge
port link-type trunk
port trunk permit vlan all
combo enable copper
interface GigabitEthernet1/0/3
port link-mode bridge
port link-type trunk
port trunk permit vlan all
combo enable copper
port link-aggregation group 1
interface GigabitEthernet1/0/4
port link-mode bridge
port link-type trunk
port trunk permit vlan all
combo enable copper
port link-aggregation group 1
interface GigabitEthernet1/0/5
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/6
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/7
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/8
port link-mode bridge
port link-type trunk
port trunk permit vlan all
combo enable copper
port link-aggregation group 2
interface GigabitEthernet1/0/9
port link-mode bridge
port link-type trunk
port trunk permit vlan all
combo enable copper
port link-aggregation group 2
interface GigabitEthernet1/0/10
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/11
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/12
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/13
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/14
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/15
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/16
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/17
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/18
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/19
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/20
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/21
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/22
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/23
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/24
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/25
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/26
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/27
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/28
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/29
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/30
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/31
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/32
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/33
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/34
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/35
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/36
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/37
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/38
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/39
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/40
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/41
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/42
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/43
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/44
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/45
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/46
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/47
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/48
port link-mode bridge
combo enable copper
interface M-GigabitEthernet0/0/0
interface Ten-GigabitEthernet1/0/49
port link-mode bridge
combo enable fiber
interface Ten-GigabitEthernet1/0/50
port link-mode bridge
combo enable fiber
interface Ten-GigabitEthernet1/0/51
port link-mode bridge
combo enable fiber
interface Ten-GigabitEthernet1/0/52
port link-mode bridge
combo enable fiber
scheduler logfile size 16
line class aux
user-role network-operator
line class console
user-role network-admin
line class tty
user-role network-operator
line class vty
user-role network-operator
line aux 0
user-role network-operator
line con 0
authentication-mode scheme
user-role network-admin
line vty 0 4
authentication-mode scheme
user-role network-operator
line vty 5 63
user-role network-operator
ip route-static 0.0.0.0 0 192.168.100.254
super password role network-admin hash $hXrPB98YGf4dC0HII$DaXZnU2cKUcg4kHXhd4Ofb3ZNl6CAjGjf7QdfAsPxrEGOI7IRKrz/jZecP4aAKM750oso8LJmWCmfJcv30LrjA==
radius scheme system
user-name-format without-domain
domain system
domain default enable system
role name level-0
description Predefined level-0 role
role name level-1
description Predefined level-1 role
role name level-2
description Predefined level-2 role
role name level-3
description Predefined level-3 role
role name level-4
description Predefined level-4 role
role name level-5
description Predefined level-5 role
role name level-6
description Predefined level-6 role
role name level-7
description Predefined level-7 role
role name level-8
description Predefined level-8 role
role name level-9
description Predefined level-9 role
role name level-10
description Predefined level-10 role
role name level-11
description Predefined level-11 role
role name level-12
description Predefined level-12 role
role name level-13
description Predefined level-13 role
role name level-14
description Predefined level-14 role
user-group system
local-user admin class manage
password hash $hEGwUpwmojx1MmOP/$0J7cZNnxGXT3+AEhCPAowKh+bOoK1wdpFe+xmLGLZH83uvzKinuSbNhJcA3vGvvUjKg15JjPMYw1u3XC+bxq0Q==
service-type ssh telnet terminal
authorization-attribute user-role network-admin
authorization-attribute user-role network-operator
return
接入交换机配置:
jxl_1#_1>dis cu
<jxl_1#_1>dis current-configuration
version 7.1.075, Alpha 7571
sysname jxl_1#_1
telnet server enable
irf mac-address persistent timer
irf auto-update enable
undo irf link-delay
irf member 1 priority 1
lldp global enable
system-working-mode standard
xbar load-single
password-recovery enable
lpu-type f-series
vlan 1
vlan 10 to 15
interface Bridge-Aggregation1
port link-type trunk
port trunk permit vlan all
interface NULL0
interface Vlan-interface15
ip address 192.168.100.2 255.255.255.0
interface FortyGigE1/0/53
port link-mode bridge
interface FortyGigE1/0/54
port link-mode bridge
interface GigabitEthernet1/0/1
port link-mode bridge
port link-type trunk
port trunk permit vlan all
combo enable copper
interface GigabitEthernet1/0/2
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/3
port link-mode bridge
port link-type trunk
port trunk permit vlan all
combo enable copper
port link-aggregation group 1
interface GigabitEthernet1/0/4
port link-mode bridge
port link-type trunk
port trunk permit vlan all
combo enable copper
port link-aggregation group 1
interface GigabitEthernet1/0/5
port link-mode bridge
port access vlan 11
combo enable copper
interface GigabitEthernet1/0/6
port link-mode bridge
port access vlan 11
combo enable copper
interface GigabitEthernet1/0/7
port link-mode bridge
port access vlan 11
combo enable copper
interface GigabitEthernet1/0/8
port link-mode bridge
port access vlan 11
combo enable copper
interface GigabitEthernet1/0/9
port link-mode bridge
port access vlan 10
combo enable copper
interface GigabitEthernet1/0/10
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/11
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/12
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/13
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/14
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/15
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/16
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/17
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/18
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/19
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/20
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/21
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/22
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/23
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/24
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/25
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/26
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/27
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/28
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/29
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/30
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/31
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/32
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/33
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/34
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/35
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/36
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/37
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/38
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/39
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/40
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/41
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/42
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/43
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/44
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/45
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/46
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/47
port link-mode bridge
combo enable copper
interface GigabitEthernet1/0/48
port link-mode bridge
combo enable copper
interface M-GigabitEthernet0/0/0
interface Ten-GigabitEthernet1/0/49
port link-mode bridge
combo enable fiber
interface Ten-GigabitEthernet1/0/50
port link-mode bridge
combo enable fiber
interface Ten-GigabitEthernet1/0/51
port link-mode bridge
combo enable fiber
interface Ten-GigabitEthernet1/0/52
port link-mode bridge
combo enable fiber
scheduler logfile size 16
line class aux
user-role network-operator
line class console
user-role network-admin
line class tty
user-role network-operator
line class vty
user-role network-operator
line aux 0
user-role network-operator
line con 0
authentication-mode scheme
user-role network-admin
line vty 0 4
authentication-mode scheme
user-role network-operator
line vty 5 63
user-role network-operator
ip route-static 0.0.0.0 0 192.168.100.254
super password role network-admin hash $hzuCJZx74qDk4t4Oz$MeCsuhoE1Dvwa0JmDrzkW9eqeWZoqJjxZPfb9xcLIyjSwuIFReGSwKtUfcrxbKdbED7RrPmSwrun6kLI2iEQkQ==
radius scheme system
user-name-format without-domain
domain system
domain default enable system
role name level-0
description Predefined level-0 role
role name level-1
description Predefined level-1 role
role name level-2
description Predefined level-2 role
role name level-3
description Predefined level-3 role
role name level-4
description Predefined level-4 role
role name level-5
description Predefined level-5 role
role name level-6
description Predefined level-6 role
role name level-7
description Predefined level-7 role
role name level-8
description Predefined level-8 role
role name level-9
description Predefined level-9 role
role name level-10
description Predefined level-10 role
role name level-11
description Predefined level-11 role
role name level-12
description Predefined level-12 role
role name level-13
description Predefined level-13 role
role name level-14
description Predefined level-14 role
user-group system
local-user admin class manage
password hash $hU2UhaYcaMnXLa/OT$IZpO2eZuCVrqdgE0HZswjiMUygRKwbXolVlYQS5MKh4wkReRcQYYIqWo/nJJnWzjhpcwTT57RW6F/CGONg7tDw==
service-type ssh telnet terminal
authorization-attribute user-role network-admin
authorization-attribute user-role network-operator
return
防火墙配置:
防火墙 命令行
version 7.1.064, Alpha 7164
sysname H3C
context Admin id 1
telnet server enable
irf mac-address persistent timer
irf auto-update enable
undo irf link-delay
irf member 1 priority 1
nat address-group 1 name 1
address 192.18.11.2 192.18.11.253
address 192.168.10.2 192.168.10.253
xbar load-single
password-recovery enable
lpu-type f-series
vlan 1
interface Route-Aggregation22
ip address 192.168.1.1 255.255.255.0
link-aggregation mode dynamic
interface NULL0
interface GigabitEthernet1/0/0
port link-mode route
combo enable copper
ip address 192.168.56.99 255.255.255.0
interface GigabitEthernet1/0/1
port link-mode route
combo enable copper
interface GigabitEthernet1/0/2
port link-mode route
combo enable copper
port link-aggregation group 22
interface GigabitEthernet1/0/3
port link-mode route
combo enable copper
port link-aggregation group 22
interface GigabitEthernet1/0/4
port link-mode route
combo enable copper
ip address 1.1.1.2 255.255.255.0
nat outbound 2000
interface GigabitEthernet1/0/5
port link-mode route
combo enable copper
interface GigabitEthernet1/0/6
port link-mode route
combo enable copper
interface GigabitEthernet1/0/7
port link-mode route
combo enable copper
interface GigabitEthernet1/0/8
port link-mode route
combo enable copper
interface GigabitEthernet1/0/9
port link-mode route
combo enable copper
interface GigabitEthernet1/0/10
port link-mode route
combo enable copper
interface GigabitEthernet1/0/11
port link-mode route
combo enable copper
interface GigabitEthernet1/0/12
port link-mode route
combo enable copper
interface GigabitEthernet1/0/13
port link-mode route
combo enable copper
interface GigabitEthernet1/0/14
port link-mode route
combo enable copper
interface GigabitEthernet1/0/15
port link-mode route
combo enable copper
interface GigabitEthernet1/0/16
port link-mode route
combo enable copper
interface GigabitEthernet1/0/17
port link-mode route
combo enable copper
interface GigabitEthernet1/0/18
port link-mode route
combo enable copper
interface GigabitEthernet1/0/19
port link-mode route
combo enable copper
interface GigabitEthernet1/0/20
port link-mode route
combo enable copper
interface GigabitEthernet1/0/21
port link-mode route
combo enable copper
interface GigabitEthernet1/0/22
port link-mode route
combo enable copper
interface GigabitEthernet1/0/23
port link-mode route
combo enable copper
object-policy ip Local-Trust
rule 0 pass
object-policy ip Trust-Untrust
rule 0 pass
object-policy ip manage
rule 0 pass
security-zone name Local
security-zone name Trust
import interface GigabitEthernet1/0/0
import interface Route-Aggregation22
security-zone name DMZ
security-zone name Untrust
import interface GigabitEthernet1/0/4
security-zone name Management
zone-pair security source Local destination Trust
object-policy apply ip Local-Trust
zone-pair security source Trust destination Local
object-policy apply ip manage
zone-pair security source Trust destination Untrust
object-policy apply ip Trust-Untrust
scheduler logfile size 16
line class aux
user-role network-operator
line class console
user-role network-admin
line class tty
user-role network-operator
line class vty
user-role network-operator
line aux 0
user-role network-admin
line con 0
authentication-mode scheme
user-role network-admin
line vty 0 4
authentication-mode scheme
user-role network-admin
line vty 5 63
user-role network-operator
ip route-static 0.0.0.0 0 1.1.1.1
ip route-static 192.168.0.0 16 192.168.1.2
acl basic 2000
rule 0 permit
rule 0 comment 2000_nat
domain system
aaa session-limit ftp 16
aaa session-limit telnet 16
aaa session-limit ssh 16
domain default enable system
role name level-0
description Predefined level-0 role
role name level-1
description Predefined level-1 role
role name level-2
description Predefined level-2 role
role name level-3
description Predefined level-3 role
role name level-4
description Predefined level-4 role
role name level-5
description Predefined level-5 role
role name level-6
description Predefined level-6 role
role name level-7
description Predefined level-7 role
role name level-8
description Predefined level-8 role
role name level-9
description Predefined level-9 role
role name level-10
description Predefined level-10 role
role name level-11
description Predefined level-11 role
role name level-12
description Predefined level-12 role
role name level-13
description Predefined level-13 role
role name level-14
description Predefined level-14 role
user-group system
local-user admin class manage
password hash $hImiztxrvB+H7b0sw$Bn5Et2ypy7xTbcNA0XwGheh4DYSz4kmaz0f4bPbxoA44XOlo1CNuz3QxHbvkbj56/tATLt53z9H+6XD9erFK1Q==
service-type telnet terminal http https
authorization-attribute user-role level-3
authorization-attribute user-role network-
authorization-attribute user-role network-admin
authorization-attribute user-role network-operator
ip http enable
ip https enable
return