H3C 7503 和 7502 MSTP+VRRP配置实例

时间:2023-02-04 17:52:27
直接贴配置H3C 7503 和 7502 MSTP+VRRP配置实例   [S7503]dis ver
H3C Comware Platform Software
Comware software, Version 3.10, Release 3132P02
Copyright(c) 2004-2006 Hangzhou Huawei-3Com Tech. Co., Ltd. All rights reserved.
H3C S7503 uptime is 0 week, 0 day, 22 hours, 15 minutes

SRPG 0:  uptime is 0 weeks,0 days,22 hours,15 minutes
H3C S7500 with 1 MPC8245 Processor
256M    bytes SDRAM
32768K  bytes Flash Memory
512K    bytes NVRAM Memory
PCB Version      :   VER.C
BootROM Version  :   527
CPLD Version     :   004
Second CPLD Ver  :   005
Software Version :   S7503-3132P02
Patch Version    :   None
LPU 1:  uptime is 0 weeks,0 days,22 hours,13 minutes
H3C S7500 LPU with 1 MPC8241 Processor
128M    bytes SDRAM
0K      bytes Flash Memory
0K      bytes NVRAM Memory               
PCB Version      :   VER.B
BootROM Version  :   530
CPLD Version     :   005
Second CPLD Ver  :   005
Software Version :   S7503-3132P02
Patch Version    :   None
LPU 2:  uptime is 0 weeks,0 days,22 hours,13 minutes
H3C S7500 LPU with 1 MPC8241 Processor
128M    bytes SDRAM
0K      bytes Flash Memory
0K      bytes NVRAM Memory
PCB Version      :   VER.C
BootROM Version  :   530
CPLD Version     :   005
Software Version :   S7503-3132P02
Patch Version    :   None
  [S7503]dis cur
#
 sysname S7503
#
 domain default enable system
#
 temperature-limit 0 10 70
 temperature-limit 1 10 70
 temperature-limit 2 10 70
#
 poe power max-value 2400
#
 vrrp ping-enable
#
radius scheme system
 primary authentication 127.0.0.1 1645
 primary accounting 127.0.0.1 1646
 user-name-format without-domain
#
domain system
 vlan-assignment-mode integer
 access-limit disable
 state active
 idle-cut disable
 self-service-url disable                
 messenger time disable
#
local-user backbone
 password cipher ewenxlf
 service-type ssh telnet
 level 3
#
 stp instance 1 root primary
 stp instance 2 root secondary
 stp TC-protection enable
 stp enable
stp region-configuration
 region-name fuda
 instance 1 vlan 100 200
 instance 2 vlan 300 400
 active region-configuration
#
acl number 3000
 rule 10 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
 rule 20 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
 rule 100 permit ip
acl number 3001
 rule 10 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
 rule 20 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
 rule 100 permit ip
acl number 3002
 rule 10 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
 rule 100 permit ip
#
vlan 1
#
vlan 88
 de.ion to_F100_M
#
vlan 100
 de.ion xingzheng
 name xingzheng
#
vlan 200
 de.ion changqu
 name changqu
#
vlan 300
 de.ion sushe
 name sushe
#                                        
vlan 400
 de.ion netbar
 name netbar
#
interface Vlan-interface88
 ip address 192.168.0.252 255.255.255.0
#
interface Vlan-interface100
 ip address 192.168.1.254 255.255.255.0
 vrrp vrid 1 virtual-ip 192.168.1.1
 vrrp vrid 1 priority 120
 vrrp vrid 1 preempt-mode timer delay 1
#
interface Vlan-interface200
 ip address 192.168.2.254 255.255.255.0
 vrrp vrid 2 virtual-ip 192.168.2.1
 vrrp vrid 2 priority 120
 vrrp vrid 2 preempt-mode timer delay 1
#
interface Vlan-interface300
 ip address 192.168.3.254 255.255.255.0
 vrrp vrid 3 virtual-ip 192.168.3.1
 vrrp vrid 3 preempt-mode timer delay 1  
#
interface Vlan-interface400
 ip address 192.168.4.254 255.255.255.0
 vrrp vrid 4 virtual-ip 192.168.4.1
 vrrp vrid 4 preempt-mode timer delay 1
#
interface Aux0/0/0
#
interface M-Ethernet0/0/0
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet1/0/1
#
interface GigabitEthernet1/0/2
#
interface GigabitEthernet1/0/3           
#
interface GigabitEthernet1/0/4
#
interface GigabitEthernet1/0/5
#
interface GigabitEthernet1/0/6
#
interface GigabitEthernet1/0/7
#
interface GigabitEthernet1/0/8
#
interface GigabitEthernet1/0/9
 de.ion to_S7502_9
 port link-type trunk
 port trunk permit vlan 1 100 200 300 400
#
interface GigabitEthernet1/0/10
 de.ion to_changqu
 port access vlan 200
 qos
 packet-filter inbound ip-group 3001 rule 10 system-index 58
 packet-filter inbound ip-group 3001 rule 20 system-index 59
 packet-filter inbound ip-group 3001 rule 100 system-index 60
#
interface GigabitEthernet1/0/11
 de.ion to_sushe
 port access vlan 300
 qos
 packet-filter inbound ip-group 3002 rule 10 system-index 61
 packet-filter inbound ip-group 3002 rule 100 system-index 62
#
interface GigabitEthernet1/0/12
 de.ion to_netbar
 port access vlan 400
#
interface GigabitEthernet1/0/13
#
interface GigabitEthernet1/0/14
#
interface GigabitEthernet1/0/15
#
interface GigabitEthernet1/0/16
#
interface GigabitEthernet1/0/17
#                                        
interface GigabitEthernet1/0/18
#
interface GigabitEthernet1/0/19
#
interface GigabitEthernet1/0/20
#
interface GigabitEthernet2/0/1
 stp disable
 port access vlan 88
#
interface GigabitEthernet2/0/2
 port access vlan 100
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 1
 packet-filter inbound ip-group 3000 rule 20 system-index 2
 packet-filter inbound ip-group 3000 rule 100 system-index 3
#
interface GigabitEthernet2/0/3
 port access vlan 100
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 4
 packet-filter inbound ip-group 3000 rule 20 system-index 5
 packet-filter inbound ip-group 3000 rule 100 system-index 6
#
interface GigabitEthernet2/0/4
 port access vlan 100
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 7
 packet-filter inbound ip-group 3000 rule 20 system-index 8
 packet-filter inbound ip-group 3000 rule 100 system-index 9
#
interface GigabitEthernet2/0/5
 port access vlan 100
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 10
 packet-filter inbound ip-group 3000 rule 20 system-index 11
 packet-filter inbound ip-group 3000 rule 100 system-index 12
#
interface GigabitEthernet2/0/6
 port access vlan 100
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 13
 packet-filter inbound ip-group 3000 rule 20 system-index 14
 packet-filter inbound ip-group 3000 rule 100 system-index 15
#                                        
interface GigabitEthernet2/0/7
 port access vlan 100
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 16
 packet-filter inbound ip-group 3000 rule 20 system-index 17
 packet-filter inbound ip-group 3000 rule 100 system-index 18
#
interface GigabitEthernet2/0/8
 port access vlan 100
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 19
 packet-filter inbound ip-group 3000 rule 20 system-index 20
 packet-filter inbound ip-group 3000 rule 100 system-index 21
#
interface GigabitEthernet2/0/9
stp edged-port enable  边缘口设置
 port access vlan 100
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 22
 packet-filter inbound ip-group 3000 rule 20 system-index 23
 packet-filter inbound ip-group 3000 rule 100 system-index 24
#
interface GigabitEthernet2/0/10          
 port access vlan 100
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 25
 packet-filter inbound ip-group 3000 rule 20 system-index 26
 packet-filter inbound ip-group 3000 rule 100 system-index 27
#
interface GigabitEthernet2/0/11
 port access vlan 100
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 28
 packet-filter inbound ip-group 3000 rule 20 system-index 29
 packet-filter inbound ip-group 3000 rule 100 system-index 30
#
interface GigabitEthernet2/0/12
 stp disable
 port access vlan 88
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 31
 packet-filter inbound ip-group 3000 rule 20 system-index 32
 packet-filter inbound ip-group 3000 rule 100 system-index 33
#
interface GigabitEthernet2/0/13          
 port access vlan 100
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 34
 packet-filter inbound ip-group 3000 rule 20 system-index 35
 packet-filter inbound ip-group 3000 rule 100 system-index 36
#
interface GigabitEthernet2/0/14
 port access vlan 200
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 37
 packet-filter inbound ip-group 3000 rule 20 system-index 38
 packet-filter inbound ip-group 3000 rule 100 system-index 39
#
interface GigabitEthernet2/0/15
 port access vlan 100
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 40
 packet-filter inbound ip-group 3000 rule 20 system-index 41
 packet-filter inbound ip-group 3000 rule 100 system-index 42
#
interface GigabitEthernet2/0/16
 port access vlan 100                    
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 43
 packet-filter inbound ip-group 3000 rule 20 system-index 44
 packet-filter inbound ip-group 3000 rule 100 system-index 45
#
interface GigabitEthernet2/0/17
 port access vlan 100
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 46
 packet-filter inbound ip-group 3000 rule 20 system-index 47
 packet-filter inbound ip-group 3000 rule 100 system-index 48
#
interface GigabitEthernet2/0/18
 port access vlan 100
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 49
 packet-filter inbound ip-group 3000 rule 20 system-index 50
 packet-filter inbound ip-group 3000 rule 100 system-index 51
#
interface GigabitEthernet2/0/19
 port access vlan 100
 qos                                     
 packet-filter inbound ip-group 3000 rule 10 system-index 52
 packet-filter inbound ip-group 3000 rule 20 system-index 53
 packet-filter inbound ip-group 3000 rule 100 system-index 54
#
interface GigabitEthernet2/0/20
 port access vlan 100
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 55
 packet-filter inbound ip-group 3000 rule 20 system-index 56
 packet-filter inbound ip-group 3000 rule 100 system-index 57
#
interface NULL0
#
 ip route-static 0.0.0.0 0.0.0.0 192.168.0.1 preference 60
#
user-interface aux 0
 authentication-mode password
 set authentication password   xxxxxxx
user-interface vty 0 4
 authentication-mode scheme
------------------------------------------------------------------------------------------------------------- [S7502]dis ver
H3C Comware Platform Software
Comware software, Version 3.10, Release 3135
Copyright (c) 2004-2007 Hangzhou H3C Technologies Co., Ltd. All rights reserved.
H3C S7502 uptime is 0 week, 0 day, 22 hours, 17 minutes

P12TE 0:  uptime is 0 weeks,0 days,22 hours,17 minutes
H3C S7500 with 1 MPC8245 Processor
256M    bytes SDRAM
32768K  bytes Flash Memory
0K      bytes NVRAM Memory
PCB Version      :   VER.B
BootROM Version  :   531
CPLD Version     :   005
Second CPLD Ver  :   005
Software Version :   S7502-3135
Patch Version    :   None
  [S7502]dis cur
#
 sysname S7502
#
 super password level 3 cipher PLP0V73A)D[Q=^Q`MAF4<1!!
#
 local-server nas-ip 127.0.0.1 key h3c
#
 domain default enable system
#
 temperature-limit 0 10 70
#
 poe power max-value 2400
#
radius scheme system
 primary authentication 127.0.0.1 1645
 primary accounting 127.0.0.1 1646
 user-name-format without-domain
#
domain system
 vlan-assignment-mode integer
 access-limit disable
 state active
 idle-cut disable
 self-service-url disable                
 messenger time disable
#
local-user backbone
 password cipher backboneewenxlf
 service-type ssh telnet
 level 3
#
 stp instance 1 root secondary
 stp instance 2 root primary
 stp TC-protection enable
 stp enable
stp region-configuration
 region-name fuda
 instance 1 vlan 100 200
 instance 2 vlan 300 400
 active region-configuration
#
acl number 3000
 rule 10 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
 rule 20 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
 rule 100 permit ip
acl number 3001
 rule 10 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
 rule 20 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
 rule 100 permit ip
#
vlan 1
#
vlan 88
#
vlan 100
 de.ion to_xingzheng
 name xingzheng
#
vlan 200
 de.ion to_changqu
 name changqu
#
vlan 300
 de.ion to_sushe
 name sushe
#
vlan 400
 de.ion to_netbar
 name netbar
#                                        
interface Vlan-interface88
 ip address 192.168.0.253 255.255.255.0
#
interface Vlan-interface100
 ip address 192.168.1.253 255.255.255.0
 vrrp vrid 1 virtual-ip 192.168.1.1
 vrrp vrid 1 preempt-mode timer delay 1
#
interface Vlan-interface200
 ip address 192.168.2.253 255.255.255.0
 vrrp vrid 2 virtual-ip 192.168.2.1
 vrrp vrid 2 preempt-mode timer delay 1
#
interface Vlan-interface300
 ip address 192.168.3.253 255.255.255.0
 vrrp vrid 3 virtual-ip 192.168.3.1
 vrrp vrid 3 priority 120
 vrrp vrid 3 preempt-mode timer delay 1
#
interface Vlan-interface400
 ip address 192.168.4.253 255.255.255.0
 vrrp vrid 4 virtual-ip 192.168.4.1      
 vrrp vrid 4 priority 120
 vrrp vrid 4 preempt-mode timer delay 1
#
interface Aux0/0/0
#
interface M-Ethernet0/0/0
#
interface GigabitEthernet0/0/1
 stp disable
 port access vlan 88
#
interface GigabitEthernet0/0/2
 port access vlan 200
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#                                        
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
 port link-type trunk
 port trunk permit vlan 1 100 200 300 400
#
interface GigabitEthernet0/0/10
 de.ion to_changqu
 port access vlan 200
 qos
 packet-filter inbound ip-group 3000 rule 10 system-index 1
 packet-filter inbound ip-group 3000 rule 20 system-index 2
 packet-filter inbound ip-group 3000 rule 100 system-index 3
#
interface GigabitEthernet0/0/11
 de.ion to_sushe
 port access vlan 300
 qos
 packet-filter inbound ip-group 3001 rule 10 system-index 4
 packet-filter inbound ip-group 3001 rule 20 system-index 5
 packet-filter inbound ip-group 3001 rule 100 system-index 6
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface NULL0
#
 ip route-static 0.0.0.0 0.0.0.0 192.168.0.1 preference 60
#
user-interface aux 0
 set authentication password xxxxxx
user-interface vty 0 4
 authentication-mode scheme
#
return
   

本文出自 “我是木头” 博客,请务必保留此出处http://infotech.blog.51cto.com/391844/123868