免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 3215 | 回复: 2

(已解决!)分支机构互联网统一出口网络配置疑问? [复制链接]

论坛徽章:
0
发表于 2013-01-14 09:14 |显示全部楼层
本帖最后由 xy-coordinate 于 2013-01-15 15:20 编辑

H3C UTM200
5个以太口
2条100M 互联网出口

部门:5个
机构:10个

H3C S3600 3层交换机
10个机构由MSTP网络 光纤汇集到 S3600
5个部门接在S3600 以太口

H3C UTM200
#
acl number 2000
rule 15 permit source 192.168.100.0 0.0.0.255
rule 20 permit source 192.168.201.0 0.0.0.255
rule 25 permit source 192.168.202.0 0.0.0.255
rule 30 permit source 192.168.203.0 0.0.0.255
rule 35 permit source 192.168.204.0 0.0.0.255
rule 1000 deny
acl number 2001
rule 5 permit source 192.168.101.0 0.0.0.255
rule 10 permit source 192.168.102.0 0.0.0.255
rule 15 permit source 192.168.103.0 0.0.0.255
rule 20 permit source 192.168.104.0 0.0.0.255
rule 25 permit source 192.168.105.0 0.0.0.255
rule 30 permit source 192.168.106.0 0.0.0.255
rule 35 permit source 192.168.107.0 0.0.0.255
rule 40 permit source 192.168.108.0 0.0.0.255
rule 45 permit source 192.168.109.0 0.0.0.255
rule 50 permit source 192.168.110.0 0.0.0.255
rule 1000 deny
#
#
interface GigabitEthernet0/1
port link-mode route
nat outbound 2000
ip address 158.43.114.226 255.255.255.248
#
interface GigabitEthernet0/2
port link-mode route
nat outbound 2001
ip address 136.132.162.18 255.255.255.248
#
interface GigabitEthernet0/3
port link-mode route
ip address 192.168.101.1 255.255.255.0
ip address 192.168.102.1 255.255.255.0 sub
ip address 192.168.104.1 255.255.255.0 sub
ip address 192.168.105.1 255.255.255.0 sub
ip address 192.168.106.1 255.255.255.0 sub
ip address 192.168.107.1 255.255.255.0 sub
ip address 192.168.108.1 255.255.255.0 sub
ip address 192.168.109.1 255.255.255.0 sub
ip address 192.168.110.1 255.255.255.0 sub
ip policy-based-route 1    //*UTM不能做双出口负载均衡,不过可以做指定出口
#
interface GigabitEthernet0/4
port link-mode route
ip address 192.168.100.1 255.255.255.0
ip address 192.168.201.1 255.255.255.0 sub
ip address 192.168.202.1 255.255.255.0 sub
ip address 192.168.203.1 255.255.255.0 sub
ip address 192.168.204.1 255.255.255.0 sub
#

#
policy-based-route 1 permit node 10
   if-match acl 2001
   apply ip-address next-hop 136.132.162.17

#
ip route-static 0.0.0.0 0.0.0.0 158.43.114.225    //*不能再写1条到136.132.162.17得缺省路由,可以做指定出口
#
部门使用1条100M出口,机构使用1条100M出口

现在,网络通畅,但是分支机构网络没有固定,任一机构都能配置192.168.101.0或者192.168.102.0……,想每个机构固定一个网段,如何配置?
机构可以将HUB更换成TP-LINK路由器。
              
截图1358126184.jpg

论坛徽章:
0
发表于 2013-01-15 15:09 |显示全部楼层
本帖最后由 xy-coordinate 于 2013-01-15 15:32 编辑

UTM web配置界面

UTM web配置界面
UTM200 某一以太口配置vlan或者起子接口
#
interface GigabitEthernet0/3.1
vlan-type dot1q vid 101
ip address 192.168.101.1 255.255.255.0
#
interface GigabitEthernet0/3.2
vlan-type dot1q vid 102
ip address 192.168.102.1 255.255.255.0
#

+++++++++++++++++++++++++++++++
#
interface GigabitEthernet0/3
port link-mode bridge
port link-type trunk
port trunk permit vlan all
#

vlan 101
interface vlan101
ip address 192.168.101.1 255.255.255.0

vlan 102
interface vlan102
ip address 192.168.102.1 255.255.255.0
......
+++++++++++++++++++++++++++++++

注意:UTM还必须在WEB界面,设备管理——安全域——添加vlan或者子接口 到 trust域,否则下联交换机接收相应配置

论坛徽章:
0
发表于 2013-01-16 10:19 |显示全部楼层
单臂路由的做法啊,不错

也可以考虑在s3600起三层vlan,就是hub得换了
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP