接口策略路由(接口策略路由与bfd)

网友投稿 355 2022-09-19


接口策略路由(接口策略路由与bfd)

接口策略路由配置:通过流策略技术实现

流策略:将流分类和流行为关联,就是流策略,形成了“模板化”配置方式,最大优点是可以节省配置,支持批量修改。

traffic classifier:用if-match语句设定流分类的匹配规则

traffic Behavior:执行动作,例如重标记、重定向、负载分担、报文分片、流量限速、流量统计等等

traffic policy:将流分类和流行为关联,应用到流量的​入接口

​​策略配置:​

第一步:配置访问控制列表

acl number​ 3001​

第二步:流分类和流行为

traffic classifier ​control1

if-match acl

traffic Behavior ​control1

​​第三步:流策略

traffic policy control1

第四步:端口应用

interface gigabitethernet 0/0/0

traffic-policy ​control1 inbound​

instance:

display current-configuration [V200R003C00]

sysname r1

snmp-agent local-engineid 800007DB03000000000000 snmp-agent

clock timezone China-Standard-Time minus 08:00:00

portal local-server load portalpage.zip

drop illegal-mac alarm

set cpu-usage threshold 80 restore 75

aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$ local-user admin service-type zone Local priority 15

interface GigabitEthernet0/0/0 ip address 10.1.1.1 255.255.255.252

interface GigabitEthernet0/0/1 ip address 10.1.2.1 255.255.255.252

interface GigabitEthernet0/0/2 ip address 10.1.3.1 255.255.255.252

interface NULL0

interface LoopBack0 ip address 1.1.1.1 255.255.255.255

ospf 1 router-id 1.1.1.1 area 0.0.0.0 network 10.1.1.0 0.0.0.3 network 10.1.2.0 0.0.0.3 network 10.1.3.0 0.0.0.3

user-interface con 0 authentication-mode passworduser-interface vty 0 4user-interface vty 16 20

wlan ac

return​​R1​

display current-configuration [V200R003C00]

sysname r2

snmp-agent local-engineid 800007DB03000000000000 snmp-agent

clock timezone China-Standard-Time minus 08:00:00

portal local-server load portalpage.zip

drop illegal-mac alarm

set cpu-usage threshold 80 restore 75

acl number 3001 rule 5 permit ip source 10.1.1.0 0.0.0.255 destination 13.1.1.0 0.0.0.255 acl number 3002 rule 5 permit ip source 10.1.2.0 0.0.0.255 destination 13.1.1.0 0.0.0.255

traffic classifier control1 operator or if-match acl 3001traffic classifier control2 operator or if-match acl 3002

traffic behavior control1 redirect ip-nexthop 11.1.1.2traffic behavior control2 redirect ip-nexthop 12.1.1.2

traffic policy control1 classifier control1 behavior control1 classifier control2 behavior control2traffic policy control2 classifier control2 behavior control2

aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$ local-user admin service-type zone Local priority 15

interface GigabitEthernet0/0/0 ip address 10.1.3.2 255.255.255.252 traffic-policy control1 inbound

interface GigabitEthernet0/0/1 ip address 11.1.1.1 255.255.255.252

interface GigabitEthernet0/0/2 ip address 12.1.1.1 255.255.255.252

interface NULL0

interface LoopBack0 ip address 2.2.2.2 255.255.255.255

ospf 1 router-id 2.2.2.2 area 0.0.0.0 network 10.1.3.0 0.0.0.3 network 11.1.1.0 0.0.0.3 network 12.1.1.0 0.0.0.3

user-interface con 0 authentication-mode passworduser-interface vty 0 4user-interface vty 16 20

wlan ac

return​​

display current-configuration [V200R003C00]

sysname r3

snmp-agent local-engineid 800007DB03000000000000 snmp-agent

clock timezone China-Standard-Time minus 08:00:00

portal local-server load portalpage.zip

drop illegal-mac alarm

set cpu-usage threshold 80 restore 75

aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$ local-user admin service-type zone Local priority 15

interface GigabitEthernet0/0/0 ip address 11.1.1.2 255.255.255.252

interface GigabitEthernet0/0/1 ip address 11.1.2.1 255.255.255.252

interface GigabitEthernet0/0/2

interface NULL0

interface LoopBack0 ip address 3.3.3.3 255.255.255.255

ospf 1 router-id 3.3.3.3 area 0.0.0.0 network 11.1.1.0 0.0.0.3 network 11.1.2.0 0.0.0.3

user-interface con 0 authentication-mode passworduser-interface vty 0 4user-interface vty 16 20

wlan ac

return​​

display current-configuration [V200R003C00]

sysname r4

snmp-agent local-engineid 800007DB03000000000000 snmp-agent

clock timezone China-Standard-Time minus 08:00:00

portal local-server load portalpage.zip

drop illegal-mac alarm

set cpu-usage threshold 80 restore 75

aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$ local-user admin service-type zone Local priority 15

interface GigabitEthernet0/0/0 ip address 12.1.1.2 255.255.255.252

interface GigabitEthernet0/0/1 ip address 12.1.2.1 255.255.255.252

interface GigabitEthernet0/0/2

interface NULL0

interface LoopBack0 ip address 4.4.4.4 255.255.255.255

ospf 1 router-id 4.4.4.4 area 0.0.0.0 network 12.1.1.0 0.0.0.3 network 12.1.2.0 0.0.0.3

user-interface con 0 authentication-mode passworduser-interface vty 0 4user-interface vty 16 20

wlan ac

return​​

display current-configuration [V200R003C00]

sysname r5

snmp-agent local-engineid 800007DB03000000000000 snmp-agent

clock timezone China-Standard-Time minus 08:00:00

portal local-server load portalpage.zip

drop illegal-mac alarm

set cpu-usage threshold 80 restore 75

aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$ local-user admin service-type zone Local priority 15

interface GigabitEthernet0/0/0 ip address 12.1.2.2 255.255.255.252

interface GigabitEthernet0/0/1 ip address 11.1.2.2 255.255.255.252

interface GigabitEthernet0/0/2 ip address 13.1.1.1 255.255.255.252

interface NULL0

interface LoopBack0 ip address 5.5.5.5 255.255.255.255

ospf 1 router-id 5.5.5.5 area 0.0.0.0 network 11.1.2.0 0.0.0.3 network 12.1.2.0 0.0.0.3 network 13.1.1.0 0.0.0.3

user-interface con 0 authentication-mode passworduser-interface vty 0 4user-interface vty 16 20

wlan ac

return​​


版权声明:本文内容由网络用户投稿,版权归原作者所有,本站不拥有其著作权,亦不承担相应法律责任。如果您发现本站中有涉嫌抄袭或描述失实的内容,请联系我们jiasou666@gmail.com 处理,核实后本网站将在24小时内删除侵权内容。

上一篇:思科 3850交换机升级实战 3.X版本升级到16.X几版本
下一篇:Java 线程池全面总结与详解
相关文章

 发表评论

暂时没有评论,来抢沙发吧~