
//配置VLAN和接口
vlan 10
name XXXX
vlan 20
name XXXX
vlan 30
name XXXX
interface Gigabitetherent 0/x(配置城域网上行口)
ip address 61.X.X.X 255.255.255.252
description XXXX
interface Gigabitetherent 0/x(配置CN2网上行口)
ip address X.X.X.X X.X.X.X
description XXXX
ip nat outside
interface Gigabitetherent 0/x(配置DCN网上行口)
ip address 134.132.10.X 255.255.255.248
description XXXX
ip nat outside
interface range Gigabitetherent 0/x – y
switchport mode trunk
switchport trunk encapsulation dot1q(这是用来打掉由二层上来的tag头的,这样从这个端口出去的包就不带tag头了,ip包)
switchport trunk allowed vlan 10,20
interface range Gigabitetherent 0/x – y
switchport mode access(access(普通模式)?只能加到某个vlan中)
switchport aceess vlan 30
interface Vlan 10(配置城域网下行子接口)
ip address 218.85.154.X X.X.X.X
description XXXX
interface Vlan 20(配置CN2/DCN网下行子接口)
ip address 192.168.1.X X.X.X.X
description XXXX
ip nat inside
interface Vlan 30(配置子系统下行口)
ip address 218.85.154.X 255.255.255.240
description XXXX
interface Loopback 0(配置环回口)
ip address X.X.X.X X.X.X.X
description XXXX
interface Gigabitetherent 0/x(配置与备路由器间接口)
switchport mode trunk
switchport trunk encapsulation dot1q
//配置生成树
spanning-tree mode rstp
spanning-tree vlan 10 priority 0
spanning-tree vlan 20 priority 0
spanning-tree vlan 30 priority 0
//配置静态路由:
ip route X.X.X.X X.X.X.X next-hop 134.132.10.X(配置到DCN网的静态路由)
ip route X.X.X.X X.X.X.X next-hop X.X.X.X(配置到备路由器环回口的静态路由)
//配置BGP路由协议:(与CN2、城域网之间运行BGP)
router bgp XX
no auto-summary
no synchronization
bgp router-id X.X.X.X
neighbor X.X.X.X remote-as YY(配置EBGP邻居)
neighbor X.X.X.X update-source Loopback0
neighbor X.X.X.X ebgp-multihop 255
neighbor X.X.X.X remote-as XX(配置IBGP邻居)
neighbor X.X.X.X update-source Loopback0
network X.X.X.X mask X.X.X.X(通告本AS内部城域网部分网络)
//配置NAT转换
ip nat pool XX X.X.X.X X.X.X.X netmask X.X.X.X(配置CN2网地址池)
ip access-list extend XX
permit ip X.X.X.X X.X.X.X X.X.X.X X.X.X.X
ip nat inside source list XX pool XX overload
ip nat inside source static X.X.X.X X.X.X.X(根据实际情况逐条配置CN2网静态地址映射)
ip nat pool YY X.X.X.X X.X.X.X netmask X.X.X.X(配置DCN网地址池)
ip access-list extend YY
permit ip X.X.X.X X.X.X.X X.X.X.X X.X.X.X
ip nat inside source list YY pool YY overload
ip nat inside source static X.X.X.X X.X.X.X(根据实际情况逐条配置DCN网静态地址映射)
//配置VRRP
interface Vlan 10(配置城域网下行子接口)
vrrp 10 ip 218.85.154.X
vrrp 10 priority 15
0
vrrp 10 preempt
interface Vlan 20(配置CN2/DCN网下行子接口)
vrrp 20 ip 192.168.1.X
vrrp 20 priority 150
vrrp 20 preempt
interface Vlan 30(配置子系统下行口)
vrrp 30 ip 218.85.154.X
vrrp 30 priority 150
vrrp 30 preempt
//配置Syslog
logging on
logging ip-address-server X.X.X.X(地址更改为soc采集地址)
logging facility local7(事件级别根据soc平台要求定义)
logging trap warning
logging source-interface loopback0
service timestamps log datetime
