sw1vrfvlan batch 401 402int g 0/0/3po li t po t all vlan 401 402int g 0/0/4po t all vlan 401 402int v 401ip banding vpn-instance vrfip ad 10.40.1.1 24vrrp vrid 1 virtual-ip 10.40.1.100vrrp vrid 1 priority 120vrrp vrid 1 preempt-mode timer delay 60vrrp vrid 1 track int g 0/0/3 reduced 30int v 402ip banding vpn-instance vrfip ad 10.40.2 .1 24vrrp vrid 2 virtual-ip 10.40.2.100publicvlan batch 403 404int g 0/0/1po li tpo t all vlan 403 404int g 0/0/2po li tpo t all vlan 403 404int v 403ip ad 10.40.3.1 24vrrp vrid 3 virtual-ip 10.40.3.100vrrp vrid 3 priority 120vrrp vrid 3 preempt-mode timer delay 60int v 404ip ad 10.40.4.1 24vrrp vrid 4 virtual-ip 10.40.4.100路由配置IP route-static vpn-instance vrf 0.0.0.0 0 10.40.1.200IP route-static vpn-instance vrf 0.0.0.0 0 10.40.2.200 preference 70ip route-static 192.168.0.0 16 10.40.3.200ip route-static 192.168.0.0 16 10.40.4.200 preference 70
sw2publicvlan batch 403 404int g 0/0/1po li tpo t all vlan 403 404int g 0/0/2po li tpo t all vlan 403 404int v 403ip ad 10.40.3.2 24vrrp vrid 3 virtual-ip 10.40.3.100int v 404ip ad 10.40.4.2 24vrrp vrid 4 virtual-ip 10.40.4.100vrrp vrid 4 priority 120vrrp vrid 4 preempt-mode timer delay 60vrrp vrid 4 track interface g 0/0/1 reduced 30vrfvlan batch 401 402int g 0/0/3po li t po t all vlan 401 402int g 0/0/4po lin tpo t all vlan 401 402int v 401ip banding vpn-instance vrfip ad 10.40.1.2 24vrrp vrid 1 virtual-ip 10.40.1.100int v 402ip banding vpn-instance vrfip ad 10.40.2 .2 24vrrp vrid 2 virtual-ip 10.40.2.100vrrp vrid 2 priority 120vrrp vrid 2 preempt-mode timer delay 60vrrp vrid 2 track interace g 0/0/3 reduced 30路由配置IP route-static vpn-instance vrf 0.0.0.0 0 10.40.2.200IP route-static vpn-instance vrf 0.0.0.0 0 10.40.1.200 preference 70ip route-static 192.168.0.0 16 10.40.4.200ip route-static 192.168.0.0 16 10.40.3.200 preference 70
fw1vlan batch 401 402 403 404interface virtual-templateint g 1/0/0ip ad 10.10.10.1 30interface g 1/0/2.401ip ad 10.40.1.10 24vlan-type dotlq 401int g 1/0/2 .402ip ad 10.40.2.10 24vlan-type dotlq 402int g 1/0/3.403ip ad 10.40.3.10 24vlan-type dotlq 403int g 1/0/3.404ip ad 10.40.4.10 24vlan-type dotlq 404firewall zone trustadd int g 1/0/2.401add int g 1/0/2.402firewall zone untrustadd int g 1/0/3.403add int g 1/0/3.404firewall zone dmzadd int g 1/0/0双机热备int g 1/0/2.401vrrp vrid 5 virtual-ip 10.40.1.200 activeint g 1/0/2.402vrrp vrid 6 virtual-ip 10.40.2.200 standbyint g 1/0/3.403vrrp vrid 7 virtual-ip 10.40.3.200 activeint g 1/0/3.404vrrrp vrid 8 virtual-ip 10.40.4.200 standbyhrp mrror session enable快速备份hrp interface g 1/0/0 remote 10.10.10.2定义心跳线与对端IPhrp enable路由配置IP route-static 0.0.0.0 0 10.40.3.100IP route-static 0.0.0.0 0 10.40.4.100 preference 70ip route-static 192.168.0.0 16 10.40.1.100ip route-static 192.168.0.0 16 10.40.2.100 preference 70安全策略security-policyrule name t_to_usouce-zone trustdestination-zone untrustsouce-addess 192.168.0.0 16action permitdis security -policy rule all显示所有策略激活接口int g 1/0/2ip ad 1.1.1.1 24undo ip adint g 1/0/3ip ad 1.1.1.1 24undo ip ad
fw2vlan batch 401 402 403 404interface virtual-template待定int g 1/0/0ip ad 10.10.10.2 30interface g 1/0/2.401ip ad 10.40.1.20 24vlan-type dotlq 401int g 1/0/2 .402ip ad 10.40.2.20 24vlan-type dotlq 402int g 1/0/3.403ip ad 10.40.3.20 24vlan-type dotlq 403int g 1/0/3.404ip ad 10.40.4.20 24vlan-type dotlq 404firewall zone trustadd int g 1/0/2.401add int g 1/0/2.402firewall zone untrustadd int g 1/0/3.403add int g 1/0/3.404firewall zone dmzadd int g 1/0/0双机热备int g 1/0/2.401vrrp vrid 5 virtual-ip 10.40.1.200 standbyint g 1/0/2.402vrrp vrid 6 virtual-ip 10.40.2.200 avtiveint g 1/0/3.403vrrp vrid 7 virtual-ip 10.40.3.200 standbyint g 1/0/3.404vrrrp vrid 8 virtual-ip 10.40.4.200 activehrp mrror session enable快速备份hrp interface g 1/0/0 remote 10.10.10.1定义心跳线与对端IPhrp enable路由配置IP route-static 0.0.0.0 0 10.40.4.100IP route-static 0.0.0.0 0 10.40.3.100 preference 70ip route-static 192.168.0.0 16 10.40.2.100ip route-static 192.168.0.0 16 10.40.1.100 preference 70激活接口int g 1/0/2ip ad 1.1.1.1 24undo ip adint g 1/0/3ip ad 1.1.1.1 24undo ip ad
sw1vlan batch 201 105int g 0/0/7po lin accpo default vlan 105undo stp enableint g 0/0/2po t all vlan 201undo stp enableint v 105ip ad 10.10.5.1 24int v 201 ip ad 10.20.1.1 24ospf 2 route-id 1.1.1.1area 0network 10.20.1.1 0.0.0.0network 10.10.5.1 0.0.0.0ospf 2import-route static
sw2vlan batch 201 206int g 0/0/7po lin accpo default vlan 206undo stp enableint g 0/0/2po t all vlan 201undo stp enableint v 206ip ad 10.20.6.2 24int v 201 ip ad 10.20.1.2 24ospf 2 route-id 2.2.2.2area 0network 10.20.1.2 0.0.0.0network 10.20.6.2 0.0.0.0ospf 1default-route-advertise--------下放路由ospf 2import-route static-------导入静态路由
r5int g 0/0/0ip ad 10.10.5.5 24int g 0/0/1ip ad 10.56.0.5 24ospf 1 route-id 5.5.5.5area 0network 10.56.0.5 0.0.0.0network 10.10.5.5 0.0.0.0int g 0/0/2ip ad 12.0.0.5 24ip route-static 0.0.0.0 0 12.0.0.100ospf 1default-route-advertiseacl 2000rule permit souce 192.168.0.0 0.0.255.255int g 0/0/2nat outbound 2000
r6int g 0/0/0ip ad 10.20.6.6 24int g 0/0/1ip ad 10.56.0.6 24ospf 1 route-id 6.6.6.6aera 0 nerwork 10.56.0.6 0.0.0.0network 10.20.6.6 0.0.0.0int g 0/0/2ip ad 13.0.0.6 24ip route-static 0.0.0.0 0 13.0.0.100ospf 1default-route-advertiseacl 2000rule permit souce 192.168.0.0 0.0.255.255int g 0/0/2nat outbound 2000
ispint g 0/0/0ip ad 12.0.0.100 24int g 0/0/1ip ad 13.0.0.100 24interface loopback 0ip ad 100.1.1 24