路由器R1故障及恢复全过程时捕捉到的示意图。PC1在ping网关时发生丢包,之后通信又恢复正常,这是由于R1掉线之后R2的两个虚拟备份组虚拟端口状态由一主一备变成两个都是主,这一变化过程中发生短暂丢包现象,待变化完成之后,通信又恢复正常。
到此,用H3C网络设备模拟双出口网络的主要部分实训内容介绍完毕。
19.7.5选用神州数码网络设备的实现步骤和方法
若采用神州数码网络设备,其配置实现如下。
1.设备选用表
2.两台路由器冗余备份链路部分的主要配置
(1)第一台路由器配置
Welcome to DCR Multi-Protocol1751Series
Router>
Router>enable
Router#2004-1-100∶13:00UnknoWn user enter priVilege mode from console0,leVel=15
Router#config t
Router_config#hostname R1
R1_config#interface e0/0
interface e0/0
^
UnknoWn command
R1_config#interface f0/0
R1_config_f0/0#ip address192.168.0.254255.255.255.0
R1_config_f0/0#no shutdoWn
R1_config_f0/0#Vrrp ?
<0-255>——VRRP Group ID
associate——Config VRRP group Virtual IP
deion——Config VRRP group deion string
priority——Config VRRP group priority leVel
preempt——Config VRRP group preempt
track——Config VRRP group priority track
authentication——Config VRRP group authentication string
timers——Config VRRP group timer
R1_config_f0/0#Vrrp10?
associate——Config VRRP group Virtual IP
deion——Config VRRP group deion string
priority——Config VRRP group priority leVel
preempt——Config VRRP group preempt
track——Config VRRP group priority track
authentication——Config VRRP group authentication string
timers——Config VRRP group timer
R1_config_f0/0#Vrrp10associate ?
A.B.C.D——VRRP Group Virtual address
< cr>
R1_config_f0/0#Vrrp10associate192.168.0.1?
A.B.C.D——VRRP Group Virtual netmask
R1_config_f0/0#Vrrp10associate192.168.0.1255.255.255.0?
secondary——VRRP Group Virtual secondary address
< cr>
R1_config_f0/0#Vrrp10associate192.168.0.1255.255.255.0
R1_config_f0/0#Vrrp20associate192.168.0.2255.255.255.0
R1_config_f0/0#Vrrp10priority ?
<1-254>——Priority Value
R1_config_f0/0#Vrrp10priority105 ?
< cr>
R1_config_f0/0#Vrrp10priority105
R1_config_f0/0#Vrrp20priority100
R1_config_f0/0#exit
R1_config#exit
R1#2004-1-100∶19∶16Configured from console0by UNKNOWN
R1#shoW Vrrp ?
interface——ShoW VRRP protocol information of interface
brief——ShoW VRRP brief protocol information
detail——ShoW all VRRP group protocol information
< cr>
R1#
R1#2004-1-100∶21:56Line on Interface FastEthernet0/0,changed state to up
2004-1-100∶21:56Line protocol on Interface FastEthernet0/0,changed state to u
p
R1#shoW Vrrp brief
Interface Grp Prio Pree State Master addr Virtual addr
f0/010105Y Master192.168.0.254192.168.0.1
f0/020100Y Master192.168.0.254192.168.0.2
(2)第二台路由器配置
Welcome to DCR Multi-Protocol1700Series
Router>
Router>enable
Router#2004-1-100∶25∶14UnknoWn user enter priVilege mode from console0,leVel=15
Router#
Router#hostname R2
hostname R2
^
UnknoWn command
Router#config t
Router_config#hostname R2
R2_config#int f0/0
R2_config_f0/0#ip add192.168.0.253255.255.255.0
R2_config_f0/0#no shut
R2_config_f0/0#Vrrp10?
associate——Config VRRP group Virtual IP
deion——Config VRRP group deion string
priority——Config VRRP group priority leVel
preempt——Config VRRP group preempt
track——Config VRRP group priority track
authentication——Config VRRP group authentication string
timers——Config VRRP group timer
R2_config_f0/0#Vrrp10associate192.168.0.1255.255.255.0?
secondary——VRRP Group Virtual secondary address
< cr>
R2_config_f0/0#Vrrp10associate192.168.0.1255.255.255.0
R2_config_f0/0#Vrrp20associate192.168.0.2255.255.255.0
R2_config_f0/0#Vrrp10priority105 ?
< cr>
R2_config_f0/0#Vrrp10priority105
R2_config_f0/0#Vrrp10priority100
R2_config_f0/0#Vrrp20priority150
R2_config_f0/0#2004-1-100∶28:05 %Warning:Duplicate IPaddress192.168.0.2on FastEthernet0/
0,sourced by00:e0:0f:7c:07:f4
^ Z
R2#2004-1-100∶28:07 Configured from console0by
R2#shoW Vrrp brief
Interface Grp Prio Pree State Master addr Virtual addr
f0/0 10100Y BACKUP 192.168.0.254192.168.0.1
f0/0 20150Y Master192.168.0.253192.168.0.2
R2#ping192.168.0.254
PING192.168.0.254(192.168.0.254):56data bytes
!!!!!
——192.168.0.254ping statistics——
5 packets transmitted,5 packets receiVed,0% packet loss
round-trip min/aVg/max=0/0/0ms
R2#
R1#2004-1-100∶27:56%Warning:Duplicate IPaddress192.168.0.2on FastEthernet0/0,sourced by
00:00:5e:00:01∶14
R1#shoW Vrrp brief
Interface Grp Prio Pree State Master addr Virtual addr
f0/010105Y Master192.168.0.254192.168.0.1
f0/020100Y BACKUP192.168.0.253192.168.0.2
R1#
19.8实训总结
本项目以某市人民医院为背景,主要完成双出口网络的链路冗余和流量分担。上述实现方案与配置过程分别利用了神州数码、H3C和锐捷三家网络厂商的网络设备,其主要目的是为了读者在实际工程中遇到同类项目且设备厂商相同时能够借鉴。为了保证实训的真实性,所有过程都经过真实设备检验,而且保留了全部配置过程,保证了配置的完整性。
19.9实训思考
按照本项目的设计方案实施之后,能够完成该医院局域网组建和广域网接入的要求,但是用户发现系统安全与保密等方面仍有疏漏,如各个科室虽然相互独立,但是仍然能够随意互相访问,现在要求其他部门需要授权之后才能访问,请设计网络访问控制策略实现用户需求。