|
楼主 |
发表于 2008-5-28 11:42:54
|
显示全部楼层
上网的网关
Building configuration...
Current configuration : 7153 bytes
!
version RGNOS 10.1.00(4), Release(18865)(Thu Jul 26 21:37:16 CST 2007 -ubu1server)
hostname NIC_8610E
install 2 24sfp/12gt
install 4 24gt/12sfp
!
!
!
route-map ckq10 permit 1
match ip address 100
set ip next-hop 172.16.200.4
!
route-map ckq172 permit 10
match ip address 172
set ip next-hop 172.16.200.8
!
route-map ckq12 permit 1
match ip address 102
set ip next-hop 172.16.200.4
!
vlan 1
!
vlan 96
!
vlan 97
!
vlan 98
!
vlan 99
!
vlan 100
!
vlan 101
!
vlan 102
!
vlan 1010
!
vlan 1011
!
vlan 1012
!
vlan 1013
!
vlan 1014
!
vlan 1015
!
!
service dhcp
ip helper-address #########
!
!
!
!
!
!
!
!
!
!
!
ip multicast-routing
!
!
!
!
ip access-list extended 100
10 deny ip 10.16.0.0 0.0.127.255 210.45.240.0 0.0.15.255
20 deny ip 10.16.0.0 0.0.127.255 222.195.0.0 0.0.15.255
30 deny ip 10.16.0.0 0.0.127.255 121.251.16.0 0.0.7.255
40 deny ip 10.16.0.0 0.0.127.255 10.17.0.0 0.0.127.255
50 deny ip 10.16.0.0 0.0.127.255 172.16.0.0 0.0.127.255
60 permit ip 10.16.0.0 0.0.127.255 any
!
!
ip access-list extended 102
10 deny ip 10.17.0.0 0.0.127.255 210.45.240.0 0.0.15.255
20 deny ip 10.17.0.0 0.0.127.255 222.195.0.0 0.0.15.255
30 deny ip 10.17.0.0 0.0.127.255 121.251.16.0 0.0.7.255
40 deny ip 10.17.0.0 0.0.127.255 10.17.0.0 0.0.127.255
50 deny ip 10.17.0.0 0.0.127.255 172.16.0.0 0.0.127.255
60 permit ip 10.17.0.0 0.0.127.255 any
!
!
ip access-list extended 172
10 deny ip 172.16.0.0 0.0.127.255 210.45.240.0 0.0.15.255
20 deny ip 172.16.0.0 0.0.127.255 222.195.0.0 0.0.15.255
30 deny ip 172.16.0.0 0.0.127.255 121.251.16.0 0.0.7.255
40 deny ip 172.16.0.0 0.0.127.255 10.17.0.0 0.0.127.255
50 deny ip 172.16.0.0 0.0.127.255 10.16.0.0 0.0.127.255
60 permit ip 172.16.0.0 0.0.127.255 any
!
enable secret 5 ##################
!
!
!
!
interface GigabitEthernet 2/1
switchport access vlan 1010
medium-type fiber
!
interface GigabitEthernet 2/2
switchport access vlan 1013
medium-type fiber
!
interface GigabitEthernet 2/3
!
interface GigabitEthernet 2/4
no switchport
medium-type fiber
ip policy route-map ckq10
ip address 192.168.1.9 255.255.255.252
!
interface GigabitEthernet 2/5
switchport access vlan 1015
medium-type fiber
!
interface GigabitEthernet 2/6
switchport access vlan 1012
medium-type fiber
!
interface GigabitEthernet 2/7
switchport access vlan 1011
medium-type fiber
!
interface GigabitEthernet 2/8
switchport access vlan 1014
!
interface GigabitEthernet 2/9
!
interface GigabitEthernet 2/10
switchport access vlan 102
!
interface GigabitEthernet 2/11
switchport access vlan 99
!
interface GigabitEthernet 2/12
switchport access vlan 100
!
interface GigabitEthernet 2/13
switchport access vlan 1014
!
interface GigabitEthernet 2/14
!
interface GigabitEthernet 2/15
!
interface GigabitEthernet 2/16
!
interface GigabitEthernet 2/17
!
interface GigabitEthernet 2/18
!
interface GigabitEthernet 2/19
!
interface GigabitEthernet 2/20
!
interface GigabitEthernet 2/21
!
interface GigabitEthernet 2/22
!
interface GigabitEthernet 2/23
!
interface GigabitEthernet 2/24
!
interface GigabitEthernet 4/1
switchport mode trunk
switchport trunk allowed vlan remove 2-95,100-4093
!
interface GigabitEthernet 4/2
switchport access vlan 99
!
interface GigabitEthernet 4/3
switchport access vlan 101
!
interface GigabitEthernet 4/4
switchport access vlan 96
!
interface GigabitEthernet 4/5
switchport access vlan 100
!
interface GigabitEthernet 4/6
switchport access vlan 100
!
interface GigabitEthernet 4/7
switchport access vlan 100
!
interface GigabitEthernet 4/8
switchport mode trunk
switchport trunk allowed vlan remove 2-99,101-4093
!
interface GigabitEthernet 4/9
switchport mode trunk
switchport trunk allowed vlan remove 2-99,101-4093
!
interface GigabitEthernet 4/10
switchport mode trunk
switchport trunk allowed vlan remove 2-99,101-4093
!
interface GigabitEthernet 4/11
switchport access vlan 100
!
interface GigabitEthernet 4/12
switchport access vlan 100
!
interface GigabitEthernet 4/13
switchport access vlan 100
!
interface GigabitEthernet 4/14
switchport access vlan 102
!
interface GigabitEthernet 4/15
switchport access vlan 102
!
interface GigabitEthernet 4/16
switchport access vlan 102
!
interface GigabitEthernet 4/17
no switchport
ip address 192.168.1.33 255.255.255.252
!
interface GigabitEthernet 4/18
no switchport
ip address 192.168.1.41 255.255.255.252
!
interface GigabitEthernet 4/19
switchport access vlan 102
!
interface GigabitEthernet 4/20
switchport access vlan 102
!
interface GigabitEthernet 4/21
switchport access vlan 100
!
interface GigabitEthernet 4/22
switchport access vlan 100
!
interface GigabitEthernet 4/23
switchport access vlan 100
!
interface GigabitEthernet 4/24
no switchport
medium-type fiber
ipv6 enable
ipv6 address 2001:da8:b3:12::2/64
!
interface VLAN 1
ip address 192.168.100.1 255.255.255.0
!
interface VLAN 96
ip address ###############255.255.255.192
ipv6 enable
ipv6 address 2001:da8:d805:96::1/64
no ipv6 nd suppress-ra
ipv6 nd dad attempts 0
ipv6 mtu 1492
!
interface VLAN 97
ip pim dense-mode
ip address ############# 255.255.255.192
ipv6 enable
ipv6 address 2001:da8:d805:97::1/64
no ipv6 nd suppress-ra
!
interface VLAN 98
ip address ############### 255.255.255.192
!
interface VLAN 99
ip address ############# 255.255.255.192
ipv6 enable
ipv6 address 2001:da8:d805:99::1/64
no ipv6 nd suppress-ra
!
interface VLAN 100
ip address ############ 255.255.255.0
ipv6 enable
ipv6 address 2001:da8:d805::ffff/64
no ipv6 nd suppress-ra
ipv6 mtu 1492
!
interface VLAN 101
ip address ############ 255.255.255.192
!
interface VLAN 102
ip address 172.16.200.1 255.255.255.192
ipv6 enable
ipv6 address 2001:da8:d805:102::1/64
!
interface VLAN 1010
ip address 192.168.1.1 255.255.255.252
!
interface VLAN 1011
!
interface VLAN 1012
ip pim dense-mode
ip address 192.168.1.5 255.255.255.252
!
interface VLAN 1013
ip policy route-map ckq12
ip address 192.168.1.13 255.255.255.252
!
interface VLAN 1014
ip policy route-map ckq172
ip address 192.168.0.1 255.255.255.252
!
interface VLAN 1015
ip address 192.168.0.5 255.255.255.252
!
!
!
!
router ospf 1
router-id 192.168.10.1
redistribute connected subnets
redistribute static subnets
network 192.168.0.0 0.0.0.3 area 0.0.0.0
network 192.168.0.4 0.0.0.3 area 0.0.0.0
network 192.168.1.0 0.0.0.3 area 1.1.1.1
network 192.168.1.4 0.0.0.3 area 4.4.4.4
network 192.168.1.8 0.0.0.3 area 2.2.2.2
network 192.168.1.12 0.0.0.3 area 3.3.3.3
!
!
!
ip route 0.0.0.0 0.0.0.0 ##########172.16.200.2
ip route ###################### 172.16.200.20
ip route ######################192.168.1.34
!
!
snmp-server community ########
line con 0
line vty 0 4
login
password 7 ##############
!
ipv6 source-route
!
ipv6 route ::/0 2001:da8:b3:12::1
!
!
!
!
[ 本帖最后由 lyregale 于 2008-5-29 15:25 编辑 ] |
|