当前位置:文档之家› Cisco 思科路由器双线接入方案

Cisco 思科路由器双线接入方案

Router#show run

Building configuration...!

version 12.4

service timestamps debug datetime msec

service timestamps log datetime msec

no service password-encryption

!

hostname Router

!

boot-start-marker

boot-end-marker

!

enable password ciscocisco

!

no aaa new-model

!



resource policy

!

mmi polling-interval 60

no mmi auto-configure

no mmi pvc

mmi snmp-timeout 180

ip subnet-zero

ip cef

!

no ip dhcp use vrf connected

interface Ethernet0


description wt


ip address *.*.*.* 255.255.255.0

****设置网通ip地址****


ip nat outside

*****设置广域网口******


full-duplex

!

interface Ethernet1


description dx


ip address *.*.*.* 255.255.255.240

****设置电信ip地址****


ip nat outside

*****设置广域网口******


full-duplex

!

interface FastEthernet0


ip address 192.168.1.254 255.255.255.0


ip nat inside

*****设置内网口*********


speed auto

!

ip classless

ip route 0.0.0.0 0.0.0.0 *.*.*.*

*****将电信设置为出口默认路由********


*********网通静态路由地址段,费了不少劲儿才收集到的*****************


ip route 58.16.0.0 255.248.0.0 *.*.*.*


ip route 58.100.0.0 255.254.0.0 *.*.*.*


ip route 58.240.0.0 255.240.0.0 *.*.*.*


ip route 60.0.0.0 255.248.0.0 *.*.*.*


ip route 60.8.0.0 255.252.0.0 *.*.*.*


ip route 60.12.0.0 255.255.0.0 *.*.*.*


ip route 60.13.0.0 255.255.192.0 *.*.*.*


ip route 60.13.128.0 255.255.128.0 *.*.*.*


ip route 60.16.0.0 255.240.0.0 *.*.*.*


ip route 60.24.0.0 255.248.0.0 *.*.*.*


ip route 60.31.0.0 255.255.0.0 *.*.*.*


ip route 60.208.0.0 255.248.0.0 *.*.*.*


ip route 60.216.0.0 255.254.0.0 *.*.*.*


ip route 60.220.0.0 255.252.0.0 *.*.*.*


ip route 61.48.0.0 255.252.0.0 *.*.*.*


ip route 61.52.0.0 255.254.0.0 *.*.*.*


ip route 61.54.0.0 255.255.0.0 *.*.*.*


ip route 61.55.0.0 255.255.0.0 *.*.*.*


ip route 61.133.0.0 255.255.128.0 *.*.*.*


ip route 61.134.64.0 255.255.192.0 *.*.*.*


ip route 61.134.128.0 255.255.128.0 *.*.*.*


ip route 61.135.0.0 255.255.0.0 *.*.*.*


ip route 61.136.0.0 255.255.0.0 *.*.*.*


ip route 61.138.0.0 255.255.128.0 *.*.*.*


ip route 61.139.128.0 255.255.192.0 *.*.*.*


ip route 61.148.0.0 255.255.0.0 *.*.*.*


ip route 61.149.0.0 255.255.0.0 *.*.*.*


ip route 61.156.0.0 255.255.0.0 *.*.*.*


ip route 61.158.0.0 255.255.0.0 *.*.*.*


ip route 61.159.0.0 255.255.192.0 *.*.*.*


ip route 61.161.0.0 255.255.192.0 *.*.*.*


ip route 61.161.128.0 255.255.128.0 *.*.*.*


ip route 61.162.0.0 255.255.0.0 *.*.*.*


ip route 61.163.0.0 255.255.0.0 *.*.*.*


ip route 61.167.0.0 255.255.0.0 *.*.*.*


ip route 61.168.0.0 255.255.0.0 *.*.*.*


ip route 61.176.0.0 255.255.0.0 *.*.*.*


ip route 61.179.0.0 255.255.0.0 *.*.*.*


ip route 61.180.128.0 255.255.128.0 *.*.*.*



ip route 61.181.0.0 255.255.0.0 *.*.*.*


ip route 61.182.0.0 255.255.0.0 *.*.*.*


ip route 61.189.0.0 255.255.128.0 *.*.*.*


ip route 124.90.0.0 255.254.0.0 *.*.*.*


ip route 124.162.0.0 255.255.0.0 *.*.*.*


ip route 202.32.0.0 255.224.0.0 *.*.*.*


ip route 202.96.64.0 255.255.224.0 *.*.*.*


ip route 202.97.128.0 255.255.128.0 *.*.*.*


ip route 202.98.0.0 255.255.224.0 *.*.*.*


ip route 202.99.0.0 255.255.0.0 *.*.*.*


ip route 202.102.128.0 255.255.192.0 *.*.*.*


ip route 202.102.224.0 255.255.254.0 *.*.*.*


ip route 202.106.0.0 255.255.0.0 *.*.*.*


ip route 202.107.0.0 255.255.128.0 *.*.*.*


ip route 202.108.0.0 255.255.0.0 *.*.*.*


ip route 202.110.0.0 255.255.128.0 *.*.*.*


ip route 202.110.192.0 255.255.192.0 *.*.*.*


ip route 202.111.128.0 255.255.192.0 *.*.*.*


ip route 203.79.0.0 255.255.0.0 *.*.*.*


ip route 203.80.0.0 255.255.0.0 *.*.*.*


ip route 203.81.0.0 255.255.224.0 *.*.*.*


ip route 203.86.32.0 255.255.224.0 *.*.*.*


ip route 203.86.64.0 255.255.224.0 *.*.*.*


ip route 203.90.0.0 255.255.128.0 *.*.*.*


ip route 203.90.128.0 255.255.192.0 *.*.*.*


ip route 203.90.192.0 255.255.224.0 *.*.*.*


ip route 203.92.0.0 255.254.0.0 *.*.*.*


ip route 210.12.0.0 255.255.128.0 *.*.*.*


ip route 210.12.192.0 255.255.192.0 *.*.*.*


ip route 210.13.0.0 255.255.255.0 *.*.*.*


ip route 210.14.160.0 255.255.224.0 *.*.*.*


ip route 210.14.192.0 255.255.192.0 *.*.*.*


ip route 210.15.0.0 255.255.128.0 *.*.*.*


ip route 210.15.128.0 255.255.192.0 *.*.*.*


ip route 210.16.128.0 255.255.192.0 *.*.*.*


ip route 210.21.0.0 255.255.0.0 *.*.*.*


ip route 210.22.0.0 255.255.0.0 *.*.*.*


ip route 210.51.0.0 255.255.0.0 *.*.*.*


ip route 210.52.0.0 255.254.0.0 *.*.*.*


ip route 210.52.128.0 255.255.128.0 *.*.*.*


ip route 210.53.0.0 255.255.0.0 *.*.*.*


ip route 210.74.64.0 255.255.192.0 *.*.*.*


ip route 210.74.128.0 255.255.192.0 *.*.*.*


ip route 210.78.0.0 255.255.224.0 *.*.*.*


ip route 210.82.0.0 255.254.0.0 *.*.*.*


ip route 211.100.0.0 255.255.0.0 *.*.*.*


ip route 211.101.0.0 255.255.192.0 *.*.*.*


ip route 211.147.0.0 255.255.0.0 *.*.*.*


ip route 211.167.96.0 255.255.224.0 *.*.*.*


ip route 218.4.0.0 255.252.0.0 *.*.*.*


ip route 218.10.0.0 255.254.0.0 *.*.*.*


ip route 218.21.128.0 255.255.128.0 *.*.*.*


ip route 218.24.0.0 255.254.0.0 *.*.*.*


ip route 218.26.0.0 255.255.0.0 *.*.*.*


ip route 218.27.0.0 255.255.0.0 *.*.*.*


ip route 218.28.0.0 255.254.0.0 *.*.*.*


ip route 218.56.0.0 255.252.0.0 *.*.*.*


ip route 218.60.0.0 255.254.0.0 *.*.*.*


ip route 218.62.0.0 255.255.128.0 *.*.*.*


ip route 218.67.128.0 255.255.128.0 *.*.*.*


ip route 218.68.0.0 255.254.0.0 *.*.*.*


ip route 218.109.159.0 255.255.255.0 *.*.*.*


ip route 219.141.128.0 255.255.128.0 *.*.*.*


ip route 219.142.0.0 255.254.0.0 *.*.*.*




ip route 219.154.0.0 255.254.0.0 *.*.*.*


ip route 219.156.0.0 255.254.0.0 *.*.*.*


ip route 219.158.0.0 255.255.0.0 *.*.*.*


ip route 219.159.0.0 255.255.192.0 *.*.*.*


ip route 220.248.0.0 255.252.0.0 *.*.*.*


ip route 220.252.0.0 255.255.0.0 *.*.*.*


ip route 221.0.0.0 255.252.0.0 *.*.*.*


ip route 221.4.0.0 255.254.0.0 *.*.*.*


ip route 221.6.0.0 255.255.0.0 *.*.*.*


ip route 221.7.128.0 255.255.128.0 *.*.*.*


ip route 221.8.0.0 255.254.0.0 *.*.*.*


ip route 221.10.0.0 255.255.0.0 *.*.*.*


ip route 221.11.0.0 255.255.128.0 *.*.*.*


ip route 221.12.0.0 255.252.0.0 *.*.*.*


ip route 221.12.0.0 255.255.128.0 *.*.*.*


ip route 221.12.128.0 255.255.192.0 *.*.*.*


ip route 221.192.0.0 255.252.0.0 *.*.*.*


ip route 221.195.0.0 255.255.0.0 *.*.*.*


ip route 221.196.0.0 255.254.0.0 *.*.*.*


ip route 221.199.0.0 255.255.224.0 *.*.*.*


ip route 221.199.32.0 255.255.240.0 *.*.*.*


ip route 221.199.128.0 255.255.192.0 *.*.*.*


ip route 221.199.192.0 255.255.240.0 *.*.*.*


ip route 221.200.0.0 255.252.0.0 *.*.*.*


ip route 221.204.0.0 255.254.0.0 *.*.*.*


ip route 221.207.0.0 255.255.192.0 *.*.*.*


ip route 221.208.0.0 255.240.0.0 *.*.*.*


ip route 221.208.0.0 255.252.0.0 *.*.*.*


ip route 221.213.0.0 255.255.0.0 *.*.*.*


ip route 221.214.0.0 255.254.0.0 *.*.*.*


ip route 222.128.0.0 255.252.0.0 *.*.*.*


ip route 222.132.0.0 255.252.0.0 *.*.*.*


ip route 222.136.0.0 255.248.0.0 *.*.*.*


ip route 222.160.0.0 255.252.0.0 *.*.*.*


ip route 222.163.0.0 255.255.224.0 *.*.*.*


!


*******************************************************************************


no ip http server


ip nat translation timeout 120


ip nat translation tcp-timeout 60


ip nat translation icmp-timeout 180


ip nat inside source route-map dx interface Ethernet1 overload *****通过电信接口NAT转换


ip nat inside source route-map wt interface Ethernet0 overload *****通过网通接口NAT转换


!


access-list 101 permit ip 192.168.1.0 0.0.0.255 any


access-list 102 permit ip 192.168.1.0 0.0.0.255 any


route-map wt permit 10 *****网通策略路由地址段匹配101*******


match ip address 101


match interface Ethernet0 ******匹配接口E0***************


set ip default next-hop *.*.*.*


!


route-map dx permit 10 *****电信策略路由地址段匹配102*********


match ip address 102


match interface Ethernet1 ******匹配接口E1***************


set ip default next-hop *.*.*.*


!


!


control-plane


!


!


line con 0


line aux 0


line vty 0 4


password ########


login


!


end





经验共享:路由备份和负载均衡
近期有部分网友问我有关多条外线路由备份和负载均衡的问题,由于时间关系,我简单的写了一下配置....下面是以双外线路由备份为例的..多外线

路无非就是在原来的基础上增加相应的策略路由....如有遗漏,请指教....

前提是在各接口等基础配置完毕的情况下.

(1)可以针对两条线路先加两条默认路由:以第一条优先,如果第一条线路出现故障,将自动跳转到第二条线路上。

ip route 0.0.0.0 0.0.0.0 x.x.x.x

ip route 0.0.0.0 0.0.0.0 y.y.y.y

(2)如果在第一条线路正常的情况下,需要由第二条线路负载部分,可以在(1)的基础上,做策略路由。如下:

进入路由器内网接口假设是fa0/0

int fa0/0

ip policy route-map yy ( 在端口绑定策略路由)

A、对部分网段做策略,例把192.168.1.0和192.168.2.0 跳转到y.y.y.y线路上部分负载。

access-list 12 permit 192.168.1.0 0.0.0.255

access-list 12 permit 192.168.2.0 0.0.0.255

route-map yy permit 10 (定义策略yy)

match ip address 12 (匹配控制列表12)

set ip next-hop y.y.y.y (设置下一跳地址,即数据包途经的下一个路由器接口地址[网关])

B、对部分主机做策略,例把主机192.168.3.11和主机192.168.4.12 跳转到y.y.y.y线路上部分负载(默认这两个网段地址是走第一条默认路由的,即x.x.x.x)。

access-list 101 permit ip host 192.168.3.11 any

access-list 101 permit ip host 192.168.4.12 any

route-map yy permit 20 (定义策略yy)

match ip address 101 (匹配控制列表101)

set ip next-hop y.y.y.y (设置下一跳地址,即数据包途经的下一个路由器接口地址[网关])


这样在默认情况下,除了以上策略路由中定义的网段和主机外,其他网段所有主机均通过线路x.x.x.x连接到外部网络,如果x.x.x.x这条线路出现故障,默认路由就会变成y.y.y.y,并且策略路由都在y.y.y.y线路上,所以不会受到影响....










环境描述:使用设备为Cisco2621XM + NE-1E模块,该配置拥有两个FastEthernet以及一个Ethernet端口。

现使用Ethernet 1/0 端口连接内部局域网,模拟内部拥有100.100.23.0 255.255.0.0 与100.100.24.0 255.255.0.0 两组客户机情况下基于原地址的策略路由。

Fastethernet 0/0 模拟第一个ISP接入端口,Fastethernet 0/1模拟第二个ISP接入端口,地址分别为 Fastethernet 0/0 的ip地址192.168.1.2 255.255.255.0 对端ISP地址192.168.1.1 255.255.255.0

Fastethernet 0/1 的ip地址192.168.2.2 255.255.255.0 对端ISP地址192.168.2.1 255.255.255.0

通过策略路由后对不同原地址数据流量进行分流,使得不同原地址主机通过不同ISP接口访问Internet,并为不同原地址主机同不同NAT地址进行转换。

具体配置:

version 12.2
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname Router
!!
ip subnet-zero
!!
call rsvp-sync
!
interfa

ce FastEthernet0/0 --------------------假设该端口为ISP 1接入端口
ip address 192.168.1.2 255.255.255.0 --------分配地址
ip nat outside --------指定为NAT Outside端口
duplex auto
speed auto
!
interface FastEthernet0/1 --------------------假设该端口为ISP 2接入端口
ip address 192.168.2.2 255.255.255.0 --------分配地址
ip nat outside --------指定为NAT Outside端口
duplex auto
speed auto
!
interface Ethernet1/0 --------------------假设该端口为内部网络端口
ip address 100.100.255.254 255.255.0.0 --------分配地址
ip nat inside --------指定为NAT Inside端口
ip policy route-map t0 --------在该端口上使用route-map t0进行策略控制
half-duplex
!
ip nat inside source list 1 interface FastEthernet0/0 overload ------Nat转换,指定原地址为100.100.23.0的主机使用Fastethernet 0/0的地址进行转换
ip nat inside source list 2 interface FastEthernet0/1 overload ------Nat转换,指定原地址为100.100.24.0的主机使用Fastethernet 0/1的地址进行转换
ip classless
ip route 0.0.0.0 0.0.0.0 192.168.2.1 ------静态路由,对Internet的访问通过192.168.2.1(ISP2)链路
ip route 0.0.0.0 0.0.0.0 192.168.1.1 ------静态路由,对Internet的访问通过192.168.1.1(ISP1)链路
ip http server
静太路由不起很大的作用,因为存在策略路由,主要是set int 要求有显示的去往目的的路由
!
access-list 1 permit 100.100.23.0 0.0.0.255 ----访问控制列表1,用于过滤原地址,允许100.100.23.0网段主机流量通过
access-list 2 permit 100.100.24.0 0.0.0.255 ----访问控制列表2,用于过滤原地址,允许100.100.23.0网段主机流量通过
如果做set int 备份,则acl1,acl2应该允许所有的,进行nat
route-map t0 permit 10 ----定义route-map t0,permit序列为10
match ip address 1 ----检查原地址,允许100.100.23.0 网段地址
set interface FastEthernet0/0 ----指定出口为Fastethetnet 0/0
(set interface FastEthernet0/1) 我认为可以做备份
!
route-map t0 permit 20 ----定义route-map t0,permit序列为20
match ip address 2 ----检查原地址,允许100.100.24.0 网段地址
set interface FastEthernet0/1 ----指定出口为Fastethetnet 0/1
!
(set interface FastEthernet0/1) 我认为可做备份 !
dial-peer cor custom
!
line con 0
line aux 0
line vty 0 4
!
end




相关主题
文本预览
相关文档 最新文档