30选5玩法|福彩30选5开奖结果321|
 

标签:h3c

LACP学习笔记

28 Comments 网络技术 ,

 

一、LACP简介

1、LACP协议简介

基于 IEEE802.3ad 标准的LACP(Link Aggregation Control Protocol,链路汇聚控

制协议)是一种实现链路动态汇聚与解汇聚的协议。LACP 协议通过LACPDU(Link

Aggregation Control Protocol Data Unit,链路汇聚控制协议数据单元)与对端交互信息。

使能某端口的 LACP 协议后,该端口将通过发送LACPDU 向对端通告自己的系统优

先级、系统MAC、端口优先级、端口号和操作Key。对端接收到这些信息后,将这些信息与其它端口所保存的信息比较以选择能够汇聚的端口,从而双方可以对端口

加入或退出某个动态汇聚组达成一致。

2、LACP报文

clip_image002

主要字段介绍:

Actor_Port/Partner_Port:本端/对端接口信息。

Actor_State/Partner_State:本端/对端状态。

Actor_System_Priority/Partner_System_Priority:本端/对端系统优先级。

Actor_System/Partner_System:本端/对端系统ID。

Actor_Key/Partner_Key:本端/对端操作Key,各接口的该值相同才能够聚合。

Actor_Port_Priority/Partner_Port_Priority:本端/对端接口优先级。

二、链路聚合的分类

1、 手工负载?#20540;?#27169;式链路聚合

1)手工汇聚概述

手工负载?#20540;?#27169;式是一种最基本的链路聚合方式,在该模?#36739;攏珽th-Trunk 接口的建

立,成员接口的加入完全由手工来配置,没有链路聚合控制协议的参与。该模?#36739;?#25152;有成员接口(selected)都参与数据的转发,?#20540;?#36127;载流量,因此称为手工负载?#20540;?#27169;式。手工汇聚端口的 LACP 协议为关闭状态,禁止?#27809;?#20351;能手工汇聚端口的LACP 协议。

2 手工汇聚组中的端口状态

在手工汇聚组中,端口可能处于两种状态:Selected 或Standby。处于Selected 状

态且端口号最小的端口为汇聚组的主端口,其他处于Selected 状态的端口为汇聚组

的成员端口。

由于设备所能支持的汇聚组中的最大端口数有限制,如果处于Selected 状态的端口

数超过设备所能支持的汇聚组中的最大端口数,系统将按照端口号从小到大的顺序

选择一些端口为Selected 端口,其他则为Standby 端口。

3)手工汇聚对端口配置的要求

一般情况下,手工汇聚对汇聚前的端口速率和双工模式不作限制。但对于以下情况,

系统会作特殊处理:

对于初始就处于 DOWN 状态的端口,在汇聚时对端口的速率和双工模式没有限制;

对于曾经处于 UP 状态,并协商或强制指定过端口速率和双工模式,而当前处于DOWN 状态的端口,在汇聚时要求速率和双工模式一致;

对于一个汇聚组,当汇聚组中某个端口的速率和双工模式发生改变?#20445;?#31995;统不进行解汇聚,汇聚组中的端口也都处于正常工作状态。但如果是主端口出现速?#24335;档?#21644;双工模式变化,则该端口的转发可能出现丢包现象。

2、 LACP 协议链路聚合

LACP(Link Aggregation Control Protocol)链路聚?#20064;?#21547;两种类型:

1) 静态 LACP 模式链路聚合

a)静态 LACP 模式链路聚合简介

静态 LACP 模?#36739;攏珽th-Trunk 接口的建立,成员接口的加入,都是由手工配置完成的。但与手工负载?#20540;?#27169;式链路聚合不同的是,该模?#36739;翷ACP 协议报文参与活动接口的选择。也就是?#25285;?#24403;把一组接口加入Eth-Trunk 接口后,这些成员接口中哪些接口作为活动接口,哪些接口作为非活动接口还需要经过LACP 协议报文的协商确定。

静态汇聚端口的 LACP 协议为使能状态,当一个静态汇聚组被删除?#20445;?#20854;成员端口

将形成一个或多个动态LACP 汇聚,并保持LACP 使能。禁止?#27809;?#20851;?#31449;?#24577;汇聚端口的LACP 协议。

b)静态汇聚组中的端口状态

在静态汇聚组中,端口可能处于两种状态:Selected 或Standby。Selected 端口和

Standby 端口都能收发LACP 协议,但Standby 端口不能转发?#27809;?#25253;文。

说明:

在一个汇聚组中,处于Selected 状态且端口号最小的端口为汇聚组的主端口,其他

处于Selected 状态的端口为汇聚组的成员端口。

在静态汇聚组中,系统按照以下原则设置端口处于 Selected 或者Standby 状态:

系统按照端口全双工/高速率、全双工/?#36864;?#29575;、半双工/高速率、半双工/?#36864;?#29575;的优先次序,选择优先次序最高的端口处于Selected 状态,其他端口则处于Standby 状态。

与处于 Selected 状态的最小端口所连接的对端设备不同,或者连接的是同一个对端设备但端口在不同的汇聚组内的端口将处于Standby 状态。

端口因存在?#24067;?#38480;制(如不能跨板汇聚)无法汇聚在一起,而无法与处于Selected 状态的最小端口汇聚的端口将处于Standby 状态。

与处于 Selected 状态的最小端口的基本配置不同的端口将处于Standby 状态。由于设备所能支持的汇聚组中的 Selected 端口数有限制,如果当前的成员端口数超过了设备所能支持的最大Selected 端口数,系统将按照端口号从小到大的顺序选择一些端口为Selected 端口,其他则为Standby 端口。

2) 动态 LACP 模式链路聚合

a)动态 LACP 模式链路聚合简介

动态 LACP 模?#36739;攏珽th-Trunk 接口的建立,成员接口的加入,活动接口的选择完

全由LACP 协议通过协商完成。这就意味着启用了动态LACP 协议的两台直连设备上,不需要创建Eth-Trunk 接口,也不需要指定哪些接口作为聚合组成员接口,两台设备会通过LACP 协商自动完成链路的聚合操作。动态 LACP 汇聚是一种系统自动创建/删除的汇聚,不允许?#27809;?#22686;加或删除动态LACP 汇聚中的成员端口。只有速率和双工属性相同、连接到同一个设备、有相同基本配置的端口才能被动态汇聚在一起。即使只有一个端口也可以创建动态汇聚,此时为单端口汇聚。动态汇聚中,端口的LACP 协议处于使能状态。

b)动态汇聚组中的端口状态

在动态汇聚组中,端口可能处于两种状态:Selected 或Standby。Selected 端口和

Standby 端口都能收发LACP 协议,但Standby 端口不能转发?#27809;?#25253;文。由于设备所能支持的汇聚组中的最大端口数有限制,如果当前的成员端口数量超过了最大端口数的限制,则本端系统和对端系统会进行协商,根据设备ID 优的一端的

端口ID 的大小,来决定端口的状态。具体协商步骤如下:

比较设备 ID(系统优先级+系统MAC 地址)。先比较系统优先级,如果相同再比较系统MAC 地址。设备ID 小的一端被认为优。

比较端口 ID(端口优先级+端口号)。对于设备ID 优的一端的各个端口,首先比较端口优先级,如果优先级相同再比较端口号。端口ID 小的端口为

Selected 端口,剩余端口为Standby 端口。在一个汇聚组中,处于Selected 状态且端口号最小的端口为汇聚组的主端口,其他处于Selected 状态的端口为汇聚组的成员端口。

说明:

与手工汇聚组不同的是,在静态汇聚组和动态汇聚组中,处于 DOWN 的端口为

Standby 状态。

三、LACP实现原理

1手工汇聚原理

手工负载?#20540;?#27169;式链路聚合是应用比较广泛的一种链路聚合,大多数运营级网络设备

均支持该特性,当需要在两个直连设备间提供一个较大的链路带宽而对端设备又不支

持LACP 协议?#20445;?#21487;以使用手工负载?#20540;?#27169;式

clip_image004

说明:

手工负载?#20540;?#27169;式的Eth-Trunk 接口可以聚合不同单板、不同双工模式的成员接口。

------中间广告---------

2、静态汇聚原理

a基本概念

静态LACP 模式链路聚合是一种利用LACP 协议进行?#38382;?#21327;商选取活动链路的聚合模

式。该模式由LACP 协议确定聚合组中的活动和非活动链路,又称为M∶N 模式,即

M 条活动链路与N 条备份链路的模式。这种模式提供了更高的链路可靠性,并且可以

在M 条链路中实现不同方式的负载均衡。

clip_image006

M:N 模式的Eth-Trunk 接口中M 和N 的值可以通过配置活动接口数上限阈值来确定。

b)系统 LACP 优先级

静态LACP 模?#36739;攏?#20004;端设备所选择的活动接口必须保持一致,否则链路聚合组就无法建立。而要想使两端活动接口保持一致,可以使其中一端具有更高的优先级,另一端根据高优先级的一端来选择活动接口即可。系统LACP 优先级就是为了区分两端优先级的高低而配置的?#38382;?/p>

系统 LACP 优先级值越小优先?#23545;?#39640;,?#31508;?#31995;统LACP 优先级值为32768。

c)接口 LACP 优先级

接口LACP 优先级是为了区别不同接口被选为活动接口的优先程?#21462;?#25509;口LACP 优先级值越小,优先?#23545;?#39640;。?#31508;?#24773;况下,接口LACP 优先级为32768。

d)静态模式Eth-Trunk 接口建立过程

静态模式Eth-Trunk 接口建立过程如下所示:

① 两端互相发送 LACPDU 报文。

② 两端设备根据系统 LACP 优先级确定主动端。

③ 两端设备根据接口LACP 优先级确定活动接口,最终以主动端设备的活动接口确定两端的活动接口。

e) 互发 LACPDU 报文

在两端设备CX-A 和CX-B 上创建Eth-Trunk 接口并配置为静态LACP 模式,然后向Eth-Trunk 接口中手工加入成员接口。此时成员接口上便启用了LACP 协议,两端互相发出LACPDU 报文,如下图所示。

clip_image008

f)确定主动端

Eth-Trunk 两端设备均会收到对端发来的LACP 报文,根据报文中的优先级字段,确认

活动接口。优先级字段的值越小,优先?#23545;?#39640;。

如下图所示,当CX-B 收到CX-A 发送LACP 报文?#20445;珻X-B 会查看并记录对端信息,并且比较系统优先级字段。CX-A 的系统优先级为10,高于CX-B 的系统优先级,所以选择CX-A 为主动端。此时CX-B 将按照CX-A 的接口优先级选择活动接口。如果 Eth-Trunk 链路两端设备的系统优先级一致,系统将选择系统ID 字段较小的作为主动端。系统ID 由设备的MAC 地址产生。

clip_image010

g)选择活动接口

选出主动端后,两端都会以主动端的接口优先级来选择活动接口。如上图所示,CX-A 为主动端,CX-A 的接口GE1/0/1、GE1/0/2 的优先级高于接口GE2/0/1,此时接口GE1/0/1、GE1/0/2 被选为活动接口,组成LACP 聚合组,以负载?#20540;?#30340;方式转发数据。

2、静态汇聚原理

动态汇聚和静态汇聚原理类似,只是动态汇聚中所有端口都是通过协议确定,而不是像静态汇聚通过协议在指定端口中确定汇聚相关端口。

四、实现细节

1、链路聚合控制的相关?#38382;?/b>

a)LACP协议如何唯一的标识聚合组:

系统ID(System ID) ,由“系统优先级+系统MAC地址”组成,其中,之所以要?#23567;?#31995;统优先级?#20445;?#26159;因为LACP协议中,链路聚合两端设备扮演不同?#24039;?#26377;了“系统优先级?#20445;?#31649;理员可以通过配置干预?#24039;?#36873;举。

b)端口ID(Port ID):

对于参与链路聚合的各个端口,也需要在设备内部唯一标识,端口ID由“端口优先级+端口号”组成,之所以需要“端口优先级?#20445;?#20063;是因为涉及端口的不同?#24039;?#36873;举

c)Aggregator ID:

在一个设备上,能进行多组聚合,?#20174;?#22810;个Aggregator,为了区分这些Aggregator,给每个Aggregator分配了一个聚合ID(Aggregator ID),为一个16位整数

2、端口key

聚合端口中有两种key:一种是操作key,一种是管理key。

操作key是为形成聚?#31995;?#21069;使用的key,管理key是允许管理者对key?#21040;?#34892;操作的key。

3、 操作key

在动态LACP聚?#29616;校?#21482;有操作KEY相同的端口才能属于同一个聚合组,你可以认为操作KEY相同的端口,其属性相同。

在手工聚合和静态LACP聚?#29616;校?#34429;然同一个聚合组中的端口的操作KEY不一定相同(因端口由管理?#31508;?#24037;加入),但是Selected端口的操作KEY一定相同。

操作Key 是在端口汇聚?#20445;?#31995;统根据端口的配置(?#27492;?#29575;、双工、基本配置、管理

Key)生成的一个配置组合。

(1) 对于手工汇聚组和静态汇聚组,Selected 的端口有相同的操作Key。

(2) 静态汇聚端口在使能LACP 后,端口的管理Key 与汇聚组ID 相同。

(3) 动态汇聚端口在使能LACP 协议后,其管理Key ?#31508;?#20026;零。

(4) 对于动态汇聚组,同组成员一定有相同的操作Key。

4、六要素

a)四个要素

一个聚合组来?#25285;?#22914;果需要进行唯一标识的话,需要包含四个元素:本端系统ID、本端操作KEY、对端系统ID、对端操作KEY

b)两个要素

系统中并不是所有聚合组都包含多个链路,为了区?#31181;?#21253;含单个链路的聚合组?#37027;?#20917;,还需要额外?#30001;?#20004;个元素:本端端口ID和对端端口ID。

c)结论

这六个元素唯一确定了一个聚合组,称为聚合组 ID(Link Aggregation Group ID,LAG ID)。如果一个聚合组中包含多个链路,那么LAG ID中,本端端口ID和对端端口ID为0,相当于只用四元组就可以刻画包含多个链路的聚合组。

5、端口类型:

aSelectetUnselected

参与流量转发的端口称为Selected端口,否则称为Unselected端口

b)主端口(master端口)

处于Selected状态且端口号最小的端口称为主端口(Master Port),可以形象的认为,聚合组中的所有端口被汇聚到了主端口,主端口在逻辑上代表了整个聚合组,对于GVRP/GMRP、STP/RSTP/MSTP等二层协议,都只从主端口发送,其他数据报文则在各个Selected端口间?#20540;!?/p>

c)补充:

由于Selected与Unselected端口在实际状态下的选取受?#25509;布?#30340;影响,所以不同厂?#20063;?#21697;的具体表现?#38382;?#21487;能有差异

5、LACP绑定端口

判断将一个端口绑定到Aggregator的关键依据是 LAG ID,判断方法是:

(1)Aggregator的操作KEY和端口的操作KEY相同。

(2)已经绑定到这个Aggregator的其他端口和这个端口有相同的链路LAG ID,即与Aggregator关联的LAG ID必须和端口的LAG ID相同。

(3) “LAG ID”则指的是聚合组ID( Link Aggregation Group ID),“聚合ID”则指的是Aggregator ID. (LAG ID就是指属于同一个聚?#29616;?#30340;所有port 包括selected 和Standby,对于手工和静态比较好理解,就是指?#27809;?#25152;指定的所有port,对于动态汇聚,指所有port)

6、端口离开Aggregator

(1)如果Actor端口在一定时间内(使用long timeout?#31508;?0s,使用short timeout是3秒)收不到Partner端口发送的LACP报文,就宣告自己处于超时状态,如果在下一个short timeout时间(3秒)内还没有收到Partner的报文,就会离开这个Aggregator。

(2)如果从Partner端口收到的LACP报文,发现LAG ID发生了改变(系统ID或操作KEY发生了变化,系统ID改变说明连接到的对端设备发生了变化,操作KEY发生了变化可能是对端端口的属性发生了变化),这时端口?#19981;?#31163;开这个Aggregator。

(3)还有一种导致端口离开Aggregator?#37027;?#20917;:Actor端口本身的属性发生了变化,设备通过动态操作KEY功能给它分配的操作KEY发生变化,导致和Aggregator的LAG ID不匹配,从而离开聚合组。

7、Active模式和Passive模式

(1)Active模?#36739;攏?#31471;口正常周期性的发送LACP报文;

(2)Passive模?#36739;攏?#31471;口平时不发送LACP报文,不过,一旦收到了对端的LACP报文,就会正常发送LACP报文了。

华为(H3C)交换机版本升级遇到的问题总结

有一交换机,华为s2000系列,想升级版本。一般步骤如下:

弄一台电脑设置ip能与交换机直接通信(不经过三层交换机的方式)。

1、检查flash空间够不够,我的这个flash空间为4M,实际能使用并没有那么多。我新灌一个文件进去空间不够,需要删除原来的。

2、备份原来的系统文件,我采用ftp方式备份到本地电脑中,防止升级出故障?#25351;矗?#23454;际上这个步骤非常?#34892;唬?#21518;面升级出现故障了,还好有备份。为了以防万一,将里面所有的文件文件都做了备份。这个交换机的系统文件是app格式的,最近新出的华为和h3c交换机系统文件格式都是bin格式。

3、删除原系统文件,腾出空间,在console台,del flash:/s2006.app. 然后检查dir 确实文件删除了。

这里疏忽了,没有注意到空间容量。经验?#21644;?#36807;这种方式删除后,容量并没有减少,删除的文件依然占flash容量,需要用到一个操作清空交换机回收站 reset recycle-bin

由于第三步?#22797;?#20102;,需要?#25351;?#21407;系统文件。通过tftp方式将原来的文件灌入,悲剧提示空间不够,然后按照提示一路删除,?#25925;?#19981;够,导入失败。

没办法,除tftp外,还有ftp和xmodem方式。选择xmodem方式进行导入。方法如下:

1、重启交换机

2、进入引导菜单(如果你的交换机指定的app系统文件找不到了,自动进入升级菜单,默认密码为空);

3、按照步骤选择xmodem方式上传文件(这里估计不用考虑交换机回收站),反正我做的时候?#20174;?#25552;示空间不够;

4、在超级终端,有人?#19981;?#29992;secure之列的软件,选择?#25353;?#36865;”-》选择本地电脑上的app文件,点发送。就可以看到进?#21462;?/p>

然后就是等待了。悲剧再次出现,?#25925;?#25552;示空间不够。

这里就只能考虑一个问题了,当因为没有清理交换机回收站,导致容量不够无法导入系统文件怎么办?

只能格式化整个flash了。。有了思路尝试下,以前没有试过

方法如下:

1、重启,引导进入引导菜单;

2、按CRTL+E键开始erase flash,然后自动格式化,这时可以看到空间够了。3300000字节。

剩下的事情就简单了,可以使用tftp方式(本?#38382;?#36133;,估计我设置的ip地址是172.18开头,但是掩码用的是3个255的,他不认识这个子网段),xmodem方式成功导入。

如果你上传的文件名跟之前的不一样,还需要指定启动文件。

boot load- @@@@。app

还有引导文件。。。。

总结:

1、环境要准备足,电脑(带console口,没有的usb接口的也没有问题,不过要有usb的转接线,确认能用),交换机划分一个端口配置一个ip地址,电脑通过这个端口能与交换机同一个网段通信,最好直接接在该端口上,电脑上要有超级终端、tftp和ftp服务器,给升级提供多种选择;

2、通过del方式删除,空间并没有?#22836;牛?#38656;要清空回收站;其他?#25105;?#26041;式都需要确认空间容量?#37027;?#20917;;

3、一种方式不行,不要放弃,可以尝试其他方法,如本次tftp服务器方式提示空间不够(因容量没有?#22836;牛?#21644;网络ip设置用的是子网地址(172.18.200.100 255.255.255.0)原因,但是xmodem却可以,ftp方式没有试过。

4、版本软件和引导文件等一定要有备份,始终坚信一条,向前走?#20445;?#20063;要考虑能回头走,否则不。

5、ip地址的设置遵照标准的网络,不要利用子网的方式,如果已经设置了子网没办法修改?#37027;?#20917;下,可以使用xmodem不利用网络的方式进?#23567;?/p>

6、使用xmodem的波特率,默认是9600,在传输数据的时候最好也选这个,开始为了速度快,选择了最大的波特率,没有成功。

7、华为交换机crtl+b进入菜单后,按crtl+w出来另外一个东东,这个没有仔细看,功能蛮多的,有兴趣的朋友可尝试下。

 

转至 http://blog.chinaunix.net/uid-7411781-id-3262686.html

H3C 双出口解决方案

No Comments 网络技术 ,

策?#26376;?#30001;方法来实现双WAN链路负载均衡

V5平台应用

[U200M]acl number 3010
[U200M-acl-adv-3010]description  connect-to-dianxin
[U200M-acl-adv-3010]rule 1 permit ip source 192.168.1.0 0.0.0.255
[U200M-acl-adv-3010]quit
[U200M]acl number 3020
[U200M-acl-adv-3010]description  connect-to-wangtong
[U200M-acl-adv-3010]rule 1 permit ip source 192.168.2.0 0.0.0.255
[U200M-acl-adv-3010]quit

policy-based-route doubleline permit node 1
   if-match acl 3010
   apply ip-address next-hop 220.102.80.2
policy-based-route doubleline permit node 2
   if-match acl 3020
   apply ip-address next-hop 202.102.0.21

[H3C-GigabitEthernet0/1]ip policy-based-route doubleline

说明:acl3010,3020将内部网络的数据流分流,指定下一跳为电信或者网通的地址,应用到内网口上。

V3平台应用

[U200M]acl number 3010
[U200M-acl-adv-3010]description  connect-to-dianxin
[U200M-acl-adv-3010]rule 1 permit ip source 192.168.1.0 0.0.0.255
[U200M-acl-adv-3010]quit
[U200M]acl number 3020
[U200M-acl-adv-3010]description  connect-to-wangtong
[U200M-acl-adv-3010]rule 1 permit ip source 192.168.2.0 0.0.0.255
[U200M-acl-adv-3010]quit

[H3C] route-policy doubleline permit node 5
[H3C-route-policy] if-match acl 3010
[H3C-route-policy] apply ip-address next-hop 220.102.80.2
[H3C-route-policy] quit
H3C] route-policy doubleline permit node 10
[H3C-route-policy] if-match acl 3020
[H3C-route-policy] apply ip-address next-hop 202.102.0.21
[H3C-route-policy] quit

[H3C] interface ethernet 3/0/0

[H3C-Ethernet3/0/0] ip policy route-policy doubleline

说明:如果是外网地址不固定的,可以采用apply output-interface int eth1/0/0来做,?#27604;?#23454;际的接口不一定是eth1/0/0
      另外,如果内网只有一个网段,比如192.168.1.0/24的话,可以采用奇数/偶数ip分开走的方法,如下:

[U200M]acl number 3010
[U200M-acl-adv-3010]description  connect-to-dianxin
[U200M-acl-adv-3010]rule 1 permit ip source 192.168.1.0 255.255.255.254
[U200M-acl-adv-3010]quit
[U200M]acl number 3020
[U200M-acl-adv-3010]description  connect-to-wangtong
[U200M-acl-adv-3010]rule 1 permit ip source 192.168.1.1 255.255.255.254
[U200M-acl-adv-3010]quit

 

采用?#31508;?#36335;由+精确路由方式选路

 

电信

ip route-static 58.32.0.0 255.248.0.0 220.102.80.1 detect-group 1
ip route-static 58.40.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 58.42.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 58.43.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 58.44.0.0 255.252.0.0 220.102.80.1 detect-group 1
ip route-static 58.48.0.0 255.248.0.0 220.102.80.1 detect-group 1
ip route-static 58.56.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 58.58.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 58.59.0.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 58.60.0.0 255.252.0.0 220.102.80.1 detect-group 1
ip route-static 58.208.0.0 255.240.0.0 220.102.80.1 detect-group 1
ip route-static 59.32.0.0 255.248.0.0 220.102.80.1 detect-group 1
ip route-static 59.40.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 59.42.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 59.43.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 59.44.0.0 255.252.0.0 220.102.80.1 detect-group 1
ip route-static 59.48.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 59.49.0.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 59.49.128.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 59.50.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 59.51.0.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 59.51.128.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 59.52.0.0 255.252.0.0 220.102.80.1 detect-group 1
ip route-static 59.56.0.0 255.252.0.0 220.102.80.1 detect-group 1
ip route-static 59.60.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 59.62.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 60.160.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 60.162.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 60.164.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 60.168.0.0 255.248.0.0 220.102.80.1 detect-group 1
ip route-static 60.176.0.0 255.240.0.0 220.102.80.1 detect-group 1
ip route-static 61.132.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 61.133.128.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 61.134.0.0 255.255.192.0 220.102.80.1 detect-group 1
ip route-static 61.134.64.0 255.255.224.0 220.102.80.1 detect-group 1
ip route-static 61.136.128.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 61.137.0.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 61.138.192.0 255.255.192.0 220.102.80.1 detect-group 1
ip route-static 61.139.0.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 61.139.192.0 255.255.192.0 220.102.80.1 detect-group 1
ip route-static 61.140.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 61.144.0.0 255.252.0.0 220.102.80.1 detect-group 1
ip route-static 61.152.0.0 255.252.0.0 220.102.80.1 detect-group 1
ip route-static 61.157.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 61.159.64.0 255.255.192.0 220.102.80.1 detect-group 1
ip route-static 61.159.128.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 61.160.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 61.161.64.0 255.255.192.0 220.102.80.1 detect-group 1
ip route-static 61.164.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 61.166.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 61.169.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 61.170.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 61.172.0.0 255.252.0.0 220.102.80.1 detect-group 1
ip route-static 61.177.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 61.178.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 61.180.0.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 61.183.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 61.184.0.0 255.252.0.0 220.102.80.1 detect-group 1
ip route-static 61.188.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 61.189.128.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 61.190.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 25.64.0.0 255.248.0.0 220.102.80.1 detect-group 1
ip route-static 25.72.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 25.80.0.0 255.248.0.0 220.102.80.1 detect-group 1
ip route-static 25.88.0.0 255.248.0.0 220.102.80.1 detect-group 1
ip route-static 25.104.0.0 255.248.0.0 220.102.80.1 detect-group 1
ip route-static 25.112.0.0 255.240.0.0 220.102.80.1 detect-group 1
ip route-static 202.96.104.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.96.96.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.96.112.0 255.255.240.0 220.102.80.1 detect-group 1
ip route-static 202.96.128.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.96.136.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.96.144.0 255.255.240.0 220.102.80.1 detect-group 1
ip route-static 202.96.160.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.96.168.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.96.176.0 255.255.240.0 220.102.80.1 detect-group 1
ip route-static 202.96.200.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.96.208.0 255.255.240.0 220.102.80.1 detect-group 1
ip route-static 202.96.224.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.97.0.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.97.8.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.97.16.0 255.255.240.0 220.102.80.1 detect-group 1
ip route-static 202.97.32.0 255.255.224.0 220.102.80.1 detect-group 1
ip route-static 202.97.64.0 255.255.224.0 220.102.80.1 detect-group 1
ip route-static 202.97.96.0 255.255.240.0 220.102.80.1 detect-group 1
ip route-static 202.97.112.0 255.255.240.0 220.102.80.1 detect-group 1
ip route-static 202.98.32.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.98.48.0 255.255.240.0 220.102.80.1 detect-group 1
ip route-static 202.98.64.0 255.255.224.0 220.102.80.1 detect-group 1
ip route-static 202.98.96.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.98.128.0 255.255.224.0 220.102.80.1 detect-group 1
ip route-static 202.98.160.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.98.168.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.98.192.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.98.200.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.98.208.0 255.255.240.0 220.102.80.1 detect-group 1
ip route-static 202.98.224.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.98.232.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.98.240.0 255.255.240.0 220.102.80.1 detect-group 1
ip route-static 202.99.192.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.100.96.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.100.104.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.100.112.0 255.255.240.0 220.102.80.1 detect-group 1
ip route-static 202.100.136.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.100.160.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.100.168.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.100.176.0 255.255.240.0 220.102.80.1 detect-group 1
ip route-static 202.100.192.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.100.208.0 255.255.240.0 220.102.80.1 detect-group 1
ip route-static 202.100.224.0 255.255.224.0 220.102.80.1 detect-group 1
ip route-static 202.101.0.0 255.255.192.0 220.102.80.1 detect-group 1
ip route-static 202.101.64.0 255.255.224.0 220.102.80.1 detect-group 1
ip route-static 202.101.96.0 255.255.224.0 220.102.80.1 detect-group 1
ip route-static 202.101.128.0 255.255.192.0 220.102.80.1 detect-group 1
ip route-static 202.101.224.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.102.0.0 255.255.224.0 220.102.80.1 detect-group 1
ip route-static 202.102.32.0 255.255.224.0 220.102.80.1 detect-group 1
ip route-static 202.102.64.0 255.255.192.0 220.102.80.1 detect-group 1
ip route-static 202.103.0.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.103.8.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.103.16.0 255.255.240.0 220.102.80.1 detect-group 1
ip route-static 202.103.32.0 255.255.224.0 220.102.80.1 detect-group 1
ip route-static 202.103.192.0 255.255.224.0 220.102.80.1 detect-group 1
ip route-static 202.103.224.0 255.255.248.0 220.102.80.1 detect-group 1
ip route-static 202.104.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 202.107.128.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 202.109.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 202.110.128.0 255.255.192.0 220.102.80.1 detect-group 1
ip route-static 202.111.0.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 202.130.32.0 255.255.224.0 220.102.80.1 detect-group 1
ip route-static 202.212.0.0 255.255.240.0 220.102.80.1 detect-group 1
ip route-static 202.192.96.0 255.255.224.0 220.102.80.1 detect-group 1
ip route-static 218.4.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 218.6.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 218.13.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 218.14.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 218.16.0.0 255.252.0.0 220.102.80.1 detect-group 1
ip route-static 218.20.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 218.21.0.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 218.22.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 218.30.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 218.62.128.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 218.63.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 218.64.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 218.66.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 218.67.0.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 218.70.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 218.72.0.0 255.248.0.0 220.102.80.1 detect-group 1
ip route-static 218.80.0.0 255.240.0.0 220.102.80.1 detect-group 1
ip route-static 219.128.0.0 255.240.0.0 220.102.80.1 detect-group 1
ip route-static 219.144.0.0 255.248.0.0 220.102.80.1 detect-group 1
ip route-static 219.152.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 219.159.64.0 255.255.192.0 220.102.80.1 detect-group 1
ip route-static 219.159.128.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 220.160.0.0 255.224.0.0 220.102.80.1 detect-group 1
ip route-static 221.224.0.0 255.248.0.0 220.102.80.1 detect-group 1
ip route-static 221.232.0.0 255.252.0.0 220.102.80.1 detect-group 1
ip route-static 221.236.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 221.238.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 221.239.0.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 221.239.128.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 222.72.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 222.74.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 222.75.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 222.76.0.0 255.252.0.0 220.102.80.1 detect-group 1
ip route-static 222.80.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 222.82.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 222.83.0.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 222.83.128.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 222.84.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 222.85.0.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 222.85.128.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 222.86.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 222.88.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 222.90.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 222.92.0.0 255.252.0.0 220.102.80.1 detect-group 1
ip route-static 222.168.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 222.172.0.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 222.172.128.0 255.255.128.0 220.102.80.1 detect-group 1
ip route-static 222.173.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 222.174.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 222.176.0.0 255.248.0.0 220.102.80.1 detect-group 1
ip route-static 222.184.0.0 255.248.0.0 220.102.80.1 detect-group 1
ip route-static 222.208.0.0 255.248.0.0 220.102.80.1 detect-group 1
ip route-static 222.216.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 222.218.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 222.219.0.0 255.255.0.0 220.102.80.1 detect-group 1
ip route-static 222.220.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 222.222.0.0 255.254.0.0 220.102.80.1 detect-group 1
ip route-static 222.240.0.0 255.248.0.0 220.102.80.1 detect-group 1
ip route-static 0.0.0.0 0.0.0.0 220.102.80.2 detect-group 1
ip route-static 0.0.0.0 0.0.0.0 202.106.0.21 detect-group 2  preference 80

网通

ip route-static 58.16.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 58.17.0.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 58.17.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 58.18.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 58.19.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 58.20.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 58.21.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 58.22.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 58.100.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 58.240.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 58.242.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 58.244.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 58.246.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 58.248.0.0 255.248.0.0 202.106.0.20 detect-group 2
ip route-static 60.0.0.0 255.248.0.0 202.106.0.20 detect-group 2
ip route-static 60.8.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 60.10.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 60.11.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 60.12.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 60.13.0.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 60.13.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 60.14.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 60.16.0.0 255.248.0.0 202.106.0.20 detect-group 2
ip route-static 60.24.0.0 255.252.0.0 202.106.0.20 detect-group 2
ip route-static 60.28.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 60.30.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 60.31.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 60.208.0.0 255.248.0.0 202.106.0.20 detect-group 2
ip route-static 60.216.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 60.218.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 60.220.0.0 255.252.0.0 202.106.0.20 detect-group 2
ip route-static 61.48.0.0 255.248.0.0 202.106.0.20 detect-group 2
ip route-static 61.48.0.0 255.252.0.0 202.106.0.20 detect-group 2
ip route-static 61.52.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 61.54.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 61.55.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 61.133.0.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 61.134.96.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 61.134.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 61.135.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 61.136.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 61.137.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 61.138.0.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 61.138.128.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 61.139.128.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 61.148.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 61.149.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 61.156.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 61.158.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 61.159.0.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 61.161.0.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 61.161.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 61.162.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 61.163.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 61.167.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 61.168.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 61.176.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 61.179.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 61.180.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 61.181.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 61.182.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 61.189.0.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 124.90.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 124.162.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 125.210.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 125.32.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 202.96.0.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 202.96.64.0 255.255.248.0 202.106.0.20 detect-group 2
ip route-static 202.96.72.0 255.255.248.0 202.106.0.20 detect-group 2
ip route-static 202.97.128.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 202.97.224.0 255.255.248.0 202.106.0.20 detect-group 2
ip route-static 202.97.240.0 255.255.240.0 202.106.0.20 detect-group 2
ip route-static 202.98.0.0 255.255.248.0 202.106.0.20 detect-group 2
ip route-static 202.98.8.0 255.255.248.0 202.106.0.20 detect-group 2
ip route-static 202.99.64.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 202.99.96.0 255.255.248.0 202.106.0.20 detect-group 2
ip route-static 202.99.128.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 202.99.160.0 255.255.248.0 202.106.0.20 detect-group 2
ip route-static 202.99.168.0 255.255.248.0 202.106.0.20 detect-group 2
ip route-static 202.99.176.0 255.255.240.0 202.106.0.20 detect-group 2
ip route-static 202.99.208.0 255.255.240.0 202.106.0.20 detect-group 2
ip route-static 202.99.224.0 255.255.248.0 202.106.0.20 detect-group 2
ip route-static 202.99.232.0 255.255.248.0 202.106.0.20 detect-group 2
ip route-static 202.99.240.0 255.255.240.0 202.106.0.20 detect-group 2
ip route-static 202.102.128.0 255.255.248.0 202.106.0.20 detect-group 2
ip route-static 202.102.224.0 255.255.248.0 202.106.0.20 detect-group 2
ip route-static 202.102.232.0 255.255.248.0 202.106.0.20 detect-group 2
ip route-static 202.106.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 202.107.0.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 202.108.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 202.110.0.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 202.110.192.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 202.111.128.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 203.79.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 203.80.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 203.81.0.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 203.86.32.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 203.86.64.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 203.90.0.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 203.90.128.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 203.90.192.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 203.92.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 203.93.8.0 255.255.255.0 202.106.0.20 detect-group 2
ip route-static 203.93.192.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 210.12.0.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 210.12.192.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 210.15.128.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 210.13.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 210.14.160.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 210.14.192.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 210.15.0.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 210.15.32.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 210.15.96.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 210.15.128.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 210.16.128.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 210.21.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 210.52.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 210.52.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 210.53.0.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 210.53.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 210.74.96.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 210.74.128.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 210.78.0.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 210.82.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 210.8.0.0 255.252.0.0 202.106.0.20 detect-group 2
ip route-static 210.12.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 210.21.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 210.24.0.0 255.252.0.0 202.106.0.20 detect-group 2
ip route-static 210.56.0.0 255.252.0.0 202.106.0.20 detect-group 2
ip route-static 211.100.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 211.101.0.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 211.147.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 211.167.96.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 218.4.0.0 255.252.0.0 202.106.0.20 detect-group 2
ip route-static 218.10.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 218.21.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 218.24.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 218.26.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 218.27.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 218.28.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 218.56.0.0 255.252.0.0 202.106.0.20 detect-group 2
ip route-static 218.60.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 218.62.0.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 218.60.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 218.67.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 218.68.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 218.104.0.0 255.252.0.0 202.106.0.20 detect-group 2
ip route-static 218.108.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 218.109.159.0 255.255.255.0 202.106.0.20 detect-group 2
ip route-static 219.141.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 219.142.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 219.154.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 219.156.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 219.158.0.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 219.158.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 219.159.0.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 220.248.0.0 255.252.0.0 202.106.0.20 detect-group 2
ip route-static 220.252.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 221.0.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 221.2.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 221.3.0.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 221.3.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 221.4.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 221.5.0.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 221.5.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 221.6.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 221.7.0.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 221.7.32.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 221.7.64.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 221.7.96.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 221.8.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 221.10.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 221.11.0.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 221.11.128.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 221.11.192.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 221.12.0.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 221.12.128.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 221.13.0.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 221.13.64.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 221.13.96.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 221.13.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 221.14.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 221.192.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 221.194.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 221.195.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 221.196.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 221.198.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 221.198.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 221.199.0.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 221.199.32.0 255.255.240.0 202.106.0.20 detect-group 2
ip route-static 221.199.128.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 221.199.192.0 255.255.240.0 202.106.0.20 detect-group 2
ip route-static 221.200.0.0 255.252.0.0 202.106.0.20 detect-group 2
ip route-static 221.204.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 221.206.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 221.207.0.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 221.207.64.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 221.207.128.0 255.255.128.0 202.106.0.20 detect-group 2
ip route-static 221.208.0.0 255.252.0.0 202.106.0.20 detect-group 2
ip route-static 221.212.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 221.213.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 221.216.0.0 255.248.0.0 202.106.0.20 detect-group 2
ip route-static 222.128.0.0 255.252.0.0 202.106.0.20 detect-group 2
ip route-static 222.132.0.0 255.252.0.0 202.106.0.20 detect-group 2
ip route-static 222.136.0.0 255.248.0.0 202.106.0.20 detect-group 2
ip route-static 222.160.0.0 255.254.0.0 202.106.0.20 detect-group 2
ip route-static 222.162.0.0 255.255.0.0 202.106.0.20 detect-group 2
ip route-static 222.163.0.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 222.163.32.0 255.255.224.0 202.106.0.20 detect-group 2
ip route-static 222.163.64.0 255.255.192.0 202.106.0.20 detect-group 2
ip route-static 222.163.128.0 255.255.128.0 202.106.0.20 detect-group 2

 

 

nqa-detect-gorup

V5平台的nqa配置-检测下一跳是否可达,配合静态路由?#20174;?

nqa entry admin icmp1
type icmp-echo
destination ip 220.102.80.2
probe count 10
reaction 1 checked-element probe-fail threshold-type consecutive 3 action-type trigger-only
probe timeout 500
quit
nqa schedule admin icmp1 start now lifetime forever—–启用nqa实体检测

nqa entry admin icmp2
type icmp-echo
destination ip 202.106.0.21
probe count 10
reaction 2 checked-element probe-fail threshold-type consecutive 3 action-type trigger-only
probe timeout 500
quit
nqa schedule admin icmp2 start now lifetime forever

[H3C]track 1 nqa entry admin icmp1 reaction 1———-关联上面的reaction 1 

[H3C]track 2 nqa entry admin icmp2 reaction 2———-关联上面的reaction 2

v3平台的detect方式,检测下一跳是否可达,配合静态路由?#20174;?

[SwitchA]detect-group 1

[SwitchA-detect-group-8]detect-list 1 ip address 220.102.80.2

[SwitchA]ip route-static 192.168.0.0 255.255.255.0 10.1.1.1 detect-group 1

[SwitchA]detect-group 2

[SwitchA-detect-group-8]detect-list 1 ip address 202.106.0.21

[SwitchA]ip route-static 192.168.0.0 255.255.255.0 10.1.1.1 detect-group 2

说明:
220.102.80.2——–电信链路中的外网网关
202.106.0.21-----网通链路中的外网网关

上面的nqa是针对的V5平台的设备进行的链路检测的配置方法,在后续的两个路由表中,?#21152;?#20102;track的命令。
      detect-group是早期产品的用法,后续的两个路由表中带detect-group的命令适合其使用。

注意在实?#25163;行?#25913;网通电信的地址?#20445;?#21487;以在文本文档中进?#23567;?#26367;换”编辑,将我示例中的220.102.80.1和202.106.0.20两个地址
修改为自己的ip地址,做法不赘述。

?#27604;?#22914;果除了这些明细路由,可能还有没有匹配上的路由,这?#26412;?#38656;要做两条?#31508;?#36335;由,同时保证一条的优先级别高,如下,如果没有精确路由
就去匹配电信的路由,同时网通线路做备份:

V5平台:

ip route-static 0.0.0.0 0.0.0.0 220.102.80.2 track 1
ip route-static 0.0.0.0 0.0.0.0 202.106.0.21 track 2

V3平台:

ip route-static 0.0.0.0 0.0.0.0 220.102.80.2 detect-group 1
ip route-static 0.0.0.0 0.0.0.0 202.106.0.21 detect-group 2

 

ip route-static 58.32.0.0 255.248.0.0 220.102.80.1 track 1
ip route-static 58.40.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 58.42.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 58.43.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 58.44.0.0 255.252.0.0 220.102.80.1 track 1
ip route-static 58.48.0.0 255.248.0.0 220.102.80.1 track 1
ip route-static 58.56.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 58.58.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 58.59.0.0 255.255.128.0 220.102.80.1 track 1
ip route-static 58.60.0.0 255.252.0.0 220.102.80.1 track 1
ip route-static 58.208.0.0 255.240.0.0 220.102.80.1 track 1
ip route-static 59.32.0.0 255.248.0.0 220.102.80.1 track 1
ip route-static 59.40.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 59.42.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 59.43.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 59.44.0.0 255.252.0.0 220.102.80.1 track 1
ip route-static 59.48.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 59.49.0.0 255.255.128.0 220.102.80.1 track 1
ip route-static 59.49.128.0 255.255.128.0 220.102.80.1 track 1
ip route-static 59.50.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 59.51.0.0 255.255.128.0 220.102.80.1 track 1
ip route-static 59.51.128.0 255.255.128.0 220.102.80.1 track 1
ip route-static 59.52.0.0 255.252.0.0 220.102.80.1 track 1
ip route-static 59.56.0.0 255.252.0.0 220.102.80.1 track 1
ip route-static 59.60.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 59.62.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 60.160.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 60.162.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 60.164.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 60.168.0.0 255.248.0.0 220.102.80.1 track 1
ip route-static 60.176.0.0 255.240.0.0 220.102.80.1 track 1
ip route-static 61.132.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 61.133.128.0 255.255.128.0 220.102.80.1 track 1
ip route-static 61.134.0.0 255.255.192.0 220.102.80.1 track 1
ip route-static 61.134.64.0 255.255.224.0 220.102.80.1 track 1
ip route-static 61.136.128.0 255.255.128.0 220.102.80.1 track 1
ip route-static 61.137.0.0 255.255.128.0 220.102.80.1 track 1
ip route-static 61.138.192.0 255.255.192.0 220.102.80.1 track 1
ip route-static 61.139.0.0 255.255.128.0 220.102.80.1 track 1
ip route-static 61.139.192.0 255.255.192.0 220.102.80.1 track 1
ip route-static 61.140.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 61.144.0.0 255.252.0.0 220.102.80.1 track 1
ip route-static 61.152.0.0 255.252.0.0 220.102.80.1 track 1
ip route-static 61.157.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 61.159.64.0 255.255.192.0 220.102.80.1 track 1
ip route-static 61.159.128.0 255.255.128.0 220.102.80.1 track 1
ip route-static 61.160.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 61.161.64.0 255.255.192.0 220.102.80.1 track 1
ip route-static 61.164.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 61.166.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 61.169.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 61.170.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 61.172.0.0 255.252.0.0 220.102.80.1 track 1
ip route-static 61.177.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 61.178.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 61.180.0.0 255.255.128.0 220.102.80.1 track 1
ip route-static 61.183.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 61.184.0.0 255.252.0.0 220.102.80.1 track 1
ip route-static 61.188.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 61.189.128.0 255.255.128.0 220.102.80.1 track 1
ip route-static 61.190.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 25.64.0.0 255.248.0.0 220.102.80.1 track 1
ip route-static 25.72.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 25.80.0.0 255.248.0.0 220.102.80.1 track 1
ip route-static 25.88.0.0 255.248.0.0 220.102.80.1 track 1
ip route-static 25.104.0.0 255.248.0.0 220.102.80.1 track 1
ip route-static 25.112.0.0 255.240.0.0 220.102.80.1 track 1
ip route-static 202.96.104.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.96.96.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.96.112.0 255.255.240.0 220.102.80.1 track 1
ip route-static 202.96.128.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.96.136.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.96.144.0 255.255.240.0 220.102.80.1 track 1
ip route-static 202.96.160.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.96.168.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.96.176.0 255.255.240.0 220.102.80.1 track 1
ip route-static 202.96.200.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.96.208.0 255.255.240.0 220.102.80.1 track 1
ip route-static 202.96.224.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.97.0.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.97.8.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.97.16.0 255.255.240.0 220.102.80.1 track 1
ip route-static 202.97.32.0 255.255.224.0 220.102.80.1 track 1
ip route-static 202.97.64.0 255.255.224.0 220.102.80.1 track 1
ip route-static 202.97.96.0 255.255.240.0 220.102.80.1 track 1
ip route-static 202.97.112.0 255.255.240.0 220.102.80.1 track 1
ip route-static 202.98.32.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.98.48.0 255.255.240.0 220.102.80.1 track 1
ip route-static 202.98.64.0 255.255.224.0 220.102.80.1 track 1
ip route-static 202.98.96.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.98.128.0 255.255.224.0 220.102.80.1 track 1
ip route-static 202.98.160.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.98.168.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.98.192.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.98.200.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.98.208.0 255.255.240.0 220.102.80.1 track 1
ip route-static 202.98.224.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.98.232.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.98.240.0 255.255.240.0 220.102.80.1 track 1
ip route-static 202.99.192.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.100.96.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.100.104.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.100.112.0 255.255.240.0 220.102.80.1 track 1
ip route-static 202.100.136.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.100.160.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.100.168.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.100.176.0 255.255.240.0 220.102.80.1 track 1
ip route-static 202.100.192.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.100.208.0 255.255.240.0 220.102.80.1 track 1
ip route-static 202.100.224.0 255.255.224.0 220.102.80.1 track 1
ip route-static 202.101.0.0 255.255.192.0 220.102.80.1 track 1
ip route-static 202.101.64.0 255.255.224.0 220.102.80.1 track 1
ip route-static 202.101.96.0 255.255.224.0 220.102.80.1 track 1
ip route-static 202.101.128.0 255.255.192.0 220.102.80.1 track 1
ip route-static 202.101.224.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.102.0.0 255.255.224.0 220.102.80.1 track 1
ip route-static 202.102.32.0 255.255.224.0 220.102.80.1 track 1
ip route-static 202.102.64.0 255.255.192.0 220.102.80.1 track 1
ip route-static 202.103.0.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.103.8.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.103.16.0 255.255.240.0 220.102.80.1 track 1
ip route-static 202.103.32.0 255.255.224.0 220.102.80.1 track 1
ip route-static 202.103.192.0 255.255.224.0 220.102.80.1 track 1
ip route-static 202.103.224.0 255.255.248.0 220.102.80.1 track 1
ip route-static 202.104.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 202.107.128.0 255.255.128.0 220.102.80.1 track 1
ip route-static 202.109.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 202.110.128.0 255.255.192.0 220.102.80.1 track 1
ip route-static 202.111.0.0 255.255.128.0 220.102.80.1 track 1
ip route-static 202.130.32.0 255.255.224.0 220.102.80.1 track 1
ip route-static 202.212.0.0 255.255.240.0 220.102.80.1 track 1
ip route-static 202.192.96.0 255.255.224.0 220.102.80.1 track 1
ip route-static 218.4.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 218.6.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 218.13.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 218.14.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 218.16.0.0 255.252.0.0 220.102.80.1 track 1
ip route-static 218.20.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 218.21.0.0 255.255.128.0 220.102.80.1 track 1
ip route-static 218.22.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 218.30.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 218.62.128.0 255.255.128.0 220.102.80.1 track 1
ip route-static 218.63.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 218.64.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 218.66.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 218.67.0.0 255.255.128.0 220.102.80.1 track 1
ip route-static 218.70.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 218.72.0.0 255.248.0.0 220.102.80.1 track 1
ip route-static 218.80.0.0 255.240.0.0 220.102.80.1 track 1
ip route-static 219.128.0.0 255.240.0.0 220.102.80.1 track 1
ip route-static 219.144.0.0 255.248.0.0 220.102.80.1 track 1
ip route-static 219.152.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 219.159.64.0 255.255.192.0 220.102.80.1 track 1
ip route-static 219.159.128.0 255.255.128.0 220.102.80.1 track 1
ip route-static 220.160.0.0 255.224.0.0 220.102.80.1 track 1
ip route-static 221.224.0.0 255.248.0.0 220.102.80.1 track 1
ip route-static 221.232.0.0 255.252.0.0 220.102.80.1 track 1
ip route-static 221.236.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 221.238.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 221.239.0.0 255.255.128.0 220.102.80.1 track 1
ip route-static 221.239.128.0 255.255.128.0 220.102.80.1 track 1
ip route-static 222.72.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 222.74.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 222.75.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 222.76.0.0 255.252.0.0 220.102.80.1 track 1
ip route-static 222.80.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 222.82.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 222.83.0.0 255.255.128.0 220.102.80.1 track 1
ip route-static 222.83.128.0 255.255.128.0 220.102.80.1 track 1
ip route-static 222.84.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 222.85.0.0 255.255.128.0 220.102.80.1 track 1
ip route-static 222.85.128.0 255.255.128.0 220.102.80.1 track 1
ip route-static 222.86.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 222.88.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 222.90.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 222.92.0.0 255.252.0.0 220.102.80.1 track 1
ip route-static 222.168.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 222.172.0.0 255.255.128.0 220.102.80.1 track 1
ip route-static 222.172.128.0 255.255.128.0 220.102.80.1 track 1
ip route-static 222.173.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 222.174.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 222.176.0.0 255.248.0.0 220.102.80.1 track 1
ip route-static 222.184.0.0 255.248.0.0 220.102.80.1 track 1
ip route-static 222.208.0.0 255.248.0.0 220.102.80.1 track 1
ip route-static 222.216.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 222.218.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 222.219.0.0 255.255.0.0 220.102.80.1 track 1
ip route-static 222.220.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 222.222.0.0 255.254.0.0 220.102.80.1 track 1
ip route-static 222.240.0.0 255.248.0.0 220.102.80.1 track 1
ip route-static 0.0.0.0 0.0.0.0 220.102.80.2 track 1
ip route-static 0.0.0.0 0.0.0.0 202.106.0.21 track 2  preference  80

 

 

网通 

ip route-static 58.16.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 58.17.0.0 255.255.128.0 202.106.0.20 track 2
ip route-static 58.17.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 58.18.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 58.19.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 58.20.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 58.21.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 58.22.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 58.100.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 58.240.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 58.242.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 58.244.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 58.246.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 58.248.0.0 255.248.0.0 202.106.0.20 track 2
ip route-static 60.0.0.0 255.248.0.0 202.106.0.20 track 2
ip route-static 60.8.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 60.10.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 60.11.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 60.12.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 60.13.0.0 255.255.192.0 202.106.0.20 track 2
ip route-static 60.13.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 60.14.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 60.16.0.0 255.248.0.0 202.106.0.20 track 2
ip route-static 60.24.0.0 255.252.0.0 202.106.0.20 track 2
ip route-static 60.28.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 60.30.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 60.31.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 60.208.0.0 255.248.0.0 202.106.0.20 track 2
ip route-static 60.216.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 60.218.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 60.220.0.0 255.252.0.0 202.106.0.20 track 2
ip route-static 61.48.0.0 255.248.0.0 202.106.0.20 track 2
ip route-static 61.48.0.0 255.252.0.0 202.106.0.20 track 2
ip route-static 61.52.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 61.54.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 61.55.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 61.133.0.0 255.255.128.0 202.106.0.20 track 2
ip route-static 61.134.96.0 255.255.224.0 202.106.0.20 track 2
ip route-static 61.134.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 61.135.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 61.136.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 61.137.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 61.138.0.0 255.255.128.0 202.106.0.20 track 2
ip route-static 61.138.128.0 255.255.192.0 202.106.0.20 track 2
ip route-static 61.139.128.0 255.255.192.0 202.106.0.20 track 2
ip route-static 61.148.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 61.149.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 61.156.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 61.158.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 61.159.0.0 255.255.192.0 202.106.0.20 track 2
ip route-static 61.161.0.0 255.255.192.0 202.106.0.20 track 2
ip route-static 61.161.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 61.162.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 61.163.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 61.167.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 61.168.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 61.176.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 61.179.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 61.180.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 61.181.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 61.182.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 61.189.0.0 255.255.128.0 202.106.0.20 track 2
ip route-static 124.90.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 124.162.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 125.210.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 125.32.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 202.96.0.0 255.255.192.0 202.106.0.20 track 2
ip route-static 202.96.64.0 255.255.248.0 202.106.0.20 track 2
ip route-static 202.96.72.0 255.255.248.0 202.106.0.20 track 2
ip route-static 202.97.128.0 255.255.192.0 202.106.0.20 track 2
ip route-static 202.97.224.0 255.255.248.0 202.106.0.20 track 2
ip route-static 202.97.240.0 255.255.240.0 202.106.0.20 track 2
ip route-static 202.98.0.0 255.255.248.0 202.106.0.20 track 2
ip route-static 202.98.8.0 255.255.248.0 202.106.0.20 track 2
ip route-static 202.99.64.0 255.255.224.0 202.106.0.20 track 2
ip route-static 202.99.96.0 255.255.248.0 202.106.0.20 track 2
ip route-static 202.99.128.0 255.255.224.0 202.106.0.20 track 2
ip route-static 202.99.160.0 255.255.248.0 202.106.0.20 track 2
ip route-static 202.99.168.0 255.255.248.0 202.106.0.20 track 2
ip route-static 202.99.176.0 255.255.240.0 202.106.0.20 track 2
ip route-static 202.99.208.0 255.255.240.0 202.106.0.20 track 2
ip route-static 202.99.224.0 255.255.248.0 202.106.0.20 track 2
ip route-static 202.99.232.0 255.255.248.0 202.106.0.20 track 2
ip route-static 202.99.240.0 255.255.240.0 202.106.0.20 track 2
ip route-static 202.102.128.0 255.255.248.0 202.106.0.20 track 2
ip route-static 202.102.224.0 255.255.248.0 202.106.0.20 track 2
ip route-static 202.102.232.0 255.255.248.0 202.106.0.20 track 2
ip route-static 202.106.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 202.107.0.0 255.255.128.0 202.106.0.20 track 2
ip route-static 202.108.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 202.110.0.0 255.255.128.0 202.106.0.20 track 2
ip route-static 202.110.192.0 255.255.192.0 202.106.0.20 track 2
ip route-static 202.111.128.0 255.255.192.0 202.106.0.20 track 2
ip route-static 203.79.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 203.80.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 203.81.0.0 255.255.224.0 202.106.0.20 track 2
ip route-static 203.86.32.0 255.255.224.0 202.106.0.20 track 2
ip route-static 203.86.64.0 255.255.224.0 202.106.0.20 track 2
ip route-static 203.90.0.0 255.255.128.0 202.106.0.20 track 2
ip route-static 203.90.128.0 255.255.192.0 202.106.0.20 track 2
ip route-static 203.90.192.0 255.255.224.0 202.106.0.20 track 2
ip route-static 203.92.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 203.93.8.0 255.255.255.0 202.106.0.20 track 2
ip route-static 203.93.192.0 255.255.192.0 202.106.0.20 track 2
ip route-static 210.12.0.0 255.255.128.0 202.106.0.20 track 2
ip route-static 210.12.192.0 255.255.192.0 202.106.0.20 track 2
ip route-static 210.15.128.0 255.255.192.0 202.106.0.20 track 2
ip route-static 210.13.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 210.14.160.0 255.255.224.0 202.106.0.20 track 2
ip route-static 210.14.192.0 255.255.224.0 202.106.0.20 track 2
ip route-static 210.15.0.0 255.255.128.0 202.106.0.20 track 2
ip route-static 210.15.32.0 255.255.224.0 202.106.0.20 track 2
ip route-static 210.15.96.0 255.255.224.0 202.106.0.20 track 2
ip route-static 210.15.128.0 255.255.192.0 202.106.0.20 track 2
ip route-static 210.16.128.0 255.255.192.0 202.106.0.20 track 2
ip route-static 210.21.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 210.52.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 210.52.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 210.53.0.0 255.255.128.0 202.106.0.20 track 2
ip route-static 210.53.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 210.74.96.0 255.255.224.0 202.106.0.20 track 2
ip route-static 210.74.128.0 255.255.224.0 202.106.0.20 track 2
ip route-static 210.78.0.0 255.255.224.0 202.106.0.20 track 2
ip route-static 210.82.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 210.8.0.0 255.252.0.0 202.106.0.20 track 2
ip route-static 210.12.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 210.21.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 210.24.0.0 255.252.0.0 202.106.0.20 track 2
ip route-static 210.56.0.0 255.252.0.0 202.106.0.20 track 2
ip route-static 211.100.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 211.101.0.0 255.255.192.0 202.106.0.20 track 2
ip route-static 211.147.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 211.167.96.0 255.255.224.0 202.106.0.20 track 2
ip route-static 218.4.0.0 255.252.0.0 202.106.0.20 track 2
ip route-static 218.10.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 218.21.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 218.24.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 218.26.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 218.27.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 218.28.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 218.56.0.0 255.252.0.0 202.106.0.20 track 2
ip route-static 218.60.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 218.62.0.0 255.255.128.0 202.106.0.20 track 2
ip route-static 218.60.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 218.67.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 218.68.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 218.104.0.0 255.252.0.0 202.106.0.20 track 2
ip route-static 218.108.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 218.109.159.0 255.255.255.0 202.106.0.20 track 2
ip route-static 219.141.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 219.142.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 219.154.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 219.156.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 219.158.0.0 255.255.128.0 202.106.0.20 track 2
ip route-static 219.158.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 219.159.0.0 255.255.192.0 202.106.0.20 track 2
ip route-static 220.248.0.0 255.252.0.0 202.106.0.20 track 2
ip route-static 220.252.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 221.0.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 221.2.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 221.3.0.0 255.255.128.0 202.106.0.20 track 2
ip route-static 221.3.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 221.4.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 221.5.0.0 255.255.128.0 202.106.0.20 track 2
ip route-static 221.5.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 221.6.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 221.7.0.0 255.255.224.0 202.106.0.20 track 2
ip route-static 221.7.32.0 255.255.224.0 202.106.0.20 track 2
ip route-static 221.7.64.0 255.255.224.0 202.106.0.20 track 2
ip route-static 221.7.96.0 255.255.224.0 202.106.0.20 track 2
ip route-static 221.8.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 221.10.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 221.11.0.0 255.255.128.0 202.106.0.20 track 2
ip route-static 221.11.128.0 255.255.192.0 202.106.0.20 track 2
ip route-static 221.11.192.0 255.255.224.0 202.106.0.20 track 2
ip route-static 221.12.0.0 255.255.128.0 202.106.0.20 track 2
ip route-static 221.12.128.0 255.255.192.0 202.106.0.20 track 2
ip route-static 221.13.0.0 255.255.192.0 202.106.0.20 track 2
ip route-static 221.13.64.0 255.255.224.0 202.106.0.20 track 2
ip route-static 221.13.96.0 255.255.224.0 202.106.0.20 track 2
ip route-static 221.13.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 221.14.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 221.192.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 221.194.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 221.195.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 221.196.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 221.198.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 221.198.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 221.199.0.0 255.255.224.0 202.106.0.20 track 2
ip route-static 221.199.32.0 255.255.240.0 202.106.0.20 track 2
ip route-static 221.199.128.0 255.255.192.0 202.106.0.20 track 2
ip route-static 221.199.192.0 255.255.240.0 202.106.0.20 track 2
ip route-static 221.200.0.0 255.252.0.0 202.106.0.20 track 2
ip route-static 221.204.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 221.206.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 221.207.0.0 255.255.192.0 202.106.0.20 track 2
ip route-static 221.207.64.0 255.255.192.0 202.106.0.20 track 2
ip route-static 221.207.128.0 255.255.128.0 202.106.0.20 track 2
ip route-static 221.208.0.0 255.252.0.0 202.106.0.20 track 2
ip route-static 221.212.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 221.213.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 221.216.0.0 255.248.0.0 202.106.0.20 track 2
ip route-static 222.128.0.0 255.252.0.0 202.106.0.20 track 2
ip route-static 222.132.0.0 255.252.0.0 202.106.0.20 track 2
ip route-static 222.136.0.0 255.248.0.0 202.106.0.20 track 2
ip route-static 222.160.0.0 255.254.0.0 202.106.0.20 track 2
ip route-static 222.162.0.0 255.255.0.0 202.106.0.20 track 2
ip route-static 222.163.0.0 255.255.224.0 202.106.0.20 track 2
ip route-static 222.163.32.0 255.255.224.0 202.106.0.20 track 2
ip route-static 222.163.64.0 255.255.192.0 202.106.0.20 track 2
ip route-static 222.163.128.0 255.255.128.0 202.106.0.20 track 2

H3C MSR系列多业务融合VPN路由器网关

 

1. 产品概述:

H3C MSR多业务融合VPN路由器是杭州华三通信技术有限公司(以下简称“H3C?#20445;?#19987;门面向中小企业而推出的多功能出口网关产品,该系列产品在MSR系列路由器的基础上增配了专用的?#24067;?#21152;密芯片使得各项VPN业务性能获得极大的提升,能够在最小的投资?#27573;?#20869;为中小企业提供高性能的VPN中心网关,该类产品与MSR900系列3G VPN?#31181;?#32593;点接入路由器配合可以为企业提供高性价比的?#31181;?#26426;构VPN网络互联解决方案,并充?#33268;?#36275;未来业务扩展的多元化应用需求,符?#29616;?#23567;企业IT应用随业务发展不断提升?#37027;?#21183;。

n clip_image002MSR2020-AC-S型融合VPN路由器

2 Ipsec VPN加密性能100Mbps/1000条隧道;

2 SSL VPN 支持50?#27809;?并发500连接数;

n clip_image004 MSR3020-AC-AS型融合VPN路由器

2 Ipsec VPN加密性能250Mbps/2000条隧道;

2 SSL VPN 支持100?#27809;?并发1000连接数;

n clip_image006 MSR5040-AC-AS型融合VPN路由器

2 Ipsec VPN加密性能600Mbps/3000条隧道;

2 SSL VPN 支持200?#27809;?并发2000连接数;

2. 产品特点:

2.1 支持多种VPN功能协议,满足多种类型VPN业务应用:

MSR多业务融合VPN路由器支持L2TP、GRE、IPsec、DVPN(动态地址VPN)、SSL VPN 以及MPLS VPN协议,并支持L2TP+Ipsec+Nat融合组网、L2TP自动触发、GREoverIPsec、Ipsec野蛮模式+Nat穿越、Ipsec多机备份、Ipsec与DDNS联动等特色VPN技术,可以很好的满足各行业不同的VPN组网需求。

?#36865;?#35813;系列产品可同时启用多种VPN业务,如同时启用Ipsec和SSL VPN,一台设备即可同时满足?#31181;?#26426;构互联和移动办公应用的VPN混合组网需求。

2.2 专用?#24067;?#21152;密芯片+网络处理器,VPN加密转发性能强劲:

MSR多业务融合VPN路由器采用专用?#24067;?#21152;密芯片来处理VPN业务数据流的加密和解密,而设备主引擎网络处理器(CPU)则专注于处理数据流的高速路由转发,由此保证了MSR多业务融合VPN路由器的VPN业务处理性能。

2.3 提供NAQ网络质量分析工具,确保VPN链路的稳定可靠;

NQA(网络质量分析)是测量网络上运行的各种协议性能的一种工具。它可以实现端到端的网络状况监测,包括时延、抖动、丢包?#23454;取?#19981;仅能使用ICMP协议来测试数据包在本端和指定的目的端之间的往返时间,从而判断目的主机是否可达,还可以探测DLSw、DHCP、FTP、HTTP、SNMP服务器是否打开,以?#23433;?#35797;各种服务的响应时间等,提供对网络应用的质量检测,通过使用此技术可以及时检测VPN链路的可达性和VPN链路的网络质量,确保企业VPN业务的永续性。

2.4 支持VPN应用与多种业务融合,持久保护?#27809;?#30340;IT投?#21097;?/b>

随着企?#26723;?#21457;展IT应?#27809;?#26085;益?#30001;睿琈SR多业务融合VPN路由器不仅可以提供基本的路由转发和VPN业务,还可以?#20013;?#21319;级为企业提供基于VPN链路的H3C OCS企业统一通信业务(包括IP即时通信业务,IP会议电话业务)满足企业协同办公需求,以及扩展OAP模块提供网络防毒墙、网络流量分析、广域网优化等应用。

3. 产品规格:

表1-1 MSR多业务融合VPN路由器规格简表

项目

MSR 2020-AC-S

MSR 3020-AC-AS

MSR 5040-AC-AS

处理器CPU

RISC新一代处理器(400MHz)

RISC新一代处理器(533MHz)

RISC新一代处理器(833MHz)

内存(可扩展)

128M(DDR)

256M(DDR)

512M(DDR)

数据包转发性能

180Kpps

300Kpps

800Kpps

固定接口

2个百兆以太电口

2个千兆以太电口

2个千兆以太电口(combo)

模块插槽

2个SIC插槽

4个SIC插槽

4个SIC插槽

2个MIM插槽

4个FIC插槽

USB

1个(支?#31181;?#23450;型号的3G上网卡)

VPN?#24067;?#21152;密

100Mbps

250Mbps

600Mbps

Ipsec VPN?#27809;?#25968;

50?#27809;?#20197;内

50~300?#27809;?/p>

300?#27809;?#20197;上

SSL VPN?#27809;?#25968;

50?#27809;?/p>

100?#27809;?/p>

200?#27809;?/p>

最大功耗

54W

125W

350W

电源(AC)

输入额定?#27573;В?/p>

输入额定?#27573;В?/p>

输入额定?#27573;В?/p>

100~240V 50/60Hz

100~240V 50/60Hz

100~240V 50/60Hz

外形尺寸

(W×D×H)

360mm×287mm×44.2mm

442mm×442mm×44.2mm

436mm×442mm×

131mm

环境温度

0~40℃

0~40℃

0~40℃

环境相对湿度

5~90%(不结露)

5~90%(不结露)

5~90%(不结露)

4. 典型应用:

4.1 :L2TP+IPsec VPN融合组网,构建企业?#31181;?#32593;点互联VPN网络

clip_image008

设备推荐

规模

50人以下

50~300人

300人以上

总部

MSR2020-AC-S

MSR3020-AC-AS

MSR5040-AC-AS

?#31181;?/p>

MSR900

MSR920

MSR2010

适用?#27573;?/b>

农村合作医疗、社区医疗、社保、加油站

方案特色

1) ?#31181;?#32593;点采用L2TP和IPsec配合实现更安全的数据加密;

2) ?#31181;?#32593;点可以采用ADSL线路,可以为动态IP地址模式;

3) 中心点可以也可以为动态IP地址模式,但需要启动IPSEC+DDNS联动;

4) H3C可以提供中心点双设备热备份,及NAQ VPN网络链路性能检测

4.2 :SSL VPN标准组网(为企业移动员工访问企业总部网络提供安全VPN接入)

clip_image010

设备推荐

规模

50人以下

100人以下

200人以下

总部

MSR2020-AC-S

MSR3020-AC-AS

MSR5040-AC-AS

适用?#27573;?/b>

中小企业、制造业、贸易、连锁零售业、保险网点、房地产中介等

方案特色

1) 无需客户端,使用IE浏览器即可通过?#27809;?#21517;和密码登陆。

2) 中心点可以是动态IP地址模式,需要启动DDNS;

3) 一台设备兼做企业出口路由器和SSL VPN网关,最优化?#27809;?#25237;?#21097;?/p>

4.3 :SSL VPN+IPsec VPN融合组网(为企业总部、?#31181;?#21644;移动员工提供安全VPN接入)

clip_image012

设备推荐

规模

50人以下

50~300

300人以上

总部

MSR2020-AC-S

MSR3020-AC-AS

MSR5040-AC-AS

?#31181;?/p>

MSR900

MSR920

MSR2010

适用?#27573;?/b>

企业?#31181;?#26426;构互连、连锁、物流、制造业、贸易,零售业。

方案特色

1. SSL VPN无客户端,易布署,接入方便,满足移动办工的需求;

2. MSR路由器可同时开启IPsec和SSL,最优化?#27809;?#25237;?#21097;?/p>

成大方圆连锁药店VPN解决方案

No Comments 网络技术 ,

 

成大方圆新建26家连锁?#20540;輳?#38656;要每天向总?#30475;?#36865;数据。公司总部使用两台F1000千兆VPN网关设备。沈阳总部使用原有VPN设备,保护投?#30465;?#26032;建连锁?#20540;?#20351;用MSR900自带的VPN功能与总部建立IPSEC VPN进行通讯。

clip_image002

方案特点:

1、强大的VPN处理性能。千兆VPN网关可以提供标?#25216;用?#31639;法下600Mbps以上的加密吞吐量

2、独特的冗余链路解决方案。总部的主用和备用VPN网关负载?#20540;?#19994;务,或者链路失效?#20445;?#21487;以自动切换到备用链路上,保障业务连续性。

3、提供图形化界面的VPN管理工具。H3C IPSec VPN软件能够自动发现和构建VPN拓扑,实时接收IPSec VPN设备的告警,并利用该模块提供的丰富的过滤功能定位关键的告警数据。

4、设备支持的VPN功能丰富。支持IPSec、L2TP、GRE等多种模式VPN,而且能够集成应用,充?#33268;?#36275;将来系统扩展的需求。

5、MSR900还支持CDMA2000、WCDMA、TD-SCDMA无线3G通信功能,满足?#27809;?#23545;于3G无线上行主链路和备份链路的应用需求。该产品同时具有强大的防火墙与VPN功能,支持包过滤防火墙、状态防火墙、DDOS防攻击、IPSec VPN等安全功能。

H3C NTP服务器相关配置

No Comments 网络技术 ,

配置NTP 服务器1. 组网需求

    router1 设置本地时钟作为ntp 主时钟,层数为2,router2 以router1 作为时间服务器,将其设为server 模式,自己为client 模式。

    2. 组网图

    3. 配置步骤

    (1) 配置router1

    # 进入系统视图。

    [h3c] system-view

    # 设置本地时钟作为ntp 主时钟,层数为2。

    [h3c] ntp-service refclock-master 2

    (2) 配置router2

    # 进入系统视图。

    [h3c] system-view

    # 设置router1 为时间服务器。

    [h3c] ntp-service unicast-server 1.0.1.11

    以上配置将router2 向router1 进行时间同步,同步前观察router2 的状态为:

    [h3c] display ntp-service status

    clock status: unsynchronized

    clock stratum: 16

    reference clock id: none

    nominal frequency: 99.8562 hz

    actual frequency: 99.8562 hz

    clock precision: 2^7

    clock offset: 0.0000 ms

    root delay : 0.00 ms

    root dispersion: 0.00 ms

    peer dispersion: 0.00 ms

    reference time: 00:00:00.000 utc jan 1 1900 (00000000.00000000)

    同步后观测router2 的状态为:

    [h3c] display ntp-service status

    clock status: synchronized

    clock stratum: 3

    reference clock id: 1.0.1.11

    nominal frequency: 250.0000 hz

    actual frequency: 249.9992 hz

    clock precision: 2^19

    clock offset: 198.7425 ms

    root delay : 27.47 ms

    root dispersion: 208.39 ms

    peer dispersion: 9.63 ms

    reference time: 17:03:32.022 utc thu apr 6 2006 (bf422ae4.05aea86c)

    此时router2 已经与router1 同步,层数比router1 大1,为3。

    观察router2 的sessions 情况,router2 与router1 建立了连接。

H3C 对通过SNMP访问交换机的?#27809;?#30340;ACL控制配置

 

配置举例1. 组网需求

仅允许来自10.110.100.52和10.110.100.46的SNMP?#27809;?#35775;问交换机。

2. 组网图

clip_image001

图3-3 对Switch的SNMP?#27809;?#36827;行ACL控制

3. 配置步骤

# 定义基本访问控制列表和子规则。

<H3C> system-view

System View: return to User View with Ctrl+Z.

[H3C] acl number 2000 match-order config

[H3C-acl-baisc-2000] rule 1 permit source 10.110.100.52 0

[H3C-acl-baisc-2000] rule 2 permit source 10.110.100.46 0

[H3C-acl-basic-2000] rule 3 deny source any

[H3C-acl-baisc-2000] quit

# 引用访问控制列表。

[H3C] snmp-agent community read H3C acl 2000

[H3C] snmp-agent group v3 H3Cgroup acl 2000

[H3C] snmp-agent usm-user v3 H3Cuser H3Cgroup acl 2000

H3C配置对SSH/Telnet ?#27809;?#30340;ACL 控制

No Comments 网络技术 , , ,

配置对Telnet/SSH ?#27809;?#30340;ACL 控制通过配置对telnet 或ssh ?#27809;?#30340;acl 控制,可以在登?#21152;没?#36827;行口令?#29616;?#20043;前将一些恶意或者不合法的连接请求过?#35828;簦?#20445;证设备的安全。

    4.2.1 配置准备

    ?#27809;?#23545;telnet 或ssh 方式登录交换机进行了正确配置。

    4.2.2 配置过程

    ?#31508;?#24773;况下,不对?#27809;?#30028;面的呼入(inbound)/ 呼出(outbound)进行限制。

    telnet 或ssh ?#27809;?#30340;acl 控制功能只能引用基于数字标识的访问控制列表。

    telnet 或ssh ?#27809;?#24341;用基本访问控制列表或高级访问控制列表?#20445;?#22522;于源ip或目的ip 地址对呼入/呼出进行限制。因此引用基本访问控制列表和高级访问控制列表子规则?#20445;?#21482;有源ip 及其掩码、目的ip 及其掩码、time-range ?#38382;?#26377;效。类似的,telnet 和ssh ?#27809;?#24341;用二层访问控制列表?#20445;?#22522;于源mac 地址对呼入/呼出进行限制。因此引用二层访问控制列表子规则?#20445;?#21482;有源mac 及其掩码、time-range ?#38382;?#26377;效。

    基于二层访问控制列表对telnet、ssh ?#27809;?#36827;行控制?#20445;?#21482;能限制呼入。

    对由于受acl 限制而被拒绝登录的?#27809;В?#20250;记录一次访问失败日志信息。日志内容包括该?#27809;?#30340;ip 地址、登录方式、登入?#27809;?#30028;面索引值和登录失败原因。

    4.2.3 二层acl 控制配置举例

    1. 组网需求

    仅允许源mac 地址为00e0-fc01-0101 和00e0-fc01-0303 的telnet ?#27809;?#35775;问交换机。

    2. 组网图

    3. 配置步骤

    # 定义二层访问控制列表。

    [h3c] system-view

    system view: return to user view with ctrl+z.

    [h3c] acl number 4000 match-order config

    # 定义子规则。

    [h3c-acl-link-4000] rule 1 permit ingress 00e0-fc01-0101 0000-0000-0000 [h3c-acl-link-4000] rule 2 permit ingress 00e0-fc01-0303 0000-0000-0000 [h3c-acl-link-4000] rule 3 deny ingress any

    [h3c-acl-link-4000] rule 3 deny ingress any

    [h3c-acl-link-4000] quit

    # 进入?#27809;?#30028;面视图。

    [h3c] user-interface vty 0 4

    # 引用二层访问控制列表,对?#27809;?#30028;面的呼入进行限制。

    [h3c-user-interface-vty0-4] acl 4000 inbound

    4.2.4 基本acl 控制配置举例

    1. 组网需求

    仅允许来自10.110.100.52 和10.110.100.46 的telnet ?#27809;?#35775;问交换机。

    2. 组网图

    3. 配置步骤

    # 定义基本访问控制列表。

    [h3c] system-view

    system view: return to user view with ctrl+z.

    [h3c] acl number 2000 match-order config

    # 定义子规则。

    [h3c-acl-basic-2000] rule 1 permit source 10.110.100.52 0

    [h3c-acl-basic-2000] rule 2 permit source 10.110.100.46 0

    [h3c-acl-basic-2000] rule 3 deny source any

    [h3c-acl-basic-2000] quit

    # 进入?#27809;?#30028;面视图。

    [h3c] user-interface vty 0 4

    # 引用访问控制列表。

    [h3c-user-interface-vty0-4] acl 2000 inbound

H3C各种型号交换机端口镜像配置方法总结

H3C各种型号交换机端口镜像配置方法总结一、端口镜像概念:
Port Mirror(端口镜像)是用于进行网络性能监测。可以这样理解:在端口A 和端口B 之间建立镜像关系,这样,通过端口A 传输的数据将同?#22791;?#21046;到端口B ,以便于在端口B 上连接的分析仪或者分析软件进行性能分析或故障判断。
二、端口镜像配置
『环境配置?#38382;?
1. PC1接在交换机E0/1端口,IP地址1.1.1.1/24
2. PC2接在交换机E0/2端口,IP地址2.2.2.2/24
3. E0/24为交换机上行端口
4. Server接在交换机E0/8端口,该端口作为镜像端口
『组网需求』
1. 通过交换机端口镜像的功能使用server对两台pc的业务报文进行监控。
2. 按?#31449;?#20687;的不同方式进?#20449;?#32622;:
1) 基于端口的镜像
2) 基于流的镜像
2 数据配置步骤
『端口镜像的数据流程』
基于端口的镜像是把被镜像端口的进出数据报文完全拷贝一份到镜像端口,这样来进行流量观测或者故障定位。
【3026等交换机镜像】
S2008/S2016/S2026/S2403H/S3026等交换机支持的都是基于端口的镜像,有两种方法:
方法一
1. 配置镜像(观测)端口
[SwitchA]monitor-port e0/8
2. 配置被镜像端口
[SwitchA]port mirror Ethernet 0/1 to Ethernet 0/2
方法二
1. 可以一次性定义镜像和被镜像端口
[SwitchA]port mirror Ethernet 0/1 to Ethernet 0/2 observing-port Ethernet 0/8
【8016交换机端口镜像配置】
1. 假设8016交换机镜像端口为E1/0/15,被镜像端口为E1/0/0,设置端口1/0/15为端口镜像的观测端口。
[SwitchA] port monitor ethernet 1/0/15
2. 设置端口1/0/0为被镜像端口,对其输入输出数据都进行镜像。
[SwitchA] port mirroring ethernet 1/0/0 both ethernet 1/0/15
也可以通过两个不同的端口,对输入和输出的数据分别镜像
1. 设置E1/0/15和E2/0/0为镜像(观测)端口
[SwitchA] port monitor ethernet 1/0/15
2. 设置端口1/0/0为被镜像端口,分别使用E1/0/15和E2/0/0对输入和输出数据进行镜像。
[SwitchA] port mirroring gigabitethernet 1/0/0 ingress ethernet 1/0/15
[SwitchA] port mirroring gigabitethernet 1/0/0 egress ethernet 2/0/0
『基于流镜像的数据流程』
基于流镜像的交换机针对某些流进行镜像,每个连接?#21152;?#20004;个方向的数据流,对于交换机来说这两个数据流是要分开镜像的。
【3500/3026E/3026F/3050】
〖基于三层流的镜像〗
1. 定义一条扩展访问控制列表
[SwitchA]acl num 100
2. 定义一条规则报文源地址为1.1.1.1/32去往所有目的地址
[SwitchA-acl-adv-101]rule 0 permit ip source 1.1.1.1 0 destination any
3. 定义一条规则报文源地址为所有源地址目的地址为1.1.1.1/32
[SwitchA-acl-adv-101]rule 1 permit ip source any destination 1.1.1.1 0
4. 将符合上述ACL规则的报文镜像到E0/8端口
[SwitchA]mirrored-to ip-group 100 interface e0/8
〖基于二层流的镜像〗
1. 定义一个ACL
[SwitchA]acl num 200
2. 定义一个规则从E0/1发送至其它所有端口的数据包
[SwitchA]rule 0 permit ingress interface Ethernet0/1 egress interface Ethernet0/2
3. 定义一个规则从其它所有端口到E0/1端口的数据包
[SwitchA]rule 1 permit ingress interface Ethernet0/2 egress interface Ethernet0/1
4. 将符合上述ACL的数据包镜像到E0/8
[SwitchA]mirrored-to link-group 200 interface e0/8
【5516/6506/6503/6506R】
目前该三款产?#20998;?#25345;对入端口流量进行镜像
1. 定义镜像端口
[SwitchA]monitor-port Ethernet 3/0/2
2. 定义被镜像端口
[SwitchA]mirroring-port Ethernet 3/0/1 inbound
?#38745;?#20805;说明】
1. 镜像一般都可以实现高速率端口镜像?#36864;?#29575;端口,例如1000M端口可以镜像100M端口,反之则无法实现
2. 8016支持跨单板端口镜像端口镜像配置
『环境配置?#38382;?
1. PC1接在交换机E0/1端口,IP地址1.1.1.1/24
2. PC2接在交换机E0/2端口,IP地址2.2.2.2/24
3. E0/24为交换机上行端口
4. Server接在交换机E0/8端口,该端口作为镜像端口
『组网需求』
1. 通过交换机端口镜像的功能使用server对两台pc的业务报文进行监控。
2. 按?#31449;?#20687;的不同方式进?#20449;?#32622;:
1) 基于端口的镜像
2) 基于流的镜像
2 数据配置步骤
『端口镜像的数据流程』
基于端口的镜像是把被镜像端口的进出数据报文完全拷贝一份到镜像端口,这样来进行流量观测或者故障定位。
【3026等交换机镜像】
S2008/S2016/S2026/S2403H/S3026等交换机支持的都是基于端口的镜像,有两种方法:
方法一
1. 配置镜像(观测)端口
[SwitchA]monitor-port e0/8
2. 配置被镜像端口
[SwitchA]port mirror Ethernet 0/1 to Ethernet 0/2
方法二
1. 可以一次性定义镜像和被镜像端口
[SwitchA]port mirror Ethernet 0/1 to Ethernet 0/2 observing-port Ethernet 0/8
【8016交换机端口镜像配置】
1. 假设8016交换机镜像端口为E1/0/15,被镜像端口为E1/0/0,设置端口1/0/15为端口镜像的观测端口。
[SwitchA] port monitor ethernet 1/0/15
2. 设置端口1/0/0为被镜像端口,对其输入输出数据都进行镜像。
[SwitchA] port mirroring ethernet 1/0/0 both ethernet 1/0/15
也可以通过两个不同的端口,对输入和输出的数据分别镜像
1. 设置E1/0/15和E2/0/0为镜像(观测)端口
[SwitchA] port monitor ethernet 1/0/15
2. 设置端口1/0/0为被镜像端口,分别使用E1/0/15和E2/0/0对输入和输出数据进行镜像。
[SwitchA] port mirroring gigabitethernet 1/0/0 ingress ethernet 1/0/15
[SwitchA] port mirroring gigabitethernet 1/0/0 egress ethernet 2/0/0
『基于流镜像的数据流程』
基于流镜像的交换机针对某些流进行镜像,每个连接?#21152;?#20004;个方向的数据流,对于交换机来说这两个数据流是要分开镜像的。
【3500/3026E/3026F/3050】
〖基于三层流的镜像〗
1. 定义一条扩展访问控制列表
[SwitchA]acl num 100
2. 定义一条规则报文源地址为1.1.1.1/32去往所有目的地址
[SwitchA-acl-adv-101]rule 0 permit ip source 1.1.1.1 0 destination any
3. 定义一条规则报文源地址为所有源地址目的地址为1.1.1.1/32
[SwitchA-acl-adv-101]rule 1 permit ip source any destination 1.1.1.1 0
4. 将符合上述ACL规则的报文镜像到E0/8端口
[SwitchA]mirrored-to ip-group 100 interface e0/8
〖基于二层流的镜像〗
1. 定义一个ACL
[SwitchA]acl num 200
2. 定义一个规则从E0/1发送至其它所有端口的数据包
[SwitchA]rule 0 permit ingress interface Ethernet0/1 egress interface Ethernet0/2
3. 定义一个规则从其它所有端口到E0/1端口的数据包
[SwitchA]rule 1 permit ingress interface Ethernet0/2 egress interface Ethernet0/1
4. 将符合上述ACL的数据包镜像到E0/8
[SwitchA]mirrored-to link-group 200 interface e0/8
【5516/6506/6503/6506R】
目前该三款产?#20998;?#25345;对入端口流量进行镜像
1. 定义镜像端口
[SwitchA]monitor-port Ethernet 3/0/2
2. 定义被镜像端口
[SwitchA]mirroring-port Ethernet 3/0/1 inbound

30选5玩法