本帖最后由 kevin0807 于 2015-4-21 11:09 编辑
( D0 p! Y. `# m
& @0 @. Q% S/ d6 L7 s! f1.LACP with STP SW-A(config)#spanning-tree vlan 11-13,21-23 root primary SW-A(config)#vlan 21 name Marketing SW-A(config)#vlan 22 name Sales SW-A(config)#vlan 23 name Engineering SW-A(config)#interface port-channel 1 SW-A(config)#interface range Fa0/3–4 SW-A(config-if-range)#no switchport mode access SW-A(config-if-range)#no switchport access vlan 98 SW-A(config-if-range)#switchport trunk encapsulation dot1q SW-A(config-if-range)#switchport mode trunk SW-A(config-if-range)#switchport trunk native vlan 99 SW-A(config-if-range)#switchport trunk allowed vlan 1,21-23 SW-A(config-if-range)#channel-group 1 mode active SW-A(config-if-range)#channel-protocol lacp SW-A(config-if-range)#no shutdown SW-B(config)#vtp mode transparent SW-B(config)#spanning-tree mode rapid-pvst SW-B(config)#ip default-gateway 192.168.1.1 (you can get this IP fromSW-A with command show cdp neighbour detail) SW-B(config)#interface vlan 1 SW-B(config-if)#ip address 192.168.1.11 255.255.255.0 SW-B(config-if)#no shutdown SW-B(config)#interface port-channel 1 SW-B(config)#interface range Fa0/3 – 4 SW-B(config-if-range)#switchport trunk encapsulation dot1q SW-B(config-if-range)#switchport mode trunk SW-B(config-if-range)#switchport trunk native vlan 99 SW-B(config-if-range)#switchport trunk allowed vlan 1,21-23 SW-B(config-if-range)#channel-group 1 mode passive (mode passive because“SwitchA controlling activation”) SW-B(config-if-range)#channel-protocol lacp SW-B(config-if-range)#no shutdown SW-B(config)#vlan 21 name Marketing SW-B(config)#interface range Fa0/9 – 10 SW-B(config-if-range)#switchport mode access SW-B(config-if-range)#switchport access vlan 21 SW-B(config-if-range)#spanning-tree portfast SW-B(config-if-range)#no shutdown SW-B(config)#vlan 22 name Sales SW-B(config)#interface range Fa0/13 – 14 SW-B(config-if-range)#switchport mode access SW-B(config-if-range)#switchport access vlan 22 SW-B(config-if-range)#spanning-tree portfast SW-B(config-if-range)#no shutdown SW-B(config)#vlan 23 name Engineering SW-B(config)#interface range Fa0/15 – 16 SW-B(config-if-range)#switchport mode access SW-B(config-if-range)#switchport access vlan 23 SW-B(config-if-range)#spanning-tree portfast SW-B(config-if-range)#no shutdown 2.AAA ASW1(config)#aaa new-model ASW1(config)#aaa authentication dot1x default group radius ASW1(config)#radius-server host 172.120.39.46 key rad123 ASW1(config)#dot1x system-auth-control ASW1(config)#interface fastEthernet 0/1 ASW1(config-if)#switchport mode access ASW1(config-if)#dot1x port-control auto DSW1(config)#access-list 10 permit 172.120.40.0 0.0.0.255 DSW1(config)#vlan access-map MYACCMAP 10 DSW1(config-access-map)#match ip address 10 DSW1(config-access-map)#action forward DSW1(config)#vlan access-map MYACCMAP 20 DSW1(config-access-map)#action drop DSW1(config)#vlan filter MYACCMAP vlan-list 20 3.MLS and EIGRP mls(config)# int gi0/1 mls(config-if)#no switchport mls(config-if)#ip address 10.10.10.2 255.255.255.0 mls(config-if)#no shutdown mls(config)# int vlan 2 mls(config-if)#ip address 190.200.250.33 255.255.255.224 mls(config-if)#no shutdown mls(config-if)# int vlan 3 mls(config-if)# ip address 190.200.250.65 255.255.255.224 mls(config-if)# no shutdown mls(config)# ip routing mls(config)# router eigrp 65010 mls(config-router)# network 10.10.10.0 0.0.0.255 mls(config-router)# network 190.200.250.32 0.0.0.31 mls(config-router)# network 190.200.250.64 0.0.0.31
& l. A' V2 ?$ y: E
|