我有两个 L3 交换机为 3 个 VLAN(64、65、66)执行 HSRP。
查看“show standby brief”命令的输出时,我可以看到两台交换机都为一个 vlan (65) 形成了一个虚拟路由器。
这是我的拓扑:
这是Core1上的配置:
en
conf t
no ip domain-lookup
ipv6 unicast-routing
ip routing
int loopback 0
ip add 2.2.2.3 255.255.255.255
exit
vlan 64
exit
vlan 65
exit
vlan 66
exit
ipv6 router ospf 1
auto-cost reference-bandwidth 100000
router-id 2.2.2.3
area 64 range 2001:db8:18:6400::/58
area 65 range 2001:db8:18:6500::/58
area 66 range 2001:db8:18:6600::/58
passive-interface g0/1
passive-interface g0/2
exit
router ospf 1
auto-cost reference-bandwidth 100000
area 64 range 10.0.64.0 255.255.255.0
area 65 range 10.0.65.0 255.255.255.0
area 66 range 10.0.66.0 255.255.255.0
passive-interface g0/1
passive-interface g0/2
exit
int vlan 64
ip add 10.0.64.3 255.255.255.0
ipv6 add 2001:db8:18:6400::3/64
ipv6 ospf 1 area 0
ip ospf 1 area 0
no sh
int vlan 65
ip add 10.0.65.3 255.255.255.0
ipv6 add 2001:db8:18:6500::3/64
ipv6 ospf 1 area 0
ip ospf 1 area 0
no sh
int vlan 66
ip add 10.0.66.3 255.255.255.0
ipv6 add 2001:db8:18:6600::3/64
ipv6 ospf 1 area 0
ip ospf 1 area 0
no sh
int fa0/5
switchport mode trunk
switchport trunk enc dot1q
switchport native vlan 99
exit
int f0/4
switchport mode trunk
switchport trunk enc dot1q
switchport native vlan 99
exit
int g0/1
switchport mode trunk
switchport trunk enc dot1q
int g0/2
switchport mode trunk
switchport trunk enc dot1q
int f0/24
no switchport
ip add 10.0.0.45 255.255.255.252
ipv6 add 2001:db8:18:0010::1/64
ipv6 ospf 1 area 0
ip ospf 1 area 0
ip ospf hello-interval 3
ipv6 ospf hello-interval 3
no sh
exit
int fa0/1
no switchport
ip add 10.0.0.26 255.255.255.252
ipv6 add 2001:db8:18:0006::2/64
ipv6 ospf 1 area 0
ip ospf hello-interval 3
ipv6 ospf hello-interval 3
no sh
exit
int fa0/2
no switchport
ip add 10.0.0.18 255.255.255.252
ipv6 add 2001:db8:18:0005::2/64
ipv6 ospf 1 area 0
ip ospf hello-interval 3
ipv6 ospf hello-interval 3
no sh
exit
int vlan 64
standby 64 priority 100
standby 64 ip 10.0.64.2
exit
int vlan 65
standby 65 priority 100
standby 65 ip 10.0.65.2
exit
int vlan 66
standby 66 priority 100
standby 66 ip 10.0.66.2
exit
router ospf 1
passive-interface Vlan 64
passive-interface Vlan 65
passive-interface Vlan 66
exit
ip access-list extended VLAN64
deny ip 10.0.0.0 0.255.255.255 any
exit
ip access-list extended VLAN65
deny ip 10.0.0.0 0.255.255.255 any
exit
ip access-list extended VLAN66
permit tcp 10.0.0.0 0.255.255.255 host 10.0.66.101 eq 80
permit tcp 10.0.0.0 0.255.255.255 host 10.0.66.101 eq 443
permit tcp 10.0.0.0 0.255.255.255 host 10.0.66.101 eq 139
permit tcp 10.0.0.0 0.255.255.255 host 10.0.66.101 eq 445
deny ip 10.0.0.0 0.255.255.255 any
exit
ipv6 access-list VLAN64IPv6
deny ipv6 any any
exit
ipv6 access-list VLAN65IPv6
deny ipv6 any any
exit
ipv6 access-list VLAN66IPv6
permit tcp 2001:db8:18::/48 host 2001:db8:18:6600::0010 eq 80
permit tcp 2001:db8:18::/48 host 2001:db8:18:6600::0010 eq 443
permit tcp 2001:db8:18::/48 host 2001:db8:18:6600::0010 eq 139
permit tcp 2001:db8:18::/48 host 2001:db8:18:6600::0010 eq 445
deny ipv6 any any
exit
int vlan 64
ip access-group VLAN64 out
ipv6 traffic-filter VLAN64IPv6 out
exit
int vlan 65
ip access-group VLAN65 out
ipv6 traffic-filter VLAN65IPv6 out
exit
int vlan 66
ip access-group VLAN66 out
ipv6 traffic-filter VLAN66IPv6 out
end
这是Core0上的配置:
en
conf t
no ip domain-lookup
ipv6 unicast-routing
ip routing
int loopback 0
ip add 2.2.2.1 255.255.255.255
exit
vlan 64
exit
vlan 65
exit
vlan 66
exit
ipv6 router ospf 1
auto-cost reference-bandwidth 100000
router-id 2.2.2.1
area 64 range 2001:db8:18:6400::/58
area 65 range 2001:db8:18:6500::/58
area 66 range 2001:db8:18:6600::/58
passive-interface g0/1
passive-interface g0/2
exit
router ospf 1
auto-cost reference-bandwidth 100000
area 64 range 10.0.64.0 255.255.255.0
area 65 range 10.0.65.0 255.255.255.0
area 66 range 10.0.66.0 255.255.255.0
passive-interface g0/1
passive-interface g0/2
int vlan 64
ip add 10.0.64.1 255.255.255.0
ipv6 add 2001:db8:18:6400::1/64
ipv6 ospf 1 area 0
ip ospf 1 area 0
no sh
int vlan 65
ip add 10.0.65.1 255.255.255.0
ipv6 add 2001:db8:18:6500::1/64
ipv6 ospf 1 area 0
ip ospf 1 area 0
no sh
int vlan 66
ip add 10.0.66.1 255.255.255.0
ipv6 add 2001:db8:18:6600::1/64
ipv6 ospf 1 area 0
ip ospf 1 area 0
no sh
int fa0/5
switchport mode trunk
switchport trunk enc dot1q
switchport native vlan 99
exit
int f0/4
switchport mode trunk
switchport trunk enc dot1q
switchport native vlan 99
exit
int g0/1
switchport mode trunk
switchport trunk enc dot1q
int g0/2
switchport mode trunk
switchport trunk enc dot1q
int f0/24
no switchport
ip add 10.0.0.41 255.255.255.252
ipv6 add 2001:db8:18:0009::1/64
ipv6 ospf 1 area 0
ip ospf 1 area 0
ip ospf hello-interval 3
ipv6 ospf hello-interval 3
no sh
exit
int fa0/1
no switchport
ip add 10.0.0.30 255.255.255.252
ipv6 add 2001:db8:18:0008::2/64
ipv6 ospf 1 area 0
ip ospf 1 area 0
ip ospf hello-interval 3
ipv6 ospf hello-interval 3
no sh
exit
int fa0/2
no switchport
ip add 10.0.0.22 255.255.255.252
ipv6 add 2001:db8:18:0007::2/64
ipv6 ospf 1 area 0
ip ospf 1 area 0
ip ospf hello-interval 3
ipv6 ospf hello-interval 3
no sh
exit
router ospf 1
passive-interface Vlan 64
passive-interface Vlan 65
passive-interface Vlan 66
exit
int vlan 64
standby 64 priority 200
standby 64 ip 10.0.64.2
exit
int vlan 65
standby 65 priority 200
standby 65 ip 10.0.65.2
exit
int vlan 66
standby 66 priority 200
standby 66 ip 10.0.66.2
exit
ip access-list extended VLAN64
deny ip 10.0.0.0 0.255.255.255 any
exit
ip access-list extended VLAN65
deny ip 10.0.0.0 0.255.255.255 any
exit
ip access-list extended VLAN66
permit tcp 10.0.0.0 0.255.255.255 host 10.0.66.101 eq 80
permit tcp 10.0.0.0 0.255.255.255 host 10.0.66.101 eq 443
permit tcp 10.0.0.0 0.255.255.255 host 10.0.66.101 eq 139
permit tcp 10.0.0.0 0.255.255.255 host 10.0.66.101 eq 445
deny ip 10.0.0.0 0.255.255.255 any
exit
ipv6 access-list VLAN64IPv6
deny ipv6 any any
exit
ipv6 access-list VLAN65IPv6
deny ipv6 any any
exit
ipv6 access-list VLAN66IPv6
permit tcp 2001:db8:18::/48 host 2001:db8:18:6600::0010 eq 80
permit tcp 2001:db8:18::/48 host 2001:db8:18:6600::0010 eq 443
permit tcp 2001:db8:18::/48 host 2001:db8:18:6600::0010 eq 139
permit tcp 2001:db8:18::/48 host 2001:db8:18:6600::0010 eq 445
deny ipv6 any any
exit
int vlan 64
ip access-group VLAN64 out
ipv6 traffic-filter VLAN64IPv6 out
exit
int vlan 65
ip access-group VLAN65 out
ipv6 traffic-filter VLAN65IPv6 out
exit
int vlan 66
ip access-group VLAN66 out
ipv6 traffic-filter VLAN66IPv6 out
exit
exit
core1 上的“显示待机简介”