华为交换机常用配置大全2010-02-27目录一、基础配置举例........................................................................................................31.1配置文件处理...................................................................................................31.2配置交换机远程管理.......................................................................................3二、以太网配置举例....................................................................................................42.1配置端口属性...................................................................................................42.2配置链路聚合...................................................................................................62.3配置VLAN......................................................................................................79.配置MSTP........................................................................................................14三、可靠性..................................................................................................................203.1配置基于主备份VRRP.................................................................................203.2配置基于负载分担VRRP.............................................................................21四、IP路由.................................................................................................................234.1配置静态路由.................................................................................................234.2配置动态路由.................................................................................................24五、IP业务.................................................................................................................265.1配置虚接口IP地址.......................................................................................265.2DHCP设置......................................................................................................275.3ACL举例.......................................................................................................29六、IGMP...................................................................................................................31七、QOS.....................................................................................................................32八、安全性..................................................................................................................338.1接口安全.........................................................................................................33九、网络管理..............................................................................................................349.1简单网络管理协议配置.................................................................................34十、设备管理..............................................................................................................3610.1测试命令.......................................................................................................36一、基础配置举例1.1配置文件处理导入配置文件tftpx.x.x.xgetvrpcfg.zipvrpcfg.zip导出配置文件tftpx.x.x.xputvrpcfg.zipvrpcfg.zip1.2配置交换机远程管理aaa方式system-viewaaalocal-userhuaweipasswordsimplehuaweilocal-userhuaweiservice-typetelnetlocal-userhuaweiprioritylevel3quituser-interfacevty04authentication-modeaaaquit没有密码和使用密码认证同上二、以太网配置举例2.1配置端口属性system-viewinterfacegigabitethernet0/0/24combo-portfiber/coppernetgotinationautoloopback-detectenable//环路检测port-isolateenable//端口隔离qoslrcir625cbs625000//端口限速quit端口隔离举例2.2配置链路聚合system-viewinterfaceeth-trunk1interfacegigabitgibabitethernet0/0/1eth-trunk1interfacegigabitgibabitethernet0/0/2eth-trunk12.3配置VLAN1.创建单一vlansysvlan2quit2.创建批量vlansystem-viewvlanbatchvlan10tovlan20quit3.基于干道链路VLAN实例4.配置基于子网vlan允许一个vlan通过某个接口Vlan2portgigabitethernet0/0/1quit允许多个vlan通过某个接口sysportgigabitethernet0/0/1portlink-typetrunkporttrunkallow-passvlanall5.配置VLAN聚合6.配置VLAN映射7.配置QINQ8.配置MAC学习限制功能2.4.配置MSTP三、可靠性3.1配置基于主备份VRRP3.2配置基于负载分担VRRP四、IP路由4.1配置静态路由配置默认静态路由system-viewiproute-static0.0.0.00.0.0.0next-hop配置静态路由system-viewiproute-static10.1.1.0255.255.255.0next-hop4.2配置动态路由五、IP业务5.1配置虚接口IP地址1.单一地址SysVlan2QuitInterfacevlanif2Ipaddress192.168.1.124Quit2.配置主从IP地址system-viewinterfacevlanif2ipaddress10.1.1.124ipaddress10.1.2.124sub5.2DHCP设置1.基于全局的DHCP2.DHCP中继5.3ACL举例六、IGMP七、QOS基于端口限速的QOS八、安全性8.1接口安全九、网络管理9.1简单网络管理协议配置system-viewsnmp-agentsys-infoversionv3snmp-agentcommunityreadpublicsnmp-agentcommunitywriteprivatesnmp-agenttrapenablesnmp-agenttarget-hosttrapaddressudp-domain10.10.10.2udp-port5000paramssecuritynamepublic十、设备管理10.1测试命令十一、802.1X认证1创建认证模板设置认证服务器的IP地址和协议端口号、密钥Radius-servertemplateradiusserverRadius-serverauthentication10.1.1.2541812Radius-serveraccording10.1.1.2541813Radius-servershared-keyhuaweiUndoradius-serveruser-namedomain-included2配置用户认证域aaadomainsystemradius-serverradiusserver3使能全局和接口下的802.1x功能Dot1xInterfaceethernet0/0/1Dot1x