武穴论坛

 找回密码
 中文注册
查看: 644|回复: 0

Cisco 3550交换机上流量控制的实现

[复制链接]
发表于 2007-7-20 16:31:24 | 显示全部楼层 |阅读模式

马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。

您需要 登录 才可以下载或查看,没有账号?中文注册

x
<p>Cisco 3550交换机上流量控制的实现</p><p>3550上接一PIX,VLAN 1中接有各种服务器(有公网映射IP),故各VLAN必须能访问服务器。<br/>  <br/>  cr20g#show run<br/>  Building configuration...<br/>  <br/>  Current configuration : 5488 bytes<br/>  !<br/>  version 12.1<br/>  no service pad<br/>  service timestamps debug uptime<br/>  service timestamps log uptime<br/>  service password-encryption<br/>  !<br/>  hostname cr20g<br/>  !<br/>  enable secret 5 $1$Xtuj$E.l2l.ev7mOCVtwPeEXz1.<br/>  enable password 7 08771A1D5A4152404B0805172924<br/>  !<br/>  username jary password 7 070C285F4D0648564E43595B5D7E797179<br/>  ip subnet-zero<br/>  ip routing<br/>  !<br/>  mls qos<br/>  !<br/>  class-map match-all part6<br/>  match access-group 116<br/>  class-map match-all part5<br/>  match access-group 115<br/>  class-map match-all part4<br/>  match access-group 114<br/>  class-map match-all part3<br/>  match access-group 113<br/>  class-map match-all part2<br/>  match access-group 112<br/>  !<br/>  !<br/>  policy-map download<br/>  class part2<br/>  police 1000000 8000 exceed-action drop<br/>  class part3<br/>  police 1800000 8000 exceed-action drop<br/>  class part4<br/>  police 496000 8000 exceed-action drop<br/>  class part5<br/>  police 496000 8000 exceed-action drop<br/>  class part6<br/>  police 800000 8000 exceed-action drop<br/>  !<br/>  !<br/>  spanning-tree mode pvst<br/>  spanning-tree extend system-id<br/>  !<br/>  !<br/>  !<br/>  interface FastEthernet0/1<br/>  switchport mode access<br/>  !<br/>  interface FastEthernet0/2<br/>  switchport mode access<br/>  !<br/>  interface FastEthernet0/3<br/>  switchport mode access<br/>  !<br/>  interface FastEthernet0/4<br/>  switchport mode access<br/>  !<br/>  interface FastEthernet0/5<br/>  switchport mode access<br/>  !<br/>  interface FastEthernet0/6<br/>  switchport mode access<br/>  !<br/>  interface FastEthernet0/7<br/>  switchport mode access<br/>  !<br/>  interface FastEthernet0/8<br/>  switchport mode access<br/>  !<br/>  interface FastEthernet0/9<br/>  switchport mode access<br/>  !<br/>  interface FastEthernet0/10<br/>  switchport mode access<br/>  !<br/>  interface FastEthernet0/11<br/>  switchport access vlan 2<br/>  switchport mode access<br/>  service-policy input download<br/>  !<br/>  interface FastEthernet0/12<br/>  switchport access vlan 2<br/>  switchport mode access<br/>  service-policy input download<br/>  !<br/>  interface FastEthernet0/13<br/>  switchport access vlan 2<br/>  switchport mode access<br/>  service-policy input download<br/>  !<br/>  interface FastEthernet0/14<br/>  switchport access vlan 3<br/>  switchport mode access<br/>  service-policy input download<br/>  !<br/>  interface FastEthernet0/15<br/>  switchport access vlan 4<br/>  switchport mode access<br/>  service-policy input download<br/>  !<br/>  interface FastEthernet0/16<br/>  switchport access vlan 5<br/>  switchport mode access<br/>  service-policy input download<br/>  !<br/>  interface FastEthernet0/17<br/>  switchport access vlan 6<br/>  switchport mode access<br/>  service-policy input download<br/>  !<br/>  interface FastEthernet0/18<br/>  switchport access vlan 6<br/>  switchport mode access<br/>  service-policy input download<br/>  !<br/>  interface FastEthernet0/19<br/>  switchport mode access<br/>  !<br/>  interface FastEthernet0/20<br/>  switchport mode access<br/>  !<br/>  interface FastEthernet0/21<br/>  switchport mode access<br/>  !<br/>  interface FastEthernet0/22<br/>  switchport mode access<br/>  !<br/>  interface FastEthernet0/23<br/>  switchport mode access<br/>  !<br/>  interface FastEthernet0/24<br/>  switchport mode access<br/>  !<br/>  interface GigabitEthernet0/1<br/>  switchport mode dynamic desirable<br/>  !<br/>  interface GigabitEthernet0/2<br/>  switchport mode dynamic desirable<br/>  !<br/>  interface Vlan1<br/>  ip address 192.168.0.254 255.255.255.0<br/>  !<br/>  interface Vlan2<br/>  ip address 192.168.2.1 255.255.255.0<br/>  !<br/>  interface Vlan3<br/>  ip address 192.168.3.1 255.255.255.0<br/>  !<br/>  interface Vlan4<br/>  ip address 192.168.4.1 255.255.255.0<br/>  !<br/>  interface Vlan5<br/>  ip address 192.168.5.1 255.255.255.0<br/>  !<br/>  interface Vlan6<br/>  ip address 192.168.6.1 255.255.255.0<br/>  !<br/>  ip default-gateway 192.168.0.1<br/>  ip classless<br/>  ip route 0.0.0.0 0.0.0.0 192.168.0.1<br/>  ip http server<br/>  !<br/>  !<br/>  access-list 112 deny ip 192.168.2.0 0.0.0.255 192.168.3.0 0.0.0.255<br/>  access-list 112 deny ip 192.168.2.0 0.0.0.255 192.168.4.0 0.0.0.255<br/>  access-list 112 deny ip 192.168.2.0 0.0.0.255 192.168.5.0 0.0.0.255<br/>  access-list 112 deny ip 192.168.2.0 0.0.0.255 192.168.6.0 0.0.0.255<br/>  access-list 112 deny ip 192.168.2.0 0.0.0.255 192.168.0.0 0.0.0.255<br/>  access-list 112 permit ip 192.168.2.0 0.0.0.255 any<br/>  access-list 113 deny ip 192.168.3.0 0.0.0.255 192.168.0.0 0.0.0.255<br/>  access-list 113 deny ip 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255<br/>  access-list 113 deny ip 192.168.3.0 0.0.0.255 192.168.4.0 0.0.0.255<br/>  access-list 113 deny ip 192.168.3.0 0.0.0.255 192.168.5.0 0.0.0.255<br/>  access-list 113 deny ip 192.168.3.0 0.0.0.255 192.168.6.0 0.0.0.255<br/>  access-list 113 permit ip 192.168.3.0 0.0.0.255 any<br/>  access-list 114 deny ip 192.168.4.0 0.0.0.255 192.168.0.0 0.0.0.255<br/>  access-list 114 deny ip 192.168.4.0 0.0.0.255 192.168.2.0 0.0.0.255<br/>  access-list 114 deny ip 192.168.4.0 0.0.0.255 192.168.3.0 0.0.0.255<br/>  access-list 114 deny ip 192.168.4.0 0.0.0.255 192.168.5.0 0.0.0.255<br/>  access-list 114 deny ip 192.168.4.0 0.0.0.255 192.168.6.0 0.0.0.255<br/>  access-list 114 permit ip 192.168.4.0 0.0.0.255 any<br/>  access-list 115 deny ip 192.168.4.0 0.0.0.255 192.168.0.0 0.0.0.255<br/>  access-list 115 deny ip 192.168.4.0 0.0.0.255 192.168.2.0 0.0.0.255<br/>  access-list 115 deny ip 192.168.4.0 0.0.0.255 192.168.3.0 0.0.0.255<br/>  access-list 115 deny ip 192.168.4.0 0.0.0.255 192.168.4.0 0.0.0.255<br/>  access-list 115 deny ip 192.168.4.0 0.0.0.255 192.168.6.0 0.0.0.255<br/>  access-list 115 permit ip 192.168.5.0 0.0.0.255 any<br/>  access-list 116 deny ip 192.168.6.0 0.0.0.255 192.168.0.0 0.0.0.255<br/>  access-list 116 deny ip 192.168.6.0 0.0.0.255 192.168.2.0 0.0.0.255<br/>  access-list 116 deny ip 192.168.6.0 0.0.0.255 192.168.3.0 0.0.0.255<br/>  access-list 116 deny ip 192.168.6.0 0.0.0.255 192.168.4.0 0.0.0.255<br/>  access-list 116 deny ip 192.168.6.0 0.0.0.255 192.168.5.0 0.0.0.255<br/>  access-list 116 permit ip 192.168.6.0 0.0.0.255 any<br/>  !<br/>  line con 0<br/>  password 7 14141B180F0B7B787D7961627B47554352<br/>  logging synchronous<br/>  login<br/>  line vty 0 4<br/>  password 7 104D000A061843585555787C7D7C616073<br/>  login<br/>  line vty 5 15<br/>  password 7 104D000A061843585555787C7D7C616073<br/>  login<br/>  !<br/>  end<br/>  <br/>  cr20g#<font></font></p>
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 中文注册

本版积分规则

手机版|武穴信息网 ( 鄂ICP备2021017331号-1 )

鄂公网安备 42118202000100号

GMT+8, 2024-11-23 05:19 , Processed in 0.050411 second(s), 15 queries .

Powered by Discuz! X3.4 Licensed

© 2001-2023 Discuz! Team.

快速回复 返回顶部 返回列表