双ISP接入负载均衡NAT与IP SLA链路检测实验配置.doc_第1页
双ISP接入负载均衡NAT与IP SLA链路检测实验配置.doc_第2页
双ISP接入负载均衡NAT与IP SLA链路检测实验配置.doc_第3页
双ISP接入负载均衡NAT与IP SLA链路检测实验配置.doc_第4页
双ISP接入负载均衡NAT与IP SLA链路检测实验配置.doc_第5页
已阅读5页,还剩7页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

双ISP接入负载均衡NAT与IP SLA链路检测实验配置CE路由器为企业边缘路由器,f0/0,f2/0分别为ISP1,ISP2接口做负载均衡,loopback0接口模拟内部主机。内部流量负载均衡到ISP1与ISP2两条链路上,为模拟出负载均衡流量,CE的loopback0、f0/0、f2/0接口上禁用了快速交换(ip route cache)以及CEF并启用了基于per-packet的负载均衡(ip load-sharing per-packet)。通过在CE路由器上配置IP SLA来检测ISP链路的可用性。Internet-server路由器的loopback0接口模拟internet上的某个server,并且此server也是双ISP接入。CE configurationCE#sh runBuilding configuration.Current configuration : 2288 bytes!version 12.4service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname CE!boot-start-markerboot-end-marker!no aaa new-modelmemory-size iomem 5!ip cefno ip domain lookup!ip sla monitor 1 type echo protocol ipIcmpEcho source-interface FastEthernet0/0ip sla monitor schedule 1 life forever start-time nowip sla monitor 2 type echo protocol ipIcmpEcho source-interface FastEthernet2/0ip sla monitor schedule 2 life forever start-time now!track 1 rtr 1 reachability #将track与ip sla 关联起来,track根据ip sla的返回代码来断定链路UP/DOWN!track 2 rtr 2 reachability!interface Loopback0 ip address 55 ip load-sharing per-packet ip nat inside ip virtual-reassembly no ip route-cache cef no ip route-cache!interface FastEthernet0/0 description isp1 ip address ip load-sharing per-packet ip nat outside ip virtual-reassembly no ip route-cache cef no ip route-cache duplex auto speed auto!interface Serial1/0 no ip address shutdown serial restart-delay 0!interface Serial1/1 no ip address shutdown serial restart-delay 0!interface Serial1/2 no ip address shutdown serial restart-delay 0!interface Serial1/3 no ip address shutdown serial restart-delay 0!interface FastEthernet2/0 description isp2 ip address ip load-sharing per-packet ip nat outside ip virtual-reassembly no ip route-cache cef no ip route-cache duplex auto speed auto!ip http serverno ip http secure-server!ip route FastEthernet0/0 track 1 #根据track reachability状态UP/DOWN默认路由ip route FastEthernet2/0 track 2ip route 55 FastEthernet0/0 #首先解决IP SLA 检测目标的路由,而后默认路由才能UPip route 55 FastEthernet2/0!ip nat inside source route-map isp1 interface FastEthernet0/0 overloadip nat inside source route-map isp2 interface FastEthernet2/0 overload #通过使用route map来匹配数据包的路由出接口!access-list 1 permit access-list 100 permit ip host host # 此ACL仅用于debug调试!route-map isp2 permit 10 match ip address 1 match interface FastEthernet2/0!route-map isp1 permit 10 match ip address 1 match interface FastEthernet0/0!control-plane!line con 0 logging synchronousline aux 0line vty 0 4 login!EndISP1 configurationISP1#sh runBuilding configuration.Current configuration : 955 bytes!version 12.4service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname ISP1!boot-start-markerboot-end-marker!no aaa new-model!resource policy!ip cef!no ip domain lookup!interface FastEthernet0/0 ip address duplex half!interface Serial1/0 no ip address shutdown serial restart-delay 0!interface Serial1/1 ip address serial restart-delay 0!interface Serial1/2 no ip address shutdown serial restart-delay 0!interface Serial1/3 no ip address shutdown serial restart-delay 0!interface FastEthernet2/0 no ip address shutdown duplex half!ip route 55 Serial1/1no ip http serverno ip http secure-server!logging alarm informational!control-plane!line con 0 logging synchronous stopbits 1line aux 0 stopbits 1line vty 0 4 login!EndISP2 configurationISP2#sh runBuilding configuration.Current configuration : 955 bytes!version 12.4service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname ISP2!boot-start-markerboot-end-marker!no aaa new-model!resource policy!ip cef!no ip domain lookup!interface FastEthernet0/0 no ip address shutdown duplex half!interface Serial1/0 ip address serial restart-delay 0!interface Serial1/1 no ip address shutdown serial restart-delay 0!interface Serial1/2 no ip address shutdown serial restart-delay 0!interface Serial1/3 no ip address shutdown serial restart-delay 0!interface FastEthernet2/0 ip address duplex half!ip route 55 Serial1/0no ip http serverno ip http secure-server!logging alarm informational!control-plane!line con 0 logging synchronous stopbits 1line aux 0 stopbits 1line vty 0 4 login!EndInternet-server configurationInternet-server#sh runBuilding configuration.Current configuration : 1065 bytes!version 12.4service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname Internet-server!boot-start-markerboot-end-marker!no aaa new-model!resource policy!ip cef!no ip domain lookup!interface Loopback0 ip address 55!interface FastEthernet0/0 no ip address shutdown duplex half!interface Serial1/0 ip address serial restart-delay 0!interface Serial1/1 ip address serial restart-delay 0!interface Serial1/2 no ip address shutdown serial restart-delay 0!interface Serial1/3 no ip address shutdown serial restart-delay 0!interface FastEthernet2/0 no ip address shutdown duplex half!ip route Serial1/0ip route Serial1/1no ip http serverno ip http secure-server!logging alarm informational!control-plane!line con 0 logging synchronous

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论