设为首页 收藏本站
查看: 1111|回复: 0

[经验分享] 华为三层交换机基于ip地址的限速

[复制链接]

尚未签到

发表于 2018-7-24 08:24:13 | 显示全部楼层 |阅读模式
[H3C]dis cur  #

  version 5.20,>  #
  sysname H3C
  #
  clock timezone beijing add 13:01:45
  #
  super password level 3 cipher :Aa.-B3\6E@ZY#9\EO)311!!
  #
  irf mac-address persistent timer
  irf auto-update enable
  undo irf link-delay
  #
  domain default enable system
  #
  telnet server enable
  #
  undo ip ttl-expires
  #
  acl number 2000 match-order auto
  #
  vlan 1
  #
  vlan 1000 to 1010
  #
  radius scheme system
  server-type extended
  primary authentication 127.0.0.1 1645
  primary accounting 127.0.0.1 1646
  user-name-format without-domain
  #
  domain system
  access-limit disable
  state active
  idle-cut disable
  self-service-url disable
  #

  traffic>  if-match any

  traffic>  if-match any

  traffic>  if-match any
  #
  traffic behavior ban-gong
  car cir 20480 cbs 4000 ebs 4000 green pass red discard yellow pass
  traffic behavior bi-sai
  car cir 40960 cbs 4000 ebs 4000 green pass red discard yellow pass
  traffic behavior zhang-xin-da
  car cir 3072 cbs 4000 ebs 4000 green pass red discard yellow pass
  #
  qos policy bi-sai-upload
  classifier bi-sai behavior bi-sai
  qos policy ban-gong-out
  classifier ban-gong behavior ban-gong
  qos policy zhang-xin-da-out
  classifier zhang-xin-da behavior zhang-xin-da
  #
  user-group system
  #
  interface NULL0
  #
  interface LoopBack0
  ip address 119.255.3.49 255.255.255.255
  #
  interface Vlan-interface1000
  description connet-li-gong
  ip address 10.2.59.66 255.255.255.252
  ospf cost 30
  #
  interface Vlan-interface1001
  description connect-to-kecai
  ip address 10.2.59.70 255.255.255.252
  #
  interface Vlan-interface1003
  #
  interface Vlan-interface1004
  ip address 192.168.116.1 255.255.255.252
  #
  interface Vlan-interface1005
  ip address 192.168.117.1 255.255.255.252
  #
  interface Vlan-interface1007
  ip address 192.168.104.1 255.255.255.252
  #
  interface Vlan-interface1008
  ip address 192.168.103.1 255.255.255.252
  #
  interface Vlan-interface1009
  ip address 192.168.105.1 255.255.255.252
  #
  interface Vlan-interface1010
  ip address 192.168.106.1 255.255.255.252
  #
  interface GigabitEthernet1/0/1
  description connect-to-ligong
  port access vlan 1000
  #
  interface GigabitEthernet1/0/2
  description connect-to-kecai
  port access vlan 1001
  #
  interface GigabitEthernet1/0/3
  port access vlan 1003
  #
  interface GigabitEthernet1/0/4
  #
  interface GigabitEthernet1/0/5
  description zhang-xin-da
  port access vlan 1004
  qos apply policy zhang-xin-da-out inbound
  qos apply policy zhang-xin-da-out outbound
  #
  interface GigabitEthernet1/0/6
  description zhang-xin-da
  port access vlan 1005
  qos apply policy zhang-xin-da-out inbound
  qos apply policy zhang-xin-da-out outbound
  #
  interface GigabitEthernet1/0/7
  description ban-gong
  port access vlan 1007
  qos apply policy ban-gong-out inbound
  qos apply policy ban-gong-out outbound
  #
  interface GigabitEthernet1/0/8
  description ban-gong
  port access vlan 1008
  #
  interface GigabitEthernet1/0/9
  description bi-sai
  port access vlan 1009
  qos apply policy bi-sai-upload inbound
  qos apply policy bi-sai-upload outbound
  #
  interface GigabitEthernet1/0/10
  description bi-sai
  port access vlan 1010
  qos apply policy bi-sai-upload inbound
  qos apply policy bi-sai-upload outbound
  shutdown
  #
  bgp 23844
  import-route direct route-policy first_test
  import-route static route-policy first_test
  undo synchronization
  group edge internal
  peer edge password cipher 'E'9D=OF"='Q=^Q`MAF4<1!!
  peer edge next-hop-local
  peer edge connect-interface LoopBack0
  peer 203.86.64.16 group edge
  #
  ospf 17 router-id 119.255.3.49
  area 0.0.0.1
  network 10.2.59.66 0.0.0.0
  network 119.255.3.49 0.0.0.0
  network 10.2.59.70 0.0.0.0
  #
  route-policy first_test permit node 2
  if-match ip-prefix deny_private
  #
  nqa entry admin test
  type icmp-echo
  destination ip 192.168.116.2
  frequency 100
  reaction 1 checked-element probe-fail threshold-type consecutive 2 action-type
  trigger-only
  #
  nqa entry admin1 test
  type icmp-echo
  destination ip 192.168.117.2
  frequency 100
  reaction 2 checked-element probe-fail threshold-type consecutive 2 action-type
  trigger-only
  #
  nqa entry weisheng test
  type icmp-echo
  destination ip 192.168.105.2
  frequency 100
  reaction 3 checked-element probe-fail threshold-type consecutive 2 action-type
  trigger-only
  #
  nqa entry weisheng1 test
  type icmp-echo
  destination ip 192.168.106.2
  frequency 100
  reaction 4 checked-element probe-fail threshold-type consecutive 2 action-type
  trigger-only
  #
  ip ip-prefix deny_private index 9 permit 203.86.66.32 27 greater-equal 27 less-
  equal 32
  ip ip-prefix deny_private index 11 permit 118.102.28.0 25 greater-equal 25 less
  -equal 32
  ip ip-prefix deny_private index 13 permit 203.86.66.128 25 greater-equal 25 les
  s-equal 32
  ip ip-prefix deny_private index 14 permit 119.255.3.48 29 greater-equal 29 less
  -equal 32
  ip ip-prefix deny_private index 20 deny 0.0.0.0 0 less-equal 32
  #
  ip route-static 118.102.28.64 255.255.255.192 192.168.105.2 track 3
  ip route-static 118.102.28.64 255.255.255.192 192.168.106.2 track 4
  ip route-static 203.86.66.32 255.255.255.224 192.168.116.2 track 1
  ip route-static 203.86.66.32 255.255.255.224 192.168.117.2 track 2
  ip route-static 203.86.66.128 255.255.255.128 192.168.104.2
  #
  snmp-agent
  snmp-agent local-engineid 800063A203000FE2E9B528
  snmp-agent community read pop-nortel
  snmp-agent sys-info version all
  #
  track 1 nqa entry admin test reaction 1
  track 2 nqa entry admin1 test reaction 2
  track 3 nqa entry weisheng test reaction 3
  track 4 nqa entry weisheng1 test reaction 4
  #
  nqa schedule admin test start-time now lifetime forever
  nqa schedule admin1 test start-time now lifetime forever
  nqa schedule weisheng test start-time now lifetime forever
  nqa schedule weisheng1 test start-time now lifetime forever
  #
  user-interface aux 0 8
  user-interface vty 0 4
  set authentication password cipher E!GR*G<E.T/Q=^Q`MAF4<1!!
  #
  return
  [H3C]

运维网声明 1、欢迎大家加入本站运维交流群:群②:261659950 群⑤:202807635 群⑦870801961 群⑧679858003
2、本站所有主题由该帖子作者发表,该帖子作者与运维网享有帖子相关版权
3、所有作品的著作权均归原作者享有,请您和我们一样尊重他人的著作权等合法权益。如果您对作品感到满意,请购买正版
4、禁止制作、复制、发布和传播具有反动、淫秽、色情、暴力、凶杀等内容的信息,一经发现立即删除。若您因此触犯法律,一切后果自负,我们对此不承担任何责任
5、所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其内容的准确性、可靠性、正当性、安全性、合法性等负责,亦不承担任何法律责任
6、所有作品仅供您个人学习、研究或欣赏,不得用于商业或者其他用途,否则,一切后果均由您自己承担,我们对此不承担任何法律责任
7、如涉及侵犯版权等问题,请您及时通知我们,我们将立即采取措施予以解决
8、联系人Email:admin@iyunv.com 网址:www.yunweiku.com

所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其承担任何法律责任,如涉及侵犯版权等问题,请您及时通知我们,我们将立即处理,联系人Email:kefu@iyunv.com,QQ:1061981298 本贴地址:https://www.yunweiku.com/thread-540505-1-1.html 上篇帖子: 内部资料:华为技术白皮书(中文版) 下篇帖子: 华为研发的二面(紧张,刺激,有趣)
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

扫码加入运维网微信交流群X

扫码加入运维网微信交流群

扫描二维码加入运维网微信交流群,最新一手资源尽在官方微信交流群!快快加入我们吧...

扫描微信二维码查看详情

客服E-mail:kefu@iyunv.com 客服QQ:1061981298


QQ群⑦:运维网交流群⑦ QQ群⑧:运维网交流群⑧ k8s群:运维网kubernetes交流群


提醒:禁止发布任何违反国家法律、法规的言论与图片等内容;本站内容均来自个人观点与网络等信息,非本站认同之观点.


本站大部分资源是网友从网上搜集分享而来,其版权均归原作者及其网站所有,我们尊重他人的合法权益,如有内容侵犯您的合法权益,请及时与我们联系进行核实删除!



合作伙伴: 青云cloud

快速回复 返回顶部 返回列表