µ±Ç°Î»ÖãºÊ×Ò³ > »ªÎªME60 BRASÉ豸ÅäÖù淶
ÎĵµÃû³Æ ÎĵµÃܼ¶£º
4 ÅäÖÃRADIUS ·þÎñÆ÷×é/HWTACACS ·þÎñÆ÷Ä£°å 5 ÅäÖÃIPv4 µØÖ·³Ø 6 ÅäÖÃÓò
7 Ϊ½Ó¿ÚÖ¸¶¨ÐéÄ£°å½Ó¿Ú£¨¶ÔPPPoE¡¢PPPoEoVLAN¡¢PPPoEoQ ½ÓÈëÓÐЧ£© 8 ×Ó½Ó¿Ú°ó¶¨VLAN£¨Ö»¶ÔPPPoEoVLAN¡¢PPPoEoQ ½ÓÈëÓÐЧ£© 9 ÅäÖÃBAS ½Ó¿Ú 2.6.2 PPPOEÏà¹ØÅäÖà 1¡¢ÅäÖÃPPPÐéÄâÄ£°å
interface Virtual-Template1 ppp authentication-mode auto ppp keepalive interval 30 retransmit 3 tcp adjust-mss 1400
[½¨Á¢PPPÐéÄ£°å£¬ÔÚÆäÖпÉÒÔ¶¨ÒåPPPOEµÄÒ»Ð©ÌØÐÔ¡£±ÈÈçµÚÒ»Ðж¨ÒåÁËPPPʹÓõÄÈÏÖ¤·½·¨Îª×ÔÊÊÓ¦£¬Ò²¾ÍÊǸù¾Ý²¦ºÅ¿Í»§¶ËµÄ·½·¨À´¾ö¶¨ME60µÄÈÏÖ¤·½Ê½¡£PPP keepalive¶¨ÒåPPPÐÒéLCP̽²â±¨Îĵķ¢ËÍÆµÂÊ£¬´Ë´¦ÎÒÃÇÅäÖÃÿ30Ãë·¢ËÍÒ»´Î£¬ÖØ´«ÆµÂÊΪ3£¬ÕâÑù£¬Ö»ÒªÔÚ90ÃëÄÚ¿ÉÒÔ½ÓÊÕµ½Óû§·´À¡£¬¼´ÈÏΪÓû§ÔÚÏß¡£]
2¡¢ÅäÖÃÈÏÖ¤·½°¸
authentication-scheme radius
3¡¢ÅäÖüƷѷ½°¸
accounting-scheme radius accounting start-fail online
4¡¢ÅäÖÃRADIUS ·þÎñÆ÷×é
radius-server group dial radius-server shared-key henancnc authentication 221.13.223.140 1645 weight 0
radius-server shared-key henancnc accounting 221.13.223.140 1646 weight 0 radius-server shared-key henancnc radius-server class-as-car radius-server source interface LoopBack0
2020-3-1
»ªÎª»úÃÜ£¬Î´¾Ðí¿É²»µÃÀ©É¢
µÚ41Ò³, ¹²75Ò³
ÎĵµÃû³Æ ÎĵµÃܼ¶£º
undo radius-server user-name domain-included
5¡¢ÅäÖÃIPV4µØÖ·³Ø ip pool dial local
gateway 61.168.104.1 255.255.248.0 section 0 61.168.104.2 61.168.111.254 excluded-ip-address 61.168.104.2 conflict-ip-address 61.168.108.187 dns-server 202.102.224.68
dns-server 202.102.227.68 secondary
6¡¢ÅäÖÃÓò
domain dial
authentication-scheme radius
[¸ÃÓòÓÃÃû³ÆÎªRADIUSµÄSCHEMEÀ´½øÐÐÈÏÖ¤]
accounting-scheme radius service-type hsi
[½«¸ÃÓòµÄģʽÅäÖóÉHISģʽ£¬PPPOEµÄÓò¶¼ÒªÅäÖóɸÃģʽ] radius-server group dial [Ö¸¶¨Ê¹ÓõÄRADIUS·þÎñÆ÷×é] ip-pool dial
[Ö¸¶¨¸ÃÓòʹÓõĵØÖ·³Ø] qos profile 2m
[Ö¸¶¨¸ÃÓòʹÓõÄQOSÄ£°å]
7 Ϊ½Ó¿ÚÖ¸¶¨ÐéÄ£°å½Ó¿Ú
interface GigabitEthernet1/0/9.600 pppoe-server bind Virtual-Template 1
8¡¢×Ó½Ó¿Ú°ó¶¨VLAN
interface GigabitEthernet1/0/9.600 user-vlan 256 1000 QinQ 802
9 ÅäÖÃBAS ½Ó¿Ú
interface GigabitEthernet1/0/9.600 bas
2020-3-1
»ªÎª»úÃÜ£¬Î´¾Ðí¿É²»µÃÀ©É¢
µÚ42Ò³, ¹²75Ò³
ÎĵµÃû³Æ ÎĵµÃܼ¶£º
access-type layer2-subscriber default-domain authentication dial
2.7 Óû§ÈÏÖ¤ÓòÑ¡Ôñ
1¡¢¶ÔÓÚÉÏËÍÓû§Ãû´øÓòÃûµÄÇé¿ö£¬É豸½«ÆäËÍÈëÏàÓ¦µÄÓò½øÐÐÈÏÖ¤¡£ 2¡¢Óû§VLAN°ó¶¨¶Ë¿ÚÈÏÖ¤
access-type layer2-subscriber default-domain authentication dial ¶ÔÓÚûÓÐЯ´øÓòÃûµÄÓû§Ãû£¬ÔÚ¶Ë¿Úϰó¶¨ÁËÏàÓ¦VLAN£¬ËÍÈë¸Ã¶Ë¿ÚÏÂȱʡµÄÓò½øÐÐÈÏÖ¤£¬ÉÏÊöÃüÁîÖÐÉèÖÃȱʡÓòÊÇDIALÓò¡£
2.8 ·´Ïò·Óɼì²â
URPF£¨Unicast Reverse Path Forwarding£©Êǵ¥²¥ÄæÏò·¾¶×ª·¢µÄ¼ò³Æ£¬ÆäÖ÷Òª¹¦ÄÜÊÇ·ÀÖ¹»ùÓÚÔ´µØÖ·ÆÛƵÄÍøÂç¹¥»÷ÐÐΪ¡£
Ö®ËùÒÔ³ÆÎª¡°ÄæÏò¡±£¬ÊÇÕë¶ÔÕý³£µÄ·ÓɲéÕÒ¶øÑԵġ£Ò»°ãÇé¿öÏ£¬Â·ÓÉÆ÷½ÓÊÕµ½±¨ÎÄ£¬»ñÈ¡±¨ÎĵÄÄ¿µÄµØÖ·£¬Õë¶ÔÄ¿µÄµØÖ·²éÕÒ·ÓÉ£¬Èç¹ûÕÒµ½Á˾Íת·¢±¨ÎÄ£¬·ñÔò¶ªÆú¸Ã±¨ÎÄ¡£URPFͨ¹ý»ñÈ¡±¨ÎĵÄÔ´µØÖ·ºÍÈë½Ó¿Ú£¬ÒÔÔ´µØÖ·ÎªÄ¿µÄµØÖ·£¬ÔÚת·¢±íÖвéÕÒÔ´µØÖ·¶ÔÓ¦µÄ½Ó¿ÚÊÇ·ñÓëÈë½Ó¿ÚÆ¥Åä¡£Èç¹û²»Æ¥Å䣬ÈÏΪԴµØÖ·ÊÇαװµÄ£¬¶ªÆú¸Ã±¨ÎÄ¡£Í¨¹ýÕâÖÖ·½Ê½£¬URPF¾ÍÄÜÓÐЧµØ·À·¶ÍøÂçÖÐͨ¹ýÐÞ¸ÄÔ´µØÖ·¶ø½øÐеĶñÒâ¹¥»÷ÐÐΪµÄ·¢Éú¡£Ô´µØÖ·ÆÛƹ¥»÷Ä£ÐÍÈçÏ¡£
2020-3-1
»ªÎª»úÃÜ£¬Î´¾Ðí¿É²»µÃÀ©É¢
µÚ43Ò³, ¹²75Ò³
ÎĵµÃû³Æ ÎĵµÃܼ¶£º
ÔÚRouterA£¨¿Í»§ÍøÂ磩ËùÁ¬½ÓµÄÖ÷»úÉÏαÔìÔ´µØÖ·Îª2.1.1.1µÄ±¨ÎÄ£¬ÏòRouterB·¢ÆðÇëÇó£¬RouterB»ØÓ¦ÇëÇóʱ½«ÏòÕæÕýµÄ¡°2.1.1.1¡±·¢Ëͱ¨ÎÄ¡£ÕâÖÖ±¨ÎĶÔRouterBºÍRouterC¶¼Ôì³ÉÁ˹¥»÷¡£ ME60ËùÖ§³ÖµÄURPF
ME60Ö§³Ö¶Ôij½Ó¿ÚϵÄËùÓÐIP±¨ÎÄͨ¹ýÈçÏÂÁ½ÖÖ·½Ê½½øÐÐURPF¼ì²é£º
? ËÉÉ¢¼ì²é£º¶ÔÓÚ½øÈë¸Ã½Ó¿ÚµÄIP±¨ÎÄ£¬ME60¼ì²éת·¢±íÖÐÊÇ·ñ´æÔÚµ½IP±¨ÎÄÔ´µØÖ·µÄ±íÏî¡£Èç¹û´æÔÚ£¬ÔòURPF¼ì²éͨ¹ý¡£
? Ñϸñ¼ì²é£º¶ÔÓÚ½øÈë¸Ã½Ó¿ÚµÄIP±¨ÎÄ£¬ME60¼ì²éת·¢±íÖÐÊÇ·ñ´æÔÚµ½IP±¨ÎÄÔ´µØÖ·µÄ±íÏî¡£Èç¹û²»´æÔÚ£¬ÔòURPF¼ì²é²»Í¨¹ý¡£Èç¹û´æÔÚ£¬Ôò¼ÌÐø¼ì²é¸Ã±íÏîµÄ³ö½Ó¿ÚÊÇ·ñΪIP±¨ÎĽøÈëµÄ½Ó¿Ú¡£Èç¹ûÁ½¸ö½Ó¿ÚÒ»Ö£¬ÔòURPF¼ì²éͨ¹ý¡£
ME60»¹Ö§³Ö¶Ô·ûºÏijÀàÌØÕ÷µÄ±¨ÎĽøÐÐURPF¼ì²é¡£´ËÀàURPF¼ì²éͨ¹ý»ùÓÚÀàµÄQoSµÄÀ´ÊµÏÖ¡£ÅäÖÃʵÏÖ¹ý³ÌÈçÏ£º
1. ÔÚME60ÉÏ´´½¨²¢ÅäÖÃtraffic classifier£¬ÉèÖÃQoSÁ÷·ÖÀ࣬ÓÃÓÚʶ±ð·ûºÏijÀàÌØÕ÷µÄ±¨ÎÄ¡£
2. ÔÚME60ÉÏ´´½¨²¢ÅäÖÃtraffic behavior£¬ÉèÖÃQoS¶¯×÷ΪURPF¼ì²é¡£¾ßÌåÇë²Î¼û¡°8.2.3 £¨¿ÉÑ¡£©ÅäÖöÔijÀ౨ÎĽøÐÐURPF¼ì²é¡±¡£
3. ÔÚME60ÉÏ´´½¨Á÷Á¿²ßÂÔtraffic policy£¬ÉèÖöÔijÀ౨ÎĽøÐÐURPF¼ì²é¡£
4. ÔÚ½Ó¿ÚÉÏ»òÕßijҵÎñ²ßÂÔÖÐÓ¦ÓøÃÁ÷Á¿²ßÂÔ¡£Ò²¿ÉÈ«¾ÖÓ¦ÓøÃÁ÷Á¿²ßÂÔ£¬´Ëʱ¶ÔËùÓзûºÏÌõ¼þµÄ±¨ÎĽøÐÐURPF¼ì²é
URPFÅäÖ÷¶Àý
²½Öè 1 Ö´ÐÐÃüÁîsystem-view£¬½øÈëϵͳÊÓͼ¡£
2020-3-1
»ªÎª»úÃÜ£¬Î´¾Ðí¿É²»µÃÀ©É¢
µÚ44Ò³, ¹²75Ò³
¹²·ÖÏí92ƪÏà¹ØÎĵµ