H3C之VRRP实验部署
环境:H3C模拟器
1.实验拓扑:
SWA与SWB通过各自的以太网端口GigabitEthernet 1/0/1~GigabitEthernet 1/0/2相互连接SWC、SWD。HostA、HostB、HostC通过以太网线分别连接SWC、SWD各自的以太网端口。本组网模拟了实际组网中涉及的VRRP主要应用。
【配置步骤】
1.1配置VRRP单备份组
通过配置VRRP单备份组,实现HostA能够访问HostC。HostA的缺省网关为192.168.0.254/24。
SWA和SWB属于虚拟IP地址为192.168.0.254/24的备份组1。当SWA正常工作时,局域网流量通过SWA转发,当SWA出现故障时,局域网流量通过SWB转发。
搭建实验环境
按照上图,搭建实验环境,完成交换机SWA、SWB、SWC、SWD的链路连接。配置主机HostA的IP地址为192.168.0.1/24,网关为192.168.0.254;配置主机HostC的IP地址为10.0.0.1/24,网关为10.0.0.254/24。
基本配置
在SWA上创建VRRP单备份组1,并配置备份组1的虚拟IP地址为192.168.0.254/24。 [SWA]interface Vlan-interface 10 [SWA-Vlan-interface10]vrrp vrid 1 virtual-ip 192.168.0.254 在SWA上,设置在备份组1中的优先级为120.设置SWA工作在抢占模式。 [SWA-Vlan-interface10]vrrp vrid 1 priority 120 [SWA-Vlan-interface10]vrrp vrid 1 preempt-mode 在SWB上创建VRRP单备份组1,并配置备份组1的虚拟IP地址为192.168.0.254/24。 [SWB]interface Vlan-interface 10 [SWB-Vlan-interface10]vrrp vrid 1 virtual-ip 192.168.0.254 在SWB上,设置在备份组1中的优先级为100.设置SWB工作在抢占模式。 [SWB-Vlan-interface10]vrrp vrid 1 priority 100 [SWB-Vlan-interface10]vrrp vrid 1 preempt-mode 由配置可见,在SWA、SWB上分别创建VRRP单备份组1,形成了VRRP端口。
测试连通性
在HostA上ping HostC,显示如下:
关闭STP配置: [SWA]interface GigabitEthernet 1/0/1 [SWA-GigabitEthernet1/0/1]undo stp enable [SWB]interface GigabitEthernet 1/0/1 [SWB-GigabitEthernet1/0/1]undo stp enable [SWD]interface GigabitEthernet 1/0/1 [SWD-GigabitEthernet1/0/1]undo stp enable [SWD]interface GigabitEthernet 1/0/2 [SWD-GigabitEthernet1/0/2]undo stp enable 完成trunk基本配置: [SWA]interface g1/0/2 [SWA-GigabitEthernet1/0/2]port link-type trunk [SWA-GigabitEthernet1/0/2]port trunk permit vlan 10 [SWB]interface GigabitEthernet 1/0/2 [SWB-GigabitEthernet1/0/2]port link-type trunk [SWB-GigabitEthernet1/0/2]port trunk permit vlan 10 [SWC]interface GigabitEthernet 1/0/1 [SWC-GigabitEthernet1/0/1]port link-type trunk [SWC-GigabitEthernet1/0/1]port trunk permit vlan 10 [SWC-GigabitEthernet1/0/1]quit [SWC]interface GigabitEthernet 1/0/2 [SWC-GigabitEthernet1/0/2]port link-type trunk [SWC-GigabitEthernet1/0/2]port trunk permit vlan 10 完成路由基本配置: [SWA]rip 1 [SWA-rip-1]version 2 [SWA-rip-1]undo summary [SWA-rip-1]network 192.168.0.0 [SWA-rip-1]network 192.168.255.0 [SWA-rip-1]silent-interface Vlan-interface 10 [SWB]rip 1 [SWB-rip-1]version 2 [SWB-rip-1]undo summary [SWB-rip-1]network 192.168.0.0 [SWB-rip-1]network 192.168.255.0 [SWB-rip-1]silent-interface Vlan-interface 10 [SWD]rip 1 [SWD-rip-1]ver [SWD-rip-1]version 2 [SWD-rip-1]undo su [SWD-rip-1]undo summary [SWD-rip-1]network 10.0.0.0 [SWD-rip-1]network 192.168.255.0 [SWD-rip-1]quit
检查VRRP端口
完成上一步骤后,在SWA、SWB上检查VRRP端口表项:
<SWA>display vrrp verbose
IPv4 Virtual Router Information:
Running mode : Standard
Total number of virtual routers : 1
Interface Vlan-interface10
VRID : 1 Adver Timer : 100
Admin Status : Up State : Master
Config Pri : 120 Running Pri : 120
Preempt Mode : Yes Delay Time : 0
Auth Type : None
Virtual IP : 192.168.0.254
Virtual MAC : 0000-5e00-0101
Master IP : 192.168.0.252
从显示信息中可以看出,SWA为VRRP单备份组1 Master设备,备份组1的虚拟IP地址为192.168.0.254/24。
[SWB]display vrrp verbose
IPv4 Virtual Router Information:
Running mode : Standard
Total number of virtual routers : 1
Interface Vlan-interface10
VRID : 1 Adver Timer : 100
Admin Status : Up State : Backup
Config Pri : 100 Running Pri : 100
Preempt Mode : Yes Delay Time : 0
Become Master : 3370ms left
Auth Type : None
Virtual IP : 192.168.0.254
Master IP : 192.168.0.252
从显示信息中可以看出,SWB为VRRP单备份组1 Backup设备,备份组1的虚拟IP地址为192.168.0.254/24。
1.2配置VRRP双备份组
在SWA上创建VRRP单备份组1,并配置备份组1的虚拟IP地址为192.168.0.254/24。在SWA上创建VRRP单备份组2,并配置备份组2的虚拟IP地址为192.168.1.254/24。
[SWA]interface Vlan-interface 10
[SWA-Vlan-interface10]vrrp vrid 1 virtual-ip 192.168.0.254
[SWA]interface Vlan-interface 20
[SWA-Vlan-interface20]vrrp vrid 2 virtual-ip 192.168.1.254
在SWA上,设置在备份组1中的优先级为120,设置在备份组2中的优先级为100。设置SWA工作在抢占模式。
[SWA-Vlan-interface10]vrrp vrid 1 priority 120
[SWA-Vlan-interface10]vrrp vrid 1 preempt-mode
[SWA-Vlan-interface20]vrrp vrid 2 priority 100
[SWA-Vlan-interface20]vrrp vrid 2 preempt-mode
在SWB上创建VRRP单备份组1,并配置备份组1的虚拟IP地址为192.168.0.254/24。在SWB上创建VRRP单备份组2,并配置备份组2的虚拟IP地址为192.168.1.254/24。
[SWB]interface Vlan-interface 10
[SWB-Vlan-interface10]vrrp vrid 1 virtual-ip 192.168.0.254
[SWB]interface Vlan-interface 20
[SWB-Vlan-interface20]vrrp vrid 2 virtual-ip 192.168.0.254
在SWB上,设置在备份组1中的优先级为100,设置SWB工作在抢占模式。在SWB上,设置在备份组2中的优先级为120,设置SWB工作在抢占模式。
[SWA-Vlan-interface10]vrrp vrid 1 priority 100
[SWA-Vlan-interface10]vrrp vrid 1 preempt-mode
[SWA-Vlan-interface20]vrrp vrid 2 priority 120
[SWA-Vlan-interface20]vrrp vrid 2 preempt-mode
由配置可见,在SWA、SWB上分别创建VRRP单备份组1,VRRP单备份组2,形成了VRRP端口。
测试连通性
在HostA上ping HostC,显示如下:
C:\>ping 10.0.0.1
Ping 10.0.0.1 (10.0.0.1): 56 data bytes, press CTRL_C to break
56 bytes from 10.0.0.1: icmp_seq=0 ttl=253 time=11.000 ms
56 bytes from 10.0.0.1: icmp_seq=1 ttl=253 time=20.000 ms
56 bytes from 10.0.0.1: icmp_seq=2 ttl=253 time=4.000 ms
56 bytes from 10.0.0.1: icmp_seq=3 ttl=253 time=7.000 ms
56 bytes from 10.0.0.1: icmp_seq=4 ttl=253 time=4.000 ms
--- Ping statistics for 10.0.0.1 ---
5 packet(s) transmitted, 5 packet(s) received, 0.0% packet loss
结果显示,从HostA可以ping通HostC,并且从HostA发送给HostC的报文通过SWA转发。
检查VRRP端口
完成上一步骤后,在SWA、SWB上检查VRRP端口表项:
<SWA>display vrrp verbose
IPv4 Virtual Router Information:
Running mode : Standard
Total number of virtual routers : 2
Interface Vlan-interface10
VRID : 1 Adver Timer : 100
Admin Status : Up State : Master
Config Pri : 120 Running Pri : 120
Preempt Mode : Yes Delay Time : 0
Auth Type : None
Virtual IP : 192.168.0.254
Virtual MAC : 0000-5e00-0101
Master IP : 192.168.0.252
Interface Vlan-interface20
VRID : 2 Adver Timer : 100
Admin Status : Up State : Backup
Config Pri : 100 Running Pri : 100
Preempt Mode : Yes Delay Time : 0
Become Master : 3120ms left
Auth Type : None
Virtual IP : 192.168.1.254
Master IP : 192.168.1.253
从显示信息中可以看出,SWA为VRRP单备份组1 Master设备,备份组1的虚拟IP地址为192.168.0.254/24。SWA为VRRP单备份组2 Backup设备,备份组2的虚拟IP地址为192.168.1.254/24。
<SWB>display vrrp verbose
IPv4 Virtual Router Information:
Running mode : Standard
Total number of virtual routers : 2
Interface Vlan-interface10
VRID : 1 Adver Timer : 100
Admin Status : Up State : Backup
Config Pri : 100 Running Pri : 100
Preempt Mode : Yes Delay Time : 0
Become Master : 2940ms left
Auth Type : None
Virtual IP : 192.168.0.254
Master IP : 192.168.0.252
Interface Vlan-interface20
VRID : 2 Adver Timer : 100
Admin Status : Up State : Master
Config Pri : 120 Running Pri : 120
Preempt Mode : Yes Delay Time : 0
Auth Type : None
Virtual IP : 192.168.1.254
Virtual MAC : 0000-5e00-0102
Master IP : 192.168.1.253
从显示信息中可以看出,SWB为VRRP单备份组1 Backup设备,备份组1的虚拟IP地址为192.168.0.254/24。从SWB为VRRP单备份组2 Master设备,备份组2的虚拟IP地址为192.168.1.254/24。
检查VRRP特性
在SWB上,关闭与SWC相连端口GigabitEthernet1/0/2。
[SWB]interface GigabitEthernet 1/0/2
[SWB-GigabitEthernet1/0/2]shu
[SWB-GigabitEthernet1/0/2]shutdown
同时在HostB上ping HostC,显示如下:
C:\>ping -n 10.0.0.1
Ping 10.0.0.1 (10.0.0.1): 56 data bytes, press CTRL_C to break
Request timeout
56 bytes from 10.0.0.1: icmp_seq=1 ttl=253 time=23.000 ms
56 bytes from 10.0.0.1: icmp_seq=2 ttl=253 time=11.000 ms
56 bytes from 10.0.0.1: icmp_seq=3 ttl=253 time=8.000 ms
56 bytes from 10.0.0.1: icmp_seq=4 ttl=253 time=4.000 ms
--- Ping statistics for 10.0.0.1 ---
5 packet(s) transmitted, 5 packet(s) received, 0.0% packet loss
结果显示,从HostB可以ping通HostC,只丢弃了1个报文。证明当SWB设备出现故障时,VRRP状态发生了迁移。HostB发送给HostC的报文通过SWA转发。在SWB上检查VRRP端口表项:
<SWA>display vrrp verbose
IPv4 Virtual Router Information:
Running mode : Standard
Total number of virtual routers : 2
Interface Vlan-interface10
VRID : 1 Adver Timer : 100
Admin Status : Up State : Master
Config Pri : 120 Running Pri : 120
Preempt Mode : Yes Delay Time : 0
Auth Type : None
Virtual IP : 192.168.0.254
Virtual MAC : 0000-5e00-0101
Master IP : 192.168.0.252
Interface Vlan-interface20
VRID : 2 Adver Timer : 100
Admin Status : Up State : Master
Config Pri : 100 Running Pri : 100
Preempt Mode : Yes Delay Time : 0
Auth Type : None
Virtual IP : 192.168.1.254
Virtual MAC : 0000-5e00-0102
Master IP : 192.168.1.252
从显示信息中可以看出,SWA为VRRP单备份组1 Master设备,备份组1的虚拟IP地址为192.168.0.254/24。SWA为VRRP单备份组2 Master设备,备份组2的虚拟IP地址为192.168.1.254/24。
此文章若有错误请大大佬指正