作者:邓聪聪

华为系列路由器的负载均衡NQA联动侦测配置案例:

需求:该局域网,IP地址(末位奇数)走联通,IP地址(末位偶数)走电信当某个运营商不可达时,自动切换。通过NQA来确定运营商是否可达。,并与流行为、静态路由联动,实现自动切换。默认路由走联通,当联通不可达切至电信(配置的路由优先级,华为交换机静态路由默认优先级为60)

配置详情:

内网核心路由器配置;

  1. <Huawei>dis cu
  2. [V200R003C00]
  3. #
  4. snmp-agent local-engineid 800007DB03000000000000
  5. snmp-agent
  6. #
  7. clock timezone China-Standard-Time minus 08:00:00
  8. #
  9. portal local-server load portalpage.zip
  10. #
  11. drop illegal-mac alarm
  12. #
  13. set cpu-usage threshold 80 restore 75
  14. #
  15. bfd
  16. #
  17. acl number 2000
  18. description To-Unicom
  19. rule 10 permit source 192.168.0.0 0.0.0.255
  20. acl number 2001
  21. description To-Telecom
  22. rule 10 permit source 192.168.1.0 0.0.0.255
  23. #
  24. acl number 3000
  25. description NAT
  26. rule 10 permit ip source 192.168.0.0 0.0.1.255
  27. #
  28. traffic classifier DX operator and
  29. if-match acl 2001
  30. traffic classifier LT operator and
  31. if-match acl 2000
  32. #
  33. traffic behavior DX
  34. redirect ip-nexthop 20.1.1.1 track nqa test DX
  35. traffic behavior LT
  36. redirect ip-nexthop 10.1.1.1 track nqa test LT
  37. #
  38. traffic policy load
  39. classifier LT behavior LT
  40. classifier DX behavior DX
  41. #
  42. aaa
  43. authentication-scheme default
  44. authorization-scheme default
  45. accounting-scheme default
  46. domain default
  47. domain default_admin
  48. local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$
  49. local-user admin service-type http
  50. #
  51. firewall zone Local
  52. priority 15
  53. #
  54. interface GigabitEthernet0/0/0
  55. ip address 10.1.1.2 255.255.255.252
  56. nat outbound 3000
  57. #
  58. interface GigabitEthernet0/0/1
  59. ip address 20.1.1.2 255.255.255.252
  60. nat outbound 3000
  61. #
  62. interface GigabitEthernet0/0/2
  63. ip address 10.16.0.1 255.255.255.252
  64. traffic-policy load inbound
  65. #
  66. interface NULL0
  67. #
  68. bfd lt bind peer-ip 10.1.1.1 interface GigabitEthernet0/0/0 source-ip 10.1.1.2 o
  69. ne-arm-echo
  70. discriminator local 1
  71. min-echo-rx-interval 200
  72. commit
  73. #
  74. ip route-static 0.0.0.0 0.0.0.0 20.1.1.1 preference 150
  75. ip route-static 0.0.0.0 0.0.0.0 10.1.1.1 track nqa test LT
  76. ip route-static 192.168.0.0 255.255.254.0 10.16.0.2
  77. ip route-static 202.106.0.30 255.255.255.255 10.1.1.1
  78. ip route-static 219.141.140.10 255.255.255.255 20.1.1.1
  79. #
  80. nqa test-instance test DX
  81. test-type icmp
  82. destination-address ipv4 219.141.140.10
  83. frequency 5
  84. probe-count 2
  85. start now
  86. nqa test-instance test LT
  87. test-type icmp
  88. destination-address ipv4 202.106.0.30
  89. frequency 5
  90. probe-count 1
  91. start now
  92. #
  93. user-interface con 0
  94. authentication-mode password
  95. user-interface vty 0 4
  96. user-interface vty 16 20
  97. #
  98. wlan ac
  99. #
  100. return
  101. <Huawei>

内网汇聚设备配置;

  1. [Huawei]dis cu
  2. #
  3. sysname Huawei
  4. #
  5. vlan batch 10 100
  6. #
  7. cluster enable
  8. ntdp enable
  9. ndp enable
  10. #
  11. drop illegal-mac alarm
  12. #
  13. diffserv domain default
  14. #
  15. drop-profile default
  16. #
  17. aaa
  18. authentication-scheme default
  19. authorization-scheme default
  20. accounting-scheme default
  21. domain default
  22. domain default_admin
  23. local-user admin password simple admin
  24. local-user admin service-type http
  25. #
  26. interface Vlanif1
  27. ip address 192.168.0.1 255.255.254.0
  28. #
  29. interface Vlanif10
  30. ip address 10.16.0.2 255.255.255.252
  31. #
  32. interface MEth0/0/1
  33. #
  34. interface GigabitEthernet0/0/1
  35. #
  36. interface GigabitEthernet0/0/2
  37. #
  38. interface GigabitEthernet0/0/3
  39. port link-type access
  40. port default vlan 10
  41. #
  42. interface GigabitEthernet0/0/4
  43. #
  44. interface GigabitEthernet0/0/5
  45. #
  46. interface GigabitEthernet0/0/6
  47. #
  48. interface GigabitEthernet0/0/7
  49. #
  50. interface GigabitEthernet0/0/8
  51. #
  52. interface GigabitEthernet0/0/9
  53. #
  54. interface GigabitEthernet0/0/10
  55. #
  56. interface GigabitEthernet0/0/11
  57. #
  58. interface GigabitEthernet0/0/12
  59. #
  60. interface GigabitEthernet0/0/13
  61. #
  62. interface GigabitEthernet0/0/14
  63. #
  64. interface GigabitEthernet0/0/15
  65. #
  66. interface GigabitEthernet0/0/16
  67. #
  68. interface GigabitEthernet0/0/17
  69. #
  70. interface GigabitEthernet0/0/18
  71. #
  72. interface GigabitEthernet0/0/19
  73. #
  74. interface GigabitEthernet0/0/20
  75. #
  76. interface GigabitEthernet0/0/21
  77. #
  78. interface GigabitEthernet0/0/22
  79. #
  80. interface GigabitEthernet0/0/23
  81. #
  82. interface GigabitEthernet0/0/24
  83. #
  84. interface NULL0
  85. #
  86. ip route-static 0.0.0.0 0.0.0.0 10.16.0.1
  87. #
  88. user-interface con 0
  89. user-interface vty 0 4
  90. #
  91. return
  92. [Huawei]

模拟运营商配置 unicom;

  1. <Huawei>dis cu
  2. #
  3. sysname Huawei
  4. #
  5. aaa
  6. authentication-scheme default
  7. authorization-scheme default
  8. accounting-scheme default
  9. domain default
  10. domain default_admin
  11. local-user admin password cipher OOCM4m($F4ajUn1vMEIBNUw#
  12. local-user admin service-type http
  13. #
  14. firewall zone Local
  15. priority 16
  16. #
  17. interface Ethernet0/0/0
  18. #
  19. interface Ethernet0/0/1
  20. #
  21. interface Serial0/0/0
  22. link-protocol ppp
  23. #
  24. interface Serial0/0/1
  25. link-protocol ppp
  26. #
  27. interface Serial0/0/2
  28. link-protocol ppp
  29. #
  30. interface Serial0/0/3
  31. link-protocol ppp
  32. #
  33. interface GigabitEthernet0/0/0
  34. ip address 1.1.1.1 255.255.255.252
  35. #
  36. interface GigabitEthernet0/0/1
  37. ip address 10.1.1.1 255.255.255.252
  38. #
  39. interface GigabitEthernet0/0/2
  40. #
  41. interface GigabitEthernet0/0/3
  42. #
  43. wlan
  44. #
  45. interface NULL0
  46. #
  47. interface LoopBack1
  48. ip address 202.106.0.30 255.255.255.255
  49. #
  50. interface LoopBack12
  51. ip address 202.106.0.100 255.255.255.255
  52. #
  53. ospf 1
  54. import-route direct
  55. area 0.0.0.0
  56. network 1.1.1.0 0.0.0.3
  57. network 202.106.0.0 0.0.0.255
  58. #
  59. user-interface con 0
  60. user-interface vty 0 4
  61. user-interface vty 16 20
  62. #
  63. return
  64. <Huawei>

模拟运营商配置 telecom;

  1. <Huawei>dis cu
  2. #
  3. sysname Huawei
  4. #
  5. aaa
  6. authentication-scheme default
  7. authorization-scheme default
  8. accounting-scheme default
  9. domain default
  10. domain default_admin
  11. local-user admin password cipher OOCM4m($F4ajUn1vMEIBNUw#
  12. local-user admin service-type http
  13. #
  14. firewall zone Local
  15. priority 16
  16. #
  17. interface Ethernet0/0/0
  18. #
  19. interface Ethernet0/0/1
  20. #
  21. interface Serial0/0/0
  22. link-protocol ppp
  23. #
  24. interface Serial0/0/1
  25. link-protocol ppp
  26. #
  27. interface Serial0/0/2
  28. link-protocol ppp
  29. #
  30. interface Serial0/0/3
  31. link-protocol ppp
  32. #
  33. interface GigabitEthernet0/0/0
  34. ip address 1.1.1.2 255.255.255.252
  35. #
  36. interface GigabitEthernet0/0/1
  37. #
  38. interface GigabitEthernet0/0/2
  39. ip address 20.1.1.1 255.255.255.252
  40. #
  41. interface GigabitEthernet0/0/3
  42. #
  43. wlan
  44. #
  45. interface NULL0
  46. #
  47. interface LoopBack1
  48. ip address 219.141.140.10 255.255.255.255
  49. #
  50. ospf 1
  51. import-route direct
  52. area 0.0.0.0
  53. network 1.1.1.0 0.0.0.3
  54. #
  55. nqa test-instance test 1
  56. test-type icmp
  57. destination-address ipv4 1.1.1.1
  58. frequency 5
  59. probe-count 1
  60. start now
  61. #
  62. user-interface con 0
  63. user-interface vty 0 4
  64. user-interface vty 16 20
  65. #
  66. return
  67. <Huawei>

模拟故障;修改unicom的 interface GigabitEthernet0/0/1端口配置,使其互联不可达,但链路状态依然up。

故障前路由表状态;

  1. 0.0.0.0/0 Static 60 0 RD 10.1.1.1 GigabitEthernet
  2. 0/0/0
  3. 10.1.1.0/30 Direct 0 0 D 10.1.1.2 GigabitEthernet
  4. 0/0/0
  5. 10.1.1.2/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
  6. 0/0/0
  7. 10.1.1.3/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
  8. 0/0/0
  9. 10.16.0.0/30 Direct 0 0 D 10.16.0.1 GigabitEthernet
  10. 0/0/2
  11. 10.16.0.1/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
  12. 0/0/2
  13. 10.16.0.3/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
  14. 0/0/2
  15. 20.1.1.0/30 Direct 0 0 D 20.1.1.2 GigabitEthernet
  16. 0/0/1
  17. 20.1.1.2/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
  18. 0/0/1
  19. 20.1.1.3/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
  20. 0/0/1
  21. 127.0.0.0/8 Direct 0 0 D 127.0.0.1 InLoopBack0
  22. 127.0.0.1/32 Direct 0 0 D 127.0.0.1 InLoopBack0
  23. 127.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
  24. 192.168.0.0/23 Static 60 0 RD 10.16.0.2 GigabitEthernet
  25. 0/0/2
  26. 202.106.0.30/32 Static 60 0 RD 10.1.1.1 GigabitEthernet
  27. 0/0/0
  28. 219.141.140.10/32 Static 60 0 RD 20.1.1.1 GigabitEthernet
  29. 0/0/1
  30. 255.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0

故障后路由表状态;

  1. 0.0.0.0/0 Static 150 0 RD 20.1.1.1 GigabitEthernet
  2. 0/0/1
  3. 10.1.1.0/30 Direct 0 0 D 10.1.1.2 GigabitEthernet
  4. 0/0/0
  5. 10.1.1.2/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
  6. 0/0/0
  7. 10.1.1.3/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
  8. 0/0/0
  9. 10.16.0.0/30 Direct 0 0 D 10.16.0.1 GigabitEthernet
  10. 0/0/2
  11. 10.16.0.1/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
  12. 0/0/2
  13. 10.16.0.3/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
  14. 0/0/2
  15. 20.1.1.0/30 Direct 0 0 D 20.1.1.2 GigabitEthernet
  16. 0/0/1
  17. 20.1.1.2/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
  18. 0/0/1
  19. 20.1.1.3/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
  20. 0/0/1
  21. 127.0.0.0/8 Direct 0 0 D 127.0.0.1 InLoopBack0
  22. 127.0.0.1/32 Direct 0 0 D 127.0.0.1 InLoopBack0
  23. 127.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
  24. 192.168.0.0/23 Static 60 0 RD 10.16.0.2 GigabitEthernet
  25. 0/0/2
  26. 202.106.0.30/32 Static 60 0 RD 10.1.1.1 GigabitEthernet
  27. 0/0/0
  28. 219.141.140.10/32 Static 60 0 RD 20.1.1.1 GigabitEthernet
  29. 0/0/1
  30. 255.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0

配置验证:

display ip routing-table   #用于查看当前设备的路由表状态

display nqa results test-instance test LT   #用于验证NQA的状态

 

版权声明:本文为dengcongcong原创文章,遵循 CC 4.0 BY-SA 版权协议,转载请附上原文出处链接和本声明。
本文链接:https://www.cnblogs.com/dengcongcong/p/8393716.html