
! Current configuration : 13758 bytes
. b1 k# e+ |: O0 [4 _$ ]!
$ Z9 t& C/ p* c6 z6 z% o# Y! Last configuration change at BEIJING(UTC+08:00) TUE NOV 21 10:21:05 2017( V; I% C$ V" r6 x
! Flash config last updated at BEIJING(UTC+08:00) TUE NOV 21 09:55:02 2017
0 u" `# r1 v; l: `5 r! Configuration version 0.33
3 Y. D, S s, @: s# i4 Z% p5 h!
! M, w+ q2 }: V9 B!software version 7.1.0.30(R)(integrity)
* F; ]- n) r- L" r* [: `!software image file flash0: /flash/rp23-7.1.0.30(R).pck
& z. e/ }9 `/ o!compiled on Apr 4 2016, 02:03:40
& H) q( I( g. v3 Bhostname TJSMSSD5=5FWN=5FAR
2 P& P/ @) B# a3 P, Sservice password-encryption- s) r8 M9 i9 |$ w
3 T. ]! r: L/ W* s; K; _* J6 Xenable password 6aa5ae297827 encrypt
) `+ M8 d i! H# T1 [" l- u9 _9 b4 F$ K9 @3 J
user maipu password 7 18498784e555d7, T5 m3 \2 Z7 \3 L% K6 h1 T
) N# F/ x! @3 c# Rip ctrl-protocol unicast7 I" r8 H- }9 m& h) W
ip ctrl-protocol multicast
( u* B/ ]7 x* F# d8 O+ L2 m# Qip mef* r; y% |/ [( q2 B
ip load-sharing per-destination
0 q! U5 \4 ?/ g/ _% r: aipv6 load-sharing per-destination
. F8 |+ I$ Y9 N5 y/ a2 {3 N9 B; o. n5 W9 ^% ?
ip access-list standard 1
5 o5 B7 @. n1 a# i 10 permit host 10.169.18.1) r; i' s2 f; x$ ^# k' {0 d. E" b
20 permit host 10.169.18.20 N+ Y Z! h# i5 A6 u8 k4 {
30 permit host 10.169.18.3
8 r% l+ s8 A; r: _ G8 i% Y 40 permit host 10.169.18.4
}$ H. X) C5 H( J; S 50 permit host 10.169.18.5# ~. D c6 D2 u8 E- l1 N
60 permit host 10.169.18.33
% X& u& E9 c/ d) O. ] 70 permit host 10.169.18.34" k4 ]# u2 @0 l- p% T! [
exit
2 J, j2 | u Uip access-list extended 1002. @7 ^) H- m/ c
1 permit tcp host 10.169.197.126 any eq telnet" } _/ T6 K9 w) ^. d
20 permit tcp 10.170.0.0 0.0.255.255 host 10.169.0.163 eq www
, z- W( Z) v9 Z$ w. T 30 permit ip 10.170.0.0 0.0.255.255 10.169.1.0 0.0.0.311 Q' V* L1 j0 e( o& ?5 ~
40 permit ip 10.170.0.0 0.0.255.255 10.169.12.0 0.0.0.255
% |2 C; B5 F3 U# p! K5 d$ f 50 permit ip 10.170.0.0 0.0.255.255 10.169.13.0 0.0.0.255
- v& Q, L r+ I0 \0 H6 V 60 permit tcp 10.170.0.0 0.0.255.255 host 10.169.7.150 eq 9001: u0 t7 p( |" t) y
70 permit tcp 10.170.0.0 0.0.255.255 host 10.169.7.137 eq 9003
- X- n% h! g4 \5 y: k( E 80 permit ip 10.170.0.0 0.0.255.255 10.169.19.0 0.0.0.31
9 u9 p( G* R* m( f( d1 f; Q 90 permit tcp 10.170.0.0 0.0.255.255 host 10.169.7.137 eq 2008
$ U0 O4 g" V- Z6 m% l- N 100 permit tcp 10.170.0.0 0.0.255.255 host 10.169.7.137 eq 9001
0 S+ h; J& b0 z r t 101 permit tcp 10.170.0.0 0.0.255.255 host 10.169.8.47 eq 55973 @" C2 z) A1 z/ l
102 permit tcp 10.170.0.0 0.0.255.255 host 10.169.8.47 eq 5599
& h/ L9 f/ w$ a! }' i$ T 103 permit tcp 10.170.0.0 0.0.255.255 host 10.169.8.47 eq 8071) n0 r3 \' V5 K& ~9 Z2 ^
104 permit tcp 10.170.0.0 0.0.255.255 host 10.169.8.47 eq 80728 K; Y+ ]- X" h' P5 j, J8 ^% ?3 y
110 deny ip 10.170.0.0 0.0.255.255 10.169.0.0 0.0.255.255
) l! x4 b- X$ ?: B9 w; r* N; }, N 111 deny tcp any any eq 445) x( H4 _* f5 W }# M
112 deny udp any any eq 4459 Q5 W/ t9 a$ |" j# N/ c" _1 H3 v$ q
120 deny tcp any any eq telnet
7 d7 D& q% \5 k) w8 o. l! l& A. a 130 permit ip any any9 \* t. J9 y, N; f3 {- \9 S% H
exit3 h. ^( r( P( {6 r3 I5 p
ip access-list extended 10031 O, C4 O2 ^: `9 m( ? j4 O- U) C
1 permit tcp host 10.169.197.126 any eq telnet7 V% k8 j( j+ Q$ s8 d" I5 p
10 permit tcp any host 10.2.0.19 eq telnet
2 R8 Y/ w/ V. G; ` 20 permit tcp 10.169.0.0 0.0.255.255 host 10.170.3.17 eq www7 E0 k% H2 `, {! ~' Q& v% o
30 deny ip 10.169.0.0 0.0.255.255 10.169.12.0 0.0.0.255
6 r& m, N% N" W( Z 40 deny ip 10.169.0.0 0.0.255.255 10.169.13.0 0.0.0.2554 |! }- b. P/ \# J4 p* y1 H
50 deny ip 10.169.0.0 0.0.255.255 10.169.1.0 0.0.0.31
: _( T5 a2 K9 l3 L 60 permit ip 10.169.0.0 0.0.255.255 10.170.0.0 0.0.0.255, b$ Y& z V( o" X4 d
70 permit ip 10.169.0.0 0.0.255.255 10.170.1.0 0.0.0.255/ j4 }2 N; I2 g8 H, J: @
80 permit ip 10.169.0.0 0.0.255.255 10.170.14.0 0.0.0.2552 n5 q5 u+ L& S* g/ O" u
90 permit ip 10.169.0.0 0.0.255.255 10.170.15.0 0.0.0.255
3 w! M* M4 y" F% V 100 deny ip 10.169.0.0 0.0.255.255 10.170.0.0 0.0.255.255! o1 V1 R- z& `
110 deny tcp any any eq telnet
' }& t' X- Q$ | 111 deny tcp any any eq 445
/ W; r7 ~* S$ R. o2 ^/ c 112 deny udp any any eq 445' R" a0 O2 ~: z6 P7 M2 w
120 permit ip any any7 P/ A( A& f2 E! e1 Q% ~7 A
exit
* [6 v4 |- @$ [+ @6 H& Bip access-list extended 15007 ]. D; h+ ~, I. m
10 permit ip 10.169.0.0 0.0.255.255 any: Q& C: k# y8 z4 i- }2 U) Q$ V! y* @
exit
- b! `" {8 x4 J& Z1 m, e! g: x6 Iip access-list extended 16009 U A. o' Z7 D# X' }1 [
10 permit ip 10.170.196.248 0.0.0.7 any1 Z# F2 k3 S- h% S
exit
& ^0 x( R+ i- O: H xip access-list extended 1700
7 _& c( {" D. h3 G- D7 ? 10 permit ip 10.170.0.0 0.0.255.255 any
% u9 }" ~( M: z exit- o6 n, ]0 f, }
% L) w& q0 j' X! P, B1 H: s! a% H0 P- j( W& @+ i& F. N' I
" G: Y; u1 p9 }# U) n0 ovlan 1
5 Y/ e! y4 Z! K/ M* u: n' w7 F9 f exit
* k, i6 ~- \, Z' @7 `2 ?/ j6 Nvlan 10* s9 k' p" `& R$ s1 a
name yewu!
2 D/ G3 ?, u! ?0 X% U, D0 b# Q ip access-group 1003 in0 d: X, O: h# U, i% v# F
exit9 X3 r; F: M0 X( L- S
vlan 203 l4 u9 U7 u7 \( O% c' P
name oa!5 v; Q: [, D% x3 ?. u, C
ip access-group 1002 in1 {. }+ s" h# |* s
exit
; Q, y& x5 c* y/ `7 q& s# |, t+ u( U9 Q; U; U) g9 E
0 y' e" j; P( y- y; F8 e
!slot=5F0=5F3=5F24FET
2 E* v' t* _" r. `interface fastethernet0/0
+ d- ^" B8 e$ P description description This is for yewu!
% x0 q# p) K, t switchport access vlan 10+ ?/ _1 x" \* ^; S2 c3 ]
dot1x port-control enable
1 g1 k6 ]7 [$ p& ]$ g5 [ no dot1x reauthentication
0 ~% |, `) [5 O: M0 V. j dot1x eap-relay enable
1 e6 t8 L9 _6 B3 G* F4 o1 N5 e dot1x client-probe enable4 j6 o; P5 E8 L% d2 y3 x
exit
% X# K0 V7 A1 pinterface fastethernet0/1
6 r3 \ u4 a+ b4 |! ^! n description description This is for yewu!2 e; B, \+ U- [* b% j
switchport access vlan 10
- E; f- F% \; l" M8 n/ ]% I dot1x port-control enable* Q. d" n$ L3 b; x7 u3 A
no dot1x reauthentication0 @2 L$ E$ R, o( U0 n; g
dot1x eap-relay enable
: O% }% f. O! e" X% O dot1x client-probe enable
[4 s% Y& q! j$ ^ exit5 i3 h6 {9 l8 N( G* c
interface fastethernet0/27 k* Y9 Q/ M9 J! M' O
description description This is for yewu!) W2 J+ v q' k: b& h0 V
switchport access vlan 10
& ~! k2 b0 U5 Y6 R; f& o dot1x port-control enable E4 o' d4 F0 M9 ?
no dot1x reauthentication
" d1 F- j" G$ c) s0 V+ d! | dot1x eap-relay enable+ V8 B' e) [1 R. ~
dot1x client-probe enable' R( M: _% x, {! y5 ~: e
exit- g* x8 w9 k% I6 ]& X8 W3 k
interface fastethernet0/3
! o3 A+ k/ t$ |2 T6 u1 U- a description description This is for yewu!0 s3 s6 N. S4 B1 S( e
switchport access vlan 10* t) }: t* q0 ^; B0 l
dot1x port-control enable' P/ ^9 r8 `6 w% t) r
no dot1x reauthentication
$ g7 F! V: c+ j' E' e8 Y: T dot1x eap-relay enable
5 C9 F) }. t/ A, b/ {% c( h u dot1x client-probe enable. _4 ~0 ^; `+ E1 w
exit
, t3 y0 \7 c6 ]* r# Q1 T p% sinterface fastethernet0/4' {; Z+ _' d- g' P8 `* E
description description This is for yewu!" p+ K4 W+ P2 N, w! c* V n
switchport access vlan 10
+ f+ O) `- @0 o dot1x port-control enable" p1 C" E& N2 r' s, E- s
no dot1x reauthentication
/ P, ~ }- m( Y' p9 U dot1x eap-relay enable- q* o' T1 B0 F( @
dot1x client-probe enable5 N, l3 ^+ M" S4 G7 N2 l& D r
exit' d2 q! x+ u* ]* {5 u. Z
interface fastethernet0/5
, a# a8 T; N0 q; {) P& S7 l description description This is for yewu! F$ h# X) E8 Q$ w+ E4 C8 i( d
switchport access vlan 10# o/ Y% e* s: m$ f% [) J
dot1x port-control enable
( M# ?' r B# T$ s1 g! ~ no dot1x reauthentication
k% H4 o9 Q m dot1x eap-relay enable& d/ h1 k6 }# e" O, P. N( X
dot1x client-probe enable$ H& F: a; g) M9 L. i
exit3 o5 B# g% O5 u
interface fastethernet0/6
6 q+ p6 G# e+ }7 r. l8 I1 A7 a description description This is for yewu!
" d8 p$ p' v5 K/ @+ U) f+ r switchport access vlan 10
, \. S3 z+ s/ [1 c dot1x port-control enable
9 A4 y0 {( j, s4 h, k3 a2 ^" ~9 k no dot1x reauthentication: Q/ n# {# g6 R0 P
dot1x eap-relay enable6 B7 N4 Q Z) [# a
dot1x client-probe enable
/ s4 E; H/ P$ F* r; s exit6 X. t) c6 a' C w% N \" K
interface fastethernet0/7
" P) ?9 @5 K5 c i5 k description description This is for yewu!
, o$ W6 W }2 z5 j" h+ ~ switchport access vlan 10
/ C" j1 D4 e1 J& S; v; D2 Y dot1x port-control enable
5 T/ Z: y9 p- k e1 g no dot1x reauthentication
3 D! [5 U4 L1 Z" w dot1x eap-relay enable8 h4 v- v K" i- A# f3 @
dot1x client-probe enable8 |9 `: N6 Q& v! A3 Q
exit
7 f" [' P G& d6 G! Vinterface fastethernet0/8' Y: f" F6 v4 M5 R4 S) o3 i. C8 B
description description This is for yewu!
: {2 q+ D/ W- `# K+ k switchport access vlan 10) m5 j( `7 P/ N! z% h9 c; x
dot1x port-control enable
) u# M! y3 V8 j( J% r no dot1x reauthentication
2 ]1 w# s2 R( L$ s+ x; X& e dot1x eap-relay enable5 S; w- V( G- Y6 T- o; o
dot1x client-probe enable; |$ y1 o2 |* W+ p5 C& x
exit% s4 ^ v3 e; z0 K% \) a0 c* q* k6 M
interface fastethernet0/9
" }. X/ T- \/ a5 y description description This is for yewu!
& {* ]5 V6 S- l8 L switchport access vlan 10
/ V$ x# l) y9 F: }- c8 _" _9 H dot1x port-control enable4 k; u+ C7 f* d6 H1 h' [6 k
no dot1x reauthentication
4 s) c2 e) t$ s& ]2 e! o dot1x eap-relay enable" S. E2 L! w. h. V/ h
dot1x client-probe enable
& L1 A; U! Y! |8 C% C. S exit$ Z- f0 j# {: i4 c$ Q
interface fastethernet0/10
! d# N) x( {9 _/ A& n description description This is for yewu!
6 @8 m1 o, l! g. | switchport access vlan 10
, q: J3 v8 ?* f0 `& _& z& u dot1x port-control enable
" ?0 W* ?% b( i8 q+ ^: S no dot1x reauthentication
# q* L1 @7 k6 N dot1x eap-relay enable# N5 z, V1 }6 b6 X& W
dot1x client-probe enable+ k' ^! ?9 U& T/ o& B. Z
exit; P& H6 e( q$ ^( m- J# Z- o) `8 k, O
interface fastethernet0/11
7 R2 ?# t( f: s description description This is for yewu! }$ \* O9 N$ T) n1 R0 N, F
switchport access vlan 107 O4 r% t, i1 f" J$ ?6 S" g
dot1x port-control enable
9 o9 w" C, s+ c no dot1x reauthentication! A2 r4 M: J- v& s& n2 {
dot1x eap-relay enable/ K; P' D# Z+ j
dot1x client-probe enable
- E8 X& f7 B7 F. Y7 q0 e exit% b' {5 B! }& n: @! ]
interface fastethernet0/12
! R# a; H( I& J& w3 l$ W description description This is for yewu!
; _7 X, R& z& _ switchport access vlan 10
: @8 t" F$ T; c+ p* c dot1x port-control enable
) G: h0 h2 w$ o: `! x no dot1x reauthentication
5 R R, [% O9 Z9 l1 b/ A- S8 ^ dot1x eap-relay enable
, x( c3 M7 R& d4 f |8 W! E dot1x client-probe enable& n+ a( H, S: ]7 U/ ~, x
exit
$ p9 M! f# _/ A. Uinterface fastethernet0/13; {4 W: I$ w. R1 p8 |4 a$ G
description description This is for oa!
$ f2 a' i. ~& k, F! N switchport access vlan 205 n/ O$ N/ V f5 N7 R# |3 q K+ N
dot1x port-control enable
" B- @ p9 F5 ]; E0 d8 c5 C no dot1x reauthentication
7 J8 [$ F7 M$ q8 Q: ?/ ^) O2 j3 p dot1x eap-relay enable1 o: l0 l! T" H$ u
dot1x client-probe enable P( H* o/ ]8 }$ b
exit
+ B! R4 ?' c& ?& R2 @5 winterface fastethernet0/14
# R4 z" P& v$ Z' P6 g/ r description description This is for oa!
Y$ X. W$ R) H# n) d switchport access vlan 20/ w+ f6 A% w. i& m# a3 ]
dot1x port-control enable
Y# `8 x. i, d5 R no dot1x reauthentication
* W9 z- C y( Z, X ^3 n+ Z, s dot1x eap-relay enable! D1 u5 p+ x2 H) n& k5 E9 O
dot1x client-probe enable
, Z. r$ b% A& F& l( _+ w. M+ C exit
, [) t5 q1 Q8 p1 z1 w) [+ ~interface fastethernet0/15
4 Q/ h7 C5 K2 x description description This is for oa!
& I3 f3 r# ]! p1 \0 a switchport access vlan 203 ~5 D) V) A; \! V0 @. L, V9 N
dot1x port-control enable9 b/ B, j/ {2 W3 W( l* B0 h
no dot1x reauthentication
% Y1 |, R# U7 o' }) i dot1x eap-relay enable
" i6 |& ~6 j( H' a4 t dot1x client-probe enable$ l/ x) ^* c9 E& B5 {: q* Y7 f
exit
6 U8 v+ v/ j2 x7 X/ B, xinterface fastethernet0/16) j% n( ^6 w9 X1 K8 Q# m
description this link jiankong-sw
: j8 e" V2 c5 Q" N- e2 Y7 Y switchport access vlan 20' g: H% C, ^% P, d6 F( O" _% e
dot1x port-control enable! Q$ R; Y! ^* S0 i* a. J
no dot1x reauthentication$ Y2 W0 h8 A1 i: f' c
dot1x eap-relay enable3 |! x9 l7 @5 ]& y# P
dot1x client-probe enable9 l, e2 p. }+ h0 m4 B8 \+ `
exit
* b7 m; r W+ Xinterface fastethernet0/176 U8 G3 L8 h2 m7 d/ K
description this is for oa link zhangyingPC4 I/ S& m0 Q$ d
switchport access vlan 20: c! ]& d' ^+ G8 l- X q$ g/ N4 g' t
dot1x port-control enable$ w1 J2 s" G4 e4 B
no dot1x reauthentication
+ _9 |: S$ L! l, z! X dot1x eap-relay enable) `/ I; i: [' h$ ~: G3 Y
dot1x client-probe enable
' `2 B& i( h( u exit7 O3 q5 c( W5 ^+ i A5 J9 c4 r
interface fastethernet0/18
: i4 I v7 f) [" e$ E6 f description description This is for oa!" J2 @% [* _% T& Y
switchport access vlan 20
3 p$ E! o- V0 C3 F, t1 E dot1x port-control enable" @: A: m; ~) M. r3 p0 v8 M0 C0 p
no dot1x reauthentication
) r) ^* F# ?- Q5 w4 ?2 a dot1x eap-relay enable$ h1 Y B4 Q* C, I
dot1x client-probe enable- E" K0 p; h0 Z: [
exit3 k2 d. v* T- a9 J% O; B: z
interface fastethernet0/19
9 G5 J# v$ Q, x, k* e8 m1 h. N description this is link PMP for oa7 i, w# d3 W! W; X
switchport access vlan 20; n7 ^& h& T0 ~6 y& c" l4 c) Q
dot1x port-control enable
' K2 H/ j/ V1 { b no dot1x reauthentication, D8 I; T: a0 a
dot1x eap-relay enable
0 U' I7 L0 `& ~9 p dot1x client-probe enable- f8 L9 m2 `/ f5 C
exit4 X6 |' R6 x0 e t3 i$ n2 F. w
interface fastethernet0/20/ B$ j7 p' d' \0 w9 F0 W4 _
description this link sw2-48-oa3 }9 ^5 Q6 w) Q! @/ X3 ^7 }2 {0 r; J- ?
switchport access vlan 20/ e. ?3 Z7 @' [( a! P$ D) Y5 o. d8 m
dot1x port-control enable/ Q( T, }3 t$ k0 o% m3 q1 A
no dot1x reauthentication+ L1 D* h$ a3 l
dot1x eap-relay enable" T$ M$ W3 i$ ^4 t' o4 ~1 ?1 l. O
dot1x client-probe enable
6 [8 f, o8 h* `) \. I2 r9 f( D exit
n, I6 y6 D; v! Y) H+ Uinterface fastethernet0/21) N9 E8 e: @+ W# Y$ [: ^
description this link sw2-47-sc, J9 y0 l3 v& q0 E
switchport access vlan 10
! r% ]4 |2 P l Z+ M; g0 [: S dot1x port-control enable
/ p, o# ~; q9 [. y% E! ? no dot1x reauthentication. U V9 c9 P& Q* x
dot1x eap-relay enable' f& E6 |& A; F+ \, l
dot1x client-probe enable( `2 x* f8 h I/ ~! B
exit' o( n/ e' I0 \% p- P+ Y8 p
interface fastethernet0/22
2 h1 n/ R( w( Y/ T- k; e, P3 J0 m- a description this link sw1-48-oa* Q5 }, c# p3 O/ k' [/ ~
switchport access vlan 209 @5 b/ E9 S! B" P" c
dot1x port-control enable
5 L6 i& p6 V7 q7 g1 R# m2 r no dot1x reauthentication2 @; i( ^, c, h& E, n
dot1x eap-relay enable7 E; c9 O7 y" q0 {& i5 L9 y0 d
dot1x client-probe enable1 i& Z" F1 K$ d) I' [+ K, ^
exit5 @* j% m5 A H# v/ [3 o, R
interface fastethernet0/23
9 F7 l3 E0 ^. [( ~, r; A description this link sw1-47-sc8 _5 \9 C( Y0 y0 k% u, T9 k
switchport access vlan 100 ]7 w1 `# `. X2 A* `
dot1x port-control enable. {8 _- U* l0 I2 S4 X# P7 ~
no dot1x reauthentication9 Y, a4 V' Y7 k/ |( _
dot1x eap-relay enable# j3 h+ _0 E; f& ~3 N; n: h, l7 q4 g% Z
dot1x client-probe enable) k3 ^0 p* E1 f1 T) ~: k
exit
$ n; K: S( @/ A$ x% j9 e!end
/ ?( r# K+ p& D! {5 N* H( @% R( u- H& I# \/ p/ u; Y9 E% ?
class-map match-all JK
& G- u4 j5 B# A& t" m1 ] match access-group 1600/ T! x! w- U [4 h6 g$ C
exit: ~2 O$ f& K( p' T |5 s! A
class-map match-all YW, \$ A8 {1 p2 X o( U# ^
match access-group 15007 S6 j+ R+ x1 ^( A- q' n
exit6 P9 [1 {+ i6 k; Z9 I0 v
class-map match-all OA
9 s2 G3 _4 \$ h1 h4 T/ I5 P* _. U) B match access-group 1700! b( v$ S5 v. [6 [, |, R7 j
exit4 F; g! r8 K: y a
policy-map QOS
9 }' m' @8 W1 l: e8 g class YW7 g) _, w& i# W w* x6 L9 P
priority 500
: E' ]" S3 D$ H4 q5 A9 M exit
% V( [/ P1 s" e0 k# {5 } class OA% w+ S5 L4 {1 `9 L ^
bandwidth 2048
. _3 q4 e3 o; E+ @% d$ _5 { exit
1 Q+ b- d$ I8 ~" e class class-default
, u$ | H9 p0 [) O S random-detect% G" n" Q1 m: z$ |1 h2 a
exit
k7 Q, O) N3 [) Z3 F# n3 m. t2 F exit9 q, b% K! E. W$ {
interface loopback1
( P w4 `% K" \- H) c ip address 10.169.199.242 255.255.255.255! E" T5 E) {3 ^" u5 x
exit
, w0 K& x H* W$ {2 t!slot=5F0=5F1=5F3GE& u" C& S/ l# ?, a7 F- C5 w. S# O
interface gigabitethernet0. u& g/ a; A8 V3 C" e7 ^
description MSTP-DIANXIN
/ T4 B. G: d* \" h: T0 ? ip address 10.251.147.182 255.255.255.252
6 R. c4 f: F* i6 b- _1 \5 g/ S% y keepalive gateway 10.251.147.181 interval sec 2
, M( M4 @" C1 {) I1 m ip ospf network point-to-point9 v0 t4 E. J, m9 \- J
exit/ e0 @1 [0 h2 |2 V* y" y# c: h
! Z- Z# K2 J& R5 f/ c9 t, u) ~2 U& Binterface gigabitethernet1$ M/ `; T% E; u! T, R; {- P/ T" f
description MSTP-YIDONG2M
$ j9 I6 S/ D A8 b8 x# K: o0 B9 V ip address 10.251.172.182 255.255.255.2524 M& g' b* Z, X4 g
keepalive gateway 10.251.172.181 interval sec 2
$ ]! m6 X- B2 G1 I* m. d( k9 { service-policy output QOS6 I$ \3 B' j" C& Q; E
ip ospf cost 781( G$ W& d/ ~" j3 R7 h( {. g
ip ospf network point-to-point
) J4 @: {2 d t6 M1 u0 y# @ exit
, u6 a* [$ x$ O- j) Q1 o1 q& ]2 j0 Y
interface gigabitethernet2
1 q4 R5 @+ N( t/ N. R5 b6 z exit
5 \* ?: Z, D& ^$ c |% `* U2 O) k!end
/ j9 T/ n0 f' x! H# f- Z/ \4 z# l
2 B c) Y/ ?0 k( H5 p- Winterface vlan10
0 J) B1 R4 T0 L* O8 {6 I description This is for yewu!
, [6 V i. m& K& b i) Q% ]/ c ip address 10.169.194.126 255.255.255.2248 N7 t, B! `# [# K! T) `$ z
ip address 10.169.197.126 255.255.255.224 secondary. ~( Y6 l3 n* G
exit
$ A' a" z/ Z8 q# L+ Q- ~/ J7 y) J& n6 q
interface vlan20
0 h- u5 d/ m# q description This is for OA!. E) l7 F) ^, Y5 X( |
ip address 10.170.194.126 255.255.255.224
% n2 n3 R1 _' z2 {) X( e ip address 10.170.197.126 255.255.255.224 secondary( L& u, ]% J x/ G7 o4 D0 G
exit
' S8 l; T' P$ F8 C" _
8 K. I# ]4 l' z( w9 R% Linterface null0
! B" ~4 w" T0 s2 `: A- C) R# G5 R no ip unreachables
" d$ N9 ]* R* m! q" F' `5 o* W exit, x6 L+ T, I* ~$ N; B
=20 Z2 @8 `0 D; R! `$ X
router ospf 4005 A3 r* t0 ?! v5 m
router-id 10.169.199.2429 I# o9 w6 [4 ]; W. z4 {5 v+ Z
area 17 stub
% W; `5 X6 f+ L- ` N8 d* R network 10.169.194.96 0.0.0.31 area 17
' s+ `* w/ B# Z. }; l, q network 10.169.197.96 0.0.0.31 area 175 c' e; P. q- A3 Q8 t. k h3 [; x
network 10.169.199.242 0.0.0.0 area 17
) E6 H- j- r0 {5 w% J network 10.170.194.96 0.0.0.31 area 17& E/ A; w& c) y: i7 z; M8 m
network 10.170.197.96 0.0.0.31 area 17
3 Y1 ^2 \8 z1 P, x network 10.251.147.180 0.0.0.3 area 17
" w% g% g$ c3 j4 m8 P0 p: `' m2 _ network 10.251.172.180 0.0.0.3 area 17" h1 h1 _0 e; A" E0 j
exit& a, K0 z. C" a7 ?2 d
radius-server dead-time 59 I+ f# z! t& y2 g+ W
ip radius source-interface loopback1
' H. @7 Z% u5 rroute-map Policy permit 10
; g3 }9 M+ X( x+ b8 i4 M match ip address 1500
* G: s- ?( R& s3 G set ip next-hop 10.251.172.181
# f0 R9 G+ T W7 ?$ }: ^: j exit' M# t( P9 x) l5 k" u2 T6 Z
' C' {* t3 x# Q4 C9 h2 c, |
logging source-ip 10.169.199.242. j9 Y9 h; h( G. L* C! d% @
ntp authenticate# R$ B: L: K g a
ntp authentication-key 1 md5 0e154ff9dd encrypt& j: p' S* G# T+ }& R# r& B
ntp trusted-key 11 W# Z; W5 K+ { H0 P
ntp source loopback1
C0 A9 o) o9 q# g+ pntp server 10.169.18.5 key 1/ ?5 V( ?- ^! i& {3 D% A
ntp server 10.169.18.1 key 12 v7 s0 L8 v# Y9 \
clock timezone BEIJING 8) U8 f1 a: G# Q+ t0 S( ~
snmp-server start=20
# z$ G4 _* G: H9 f# l- |snmp-server location Maipu Mansion,Jiuxing Avenue 16#,High-tech Park,Chengd= F! R' }3 p% s/ V; ~, F/ @: z6 D
u, P.R.China 610041
) Y, e6 c' c* K* S8 `' ?snmp-server view default 1.2 include
0 q' n! R( E B d9 |! w& R( g2 Bsnmp-server view default 1.0.8802 include' a5 X9 Q5 E# B9 {" \# v
snmp-server view default 1.1.2 include
5 V" L. L9 u. q* qsnmp-server view default 1.3.111 include4 O. F* G; c6 M2 _. [
snmp-server view default 1.3.6.1 include4 ^. f" ~. Z7 O8 ?, p$ r3 ~
snmp-server community 8474ee03b631c5=80 view default ro
% n2 L# R( z8 a2 ^3 @) i% ^% asnmp-server community a69ac126b454545c0c=80 view default ro 1
; v8 f# r" B2 @( K8 ?
* H+ h! Z+ N, e" g1 w' l$ l3 u. l. T
line vty 0 4
+ ~: j& T& Z2 Q/ [$ F password 7 6cad7152fdd05b
3 ]& D7 x; r$ w; p& s8 A2 w3 b, x N exit+ I3 j9 U2 V7 v) W5 ]; m3 s( R6 L
!Do NOT modify the following configuration version
2 V9 y0 }$ U5 R% [7 l' i* V* k! Configuration version 0.333 j7 N" z; y- i
!=20
$ h2 K( c+ r/ f9 |" m% z1 D!end=20
' J! m% l; e5 i6 ` j: U
4 K& o4 a9 L5 n, X
, i- q9 i3 c1 B' \8 G( S( ]; H+ q+ p
# m' ?6 N- w' |+ f6 _% e4 ^
) ^8 X3 L) R) D! v6 @% L5 i这是现网配置文件,请看两处红字标识的语句,ospf的cost值设为了781,另一处是策略路由,内网中有两个网段,如果路由按照ospf走,那么应该走cost值小的,即所有网段流量从电信出口走,可是后面又有一条策略路由,表示“10.169.0.0”这个段走移动出口,我想知道,ospf和策略路由哪个优先,内网中俩个段流量如何走?请高手指教!
5 H( S# P2 f2 ], p=6 q$ v) q) j5 I- l
# h& q1 R, P4 P3 I3 J
|
评分
-
查看全部评分
|