项目名称:有线网络高可用实施方案
项目需求:RouterOS 或SecPathF1000-S 2台, H3C S5500核心交换机2台,汇聚层S5120千兆交换机2台。
项目目的:汇聚层--核心层--网关实现高可用。防止单台设备或者链路故障导致全局或者局部网络不可用 ,防止单点故障造成损失,同时
汇聚层核心层实现负载均衡。
网路拓扑图:
说明与实现:
1. 两台出口设备一主一备,防止单台(路由)故障导致全局网络不可用。
2. 两台S5500核心交换机负载均衡,同时防止单台(核心)设备故障导致局部网络不可用。核心交换机配置两条缺省路由(优先级不同),
下一跳分别为两台Routeros IP,并与track项联动,在核心上开启nqa的icmp-echo监测功能,判断吓一跳路由是否可达。若不可达则
对应的缺省路由失效,启动另一缺省路由。
3.每台汇聚层交换机分别开启两个trunk并上行分别链接至两台核心交换机,防止单台(核心)设备故障导致局部网络不可用。
补充:
经过最近一段时间的考虑,遇到了一个比较男解决的问题: panabit的网桥设计。
panabit的每个网桥只能使用两个端口,一进一出。 每台核心都需要物理连接到两台RouterOS。
目前想到的有两个方案:
每台核心出两条线经过panabit连接到两台RouterOS,需要四个网桥8个端口。 缺点:这样panabit所有网桥都是用,网线增多,出了问题不好定位,走线乱。每台核心出一条线连接到panabit,panabit接外网的线挂个傻瓜交换机分流到两台RouterOS。 这种方式理论上应该可以,但是我致电咨询panabit工程师,
工程师说不可以,不知道是不是没听清楚的原因。
综合布线:
P : 主机房
S1: 从1机房
S2: 从2机房
汇聚层: 汇聚层设备分别放置在12F对应位置的机房,如S1区域的汇聚设备安装在12F-S1机房,S2区域的汇聚设备安装在12F-S2机房.
交换机统计:
机房位置 | 交换机数量 |
---|---|
11F-S1 | 4 |
12F-S1 | 6 |
13F-S1 | 5 |
累计15台 | |
11F-S2 | 5 |
12F-S2 | 6 |
13F-S2 | 5 |
累计16台 |
拉线统计:
源机房 | 目的机房 | 拉线数量 |
---|---|---|
12F-S1 | 13F-S1 | 5+3(预留)=8 |
11F-S1 | 4+4(预留)=8 | |
累计16条网线 | ||
12F-S2 | 13F-S2 | 5+3(预留)=8 |
11F-S2 | 5+3(预留)=8 | |
累计16条网线 |
所以拉线总数为:16+16=32条。
相关配置:
可参考:http://book.51cto.com/art/201205/339440.htm
VRRP配置: 目前共有vlan 1(default), 2-3, 5-6, 9-10, 15-16, 20, 30, 36, 40, 50, 60, 70, 80,90-91, 100, 110, 114, 119- 120, 123, 130, 140, 150, 180-181, 185,190-191, 200, 220, 222, 240, 253,888, 2000,4092-4094, 计43个 vlan. 通过在一个 VRRP 备份组中创建多个 VRRP 备份组(分属于不同VLAN),在实现主备备份 VRRP 应用的同时实现 VRRP 备份组中交换机的负载分担(100网段以下 流量走CoreSW1,100网段以上 流量走CoreSW2,vlan 888为电信公网网段,不做高可用节省IP地址)
注:目前H3C部分高端交换机VRRP支持负载均衡模式,但是S5500不支持,只能选择负载分担了。
配置命令:
CoreSW01:
interface Vlan-interface 1
ip address 192.168.1.2 255.255.255.0
vrrp vrid 1 virtual-ip 192.168.1.1
vrrp vrid 1 priority 120
vrrp vrid 1 preempt-mode timer delay 5
interface Vlan-interface 2
ip address 192.168.2.2 255.255.255.0
vrrp vrid 2 virtual-ip 192.168.2.1
vrrp vrid 2 priority 120
vrrp vrid 2 preempt-mode timer delay 5
interface Vlan-interface 3
ip address 192.168.3.2 255.255.255.0
vrrp vrid 3 virtual-ip 192.168.3.1
vrrp vrid 3 priority 120
vrrp vrid 3 preempt-mode timer delay 5
interface Vlan-interface 5
ip address 192.168.0.2 255.255.255.0
vrrp vrid 5 virtual-ip 192.168.0.1
vrrp vrid 5 priority 120
vrrp vrid 5 preempt-mode timer delay 5
interface Vlan-interface 6
ip address 192.168.6.2 255.255.255.0
vrrp vrid 6 virtual-ip 192.168.6.1
vrrp vrid 6 priority 120
vrrp vrid 6 preempt-mode timer delay 5
interface Vlan-interface 9
ip address 192.168.9.2 255.255.255.248
vrrp vrid 9 virtual-ip 192.168.9.1
vrrp vrid 9 priority 120
vrrp vrid 9 preempt-mode timer delay 5
interface Vlan-interface 10
ip address 192.168.10.2 255.255.255.0
vrrp vrid 10 virtual-ip 192.168.10.1
vrrp vrid 10 priority 120
vrrp vrid 10 preempt-mode timer delay 5
interface Vlan-interface 15
ip address 192.168.15.2 255.255.255.0
vrrp vrid 15 virtual-ip 192.168.15.1
vrrp vrid 15 priority 120
vrrp vrid 15 preempt-mode timer delay 5
interface Vlan-interface 16
ip address 192.168.16.2 255.255.255.0
vrrp vrid 16 virtual-ip 192.168.16.1
vrrp vrid 16 priority 120
vrrp vrid 16 preempt-mode timer delay 5
interface Vlan-interface 20
ip address 192.168.20.2 255.255.255.0
vrrp vrid 20 virtual-ip 192.168.20.1
vrrp vrid 20 priority 120
vrrp vrid 20 preempt-mode timer delay 5
interface Vlan-interface 30
ip address 192.168.30.2 255.255.255.0
vrrp vrid 30 virtual-ip 192.168.30.1
vrrp vrid 30 priority 120
vrrp vrid 30 preempt-mode timer delay 5
interface Vlan-interface 40
ip address 192.168.40.2 255.255.255.0
vrrp vrid 40 virtual-ip 192.168.40.1
vrrp vrid 40 priority 120
vrrp vrid 40 preempt-mode timer delay 5
interface Vlan-interface 50
ip address 192.168.50.2 255.255.255.0
vrrp vrid 50 virtual-ip 192.168.50.1
vrrp vrid 50 priority 120
vrrp vrid 50 preempt-mode timer delay 5
interface Vlan-interface 60
ip address 192.168.60.2 255.255.255.0
vrrp vrid 60 virtual-ip 192.168.60.1
vrrp vrid 60 priority 120
vrrp vrid 60 preempt-mode timer delay 5
interface Vlan-interface 70
ip address 192.168.70.2 255.255.255.0
vrrp vrid 70 virtual-ip 192.168.70.1
vrrp vrid 70 priority 120
vrrp vrid 70 preempt-mode timer delay 5
interface Vlan-interface 80
ip address 192.168.80.2 255.255.255.0
vrrp vrid 80 virtual-ip 192.168.80.1
vrrp vrid 80 priority 120
vrrp vrid 80 preempt-mode timer delay 5
interface Vlan-interface 90
ip address 192.168.90.2 255.255.255.0
vrrp vrid 90 virtual-ip 192.168.90.1
vrrp vrid 90 priority 120
vrrp vrid 90 preempt-mode timer delay 5
interface Vlan-interface 91
ip address 192.168.91.2 255.255.255.0
vrrp vrid 91 virtual-ip 192.168.91.1
vrrp vrid 91 priority 120
vrrp vrid 91 preempt-mode timer delay 5
interface Vlan-interface 100
ip address 192.168.100.2 255.255.255.0
vrrp vrid 100 virtual-ip 192.168.100.1
vrrp vrid 100 priority 120
vrrp vrid 100 preempt-mode timer delay 5
interface Vlan-interface 110
ip address 192.168.110.3 255.255.255.0
vrrp vrid 110 virtual-ip 192.168.110.1
vrrp vrid 110 preempt-mode timer delay 5
interface Vlan-interface 120
ip address 192.168.120.3 255.255.255.0
vrrp vrid 120 virtual-ip 192.168.120.1
vrrp vrid 120 preempt-mode timer delay 5
interface Vlan-interface 130
ip address 192.168.130.3 255.255.255.0
vrrp vrid 130 virtual-ip 192.168.130.1
vrrp vrid 130 preempt-mode timer delay 5
interface Vlan-interface 140
ip address 192.168.140.3 255.255.255.0
vrrp vrid 140 virtual-ip 192.168.140.1
vrrp vrid 140 preempt-mode timer delay 5
interface Vlan-interface 150
ip address 192.168.254.5 255.255.255.248
vrrp vrid 150 virtual-ip 192.168.254.1
vrrp vrid 150 preempt-mode timer delay 5
interface Vlan-interface 180
ip address 192.168.180.3 255.255.255.0
vrrp vrid 180 virtual-ip 192.168.180.1
vrrp vrid 180 preempt-mode timer delay 5
interface Vlan-interface 181
ip address 192.168.181.3 255.255.255.0
vrrp vrid 181 virtual-ip 192.168.181.1
vrrp vrid 181 preempt-mode timer delay 5
interface Vlan-interface 185
ip address 192.168.185.3 255.255.255.0
vrrp vrid 185 virtual-ip 192.168.185.1
vrrp vrid 185 preempt-mode timer delay 5
interface Vlan-interface 190
ip address 192.168.190.3 255.255.255.252
vrrp vrid 190 virtual-ip 192.168.190.1
vrrp vrid 190 preempt-mode timer delay 5
interface Vlan-interface 200
ip address 192.168.200.3 255.255.254.0
vrrp vrid 200 virtual-ip 192.168.200.1
vrrp vrid 200 preempt-mode timer delay 5
interface Vlan-interface 220
ip address 192.168.220.3 255.255.254.0
vrrp vrid 220 virtual-ip 192.168.220.1
vrrp vrid 220 preempt-mode timer delay 5
interface Vlan-interface 222
ip address 192.168.222.3 255.255.255.0
vrrp vrid 222 virtual-ip 192.168.222.1
vrrp vrid 222 preempt-mode timer delay 5
interface Vlan-interface 240
ip address 192.168.240.3 255.255.254.0
vrrp vrid 240 virtual-ip 192.168.240.1
vrrp vrid 240 preempt-mode timer delay 5
CoreSW02:
interface Vlan-interface 1
ip address 192.168.1.3 255.255.255.0
vrrp vrid 1 virtual-ip 192.168.1.1
vrrp vrid 1 preempt-mode timer delay 5
interface Vlan-interface 2
ip address 192.168.2.3 255.255.255.0
vrrp vrid 2 virtual-ip 192.168.2.1
vrrp vrid 2 preempt-mode timer delay 5
interface Vlan-interface 3
ip address 192.168.3.3 255.255.255.0
vrrp vrid 3 virtual-ip 192.168.3.1
vrrp vrid 3 preempt-mode timer delay 5
interface Vlan-interface 5
ip address 192.168.0.3 255.255.255.0
vrrp vrid 5 virtual-ip 192.168.0.1
vrrp vrid 5 preempt-mode timer delay 5
interface Vlan-interface 6
ip address 192.168.6.3 255.255.255.0
vrrp vrid 6 virtual-ip 192.168.6.1
vrrp vrid 6 preempt-mode timer delay 5
interface Vlan-interface 9
ip address 192.168.9.3 255.255.255.248
vrrp vrid 9 virtual-ip 192.168.9.1
vrrp vrid 9 preempt-mode timer delay 5
interface Vlan-interface 10
ip address 192.168.10.3 255.255.255.0
vrrp vrid 10 virtual-ip 192.168.10.1
vrrp vrid 10 preempt-mode timer delay 5
interface Vlan-interface 15
ip address 192.168.15.3 255.255.255.0
vrrp vrid 15 virtual-ip 192.168.15.1
vrrp vrid 15 preempt-mode timer delay 5
interface Vlan-interface 16
ip address 192.168.16.3 255.255.255.0
vrrp vrid 16 virtual-ip 192.168.16.1
vrrp vrid 16 preempt-mode timer delay 5
interface Vlan-interface 20
ip address 192.168.20.3 255.255.255.0
vrrp vrid 20 virtual-ip 192.168.20.1
vrrp vrid 20 preempt-mode timer delay 5
interface Vlan-interface 30
ip address 192.168.30.3 255.255.255.0
vrrp vrid 30 virtual-ip 192.168.30.1
vrrp vrid 30 preempt-mode timer delay 5
interface Vlan-interface 40
ip address 192.168.40.3 255.255.255.0
vrrp vrid 40 virtual-ip 192.168.40.1
vrrp vrid 40 preempt-mode timer delay 5
interface Vlan-interface 50
ip address 192.168.50.3 255.255.255.0
vrrp vrid 50 virtual-ip 192.168.50.1
vrrp vrid 50 preempt-mode timer delay 5
interface Vlan-interface 60
ip address 192.168.60.3 255.255.255.0
vrrp vrid 60 virtual-ip 192.168.60.1
vrrp vrid 60 preempt-mode timer delay 5
interface Vlan-interface 70
ip address 192.168.70.3 255.255.255.0
vrrp vrid 70 virtual-ip 192.168.70.1
vrrp vrid 70 preempt-mode timer delay 5
interface Vlan-interface 80
ip address 192.168.80.3 255.255.255.0
vrrp vrid 80 virtual-ip 192.168.80.1
vrrp vrid 80 preempt-mode timer delay 5
interface Vlan-interface 90
ip address 192.168.90.3 255.255.255.0
vrrp vrid 90 virtual-ip 192.168.90.1
vrrp vrid 90 preempt-mode timer delay 5
interface Vlan-interface 91
ip address 192.168.91.3 255.255.255.0
vrrp vrid 91 virtual-ip 192.168.91.1
vrrp vrid 91 preempt-mode timer delay 5
interface Vlan-interface 100
ip address 192.168.100.3 255.255.255.0
vrrp vrid 100 virtual-ip 192.168.100.1
vrrp vrid 100 preempt-mode timer delay 5
interface Vlan-interface 110
ip address 192.168.110.2 255.255.255.0
vrrp vrid 110 virtual-ip 192.168.110.1
vrrp vrid 110 priority 120
vrrp vrid 110 preempt-mode timer delay 5
interface Vlan-interface 120
ip address 192.168.120.2 255.255.255.0
vrrp vrid 120 virtual-ip 192.168.120.1
vrrp vrid 120 priority 120
vrrp vrid 120 preempt-mode timer delay 5
interface Vlan-interface 130
ip address 192.168.130.2 255.255.255.0
vrrp vrid 130 virtual-ip 192.168.130.1
vrrp vrid 130 priority 120
vrrp vrid 130 preempt-mode timer delay 5
interface Vlan-interface 140
ip address 192.168.140.2 255.255.255.0
vrrp vrid 140 virtual-ip 192.168.140.1
vrrp vrid 140 priority 120
vrrp vrid 140 preempt-mode timer delay 5
interface Vlan-interface 150
ip address 192.168.254.5 255.255.255.248
vrrp vrid 150 virtual-ip 192.168.254.1
vrrp vrid 150 priority 120
vrrp vrid 150 preempt-mode timer delay 5
interface Vlan-interface 180
ip address 192.168.180.2 255.255.255.0
vrrp vrid 180 virtual-ip 192.168.180.1
vrrp vrid 180 priority 120
vrrp vrid 180 preempt-mode timer delay 5
interface Vlan-interface 181
ip address 192.168.181.2 255.255.255.0
vrrp vrid 181 virtual-ip 192.168.181.1
vrrp vrid 181 priority 120
vrrp vrid 181 preempt-mode timer delay 5
interface Vlan-interface 185
ip address 192.168.185.2 255.255.255.0
vrrp vrid 185 virtual-ip 192.168.185.1
vrrp vrid 185 priority 120
vrrp vrid 185 preempt-mode timer delay 5
interface Vlan-interface 190
ip address 192.168.190.2 255.255.255.252
vrrp vrid 190 virtual-ip 192.168.190.1
vrrp vrid 190 priority 120
vrrp vrid 190 preempt-mode timer delay 5
interface Vlan-interface 200
ip address 192.168.200.2 255.255.254.0
vrrp vrid 200 virtual-ip 192.168.200.1
vrrp vrid 200 priority 120
vrrp vrid 200 preempt-mode timer delay 5
interface Vlan-interface 220
ip address 192.168.220.2 255.255.254.0
vrrp vrid 220 virtual-ip 192.168.220.1
vrrp vrid 220 priority 120
vrrp vrid 220 preempt-mode timer delay 5
interface Vlan-interface 222
ip address 192.168.222.2 255.255.255.0
vrrp vrid 222 virtual-ip 192.168.222.1
vrrp vrid 222 priority 120
vrrp vrid 222 preempt-mode timer delay 5
interface Vlan-interface 240
ip address 192.168.240.2 255.255.254.0
vrrp vrid 240 virtual-ip 192.168.240.1
vrrp vrid 240 priority 120
vrrp vrid 240 preempt-mode timer delay 5
本文转自marbury 51CTO博客,原文链接:http://blog.51cto.com/magic3/1140053,如需转载请自行联系原作者