HX_SW1: <HX_SW1>dis vrrp br VRID State Interface Type Virtual IP ---------------------------------------------------------------- 10 Master Vlanif10 Normal 192.168.10.1 20 Master Vlanif20 Normal 192.168.20.1 30 Backup Vlanif30 Normal 192.168.30.1 40 Backup Vlanif40 Normal 192.168.40.1 200 Master Vlanif200 Normal 192.168.200.1 <HX_SW1> ------------------------------------ HX_SW2: <HX_SW2>dis vrrp br VRID State Interface Type Virtual IP ---------------------------------------------------------------- 10 Backup Vlanif10 Normal 192.168.10.1 20 Backup Vlanif20 Normal 192.168.20.1 30 Master Vlanif30 Normal 192.168.30.1 40 Master Vlanif40 Normal 192.168.40.1 200 Backup Vlanif200 Normal 192.168.200.1 <HX_SW2>
FW1: [FW1]un in en [FW1]sysname FW1 [FW1]int g1/0/0 [FW1-GigabitEthernet1/0/0]ip add 192.168.6.1 24 [FW1-GigabitEthernet1/0/0]service-manage all permit [FW1-GigabitEthernet1/0/0]int g1/0/1 [FW1-GigabitEthernet1/0/1]ip add 192.168.2.1 24 [FW1-GigabitEthernet1/0/1]service-manage all permit [FW1-GigabitEthernet1/0/1]int g1/0/2 [FW1-GigabitEthernet1/0/2]ip add 192.168.4.1 24 [FW1-GigabitEthernet1/0/2]service-manage all permit [FW1-GigabitEthernet1/0/2]int g1/0/3 [FW1-GigabitEthernet1/0/3]ip add 192.168.7.1 24 [FW1-GigabitEthernet1/0/3]service-manage all permit [FW1-GigabitEthernet1/0/3]int g1/0/6 [FW1-GigabitEthernet1/0/6]ip add 192.168.1.1 24 [FW1-GigabitEthernet1/0/6]service-manage all permit [FW1-GigabitEthernet1/0/6]qui [FW1]firewall zone untrust [FW1-zone-untrust]add int g1/0/0 [FW1-zone-untrust]add int g1/0/3 [FW1-zone-untrust]qui [FW1]firewall zone trust [FW1-zone-trust]add int g1/0/1 [FW1-zone-trust]add int g1/0/2 [FW1-zone-trust]qui [FW1]firewall zone dmz [FW1-zone-dmz]add int g1/0/6 [FW1-zone-dmz]qui [FW1]ip route-static 0.0.0.0 0 192.168.6.3 [FW1]ip route-static 0.0.0.0 0 192.168.7.3 preference 70 [FW1]security-policy [FW1-policy-security]rule name permit_heat [FW1-policy-security-rule-permit_heat]source-zone local [FW1-policy-security-rule-permit_heat]destination-zone dmz [FW1-policy-security-rule-permit_heat]action permit [FW1-policy-security-rule-permit_heat]q [FW1-policy-security]rule name permit_trust_untrust [FW1-policy-security-rule-permit_trust_untrust]source-zone trust [FW1-policy-security-rule-permit_trust_untrust]destination-zone untrust [FW1-policy-security-rule-permit_trust_untrust]action permit [FW1-policy-security-rule-permit_trust_untrust]q [FW1-policy-security]q [FW1]int g1/0/1 [FW1-GigabitEthernet1/0/1]vrrp vrid 2 virtual-ip 192.168.2.100 active [FW1-GigabitEthernet1/0/1]qui [FW1]int g1/0/0 [FW1-GigabitEthernet1/0/0]vrrp vrid 6 virtual-ip 192.168.6.100 active [FW1-GigabitEthernet1/0/0]qui [FW1]int g1/0/2 [FW1-GigabitEthernet1/0/2]vrrp vrid 4 virtual-ip 192.168.4.100 active [FW1-GigabitEthernet1/0/2]qui [FW1]int g1/0/3 [FW1-GigabitEthernet1/0/3]vrrp vrid 7 virtual-ip 192.168.7.100 active [FW1-GigabitEthernet1/0/3]qui [FW1]hrp interface g1/0/6 remote 192.168.1.2 [FW1]hrp en HRP_S[FW1]hrp auto-sync HRP_S[FW1]dis hrp state HRP_S[FW1]dis hrp int ------------------------------------ FW2: [FW2]un in en [FW2]sysname FW2 [FW2]int g1/0/0 [FW2-GigabitEthernet1/0/0]ip add 192.168.6.2 24 [FW2-GigabitEthernet1/0/0]service-manage all permit [FW2-GigabitEthernet1/0/0]int g1/0/1 [FW2-GigabitEthernet1/0/1]ip add 192.168.2.4 24 [FW2-GigabitEthernet1/0/1]service-manage all permit [FW2-GigabitEthernet1/0/1]int g1/0/2 [FW2-GigabitEthernet1/0/2]ip add 192.168.4.4 24 [FW2-GigabitEthernet1/0/2]service-manage all permit [FW2-GigabitEthernet1/0/2]int g1/0/3 [FW2-GigabitEthernet1/0/3]ip add 192.168.7.2 24 [FW2-GigabitEthernet1/0/3]service-manage all permit [FW2-GigabitEthernet1/0/3]int g1/0/6 [FW2-GigabitEthernet1/0/6]ip add 192.168.1.2 24 [FW2-GigabitEthernet1/0/6]service-manage all permit [FW2-GigabitEthernet1/0/6]qui [FW2]firewall zone untrust [FW2-zone-untrust]add int g1/0/0 [FW2-zone-untrust]add int g1/0/3 [FW2-zone-untrust]qui [FW2]firewall zone trust [FW2-zone-trust]add int g1/0/1 [FW2-zone-trust]add int g1/0/2 [FW2-zone-trust]qui [FW2]firewall zone dmz [FW2-zone-dmz]add int g1/0/6 [FW2-zone-dmz]qui [FW2]ip route-static 0.0.0.0 0 192.168.6.3 [FW2]ip route-static 0.0.0.0 0 192.168.7.3 preference 70 [FW2]security-policy [FW2-policy-security]rule name permit_heat [FW2-policy-security-rule-permit_heat]source-zone local [FW2-policy-security-rule-permit_heat]destination-zone dmz [FW2-policy-security-rule-permit_heat]action permit [FW2-policy-security-rule-permit_heat]q [FW2-policy-security]rule name permit_trust_untrust [FW2-policy-security-rule-permit_trust_untrust]source-zone trust [FW2-policy-security-rule-permit_trust_untrust]destination-zone untrust [FW2-policy-security-rule-permit_trust_untrust]action permit [FW2-policy-security-rule-permit_trust_untrust]q [FW2-policy-security]q [FW2]int g1/0/1 [FW2-GigabitEthernet1/0/1]vrrp vrid 2 virtual-ip 192.168.2.100 standby [FW2-GigabitEthernet1/0/1]qui [FW2]int g1/0/0 [FW2-GigabitEthernet1/0/0]vrrp vrid 6 virtual-ip 192.168.6.100 standby [FW2-GigabitEthernet1/0/0]qui [FW2]int g1/0/2 [FW2-GigabitEthernet1/0/2]vrrp vrid 4 virtual-ip 192.168.4.100 standby [FW2-GigabitEthernet1/0/2]qui [FW2]int g1/0/3 [FW2-GigabitEthernet1/0/3]vrrp vrid 7 virtual-ip 192.168.7.100 standby [FW2-GigabitEthernet1/0/3]qui [FW2]hrp interface g1/0/6 remote 192.168.1.1 [FW2]hrp en HRP_S[FW2]hrp auto-sync HRP_S[FW2]dis hrp state HRP_S[FW2]dis hrp int ------------------------------------ AR1: un in en sysname AR1 int g0/0/1 ip add 192.168.6.3 24 int g0/0/0 ip add 192.168.8.1 24 qui int loo 0 ip add 5.5.5.5 32 qui
qui save ------------------------------------ AR2: un in en sysname AR2 int g0/0/1 ip add 192.168.7.3 24 qui int loo 0 ip add 9.9.9.9 32 qui
qui save ------------------------------------ HX_SW1: int g0/0/1 port link-type access port default vlan 2 qui int g0/0/2 port link-type access port default vlan 4 qui int vlan 2 ip add 192.168.2.2 24 qui int vlan 4 ip add 192.168.4.3 24 qui ip route-static 0.0.0.0 0 192.168.2.10 ip route-static 0.0.0.0 0 192.168.4.100 preference 70 qui save ------------------------------------ HX_SW2: int g0/0/1 port link-type access port default vlan 2 qui int g0/0/2 port link-type access port default vlan 4 qui int vlan 2 ip add 192.168.2.3 24 qui int vlan 4 ip add 192.168.4.2 24 qui ip route-static 0.0.0.0 0 192.168.2.10 ip route-static 0.0.0.0 0 192.168.4.100 preference 70 qui save
HX_SW2: <HX_SW2>sys [HX_SW2]vlan batch 100 101 102 [HX_SW2]int g0/0/12 [HX_SW2-GigabitEthernet0/0/12]port link-type trunk [HX_SW2-GigabitEthernet0/0/12]port trunk allow-pass vlan all [HX_SW2-GigabitEthernet0/0/12]int g0/0/4 [HX_SW2-GigabitEthernet0/0/4]port trunk allow-pass vlan 100 101 102 [HX_SW2-GigabitEthernet0/0/4]int g0/0/8 [HX_SW2-GigabitEthernet0/0/8]port trunk allow-pass vlan 100 101 102 [HX_SW2-GigabitEthernet0/0/8]qui [HX_SW2]int vlan 100 [HX_SW2-Vlanif100]ip add 192.168.100.1 24 [HX_SW2-Vlanif100]int vlan 101 [HX_SW2-Vlanif101]ip add 192.168.101.1 24 [HX_SW2-Vlanif101]int vlan 102 [HX_SW2-Vlanif102]ip add 192.168.102.1 24 [HX_SW2-Vlanif102]qui [HX_SW2]dhcp enable [HX_SW2]ip pool ap_pool Info:It's successful to create an IP address pool. [HX_SW2-ip-pool-ap_pool]gateway-list 192.168.100.1 [HX_SW2-ip-pool-ap_pool]network 192.168.100.0 mask 24 [HX_SW2-ip-pool-ap_pool]excluded-ip-address 192.168.100.100 [HX_SW2-ip-pool-ap_pool]dns-list 192.168.200.2 [HX_SW2-ip-pool-ap_pool]qui [HX_SW2]ip pool hua_1 Info:It's successful to create an IP address pool. [HX_SW2-ip-pool-hua_1]gateway-list 192.168.101.1 [HX_SW2-ip-pool-hua_1]network 192.168.101.0 mask 24 [HX_SW2-ip-pool-hua_1]dns-list 192.168.200.2 [HX_SW2-ip-pool-hua_1]qui [HX_SW2]ip pool hua_2 Info:It's successful to create an IP address pool. [HX_SW2-ip-pool-hua_2]gateway-list 192.168.102.1 [HX_SW2-ip-pool-hua_2]network 192.168.102.0 mask 24 [HX_SW2-ip-pool-hua_2]dns-list 192.168.200.2 [HX_SW2-ip-pool-hua_2]qui [HX_SW2]int vlan 100 [HX_SW2-Vlanif100]dhcp select global [HX_SW2-Vlanif100]int vlan 101 [HX_SW2-Vlanif101]dhcp select global [HX_SW2-Vlanif101]int vlan 102 [HX_SW2-Vlanif102]dhcp select global [HX_SW2-Vlanif102]qui [HX_SW2]qui <HX_SW2>save ------------------------------------ JR_SW4: <JR_SW4>sys [JR_SW4]vlan batch 100 101 102 [JR_SW4]int g0/0/2 [JR_SW4-GigabitEthernet0/0/2]port trunk allow-pass vlan 100 101 102 [JR_SW4-GigabitEthernet0/0/2]int g0/0/4 [JR_SW4-GigabitEthernet0/0/4]port link-type trunk [JR_SW4-GigabitEthernet0/0/4]port trunk pvid vlan 100 [JR_SW4-GigabitEthernet0/0/4]port trunk allow-pass vlan 100 101 [JR_SW4-GigabitEthernet0/0/4]qui [JR_SW4]qui <JR_SW4>save ------------------------------------ JR_SW8: <JR_SW8>sys [JR_SW8]vlan batch 100 101 102 [JR_SW8]int g0/0/2 [JR_SW8-GigabitEthernet0/0/2]port trunk allow-pass vlan 100 101 102 [JR_SW8-GigabitEthernet0/0/2]int g0/0/4 [JR_SW8-GigabitEthernet0/0/4]port link-type trunk [JR_SW8-GigabitEthernet0/0/4]port trunk pvid vlan 100 [JR_SW8-GigabitEthernet0/0/4]port trunk allow-pass vlan 100 102 [JR_SW8-GigabitEthernet0/0/4]qui [JR_SW8]qui <JR_SW8>SAVE ------------------------------------ AC: <AC6605>sys [AC6605]un in en [AC6605]sysname AC1 [AC1]vlan batch 100 to 102 [AC1]int g0/0/1 [AC1-GigabitEthernet0/0/1]port link-type trunk [AC1-GigabitEthernet0/0/1]port trunk allow-pass vlan all [AC1-GigabitEthernet0/0/1]qui [AC1]int vlan 100 [AC1-Vlanif100]ip add 192.168.100.100 24 [AC1-Vlanif100]qui [AC1]capwap source int vlanif100 [AC1]wlan [AC1-wlan-view]ap-group name CYY [AC1-wlan-ap-group-CYY]qui [AC1-wlan-view]regulatory-domain-profile name domain1 [AC1-wlan-regulate-domain-domain1]country-code cn [AC1-wlan-regulate-domain-domain1]qui [AC1-wlan-view]ap-group name CYY [AC1-wlan-ap-group-CYY]regulatory-domain-profile domain1 Warning: Modifying the country code will clear channel, power and antenna gain c onfigurations of the radio and reset the AP. Continue?[Y/N]:y [AC1-wlan-ap-group-CYY]qui [AC1-wlan-view]qui [AC1]wlan [AC1-wlan-view]ap-group name YYC [AC1-wlan-ap-group-YYC]qui [AC1-wlan-view]regulatory-domain-profile name domain2 [AC1-wlan-regulate-domain-domain2]country-code cn [AC1-wlan-regulate-domain-domain2]q [AC1-wlan-view]ap-group name YYC [AC1-wlan-ap-group-YYC]regulatory-domain-profile domain2 Warning: Modifying the country code will clear channel, power and antenna gain c onfigurations of the radio and reset the AP. Continue?[Y/N]:y [AC1-wlan-ap-group-YYC]qui [AC1-wlan-view]ap auth-mode mac-auth [AC1-wlan-view]ap-id 0 ap-mac 00e0-fc35-17d0 [AC1-wlan-ap-0]ap-name area_0 [AC1-wlan-ap-0]ap-group CYY Warning: This operation may cause AP reset. If the country code changes, it will clear channel, power and antenna gain configurations of the radio, Whether to c ontinue? [Y/N]:y [AC1-wlan-ap-0]qui [AC1-wlan-view]ap auth-mode mac-auth [AC1-wlan-view]ap-id 1 ap-mac 00e0-fc5f-17a0 [AC1-wlan-ap-1]ap-name area_1 [AC1-wlan-ap-1]ap-group YYC Warning: This operation may cause AP reset. If the country code changes, it will clear channel, power and antenna gain configurations of the radio, Whether to c ontinue? [Y/N]:y [AC1-wlan-ap-1]qui [AC1-wlan-view]qui [AC1]wlan [AC1-wlan-view]security-profile name A [AC1-wlan-sec-prof-A]security wpa2 psk pass-phrase a1234567 aes [AC1-wlan-sec-prof-A]q [AC1-wlan-view]security-profile name X [AC1-wlan-sec-prof-X]security wpa2 psk pass-phrase huawei@123 aes [AC1-wlan-sec-prof-X]qui [AC1-wlan-view]ssid-profile name B [AC1-wlan-ssid-prof-B]ssid CYY-CY [AC1-wlan-ssid-prof-B]q [AC1-wlan-view]ssid-profile name Y [AC1-wlan-ssid-prof-Y]ssid YYC-YC [AC1-wlan-ssid-prof-Y]q [AC1-wlan-view]vap-profile name C [AC1-wlan-vap-prof-C]forward-mode tunnel [AC1-wlan-vap-prof-C]service-vlan vlan-id 101 [AC1-wlan-vap-prof-C]security-profile A [AC1-wlan-vap-prof-C]ssid-profile B [AC1-wlan-vap-prof-C]qui [AC1-wlan-view]vap-profile name Z [AC1-wlan-vap-prof-Z]forward-mode tunnel [AC1-wlan-vap-prof-Z]service-vlan vlan-id 102 [AC1-wlan-vap-prof-Z]security-profile X [AC1-wlan-vap-prof-Z]ssid-profile Y [AC1-wlan-vap-prof-Z]qui [AC1-wlan-view]ap-group name CYY [AC1-wlan-ap-group-CYY]vap-profile C wlan 1 radio 0 [AC1-wlan-ap-group-CYY]vap-profile C wlan 1 radio 1 [AC1-wlan-ap-group-CYY]qui [AC1-wlan-view]ap-group name YYC [AC1-wlan-ap-group-YYC]vap-profile Z wlan 1 radio 0 [AC1-wlan-ap-group-YYC]vap-profile Z wlan 1 radio 1 [AC1-wlan-ap-group-YYC]qui [AC1-wlan-view]qui [AC1]qui <AC1>save