網(wǎng)絡(luò)配置實(shí)驗(yàn)報(bào)告
一、實(shí)驗(yàn)整體配置思路
本實(shí)驗(yàn)以企業(yè)三層網(wǎng)絡(luò)架構(gòu)為基礎(chǔ),圍繞“業(yè)務(wù)隔離、全網(wǎng)可達(dá)、安全可控、靈活擴(kuò)展”的目標(biāo),分模塊拆解需求并逐一實(shí)現(xiàn):
地址與接入層:通過(guò)DHCP和VLAN實(shí)現(xiàn)終端的自動(dòng)化地址分配與業(yè)務(wù)域隔離,遵循“最小VLAN透?jìng)鳌睖p少?gòu)V播干擾;
路由層:采用OSPF協(xié)議實(shí)現(xiàn)全網(wǎng)路由互通,通過(guò)“手工RID、精準(zhǔn)宣告、路由匯總”優(yōu)化路由效率,結(jié)合區(qū)域認(rèn)證保障內(nèi)網(wǎng)安全;
邊界與安全層:通過(guò)NAT實(shí)現(xiàn)內(nèi)網(wǎng)互聯(lián)網(wǎng)訪問(wèn),利用ACL細(xì)化流量權(quán)限控制,配置備份鏈路提升網(wǎng)絡(luò)可靠性,同時(shí)支持遠(yuǎn)程運(yùn)維需求。
二、分模塊配置思路
- VLAN與DHCP配置:終端接入與地址自動(dòng)化
配置思路:
先規(guī)劃VLAN與地址池的對(duì)應(yīng)關(guān)系,接入層交換機(jī)將終端接口設(shè)置為access模式并綁定VLAN,匯聚層交換機(jī)與接入層的接口設(shè)置為trunk模式且僅透?jìng)鳂I(yè)務(wù)必需的VLAN(遵循最小透?jìng)髟瓌t);在匯聚層或核心設(shè)備上部署DHCP服務(wù),為業(yè)務(wù)B網(wǎng)絡(luò)的地址池額外配置DNS服務(wù)器地址。 - OSPF配置:全網(wǎng)路由互通與優(yōu)化
配置思路:
手工配置各路由器的Router-ID(與設(shè)備編號(hào)一致),在OSPF區(qū)域0啟用MD5認(rèn)證(密碼123456)保障內(nèi)網(wǎng)路由安全;對(duì)每個(gè)接口的網(wǎng)段進(jìn)行精準(zhǔn)宣告,同時(shí)對(duì)連續(xù)內(nèi)網(wǎng)網(wǎng)段進(jìn)行精確匯總以減少路由表?xiàng)l目;將無(wú)需宣告的接口(如R3-0/0/2)設(shè)置為靜默模式。 - NAT與互聯(lián)網(wǎng)訪問(wèn):邊界流量轉(zhuǎn)發(fā)
配置思路:
在邊界路由器上配置基礎(chǔ)ACL(編號(hào)2000)放行所有內(nèi)網(wǎng)流量,再通過(guò)nat outbound將內(nèi)網(wǎng)流量轉(zhuǎn)換為公網(wǎng)地址,實(shí)現(xiàn)內(nèi)網(wǎng)全網(wǎng)訪問(wèn)互聯(lián)網(wǎng);同時(shí)確保R3-0/0/2接口的路由不被宣告,避免內(nèi)網(wǎng)路由混亂。 - ACL訪問(wèn)控制:流量權(quán)限細(xì)化
配置思路:
針對(duì)“禁止VLAN40/50訪問(wèn)業(yè)務(wù)B”需求,配置基礎(chǔ)ACL(編號(hào)2001)拒絕對(duì)應(yīng)網(wǎng)段流量;針對(duì)“禁止PC1訪問(wèn)PC5”需求,配置高級(jí)ACL(編號(hào)3000)精確匹配源目IP;將ACL應(yīng)用到業(yè)務(wù)B所在VLAN的入方向接口和PC1所在VLAN的出方向接口,實(shí)現(xiàn)流量攔截。 - 備份鏈路與遠(yuǎn)程登錄:可靠性與運(yùn)維支持
備份鏈路配置思路:
將R3-R4的百兆鏈路配置較高的OSPF cost值(如100),使正常情況下流量不經(jīng)過(guò)該鏈路,僅在主鏈路故障時(shí)自動(dòng)切換,實(shí)現(xiàn)備份功能。
遠(yuǎn)程登錄配置思路:
在內(nèi)網(wǎng)telnet-server設(shè)備上啟用Telnet服務(wù),創(chuàng)建高權(quán)限本地用戶(賬號(hào)huawei、密碼123456、權(quán)限level 15),使test設(shè)備可通過(guò)互聯(lián)網(wǎng)遠(yuǎn)程登錄運(yùn)維。
三、驗(yàn)證思路與步驟 - DHCP驗(yàn)證:查看PC的IP獲取情況,業(yè)務(wù)B網(wǎng)絡(luò)PC需驗(yàn)證DNS解析功能。
- OSPF驗(yàn)證:通過(guò)查看OSPF鄰居狀態(tài)和路由表,確認(rèn)全網(wǎng)路由可達(dá)且條目精簡(jiǎn)。
- NAT驗(yàn)證:內(nèi)網(wǎng)設(shè)備ping互聯(lián)網(wǎng)模擬地址,檢查是否通聯(lián)。
- ACL驗(yàn)證:分別測(cè)試VLAN40/50對(duì)業(yè)務(wù)B的訪問(wèn)、PC1對(duì)PC5的訪問(wèn),確認(rèn)攔截規(guī)則生效。
- 備份鏈路驗(yàn)證:斷開主鏈路,觀察備份鏈路是否自動(dòng)接管流量。
- 遠(yuǎn)程登錄驗(yàn)證:test設(shè)備通過(guò)Telnet登錄內(nèi)網(wǎng)服務(wù)器,檢查賬號(hào)權(quán)限是否正常。
四、配置思路總結(jié)
本實(shí)驗(yàn)以“分層拆解、模塊聯(lián)動(dòng)”的思路,將復(fù)雜需求分解為接入層、路由層、邊界層的子任務(wù),每個(gè)模塊遵循“功能實(shí)現(xiàn)→優(yōu)化→安全”的配置邏輯:
接入層聚焦“自動(dòng)化與隔離”,通過(guò)DHCP和VLAN實(shí)現(xiàn)終端管理;
路由層聚焦“互通與效率”,通過(guò)OSPF的精準(zhǔn)配置保障全網(wǎng)可達(dá)并精簡(jiǎn)路由;
邊界與安全層聚焦“訪問(wèn)控制與可靠性”,通過(guò)NAT、ACL、備份鏈路和遠(yuǎn)程登錄滿足業(yè)務(wù)與運(yùn)維需求。
這種思路既保證了功能的完整性,又通過(guò)“最小化配置原則”(如最小VLAN透?jìng)?、精?zhǔn)宣告)提升了網(wǎng)絡(luò)的性能與安全性,是企業(yè)網(wǎng)絡(luò)工程中典型的“需求驅(qū)動(dòng)型”配置方法論。
具體代碼
R2
[V200R003C00]
sysname R2
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
clock timezone China-Standard-Time minus 08:00:00
portal local-server load flash:/portalpage.zip
drop illegal-mac alarm
wlan ac-global carrier id other ac id 0
set cpu-usage threshold 80 restore 75
dhcp enable
ip pool vlan40
gateway-list 172.16.0.1
network 172.16.0.0 mask 255.255.255.0
ip pool vlan50
gateway-list 172.16.1.1
network 172.16.1.0 mask 255.255.255.0
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %K8m.Nt84DZ}e#<0
8bmE3Uw}%$%$ local-user admin service-type http firewall zone Local priority 15 interface GigabitEthernet0/0/0 ip address 172.16.67.2 255.255.255.0 interface GigabitEthernet0/0/1 interface GigabitEthernet0/0/1.1 dot1q termination vid 40 ip address 172.16.0.1 255.255.255.0 arp broadcast enable dhcp select global interface GigabitEthernet0/0/1.2 dot1q termination vid 50 ip address 172.16.1.1 255.255.255.0 arp broadcast enable dhcp select global interface GigabitEthernet0/0/2 ip address 172.16.2.1 255.255.255.0 interface NULL0 ospf 1 router-id 2.2.2.2 silent-interface GigabitEthernet0/0/1.1 silent-interface GigabitEthernet0/0/1.2 area 0.0.0.0 abr-summary 172.16.0.0 255.255.192.0 authentication-mode md5 1 cipher %$%$$V_|'o\_QBYyP2Oz*FJWi4y%
network 172.16.0.1 0.0.0.0
network 172.16.1.1 0.0.0.0
network 172.16.2.1 0.0.0.0
area 0.0.0.1
abr-summary 172.16.64.0 255.255.192.0
network 172.16.67.2 0.0.0.0
ip route-static 172.16.0.0 255.255.192.0 NULL0
ip route-static 172.16.64.0 255.255.192.0 NULL0
user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
wlan ac
test
[V200R003C00]
sysname text
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
clock timezone China-Standard-Time minus 08:00:00
portal local-server load flash:/portalpage.zip
drop illegal-mac alarm
wlan ac-global carrier id other ac id 0
set cpu-usage threshold 80 restore 75
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %K8m.Nt84DZ}e#<0
8bmE3Uw}%$%$ local-user admin service-type http firewall zone Local priority 15 interface GigabitEthernet0/0/0 ip address 100.0.0.2 255.255.255.0 interface GigabitEthernet0/0/1 interface GigabitEthernet0/0/2 interface NULL0 user-interface con 0 authentication-mode password user-interface vty 0 4 user-interface vty 16 20 wlan ac R3 [V200R003C00] sysname R3 board add 0/4 2FE snmp-agent local-engineid 800007DB03000000000000 snmp-agent clock timezone China-Standard-Time minus 08:00:00 portal local-server load flash:/portalpage.zip drop illegal-mac alarm wlan ac-global carrier id other ac id 0 set cpu-usage threshold 80 restore 75 acl number 2000 rule 5 permit source 172.16.0.0 0.0.255.255 acl number 2001 rule 5 deny source 172.16.0.0 0.0.0.255 rule 10 deny source 172.16.1.0 0.0.0.255 aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password cipher %$%$K8m.Nt84DZ}e#<08bmE3Uw}%
local-user admin service-type http
firewall zone Local
priority 15
interface Ethernet4/0/0
ip address 172.16.130.1 255.255.255.0
interface Ethernet4/0/1
interface GigabitEthernet0/0/0
ip address 172.16.2.2 255.255.255.0
traffic-filter inbound acl 2001
interface GigabitEthernet0/0/1
ip address 172.16.129.1 255.255.255.0
interface GigabitEthernet0/0/2
ip address 100.0.0.1 255.255.255.0
nat server protocol tcp global current-interface telnet inside 172.16.66.254 telnet
nat outbound 2000
interface NULL0
ospf 1 router-id 3.3.3.3
default-route-advertise always
area 0.0.0.0
authentication-mode md5 1 cipher %&3QFuaGUDla>0VvbGWWsbR%
network 172.16.2.2 0.0.0.0
ip route-static 172.16.128.0 255.255.255.0 172.16.129.2
ip route-static 172.16.128.0 255.255.255.0 172.16.130.2 preference 100
ip route-static 172.16.131.0 255.255.255.0 172.16.129.2
ip route-static 172.16.131.0 255.255.255.0 172.16.130.2 preference 100
ip route-static 172.16.132.0 255.255.255.0 172.16.129.2
ip route-static 172.16.132.0 255.255.255.0 172.16.130.2 preference 100
ip route-static 172.16.133.0 255.255.255.0 172.16.129.2
ip route-static 172.16.133.0 255.255.255.0 172.16.130.2 preference 100
ip route-static 172.16.134.0 255.255.255.0 172.16.129.2
ip route-static 172.16.134.0 255.255.255.0 172.16.130.2 preference 100
user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
wlan ac
R7
[V200R003C00]
sysname R7
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
clock timezone China-Standard-Time minus 08:00:00
portal local-server load flash:/portalpage.zip
drop illegal-mac alarm
wlan ac-global carrier id other ac id 0
set cpu-usage threshold 80 restore 75
dhcp enable
ip pool vlan60
gateway-list 172.16.128.1
network 172.16.128.0 mask 255.255.255.128
dns-list 172.16.128.126
ip pool vlan70
gateway-list 172.16.128.129
network 172.16.128.128 mask 255.255.255.128
dns-list 172.16.128.126
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %K8m.Nt84DZ}e#<0
8bmE3Uw}%$%$ local-user admin service-type http firewall zone Local priority 15 interface GigabitEthernet0/0/0 ip address 172.16.133.2 255.255.255.0 interface GigabitEthernet0/0/1 ip address 172.16.134.2 255.255.255.0 interface GigabitEthernet0/0/2 interface GigabitEthernet0/0/2.1 dot1q termination vid 60 ip address 172.16.128.1 255.255.255.128 arp broadcast enable dhcp select global interface GigabitEthernet0/0/2.2 dot1q termination vid 70 ip address 172.16.128.129 255.255.255.128 arp broadcast enable dhcp select global interface NULL0 ip route-static 0.0.0.0 0.0.0.0 172.16.133.1 ip route-static 0.0.0.0 0.0.0.0 172.16.134.1 ip route-static 172.16.128.0 255.255.255.0 NULL0 ip route-static 172.16.131.0 255.255.255.0 172.16.133.1 ip route-static 172.16.132.0 255.255.255.0 172.16.134.1 user-interface con 0 authentication-mode password user-interface vty 0 4 user-interface vty 16 20 wlan ac SW2 sysname sw2 vlan batch 40 50 cluster enable ntdp enable ndp enable drop illegal-mac alarm diffserv domain default drop-profile default aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password simple admin local-user admin service-type http interface Vlanif1 interface MEth0/0/1 interface GigabitEthernet0/0/1 port link-type trunk port trunk allow-pass vlan 40 50 interface GigabitEthernet0/0/2 port link-type access port default vlan 40 interface GigabitEthernet0/0/3 port link-type access port default vlan 50 interface GigabitEthernet0/0/4 interface GigabitEthernet0/0/5 interface GigabitEthernet0/0/6 interface GigabitEthernet0/0/7 interface GigabitEthernet0/0/8 interface GigabitEthernet0/0/9 interface GigabitEthernet0/0/10 interface GigabitEthernet0/0/11 interface GigabitEthernet0/0/12 interface GigabitEthernet0/0/13 interface GigabitEthernet0/0/14 interface GigabitEthernet0/0/15 interface GigabitEthernet0/0/16 interface GigabitEthernet0/0/17 interface GigabitEthernet0/0/18 interface GigabitEthernet0/0/19 interface GigabitEthernet0/0/20 interface GigabitEthernet0/0/21 interface GigabitEthernet0/0/22 interface GigabitEthernet0/0/23 interface GigabitEthernet0/0/24 interface NULL0 user-interface con 0 user-interface vty 0 4 SW1 sysname Huawei vlan batch 10 20 30 cluster enable ntdp enable ndp enable drop illegal-mac alarm diffserv domain default drop-profile default aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password simple admin local-user admin service-type http interface Vlanif1 interface MEth0/0/1 interface GigabitEthernet0/0/1 port link-type trunk port trunk allow-pass vlan 10 20 30 interface GigabitEthernet0/0/2 port link-type access port default vlan 10 interface GigabitEthernet0/0/3 port link-type access port default vlan 20 interface GigabitEthernet0/0/4 port link-type access port default vlan 30 interface GigabitEthernet0/0/5 interface GigabitEthernet0/0/6 interface GigabitEthernet0/0/7 interface GigabitEthernet0/0/8 interface GigabitEthernet0/0/9 interface GigabitEthernet0/0/10 interface GigabitEthernet0/0/11 interface GigabitEthernet0/0/12 interface GigabitEthernet0/0/13 interface GigabitEthernet0/0/14 interface GigabitEthernet0/0/15 interface GigabitEthernet0/0/16 interface GigabitEthernet0/0/17 interface GigabitEthernet0/0/18 interface GigabitEthernet0/0/19 interface GigabitEthernet0/0/20 interface GigabitEthernet0/0/21 interface GigabitEthernet0/0/22 interface GigabitEthernet0/0/23 interface GigabitEthernet0/0/24 interface NULL0 user-interface con 0 user-interface vty 0 4 telnet-server [V200R003C00] sysname telneservert snmp-agent local-engineid 800007DB03000000000000 snmp-agent clock timezone China-Standard-Time minus 08:00:00 portal local-server load flash:/portalpage.zip drop illegal-mac alarm wlan ac-global carrier id other ac id 0 set cpu-usage threshold 80 restore 75 aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password cipher %$%$K8m.Nt84DZ}e#<08bmE3Uw}%
local-user admin service-type http
firewall zone Local
priority 15
interface GigabitEthernet0/0/0
ip address 172.16.66.254 255.255.255.0
interface GigabitEthernet0/0/1
interface GigabitEthernet0/0/2
interface NULL0
user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
wlan ac
R4
[V200R003C00]
sysname R4
board add 0/4 2FE
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
clock timezone China-Standard-Time minus 08:00:00
portal local-server load flash:/portalpage.zip
drop illegal-mac alarm
wlan ac-global carrier id other ac id 0
set cpu-usage threshold 80 restore 75
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %K8m.Nt84DZ}e#<0
8bmE3Uw}%$%$ local-user admin service-type http firewall zone Local priority 15 interface Ethernet4/0/0 ip address 172.16.130.2 255.255.255.0 interface Ethernet4/0/1 interface GigabitEthernet0/0/0 ip address 172.16.129.2 255.255.255.0 interface GigabitEthernet0/0/1 ip address 172.16.131.1 255.255.255.0 interface GigabitEthernet0/0/2 ip address 172.16.132.1 255.255.255.0 interface NULL0 ip route-static 0.0.0.0 0.0.0.0 172.16.129.1 ip route-static 0.0.0.0 0.0.0.0 172.16.130.1 preference 100 ip route-static 172.16.128.0 255.255.255.0 172.16.131.2 ip route-static 172.16.128.0 255.255.255.0 172.16.132.2 ip route-static 172.16.133.0 255.255.255.0 172.16.131.2 ip route-static 172.16.134.0 255.255.255.0 172.16.132.2 user-interface con 0 authentication-mode password user-interface vty 0 4 user-interface vty 16 20 wlan ac R5 [V200R003C00] sysname R5 snmp-agent local-engineid 800007DB03000000000000 snmp-agent clock timezone China-Standard-Time minus 08:00:00 portal local-server load flash:/portalpage.zip drop illegal-mac alarm wlan ac-global carrier id other ac id 0 set cpu-usage threshold 80 restore 75 aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password cipher %$%$K8m.Nt84DZ}e#<08bmE3Uw}%
local-user admin service-type http
firewall zone Local
priority 15
interface GigabitEthernet0/0/0
ip address 172.16.133.1 255.255.255.0
interface GigabitEthernet0/0/1
interface GigabitEthernet0/0/2
interface NULL0
ip route-static 0.0.0.0 0.0.0.0 172.16.131.1
ip route-static 172.16.128.0 255.255.255.0 172.16.133.2
ip route-static 172.16.134.0 255.255.255.0 172.16.133.2
user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
wlan ac
SW3
sysname sw3
vlan batch 60 70
cluster enable
ntdp enable
ndp enable
drop illegal-mac alarm
diffserv domain default
drop-profile default
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
interface Vlanif1
interface MEth0/0/1
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 60 70
interface GigabitEthernet0/0/2
port link-type access
port default vlan 70
interface GigabitEthernet0/0/3
port link-type access
port default vlan 60
interface GigabitEthernet0/0/4
port link-type access
port default vlan 60
interface GigabitEthernet0/0/5
interface GigabitEthernet0/0/6
interface GigabitEthernet0/0/7
interface GigabitEthernet0/0/8
interface GigabitEthernet0/0/9
interface GigabitEthernet0/0/10
interface GigabitEthernet0/0/11
interface GigabitEthernet0/0/12
interface GigabitEthernet0/0/13
interface GigabitEthernet0/0/14
interface GigabitEthernet0/0/15
interface GigabitEthernet0/0/16
interface GigabitEthernet0/0/17
interface GigabitEthernet0/0/18
interface GigabitEthernet0/0/19
interface GigabitEthernet0/0/20
interface GigabitEthernet0/0/21
interface GigabitEthernet0/0/22
interface GigabitEthernet0/0/23
interface GigabitEthernet0/0/24
interface NULL0
user-interface con 0
user-interface vty 0 4
port-group defau
R1
[V200R003C00]
sysname R1
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
clock timezone China-Standard-Time minus 08:00:00
portal local-server load flash:/portalpage.zip
drop illegal-mac alarm
wlan ac-global carrier id other ac id 0
set cpu-usage threshold 80 restore 75
dhcp enable
ip pool vlan20
gateway-list 172.16.65.1
network 172.16.65.0 mask 255.255.255.0
ip pool vlan10
gateway-list 172.16.64.1
network 172.16.64.0 mask 255.255.255.0
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %K8m.Nt84DZ}e#<0
8bmE3Uw}%$%$ local-user admin service-type http firewall zone Local priority 15 interface GigabitEthernet0/0/0 ip address 172.16.67.1 255.255.255.0 interface GigabitEthernet0/0/1 dhcp select global interface GigabitEthernet0/0/1.1 dot1q termination vid 10 ip address 172.16.64.1 255.255.255.0 arp broadcast enable dhcp select global interface GigabitEthernet0/0/1.2 dot1q termination vid 20 ip address 172.16.65.1 255.255.255.0 arp broadcast enable dhcp select global interface GigabitEthernet0/0/1.3 dot1q termination vid 30 ip address 172.16.66.1 255.255.255.0 arp broadcast enable interface GigabitEthernet0/0/2 interface NULL0 ospf 1 router-id 1.1.1.1 area 0.0.0.1 network 172.16.64.1 0.0.0.0 network 172.16.65.1 0.0.0.0 network 172.16.66.1 0.0.0.0 network 172.16.67.0 0.0.0.255 network 172.16.67.1 0.0.0.0 user-interface con 0 authentication-mode password user-interface vty 0 4 user-interface vty 16 20 wlan ac R6 [V200R003C00] sysname R6 snmp-agent local-engineid 800007DB03000000000000 snmp-agent clock timezone China-Standard-Time minus 08:00:00 portal local-server load flash:/portalpage.zip drop illegal-mac alarm wlan ac-global carrier id other ac id 0 set cpu-usage threshold 80 restore 75 aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password cipher %$%$K8m.Nt84DZ}e#<08bmE3Uw}%
local-user admin service-type http
firewall zone Local
priority 15
interface GigabitEthernet0/0/0
ip address 172.16.132.2 255.255.255.0
interface GigabitEthernet0/0/1
ip address 172.16.134.1 255.255.255.0
interface GigabitEthernet0/0/2
interface NULL0
ip route-static 0.0.0.0 0.0.0.0 172.16.132.1
ip route-static 172.16.128.0 255.255.255.0 172.16.134.2
ip route-static 172.16.133.0 255.255.255.0 172.16.134.2
user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
wlan ac
LSW4
sysname Huawei
cluster enable
ntdp enable
ndp enable
drop illegal-mac alarm
diffserv domain default
drop-profile default
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
interface Vlanif1
interface MEth0/0/1
interface GigabitEthernet0/0/1
interface GigabitEthernet0/0/2
interface GigabitEthernet0/0/3
interface GigabitEthernet0/0/4
interface GigabitEthernet0/0/5
interface GigabitEthernet0/0/6
interface GigabitEthernet0/0/7
interface GigabitEthernet0/0/8
interface GigabitEthernet0/0/9
interface GigabitEthernet0/0/10
interface GigabitEthernet0/0/11
interface GigabitEthernet0/0/12
interface GigabitEthernet0/0/13
interface GigabitEthernet0/0/14
interface GigabitEthernet0/0/15
interface GigabitEthernet0/0/16
interface GigabitEthernet0/0/17
interface GigabitEthernet0/0/18
interface GigabitEthernet0/0/19
interface GigabitEthernet0/0/20
interface GigabitEthernet0/0/21
interface GigabitEthernet0/0/22
interface GigabitEthernet0/0/23
interface GigabitEthernet0/0/24
interface NULL0
user-interface con 0
user-interface vty 0 4