希望配置qos做網段整體限流,但是放過指定的ip 192.168.8.249 192.168.8.51, 完整配置如下,感謝
#
version 9.1.041, Release 9119P16
#
sysname H3C
#
clock timezone Beijing add 08:00:00
clock protocol none
#
telnet server enable
#
qos carl 1 destination-ip-address subnet 192.168.8.0 23 per-address
qos carl 2 source-ip-address subnet 192.168.8.0 23 per-address
#
dialer-group 1 rule ip permit
dialer-group 2 rule ip permit
dialer-group 3 rule ip permit
dialer-group 4 rule ip permit
#
ip load-sharing mode per-flow src-ip global
#
dhcp enable
dhcp server forbidden-ip 192.168.0.1
dhcp server forbidden-ip 192.168.2.1
dhcp server forbidden-ip 192.168.8.1
dhcp server forbidden-ip 192.168.10.1
dhcp server always-broadcast
#
dns proxy enable
#
lldp global enable
#
system-working-mode standard
password-recovery enable
#
vlan 1
#
vlan 2
#
object-group ip address 1
#
dhcp server ip-pool lan1
gateway-list 192.168.0.1
network 192.168.0.0 mask 255.255.255.0
dns-list 192.168.0.1
#
dhcp server ip-pool vlan2
gateway-list 192.168.2.1
network 192.168.2.0 mask 255.255.255.0
dns-list 192.168.2.1
expired day 3 hour 2
#
dhcp server ip-pool xg10
gateway-list 192.168.8.1
network 192.168.8.0 mask 255.255.254.0
dns-list 192.168.8.1
expired day 3 hour 2
#
dhcp server ip-pool xg11
gateway-list 192.168.10.1
network 192.168.10.0 mask 255.255.254.0
dns-list 192.168.10.1
expired day 1 hour 2
#
dhcp server ip-pool xge0/0/10
dns-list 202.96.134.33 202.96.128.86
#
interface Dialer0
ppp chap password cipher $c$3$yEw0+UXI0+xPeh17qpDUz2dAxQ6F3xlaMN+Z
ppp chap user 07551203874180@163.gd
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user 07551203874180@163.gd password cipher $c$3$iAwU7hlHt9q2hV0oTK4rn7k5+oU35yP2/UIq
mtu 1492
dialer bundle enable
dialer-group 1
dialer timer idle 0
dialer timer autodial 1
ip address ppp-negotiate
tcp mss 1280
ip last-hop hold
qos car inbound carl 1 cir 22000 cbs 687500 ebs 0 green pass red discard yellow pass
qos car outbound carl 2 cir 22000 cbs 687500 ebs 0 green pass red discard yellow pass
nat outbound
#
interface Dialer1
ppp chap password cipher $c$3$VQnUDdgsbGNwLV8uCnpggZdsoVV3mL+ee4xU
ppp chap user 075506641544@163.gd
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user 075506641544@163.gd password cipher $c$3$Pw3FaTN1Sav9HZZti03U5Zg5YkGHyIDzVlpB
mtu 1492
dialer bundle enable
dialer-group 2
dialer timer idle 0
dialer timer autodial 1
ip address ppp-negotiate
tcp mss 1280
ip last-hop hold
qos car inbound carl 1 cir 22000 cbs 687500 ebs 0 green pass red discard yellow pass
qos car outbound carl 2 cir 22000 cbs 687500 ebs 0 green pass red discard yellow pass
nat outbound
#
interface Dialer2
ppp chap password cipher $c$3$h2qp5GCDYMf6lhJhkpMwz2NZlKWmVHuBj0OY
ppp chap user 075501361873@163.gd
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user 075501361873@163.gd password cipher $c$3$/L2KBBJiYCDoo5/tHYysg5SxK0D5f+3A6Cex
mtu 1492
dialer bundle enable
dialer-group 3
dialer timer idle 0
dialer timer autodial 1
ip address ppp-negotiate
tcp mss 1280
ip last-hop hold
qos car inbound carl 1 cir 22000 cbs 687500 ebs 0 green pass red discard yellow pass
qos car outbound carl 2 cir 22000 cbs 687500 ebs 0 green pass red discard yellow pass
nat outbound
#
interface Dialer3
ppp chap password cipher $c$3$ZLDVg/nQ6b8fzU2RV7una29XzO7Hm5RrJw==
ppp chap user 000@163.gd
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user 000@163.gd password cipher $c$3$Ko4CsNpygMi7v7lQeM8Mn1Cu0GRsQAHfBg==
mtu 1492
dialer bundle enable
dialer-group 3
dialer timer idle 0
dialer timer autodial 1
ip address ppp-negotiate
tcp mss 1280
ip last-hop hold
nat outbound
#
interface NULL0
#
interface Vlan-interface1
description LAN-interface
ip address 192.168.0.1 255.255.255.0
tcp mss 1280
#
interface Vlan-interface2
description LAN-interface
ip address 192.168.2.1 255.255.255.0
tcp mss 1280
#
interface GigabitEthernet0/0/0
port link-mode route
description Multiple_Line1
combo enable copper
ip last-hop hold
pppoe-client dial-bundle-number 0
#
interface GigabitEthernet0/0/1
port link-mode route
description Multiple_Line2
combo enable copper
ip last-hop hold
pppoe-client dial-bundle-number 1
#
interface GigabitEthernet0/0/2
port link-mode route
description Multiple_Line3
ip last-hop hold
pppoe-client dial-bundle-number 2
#
interface GigabitEthernet0/0/3
port link-mode route
description Multiple_Line4
ip last-hop hold
pppoe-client dial-bundle-number 3
#
interface GigabitEthernet0/0/4
port link-mode route
description Multiple_Line5
ip address dhcp-alloc
tcp mss 1280
ip last-hop hold
nat outbound
#
interface GigabitEthernet0/0/5
port link-mode route
description Multiple_Line6
ip address dhcp-alloc
tcp mss 1280
ip last-hop hold
nat outbound
#
interface GigabitEthernet0/0/6
port link-mode bridge
#
interface GigabitEthernet0/0/7
port link-mode bridge
#
interface GigabitEthernet0/0/8
port link-mode bridge
#
interface GigabitEthernet0/0/9
port link-mode bridge
#
interface Ten-GigabitEthernet0/0/10
port link-mode route
description LAN-interface
ip address 192.168.8.1 255.255.254.0
tcp mss 1280
#
interface Ten-GigabitEthernet0/0/11
port link-mode route
arp max-learning-num 0
#
security-zone name Local
#
security-zone name Trust
#
security-zone name DMZ
#
security-zone name Untrust
#
security-zone name Management
#
scheduler logfile size 16
#
line class console
user-role network-admin
#
line class vty
user-role network-operator
#
line con 0
user-role network-admin
#
line vty 0 63
authentication-mode scheme
user-role network-operator
#
ip route-static 0.0.0.0 0 192.168.88.1
ip route-static 0.0.0.0 0 192.168.1.1
ip route-static 0.0.0.0 0 192.168.3.1
ip route-static 0.0.0.0 0 Dialer0
ip route-static 0.0.0.0 0 Dialer1
ip route-static 0.0.0.0 0 Dialer2
ip route-static 0.0.0.0 0 Dialer3
ip route-static 172.17.1.0 24 192.168.8.249
#
ntp-service unicast-server 114.118.7.163
ntp-service unicast-server 120.25.115.20
#
acl mac 4999
rule 5 deny source-mac 5cba-ef04-e16f ffff-ffff-ffff
rule 5 comment Լ ĵ
rule 10 permit
#
password-control enable
undo password-control aging enable
undo password-control history enable
password-control length 6
password-control login-attempt 3 exceed lock-time 10
password-control update-interval 0
password-control login idle-time 0
#
domain name system
#
domain default enable system
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role
#
role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
user-group system
#
local-user admin class manage
service-type telnet http https terminal
authorization-attribute user-role network-admin
#
connection-limit apply global policy 32
#
security-zone intra-zone default permit
#
ip http enable
ip https enable
webui log enable
#
cloud-management server domain cloudnet.h3c.com
#
return
(0)
用了笨辦法。。。。有更好的建議請大神們幫幫忙
(0)
暫無評論
親~登錄後才可以操作哦!
確定你的郵箱還未認證,請認證郵箱或綁定手機後進行當前操作
舉報
×
侵犯我的權益
×
侵犯了我企業的權益
×
抄襲了我的內容
×
原文鏈接或出處
誹謗我
×
對根叔社區有害的內容
×
不規範轉載
×
舉報說明
暫無評論