交换机组播配置案例.docx
- 文档编号:4818937
- 上传时间:2022-12-09
- 格式:DOCX
- 页数:27
- 大小:80.23KB
交换机组播配置案例.docx
《交换机组播配置案例.docx》由会员分享,可在线阅读,更多相关《交换机组播配置案例.docx(27页珍藏版)》请在冰豆网上搜索。
交换机组播配置案例
交换机组播配置案例
网络拓扑:
主楼实现方式:
S6806与S2126G通过TRUNK端口直接相连,我们先看一下6806与S2125G-F5S1的配置(蓝色字部分)。
在以下的配置中会发现,在6806除了正常启PIM同时还增加了一条ipmulticastvlan17interfaceGi3/7 命令
用它来指定接口的多播vlanid号,为什么要指定这个vlanid号?
是因为TRUNK端口在转发数据帧时,它会把tagvlanid号标记为端口所属vlan的id(NATIVEVLAN除外)。
如下面配置,组播源在vlan100中的,正常TRUNK端口在转发组播流时,数据帧默认tagvlanid是100.如果这样的话,当S2126G收到tagvlanid100的数据帧,它会检查交换机中是否存在vlan100,如果有向其vlan转发,如果没有数据帧被丢弃。
所以要把多播vlanid号指定21交换机存在并且有用户使用的VLAN.这样在S2126G交换机上指定IGMP SNOOPING SVGLVLAN17,就可以接收到组播流。
只要保证68指定的接口多播vlanid与21交换机指定MulticastVLAN相同即可。
教学楼实现方式:
S6806与S4909通过VLAN28相连,S4909与21-s5通过TRUNK方式连接。
我们先看一下S6806和S4909和2126G的配置(红色字部分)。
在以下的配置中会发现,在6806除了正常启PIM,S4909没有启用PIM(没有启用PIM的原因是:
6806与4909正常配置PIM时,4909上时常无法建立多播路由),S2126G-s5上启用的是IGMPSNOOPING。
虽然4909上没有启用组播配置,但它可以把多播流以广播方式转发。
在下面红色字标记中,从68-49-21上都有创建一个vlan28 ,在6806上通过PIM把多播流正常转发到4909上。
4909发现是多播地址,它会把组播流转发给每个TRUNK端口,并且tagvlanid都标记为28。
这样2126G交换机增加一个vlan28,把vlan28设置为MulticastVLAN就可以了。
以这种方式实现方式,在4909上没有用户,只做一个汇聚。
如果有用户尽量设置在vlan28内。
6806配置
S6806#shru
Buildingconfiguration...
Currentconfiguration:
7848bytes
!
version1.0
install312sfp/gt
install424t4sfp4gt
iproutingalgorithmCRC32_UPPER
!
hostnameS6806
enablesecretlevel15p7Qpw'~1^UYy7+.tY^vu/,|7UXxw&-/-
enablesecretlevel155,U38dfim32_{bckn562zyglo0Y:
aeh`@
!
ipaccess-listextended101
denytcpanyanyeq135
denytcpanyanyeq136
denytcpanyanyeq137
denytcpanyanyeq138
denytcpanyanyeq139
denytcpanyanyeq389
denytcpanyanyeq445
denytcpanyanyeq4444
denytcpanyanyeq5554
denytcpanyanyeq9995
denytcpanyanyeq9996
denyudpanyanyeqtftp
denyudpanyanyeq135
denyudpanyanyeq136
denyudpanyanyeqnetbios-ns
denyudpanyanyeqnetbios-dgm
denyudpanyanyeqnetbios-ss
denyudpanyanyeq1900
denyudpanyanyeq445
denyudpanyanyeq1433
denyudpanyanyeq593
denyudpanyanyeq1434
denyudpanyanyeq4444
denyudpanyanyeq5554
denyudpanyanyeq9995
denyudpanyanyeq9996
denyigmpanyany
permitipanyany
!
ipaccess-listextendedacl6806
permitipany10.0.200.00.0.0.255
permitip10.0.3.00.0.0.255any
permitip10.0.4.00.0.0.255any
permitip10.0.5.00.0.0.255any
permitip10.0.6.00.0.0.255any
permitip10.0.7.00.0.0.255any
permitip10.0.8.00.0.0.255any
permitip10.0.9.00.0.0.255any
permitip10.0.0.1920.0.255.63any
permitiphost172.16.1.254any
permitip192.168.100.00.0.0.255any
permitipany192.168.100.00.0.0.255
permitip10.0.0.2530.0.255.0any
permitipany10.0.0.2530.0.255.0
permitipany10.0.3.00.0.0.255
denyipany10.0.10.00.0.0.255
denyipany10.0.11.00.0.0.255
denyipany10.0.12.00.0.0.255
denyipany10.0.13.00.0.0.255
denyipany10.0.14.00.0.0.255
denyipany10.0.15.00.0.0.255
denyipany10.0.16.00.0.0.255
denyipany10.0.17.00.0.0.255
denyipany10.0.18.00.0.0.255
denyipany10.0.19.00.0.0.255
denytcpanyanyeq135
denytcpanyanyeq445
denyipanyany
!
ipaccess-liststandardigmp-group
permithost226.8.9.10
permithost224.5.5.6
denyany
!
ipaccess-listextendedrule
permitipany10.0.200.00.0.0.255
permitip10.0.3.00.0.0.255any
permitip10.0.4.00.0.0.255any
permitip10.0.5.00.0.0.255any
permitip10.0.6.00.0.0.255any
permitip10.0.7.00.0.0.255any
permitip10.0.8.00.0.0.255any
permitip10.0.9.00.0.0.255any
permitip10.0.0.1920.0.255.63any
permitiphost172.16.1.254any
permitip192.168.100.00.0.0.255any
permitipany192.168.100.00.0.0.255
permitip10.0.2.00.0.0.255any
permitip192.168.1.00.0.0.255any
permitipany10.0.0.2530.0.255.0
permitipany10.0.3.00.0.0.255
denyipanyany
!
interfaceGigabitEthernet3/1
medium-typefiber
switchportaccessvlan28
ipaccess-grouprulein
!
interfaceGigabitEthernet3/2
switchportaccessvlan28
!
interfaceGigabitEthernet3/3
switchportaccessvlan28
!
interfaceGigabitEthernet3/5
medium-typefiber
switchportmodetrunk
ipaccess-groupacl6806in
!
interfaceGigabitEthernet3/6
medium-typefiber
switchportmodetrunk
ipaccess-groupacl6806in
!
interfaceGigabitEthernet3/7
medium-typefiber
switchportmodetrunk
ipaccess-groupacl6806in
!
interfaceGigabitEthernet3/8
medium-typefiber
switchportmodetrunk
ipaccess-groupacl6806in
!
interfaceGigabitEthernet3/9
switchportaccessvlan100
!
interfaceGigabitEthernet3/10
switchportaccessvlan100
!
interfaceGigabitEthernet3/11
switchportaccessvlan100
!
interfaceGigabitEthernet3/12
noswitchport
ipaddress192.168.3.1255.255.255.252
!
interfaceFastEthernet4/1
switchportaccessvlan200
!
interfaceFastEthernet4/2
switchportaccessvlan200
!
interfaceFastEthernet4/3
switchportaccessvlan200
!
interfaceFastEthernet4/4
switchportaccessvlan200
!
interfaceFastEthernet4/5
switchportaccessvlan200
!
interfaceFastEthernet4/6
switchportaccessvlan200
!
interfaceFastEthernet4/7
switchportaccessvlan200
!
interfaceFastEthernet4/8
switchportaccessvlan200
!
interfaceFastEthernet4/9
switchportaccessvlan200
!
interfaceFastEthernet4/10
switchportaccessvlan200
!
interfaceFastEthernet4/24
switchportaccessvlan200
!
interfaceGigabitEthernet4/25
switchportaccessvlan200
!
interfaceGigabitEthernet4/27
switchportaccessvlan100
!
interfaceGigabitEthernet4/28
switchportaccessvlan60
!
interfaceGigabitEthernet4/29
switchportmodetrunk
ipaccess-groupacl6806in
!
interfaceGigabitEthernet4/30
switchportmodetrunk
ipaccess-groupacl6806in
!
interfaceGigabitEthernet4/31
switchportmodetrunk
ipaccess-groupacl6806in
!
interfaceGigabitEthernet4/32
switchportmodetrunk
ipaccess-groupacl6806in
!
interfaceVlan1
ipaddress10.0.0.100255.255.255.0
ippim
!
interfaceVlan5
ipaddress10.0.5.254255.255.255.0
ippim
!
interfaceVlan6
ipaddress10.0.6.254255.255.255.0
ippim
!
interfaceVlan7
ipaddress10.0.7.254255.255.255.0
ippim
!
interfaceVlan8
ipaddress10.0.8.254255.255.255.0
ippim
!
interfaceVlan9
ipaddress10.0.9.254255.255.255.0
ippim
!
interfaceVlan10
ipaddress10.0.10.254255.255.255.0
ippim
!
interfaceVlan11
ipaddress10.0.11.254255.255.255.0
ippim
!
interfaceVlan12
ipaddress10.0.12.254255.255.255.0
ippim
!
interfaceVlan13
ipaddress10.0.13.254255.255.255.0
ippim
!
interfaceVlan14
ipaddress10.0.14.254255.255.255.0
ippim
!
interfaceVlan15
ipaddress10.0.15.254255.255.255.0
ippim
!
interfaceVlan16
ipaddress10.0.16.254255.255.255.0
ippim
!
interfaceVlan17
ipaddress10.0.17.254255.255.255.0
ippim
!
interfaceVlan18
ipaddress10.0.18.254255.255.255.0
ippim
!
interfaceVlan19
ipaddress10.0.19.254255.255.255.0
ippim
!
interfaceVlan28
ipaddress10.0.28.160255.255.255.0
ippim
!
interfaceVlan40
ipaddress10.0.4.254255.255.255.0
ippim
!
interfaceVlan60
ipaddress10.0.3.254255.255.255.0
ippim
!
interfaceVlan100
ipaddress10.0.200.254255.255.255.0
ippim
!
interfaceVlan200
ipaddress192.168.100.254255.255.255.0
ippim
!
interfaceVlan888
ipaddress172.16.1.254255.255.255.0
ippim
!
iproute0.0.0.00.0.0.0GigabitEthernet3/12192.168.3.21enabled
iproute10.0.0.0255.255.255.0Vlan2810.0.28.2541enabled
iproute10.0.2.0255.255.255.0Vlan2810.0.28.2541enabled
iproute10.0.20.0255.255.255.0Vlan2810.0.28.2541enabled
iproute10.0.21.0255.255.255.0Vlan2810.0.28.2541enabled
iproute10.0.22.0255.255.255.0Vlan2810.0.28.2541enabled
iproute10.0.23.0255.255.255.0Vlan2810.0.28.2541enabled
iproute10.0.24.0255.255.255.0Vlan2810.0.28.2541enabled
iproute10.0.25.0255.255.255.0Vlan2810.0.28.2541enabled
iproute10.0.26.0255.255.255.0Vlan2810.0.28.2541enabled
iproute10.0.27.0255.255.255.0Vlan2810.0.28.2541enabled
iproute10.0.28.0255.255.255.0Vlan2810.0.28.2541enabled
iproute172.16.1.0255.255.255.0Vlan888172.16.1.2531enabled
iproute218.62.34.0255.255.255.0GigabitEthernet3/12192.168.3.21enabled
ipmulticast-routing
ipmulticastvlan100interfaceGi3/1
ipmulticastvlan7interfaceGi3/5
ipmulticastvlan17interfaceGi3/7
ipmulticastvlan9interfaceGi3/8
ipmulticastvlan18interfaceGi4/29
ipmulticastvlan8interfaceGi4/30
ipmulticastvlan10interfaceGi4/31
snmp-servercommunitypublicro
end
F5S1配置:
F5S1#shru
Buildingconfiguration...
Currentconfiguration:
3498bytes
!
version1.0
!
hostnameF5S1
vlan1
!
vlan5
!
vlan15
!
vlan17
!
vlan40
!
vlan50
!
vlan100
!
vlan200
!
vlan888
!
ipaccess-listextendedacl5
denytcpanyanyeq69
denytcpanyanyeq135
denytcpanyanyeq136
denytcpanyanyeq137
denytcpanyanyeq138
denytcpanyanyeq139
denyudpanyanyeq135
denyudpanyanyeq136
denyudpanyanyeqnetbios-ss
denyudpanyanyeqnetbios-dgm
denytcpanyanyeq445
denyudpanyanyeq445
denytcpanyanyeq593
denyudpanyanyeq593
denyudpanyanyeq1334
denytcpanyanyeq4444
permitipanyany
!
radius-serverhost10.0.200.1
aaaauthenticationdot1x
aaaaccountingserver10.0.200.1
aaaaccounting
enablesecretlevel15*U3\W&-/32_sv'~1562T7+.t0Y[V/,|7
enablesecretlevel155+U38U0 >H0Yuu_;C, ! ipigmpprofile1 deny ! interfacefastEthernet0/1 switchportprotected switchportaccessvlan17 dot1xport-controlauto ipaccess-groupacl5in ! interfacefastEthernet0/2 switchportprotected switchportaccessvlan17 dot1x
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- 交换 机组 配置 案例