No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

CloudEngine 12800, 12800E, 8800, 7800, 6800, and 5800 Series Switches M-LAG Best Practices

Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
Configuring M-LAG and VRRP Across Data Centers

Configuring M-LAG and VRRP Across Data Centers

Applicable Products and Versions

This example applies to the CE12800(except the CE12800E) of V100R006C00 or later, the CE8800/CE7800/CE6800/CE5800 of V200R002C50 or later.

Networking Requirements

Figure 4-6 shows the data center network across areas, and core, aggregation, and access switches are connected through 10GE interfaces. This example uses the CE12804.

Figure 4-6 Networking for configuring M-LAG and VRRP across data centers

Data preparation

Device Name

Interface Number

IP Address

Connected Device and Interface Number

SwitchA

10GE1/0/1

10.1.1.1/24

SwitchE: 10GE1/0/7

10GE1/0/2

10.1.2.1/24

SwitchF: 10GE1/0/8

10GE1/0/3

10.1.3.1/24

SwitchB: 10GE1/0/3

SwitchB

10GE1/0/1

10.1.4.1/24

SwitchF: 10GE1/0/7

10GE1/0/2

10.1.5.1/24

SwitchE: 10GE1/0/8

10GE1/0/3

10.1.3.2/24

SwitchA: 10GE1/0/3

SwitchC

10GE1/0/1

10.2.1.1/24

SwitchG: 10GE1/0/7

10GE1/0/2

10.2.2.1/24

SwitchH: 10GE1/0/8

10GE1/0/3

10.2.3.1/24

SwitchD: 10GE1/0/3

SwitchD

10GE1/0/1

10.2.4.1/24

SwitchH: 10GE1/0/7

10GE1/0/2

10.2.5.1/24

SwitchG: 10GE1/0/8

10GE1/0/3

10.2.3.2/24

SwitchC: 10GE1/0/3

SwitchE

Management interface

10.1.6.1/24

-

VLANIF11

10.1.7.1/24

Virtual IP address:

10.1.7.111

-

Eth-Trunk 5: 10GE1/0/1

-

SwitchM: Eth-Trunk 15

Eth-Trunk 0

  • 10GE1/0/3
  • 10GE2/0/3

-

SwitchF: Eth-Trunk 0

-

Eth-Trunk 10

  • 10GE1/0/5
  • 10GE1/0/6

-

SwitchI: 10GE1/0/5

-

SwitchJ: 10GE1/0/6

10GE1/0/7

10.1.1.2/24

SwitchA: 10GE1/0/1

10GE1/0/8

10.1.5.2/24

SwitchB: 10GE1/0/2

SwitchF

Management interface

10.1.6.2/24

-

VLANIF 11

10.1.7.1/24

Virtual IP address:

10.1.7.111

-

Eth-Trunk 5: 10GE1/0/1

-

SwitchM: Eth-Trunk 15

Eth-Trunk 0

  • 10GE1/0/3
  • 10GE2/0/3

-

SwitchE: Eth-Trunk 0

-

Eth-Trunk 10

  • 10GE1/0/5
  • 10GE1/0/6

-

SwitchJ: 10GE1/0/5

-

SwitchI: 10GE1/0/6

10GE1/0/7

10.1.4.2/24

SwitchB: 10GE1/0/1

10GE1/0/8

10.1.2.2/24

SwitchA: 10GE1/0/2

SwitchG

Management interface

10.2.6.1/24

-

VLANIF 11

10.1.7.3/24

Virtual IP address:

10.1.7.111

-

Eth-Trunk 5: 10GE1/0/1

-

SwitchN: Eth-Trunk 30

Eth-Trunk 0

  • 10GE1/0/3
  • 10GE2/0/3

-

SwitchH: Eth-Trunk 0

-

Eth-Trunk 10

  • 10GE1/0/5
  • 10GE1/0/6

-

SwitchK: 10GE1/0/5

-

SwitchL: 10GE1/0/6

10GE1/0/7

10.2.1.2/24

SwitchC: 10GE1/0/1

10GE1/0/8

10.2.5.2/24

SwitchD: 10GE1/0/2

SwitchH

Management interface

10.2.6.2/24

-

VLANIF11

10.1.7.3/24

Virtual IP address:

10.1.7.111

-

Eth-Trunk 5: 10GE1/0/1

-

SwitchN: Eth-Trunk 30

Eth-Trunk 0

  • 10GE1/0/3
  • 10GE2/0/3

-

SwitchG: Eth-Trunk 0

-

Eth-Trunk 10

  • 10GE1/0/5
  • 10GE1/0/6

-

SwitchL: 10GE1/0/5

-

SwitchK: 10GE1/0/6

10GE1/0/7

10.2.4.2/24

SwitchD: 10GE1/0/1

10GE1/0/8

10.2.2.2/24

SwitchC: 10GE1/0/2

SwitchI

Management interface

10.1.8.1/24

-

Eth-Trunk 40

  • 10GE1/0/2

-

SwitchK: 10GE1/0/2

Eth-Trunk 0

  • 10GE1/0/3
  • 10GE2/0/3

-

SwitchJ: Eth-Trunk 0

-

Eth-Trunk 35

  • 10GE1/0/5
  • 10GE1/0/6

-

SwitchE: 10GE1/0/5

-

SwitchF: 10GE1/0/6

SwitchJ

Management interface

10.1.8.2/24

-

Eth-Trunk 40

  • 10GE1/0/2

-

SwitchL: 10GE1/0/2

Eth-Trunk 0

  • 10GE1/0/3
  • 10GE2/0/3

-

SwitchI: Eth-Trunk 0

-

Eth-Trunk 35

  • 10GE1/0/5
  • 10GE1/0/6

-

SwitchF: 10GE1/0/5

-

SwitchE: 10GE1/0/6

SwitchK

Management interface

10.2.8.1/24

-

Eth-Trunk 50

  • 10GE1/0/2

-

SwitchI: 10GE1/0/2

Eth-Trunk 0

  • 10GE1/0/3
  • 10GE2/0/3

-

SwitchL: Eth-Trunk 0

-

Eth-Trunk 45

  • 10GE1/0/5
  • 10GE1/0/6

-

SwitchG: 10GE1/0/5

-

SwitchH: 10GE1/0/6

SwitchL

Management interface

10.2.8.2/24

-

Eth-Trunk 50

  • 10GE1/0/2

-

SwitchJ: 10GE1/0/2

Eth-Trunk 0

  • 10GE1/0/3
  • 10GE2/0/3

-

SwitchK: Eth-Trunk 0

-

Eth-Trunk 45

  • 10GE1/0/5
  • 10GE1/0/6

-

SwitchH: 10GE1/0/5

-

SwitchG: 10GE1/0/6

SwitchM

Eth-Trunk 15

  • 10GE1/0/1
  • 10GE1/0/2

-

SwitchE: 10GE1/0/1

SwitchF: 10GE1/0/1

10GE1/0/3

-

Server

SwitchN

Eth-Trunk 30

  • 10GE1/0/1
  • 10GE1/0/2

-

SwitchG: 10GE1/0/1

SwitchH: 10GE1/0/1

10GE1/0/3

-

Server

Requirement Analysis

To improve network reliability and serviceability, more and more users establish at least two data centers, and more data centers are deployed in different areas. The customer requires that the intra-city backup data center should ensure reliability. The aggregation and access layers use multi-level M-LAG interconnection to ensure reliability, improve the link usage, and extend the scale of dual-homing networking, meeting customer requirements. VRRP is deployed at the aggregation layer to provide dual-active gateways.

  • Devices at the core and aggregation layers establish cross connections to ensure device-level reliability and load balance traffic based on ECMP (preferential forwarding of local traffic is used with M-LAG at the aggregation layer).
  • The primary and backup data centers are connected through M-LAG and form a long-distance loop-free topology.

Figure 4-7 shows the logical networking after M-LAG and VRRP are deployed.

Figure 4-7 Networking for configuring M-LAG and VRRP across data centers

Configuration Roadmap

The configuration roadmap is as follows:

  1. Configure M-LAG between SwitchE and SwitchF and between SwitchG and SwitchH to implement dual-homing access at the access layer. Configure M-LAG between SwitchI and SwitchJ and between SwitchK and SwitchL to implement multi-level LAG interconnection between aggregation layers of primary and backup data centers. When aggregation switches work normally, links load balance traffic and a fault of any aggregation switch does not affect services. High service reliability is therefore ensured.
    • Configure SwitchE, SwitchF, SwitchG, and SwitchH as root bridges and enable root protection on downstream interfaces to ensure that the interfaces can forward traffic normally. Configure the edge interface and BPDU filter interface between the SwitchI and SwitchJ and between SwitchK and SwitchL so that STP calculation between primary and backup data centers is isolated. Configure interfaces on SwitchM and SwitchN connected to user terminals as edge interfaces to accelerate route convergence and enable BPDU protection to enhance network stability.
    • Create VLANIF interfaces on SwitchE, SwitchF, SwitchG, and SwitchH, assign IP addresses to VLANIF interfaces, and create VRRP groups on VLANIF interfaces to implement active-active gateways. There are dual master devices in the primary data center and two backup devices in the backup data center.
    NOTE:

    To enable two devices of the M-LAG to be simulated into one device to perform VRRP negotiation with the M-LAG of the remote data center, note the following points:

    • In a data center, configure the same interface IP address and virtual MAC address when creating VRRP groups. However, the primary and backup data centers must use different interface IP addresses and virtual MAC addresses.
    • The configured virtual MAC address must be different from the VRRP virtual MAC address, and the VRRP virtual MAC address depends on the VRID. For example, the VRID of the VRRP group composed of SwitchE and SwitchF is 1, so the MAC address of the VRRP group is 00-00-5E-00-01-01.
  2. Enable OSPF on aggregation and core switches to ensure Layer 3 connectivity.

Procedure

  1. Configure M-LAG.

    1. Configure V-STP, heartbeat links, DFS groups, peer-links, and M-LAG member interfaces on SwitchE, SwitchF, SwitchG, SwitchH, SwitchI, SwitchJ, SwitchK, and SwitchL.

      Heartbeat links are connected to management interfaces to implement interworking, DFS groups must be bound to IP addresses of management interfaces to ensure communication, and management interfaces are bound to VRF instances to implement isolation.

      It is recommended that Eth-Trunk member interfaces of the peer-link be deployed on different cards to prevent the peer-link fault caused by a single-point failure.

      # Configure SwitchE.

      Configure SwitchE as the root bridge of the STP network, and enable root protection on the Eth-Trunk of SwitchE connected to the access switch so that the Eth-Trunk can forward traffic normally.

      <HUAWEI> system-view 
      [~HUAWEI] sysname SwitchE 
      [*HUAWEI] commit 
      [~SwitchE] stp mode rstp 
      [*SwitchE] stp root primary     //Configure the aggregation device as the root bridge of the STP network. 
      [*SwitchE] stp bridge-address 200b-c739-1300     //Configure the MAC address of the root bridge (MAC address of the master device). 
      [*SwitchE] stp v-stp enable 
      [*SwitchE] stp flush disable 
      [*SwitchE] ip vpn-instance VRF-A     //Create VRF-A. 
      [*SwitchE-vpn-instance-VRF-A] ipv4-family 
      [*SwitchE-vpn-instance-VRF-A-af-ipv4] route-distinguisher 100:1 
      [*SwitchE-vpn-instance-VRF-A-af-ipv4] vpn-target 111:1 both 
      [*SwitchE-vpn-instance-VRF-A-af-ipv4] quit 
      [*SwitchE-vpn-instance-VRF-A] quit 
      [*SwitchE] interface meth 0/0/0 
      [*SwitchE-MEth0/0/0] ip binding vpn-instance VRF-A     //Bind the management interface to VRF-A. 
      [*SwitchE-MEth0/0/0] ip address 10.1.6.1 24 
      [*SwitchE-MEth0/0/0] quit 
      [*SwitchE] dfs-group 1 
      [*SwitchE-dfs-group-1] source ip 10.1.6.1 vpn-instance VRF-A     //Configure the IPv4 address and VPN instance bound to the DFS group. 
      [*SwitchE-dfs-group-1] priority 150 
      [*SwitchE-dfs-group-1] quit 
      [*SwitchE] interface eth-trunk 0 
      [*SwitchE-Eth-Trunk0] trunkport 10ge 1/0/3 
      [*SwitchE-Eth-Trunk0] trunkport 10ge 2/0/3     //Configure inter-card member interfaces of the Eth-Trunk of the peer-link. 
      [*SwitchE-Eth-Trunk0] mode lacp-static 
      [*SwitchE-Eth-Trunk0] peer-link 1 
      [*SwitchE-Eth-Trunk0] port vlan exclude 1 
      [*SwitchE-Eth-Trunk0] quit 
      [*SwitchE] vlan batch 11 
      [*SwitchE] interface eth-trunk 5 
      [*SwitchE-Eth-Trunk5] mode lacp-static 
      [*SwitchE-Eth-Trunk5] port link-type trunk 
      [*SwitchE-Eth-Trunk5] undo port trunk allow-pass vlan 1 
      [*SwitchE-Eth-Trunk5] port trunk allow-pass vlan 11 
      [*SwitchE-Eth-Trunk5] trunkport 10ge 1/0/1 
      [*SwitchE-Eth-Trunk5] dfs-group 1 m-lag 1 
      [*SwitchE-Eth-Trunk5] stp root-protection     //Enable root protection. 
      [*SwitchE-Eth-Trunk5] storm suppression broadcast cir 10 mbps     //Set the CIR of broadcast packets to 10 Mbit/s on this interface(The CE8800/CE7800/CE6800/CE5800 Series except CE6870EI and CE6875EI only support GE interface view, 10GE interface view, 25GE interface view, 40GE interface view, 100GE interface view and port group view). 
      [*SwitchE-Eth-Trunk5] quit 
      [*SwitchE] interface eth-trunk 10 
      [*SwitchE-Eth-Trunk10] mode lacp-static 
      [*SwitchE-Eth-Trunk10] port link-type trunk 
      [*SwitchE-Eth-Trunk10] undo port trunk allow-pass vlan 1 
      [*SwitchE-Eth-Trunk10] port trunk allow-pass vlan 11 
      [*SwitchE-Eth-Trunk10] trunkport 10ge 1/0/5 to 1/0/6 
      [*SwitchE-Eth-Trunk10] dfs-group 1 m-lag 2 
      [*SwitchE-Eth-Trunk10] stp root-protection     //Enable root protection. 
      [*SwitchE-Eth-Trunk10] storm suppression broadcast cir 10 mbps     //Set the CIR of broadcast packets to 10 Mbit/s on this interface(The CE8800/CE7800/CE6800/CE5800 Series except CE6870EI and CE6875EI only support GE interface view, 10GE interface view, 25GE interface view, 40GE interface view, 100GE interface view and port group view). 
      [*SwitchE-Eth-Trunk10] quit 
      [*SwitchE] lacp m-lag priority 10 
      [*SwitchE] lacp m-lag system-id 00e0-fc00-0000 
      [*SwitchE] interface 10ge 1/0/9 
      [*SwitchE-10GE1/0/9] shutdown     //Shut down the interface not in use. 10GE 1/0/9 is used as an example. 
      [*SwitchE-10GE1/0/9] quit 
      [*SwitchE] commit

      # Configure SwitchF.

      Configure SwitchF as the root bridge of the STP network, and enable root protection on the Eth-Trunk of SwitchF connected to the access switch so that the Eth-Trunk can forward traffic normally.

      <HUAWEI> system-view 
      [~HUAWEI] sysname SwitchF 
      [*HUAWEI] commit 
      [~SwitchF] stp mode rstp 
      [*SwitchF] stp root primary     //Configure the aggregation device as the root bridge of the STP network. 
      [*SwitchF] stp bridge-address 200b-c739-1300     /Configure the MAC address of the root bridge (MAC address of the master device). 
      [*SwitchF] stp v-stp enable 
      [*SwitchF] stp flush disable 
      [*SwitchF] ip vpn-instance VRF-A     //Create VRF-A. 
      [*SwitchF-vpn-instance-VRF-A] ipv4-family 
      [*SwitchF-vpn-instance-VRF-A-af-ipv4] route-distinguisher 100:2 
      [*SwitchF-vpn-instance-VRF-A-af-ipv4] vpn-target 111:1 both 
      [*SwitchF-vpn-instance-VRF-A-af-ipv4] quit 
      [*SwitchF-vpn-instance-VRF-A] quit 
      [*SwitchF] interface meth 0/0/0 
      [*SwitchF-MEth0/0/0] ip binding vpn-instance VRF-A   //Bind the management interface to VRF-A. 
      [*SwitchF-MEth0/0/0] ip address 10.1.6.2 24 
      [*SwitchF-MEth0/0/0] quit 
      [*SwitchF] dfs-group 1 
      [*SwitchF-dfs-group-1] source ip 10.1.6.2 vpn-instance VRF-A     //Configure the IPv4 address and VPN instance bound to the DFS group. 
      [*SwitchF-dfs-group-1] priority 120 
      [*SwitchF-dfs-group-1] quit 
      [*SwitchF] interface eth-trunk 0 
      [*SwitchF-Eth-Trunk0] trunkport 10ge 1/0/3 
      [*SwitchF-Eth-Trunk0] trunkport 10ge 2/0/3 
      [*SwitchF-Eth-Trunk0] mode lacp-static 
      [*SwitchF-Eth-Trunk0] peer-link 1 
      [*SwitchF-Eth-Trunk0] port vlan exclude 1 
      [*SwitchF-Eth-Trunk0] quit 
      [*SwitchF] vlan batch 11 
      [*SwitchF] interface eth-trunk 5 
      [*SwitchF-Eth-Trunk5] mode lacp-static 
      [*SwitchF-Eth-Trunk5] port link-type trunk 
      [*SwitchF-Eth-Trunk5] undo port trunk allow-pass vlan 1 
      [*SwitchF-Eth-Trunk5] port trunk allow-pass vlan 11 
      [*SwitchF-Eth-Trunk5] trunkport 10ge 1/0/1 
      [*SwitchF-Eth-Trunk5] dfs-group 1 m-lag 1 
      [*SwitchF-Eth-Trunk5] stp root-protection     //Enable root protection. 
      [*SwitchF-Eth-Trunk5] storm suppression broadcast cir 10 mbps     //Set the CIR of broadcast packets to 10 Mbit/s on this interface(The CE8800/CE7800/CE6800/CE5800 Series except CE6870EI and CE6875EI only support GE interface view, 10GE interface view, 25GE interface view, 40GE interface view, 100GE interface view and port group view). 
      [*SwitchF-Eth-Trunk5] quit 
      [*SwitchF] interface eth-trunk 10 
      [*SwitchF-Eth-Trunk10] mode lacp-static 
      [*SwitchF-Eth-Trunk10] port link-type trunk 
      [*SwitchF-Eth-Trunk10] undo port trunk allow-pass vlan 1 
      [*SwitchF-Eth-Trunk10] port trunk allow-pass vlan 11 
      [*SwitchF-Eth-Trunk10] trunkport 10ge 1/0/5 to 1/0/6 
      [*SwitchF-Eth-Trunk10] dfs-group 1 m-lag 2 
      [*SwitchF-Eth-Trunk10] stp root-protection     //Enable root protection. 
      [*SwitchF-Eth-Trunk10] storm suppression broadcast cir 10 mbps     //Set the CIR of broadcast packets to 10 Mbit/s on this interface(The CE8800/CE7800/CE6800/CE5800 Series except CE6870EI and CE6875EI only support GE interface view, 10GE interface view, 25GE interface view, 40GE interface view, 100GE interface view and port group view). 
      [*SwitchF-Eth-Trunk10] quit 
      [*SwitchF] lacp m-lag priority 10 
      [*SwitchF] lacp m-lag system-id 00e0-fc00-0000 
      [*SwitchF] interface 10ge 1/0/9 
      [*SwitchF-10GE1/0/9] shutdown     //Shut down the interface not in use. 10GE 1/0/9 is used as an example. 
      [*SwitchF-10GE1/0/9] quit 
      [*SwitchF] commit

      # The configurations of SwitchG and SwitchH are similar to the configurations of SwitchE and SwitchF, and the configuration details are not mentioned here.

      # Configure SwitchI.

      Configure the Eth-Trunk on SwitchI connected to the backup data center as the edge interface and BPDU filter interface so that STP calculation between primary and backup data centers is isolated.

      <HUAWEI> system-view 
      [~HUAWEI] sysname SwitchI 
      [*HUAWEI] commit 
      [~SwitchI] stp mode rstp 
      [*SwitchI] stp v-stp enable 
      [*SwitchI] stp flush disable 
      [*SwitchI] ip vpn-instance VRF-C     //Create VRF-C. 
      [*SwitchI-vpn-instance-VRF-C] ipv4-family 
      [*SwitchI-vpn-instance-VRF-C-af-ipv4] route-distinguisher 102:1 
      [*SwitchI-vpn-instance-VRF-C-af-ipv4] vpn-target 111:1 both 
      [*SwitchI-vpn-instance-VRF-C-af-ipv4] quit 
      [*SwitchI-vpn-instance-VRF-C] quit 
      [*SwitchI] interface meth 0/0/0 
      [*SwitchI-MEth0/0/0] ip binding vpn-instance VRF-C     //Bind the management interface to VRF-C. 
      [*SwitchI-MEth0/0/0] ip address 10.1.8.1 24 
      [*SwitchI-MEth0/0/0] quit 
      [*SwitchI] dfs-group 1 
      [*SwitchI-dfs-group-1] source ip 10.1.8.1 vpn-instance VRF-C     //Configure the IPv4 address and VPN instance bound to the DFS group. 
      [*SwitchI-dfs-group-1] priority 150 
      [*SwitchI-dfs-group-1] quit 
      [*SwitchI] interface eth-trunk 0 
      [*SwitchI-Eth-Trunk0] trunkport 10ge 1/0/3 
      [*SwitchI-Eth-Trunk0] trunkport 10ge 2/0/3 
      [*SwitchI-Eth-Trunk0] mode lacp-static 
      [*SwitchI-Eth-Trunk0] peer-link 1 
      [*SwitchI-Eth-Trunk0] port vlan exclude 1 
      [*SwitchI-Eth-Trunk0] quit 
      [*SwitchI] vlan batch 11 
      [*SwitchI] interface eth-trunk 35 
      [*SwitchI-Eth-Trunk35] mode lacp-static 
      [*SwitchI-Eth-Trunk35] port link-type trunk 
      [*SwitchI-Eth-Trunk35] undo port trunk allow-pass vlan 1 
      [*SwitchI-Eth-Trunk35] port trunk allow-pass vlan 11 
      [*SwitchI-Eth-Trunk35] trunkport 10ge 1/0/5 to 1/0/6 
      [*SwitchI-Eth-Trunk35] dfs-group 1 m-lag 1 
      [*SwitchI-Eth-Trunk35] storm suppression broadcast cir 10 mbps     //Set the CIR of broadcast packets to 10 Mbit/s on this interface(The CE8800/CE7800/CE6800/CE5800 Series except CE6870EI and CE6875EI only support GE interface view, 10GE interface view, 25GE interface view, 40GE interface view, 100GE interface view and port group view). 
      [*SwitchI-Eth-Trunk35] quit 
      [*SwitchI] interface eth-trunk 40 
      [*SwitchI-Eth-Trunk40] mode lacp-static 
      [*SwitchI-Eth-Trunk40] port link-type trunk 
      [*SwitchI-Eth-Trunk40] undo port trunk allow-pass vlan 1 
      [*SwitchI-Eth-Trunk40] port trunk allow-pass vlan 11 
      [*SwitchI-Eth-Trunk40] trunkport 10ge 1/0/2 
      [*SwitchI-Eth-Trunk40] dfs-group 1 m-lag 2 
      [*SwitchI-Eth-Trunk40] stp edged-port enable     //Configure the Eth-Trunk as the edge interface. 
      [*SwitchI-Eth-Trunk40] stp bpdu-filter enable     //Configure the Eth-Trunk as the BPDU filter interface. 
      [*SwitchI-Eth-Trunk40] storm suppression broadcast cir 10 mbps     //Set the CIR of broadcast packets to 10 Mbit/s on this interface(The CE8800/CE7800/CE6800/CE5800 Series except CE6870EI and CE6875EI only support GE interface view, 10GE interface view, 25GE interface view, 40GE interface view, 100GE interface view and port group view). 
      [*SwitchI-Eth-Trunk40] quit 
      [*SwitchI] lacp m-lag priority 10 
      [*SwitchI] lacp m-lag system-id 00e0-fc00-0002 
      [*SwitchI] interface 10ge 1/0/9 
      [*SwitchI-10GE1/0/9] shutdown     //Shut down the interface not in use. 10GE 1/0/9 is used as an example. 
      [*SwitchI-10GE1/0/9] quit 
      [*SwitchI] commit

      # Configure SwitchJ.

      Configure the Eth-Trunk on SwitchJ connected to the backup data center as the edge interface and BPDU filter interface so that STP calculation between primary and backup data centers is isolated.

      <HUAWEI> system-view 
      [~HUAWEI] sysname SwitchJ 
      [*HUAWEI] commit 
      [~SwitchJ] stp mode rstp 
      [*SwitchJ] stp v-stp enable 
      [*SwitchJ] stp flush disable 
      [*SwitchJ] ip vpn-instance VRF-C     //Create VRF-C. 
      [*SwitchJ-vpn-instance-VRF-C] ipv4-family 
      [*SwitchJ-vpn-instance-VRF-C-af-ipv4] route-distinguisher 102:2 
      [*SwitchJ-vpn-instance-VRF-C-af-ipv4] vpn-target 111:1 both 
      [*SwitchJ-vpn-instance-VRF-C-af-ipv4] quit 
      [*SwitchJ-vpn-instance-VRF-C] quit 
      [*SwitchJ] interface meth 0/0/0 
      [*SwitchJ-MEth0/0/0] ip binding vpn-instance VRF-C     //Bind the management interface to VRF-C. 
      [*SwitchJ-MEth0/0/0] ip address 10.1.8.2 24 
      [*SwitchJ-MEth0/0/0] quit 
      [*SwitchJ] dfs-group 1 
      [*SwitchJ-dfs-group-1] source ip 10.1.8.2 vpn-instance VRF-C     //Configure the IPv4 address and VPN instance bound to the DFS group. 
      [*SwitchJ-dfs-group-1] priority 120 
      [*SwitchJ-dfs-group-1] quit 
      [*SwitchJ] interface eth-trunk 0 
      [*SwitchJ-Eth-Trunk0] trunkport 10ge 1/0/3 
      [*SwitchJ-Eth-Trunk0] trunkport 10ge 2/0/3 
      [*SwitchJ-Eth-Trunk0] mode lacp-static 
      [*SwitchJ-Eth-Trunk0] peer-link 1 
      [*SwitchJ-Eth-Trunk0] port vlan exclude 1 
      [*SwitchJ-Eth-Trunk0] quit 
      [*SwitchJ] vlan batch 11 
      [*SwitchJ] interface eth-trunk 35 
      [*SwitchJ-Eth-Trunk35] mode lacp-static 
      [*SwitchJ-Eth-Trunk35] port link-type trunk 
      [*SwitchJ-Eth-Trunk35] undo port trunk allow-pass vlan 1 
      [*SwitchJ-Eth-Trunk35] port trunk allow-pass vlan 11 
      [*SwitchJ-Eth-Trunk35] trunkport 10ge 1/0/5 to 1/0/6 
      [*SwitchJ-Eth-Trunk35] dfs-group 1 m-lag 1 
      [*SwitchJ-Eth-Trunk35] storm suppression broadcast cir 10 mbps     //Set the CIR of broadcast packets to 10 Mbit/s on this interface(The CE8800/CE7800/CE6800/CE5800 Series except CE6870EI and CE6875EI only support GE interface view, 10GE interface view, 25GE interface view, 40GE interface view, 100GE interface view and port group view). 
      [*SwitchJ-Eth-Trunk35] quit 
      [*SwitchJ] interface eth-trunk 40 
      [*SwitchJ-Eth-Trunk40] mode lacp-static 
      [*SwitchJ-Eth-Trunk40] port link-type trunk 
      [*SwitchJ-Eth-Trunk40] undo port trunk allow-pass vlan 1 
      [*SwitchJ-Eth-Trunk40] port trunk allow-pass vlan 11 
      [*SwitchJ-Eth-Trunk40] trunkport 10ge 1/0/2 
      [*SwitchJ-Eth-Trunk40] dfs-group 1 m-lag 2 
      [*SwitchJ-Eth-Trunk40] stp edged-port enable     //Configure the Eth-Trunk as the edge interface. 
      [*SwitchJ-Eth-Trunk40] stp bpdu-filter enable     //Configure the Eth-Trunk as the BPDU filter interface. 
      [*SwitchJ-Eth-Trunk40] storm suppression broadcast cir 10 mbps     //Set the CIR of broadcast packets to 10 Mbit/s on this interface(The CE8800/CE7800/CE6800/CE5800 Series except CE6870EI and CE6875EI only support GE interface view, 10GE interface view, 25GE interface view, 40GE interface view, 100GE interface view and port group view). 
      [*SwitchJ-Eth-Trunk40] quit 
      [*SwitchJ] lacp m-lag priority 10 
      [*SwitchJ] lacp m-lag system-id 00e0-fc00-0002 
      [*SwitchJ] interface 10ge 1/0/9 
      [*SwitchJ-10GE1/0/9] shutdown     //Shut down the interface not in use. 10GE 1/0/9 is used as an example. 
      [*SwitchJ-10GE1/0/9] quit 
      [*SwitchJ] commit

      # The configuration of SwitchK and SwitchL is similar to the configuration of SwitchI and SwitchJ, and the configuration details are not mentioned here.

    2. Create VLANIF interfaces on SwitchE, SwitchF, SwitchG, and SwitchH and configure IP addresses for the VLANIF interfaces, and create a VRRP group as the user-side gateway on VLANIF 11. There are dual master devices in the primary data center and two backup devices in the backup data center.

      # Configure SwitchE.

      [~SwitchE] interface vlanif 11 
      [*SwitchE-Vlanif11] ip address 10.1.7.1 24 
      [*SwitchE-Vlanif11] mac-address 0000-5e00-0102 
      [*SwitchE-Vlanif11] vrrp vrid 1 virtual-ip 10.1.7.111 
      [*SwitchE-Vlanif11] vrrp vrid 1 priority 120 
      [*SwitchE-Vlanif11] quit 
      [*SwitchE] commit

      # Configure SwitchF.

      [~SwitchF] interface vlanif 11 
      [*SwitchF-Vlanif11] ip address 10.1.7.1 24 
      [*SwitchF-Vlanif11] mac-address 0000-5e00-0102 
      [*SwitchF-Vlanif11] vrrp vrid 1 virtual-ip 10.1.7.111 
      [*SwitchE-Vlanif11] vrrp vrid 1 priority 120 
      [*SwitchF-Vlanif11] quit 
      [*SwitchF] commit

      # Configure SwitchG.

      [~SwitchG] interface vlanif 11 
      [*SwitchG-Vlanif11] ip address 10.1.7.3 24 
      [*SwitchG-Vlanif11] mac-address 0000-5e00-0103 
      [*SwitchG-Vlanif11] vrrp vrid 1 virtual-ip 10.1.7.111 
      [*SwitchG-Vlanif11] quit 
      [*SwitchG] commit

      # Configure SwitchH.

      [~SwitchH] interface vlanif 11 
      [*SwitchH-Vlanif11] ip address 10.1.7.3 24 
      [*SwitchH-Vlanif11] mac-address 0000-5e00-0103 
      [*SwitchH-Vlanif11] vrrp vrid 1 virtual-ip 10.1.7.111 
      [*SwitchH-Vlanif11] quit 
      [*SwitchH] commit
    3. Add uplink interfaces on SwitchM and SwitchN to an Eth-Trunk and configure interfaces connected to servers as edge interfaces and BPDU filter interfaces. The interface connected to Server 1 is used as an example.

      # Configure SwitchM.

      <HUAWEI> system-view 
      [~HUAWEI] sysname SwitchM 
      [*HUAWEI] commit 
      [~SwitchM] stp mode rstp 
      [*SwitchM] vlan batch 11 
      [*SwitchM] interface eth-trunk 15 
      [*SwitchM-Eth-Trunk15] mode lacp-static 
      [*SwitchM-Eth-Trunk15] port link-type trunk 
      [*SwitchM-Eth-Trunk15] port trunk allow-pass vlan 11 
      [*SwitchM-Eth-Trunk15] trunkport 10ge 1/0/1 to 1/0/2 
      [*SwitchM-Eth-Trunk15] quit 
      [*SwitchM] interface 10ge 1/0/3 
      [*SwitchM-10GE1/0/3] port default vlan 11 
      [*SwitchM-10GE1/0/3] stp edged-port enable      //Configure the interface as the edge interface. 
      [*SwitchM-10GE1/0/3] quit 
      [*SwitchM] interface 10ge 1/0/9 
      [*SwitchM-10GE1/0/9] shutdown     //Shut down the interface not in use. 10GE 1/0/9 is used as an example. 
      [*SwitchM-10GE1/0/9] quit 
      [*SwitchM] stp bpdu-protection     //Enable BPDU protection. 
      [*SwitchM] commit

      # The configuration of SwitchN is similar to the configuration of SwitchM, and the configuration details are not mentioned here.

  2. Enable OSPF on SwitchA, SwitchB, SwitchC, SwitchD, SwitchE, SwitchF, SwitchG, and SwitchH.

    # Configure SwitchA.

    [~SwitchA] interface 10ge 1/0/1 
    [*SwitchA-10GE1/0/1] undo portswitch 
    [*SwitchA-10GE1/0/1] ip address 10.1.1.1 24 
    [*SwitchA-10GE1/0/1] ospf enable 1 area 0 
    [*SwitchA-10GE1/0/1] ospf network-type p2p     //Set the network type of the interface to P2P. 
    [*SwitchA-10GE1/0/1] quit 
    [*SwitchA] interface 10ge 1/0/2 
    [*SwitchA-10GE1/0/2] undo portswitch 
    [*SwitchA-10GE1/0/2] ip address 10.1.2.1 24 
    [*SwitchA-10GE1/0/2] ospf enable 1 area 0 
    [*SwitchA-10GE1/0/2] ospf network-type p2p     //Set the network type of the interface to P2P. 
    [*SwitchA-10GE1/0/2] quit 
    [*SwitchA] interface 10ge 1/0/3 
    [*SwitchA-10GE1/0/3] undo portswitch 
    [*SwitchA-10GE1/0/3] ip address 10.1.3.1 24 
    [*SwitchA-10GE1/0/3] ospf enable 1 area 0 
    [*SwitchA-10GE1/0/3] ospf network-type p2p     //Set the network type of the interface to P2P. 
    [*SwitchA-10GE1/0/3] quit 
    [*SwitchA] interface 10ge 1/0/9 
    [*SwitchA-10GE1/0/9] shutdown     //Shut down the interface not in use. 10GE 1/0/9 is used as an example. 
    [*SwitchA-10GE1/0/9] quit 
    [*SwitchA] ospf 1 
    [*SwitchA-ospf-1] area 0 
    [*SwitchA-ospf-1-area-0.0.0.0] quit 
    [*SwitchA-ospf-1] quit 
    [*SwitchA] commit

    # The configurations of SwitchB, SwitchC, and SwitchD are similar to the configuration of SwitchA, and the configuration details are not mentioned here.

    # Configure SwitchE.

    [~SwitchE] interface 10ge 1/0/7 
    [*SwitchE-10GE1/0/7] undo portswitch 
    [*SwitchE-10GE1/0/7] ip address 10.1.1.2 24 
    [*SwitchE-10GE1/0/7] ospf enable 1 area 0 
    [*SwitchE-10GE1/0/7] ospf network-type p2p     //Set the network type of the interface to P2P. 
    [*SwitchE-10GE1/0/7] quit 
    [*SwitchE] interface 10ge 1/0/8 
    [*SwitchE-10GE1/0/8] undo portswitch 
    [*SwitchE-10GE1/0/8] ip address 10.1.5.2 24 
    [*SwitchE-10GE1/0/8] ospf enable 1 area 0 
    [*SwitchE-10GE1/0/8] ospf network-type p2p     //Set the network type of the interface to P2P. 
    [*SwitchE-10GE1/0/8] quit 
    [*SwitchE] ospf 1 
    [*SwitchE-ospf-1] import-route direct      //Configure the switch to import direct routes. You can configure a routing policy to filter unnecessary routes. 
    [*SwitchE-ospf-1] area 0 
    [*SwitchE-ospf-1-area-0.0.0.0] quit 
    [*SwitchE-ospf-1] quit 
    [*SwitchE] commit

    # The configurations of SwitchF, SwitchG, and SwitchH are similar to the configuration of SwitchE, and the configuration details are not mentioned here.

  3. Verify the configuration.

    • Run the display dfs-group command to check M-LAG information.

      # Check information about the M-LAG with DFS group 1. (The M-LAG composed of SwitchE and SwitchF is used as an example. The M-LAG composed of SwitchG and SwitchH, the M-LAG composed of SwitchI and SwitchJ, and the M-LAG composed of SwitchK and SwitchL are similar.)

      [~SwitchE] display dfs-group 1 m-lag 
      *                : Local node                                                                                                        
      Heart beat state : OK                                                                                                                
      Node 1 *                                                                                                                             
        Dfs-Group ID : 1                                                                                                                 
        Priority       : 150                                                                                                               
        Address        : ip address 10.1.6.1                                                                                         
        State          : Master                                                                                                            
        Causation      : -                                                                                                                 
        System ID      : ac94-8400-df01                                                                                                    
        SysName        : SwitchE                                                                                                           
        Version        : V100R006C00                                                                                                        
        Device Type    : CE12800                                                                                                           
      Node 2                                                                                                                               
        Dfs-Group ID : 1                                                                                                                 
        Priority       : 120                                                                                                               
        Address        : ip address 10.1.6.2                                                                                         
        State          : Backup                                                                                                            
        Causation      : -                                                                                                                 
        System ID      : 0025-9e95-7c21                                                                                                    
        SysName        : switchF                                                                                                           
        Version        : V100R006C00                                                                                                        
        Device Type    : CE12800                                                     

      # Check M-LAG information on SwitchE.

      [~SwitchE] display dfs-group 1 node 1 m-lag brief 
      * - Local node 
       
      M-Lag ID     Interface      Port State    Status                                                                                      
             1     Eth-Trunk 5    Up            active(*)-active 
             2     Eth-Trunk 10 Up            active(*)-active  

      In the preceding information, the value of Heart beat state is OK, indicating that the heartbeat status is normal. SwitchE is used as Node 1, its priority is 150, and its status is Master. SwitchF is used as Node 2, its priority is 120, and its status is Backup. The value of Causation is -, the values of Port State of Node 1 and Node 2 are both Up, and the M-LAG status of both Node 1 and Node 2 is active, indicating that the MC-LAG configuration is correct.

    • Run the display vrrp command on SwitchE, SwitchF, SwitchG and SwitchH. You can see that SwitchE and SwitchF are in Master state and SwitchG and SwitchH are in Backup state.
      [~SwitchE] display vrrp verbose 
      Vlanif11 | Virtual Router 1                                                                                                          
      State          : Master                                                                                                              
      Virtual IP     : 10.1.7.111                                                                                                          
      Master IP      : 10.1.7.1                                                                                                            
      PriorityRun    : 120                                                                                                                 
      PriorityConfig : 120                                                                                                                 
      MasterPriority : 120                                                                                                                 
      Preempt        : YES Delay Time : 0s Remain : --                                                                                 
      Hold Multiplier: 3                                                                                                                   
      TimerRun       : 1s                                                                                                                  
      TimerConfig    : 1s                                                                                                                  
      Auth Type      : NONE                                                                                                                
      Virtual MAC    : 0000-5e00-0101                                                                                                      
      Check TTL      : YES                                                                                                                 
      Config Type    : Normal                                                                                                              
      Create Time       : 2016-03-14 14:26:29                                                                                              
      Last Change Time  : 2016-03-14 14:26:35                                                                                              
      [~SwitchF] display vrrp verbose 
      Vlanif11 | Virtual Router 1                                                                                                          
      State          : Master                                                                                                              
      Virtual IP     : 10.1.7.111                                                                                                          
      Master IP      : 10.1.7.1                                                                                                            
      PriorityRun    : 120                                                                                                                 
      PriorityConfig : 120                                                                                                                 
      MasterPriority : 120                                                                                                                 
      Preempt        : YES Delay Time : 0s Remain : --                                                                                 
      Hold Multiplier: 3                                                                                                                   
      TimerRun       : 1s                                                                                                                  
      TimerConfig    : 1s                                                                                                                  
      Auth Type      : NONE                                                                                                                
      Virtual MAC    : 0000-5e00-0101                                                                                                      
      Check TTL      : YES                                                                                                                 
      Config Type    : Normal                                                                                                              
      Create Time       : 2016-03-14 14:26:29                                                                                              
      Last Change Time  : 2016-03-14 14:26:35                                                                                              
      [~SwitchG] display vrrp verbose 
      Vlanif11 | Virtual Router 1 
      State          : Backup 
      Virtual IP     : 10.1.7.111 
      Master IP      : 10.1.7.3 
      PriorityRun  : 100 
      PriorityConfig : 100 
      MasterPriority : 120 
      Preempt        : YES Delay Time : 0s Remain : -- 
      Hold Multiplier: 3                                                                                                                   
      TimerRun       : 1s 
      TimerConfig    : 1s 
      Auth Type      : NONE 
      Virtual MAC    : 0000-5e00-0101 
      Check TTL      : YES 
      Config Type    : Normal 
      Create Time       : 2016-03-14 14:26:29                                                                                              
      Last Change Time  : 2016-03-14 14:26:35                                                                                             
      [~SwitchH] display vrrp verbose 
      Vlanif11 | Virtual Router 1 
      State          : Backup 
      Virtual IP     : 10.1.7.111 
      Master IP      : 10.1.7.3 
      PriorityRun    : 100 
      PriorityConfig : 100 
      MasterPriority : 120 
      Preempt        : YES Delay Time : 0s Remain : -- 
      Hold Multiplier: 3                                                                                                                   
      TimerRun       : 1s 
      TimerConfig    : 1s 
      Auth Type      : NONE 
      Virtual MAC    : 0000-5e00-0101 
      Check TTL      : YES 
      Config Type    : Normal 
      Create Time       : 2016-03-14 14:26:29                                                                                              
      Last Change Time  : 2016-03-14 14:26:35                                                                                             

Configuration Files

  • SwitchA configuration file
    # 
    sysname SwitchA 
    # 
    interface 10GE1/0/1 
     undo portswitch 
     ip address 10.1.1.1 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/2 
     undo portswitch 
     ip address 10.1.2.1 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/3 
     undo portswitch 
     ip address 10.1.3.1 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/9 
     shutdown 
    # 
    ospf 1 
     area 0.0.0.0 
    # 
    return
  • SwitchB configuration file
    # 
    sysname SwitchB 
    # 
    interface 10GE1/0/1 
     undo portswitch 
     ip address 10.1.4.1 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/2 
     undo portswitch 
     ip address 10.1.5.1 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/3 
     undo portswitch 
     ip address 10.1.3.2 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/9 
     shutdown 
    # 
    ospf 1 
     area 0.0.0.0 
    # 
    return
  • SwitchC configuration file
    # 
    sysname SwitchC 
    # 
    interface 10GE1/0/1 
     undo portswitch 
     ip address 10.2.1.1 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/2 
     undo portswitch 
     ip address 10.2.2.1 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/3 
     undo portswitch 
     ip address 10.2.3.1 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/9 
     shutdown 
    # 
    ospf 1 
     area 0.0.0.0 
    # 
    return
  • SwitchD configuration file
    # 
    sysname SwitchD 
    # 
    interface 10GE1/0/1 
     undo portswitch 
     ip address 10.2.4.1 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/2 
     undo portswitch 
     ip address 10.2.5.1 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/3 
     undo portswitch 
     ip address 10.2.3.2 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/9 
     shutdown 
    # 
    ospf 1 
     area 0.0.0.0 
    # 
    return
  • SwitchE configuration file
    # 
    sysname SwitchE 
    # 
    dfs-group 1 
     priority 150 
     source ip 10.1.6.1 vpn-instance VRF-A 
    # 
    vlan batch 11  
    # 
    stp bridge-address 200b-c739-1300  
    stp mode rstp 
    stp v-stp enable 
    stp instance 0 root primary 
    stp flush disable 
    # 
    lacp m-lag system-id 00e0-fc00-0000 
    lacp m-lag priority 10 
    # 
    ip vpn-instance VRF-A 
     ipv4-family 
      route-distinguisher 100:1 
      vpn-target 111:1 export-extcommunity 
      vpn-target 111:1 import-extcommunity 
    # 
    interface Vlanif11 
     ip address 10.1.7.1 255.255.255.0  
     vrrp vrid 1 virtual-ip 10.1.7.111  
     vrrp vrid 1 priority 120 
     mac-address 0000-5e00-0102  
    # 
    interface MEth0/0/0 
     ip binding vpn-instance VRF-A 
     ip address 10.1.6.1 255.255.255.0 
    # 
    interface Eth-Trunk0 
     mode lacp-static 
     peer-link 1 
     port vlan exclude 1 
    # 
    interface Eth-Trunk5 
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     stp root-protection 
     mode lacp-static 
     dfs-group 1 m-lag 1 
     storm suppression broadcast cir 100 mbps 
    # 
    interface Eth-Trunk10 
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     stp root-protection 
     mode lacp-static 
     dfs-group 1 m-lag 2 
     storm suppression broadcast cir 100 mbps 
    # 
    interface 10GE1/0/1 
     eth-trunk 5 
    # 
    interface 10GE1/0/3 
     eth-trunk 0 
    # 
    interface 10GE1/0/5 
     eth-trunk 10 
    # 
    interface 10GE1/0/6 
     eth-trunk 10 
    # 
    interface 10GE1/0/7 
     undo portswitch 
     ip address 10.1.1.2 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/8 
     undo portswitch 
     ip address 10.1.5.2 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/9 
     shutdown 
    # 
    interface 10GE2/0/3 
     eth-trunk 0 
    # 
    ospf 1 
     import-route direct 
     area 0.0.0.0 
    # 
    return
  • SwitchF configuration file
    # 
    sysname SwitchF 
    # 
    dfs-group 1 
     priority 120 
     source ip 10.1.6.2 vpn-instance VRF-A 
    # 
    vlan batch 11  
    # 
    stp bridge-address 200b-c739-1300  
    stp mode rstp 
    stp v-stp enable 
    stp instance 0 root primary 
    stp flush disable 
    # 
    lacp m-lag system-id 00e0-fc00-0000 
    lacp m-lag priority 10 
    # 
    ip vpn-instance VRF-A 
     ipv4-family 
      route-distinguisher 100:2 
      vpn-target 111:1 export-extcommunity 
      vpn-target 111:1 import-extcommunity 
    # 
    interface Vlanif11 
     ip address 10.1.7.1 255.255.255.0 
     vrrp vrid 1 virtual-ip 10.1.7.111 
     vrrp vrid 1 priority 120  
     mac-address 0000-5e00-0102  
    # 
    interface MEth0/0/0 
     ip binding vpn-instance VRF-A 
     ip address 10.1.6.2 255.255.255.0 
    # 
    interface Eth-Trunk0 
     mode lacp-static 
     peer-link 1 
     port vlan exclude 1 
    # 
    interface Eth-Trunk5 
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     stp root-protection 
     mode lacp-static 
     dfs-group 1 m-lag 1 
     storm suppression broadcast cir 100 mbps 
    # 
    interface Eth-Trunk10 
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     stp root-protection 
     mode lacp-static 
     dfs-group 1 m-lag 2 
     storm suppression broadcast cir 100 mbps 
    # 
    interface 10GE1/0/1 
     eth-trunk 5 
    # 
    interface 10GE1/0/3 
     eth-trunk 0 
    # 
    interface 10GE1/0/5 
     eth-trunk 10 
    # 
    interface 10GE1/0/6 
     eth-trunk 10 
    # 
    interface 10GE1/0/7 
     undo portswitch 
     ip address 10.1.4.2 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/8 
     undo portswitch 
     ip address 10.1.2.2 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/9 
     shutdown 
    # 
    interface 10GE2/0/3 
     eth-trunk 0 
    # 
    ospf 1 
     import-route direct 
     area 0.0.0.0 
    # 
    return     
  • SwitchG configuration file
    # 
    sysname SwitchG 
    # 
    dfs-group 1 
     priority 150 
     source ip 10.2.6.1 vpn-instance VRF-B 
    # 
    vlan batch 11  
    # 
    stp bridge-address 200b-c739-1300  
    stp mode rstp 
    stp v-stp enable 
    stp instance 0 root primary 
    stp flush disable 
    # 
    lacp m-lag system-id 00e0-fc00-0001 
    lacp m-lag priority 10 
    # 
    ip vpn-instance VRF-B 
     ipv4-family 
      route-distinguisher 101:1 
      vpn-target 111:1 export-extcommunity 
      vpn-target 111:1 import-extcommunity 
    # 
    interface Vlanif11 
     ip address 10.1.7.3 255.255.255.0 
     vrrp vrid 1 virtual-ip 10.1.7.111  
     mac-address 0000-5e00-0103  
    # 
    interface MEth0/0/0 
     ip binding vpn-instance VRF-B 
     ip address 10.2.6.1 255.255.255.0 
    # 
    interface Eth-Trunk0 
     mode lacp-static 
     peer-link 1 
     port vlan exclude 1 
    # 
    interface Eth-Trunk5 
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     stp root-protection 
     mode lacp-static 
     dfs-group 1 m-lag 1 
     storm suppression broadcast cir 100 mbps 
    # 
    interface Eth-Trunk10 
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     stp root-protection 
     mode lacp-static 
     dfs-group 1 m-lag 2 
     storm suppression broadcast cir 100 mbps 
    # 
    interface 10GE1/0/1 
     eth-trunk 5 
    # 
    interface 10GE1/0/3 
     eth-trunk 0 
    # 
    interface 10GE1/0/5 
     eth-trunk 10 
    # 
    interface 10GE1/0/6 
     eth-trunk 10 
    # 
    interface 10GE1/0/7 
     undo portswitch 
     ip address 10.2.1.2 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/8 
     undo portswitch 
     ip address 10.2.5.2 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/9 
     shutdown 
    # 
    interface 10GE2/0/3 
     eth-trunk 0 
    # 
    ospf 1 
     import-route direct 
     area 0.0.0.0 
    # 
    return
  • SwitchH configuration file
    # 
    sysname SwitchH 
    # 
    dfs-group 1 
     priority 120 
     source ip 10.2.6.2 vpn-instance VRF-B 
    # 
    vlan batch 11  
    # 
    stp bridge-address 200b-c739-1300  
    stp mode rstp 
    stp v-stp enable 
    stp instance 0 root primary 
    stp flush disable 
    # 
    lacp m-lag system-id 00e0-fc00-0001 
    lacp m-lag priority 10 
    # 
    ip vpn-instance VRF-B 
     ipv4-family 
      route-distinguisher 101:2 
      vpn-target 111:1 export-extcommunity 
      vpn-target 111:1 import-extcommunity 
    # 
    interface Vlanif11 
     ip address 10.1.7.3 255.255.255.0 
     vrrp vrid 1 virtual-ip 10.1.7.111 
     mac-address 0000-5e00-0103  
    # 
    interface MEth0/0/0 
     ip binding vpn-instance VRF-B 
     ip address 10.2.6.2 255.255.255.0 
    # 
    interface Eth-Trunk0 
     mode lacp-static 
     peer-link 1 
     port vlan exclude 1 
    # 
    interface Eth-Trunk5 
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     stp root-protection 
     mode lacp-static 
     dfs-group 1 m-lag 1 
     storm suppression broadcast cir 100 mbps 
    # 
    interface Eth-Trunk10 
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     stp root-protection 
     mode lacp-static 
     dfs-group 1 m-lag 2 
     storm suppression broadcast cir 100 mbps 
    # 
    interface 10GE1/0/1 
     eth-trunk 5 
    # 
    interface 10GE1/0/3 
     eth-trunk 0 
    # 
    interface 10GE1/0/5 
     eth-trunk 10 
    # 
    interface 10GE1/0/6 
     eth-trunk 10 
    # 
    interface 10GE1/0/7 
     undo portswitch 
     ip address 10.2.4.2 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/8 
     undo portswitch 
     ip address 10.2.2.2 255.255.255.0 
     ospf network-type p2p 
     ospf enable 1 area 0.0.0.0 
    # 
    interface 10GE1/0/9 
     shutdown 
    # 
    interface 10GE2/0/3 
     eth-trunk 0 
    # 
    ospf 1 
     import-route direct 
     area 0.0.0.0 
    # 
    return
  • SwitchI configuration file
    # 
    sysname SwitchI 
    # 
    dfs-group 1 
     priority 150 
     source ip 10.1.8.1 vpn-instance VRF-C 
    # 
    vlan batch 11  
    # 
    stp mode rstp 
    stp v-stp enable 
    stp flush disable 
    # 
    lacp m-lag system-id 00e0-fc00-0002 
    lacp m-lag priority 10 
    # 
    ip vpn-instance VRF-C 
     ipv4-family 
      route-distinguisher 102:1 
      vpn-target 111:1 export-extcommunity 
      vpn-target 111:1 import-extcommunity 
    # 
    interface MEth0/0/0 
     ip binding vpn-instance VRF-C 
     ip address 10.1.8.1 255.255.255.0 
    # 
    interface Eth-Trunk0 
     mode lacp-static 
     peer-link 1 
     port vlan exclude 1 
    # 
    interface Eth-Trunk35 
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     mode lacp-static 
     dfs-group 1 m-lag 1 
     storm suppression broadcast cir 100 mbps 
    # 
    interface Eth-Trunk40 
     stp edged-port enable 
     stp bpdu-filter enable      
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     stp root-protection 
     mode lacp-static 
     dfs-group 1 m-lag 2 
     storm suppression broadcast cir 100 mbps 
    # 
    interface 10GE1/0/2 
     eth-trunk 40 
    # 
    interface 10GE1/0/3 
     eth-trunk 0 
    # 
    interface 10GE1/0/5 
     eth-trunk 35 
    # 
    interface 10GE1/0/6 
     eth-trunk 35 
    # 
    interface 10GE1/0/9 
     shutdown 
    # 
    interface 10GE2/0/3 
     eth-trunk 0 
    # 
    return
  • SwitchJ configuration file
    # 
    sysname SwitchJ 
    # 
    dfs-group 1 
     priority 120 
     source ip 10.1.8.2 vpn-instance VRF-C 
    # 
    vlan batch 11  
    # 
    stp mode rstp 
    stp v-stp enable 
    stp flush disable 
    # 
    lacp m-lag system-id 00e0-fc00-0002 
    lacp m-lag priority 10 
    # 
    ip vpn-instance VRF-C 
     ipv4-family 
      route-distinguisher 102:2 
      vpn-target 111:1 export-extcommunity 
      vpn-target 111:1 import-extcommunity 
    # 
    interface MEth0/0/0 
     ip binding vpn-instance VRF-C 
     ip address 10.1.8.2 255.255.255.0 
    # 
    interface Eth-Trunk0 
     mode lacp-static 
     peer-link 1 
     port vlan exclude 1 
    # 
    interface Eth-Trunk35 
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     mode lacp-static 
     dfs-group 1 m-lag 1 
     storm suppression broadcast cir 100 mbps 
    # 
    interface Eth-Trunk40 
     stp edged-port enable 
     stp bpdu-filter enable      
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     stp root-protection 
     mode lacp-static 
     dfs-group 1 m-lag 2 
     storm suppression broadcast cir 100 mbps 
    # 
    interface 10GE1/0/2 
     eth-trunk 40 
    # 
    interface 10GE1/0/3 
     eth-trunk 0 
    # 
    interface 10GE1/0/5 
     eth-trunk 35 
    # 
    interface 10GE1/0/6 
     eth-trunk 35 
    # 
    interface 10GE1/0/9 
     shutdown 
    # 
    interface 10GE2/0/3 
     eth-trunk 0 
    # 
    return     
  • SwitchK configuration file
    # 
    sysname SwitchK 
    # 
    dfs-group 1 
     priority 150 
     source ip 10.2.8.1 vpn-instance VRF-D 
    # 
    vlan batch 11  
    # 
    stp mode rstp 
    stp v-stp enable 
    stp flush disable 
    # 
    lacp m-lag system-id 00e0-fc00-0003 
    lacp m-lag priority 10 
    # 
    ip vpn-instance VRF-D 
     ipv4-family 
      route-distinguisher 103:1 
      vpn-target 111:1 export-extcommunity 
      vpn-target 111:1 import-extcommunity 
    # 
    interface MEth0/0/0 
     ip binding vpn-instance VRF-D 
     ip address 10.2.8.1 255.255.255.0 
    # 
    interface Eth-Trunk0 
     mode lacp-static 
     peer-link 1 
     port vlan exclude 1 
    # 
    interface Eth-Trunk45 
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     mode lacp-static 
     dfs-group 1 m-lag 1 
     storm suppression broadcast cir 100 mbps 
    # 
    interface Eth-Trunk50 
     stp edged-port enable 
     stp bpdu-filter enable      
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     stp root-protection 
     mode lacp-static 
     dfs-group 1 m-lag 2 
     storm suppression broadcast cir 100 mbps 
    # 
    interface 10GE1/0/2 
     eth-trunk 50 
    # 
    interface 10GE1/0/3 
     eth-trunk 0 
    # 
    interface 10GE1/0/5 
     eth-trunk 45 
    # 
    interface 10GE1/0/6 
     eth-trunk 45 
    # 
    interface 10GE1/0/9 
     shutdown 
    # 
    interface 10GE2/0/3 
     eth-trunk 0 
    # 
    return     
  • SwitchL configuration file
    # 
    sysname SwitchK 
    # 
    dfs-group 1 
     priority 120 
     source ip 10.2.8.2 vpn-instance VRF-D 
    # 
    vlan batch 11  
    # 
    stp mode rstp 
    stp v-stp enable 
    stp flush disable 
    # 
    lacp m-lag system-id 00e0-fc00-0003 
    lacp m-lag priority 10 
    # 
    ip vpn-instance VRF-D 
     ipv4-family 
      route-distinguisher 103:2 
      vpn-target 111:1 export-extcommunity 
      vpn-target 111:1 import-extcommunity 
    # 
    interface MEth0/0/0 
     ip binding vpn-instance VRF-D 
     ip address 10.2.8.2 255.255.255.0 
    # 
    interface Eth-Trunk0 
     mode lacp-static 
     peer-link 1 
     port vlan exclude 1 
    # 
    interface Eth-Trunk45 
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     mode lacp-static 
     dfs-group 1 m-lag 1 
     storm suppression broadcast cir 100 mbps 
    # 
    interface Eth-Trunk50 
     stp edged-port enable 
     stp bpdu-filter enable      
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     stp root-protection 
     mode lacp-static 
     dfs-group 1 m-lag 2 
     storm suppression broadcast cir 100 mbps 
    # 
    interface 10GE1/0/2 
     eth-trunk 50 
    # 
    interface 10GE1/0/3 
     eth-trunk 0 
    # 
    interface 10GE1/0/5 
     eth-trunk 45 
    # 
    interface 10GE1/0/6 
     eth-trunk 45 
    # 
    interface 10GE1/0/9 
     shutdown 
    # 
    interface 10GE2/0/3 
     eth-trunk 0 
    # 
    return
  • SwitchM configuration file
    # 
    sysname SwitchM 
    # 
    vlan batch 11 
    # 
    stp mode rstp 
    stp bpdu-protection      
    # 
    interface Eth-Trunk15 
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     mode lacp-static 
     storm suppression broadcast cir 100 mbps 
    # 
    interface 10GE1/0/1 
     eth-trunk 15 
    # 
    interface 10GE1/0/2 
     eth-trunk 15 
    # 
    interface 10GE1/0/3 
     port default vlan 11 
     stp edged-port enable       
    # 
    interface 10GE1/0/9 
     shutdown 
    # 
    return
  • SwitchN configuration file
    # 
    sysname SwitchN 
    # 
    vlan batch 11 
    # 
    stp mode rstp 
    stp bpdu-protection      
    # 
    interface Eth-Trunk30 
     port link-type trunk 
     undo port trunk allow-pass vlan 1 
     port trunk allow-pass vlan 11 
     mode lacp-static 
     storm suppression broadcast cir 100 mbps 
    # 
    interface 10GE1/0/1 
     eth-trunk 15 
    # 
    interface 10GE1/0/2 
     eth-trunk 15 
    # 
    interface 10GE1/0/3 
     port default vlan 11 
     stp edged-port enable       
    # 
    interface 10GE1/0/9 
     shutdown 
    # 
    return
Translation
Download
Updated: 2018-07-02

Document ID: EDOC1000137639

Views: 38197

Downloads: 1506

Average rating:
This Document Applies to these Products
Related Version
Related Documents
Share
Previous Next