评分并提供意见反馈 :
华为采用机器翻译与人工审校相结合的方式将此文档翻译成不同语言,希望能帮助您更容易理解此文档的内容。 请注意:即使是最好的机器翻译,其准确度也不及专业翻译人员的水平。 华为对于翻译的准确性不承担任何责任,并建议您参考英文文档(已提供链接)。
配置PUPP示例
本节介绍PUPP配置示例,请结合配置思路理解PUPP配置过程。
操作步骤
- 配置高级ACL策略。
[~HUAWEI] acl number 3001
[*HUAWEI-acl-adv-3001] rule 1 permit ip source 10.11.11.1 0
[*HUAWEI-acl-adv-3001] rule 2 permit ip source 10.11.11.2 0
[*HUAWEI-acl-adv-3001] quit
[~HUAWEI] acl number 3002
[*HUAWEI-acl-adv-3002] rule 3 permit ip source 10.11.11.3 0
[*HUAWEI-acl-adv-3002] quit
- 配置流分类。
[*HUAWEI] traffic classifier tc1
[*HUAWEI-classifier-tc1] if-match acl 3001
[*HUAWEI-classifier-tc1] quit
[*HUAWEI] traffic classifier tc2
[*HUAWEI-classifier-tc2] if-match acl 3002
[*HUAWEI-classifier-tc2] quit
- 配置流行为。
[*HUAWEI] traffic behavior tb1
[*HUAWEI-behavior-tb1] permit
[*HUAWEI-behavior-tb1] match termination
[*HUAWEI-behavior-tb1] quit
[*HUAWEI] traffic behavior tb2
[*HUAWEI-behavior-tb2] permit
[*HUAWEI-behavior-tb2] match termination
[*HUAWEI-behavior-tb2] quit
- 配置流量策略。
[*HUAWEI] traffic policy p1
[*HUAWEI-trafficpolicy-p1] classifier tc1 behavior tb1
[*HUAWEI-trafficpolicy-p1] quit
[*HUAWEI] traffic policy p2
[*HUAWEI-trafficpolicy-p2] classifier tc2 behavior tb2
[*HUAWEI-trafficpolicy-p2] quit
- 配置BAS接口。
[~HUAWEI] interface GigabitEthernet 0/1/1
[~HUAWEI-GigabitEthernet0/1/1] bas
[~HUAWEI-GigabitEthernet0/1/1-bas] access-type layer3-leased-line user-name sr-test-eth password cipher root@123 default-domain authentication enterprise_sr
- 在BAS接口下应用流量策略。
[~HUAWEI] interface GigabitEthernet 0/1/1
[~HUAWEI-GigabitEthernet0/1/1] bas
[*HUAWEI-GigabitEthernet0/1/1-bas] traffic-policy p1 inbound
[*HUAWEI-GigabitEthernet0/1/1-bas] traffic-policy p2 outbound
[*HUAWEI-GigabitEthernet0/1/1-bas] quit
- 验证配置结果。
执行命令display access traffic-policy statistics查看PUPP的流量策略统计信息。
<HUAWEI> display access traffic-policy statistics user-id 18496 inbound
-------------------------------------------------------------------------------- slot 1 -------------------------------------------------------------------------------- Policy name: p1 Classifier name: tc1 Acl 3001 rule 1 permit ip source 10.11.11.1 0 (00 packets, 00 bytes)
配置文件
# sysname HUAWEI # acl number 3001 rule 1 permit ip source 10.11.11.1 0 rule 2 permit ip source 10.11.11.2 0 # acl number 3002 rule 3 permit ip source 10.11.11.3 0 # traffic classifier tc1 if-match acl 3001 traffic classifier tc2 if-match acl 3002 # traffic behavior tb1 permit match termination traffic behavior tb2 permit match termination # traffic policy p1 classifier tc1 behavior tb1 # traffic policy p2 classifier tc2 behavior tb2 # interface GigabitEthernet0/1/1 bas access-type layer3-leased-line user-name sr-test-eth password cipher %@%##!!!!!!!!!"!!!!"!!!!(!!!!1];16qfZ81fv"uMoKKZ.1k"`AO!X2K2N.b~'NB^V!!!!!!!!!!1!!!!o/4J(q"J1F.!K9%M!6x8%@%# default-domain authentication enterprise_sr traffic-policy p1 inbound traffic-policy p2 outbound # return