Juniper Network EX User Manual

Juniper EX 系列以太网交换机
操作手册
Version 1.0
Copyright © 2008 Juniper Networks, Inc.
Juniper EX 系列以太网交换机操作手册
目 录
1 章. 产品简介 ............................................................................................................................4
1.1. 产品系列....................................................................................................................................4
1.2. EX3200 系列 .............................................................................................................................5
1.3. EX4200 系列 .............................................................................................................................7
1.4. 软件特性....................................................................................................................................9
2 章. CLI 及维护......................................................................................................................12
2.1. 通过 CONSOLE 线缆连接 JUNIPER 设备 ...............................................................................12
2.2. 设备启动..................................................................................................................................13
2.3. 设备重启..................................................................................................................................13
2.4. JUNOS 升级 ............................................................................................................................14
2.5. 密码恢复..................................................................................................................................14
2.6. CLI 操作模式 ..........................................................................................................................15
2.6.1.
2.6.2.
操作模式 配置模式
........................................................................................................................16
........................................................................................................................20
3 章. 接口操作 ..........................................................................................................................26
3.1. 配置物理端口参数 .................................................................................................................26
3.2. 配置物理端口二层接口.........................................................................................................27
3.3. 配置物理端口三层接口.........................................................................................................27
4 章. VLAN 操作......................................................................................................................28
4.1. 配置 VLAN..............................................................................................................................28
4.2. 配置 RVI 接口.........................................................................................................................29
4.3. 配置 VLAN TRUNK ...................................................................................................................29
4.4. GVRP 配置..............................................................................................................................31
5 章. STP/RSTP/MSTP...........................................................................................................32
5.1. STP 配置..................................................................................................................................32
5.2. RSTP.........................................................................................................................................32
5.3. MSTP........................................................................................................................................33
6 章. 链路聚合配置..................................................................................................................36
6.1. 二层 LAG 的配置例子:.......................................................................................................36
6.2. 三层 LAG 的配置例子...........................................................................................................37
7 章. 三层协议配置..................................................................................................................38
7.1. 静态路由协议..........................................................................................................................38
- 2 -
Juniper EX 系列以太网交换机操作手册
7.2. RIP 配置...................................................................................................................................38
7.3. OPEN SHORTEST PATH FIRST (OSPF)......................................................................................39
7.3.1.
7.3.2.
7.3.3.
7.3.4.
7.3.5.
7.3.6.
单区域 配置 配置 配置 配置 配置验证
............................................................................................................................40
OSPF
多区域
.....................................................................................................40
a Stub Area..........................................................................................................40
a Not-So-Stubby Area.........................................................................................41
OSPF Router Interfaces......................................................................................41
........................................................................................................................42
8 章. VIRTUAL CHASSIS 操作 ...........................................................................................43
8.1. VCP 端口.................................................................................................................................44
8.2. MASTER 交换机选择机制 ......................................................................................................44
8.3. 带外网管端口及 CONSOLE 端口:........................................................................................45
8.4. 链路连接方式..........................................................................................................................46
8.5. 升级操作..................................................................................................................................47
8.6. 配置操作..................................................................................................................................47
8.7. 配置例子..................................................................................................................................48
9 章. 802.1X 配置 .....................................................................................................................51
9.1. 配置 RADIUS 服务器: ...........................................................................................................51
9.2. 配置接口模式。 .....................................................................................................................51
9.3. 查看状态:..............................................................................................................................52
10 章. PACKET FILTERING..............................................................................................53
10.1. 配置命令: ......................................................................................................................54
10.2. 配置接口限速: ..............................................................................................................55
11 章. COS...............................................................................................................................56
12 章. POE...............................................................................................................................62
13 章. 端口镜像.......................................................................................................................64
14 章. 配置命令索引 ..............................................................................................................65
- 3 -
Juniper EX 系列以太网交换机操作手册
第1章. 产品简介
1.1. 产品系列
如图所示,Juniper 交换机产品划分为 3 个系统,分别为: 1、固定配置(Fixed config)EX 3200 系列; 2、集群交换(virtual chassis)EX 4200 系列; 3、模块化交换机 EX 8200 系列。 EX 3200/EX 4200 目前已经上市销售,EX8200 系列产品EX 8208(8 槽位)
预计 2008 年第四季度出厂销售,EX 8216(16个业槽位)预计 2009 年第一季度出厂
主要参数:
技术指标 EX3200 EX4200 24P/24T 48P/48T 24F 24P/24T 48P/48T
交换容量 88Gbps 136Gbps 88Gbps 88Gbps 136Gbps 包转发率 65Mpps 101Mpps 65Mpps 65Mpps 101Mpps
GE 端口密度 24+4SFP 48+4SFP 24SFP+4SFP 24+4SFP 48+4SFP 10GE 端口密度 2 2 20(10*2) 20(10*2) 20(10*2) MAC 地址表 24K 24K ACL 支持数量 7K 7K IPV4 单播路由 12K 12K IPV4 组播路由 2K 2K POE 支持 YES NO YES
- 4 -
Juniper EX 系列以太网交换机操作手册
虚拟机箱技术 NO YES 最大堆叠数量 1 10
1.2. EX3200 系列
瞻博EX 3200系列以太网交换机是固定配置的高性能独立交换机,适用于
办事处远程办事处和园区络中的接入层部署
EX 3200系列以太网交换机提供第2层和第3层交换功能可满足高绩效企业的配线
连接要求。交换机支持4种平台配置模式,为部分或全部24个和48
10/100/1000BASE-T端口提供以太供电(PoE)2448端口EX 3200系列交换机的基本型支持第3PoE,在前8个端口上提供15.4瓦的电力,用于在融合网络中,支持电话、
摄像和无线局域网(WLAN)点等基于 IP的产品。EX 3200系列交换机还提供 在全部24或48个端口上都提供15.4瓦电力PoE选项,适用于高密度IP电话和其它的融络环境
EX 3200系列以太网交换机还支持可选的4端口千兆以太网(GbE)2端口万兆以太
上行链路模块,通过可插拔接口速连接汇聚层交换机或其它上产品。
换的风扇托架够最大地缩短EX 3200系列交换机的均修 (MTTR)确保最大可用性。如部署选的外冗余EX 3200系列交换机 源将支持插拔
EX 3200系列交换机的集路由引擎RE)还瞻博路由器使相同的模块化 JUNOS 软件,确保每制层特性瞻博络基上一致地实施
EX 3200系列交换机中都包括基于特定的集(ASIC)的集成据包转 发引擎EX-PFE,并通过集路由引擎(RE)提供全部制层功能EX-PFERE都基
公认的Juniper技术,EX 3200系列交换机提供高级别的运营商级性能和可 性,Juniper路由器对待球最大的信运营商网络一样。
订购信息
机型编号 说明 交换机
- 5 -
Juniper EX 系列以太网交换机操作手册
机型编号 说明
EX 3200-24T EX 3200-24P EX 3200-48T EX 3200-48P
高级特性许可
EX-24-AFL* EX-48-AFL*
上行链路模块
EX-UM-2XFP EX-UM-4SFP
电源**
EX-PWR-320-AC EX-PWR-600-AC EX-PWR-930-AC
可插拔的光接口
24 端口 10/100/1000BASE-T (8 PoE 端口)+320W AC PSU 24 端口 10/100/1000BASE-T PoE+600W AC PSU 48 端口 10/100/1000BASE-T (8 PoE 端口)+320W AC PSU 48 端口 10/100/1000BASE-T PoE+930W AC PSU
面向 EX 3200-24T EX 3200-24P 交换机的级特性 面向 EX 3200-48T EX 3200-48P 交换机的级特性
2 端口万兆以太 XFP 上行链路模块 4 端口千兆以太 SFP 上行链路模块
320W AC (PSU) 600W AC (PSU) 930W AC (PSU)
EX-SFP-1GE-SX EX-SFP-1GE-LX EX-SFP-1GE-LH
EX-SFP-1GE-T EX-SFP-1FE-FX
EX-XFP-10GE-S R
EX-XFP-10GE-L R EX-XFP-10GE-E R EX-XFP-10GE-Z R
SFP 1000BASE-SX850nm支持 550m 光纤传输距离 SFP1000BASE-LX1310nm支持 10km 光纤传输距离 SFP 1000BASE-LH,1550nm支持 70km 光纤传输距离
SFP 10/100/1000BASE-T 收发器模块,支持 100m UTP 传输距 ***
SFP 100BASE-FX1310nm支持 2km 光纤传输距离****
XFP, 10GBASE-SR, 850nm, 支持 300m 光纤传输距离;33m
光纤传输距离
XFP 10GBASE-LR; 1310nm; 支持 10km 光纤传输距离
XFP 10GBASE-ER; 1550nm; 支持 40km 光纤传输距离
XFP 10GBASE-ZR; 1550nm; 支持 80km 光纤传输距离
- 6 -
Juniper EX 系列以太网交换机操作手册
1.3. EX4200 系列
虚拟箱技术瞻博络 EX 4200系列以太网交换机模块化系统的高可用 (HA)运营商堆叠平台灵活合在一,为数 区和支办事处环境提供高扩展解决
EX 4200 系列交换机通过软件提供全第 2 和第 3 层交换功能可满足
类高要求包括支办事处园区和入部署千兆以太 (GbE)汇聚部署开始可部署一24 端口或 48 端口交换机,然后随需求增长 部署瞻博虚拟箱技术技术通过128 千兆(Gbps)背板最多将
10 EX 4200 系列交换机在一并将作为产品行管理,从而扩展络环境提供“按需购买、渐进扩展”的解决灵活千兆以太网(GbE)和万兆以
(10GbE)上行链路选件您高速连接将多层或幢楼宇互连在一汇聚层交换机。
EX 4200 系列交换机都提供高可用性特性,如 冗余热插拔部电和现场换的带风扇风扇托架用于确保最运行时间外,EX 4200 系列交换
机的基本型还支持第 3 类以太网供电(PoE)标准,在前 8 个端口上提供 15.4 瓦的电力
支持 IP 电话摄像和无线局域WLAN)入点等 IP 的产品,用于构建低融合。产品还提供在24 或 48 个端口上都提供 15.4 瓦电力PoE 选项, 适用于高IP 电话部署
EX 4200 系列交换机中都包括基于特定的集成(ASIC)的集据包转 发引擎 EX-PFE,并通过集成路由引擎(RE)提供全部制层功能基于公认瞻博 技术,路由引擎EX 4200 系列交换机提供高级别的运营商级性能和可性,像瞻博路由器为全球最大电信运营商提供一样
EX 4200 系列交换机还与瞻博路由器使相同的模块化 JUNOSTM软件, 保每制层特性瞻博络基础施上一致地实施和运行
订购信息:
机型编号 说明 交换机
- 7 -
50cm
EX-XFP
-
10GE
-
S
Juniper EX 系列以太网交换机操作手册
机型编号 说明
EX 4200-24T
EX 4200-24P
EX 4200-48T
EX 4200-48P
EX 4200-24F
24 端口 10/100/1000Base-T (8 PoE 端口) + 320 W AC PSU包括 50cm 虚拟端口缆。 24 端口 10/100/1000Base-T PoE + 600W AC PSU包括 50cm 虚拟 端口缆。 48 端口 10/100/1000Base-T (8 PoE 端口) + 320 W AC PSU包括 50cm 虚拟端口缆。 48 端口 10/100/1000Base-T PoE + 930 W AC PSU包括 50cm 虚拟 端口缆。 24 端口 1000Base-X SFP + 320 W AC PSU (模块选配),包括 虚拟端口缆。
高级特性许可
EX-24-AFL* 面向 EX 4200-24T, EX 4200-24P, EX 4200-24F 交换机的级特性 EX-48-AFL*
面向 EX 4200-48T EX 4200-48P 交换机的级特性
上行链路模块
EX-UM-2XFP EX-UM-4SFP
2 端口万兆以太XFP 上行链路模块 4 端口千兆以太 SFP 上行链路模块
电源**
EX-PWR-320-AC EX-PWR-600-AC EX-PWR-930-AC
320W AC (PSU) 600W AC (PSU) 930W AC (PSU)
虚拟机箱端口电缆
EX-CBL-VCP-50 CM EX-CBL-VCP-1 M EX-CBL-VCP-3 M
EX 4200, 50cm 虚拟端口缆(备件) EX 4200, 1m 虚拟端口 EX 4200, 3m 虚拟端口
可插拔的光接口
EX-SFP-1GE-SX EX-SFP-1GE-LX EX-SFP-1GE-LH
EX-SFP-1GE-T
SFP 1000Base-SX; 850nm; 支持 550m 光纤传输距离 SFP 1000Base-LX; 1310nm; 支持 10km 光纤传输距离 SFP 1000Base-LH; 1550nm; 支持 70km 光纤传输距离
SFP 10/100/1000Base-T 收发器模块; 支持 100m UTP 传输
距离***
EX-SFP-1FE-FX SFP 100Base-FX; 1310nm; 支持 2km 光纤传输距离****
XFP 10GBase-SR; 850nm;支持 300m 光纤传输距离; 33m
- 8 -
service (DoS) and distributed DoS(DDoS)
Juniper EX 系列以太网交换机操作手册
机型编号 说明
R EX-XFP-10GE-L
R EX-XFP-10GE-E R EX-XFP-10GE-Z R
光纤传输距离 XFP 10GBase-LR; 1310nm; 支持 10km 光纤传输距离
XFP 10GBase-ER; 1550nm; 支持 40km 光纤传输距离 XFP 10GBase-ZR; 1550nm; 支持 80km 光纤传输距离
1.4. 软件特性
特性类型 EX 的特性 版本实现 网络协议
Routed VLAN interfaces (RVIs) JUNOS 9.0R2 GVRP (GARP VLAN Registration Protocol) JUNOS 9.1R1
Spanning Tree Protocol (STP) JUNOS 9.0R2
Rapid Spanning Tree Protocol (RSTP)
Multiple Spanning Tree Protocol (MSTP)
BPDU protection for spanning-tree protocols JUNOS 9.1R1 Loop protection for spanning-tree protocols JUNOS 9.1R1 Root protection for spanning-tree protocols JUNOS 9.1R1 Storm control JUNOS 9.1R1 Link Layer Discovery Protocol (LLDP) JUNOS 9.0R2 Link Layer Discovery Protocol Media Endpoint Discovery (LLDP-MED) with voice over IP (VoIP) integration JUNOS 9.0R2
网络安全
Port security: JUNOS 9.0R2
DHCP snooping
Dynamic ARP Inspection (DAI)
MAC limiting
MAC move limiting
Static ARP support
802.1X authentication JUNOS 9.0R2 Denial-of­protection JUNOS 9.0R2 Rate limiting and firewall filters JUNOS 9.0R2
IP 协议 IPv4 JUNOS 9.0R2 IP 地址管理
Static addresses JUNOS 9.0R2 Dynamic Host Configuration Protocol(DHCP) JUNOS 9.0R2
路由及组播 Bidirectional Forwarding Detection JUNOS 9.0R2
- 9 -
Border Gateway Protocol (BGP),A separate software
Routing Information Protocol version 1 (RIPv1) and
Graceful Routing Engine switchover (GRES) for EX
through the console,
Juniper EX 系列以太网交换机操作手册
license is required for BGP. JUNOS 9.0R2 Distance Vector Multicast Routing Protocol (DVMRP) JUNOS 9.0R2 Intermediate System-to-Intermediate System (IS-IS),A separate software license is required for ISIS. JUNOS 9.0R2 Internet Group Management Protocol (IGMP) JUNOS 9.0R2 IGMP snooping JUNOS 9.1R1 Open Shortest Path First (OSPF) JUNOS 9.0R2 Protocol Independent Multicast (PIM) sparse mode JUNOS 9.0R2
RIPv2 JUNOS 9.0R2 Single-source multicast JUNOS 9.0R2 Static routes JUNOS 9.0R2
封装
Ethernet: JUNOS 9.0R2
Media access control (MAC) encapsulation
802.1p tagging Encapsulation
802.1Q filtering and forwarding JUNOS 9.0R2
管理
Policing and shaping JUNOS 9.0R2 Transparent bridging JUNOS 9.0R2 Class-based queuing with prioritization JUNOS 9.0R2
高可性及扩展
Virtual Router Redundancy Protocol (VRRP) JUNOS 9.0R2 Graceful protocol restart for OSPF and BGP JUNOS 9.0R2 Redundant interfaces JUNOS 9.0R2
4200 virtual chassis configurations JUNOS 9.1R1 Redundant trunk groups JUNOS 9.0R2 Link aggregation JUNOS 9.0R2
统管理
J-Web interfaceFor switch configuration and management JUNOS 9.0R2 JUNOS command-line interface (CLI)For switch configuration and management Telnet, SSH, or J-Web CLI terminal JUNOS 9.0R2 Simple Network Management Protocol version 1 (SNMPv1) and SNMPv2 JUNOS 9.0R2 J-Web licensing JUNOS 9.1R1
日志监控
System log (syslog) JUNOS 9.0R2 J-Web event viewer JUNOS 9.0R2 Traceroute JUNOS 9.0R2
管理 Support for RADIUS external administrator
databases
JUNOS 9.0R2
- 10 -
Juniper EX 系列以太网交换机操作手册
Autoinstallation JUNOS 9.0R2 Configuration rollback JUNOS 9.0R2 Confirmation of configuration changes JUNOS 9.0R2 Software upgrades JUNOS 9.0R2 Supports the following features for automating network operations and troubleshooting: JUNOS 9.0R2
Commit scripts
Operation scripts
Event policies
- 11 -
Juniper EX 系列以太网交换机操作手册
2章. CLI 及维护
JUNOS 软件是专门互联网设第一种路由交换操作系统。行在 Juniper 的所T-系列、M-系列和 J-系列路由器和 EX 系列路由交换机上,而且目前 部署在全球最大增长速的网络中Junos 使用 FreeBSD 内核,模块化的设JUNOS 软件提供的全具有工度的路由协议、灵活策略语言,可以高效
扩展以支持量的网接口路由。 基于标准JUNOS 软件可以支持互联网路
由协议,同时控制路由器、交换机及接口并实现对规模的网的系统管理。
便易用的面使可以配置路由协议接口性、控路由、检测排除协议 连接故障
描述 JUNOS 一些操作,这些操作会影响设备的正常功能,操作 请谨慎使
n 通过 Console 线缆连接路由器
n 设备重启
n 设备启动
n JUNOS 升级
n 密码恢复
n CLI 操作模式
2.1. 通过 Console 线Juniper 设备
使步骤连接路由器的 Console 接口:
1. Juniper设备带的 Console 线缆没有请准个 DB9-RJ45
和一条 RJ45-RJ45 线
2. Console 线缆的 DB9 PC 者笔记本电COM
到 Juniper 设备的 CONSOLE 。。
3. 端软件工具。例如:CRT Windows 带的端。设
置如
n 端口:选择中 Console 线缆插入到 PC 的端口,通COM 1
- 12 -
Juniper EX 系列以太网交换机操作手册
COM 2
n 9600 n 8 n 停止1 n
4. 开配置CRT 超级端,按“Enter键,屏幕登陆
连接。如没有显示,请检查线缆端的配置
任何现场解决的问题Juniper TAC 的帮助
2.2. 设备启动
电启动 Juniper 设备。系统第一启动建议通过 Console 端口登陆
启动,看看 login 提示入用户名为 root,缺省密码入系统
入 cli 命令入 Junos command line interface可以设备调试。如例:
login: root
Password:
Terminal type? [vt100] y
root%cli
root>
2.3. 设备重启
Juniper 设备重启必须步骤进操作:
1. console 设备连接Juniper 设备的 CONSOLE 端口
2. 使具有限的户名密码登陆 CLI 命令
3. 在提的命令:
user@host> request system reboot
4. console 设备的确认 Juniper 设备软件已启动。
- 13 -
Juniper EX 系列以太网交换机操作手册
2.4. JUNOS
Juniper 设备 JUNOS 软件升级必须步骤进操作:
1. console 设备连接到 Juniper 设备的 CONSOLE 端口
2. 载新JUNOS 软件,FTP 服务器
3. 的 JUNOS 软件复制Juniper 设备使的命令:
4. user@host> file copy
ftp://username:password@ftp.hostname.net/filename /var/tmp/filename
5. 升级前,的命令备份旧的软件及设定:
user@host> request system snapshot
6. 安装新JUNOS 软件:
user@host> request system software add source reboot
其中 source 参数为通过上一步骤系统件,
如:/var/tmp/jinstall-ex-9.1R1.8-domestic-signed.tgz
2.5. 码恢复
Juniper 设备的 Root 密码丢失而且没有其户权限,那么密码恢复,操作需要中Juniper 设备的正常功能
密码恢复,请按操作进行
1. 启动 Juniper 设备。
2. 启动过程中console 上出示的任意键正常启动方式,
然后状态:
Hit [Enter] to boot immediately, or any other key for command prompt. Booting [kernel] in 9 seconds... < Press any key other than return > ok boot –s
3. 密码恢复:在以文字recovery
Enter full pathname of shell or 'recovery' for root password recovery or RETURN for /bin/sh: recovery
NOTE: Once in the CLI, you will need to enter configuration mode using
- 14 -
Juniper EX 系列以太网交换机操作手册
NOTE: the 'configure' command to make any required changes. For example, NOTE: to reset the root password, type: NOTE: configure NOTE: set system root-authentication plain-text-password NOTE: (enter the new password when asked) NOTE: commit NOTE: exit NOTE: exit NOTE: When you exit the CLI, you will be asked if you want to reboot NOTE: the system
Starting CLI ... root>
4. 配置模式,除 root 密码:
root> configure Entering configuration mode
[edit] root# set system root-authentication plain-text-password
遍新的口令。 root@router# commit commit complete
[edit] root@router# exit
Exiting configuration mode
root@kenny> exit
Reboot the system? [y/n] y
Terminated
启动 Juniper设备恢复正常。
2.6. CLI 操作模
JUNOS 有两模式:操作模式配置模式。
1,操作模式
软件,网连接、路由器件。
2,配置模式
- 15 -
Juniper EX 系列以太网交换机操作手册
test@lab2>
配置路由器包括interface、路由、路由协议、访问、系统件参数。
test@lab2> configure
[edit]
test@lab2#
2.6.1. 操作模式
1命令层
2)主要命令
{master}
lab@ex4200-vc> ?
Possible completions:
clear Clear information in the system
configure Manipulate software configuration information
file Perform file operations
help Provide help information
monitor Show real-time debugging information
mtrace Trace multicast path from source to receiver
op Invoke an operation script
ping Ping remote target
- 16 -
Juniper EX 系列以太网交换机操作手册
quit Exit the management session
request Make system-level requests
restart Restart software process
set Set CLI properties, date/time, craft interface message
show Show system information
ssh Start secure shell on another host
start Start shell
telnet Telnet to another host
test Perform diagnostic debugging
traceroute Trace route to remote host
{master}
lab@ex4200-vc>
3)可以使列管道符号 |
compare Compare configuration changes with prior version
count Count occurrences
display Show additional kinds of information
except Show only text that does not match a pattern
find Search for first occurrence of pattern
hold Hold text without exiting the --More-- prompt
last Display end of output only
match Show only text that matches a pattern
no-more Don't paginate output
request Make system-level requests
resolve Resolve IP addresses
save Save output text to file
trim Trim specified number of columns from start of line
4使set cli 命令设置 cli 环境
{master}
lab@ex4200-vc> set cli ?
Possible completions:
- 17 -
Juniper EX 系列以太网交换机操作手册
complete-on-space Set whether typing space completes current word
directory Set working directory
idle-timeout Set maximum idle time before login session ends
prompt Set CLI command prompt string
restart-on-upgrade Set whether CLI prompts to restart after software upgrade
screen-length Set number of lines on screen
screen-width Set number of characters on a line
terminal Set terminal type
timestamp Timestamp CLI output
{master}
5编辑环境在VT-100
6)空格键功能
lab@ex4200-vc> show i
^
- 18 -
Juniper EX 系列以太网交换机操作手册
'i' is ambiguous.
Possible completions:
igmp Show Internet Group Management Protocol information
igmp-snooping Show IGMP snooping information
ike Show Internet Key Exchange information
interfaces Show interface information
ipsec Show IP Security information
isis Show Intermediate System-to-Intermediate System information
7?号命令
lab@ex4200-vc> ?
Possible completions:
clear Clear information in the system
configure Manipulate software configuration information
file Perform file operations
help Provide help information
monitor Show real-time debugging information
mtrace Trace multicast path from source to receiver
op Invoke an operation script
ping Ping remote target
quit Exit the management session
request Make system-level requests
restart Restart software process
set Set CLI properties, date/time, craft interface message
show Show system information
- 19 -
to
management
-
etherne
re
dundanc
aggregated
-
device
firewal
interface
protocol
syste
more
LessSpecific
More Specific
etherne
alar
chassi
Juniper EX 系列以太网交换机操作手册
ssh Start secure shell on another host
start Start shell
telnet Telnet to another host
test Perform diagnostic debugging
traceroute Trace route to remote host
2.6.2. 配置模式
1 配置模式
root@lab2> configure
Entering configuration mode
[edit]
root@lab2#
example:
root@lab2#set system services ftp
system {
services {
ftp; }
}
(2) 配置模式层
- 20 -
to
management
-
etherne
redundanc
aggregated
-
device
firewal
interface
protocol
syste
more
LessSpecific
More Specific
etherne
alar
chassi
top management
-
ethernet
redundancy
aggregated
-
devices
firewall
interfaces
protocols
system
more
ethernet
alarm
chassis
top
up
Juniper EX 系列以太网交换机操作手册
3使edit 命令cd 命令
使edit chassis alarm ethernet 可以ethernet 级操作 set
chassis alarm Ethernet 操作。
4 使up 和top 命令
user@host# up
[edit chassis alarm]
user@host# top
[edit]
Less Specific
More Specific
5示Candidate 配置
[edit]
- 21 -
Juniper EX 系列以太网交换机操作手册
user@host# show chassis alarm
user@host# edit chassis alarm
[edit chassis alarm]
user@host# show
[edit chassis alarm]
6)区分配置
比较Candidate active 配置的
[edit chassis]
user@host# show | compare
alarm {
xxx { + xxx xxx
- xxx xxx;
} } 其它 user@host# show | compare filename user@host# show | compare rollback number 7配置的差异更新 root@router# show | compare [edit interfaces] [edit] root@router# show | compare | save /var/tmp/patch.cfg Wrote 9 lines of output to '/var/tmp/patch.cfg' [edit] root@router# load patch /var/tmp/patch.cfg load complete
- 22 -
Juniper EX 系列以太网交换机操作手册
8配置 [edit] user@host# edit chassis alarm xxx [edit chassis alarm xxxx] user@host# delete xxx [edit chassis alarm xxxx] user@host# delete xxx [edit chassis alarm xxxx] user@host#
9配置 使 commit 配置rollback 恢复配置。 ser@host#commit and-quit 配置退配置模式 at 后commit 配置 check 检测配置,不改变配置 confirmed 知道回滚到下commit 模式是10 rollback 恢复配置。系统认9 个配置在 /config/ 3 个。file show /config/6
rollback rollback 0 恢复刚刚改变的配置
- 23 -
Juniper EX 系列以太网交换机操作手册
10配置模式层次改变 使exit 退回上一层配置模式 使exit configuration-mode 任意次退去配置模式
11存加载配置
- 24 -
Juniper EX 系列以太网交换机操作手册
可以使save filename 在任何配置模式个层的配置内容
存放便
次load [edit] cli# save filename [edit] cli# load (replace | merge | override) replace 取代的配置配置 merge 配置 override 取代的配置 user@host# load merge /var/db/config/juniper.conf.4 可以通过 show system storage 查看件系统,或用file show <pathname>
查看。
- 25 -
Juniper EX 系列以太网交换机操作手册
第3章. 接口操作
3.1. 配置物理端口
user@host#set interface ge-slot/pic/port description description
#配置端口描述
user@host#set interface ge-slot/pic/port mtu mtu-number
#配置端口MTU
user@host#set interface ge-slot/pic/port ether-options speed (10m | 100m | 1g)
#配置端口速
user@host#set interface ge-slot/pic/port ether-options link-mode (automatic | full-duplex |
half-duplex )
#配置端口
user@host#set interface ge-slot/pic/port ether-options (auto-negotiation |
no-auto-negotiation )
#配置端口动协
Example:
root@host> edit Entering configuration mode
[edit] root@host# set interfaces ge-3/0/0 description to_BJ-4200-1
[edit] root@host# set interfaces ge-3/0/0 mtu 9216
[edit] root@host# set interfaces ge-3/0/0 ether-options speed 1g
[edit] root@host# set interfaces ge-3/0/0 ether-options link-mode
full-duplex
[edit] root@host# set interfaces ge-3/0/0 ether-options auto-negotiation
[edit] root@host# commit
- 26 -
Juniper EX 系列以太网交换机操作手册
3.2. 配置物理端口层接口
[edit] root@host# set interfaces ge-0/0/16 unit 0 family ethernet-switching
port-mode access
配置物理端口作为二层access模式的接口,端口认情况二层access端口。
[edit] user@host # show interfaces ge-0/0/16 { unit 0 { family ethernet-switching; } }
3.3. 配置物理端口三层接口
EX交换机物理接口可以支持三层路由接口功能可以在接口配置三层
[edit] root@host# set interfaces ge-0/0/17 unit 0 family inet address
192.168.20.1/24
查看配置
[edit]
user@host # show interfaces ge0/0/17
unit 0 { family inet { address 192.168.20.1/24; } }
- 27 -
Juniper EX 系列以太网交换机操作手册
第4章. VLAN 操作
4.1. 配置 VLAN
化配置,所端口default VLANdefault vlan ID 0
user@host# set interfaces name unit 0 family ethernet-switching port-mode access
#配置端口的access模式,端口access模式。
user@host#set vlans vlan-name vlan-id number
#配置VLAN分配vlan ID
EX支持2种方式配置access接口分配VLAN用其中一种可以实现端口VLAN的划
分。 方式
user@host#set vlans vlan-name interface interface_name
VLAN多个物理端口
方式二: 或是在物理接口
user@host#set interfaces interface-name unit 0 family ethernet-switching vlan members vlan-name or vlan-id
#端口特定VLAN
user@host# show vlans vlan-name detail
#查看VLAN
Example:
root@host> edit Entering configuration mode
[edit] root@host# set vlans sales vlan-id 100
[edit] root@host# set vlans sales interface ge-0/0/1
#可以配置,实现相同的配置 [edit]
root@host# set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members sales
[edit]
- 28 -
Juniper EX 系列以太网交换机操作手册
root@host# commit
4.2. 配置 RVI 接口
user@host# set interfaces vlan unit number family inet address x.x.x.x/yy
#配置 RVI端口
user@host# set vlans vlan_name l3-interface vlan.unit-number
#RVI 端口VLAN
user@host# show vlans user@host# show interface terse user@host# show Ethernet-switching interface
#查看 VLAN 端口
Example:
root@host> edit Entering configuration mode
[edit] root@host# set interface vlan unit 100 family inet 192.168.3.254/24
[edit] root@host# set vlans sales l3-interface vlan.100
[edit] root@host# commit
4.3. 配置 Vlan trunk
配置端口作 trunk 端口,支持 802.1Q 的标准
user@host# set interfaces name unit 0 family ethernet-switching port-mode trunk
#配置端口的VLAN模式为trunk模式
user@host# set interfaces name unit 0 family ethernet-switching vlan members all|number
#配置trunk端口的通过的VLAN,9.1目前支持vlan-range在9.2本支持
Example:
root@host> edit Entering configuration mode
[edit]
- 29 -
Juniper EX 系列以太网交换机操作手册
root@host#show
interfaces { ge-0/0/3 { unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ orange blue ]; } } } } ge-0/0/4 { unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ 100 200 ]; } } } } }
配置 native-vlan-id
EX trunk 端口支持 native-vlan 的配置:
root@host> edit Entering configuration mode
[edit] root@host# set interface ge-0/0/8 unit 0 family Ethernet-switch
native-vlan-id purple
[edit] root@host#show interface
ge-0/0/8 { unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ orange blue purple ]; } native-vlan-id purple; } }
- 30 -
Juniper EX 系列以太网交换机操作手册
}
4.4. GVRP 配置
GVRPGARP VLAN Registration Protocol,GARP VLAN 注册协议)是GARP(Generic
Attribute Registration Protocol,通注册协议一种它基于GARP
作机制,维护设备VLAN 动态注册并传其它的设备。设备启GVRP 特性够接收来其它设备的VLAN 注册息,并动态更新地的VLAN
包括前的VLAN 这些VLAN 可以通过个端口而且设备够将本地VLAN 注册其它设备,以便使同一局域设备的VLAN
[edit]
set protocols gvrp enable join-timer 40 set protocols gvrp enable leave-timer 120 set protocols gvrp enable leaveall-timer 2000 set protocols gvrp interface all enable
通过 show gvrp show vlan 查看
- 31 -
Juniper EX 系列以太网交换机操作手册
5章. STP/RSTP/MSTP
5.1. STP 配置
STP 的配置: [edit protocol stp] set bridge-priority set hello-time set max-age
通过 show spanning-tree 查看。
5.2. RSTP
EX 交换机RSTP 可以通过配置实现
[edit protocols]
user@switch4# rstp configuration-name region1
user@switch4# rstp bridge-priority 8k user@switch4# rstp interface all cost 1000
user@switch4# rstp interface ge0/0/23.0 cost 1000 user@switch4# rstp interface ge0/0/23.0 mode point-to-point user@switch4# rstp interface ge0/0/19.0 cost 1000 user@switch4# rstp interface ge0/0/19.0 mode point-to-point
#查看RSTP状态:
[edit] lab@EX4200-VC# run show spanning-tree bridge STP bridge parameters Context ID : 0 Enabled protocol : RSTP Root ID : 8192.00:19:e2:52:ae:00 Root cost : 1000 Root port : ge-1/0/46.0 Hello time : 2 seconds Maximum age : 20 seconds Forward delay : 15 seconds Message age : 1 Number of topology changes : 1 Time since last topology change : 3692 seconds Local parameters Bridge ID : 32768.00:19:e2:54:d9:40 Extended system ID : 0
- 32 -
Juniper EX 系列以太网交换机操作手册
Internal instance ID : 0
[edit]
lab@EX4200-VC> show spanning-tree interface
Spanning tree interface parameters for instance 0
Interface Port ID Designated Designated Port State Role port ID bridge ID Cost
ge-1/0/39.0 128:664 128:664 32768.0019e254d940 1000 BLK DIS ge-1/0/46.0 128:671 128:559 8192.0019e252ae00 1000 FWD ROOT
5.3. MSTP
MSTPMultiple Spanning Tree Protocol协议)可以弥补 STP 和 RSTP 既可以也能使VLAN 沿各自的路转发从而冗余链路提供
机制。
MSTP 的特 ² MSTP 设置 VLAN 映射表VLAN 对应把 VLAN
起来。通过将多个 VLAN 个集合中)概念将多 VLAN 捆绑销和
² MSTP 把一个交换网络划分成多成多树之间
² MSTP 环路网无环避免报在环路网络中和无
同时还提供了数据转发的多个冗余路径,据转发过程中实现 VLAN 数载分
² MSTP STP RSTP。
配置例:
[edit protocols] user@switch1# mstp configuration-name region1 user@switch1# mstp bridge-priority 16k user@switch1# mstp interface ge-0/0/13.0 cost 1000 user@switch1# mstp interface ge-0/0/13.0 mode point-to-point user@switch1# mstp interface ge-0/0/9.0 cost 1000
- 33 -
Juniper EX 系列以太网交换机操作手册
user@switch1# mstp interface ge-0/0/9.0 mode point-to-point user@switch1# mstp interface ge-0/0/11.0 cost 4000 user@switch1# mstp interface ge-0/0/11.0 mode point-to-point user@switch1# mstp msti 1 bridge-priority 16k user@switch1# mstp msti 1 vlan [10 20] user@switch1# mstp msti 1 interface ge-0/0/11.0 cost 4000 user@switch1# mstp msti 2 bridge-priority 8k user@switch1# mstp msti 2 vlan [30 40]
查看状态:
user@switch1> show spanning-tree interface Spanning tree interface parameters for instance 0 Interface Port ID Designated Designated Port State Role ge-0/0/13.0 128:527 128:525 16384.0019e25040e0 1000 FWD ROOT ge-0/0/9.0 128:529 128:513 32768.0019e2503d20 1000 BLK ALT ge-0/0/11.0 128:531 128:513 8192.0019e25051e0 4000 BLK ALT
Spanning tree interface parameters for instance 1 Interface Port ID Designated Designated Port State Role ge-0/0/13.0 128:527 128:525 16385.0019e25040e0 1000 FWD ROOT ge-0/0/9.0 128:529 128:513 32769.0019e2503d20 1000 BLK ALT ge-0/0/11.0 128:531 128:513 4097.0019e25051e0 4000 BLK ALT
Spanning tree interface parameters for instance 2 Interface Port ID Designated Designated Port State Role ge-0/0/13.0 128:527 128:527 8194.0019e25044e0 1000 FWD DESG ge-0/0/9.0 128:529 128:513 4098.0019e2503d20 1000 FWD ROOT ge-0/0/11.0 128:531 128:531 8194.0019e25044e0 1000 FWD DESG
user@switch3>show spanning-tree bridge STP bridge parameters Context ID : 0 Enabled protocol : MSTP
STP bridge parameters for CIST Root ID : 8192.00:19:e2:50:51:e0 CIST regional root : 8192.00:19:e2:50:51:e0 CIST internal root cost : 0 Hello time : 2 seconds Maximum age : 20 seconds Forward delay : 15 seconds Number of topology changes : 3 Time since last topology change : 843 seconds Local parameters Bridge ID : 8192.00:19:e2:50:51:e0 Extended system ID : 0
- 34 -
Juniper EX 系列以太网交换机操作手册
Internal instance ID : 0 STP bridge parameters for MSTI 1
MSTI regional root : 4097.00:19:e2:50:51:e0 Hello time : 2 seconds Maximum age : 20 seconds Forward delay : 15 seconds Local parameters Bridge ID : 4097.00:19:e2:50:51:e0 Extended system ID : 0 Internal instance ID : 1
STP bridge parameters for MSTI 2 MSTI regional root : 4098.00:19:e2:50:3d:20 Root cost : 1000 Root port : ge-0/0/28.0 Hello time : 2 seconds Maximum age : 20 seconds Forward delay : 15 seconds Hop count : 19 Local parameters Bridge ID : 16386.00:19:e2:50:51:e0 Extended system ID : 0 Internal instance ID : 2
- 35 -
Juniper EX 系列以太网交换机操作手册
第6章. 链路聚合配置
Link Aggregation Group (LAG)链路合是将多个物理以太网端口合在一
使链路合服务的上层体把内的条物理链路
链路。链路合可以实现各个员端口
加带同时,组的员端口此动态备提高连接性。 LACPLink Aggregation Control Protocol,链路制协议)是一种基于 IEEE802.3ad 标准的协议。LACP 协议通过 LACPDULink Aggregation Control Protocol Data Unit 链路制协议数据单与对端交
6.1. LAG 的配置例子
chassis { aggregated-devices { ethernet { device-count 1; } } } interfaces { ge-0/0/9 { ether-options {
802.3ad ae0; } } ge-0/0/10 { ether-options {
802.3ad ae0; } } ae0 { aggregated-ether-options { lacp { active; } } unit 0 { family ethernet-switching; } } }
- 36 -
Juniper EX 系列以太网交换机操作手册
6.2. 三层 LAG 的配置例子
chassis { aggregated-devices { ethernet { device-count 1; } } } interfaces { ge-0/0/9 { ether-options {
802.3ad ae0; } } ge-0/0/10 { ether-options {
802.3ad ae0; } } ae0 { aggregated-ether-options { lacp { active; } } unit 0 { family inet { address 1.1.1.1/24; } } } }
配置 LAG 确保 LAG 个物理端口的配置相同错不 LAG 通过 show interfaces aeo terse 查看端口状态。
- 37 -
Juniper EX 系列以太网交换机操作手册
第7章. 三层协议配置
7.1. 静态路由协议
路由 必须 的配置 routing-options 级别
Syntax
[edit] routing-options { static { defaults {
static-options;
}
route destination-prefix { next-hop next-hop; qualified-next-hop address { metric metric; preference preference;
}
static-options;
} }
}
Example: [edit] user@host# show
routing-options { static {
route 0.0.0.0/0 next-hop 192.168.0.1;
}
}
7.2. RIP 配置
RIP 配置:
[edit protocol]
protocols {
rip {
- 38 -
Juniper EX 系列以太网交换机操作手册
group group-name {
neighbor interface-name;
}
}
}
RIP 和 Export 策略 policy-options { policy-statement statics-to-rip { from protocol static; then accept;
}
}
策略邻居 protocols { rip { group rip-neighbors { export statics-to-rip; neighbor fe-0/0/0.0;
neighbor fe-0/0/1.0;
} }
}
查看RIP路由
user@Riesling> show route protocol rip
inet.0: 27 destinations, 27 routes (27 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both
172.16.2.0/24 *[RIP/100] 00:07:25, metric 2 > to 172.16.1.2 via fe-0/0/0.0
192.168.8.1/32 *[RIP/100] 00:07:25, metric 2 > to 172.16.1.2 via fe-0/0/0.0
192.168.24.1/32 *[RIP/100] 00:00:25, metric 3 > to 172.16.1.2 via fe-0/0/0.0
7.3. Open Shortest Path First (OSPF)
式最短径优先协议是一种链路状态路由选择协议, I P 发展
用于系统路由选择信
- 39 -
Juniper EX 系列以太网交换机操作手册
7.3.1. 单区域
[edit] user@host# set protocols ospf area 0 interface ge-0/0/0
[edit] user@host# show protocols ospf ospf {
area 0.0.0.0 { interface ge-0/0/0.0;
}
}
7.3.2. 配置 OSPF 多区域
[edit] user@host# show protocols ospf
ospf { area 0.0.0.0 { interface ge-0/0/0.0;
}
}
[edit] user@host# set protocols ospf area 1 interface at-0/1/1.100 [edit] user@host# show protocols ospf ospf { area 0.0.0.0 { interface ge-0/0/0.0;
}
area 0.0.0.1 { interface at-0/1/1.100;
}
7.3.3. 配置 a Stub Area
[edit protocols ospf area area-id ]
- 40 -
Juniper EX 系列以太网交换机操作手册
stub <default-metric metric> <(no-summaries | summaries)>;
7.3.4. 配置 a Not-So-Stubby Area
[edit protocols ospf area area-id ] nssa {
area-range network/mask-length <restrict>; default-lsa { default-metric metric; metric-type type; type-7; } (no-summaries | summaries); }
8.4.4 配置 OSPF Virtual Link
过3 area使virtual Link 连接路。
[edit protocols ospf area 0.0.0.0] virtual-link neighbor-id router-id transit-area area-id;
7.3.5. 配置 OSPF Router Interfaces
Configuring an Interface on a Broadcast or Point-to-Point Network
[edit protocols ospf area area-id ] interface interface-name;
Configuring an Interface on a Point-to-Multipoint Network
[edit protocols ospf area 0.0.0.0] interface interface-name { neighbor address; }
Configuring an Interface on a Nonbroadcast, Multiaccess Network
- 41 -
Juniper EX 系列以太网交换机操作手册
[edit protocols ospf area 0] interface interface-name { interface-type nbma; neighbor address <eligible>; poll-interval seconds; }
7.3.6. 配置验证
可以使simple和MD5
[edit protocols ospf area area-id ]
authentication-type authentication;
[edit protocols ospf area area-id interface interface-name] authentication { md5 key-id { key [ key-values ]; } simple-password key-id; }
- 42 -
Juniper EX 系列以太网交换机操作手册
第8章. Virtual Chassis 操作
Virual Chassis 虚拟箱技术Juniper EX 交换机独技术。提供相同的高可
功能和大多数的故障功能 EX 4200 列交换机都能作为路由引擎发
多个 EX 4200 系列交换机在一起时有的虚拟机箱交换机共享一个控制层。两个 EX 4200 系列交换机在一起时,JUNOSTM 软件动启动选择便分配主用(活动)和备用(热备)路由引擎主用路由
引擎发故障,集2 和第 3 路由引擎故障(GRES)特性的接、服务IP 信流
以上的交换机虚拟配置主用路由引擎发故障
作为定的备路由引擎的交换机同时,可以作为线路使用。N+1 路由引擎冗余模式JUNOSTM 软件提供GRES断路由(NSR)桥接 (NSB)功能可确保生意外故障地转权。
Master RE
Master RE
Backup RE
Backup RE
Graceful Route
Graceful Route Engine Switchover
Engine Switchover (GRES) for hitless
(GRES) for hitless failovers
failovers
- 43 -
Juniper EX 系列以太网交换机操作手册
Master RE:主用路由引擎; Backup RE:路由引擎; graceful route engine
switchover(GRES) for hitless failovers:的路由引擎故障(GRES)功能实现 故障换。
虚拟端口的编号EX 4200 系列交换机瞻博络基于产品使
相同的插槽/模块/端口编号模式,提供产品的运行。由于使
的操作系统配置件,虚拟配置的所交换机都被产品,从而总体的系统维护管理工作。
基于机的模块化交换机每个 EX 4200 系列交换机都提供高可用性
特性。如果与经过践验证的 JUNOSTM 软件L2/L3 故障功能使用,这些 特性将使 EX 4200 系列交换机提供正的运营商级性。
8.1. VCP 端口
Juniper EX 交换机组建 Virtual chassis 虚拟可以2 链路方式:1
Virtual Chassis Port –VCP 的端口,支持 128Gbps 连接;2扩展插槽
EX-UM-2XFP 10GE 光纤端口连接,EX-UM-2XFP 作为 VCP 端口要配端口启Virtual chassis,该端口仍未普10GE 端口。交换机同时采 背板的 VCP 端口10GE 端口作 virtual chassis 连接优先选择背板的 VCP 作为 链路,10GE 端口作为备链路,原因背板的 VCP 带比较,链路 COST 优。
EX4200 最多支持 10 EX4200 式的交换机成虚拟机集群。
8.2. Master 交换机选择
Virtual Chassis 虚拟机箱时候,EX4200 交换机基于机制选择 master
交换机backup 交换机:
1 Virtual chassis 优先mastership priority优先128,范围 0
255。越优先级月优先选择为 master 交换机。
2 相同优先级别机启动是 master 交换机。 3 优先相同情况比较那交换机的线
master 交换机。
4 选择MAC 作为 master 交换机。
- 44 -
Juniper EX 系列以太网交换机操作手册
8.3. 带外网管端口及 console 端口:
Virtual Chassis 虚拟交换机集群,连接任意交换机的 CONSOLE
口,都可以访问整个集群行全局配置,必须连接 master 交换机的 console 端口管理。
同样带外网管端口也可以带外网管线缆连接的任意交换机的带外网管端口
访问虚拟交换机。
配置全局的带外网管端口: [edit] user@SWA-0# set interfaces vme unit 0 family inet /ip-address/mask/
- 45 -
Juniper EX 系列以太网交换机操作手册
8.4. 链路方式
Juniper EX4200 交换机组建 Virtual Chassis 集群的背板 VCP 的链路连接方式支持 标准的“菊花莲”连接,同时支持任意方式的连接。交换机流量转发基于 Juniper
VCCP 协议,实现最短转发机制
- 46 -
Juniper EX 系列以太网交换机操作手册
8.5. 级操作
Virtual Chassis 虚拟集群的交换机的 Junos 操作系统的本 要一将无成功版本EX4200 交换机连接同样 交换机分配 member-id但是集群,无全局管理。所以在集群交换机升级相同 junos 系统。交换机,需要再次升级系统的 可以通过全局将最junos 系统软件任意一台交换机的flash,通过命名可以实现全部成交换机的统一升级:
user@SWA-0>request system software add /var/tmp/xxxxx.tgz reboot
8.6. 配置操作
用 2 EX4200 VC 可以通过命令观察状态:
user@SWA-0>show virtual-chassis status Virtual Chassis ID: 0019.e250.47a0
Mastership Neighbor List Member ID Status Serial No Model priority Role ID Interface 0 (FPC 0) Prsnt AK0207360276 ex4200-48p 128 Master* 1 vcp-0 1 vcp-1 1 (FPC 1) Prsnt AK0207360281 ex4200-24t 128 Backup 0 vcp-0 0 vcp-1
Member ID for next new member: 2 (FPC 2)
user@SWA-0>show virtual-chassis vc-port all-members fpc0:
-------------------------------------------------------------------------­Interface Type Status or PIC / Port vcp-0 Dedicated Up vcp-1 Dedicated Up
fpc1:
-------------------------------------------------------------------------­Interface Type Status or PIC / Port vcp-0 Dedicated Up vcp-1 Dedicated Up
配置 Virtual chassis 交换机的优先级:
[edit]
- 47 -
Juniper EX 系列以太网交换机操作手册
user@SWA-0#set virtual-chassis member 0 mastership-priority 255
配置 10GE 端口作为 VCP 端口:
user@SWA-0> request virtual-chassis vc-port set pic-slot 1 port 0 member1 user@host>request virtual-chassis vc-port delete pic-slot 1 port 1 member 3
配置Virtual chassis member ID,组Virtual chassis 加新成员
情况分配 member ID范围09,当中间交换机退virtual chassis
member-ID 会自己释使用,通过命令member-id。全局 配置的影响
user@host> request virtual-chassis recycle member-id 3
改变交换机的 member-ID
user@SWA-0> request virtual-chassis renumber member-id 5 new-member-id 4
查看命令:
user@SWA-0> show virtual-chassis status user@SWA-0> show virtual-chassis vc-port user@SWA-0> show virtual-chassis vc-port all-members user@SWA-0>show virtual-chassis vc-port statistics member 0
8.7. 配置例子
如下拓扑,Virtual chassisLAG的配合例子
- 48 -
Juniper EX 系列以太网交换机操作手册
接的端口情况如下:
配置参考
[edit]
set chassis aggregated-devices ethernet device-count 2 set interfaces ae0 aggregated-ether-options minimum-links 2
- 49 -
Juniper EX 系列以太网交换机操作手册
set interfaces ae0 aggregated-ether-options link-speed 10g set interfaces ae1 aggregated-ether-options minimum-links 2 set interfaces ae1 aggregated-ether-options link-speed 10g set interfaces ae0 unit 0 family inet address 192.0.2.0/25 set interfaces ae1 unit 1 family inet address 192.0.2.128/25 set interfaces xe-0/1/0 ether-options 802.ad ae0 set interfaces xe-1/1/0 ether-options 802.ad ae0 set interfaces xe-0/1/1 ether-options 802.ad ae1 set interfaces xe-1/1/1 ether-options 802.ad ae1
- 50 -
Juniper EX 系列以太网交换机操作手册
第9章. 802.1X 配置
IEEE802 LAN/WAN 员会解决线局域网网问题提出802.1x 协议。
802.1x 协议作为局域网端口的通接制机制在以太中被广泛
主要解决以太问题。802.1x 协议是一种基于端口的网络接 制协议Port Based Network Access Control)。基于端口的网络接入控制在局
网接设备的端口所接用户设备制。连接端口
设备如通过可以访问局域;如果不通过无法访局域
Juniper EX 交换机支持 802.1X 标准支持 3 种模式:
1. single 模式:802.1X 的端口通过 HUB 下联端,其中一通过,
个端口他终可以访问
2. single-secure:802.1X 的端口通过 HUB 下联端,其中一通过,
访问他终止访问
3. multiple:802.1X 的端口通过 HUB 下联端,其中可以
证,通过可以基于号的 radius 配置实现动态 VLAN 的
配置操作
9.1. 配置 radius 服务器
[edit]
set access radius-server 10.0.0.100 secret juniper set access profile profile1 authentication-order radius set access profile profile1 radius authentication-server 10.0.0.100
10.2.14.200
9.2. 配置接口模式。
[edit]
set protocols dot1x authenticator interface ge-0/0/8 supplicant single set protocols dot1x authenticator interface ge-0/0/9 supplicant single-secure set protocols dot1x authenticator interface ge-0/0/11 supplicant multiple
- 51 -
Juniper EX 系列以太网交换机操作手册
9.3. 查看状态
user@switch> show dot1x interface ge-0/0/11.0 detail
- 52 -
Juniper EX 系列以太网交换机操作手册
10章. Packet Filtering
Juniper EX 交换机支持基于物理端口、VLAN 三层 VLAN 接口的技术
二层过支持
Ingress port firewall filter
Ingress VLAN firewall filter
Egress VLAN firewall filter 三层过滤下支持
Ingress port firewall filter
Ingress VLAN firewall filter (Layer 2 CoS)
Ingress router firewall filter (Layer 3 CoS)
Egress router firewall filter
Egress VLAN firewall filter
- 53 -
Juniper EX 系列以太网交换机操作手册
10.1. 配置命令:
firewall {
family family-name {
filter filter-name {
term term-name {
from {
match-conditions; } then {
action;
action-modifiers; }
}
}
} policer policer-name {
if-exceeding {
bandwidth-limit bps;
burst-size-limit bytes; } then {
policer-action; }
}
}
接口配置:
[edit interfaces] user@switch# set ge-0/0/1 unit 0 family ethernet-switching filter input
ingress-port-filter
VLAN 接口配置:
[edit vlans] user@switch# set employee-vlan vlan 20 filter output egress-vlan-filter
RVI 接口配置:
[edit interfaces] user@switch# set ge-0/1/0 unit 0 family inet source-address 10.10.10.1/24
filter input ingress-router-filter
[edit interfaces] user@switch# set ge-0/1/0 unit 0 family inet source-address 10.10.10.1/24
filter output egress-router-filter
- 54 -
Juniper EX 系列以太网交换机操作手册
10.2. 配置接口限速
(1) firewall {
policer AAAAAAAAAAAAAAAAAAA {
if-exceeding {
bandwidth-limit 1m;
burst-size-limit 30k; } then {
discard; }
}
family ethernet-switching {
filter ccccccccccccccccccc {
term xxxxx-connection { then {
policer AAAAAAAAAAAAAAAAAA }
}
(2)
interfaces {
ge-0/0/0 {
unit 0 {
family ethernet-switching {
filter {
input ccccccccccccccccccc; }
}
}
} 查看命令:
user@Shiraz> show firewall user@Shiraz> show firewall log user@Shiraz> show firewall log detail user@Shiraz> show firewall log messages user@Shiraz> show interfaces filters user@Shiraz> show interfaces policers
- 55 -
Juniper EX 系列以太网交换机操作手册
11章. COS
量监管、拥塞管理和拥塞避免地实施服务的
主要功能
流分定的类是地实施服务的前
监管设备的特定管。可以
限制惩罚措施,运营商的商利益受损害
整形一种主动,通了使
可供给的网源,避免不必要的文丢拥塞。
拥塞管理:拥塞管理必须解决竞争。通文放入队
并采取某算法安转发
拥塞避免拥塞络资损害拥塞避免使用情况
发现拥塞趋势时采取弃报策略,通过来解的过
这些管理技术中类是基据一定的别出,是
地实施服务的前提;量监管、拥塞管理和拥塞避免面对
分配的源实施控制,提供服务思想体体
Juniper EX 交换机支持端口 8 列的划分。
- 56 -
Juniper EX 系列以太网交换机操作手册
如图所示:EX3200 交换机的 ge-0/0/0 ge-0/0/1 端口连接 2 VOIP 机,分配 voice-vlan ,ge-0/0/2 连接摄像划分camera-vlan ,ge-0/0/3,ge-0/0/4,ge-0/0/5 ge0/0/6 端口分别连接 4 服务器,分配server-vlan 这 3 vlan 3 COS 理。
相应的接口址如下:
配置如
- 57 -
Juniper EX 系列以太网交换机操作手册
[edit] set class-of-service forwarding-classes class app queue-num 5 set class-of-service forwarding-classes class mail queue-num 1 set class-of-service forwarding-classes class db queue-num 2 set class-of-service forwarding-classes class erp queue-num 3 set class-of-service forwarding-classes class video queue-num 4 set class-of-service forwarding-classes class best-effort queue-num 0 set class-of-service forwarding-classes class voice queue-num 6 set class-of-service forwarding-classes class network-control queue-num 7 set firewall family ethernet-switching filter voip_class term voip from source-address 192.168.1.1/32 set firewall family ethernet-switching filter voip_class term voip from source-address 192.168.1.2/32 set firewall family ethernet-switching filter voip_class term voip from protocol udp set firewall family ethernet-switching filter voip_class term voip from source-port 2698 set firewall family ethernet-switching filter voip_class term voip then forwarding-class voice loss-priority low set firewall family ethernet-switching filter voip_class term network_control from precedence [net-control internet-control] set firewall family ethernet-switching filter voip_class term network_control then forwarding-class network-control loss-priority low set firewall family ethernet-switching filter voip_class term best_effort_traffic then forwarding-class best-effort loss-priority low set interfaces ge-0/0/0 description phone1–voip-ingress-port set interfaces ge-0/0/0 unit 0 family ethernet-switching filter input voip_class set interfaces ge-0/0/1 description phone2–voip-ingress-port set interfaces ge-0/0/1 unit 0 family ethernet-switching filter input voip_class set firewall family ethernet-switching filter video_class term video from source-address 192.168.1.14/32 set firewall family ethernet-switching filter video_class term video from protocol udp set firewall family ethernet-switching filter video_class term video from source-port 2979 set firewall family ethernet-switching filter video_class term video then forwarding-class video loss-priority low set firewall family ethernet-switching filter video_class term network_control from precedence [net-control internet-control] set firewall family ethernet-switching filter video_class term network_control then forwarding-class network-control loss-priority low
- 58 -
Juniper EX 系列以太网交换机操作手册
set firewall family ethernet-switching filter video_class term best_effort_traffic then forwarding-class best-effort loss-priority low set interfaces ge-0/0/2 description video-ingress-port set interfaces ge-0/0/2 unit 0 family ethernet-switching filter input video_class
set firewall family ethernet-switching filter app_class term app from source-address 192.168.1.23/32 set firewall family ethernet-switching filter app_class term app from protocol tcp set firewall family ethernet-switching filter app_class term app from source-port [1494 2512 2513 2598 2897] set firewall family ethernet-switching filter app_class term app then forwarding-class app loss-priority low set firewall family ethernet-switching filter app_class term mail from source-address 192.168.1.24/32 set firewall family ethernet-switching filter app_class term mail from protocol tcp set firewall family ethernet-switching filter app_class term mail from source-port [25 143 389 691 993 3268 3269] set firewall family ethernet-switching filter app_class term mail then forwarding-class mail loss-priority low set firewall family ethernet-switching filter app_class term db from source-address 192.168.1.25/32 set firewall family ethernet-switching filter app_class term db from protocol tcp set firewall family ethernet-switching filter app_class term db from source-port [1521 1525 1527 1571 1810 2481] set firewall family ethernet-switching filter app_class term db then forwarding-class db loss-priority low set firewall family ethernet-switching filter app_class term erp from source-address 192.168.1.26/32 set firewall family ethernet-switching filter app_class term erp from protocol tcp set firewall family ethernet-switching filter app_class term erp from source-port [3200 3300 3301 3600] set firewall family ethernet-switching filter app_class term erp then forwarding-class erp loss-priority low set firewall family ethernet-switching filter app_class term network_control from precedence [net-control internet-control] set firewall family ethernet-switching filter app_class term network_control then forwarding-class network-control loss-priority low set firewall family ethernet-switching filter app_class term best_effort_traffic
- 59 -
Juniper EX 系列以太网交换机操作手册
then forwarding-class best-effort loss-priority low set interfaces ge-0/0/3 unit 0 family ethernet-switching filter input app_class set interfaces ge-0/0/4 unit 0 family ethernet-switching filter input app_class set interfaces ge-0/0/5 unit 0 family ethernet-switching filter input app_class set interfaces ge-0/0/6 unit 0 family ethernet-switching filter input app_class set class-of-service schedulers voice-sched buffer-size percent 10 set class-of-service schedulers voice-sched priority strict-high set class-of-service schedulers voice-sched transmit-rate percent 10 set class-of-service schedulers video-sched buffer-size percent 15 set class-of-service schedulers video-sched priority low set class-of-service schedulers video-sched transmit-rate percent 15 set class-of-service schedulers app-sched buffer-size percent 10 set class-of-service schedulers app-sched priority low set class-of-service schedulers app-sched transmit-rate percent 10 set class-of-service schedulers mail-sched buffer-size percent 5 set class-of-service schedulers mail-sched priority low set class-of-service schedulers mail-sched transmit-rate percent 5 set class-of-service schedulers db-sched buffer-size percent 10 set class-of-service schedulers db-sched priority low set class-of-service schedulers db-sched transmit-rate percent 10 set class-of-service schedulers erp-sched buffer-size percent 10 set class-of-service schedulers erp-sched priority low set class-of-service schedulers erp-sched transmit-rate percent 10 set class-of-service schedulers nc-sched buffer-size percent 5 set class-of-service schedulers nc-sched priority strict-high
set class-of-service schedulers nc-sched transmit-rate percent 5 set class-of-service schedulers be-sched buffer-size percent 35 set class-of-service schedulers be-sched priority low set class-of-service schedulers be-sched transmit-rate percent 35 set class-of-service scheduler-maps ethernet-cos-map forwarding-class voice scheduler voice-sched set class-of-service scheduler-maps ethernet-cos-map forwarding-class video scheduler video-sched set class-of-service scheduler-maps ethernet-cos-map forwarding-class app scheduler app-sched set class-of-service scheduler-maps ethernet-cos-map forwarding-class mail scheduler mail-sched set class-of-service scheduler-maps ethernet-cos-map forwarding-class db scheduler db-sched set class-of-service scheduler-maps ethernet-cos-map forwarding-class erp
- 60 -
Juniper EX 系列以太网交换机操作手册
scheduler erp-sched set class-of-service scheduler-maps ethernet-cos-map forwarding-class network-control scheduler nc-sched set class-of-service scheduler-maps ethernet-cos-map forwarding-class best-effort scheduler be-sched set class-of-service interfaces ge-0/0/20 scheduler-map ethernet-cos-map
- 61 -
Juniper EX 系列以太网交换机操作手册
12章. POE
PoEPower over Ethernet以太供电,又称远程供电)是设备通过以太网接口,线外接 PDPowered Device,受设备设备IP 电话线 AP、网
络摄像等)行远程供电
PoE 系统包括 PoE PSE PD
n PoE 电源
PoE 个 PoE 系统供电,分为外置种类型
n PSE
PSEPower Sourcing Equipment供电设备)是子 卡 PSE 对单PoE 接口行独立管理。PSE PoE 接口的线路检测 PDPD
并向其供电。检测到 PD 拔出PSE 停止供电。PoE 供电能力以太 接口PoE 接口,包括 FE GE。
n PD
PD PSE 供电的设备。分为标准 PD 标准 PD标准 PD IEEE802.3af 标准PD 设备。PD 设备PoE 供电同时连接 供电行电源冗余
Juniper EX 交换机种电模块,分别支持 8 口、24 端口、48 端口的 POE 供电对应于 320W/600W/930W 种电模块。
POE 可以灵活配置定端口闭 POE 功能最大供电
配置命令:
配置全部接口POE 功能
[edit]
user@switch# set poe interface all
配置定接口POE 功能
[edit]
user@switch# set poe interface ge-0/0/0
- 62 -
Juniper EX 系列以太网交换机操作手册
查看POE的状态
show poe interface <ge-fpc/pic/port>
- 63 -
Juniper EX 系列以太网交换机操作手册
13章. 端口镜像
端口像是定端口的复制份到目的端口,目的端口会据监
设备连,用这些监测设备复制目的端口的,进
故障排除
Juniper EX 交换机支持本端口镜像以远程端口同时支持多对的端口其中可以支持VLAN 镜像VLAN。端口像可以通过策略相应
配置命令:
ethernet-switching-options {
analyzer {
name {
loss-priority priority; ratio number; input {
ingress {
interface (all | interface-name);
vlan (vlan-id | vlan-name); } egress {
interface (all | interface-name); }
output {
interface interface-name; vlan (vlan-id | vlan-name);
}
}
}
查看状态
show analyzer user@host> show analyzer
Analyzer name : employee-monitor Analyzer mirror ratio : 1 Analyzer loss priority : High Analyzer ingress monitored interfaces: ge-0/0/0.0 ge-0/0/1.0 Analyzer egress monitored interfaces : None Analyzer monitor interface : None Analyzer monitor VLAN : remote-analyzer
- 64 -
Juniper EX 系列以太网交换机操作手册
14章. 配置命令索引
[edit access] Configuration Statement Hierarchy on page 21
[edit chassis] Configuration Statement Hierarchy on page 22
[edit class-of-service] Configuration Statement Hierarchy on page 22
[edit ethernet-switching-options] Configuration Statement Hierarchy on page 23
[edit firewall] Configuration Statement Hierarchy on page 25
[edit interfaces] Configuration Statement Hierarchy on page 26
[edit poe] Configuration Statement Hierarchy on page 26
[edit protocols] Configuration Statement Hierarchy on page 27
[edit snmp] Configuration Statement Hierarchy on page 30
[edit virtual-chassis] Configuration Statement Hierarchy on page 31
[edit vlans] Configuration Statement Hierarchy on page 31
[edit access] Configuration Statement Hierarchy
access {
profile profile-name {
accounting {
order [ radius | none ]; stop-on-access-deny;
stop-on-failure; } authentication-order [ authentication-method ]; radius {
accounting-server [ server-address ];
authentication-server [ server-address ]; }
}
}
[edit chassis] Configuration Statement Hierarchy
chassis {
aggregated-devices {
ethernet {
device-count number; }
}
- 65 -
Juniper EX 系列以太网交换机操作手册
}
[edit class-of-service] Configuration Statement Hierarchy
class-of-service {
classifiers {
(dscp | ieee-802.1 | inet-precedence) classifier-name {
import (classifier-name | default);
forwarding-class class-name {
loss-priority loss-priority {
code-points [ aliases ] [ 6 bit-patterns ];
}
} }
} code-point-aliases {
(dscp | ieee-802.1 | inet-precedence) {
alias-name bits; }
} forwarding-classes {
class class-name queue-num queue-number;
} interfaces {
interface-name {
scheduler-map map-name;
unit logical-unit-number {
forwarding-class class-name; classifiers {
(dscp | ieee-802.1 | inet-precedence) (classifier-name | default);
}
} }
} rewrite-rules {
(dscp | ieee-802.1 | inet-precedence) rewrite-name {
import (rewrite-name | default);
forwarding-class class-name {
loss-priority loss-priority code-point (alias | bits);
}
}
}
scheduler-maps {
map-name {
forwarding-class class-name scheduler scheduler-name;
}
}
- 66 -
Juniper EX 系列以太网交换机操作手册
schedulers {
scheduler-name {
buffer-size (percent percentage | remainder); drop-profile-map loss-priority loss-priority protocol protocol drop-profile
profile-name; priority priority; transmit-rate (rate | percent percentage | remainder);
}
}
[edit ethernet-switching-options] Configuration Statement Hierarchy
ethernet-switching-options {
analyzer {
name {
loss-priority priority; ratio number; input {
ingress {
interface (all | interface-name);
vlan (vlan-id | vlan-name); } egress {
interface (all | interface-name); }
output {
interface interface-name; vlan (vlan-id | vlan-name);
}
} } bpdu-block {
interface (all | [interface-name]);
disable-timeout timeout; } redundant-trunk-group {
group-name name {
interface interface-name <primary>;
} } secure-access-port {
interface (all | interface-name) {
allowed-mac {
mac-address-list; } (dhcp-trusted | no-dhcp-trusted );
- 67 -
Juniper EX 系列以太网交换机操作手册
mac-limit limit action action;
} vlan (all | vlan-name) {
(arp-inspection | no-arp-inspection ); (examine-dhcp | no-examine-dhcp ); mac-move-limit limit action action;
} } storm-control {
interface (all | interface-name) {
level level; no-broadcast; no-unknown-unicast;
} } voip {
interface (all | [interface-name | access-ports]) {
vlan vlan-name ; forwarding-class <assured-forwarding | best-effort | expedited-forwarding |
network-control>;
} }
}
[edit firewall] Configuration Statement Hierarchy
firewall {
family family-name {
filter filter-name {
term term-name {
from {
match-conditions; } then {
action;
action-modifiers; }
}
} } policer policer-name {
if-exceeding {
bandwidth-limit bps;
burst-size-limit bytes; } then {
- 68 -
Juniper EX 系列以太网交换机操作手册
policer-action; }
}
}
[edit interfaces] Configuration Statement Hierarchy
interfaces {
ae-x {
aggregated-ether-options {
lacp mode {
periodic interval;
} }
} interface-name {
description text; mtu bytes; ether-options {
802.3ad aex;
auto-negotiation;
flow-control;
link-mode mode;
speed (speed | auto-negotiation | no-autonegotiation); } unit logical-unit-number {
family ethernet-switching {
filter input filter-name; filter output filter-name; l3-interface interface-name-logical-unit-number; native-vlan-id vlan-id port-mode mode; vlan {
members [ (names | vlan-ids) ]; translate vlan-id1 vlan-id2;
}
} }
}
}
[edit poe] Configuration Statement Hierarchy
poe {
guard-band watts; interface (all | interface-name) {
disable; maximum-power watts;
- 69 -
Juniper EX 系列以太网交换机操作手册
priority value; telemetries {
disable; duration hours; interval minutes;
}
[edit protocols] Configuration Statement Hierarchy
protocols {
dot1x {
authenticator {
authentication-profile-name access-profile-name;
static {
mac-address {
vlan-assignment (vlan-id |vlan-name); interface interface-names;
} } interface (all | interface-name) {
disable;
guest-vlan (vlan-name | vlan-id);
maximum-requests seconds;
no-reauthentication;
quiet-period seconds;
reauthentication {
interval seconds; } retries number; server-timeout seconds; supplicant (single | single-secure | multiple); supplicant-timeout seconds; transmit-period seconds;
} } gvrp {
<enable | disable>; interface (all | [interface-name]) {
disable;
} join-timer millseconds; leave-timer milliseconds;
leaveall-timer milliseconds; } igmp-snooping {
traceoptions {
- 70 -
Juniper EX 系列以太网交换机操作手册
file filename <files number> <size size> <world-readable | no-world-readable>
<match regex>;
flag flag (detail | disable | receive | send); } vlan (vlan-id | vlan-number {
immediate-leave;
interface interface-name {
multicast-router-interface; static {
group ip-address;
} } query-interval seconds; query-last-member-interval seconds; query-response-interval seconds; robust-count number;
} } lldp {
disable;
advertisement-interval seconds;
hold-multiplier number;
interface (all | interface-name) {
disable; } traceoptions {
file filename <files number> <size size> <world-readable |
no-world-readable>
<match regex>;
flag flag (detail | disable | receive | send); } transmit-delay seconds;
} lldp-med {
disable; fast-start number; interface (all | interface-name) {
disable;
location {
elin number; civic-based {
what number; country-code code; ca-type {
number {
- 71 -
Juniper EX 系列以太网交换机操作手册
ca-value value;
}
}
}
} }
} mstp {
disable; bpdu-block-on-edge; bridge-priority priority;
configuration-name name; forward-delay seconds; hello-time seconds; interface (all | interface-name) {
disable; bpdu-timeout-action {
block;
alarm; } cost cost; edge; mode mode; no-root-port; priority priority;
} max-age seconds; max-hops hops; msti msti-id {
vlan (vlan-id | vlan-name); interface interface-name {
disable;
cost cost;
edge;
mode mode;
priority priority; }
} revision-level revision-level; traceoptions {
file filename <files number > <size size> <no-stamp | world-readable |
no-world-readable>; flag flag;
}
rstp {
- 72 -
Juniper EX 系列以太网交换机操作手册
disable; bpdu-block-on-edge; bridge-priority priority; forward-delay seconds; hello-time seconds; interface (all | interface-name) {
disable; bpdu-timeout-action {
block;
alarm; } cost cost; edge; mode mode; no-root-port; priority priority;
} max-age seconds;
}
traceoptions {
file filename <files number > <size size> <no-stamp | world-readable |
no-world-readable>; flag flag;
}
stp {
disable; bridge-priority priority; forward-delay seconds; hello-time seconds; interface (all | interface-name) {
disable; bpdu-timeout-action {
block;
alarm; } cost cost; edge; mode mode; no-root-port; priority priority;
} max-age seconds;
}
traceoptions {
file filename <files number > <size size> <no-stamp |
- 73 -
Juniper EX 系列以太网交换机操作手册
world-readable |
no-world-readable>; flag flag;
}
}
[edit snmp] Configuration Statement Hierarchy
snmp {
rmon {
history index {
bucket-size number; interface interface-name; interval seconds; owner owner-name;
}
}
}
[edit virtual-chassis] Configuration Statement Hierarchy
virtual-chassis {
mac-persistence-timer seconds; preprovisioned; member member-id {
mastership-priority number; no-management-vlan; serial-number;
role; } traceoptions {
file filename <files number> <size size> <world-readable |
no-world-readable>
<match regex>;
flag flag ; }
}
[edit vlans] Configuration Statement Hierarchy
vlans {
vlan-name {
mac-limit action;
description text-description;
filter input filter-name;
filter output filter-name;
l3-interface vlan.logical-interface-number;
- 74 -
Juniper EX 系列以太网交换机操作手册
mac-table-aging-time seconds;
vlan-id number; }
}
- 75 -
Loading...