8,请根据以下情况对GP3600B的环境做相关配置 现有一网络运营商购买了上海博达数据通信有限公司的GP3600B与GP1704-4G-22A来搭建一个校园网,其中对所有学生免费开放带宽为10M的网络,同时为了满足部分需求高带宽的学生提供带宽为50M的网络,请根据以上要求组件该网络。需要具体命令
时间: 2024-02-23 14:58:33 浏览: 98
校园网的完整配置命令
感谢您的提问。针对这个情况,以下是一些具体的命令配置:
1. 将GP3600B配置为核心交换机,接入GP1704-4G-22A,并配置VLAN:
```
config
vlan 10 name STUDENTS
vlan 20 name TEACHERS
interface gigabitEthernet 0/1
switchport mode trunk
switchport trunk allowed vlan 10,20
exit
```
2. 对于所有学生,配置一个带宽限制为10M的QoS策略:
```
config
qos
policy-map STUDENT-10M
class class-default
police cir 10000
exit
interface gigabitEthernet 0/2
service-policy input STUDENT-10M
exit
```
3. 对于需要更高带宽的学生,标记他们的账户,并为他们配置一个带宽限制为50M的QoS策略:
```
config
radius-server host 10.0.0.1 key radius_secret
aaa accounting dot1x default start-stop group radius
aaa accounting update newinfo periodic 30
aaa authentication login default group radius local
aaa authentication dot1x default group radius
aaa authorization console
aaa authorization exec default group radius local
aaa authorization network default group radius
aaa server radius dynamic-author
policy-map STUDENT-50M
class class-default
police cir 50000
exit
class-map type radius match-all STUDENT-50M
match attribute 6 value "50M"
exit
interface gigabitEthernet 0/3
service-policy input STUDENT-50M
dot1x port-control auto
dot1x reauthentication
dot1x pae authenticator
dot1x guest-vlan 20
dot1x critical vlan 10
exit
```
4. 配置一些安全策略,如DHCP Snooping、IP Source Guard等,来防止未经授权的设备接入网络:
```
config
ip dhcp snooping vlan 10,20
ip dhcp snooping
ip dhcp snooping database flash:/dhcp_snooping.db
ip dhcp snooping information option
ip dhcp snooping information option allow-untrusted
interface gigabitEthernet 0/1
ip dhcp snooping trust
exit
config
ip verify source
interface gigabitEthernet 0/2
ip verify source
exit
```
以上是一些可能的命令配置,具体配置应根据实际情况进行调整。希望这些信息能够对您有所帮助。
阅读全文