Cisco雙出口策略實(shí)現(xiàn)的步驟與方法

策略路由
策略路由,是一種比基于目標(biāo)網(wǎng)絡(luò)進(jìn)行路由更加靈活的數(shù)據(jù)包路由轉(zhuǎn)發(fā)機(jī)制。路由器將通過(guò)路由圖決定如何對(duì)需要路由的數(shù)據(jù)包進(jìn)行處理,路由圖決定了一個(gè)數(shù)據(jù)包的下一跳轉(zhuǎn)發(fā)路由器。
Cisco 雙出口策略實(shí)現(xiàn)的步驟:
ROUTER#CONFIG T
Router(Config)>int fa 0/0
Router(Config-if)>ip addr 192.168.0.1 255.255.255.0
Router(Config-if)>ip nat inside
Router(Config-if)>ip policy route-map dual_isp
Router(Config-if)>int fa 0/1
Router(Config-if)>ip addr 電信分配的地址
Router(Config-if)>no shut
Router(Config-if)>ip nat outside
Router(Config-if)>int fa 1/0
Router(Config-if)>ip addr 網(wǎng)通分配的地址
Router(Config-if)>no shut
Router(Config-if)>ip nat outside
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 202.102.128.0 255.255.192.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 218.11.0.0 255.254.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 218.21.128.0 255.255.128.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 218.24.0.0 255.254.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 218.26.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 218.27.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 218.28.0.0 255.254.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 218.56.0.0 255.252.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 218.60.0.0 255.254.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 218.62.0.0 255.255.128.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 218.67.128.0 255.255.128.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 218.68.0.0 255.254.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 218.7.0.0 255.252.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 219.141.128.0 255.255.128.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 219.142.0.0 255.254.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 219.154.0.0 255.254.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 219.156.0.0 255.254.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 219.158.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 219.159.0.0 255.255.192.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 202.102.224.0 255.255.224.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 202.106.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 202.107.0.0 255.255.128.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 202.108.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 202.110.0.0 255.255.128.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 202.110.192.0 255.255.192.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 202.111.128.0 255.255.192.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 202.96.0.0 255.255.192.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 202.96.64.0 255.255.224.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 202.97.128.0 255.255.128.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 202.98.0.0 255.255.224.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 202.99.0.0 255.255.255.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.0.0.0 255.252.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.10.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.11.0.0 255.255.128.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.11.128.0 255.255.192.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.11.192.0 255.255.224.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.12.0.0 255.255.128.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.12.128.0 255.255.192.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.13.0.0 255.255.192.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.13.64.0 255.255.224.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.13.128.0 255.255.128.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.192.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.196.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.199.0.0 255.255.224.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.199.32.0 255.255.240.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.199.128.0 255.255.192.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.199.192.0 255.255.240.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.200.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.204.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.207.0.0 255.255.192.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.208.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.4.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.6.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.7.0.0 255.255.192.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.7.64.0 255.255.224.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.7.128.0 255.255.128.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 221.8.0.0 255.254.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 222.128.0.0 255.240.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 222.160.0.0 255.252.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 222.163.0.0 255.255.224.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 60.0.0.0 255.248.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 60.8.0.0 255.252.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 60.10.0.0 255.252.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 60.12.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 60.13.0.0 255.255.192.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 60.13.128.0 255.255.128.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 60.16.0.0 255.240.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 60.208.0.0 255.248.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 60.220.0.0 255.252.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 61.133.0.0 255.255.128.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 61.134.96.0 255.255.224.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 61.134.128.0 255.255.128.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 61.135.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 61.136.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 61.138.0.0 255.255.128.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 61.138.128.0 255.255.192.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 61.139.128.0 255.255.192.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 61.148.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 61.149.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 61.156.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 61.158.0.0 255.255.0.0
Router(Config)>Access-list 101 permit Ip 192.168.0.0 0.0.0.255 61.159.0.0 255.255.192.0
Router(Config)>Access-list 102 permit Ip any any
Router(Config)>Ip Nat Inside Source Route-map CT_NAT int fa 0/1 overload
Router(Config)>Ip Nat Inside Source Route-map CNC_NAT int fa 1/0 overload
Router(Config)>Route-map CT_NAT Permit 10
Router(Config-route-map)>Match Int Fa 0/1 (這里不會(huì)匹配外面發(fā)給它的包,因?yàn)镈NAT優(yōu)先于路由選擇)
Router(Config)>Route-map CNC_NAT Permit 10
Router(Config-route-map)>Match Int fa1/0 (指這個(gè)接口所收到的所有包除了DNAT匹配的,會(huì)先進(jìn)行目標(biāo)轉(zhuǎn)換,這樣目標(biāo)并不會(huì)是FA1/0,而是內(nèi)部的一個(gè)IP,這里其實(shí)可以寫(xiě)next-hop 便于理解,也便于檢測(cè)對(duì)方的存在)
Router(Config)>Route-map dual_isp Permit 10
Router(Config-route-map)>Match Ip address 101
Router(Config-route-map)>set ip next-hop 網(wǎng)通網(wǎng)關(guān) 電信網(wǎng)關(guān)(這里恰好把包發(fā)給了NAT所需要的接口,注意這里只是改變了包的下一跳而不是目標(biāo)。還要注意這里并不是把包扔給了next-hop而是改變了 尋路方式,轉(zhuǎn)發(fā)將在此之后進(jìn)行尋路,之后便是源地址轉(zhuǎn)換:路由器2大功能尋路,轉(zhuǎn)發(fā)是分開(kāi)的,由此可以看出,如果策略NAT里匹配的是對(duì)方ISP的地址為 下一跳,那可以檢測(cè)對(duì)方的存在與否)
Router(Config)>Route-map dual_isp Permit 20
Router(Config-route-map)>Match Ip address 102
Router(Config-route-map)>set ip next-hop 電信網(wǎng)關(guān) 網(wǎng)通網(wǎng)關(guān)
Router(Config)>Ip Route 0.0.0.0 0.0.0.0 電信網(wǎng)關(guān)
Router(Config)>Ip Route 0.0.0.0 0.0.0.0 網(wǎng)通網(wǎng)關(guān)
(注意 PBR優(yōu)先于路由,而源地址轉(zhuǎn)換路由又優(yōu)先于NAT,那PBR會(huì)比NAT先進(jìn)行,所以首先因該是進(jìn)行PBR把包分類,扔給2個(gè)出口,之后再做路由選擇路由 是默認(rèn)的沒(méi)什么,之后就是NAT了,策略一看在2出口上收到的包分別進(jìn)行自己的策略NAT,當(dāng)回來(lái)的時(shí)候,2個(gè)出口上收到的包并不會(huì)進(jìn)行源轉(zhuǎn)換為什么?因 為DNAT優(yōu)先于路由,SNAT比路由還慢,所以DNAT是最先進(jìn)行的。還有match next hop 匹配多個(gè)下一跳是與的關(guān)系,也就是說(shuō)要滿足全部的match才會(huì)用動(dòng)作,所以前面不能match多個(gè)nexthop,否則一定砸了,只能match一個(gè) nexthop,當(dāng)然set可以set多個(gè)。 )
此策略路由和策略nat說(shuō)明:目的地址為網(wǎng)通地址的包全部發(fā)給網(wǎng)通網(wǎng)關(guān),其他一律發(fā)給電信,由于網(wǎng)通地址段較少,所以選擇了做網(wǎng)通的acl條目,減輕工作 量。
以上就是用Cisco路由器雙出口策略實(shí)現(xiàn)的步驟與方法,策略nat部分也可以用match acl的方式,但是發(fā)現(xiàn)實(shí)際速度很慢,不知道原因,可能是需要逐條匹配吧。但是最好用match interface的方式,因?yàn)橹挥羞@樣才能實(shí)現(xiàn)備份,如果接口down掉,就不會(huì)在match接口,但是如果用acl,則會(huì)因?yàn)橛肋h(yuǎn)match而pat 成已經(jīng)down掉接口的地址,但是路由會(huì)從另一接口走掉,同樣很慢了就。地址段在今后逐漸補(bǔ)全。trace分析表明:基本上包都走對(duì)路了。而且速度比原來(lái) 單接口時(shí)訪問(wèn)其他isp網(wǎng)明顯加快了。謝謝閱讀,希望能幫到大家,請(qǐng)繼續(xù)關(guān)注腳本之家,我們會(huì)努力分享更多優(yōu)秀的文章。
相關(guān)文章
售價(jià)599元起! 華為路由器X1/Pro發(fā)布 配置與區(qū)別一覽
華為路由器X1/Pro發(fā)布,有朋友留言問(wèn)華為路由X1和X1 Pro怎么選擇,關(guān)于這個(gè)問(wèn)題,本期圖文將對(duì)這二款路由器做了期參數(shù)對(duì)比,大家看看哪款才是你的理想選擇2025-04-17路由器無(wú)法上網(wǎng)怎么辦? 四大常見(jiàn)問(wèn)題故障與解決方案
路由器安裝以后發(fā)現(xiàn)不能上網(wǎng),這可能是由于路由器未撥號(hào)、MAC地址綁定等原因所致,下面我們就來(lái)看看詳細(xì)解決辦法2025-04-09- 在現(xiàn)代生活中,路由器已成為我們工作和生活的必需品,然而,當(dāng)路由器出現(xiàn)問(wèn)題時(shí),我們往往束手無(wú)策,本文將為您提供一套實(shí)用的路由器故障排除指南,助您輕松應(yīng)對(duì)各種常見(jiàn)問(wèn)2025-04-09
支持觸屏的軟路由? GL.iNe BE3600路由器拆機(jī)評(píng)測(cè)
GL.iNet廣聯(lián)智通推出的Wi-Fi 7便攜式無(wú)線路由器Slate 7橫空出世,網(wǎng)速直接起飛!這速度,快到你懷疑人生!但問(wèn)題來(lái)了,這玩意兒真有那么神?詳細(xì)請(qǐng)看下文測(cè)評(píng)2025-03-31TPLINK TL7DR7260 v2.0和v1.0有什么區(qū)別? 兩款路由器拆機(jī)測(cè)評(píng)
TL-7DR7260易展版有兩個(gè)版本,分別是v2.0和v1.0,這兩個(gè)版本有什么區(qū)別?下面我們就來(lái)看看詳細(xì)的拆機(jī)對(duì)比2025-03-31CPU決定了不能給你10G口! TP-LINK TL-7DR7280路由器拆機(jī)測(cè)評(píng)
實(shí)力與顏值并存的TP-Link TL-7DR7280易展Turbo版以夠用問(wèn)準(zhǔn)則,是目前市面上好評(píng)非常多、用戶群體非常廣的一款無(wú)線路由器,性能穩(wěn)定,功能強(qiáng)悍,給你最可靠的網(wǎng)絡(luò)2025-03-31高性價(jià)比WiFi6路由+全屋覆蓋穿墻王! 網(wǎng)件RAX50路由器全面測(cè)評(píng)
網(wǎng)件RAX50路由器表現(xiàn)如何?確實(shí),它以穩(wěn)定高速的傳輸能力,讓無(wú)線連接體驗(yàn)變得輕松愉快,詳細(xì)測(cè)評(píng)數(shù)據(jù)如下圖文所述2025-03-15WiFi6時(shí)代來(lái)臨! 華三H3C NX54路由器還值得購(gòu)買嗎?
WiFi6時(shí)代已經(jīng)來(lái)臨,眾多路由器廠商也紛紛推出了兼容WiFi6協(xié)議的路由器,今天我們將深入體驗(yàn)H3C NX54路由器,這款由知名企業(yè)H3C新華三集團(tuán)推出的家用路由器2025-03-14游戲體驗(yàn)直接起飛! 實(shí)測(cè)這八款熱門電競(jìng)路由器型號(hào)值得推薦
玩游戲最怕什么?當(dāng)然是卡頓!延遲!關(guān)鍵時(shí)刻掉線簡(jiǎn)直心態(tài)爆炸,該怎么選電競(jìng)路由器呢?路由器這玩意兒,可不是越貴越好,適合自己的才是王道,下面我們推薦八款適合玩游戲2025-03-14FiberHome 5G CPE移動(dòng)路由器值得入手嗎? 烽火5g路由器性能測(cè)評(píng)
FiberHome烽火 5G CPE移動(dòng)路由器支持雙模4G/5G全網(wǎng)通,支持WiFi 6雙頻,配備雙千兆網(wǎng)口,無(wú)線速率高達(dá)1800Mbps,這款路由器性能如何?值得購(gòu)買嗎?詳細(xì)如下2025-03-14