|
这个需要让集成商或是厂家的工程师给你调,从技术上来说部署有点复杂,但是并不难。
我的方案是启两个虚拟机跑两个爱快,每个虚机给两个虚拟网卡(以eth1,eth2来举例)。以vmware sphere为例,设置两个不同的虚拟交换机端口组(比如把eth1划到vlan10里,eth划到vlan20里),物理适配器设成thunk口,选择一个高端一点的三层交换机(比如华为5700-ei或是hi或是更好的),vlan10设为外网网段,vlan20设为内网转发网段,所有内网网关启在交换机上。不用做默认静态路由,做策略路由,应用在vlan上。策略路由可以实现热备功能。
目前这个主要的缺点是故障后热备切换速度慢,不是无感知切换,大概5分钟以内,而且网络性能受虚拟机影响。
这是我之前做项目成功的一个案例,下为华为s7703部分配置代码。
#
acl number 3001
rule 5 permit ip source 10.47.32.0 0.0.0.255
acl number 3002
rule 5 permit ip source 10.47.34.0 0.0.0.255
rule 10 permit ip source 10.47.36.0 0.0.0.255
acl number 3003
rule 5 permit ip source 10.47.35.0 0.0.0.255
rule 10 permit ip source 10.47.33.0 0.0.0.255
rule 15 permit ip source 10.47.26.0 0.0.0.255
#
traffic classifier c1 operator or precedence 5
if-match acl 3001
traffic classifier c2 operator or precedence 10
if-match acl 3002
traffic classifier c3 operator or precedence 15
if-match acl 3003
#
traffic behavior b1
permit
redirect ip-nexthop 172.16.254.2 172.16.254.3 172.16.254.4 low-precedence
traffic behavior b2
permit
redirect ip-nexthop 172.16.254.3 172.16.254.4 172.16.254.2 low-precedence
traffic behavior b3
permit
redirect ip-nexthop 172.16.254.4 172.16.254.3 172.16.254.2 low-precedence
#
traffic policy p1 match-order auto
classifier c1 behavior b1
classifier c2 behavior b2
classifier c3 behavior b3
#
drop-profile default
#
vlan 60
description s7703_to_xiaoyuanwang
vlan 1026
description Manager
traffic-policy p1 inbound
vlan 1027
description Room_Hall_Thin_PC
vlan 1028
description Room_1112_Thin_PC
vlan 1029
description Room_1208_Thin_PC
vlan 1030
description Room_1209_Thin_PC
vlan 1031
description Room_1215__Thin_PC
vlan 1032
description Room_Hall_VM
traffic-policy p1 inbound
vlan 1033
description Room_1112_VM
traffic-policy p1 inbound
vlan 1034
description Room_1208_VM
traffic-policy p1 inbound
vlan 1035
description Room_1209_VM
traffic-policy p1 inbound
vlan 1036
description Room_1215_VM
traffic-policy p1 inbound
# |
|