3560 vlan + 限速

Switch#show run
Building configuration...

Current configuration : 11439 bytes
!
version 12.2
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname Switch
!
boot-start-marker
boot-end-marker
!
enable secret 5 $1$VsBf$po4Bcn4/yKlM2G0duTCC10
enable password cisco
!
username cisco password 0 cisco
no aaa new-model
system mtu routing 1500
ip subnet-zero
ip routing
ip dhcp excluded-address 192.168.0.1
ip dhcp excluded-address 192.168.0.123
ip dhcp excluded-address 192.168.0.74
ip dhcp excluded-address 192.168.0.111
ip dhcp excluded-address 192.168.3.111
ip dhcp excluded-address 192.168.3.150
ip dhcp excluded-address 192.168.3.50
ip dhcp excluded-address 192.168.6.150
ip dhcp excluded-address 192.168.6.180
ip dhcp excluded-address 192.168.6.50
!
ip dhcp pool vlan600
network 192.168.6.0 255.255.255.0
default-router 192.168.6.1
dns-server 192.168.8.200 210.5.153.250
netbios-name-server 192.168.8.200
lease 7
!
ip dhcp pool vlan300
network 192.168.3.0 255.255.255.0
default-router 192.168.3.1
dns-server 192.168.8.200 210.5.153.250
netbios-name-server 192.168.8.200
lease 7
!
ip dhcp pool vlan400
network 192.168.4.0 255.255.255.0
default-router 192.168.4.1
dns-server 192.168.8.200 210.5.153.250
netbios-name-server 192.168.8.200
lease 7
!
ip dhcp pool nancy
host 192.168.6.181 255.255.255.0
client-identifier 000f.1f5b.74b7
!
ip dhcp pool vlan700
network 192.168.7.0 255.255.255.0
default-router 192.168.7.1
dns-server 192.168.8.200 210.5.153.250
netbios-name-server 192.168.8.200
lease 7
!
ip dhcp pool rock
host 192.168.7.4 255.255.255.0
client-identifier 0016.ecb3.512e
!
ip dhcp pool vlan10
network 192.168.0.0 255.255.255.0
default-router 192.168.0.254
dns-server 192.168.8.200 210.5.153.250
netbios-name-server 192.168.8.200
lease 7
!
ip dhcp pool aquarium
host 192.168.3.104 255.255.255.0
client-identifier 0100.e04f.282b.74
!
ip dhcp pool clare
host 192.168.3.102 255.255.255.0
client-identifier 0100.1a6b.582c.ae
!
ip dhcp pool hunter
host 192.168.3.101 255.255.255.0
client-identifier 0100.16ec.adf2.e3
!
ip dhcp pool kinn
host 192.168.5.108 255.255.255.0
client-identifier 2c81.58e1.bd29
!
ip dhcp pool vlan500
network 192.168.5.0 255.255.255.0
default-router 192.168.5.1
dns-server 192.168.8.200 210.5.153.250
netbios-name-server 192.168.8.200
lease 7
!
ip dhcp pool vlan900
network 192.168.9.0 255.255.255.0
default-router 192.168.9.1
dns-server 192.168.8.200 210.5.153.250
lease 7
!
ip dhcp pool alin
host 192.168.5.106 255.255.255.0
client-identifier c417.fe13.5d2c
!
!
mls qos
!
crypto pki trustpoint TP-self-signed-1588244224
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1588244224
revocation-check none
r

sakeypair TP-self-signed-1588244224
!
!
crypto pki certificate chain TP-self-signed-1588244224
certificate self-signed 01
3082023F 308201A8 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31353838 32343432 3234301E 170D3933 30333031 30303030
35315A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 35383832
34343232 3430819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100AA22 61AB9D39 287F4A9E A1117BF3 BDCCE11D 9740A290 C58D0D58 DD90D577
E22AE098 1BA46307 77F1E251 94E7FB9B D8996614 5FD557AE 98E10C70 7485C218
124147B4 1C352DB2 3537C8F0 7E5135FC 9ECEB4C2 E7B6D049 4FFE573E 87EF612E
DAC7B041 CC62276F 2E92D5EB D7FB4BEA DF6B4E28 4798562F 3B8513E2 A7812D8D
EC090203 010001A3 67306530 0F060355 1D130101 FF040530 030101FF 30120603
551D1104 0B300982 07537769 7463682E 301F0603 551D2304 18301680 140F8CBF
57F4C0AE 1AEC3A49 00AE9E7B DB2FC6A6 78301D06 03551D0E 04160414 0F8CBF57
F4C0AE1A EC3A4900 AE9E7BDB 2FC6A678 300D0609 2A864886 F70D0101 04050003
8181009C C3432CFA E8A0E81C 830C5B9C A7327581 4485FD5E CBCEE378 68B68F5D
99EE88D5 C20A5012 0E537810 3A8E010A 64D9B12A 3B72C3F5 A6B03EDA 6F2B15B1
19C7E99B E580CFA2 5C1F73AA 3D2722F4 948EEC90 4830503D CB6D914D 25FB9F35
4591B8F8 C68D07CC CDEF8A84 6B12118E CE71327A C263F343 2B22256E 0593C283 18EFA0
quit
!
!
!
!
!
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
!
class-map match-all down2
match access-group name down2
class-map match-all down3
match access-group name down3
class-map match-all down0
match access-group name down0
class-map match-all down6
match access-group name down6
class-map match-all down7
match access-group name down7
class-map match-all down4
match access-group name down4
class-map match-all down5
match access-group name down5
class-map match-all down8
match access-group name down8
class-map match-all down9
match access-group name down9
class-map match-all up1
match access-group name up1
class-map match-all up2
match access-group name up2
!
!
policy-map down
class down0
police 512000 32000 exceed-action drop
class down2
police 512000 32000 exceed-action drop
class down3
police 1024000 64000 exceed-action drop
class down4
police 512000 32000 exceed-action drop
class down5
police 1024000 64000 exceed-action drop
class down6
police 1024000 64000 exceed-action drop
class down7
police 512000 32000 exceed-action drop
class down9
police 256000 16000 exceed-action drop
policy-map up1
class up1
police 1024000 64000 exceed-action drop
policy-map up2
class up2
police 512000 32000 exceed-action drop
!
!
!
!
interface FastEthernet0/1
switchport access vlan 600
switchport mode access
service

-policy input up2
!
interface FastEthernet0/2
switchport access vlan 10
switchport mode access
service-policy input up2
!
interface FastEthernet0/3
switchport access vlan 600
switchport mode access
service-policy input up1
!
interface FastEthernet0/4
switchport access vlan 600
switchport mode access
service-policy input up2
!
interface FastEthernet0/5
switchport access vlan 600
switchport mode access
service-policy input up2
!
interface FastEthernet0/6
switchport access vlan 600
switchport mode access
service-policy input up2
!
interface FastEthernet0/7
switchport access vlan 600
switchport mode access
service-policy input up2
!
interface FastEthernet0/8
switchport access vlan 600
switchport mode access
service-policy input up2
!
interface FastEthernet0/9
switchport access vlan 600
switchport mode access
service-policy input up2
!
interface FastEthernet0/10
switchport access vlan 600
switchport mode access
service-policy input up2
!
interface FastEthernet0/11
switchport access vlan 900
switchport mode access
service-policy input up2
!
interface FastEthernet0/12
switchport access vlan 900
switchport mode access
service-policy input up2
!
interface FastEthernet0/13
switchport access vlan 300
switchport mode access
service-policy input up1
!
interface FastEthernet0/14
switchport access vlan 400
switchport mode access
service-policy input up2
!
interface FastEthernet0/15
switchport access vlan 500
switchport mode access
service-policy input up1
!
interface FastEthernet0/16
switchport access vlan 600
switchport mode access
service-policy input up1
!
interface FastEthernet0/17
switchport access vlan 700
switchport mode access
service-policy input up2
!
interface FastEthernet0/18
switchport access vlan 800
switchport mode access
service-policy input up2
!
interface FastEthernet0/19
switchport access vlan 700
switchport mode access
service-policy input up2
!
interface FastEthernet0/20
switchport access vlan 800
switchport mode access
service-policy input up2
!
interface FastEthernet0/21
switchport access vlan 700
switchport mode access
service-policy input up2
!
interface FastEthernet0/22
switchport access vlan 10
switchport mode access
service-policy input up2
!
interface FastEthernet0/23
no switchport
ip address 192.168.2.2 255.255.255.0
service-policy input down
!
interface FastEthernet0/24
switchport access vlan 10
switchport mode access
service-policy input up2
!
interface GigabitEthernet0/1
switchport access vlan 10
switchport mode access
service-policy input up2
!
interface GigabitEthernet0/2
switchport access vlan 800
switchport mode access
!
interface Vlan1
no ip address
shutdown
!
interface Vlan10
ip address 192.168.0.254 255.255.255.0
rate-limit input 512000 1500 2000 conform-action transmit exceed-action drop
rate-li

mit output 512000 1500 2000 conform-action transmit exceed-action drop
!
interface Vlan100
no ip address
!
interface Vlan200
no ip address
!
interface Vlan300
ip address 192.168.3.1 255.255.255.0
rate-limit input 1024000 64000 64000 conform-action transmit exceed-action drop
rate-limit output 1024000 64000 64000 conform-action transmit exceed-action drop
!
interface Vlan400
ip address 192.168.4.1 255.255.255.0
rate-limit input 512000 32000 32000 conform-action transmit exceed-action drop
rate-limit output 512000 32000 32000 conform-action transmit exceed-action drop
!
interface Vlan500
ip address 192.168.5.1 255.255.255.0
rate-limit input 1024000 64000 64000 conform-action transmit exceed-action drop
rate-limit output 1024000 64000 64000 conform-action transmit exceed-action drop
!
interface Vlan600
ip address 192.168.6.1 255.255.255.0
rate-limit input 1024000 64000 64000 conform-action transmit exceed-action drop
rate-limit output 1024000 64000 64000 conform-action transmit exceed-action drop
!
interface Vlan700
ip address 192.168.7.1 255.255.255.0
rate-limit input 512000 32000 32000 conform-action transmit exceed-action drop
rate-limit output 512000 32000 32000 conform-action transmit exceed-action drop
!
interface Vlan800
ip address 192.168.8.1 255.255.255.0
!
interface Vlan900
ip address 192.168.9.1 255.255.255.0
rate-limit input 256000 16000 16000 conform-action transmit exceed-action drop
rate-limit output 256000 16000 16000 conform-action transmit exceed-action drop
!
ip classless
ip route 0.0.0.0 0.0.0.0 192.168.2.1
ip http server
ip http secure-server
!
!
ip access-list extended down0
permit ip 192.168.0.0 0.0.0.255 any
permit ip any 192.168.0.0 0.0.0.255
ip access-list extended down2
permit ip any 192.168.2.0 0.0.0.255
permit ip 192.168.2.0 0.0.0.255 any
ip access-list extended down3
permit ip any 192.168.3.0 0.0.0.255
permit ip 192.168.3.0 0.0.0.255 any
ip access-list extended down4
permit ip any 192.168.4.0 0.0.0.255
permit ip 192.168.4.0 0.0.0.255 any
ip access-list extended down5
permit ip any 192.168.5.0 0.0.0.255
permit ip 192.168.5.0 0.0.0.255 any
ip access-list extended down6
permit ip any 192.168.6.0 0.0.0.255
permit ip 192.168.6.0 0.0.0.255 any
ip access-list extended down7
permit ip any 192.168.7.0 0.0.0.255
permit ip 192.168.7.0 0.0.0.255 any
ip access-list extended down8
permit ip any 192.168.8.0 0.0.0.255
permit ip 192.168.8.0 0.0.0.255 any
ip access-list extended down9
permit ip any 192.168.9.0 0.0.0.255
permit ip 192.168.9.0 0.0.0.255 any
ip access-list extended up1
deny ip any 192.168.0.0 0.0.255.255
permit ip any any
ip access-list extended up2
deny ip any 192.168.0.0 0.0.255.255
permit ip any any
!
access-list 100 permit ip any 192.168.0.0 0.0.0.255
!
control-plane
!
!
line con 0
line vty 0 4
password scfow
login
line vty 5 15
password scfow
login
!
end

相关文档
最新文档