Cisco ACE实验拓扑图如下:
Cisco ACE配置real server:
- ACE_4710/Admin#config t
- ACE_4710/Admin(config) # rserver name pc1
- ACE_4710/Admin(config-rserver-host) # inservice
- ACE_4710/Admin(config-rserver-host) # ip add 192.168.100.7
- ACE_4710/Admin(config-rserver-host) # rserver name pc2
- ACE_4710/Admin(config-rserver-host) # inservice
- ACE_4710/Admin(config-rserver-host) # ip add 192.168.100.8
Cisco ACE配置server farm:
- ACE_4710/Admin(config) # serverfarm farm
- ACE_4710/Admin(config-sfarm-host) # rserver pc1
- ACE_4710/Admin(config-sfarm-host-rs) # inservice
- ACE_4710/Admin(config-sfarm-host-rs) # exit
- ACE_4710/Admin(config-sfarm-host) # rserver pc2
- ACE_4710/Admin(config-sfarm-host-rs) # inservice
- ACE_4710/Admin(config-sfarm-host-rs) # exit
Cisco ACE配置 class-map:
- ACE_4710/Admin(config) # class-map type VIP
- ACE_4710/Admin(config-cmap) # match virtual-address 172.16.5.100 tcp eq www
- ACE_4710/Admin(config-cmap) # exit
Cisco ACE配置policy-map:
- ACE_4710/Admin(config) # poliey-map type loadbalance first-match LB
- ACE_4710/Admin(config-pamp-lb-c) # class class-default
- ACE_4710/Admin(config-pamp-lb-c) # serverfarm farm
- ACE_4710/Admin(config-pamp-lb-c) # exit
- ACE_4710/Admin(config-pamp-lb) # exit
- ACE_4710/Admin(config) # policy-map multi-match police
- ACE_4710/Admin(config-pamp) # class VIP
- ACE_4710/Admin(config-pamp-c)# loadbalance police LB
- ACE_4710/Admin(config-pamp-c)# loadbalance VIP inservice
- ACE_4710/Admin(config-pamp-c)#exit
- Apply the Policy-map :
- ACE_4710/Admin(config-if) # int vlan 100
- ACE_4710/Admin(config-if) # service-policy input police
- ACE_4710/Admin(config-if) # access-group input cisco
Cisco ACE配置访问控制列表:
- ACE_4710/Admin(config)# access-list cisco ex per tcp any any eq www
Cisco ACE配置NAT:
- ACE_4710/Admin(config)# class-map NAT
- ACE_4710/Admin(config-cmap)# match source-address 192.168.100.7 255.255.255.255
- ACE_4710/Admin(config-cmap)# exit
- ACE_4710/Admin(config)# policy-map multi-match NAT
- ACE_4710/Admin(config-cmap)# class NAT
- ACE_4710/Admin(config-cmap-c)# nat static 172.16.5.101 255.255.255.255 clan 100
- ACE_4710/Admin(config-cmap-c)# exit
- ACE_4710/Admin(config-cmap)# class NAT2
- ACE_4710/Admin(config-cmap)# match source-address 192.168.100.8 255.255.255.255
- ACE_4710/Admin(config-cmap)# exit
- ACE_4710/Admin(config)#policy-map multi-match NAT
- ACE_4710/Admin(config)# nat sta 172.16.5.102 netmask 255.255.255.255
- ACE_4710/Admin(config-cmap-c)# exit
- ACE_4710/Admin(config)#int vlan 200
- ACE_4710/Admin(config)#service-poliey intput NAT
- show run:
- switch/Admin# sh run
- Generating configuration....
- boot system image:c4710ace-mz.A3_2_4.bin
- boot system image:c4710ace-mz.A1_8_0a.bin
- interface gigabitEthernet 1/1
- description outside
- switchport trunk allowed vlan 1-100
- no shutdown
- interface gigabitEthernet 1/2
- description inside
- switchport trunk allowed vlan 101-200
- no shutdown
- interface gigabitEthernet 1/3
- description man
- switchport trunk allowed vlan 300
- no shutdown
- interface gigabitEthernet 1/4
- shutdown
- access-list cisco line 8 extended permit tcp any any eq www
- rserver host pc1
- ip address 192.168.100.7
- inservice
- rserver host pc2
- ip address 192.168.100.8
- inservice
- serverfarm host farm
- rserver pc1
- inservice
- rserver pc2
- inservice
- class-map match-all NAT
- 2 match source-address 192.168.100.7 255.255.255.255
- class-map match-all NAT2
- 2 match source-address 192.168.100.8 255.255.255.255
- class-map match-all VIP
- 2 match virtual-address 172.16.5.100 tcp eq www
- class-map type management match-any mana
- 2 match protocol icmp any
- 3 match protocol http any
- 4 match protocol https any
- 5 match protocol telnet any
- policy-map type management first-match mana
- class mana
- permit
- policy-map type loadbalance first-match LB
- class class-default
- serverfarm farm
- policy-map multi-match NAT
- class NAT
- nat static 172.16.5.101 netmask 255.255.255.255 vlan 100
- class NAT2
- nat static 172.16.5.102 netmask 255.255.255.255 vlan 100
- policy-map multi-match police
- class VIP
- loadbalance vip inservice
- loadbalance policy LB
- interface vlan 100
- ip address 172.16.5.2 255.255.255.0
- access-group input cisco
- service-policy input mana
- service-policy input police
- no shutdown
- interface vlan 200
- ip address 192.168.100.1 255.255.255.0
- access-group input cisco
- service-policy input mana
- service-policy input NAT
- no shutdown
- interface vlan 300
- ip address 172.16.100.1 255.255.255.0
- access-group input cisco
- service-policy input mana
- no shutdown
- ip route 0.0.0.0 0.0.0.0 172.16.5.1
- username admin password 5 $1$PsF96z9m$UxEgWiRsv9YIPhstoL7pc. role Admin domain
- default-domain
- username www password 5 $1$.TuZPVop$MdVtkf9pZt69AGKe2y2Wg0 role Admin domain de
- fault-domain
Cisco ACE负载的配置的过程就为大家介绍完了,希望大家按照上面的步骤能够成功实现,关于Cisco ACE的其他配置请读者阅读:
Cisco ACE的基本配置实例、Cisco ACE路由器和交换机的配置实例
【编辑推荐】