华为交换机一些知识
华为PVID:Port Vlan ID,端口的虚拟局域网ID号,关系到端口收发数据帧时的VLAN TAG 标记。
修改命令:
<huawei>sy
[huawei]interface ethernet 0/0/9
[huawei-Ethernet0/0/9]port default vlan 1
====================
华为P2P限流:首先需要一个在flash里放置一个 protocol.rul 限流模板才可以是有下列命令(这个限流模板可以在华赛官方网站上下载的到)。
firewall mode transparent
firewall dpi pattern-file active
firewall dpi packet-number 48
firewall p2p-car include BT
firewall p2p-car include PPLIVE
firewall p2p-car include THUNDER
firewall p2p-car include EDEM
firewall p2p-car include FEIDIAN
firewall p2p-car include QQLIVE
firewall p2p-car include CCIPTV
firewall p2p-car include GNUTELLA
firewall p2p-car include KAZAA
firewall p2p-car include PPSTREAM
firewall p2p-car include COOLSTREAMING
firewall p2p-car include DC
firewall p2p-car include KUGOO
firewall p2p-car include ORINNOAVBT
firewall p2p-car include PPGOU
firewall p2p-car include POCO
firewall p2p-car include BAIBAO
firewall p2p-car include MAZE
firewall p2p-car include TVANTS
firewall p2p-car include UUSEE
firewall p2p-car include VAGAA
firewall p2p-car include BBSEE
firewall p2p-car include QQDOWNLOAD
firewall p2p-car include MYSEE
firewall p2p-car include FILETOPIA
firewall p2p-car include SOULSEEK
firewall p2p-car include SOPCAST
firewall p2p-car include TVU
firewall p2p-car include BEARSHARE
firewall p2p-car include KOOWO
firewall p2p-car include FENGXING
firewall p2p-car include PPFILM
firewall p2p-car include DOPOOL
firewall p2p-car include FLASHGET
firewall p2p-car include PP365
firewall p2p-car include BAIDUXIABA
firewall p2p-car include QINGYL
firewall p2p-car include FS2YOU
firewall p2p-car include TVKOO
firewall p2p-car include SPEEDYTUDOU
firewall p2p-car include PP365_DOWNLOAD
firewall p2p-car include QVOD
firewall p2p-car include SINATV
firewall p2p-car include HTTP_STREAMING
firewall p2p-car include HTTP_DOWNLOAD
firewall p2p-car default-permit
time-range daytime 00:00 to 20:00 daily
time-range night 20:00 to 24:00 daily
p2p-class 0
cir 10000 index 1 time-range daytime
cir 20000 index 2 time-range night
quit
这种限流模式是华为早期的一种P2P模式,protocol.rul P2P限流模板华为也不再更新,现在对一些P2P下载软件的限流效果不是很好,至少亲自测试对迅雷的限速不是很好。
关于迅雷限速的一些方法:
在P2P限流协议中没有勾选 HTTP_DOWNLOAD和HTTP_STREAMING 导致限流不完整
处理过程:
1、检查配置,ACL能够匹配并且在数据包统计里面也能看到丢弃了P2P的包,证明配置没有问题
2、将P2P限流协议里面添加了 HTTP_DOWNLOAD和HTTP_STREAMING 后,迅雷下载速度会下降很多,但是这么做的会导致普通的网页下载功能失效,导致是用IE之类的浏览器下载无法使用,既:下载没有任何速度。
firewall p2p-car include HTTP_STREAMING
firewall p2p-car include HTTP_DOWNLOAD
这2项应该根据实际情况谨慎使用。
现在华为改用一种数据库的模式来限制P2P端的速度,这种模式下较早生产的一些华为网关,防火墙设备是不支持的。
======================
TPID:Tag Protocol Identifier,标签协议标识
IEEE 802.1q协议规定该字段的取值为0x8100。
| 协议类型 | 对应取值 |
| ARP | 0x0806 |
| IP | 0x0800 |
| MPLS | 0x8847/0x8848 |
| IPX | 0x8137 |
| IS-IS | 0x8000 |
| LACP | 0x8809 |
| 802.1x | 0x888E |
=====================
daylight saving time:DST 夏令时
=====================
华为s2326交换机上行和下行的端口限速:
1)分类流
#traffic classifer c2326
if-match any
2)行为分类
#traffic behavior b2326
car cir 2048 cbs 204800
3)策略
#traffic policy p2326
classifier p2326 behavior b2326
4)下发策略
#interface E0/0/21
traffic-policy p2326 inbound
qos lr cir 2048 cbs 204800
最后一句是限制下行,之前是限制上行。
================
通用安全策略:
acl number 3001
rule 0 deny tcp source-port eq 3127
rule 1 deny tcp source-port eq 1025
rule 2 deny tcp source-port eq 5554
rule 3 deny tcp source-port eq 9996
rule 4 deny tcp source-port eq 1068
rule 7 deny tcp source-port eq 137
rule 8 deny udp source-port eq netbios-ns
rule 9 deny tcp source-port eq 138
rule 10 deny udp source-port eq netbios-dgm
rule 11 deny tcp source-port eq 139
rule 12 deny udp source-port eq netbios-ssn
rule 13 deny tcp source-port eq 593
rule 14 deny tcp source-port eq 4444
rule 15 deny tcp source-port eq 5800
rule 16 deny tcp source-port eq 5900
rule 18 deny tcp source-port eq 8998
rule 19 deny tcp source-port eq 445
rule 20 deny udp source-port eq 445
rule 21 deny udp source-port eq 1434
rule 30 deny tcp destination-port eq 3127
rule 31 deny tcp destination-port eq 1025
rule 32 deny tcp destination-port eq 5554
rule 33 deny tcp destination-port eq 9996
rule 34 deny tcp destination-port eq 1068
rule 35 deny tcp destination-port eq 135
rule 36 deny udp destination-port eq 135
rule 37 deny tcp destination-port eq 137
rule 38 deny udp destination-port eq netbios-ns
rule 39 deny tcp destination-port eq 138
rule 40 deny udp destination-port eq netbios-dgm
rule 41 deny tcp destination-port eq 139
rule 42 deny udp destination-port eq netbios-ssn
rule 43 deny tcp destination-port eq 593
rule 44 deny tcp destination-port eq 4444
rule 45 deny tcp destination-port eq 5800
rule 46 deny tcp destination-port eq 5900
rule 48 deny tcp destination-port eq 8998
rule 49 deny tcp destination-port eq 445
rule 50 deny udp destination-port eq 445
rule 51 deny udp destination-port eq 1434
rule 52 deny tcp destination-port eq 6969
rule 53 deny tcp source-port range 6881 6889
rule 54 deny tcp destination-port range 6881 6889
rule 55 deny tcp source-port eq 6969
===============================
**********
2012年06月11日 17时48分 百度空间:http://hi.baidu.com/sys0/
评论
发表评论