網絡拓撲結構(本次網絡爲有線、無線,因爲無線辦公流量較大,採用分流方式較好)網絡
配置說明須要作負載負擔,基於策略路由實現,使用默認路由可能產生出去丟包現象less
system-viewide
acl number 2000ui
description for_NAT-useblog
rule 0 permit ip source any
quit接口
acl number 3000ip
description for_Cable_Office_use路由
rule 0 permit ip source 192.168.10.0 0.0.0.255
quit
acl number 3001it
description for_Wireless_Office-useio
rule 0 permit ip source 10.100.2.0 0.0.0.255
rule 1 permit ip source 10.100.3.0 0.0.0.255
quit
traffic classifier c1
if-match acl 3000
traffic classifier c2
if-match acl 3001
quit
traffic behavior b1
redirect ip-nexthop 223.11.12.1
traffic behavior b2
redirect ip-nexthop 123.126.109.1
quit
traffic policy p1
classifier c1 behavior b1
classifier c2 behavior b2
quit
interface Ethernet0/0/0 #內網接口
traffic-policy p1 inbound
quit
interface Ethernet0/0/1 #內網接口
traffic-policy p1 inbound
quit
interface G0/0/0 #外網接口
nat outbound 2000
quit
interface G0/0/1 #外網接口
nat outbound 2000
quit
ip route-static 0.0.0.0 0 223.11.12.1 (當策略路由失效,能夠採用缺省路由出去)
ip route-static 0.0.0.0 0 123.126.109.1