《网络产品验收方案.docx》由会员分享,可在线阅读,更多相关《网络产品验收方案.docx(232页珍藏版)》请在得力文库 - 分享文档赚钱的网站上搜索。
1、网络产品验收方案活动 编码活动 名称活动内容角色输入输出盖章、报告签署日期、客户P。号、站点信 息等;5、签署人确认:客户签字人为合同规定证 书权签入;保证验收证书的有效性和真实 性。5文档 处理 和传1、收到验收证书后,确认证书的真实性和 有效性,对验收证书的双方签字人和验收证 书的内容进行再次检查和确认;工程文 档管理 员初验证 书原件 和相关 文档初验证 书原件2、工程文档管理员对初验证书原件进行复 印和扫描,原件在4个工作日内传递给财经 文档管理员;3、工程文档管理员按照文档管理规定对验 收证书复印件和扫描件以及相关文档进行 归档;4、将验收证书扫描件上载到工程交付IT 系统(系统或I
2、SITE);5、在无代表处文档管理员,或文档管理员 不负责处理验收证书的,由项目经理负责文 档处理与传递。6归档收到验收证书原件后,一个工作日内按照财 经文档管理要求对初验证书进行归档和传 递。财经文 档管理 员初验证 书原件初验证 书原件角色项目组执行人员验收经理/责任人项目组任命的项目验收经理/责任人验收申请人站点工程师/区域经理现场验收人员工程督导/站点工程师/客户验收负责人/分包商负责人验收证书签署人客户:CTO/CEO/客户授权的验收权签人:交付项目经理/工程经理/系统部交付副部长/交付副代表工程文档管理员项目组/代表处工程文档管理员财经文档管理员代表处财经文档管理员5.在Route
3、r上配置认证计费模板和域相关配置,并在域下引用dotlx模板。# 配置 Router。RouteraaaRouter-aaaauthentication-scheme huaweiRouter-aaa-authen-huaweiauthentication-mode radiusRouter-aaa-authen-huaweiquitRouter-aaaaccounting-scheme huaweiRouter-aaa-accounting-huaweiaccounting-mode radius Router-aaa-accounting-huaweiquit Router-aaadoma
4、in huaweiRouter-aaa-domain-huaweiauthentication-scheme huaweiRouter-aaa-domain-huaweiaccounting-scheme huaweiRouter-aaa-domain-huaweiradius-server group huaweiRouter-aaa-domain-huaweiip-pool huaweiRouter-aaa-domain-huaweidotlx-template 10Router-aaa-domain-huaweiquitRouter-aaaquit6.在Router上配置QINQ接口,外
5、层vlan为10,内层vlan为100,并且接入 类型为二层接入。# 配置 RouteroRouterinterface GigabitEthernetl/1/5.1Router-GigabitEthernetl/1/5.1user-vlan 100 qinq 10Router-GigabitEthernetl/1/5.l-vlan-100-100-QinQ-10-10basRouter-GigabitEthernetl/1/5.1-basaccess-type layer2-subscriberdefault-domain authentication huaweiRouter-Gigabi
6、tEthernetl/1/5.1-basauthentication-method dotlxRouter-GigabitEthernetl/1/5.1-basdefault-user-name-template huaweiRouter-GigabitEthernetl/1/5.1-basquitRouter-GigabitEthernetl/1/5.1quit7.酉己置 SwithcA 和 SwithcBo# 配置 SwithcA oHUAWE工system-viewHUAWEIsysname SwithcASwithcAvlan 100SwithcA-vlanlOOSwithcAinte
7、rface Ethernet2/0/lSwithcA-Ethernet2/0/lport default vlan 100SwithcAinterface Ethernet2/0/2SwithcA-Ethernet2/0/2port trunk allow-pass vlan 100#酉己置SwithcBosystem-viewHUAWEIsysname SwithcBSwithcBvlan 100SwithcB-vlanlOOquitSwithcBvlan 10SwithcB-vlanl0 quitSwithcBinterface GigabitEthernet2/0/1SwithcB-Gi
8、gabitEthernet2/0/lport trunk allow-pass vlan 100预期结果测试说明SwithcBinterface GigabitEthernet2/0/2 SwithcB-GigabitEthernet2/0/2 port vlan-stacking vlan 100 push vlan 10 outboundSwithcB-GigabitEthernet2/0/2port vlan-stacking pop vlan 10 inbound SwithcB-GigabitEthernet2/0/2port trunk allow-pass vlan 10 100
9、. PC通过dotlx拨号器,输入正确的用户名和密码,有预期结果2和3。8 .在Router上可以ping通上线用户,有预期结果4。1 .通过测试命令可以确定在Radius服务器预置的用户名和密码正确,有如下 结果:Routertest-aaa Routerhuawei huawei radius-group huaweiRouterInfo: Account test succeed!2 .用户上线成功,并正常访问网络资源。在Router和SwithcB之间进行抓包分 析,发现Router接收和发送给PC的报文打了 2层VLAN,外层是QinQ VLAN 10,内层是用户VLAN 100。3
10、 .在Router通过命令查看在线DHCP用户。Routerhuawei为用户名字, GE1/1/5.1为用户上线接口,为用户获取的IP地址, 0055-0101-0101为用户上线MAC地址。有如下结果:Routerdisplay access-user domain huaweiUserID UsernameInterface IP addressMACIPv6 address62 Routerhuawei GE1/1/5.10055-0101-0101Total users:14.在Router上可以Ping通上线用户,有如下结果:Routerping 192.168.1.3PING 1
11、92.168.1.3: 56 data bytes, press CTRL_C to breakReply from 192.168.1.3: bytes=56Sequence=l ttl=128 time=7 msReply from 192.168.1.3: bytes=56Sequence=2 ttl=128 time=2 msReply from 192.168.1.3: bytes=56Sequence=3 ttl=128 time=3 msReply from 192.168.1.3: bytes=56Sequence=4 ttl=128 time=2 msReply from 1
12、92.168.1.3: bytes=56Sequence=5 ttl=128 time=3 ms 192.168.1.3 ping statistics 5 packet(s) transmitted5 packet(s) received0.00% packet lossround-trip min/avg/max = 2/3/7 ms靠近用户侧的二层交换机上配置为用户VLAN,靠近Router侧的二层交换机上配置为QinQ VLANo内部编号T05-0901第六章MPLS验收1、MPLS LDP功能验4攵1.1 LDP本地会话基本功能验收验收目的LDP本地会话基本功能正常验收连接图编号预置
13、条件测试过程GE1/1/0RouterAGE1/1/0RouterB1.2.3.4.配置 RouterA 的 loopbackO 地址为 配置 RouterB 的 loopbackO 地址为 配置 RouterA 的接口 GE1/1/0 地址为 配置 RouterB 的接口 GE1/1/0 地址为 1. 各设备上配置IGP使得路由可达(以OSPF为例)# RouterA配置如下:RouterA ospf 1-RouterA-ospf-1 area 0RouterA-ospf-1-ara-0.0.0.0-RouterA-ospf-l-area-0.0.0.0-RouterA-ospf-l-are
14、a-0.0.0.0network 1.1.1.1 0.0.0.0 network 12.12.12.0 0.0.0.255 commit# RouterB配置如下:RouterB ospf 1-RouterB-ospf-l area 0RouterB-ospf-l-area-0.0.0.0 network 2.2.2.2 0.0.0.0 RouterB-ospf-l-area-0.0.0.0 network 12.12.12.0 0.0.0.255 -RouterB-ospf-l-area-0.0.0.0 commit2. RouterA 和 RouterB 上使能 MPLS、MPLS LDP
15、# RouterA配置如下:RouterA mplsRouterA-mpls commit-RouterA mpls IdpRouterA-mpls-ldp commit-RouterA interface gigabitethernet 1/1/0RouterA-GigabitEthernetl/l/0 mpls RouterA-GigabitEthernetl/l/0 mpls Idp RouterA-GigabitEthernetl/l/0 commit# RouterB配置如下:RouterB mpls Isr-id 2.2.2.2RouterB mpls-RouterB-mpls c
16、ommit RouterB mpls Idp -RouterB-mpls-ldp commit RouterB interface gigabitethernet 1/1/0 RouterB-GigabitEthernetl/l/0 mpls -RouterB-GigabitEthernetl/1/0 mpls Idp RouterB-GigabitEthernetl/l/0 commit3. 在 RouterA 上执行 display mpls Idp session 2.2.2.2, display mpls Idp peer 2.2.2.2,有预期结果(1)4. 在RouterA上执行p
17、ing Isp ip 2.2,22 32,有预期结果(2)预期结果1 .执行测试过程3之后,可以看到RouterA与RouterB建立LDP本地会话。LDPSession (s)inPublicNetworkPeer LDP ID: 2.2.2.2:0Local LDP ID:1.1.1.1: 0TCP Connection : 1.1.1.1 - 2.2.2.2 Session State: OperationalSession Role:PassiveLDP会话已建立成功Session FT Flag:OffMD5 Flag:OffReconnect Timer : Recovery Ti
18、mer :Keychain Name:P2MP Capability: OffMP2Mp Capability: OffNegotiated Keepalive Hold Timer : 45 Sec Configured Keepalive Send Timer : Keepalive Message Sent/Rcvd: 2/2 (Message Count)Label Advertisement Mode: Downstream UnsolicitedLabel Resource Status(Peer/Local) : Available/Available Session Age:
19、0000:00:00 (DDDD:HH:MM)Outbound Policies applied: NULLRouterA display mpls Idp peer 2.2.2.2 LDP Peer Information in Public networkPeer LDP ID: 2.2.2.2 : 0Peer Max PDU Length : 4096Peer Loop Detection : OffPeer Path Vector Limit :Peer FT Flag: OffPeer Keepalive Timer : 45 SecRecovery Timer: 300 SecRe
20、connect Timer: 300 SecPeer Type: Local建立的是本地会话Peer Label Advertisement Mode : Downstream UnsolicitedDistributedID: 0Peer Discovery Source: GigabitEthernetl/1/0发现端为直连链路,即建立的是本地会话2.执行测试过程4之后,可以看到RouterA可以ping通RouterB的LSP。RouterA ping lsp ip 2.2.2.2 32LSP PING FEC: IPV4 PREFIX 2.2.2.2/32 : 100 data byt
21、es, press CTRL_C to breakReplyfrom2.2.2.2:bytes=100Sequence=ltime=7msReplyfrom2.2.2.2:bytes=100Sequence=2time=5msReplyfrom2.2.2.2:bytes=100Sequence=3time=5msReplyfrom2.2.2.2:bytes=100Sequence=4time=5msReplyfrom2.2.2.2:bytes=100Sequence=5time=4ms 5 packet(s) transmitted5 packet(s) received0.00% packe
22、t lossround-trip min/avg/max = 4/5/7 ms测试说明无内口 B编rT09-01012、MPLS TE功能验收2.1 MPLS TE显示路径功能验收验收目的验证MPLS TE Tunnel显示路径功能正常LoopbackO1. 1. 1. 1/32LoopbackO 2. 2. 2. 2/32预置条件RouterA关RouterB验收连接图编号测试过程 1.在各设备上分别进入直连接口和LoopbackO接口视图,然后配置相应的IP地址。2. 在各设备链路上创建子接口,然后配置相应的子接口地址。# RouterA:RouterA interface Gigabit
23、Ethernetl/1/0.1 -RouterA-GigabitEthernet1/0/0.1 vlan-type dotlq 1 RouterA-GigabitEthernetl/0/0.1 ip address 12.12.2.1 24 -RouterA-GigabitEthernet1/0/0.1 commitRouterB:RouterB interface GigabitEthernetl/0/0.1 RouterB-GigabitEthernet1/0/0.1 vlan-type dotlq 1 RouterB-GigabitEthernetl/0/0.1 ip address 1
24、2.12.2.2 24 RouterB-GigabitEthernet1/0/0.1 commit3. 在各设备上配置ISIS协议,并在所有接口下使能ISIS。# RouterA:RouterA isis 1RouterA-isis-1 cost-style wide RouterA-isis-l network-entity 01.0000.0000.0001.00 RouterA-isis-l traffic-eng -RouterA-isis-1 commit bRouterA interface LoopBack 0 RouterA-LoopBackO isis enable 1 -R
25、outerA-LoopBackO commit RouterA interface GigabitEthernetl/0/0 RouterA-GigabitEthernet1/0/0 isis enable 1 -RouterA-GigabitEthernetl/0/0 commit RouterA interface GigabitEthernetl/0/0.1 -RouterA-GigabitEthernetl/0/0.1 isis enable 1 -RouterA-GigabitEthernet1/0/0.1 commit# RouterB:-RouterB isis 1 -Route
26、rB-isis-1 cost-style wide RouterB-isis-1 network-entity 01.0000.0000.0002.00 RouterB-isis-1 traffic-eng RouterB-isis-l commit -RouterB interface LoopBack 0 RouterB-LoopBackO isis enable 1 -RouterB-LoopBackO commit 卜RouterB interface GigabitEthernetl/0/0 RouterB-GigabitEthernet1/0/0 isis enable 1 Rou
27、terB-GigabitEthernetl/0/0 commit bRouterB interface GigabitEthernetl/0/0.1 RouterB-GigabitEthernet1/0/0.1 isis enable 1 RouterB-GigabitEthernetl/0/0.1 commit4. 在各设备上系统视图卜配置MPLS、MPLS TE. MPLS RSVP-TEo .# RouterA:-RouterA mpls Isr-id 1.1.1.1 RouterA mpls RouterA-mpls mpls te RouterA-mpls mpls rsvp-te
28、-RouterA-mpls mpls te cspf -RouterA-mpls commit# RouterB:-RouterB mpls Isr-id 2.2.2.2 RouterB mpls RouterB-mpls mpls te RouterB-mpls mpls rsvp-te RouterB-mpls mpls te cspf RouterB-mpls commit5. 在各设备各链路接口下使能MPLS、MPLSTE、MPLS RSVP-TEo# RouterA:RouterA interface GigabitEthernetl/0/0RouterA-GigabitEthern
29、etl/0/0 mplsRouterA-GigabitEthernetl/0/0 mpls teRouterA-GigabitEthernet1/0/0 mpls rsvp-te -RouterA-GigabitEthernetl/O/O commit RouterA interface GigabitEthernetl/0/0.1 RouterA-GigabitEthernet1/0/0.1 mpls -RouterA-GigabitEthernetl/0/0.1 mpls teRouterA-GigabitEthernetl/0/0.1 mpls rsvp-te -RouterA-Giga
30、bitEthernet1/0/0.1 commit# RouterB:-RouterB interface GigabitEthernetl/0/0 -RouterB-GigabitEthernetl/0/0 mpls RouterB-GigabitEthernet1/0/0 mpls te -RouterB-GigabitEthernet1/0/0 mpls rsvp-te RouterB-GigabitEthernetl/0/0 commit -RouterB interface GigabitEthernetl/0/0.1 -RouterB-GigabitEthernet1/0/0.1
31、mpls -RouterB-GigabitEthernetl/0/0.1 mpls te RouterB-GigabitEthernetl/0/0.1 mpls rsvp-te RouterB-GigabitEthernetl/0/0.1 commit6. 在RouterA上配置一条名为test的显式路径。# RouterA:RouterAexplicit-path test -RouterA-explicit-path-testnext hop 12.12.2.2 RouterA-explicit-path-testcommit7. 在RouterA上配置一条TE Tunnel,目的地址为R
32、outerB的LSR-ID,配置显 示路径test,有预期结果(1)o# RouterA:RouterA interface Tunnel 0/1/1 -RouterA-TunnelO/l/l ip address unnumbered interface LoopBack 0 -RouterA-TunnelO/1/1 tunnel-protocol mpls te RouterA-TunnelO/l/l destination 2.2.2.2 RouterA-TunnelO/l/l mpls te tunnel-id 1 -RouterA-TunnelO/1/1 mpls te path e
33、xplicit-path test -RouterA-TunnelO/1/1 commit8. 在 RouterA 上执行 tracert Isp te Tunnel 0/1/1 命令,有预期结果(2)。预期结果1.执行测试过程7之后,可以看到隧道Tunnel0/1/1可以UP,且引用了显示路径。 RouterA display mpls te tunnel-interface Tunnel 0/1/1 Tunnel Name:Tunnel0/l/lSignalled Tunnel Name:- Tunnel StateDesc:CR-LSPis UpTunnel Attributes:Act
34、ive LSP:PrimaryLSPTraffic Switch: -Session ID: 1Ingress LSR IDAdmin State: UPOper State : UPSignaling Protocol : RSVP FTid: 1Tie-Breaking Policy :NoneMetric Type : NoneBfd Cap:NoneReopt:DisabledReopt Freq :-Auto BW:DisabledThreshold:-Current Collected BW:Auto BW Freq :-Min BW 一 *Max BW:-Offload:Disa
35、bledOffload Freq : -Low Value:High Value :-Readjust Value:Offload Explicit Path Name: -Tunnel Group:-Interfaces Protected: -Excluded IP Address :-Referred LSP Count:0Primary Tunnel:-Backup Tunnel:-Group Status:-IPTN InLabel:-Backup Type:NoneSecondary HopLimit :32BestEffort HopLimit :32Pri Tunn Sum :
36、-Oam Status :-BestEffortDisabledSecondary Explicit Path Name:-Secondary Affinity Prop/Mask:OxO/OxOBestEffort Affinity Prop/Mask: OxO/OxO IsConfigLspConstraint: No Hot-Standby Revertive Mode: Revertive Hot-Standby Overlap-path: Disabled Hot-Standby Switch State: CLEAR Bit Error Detection: DisabledBit
37、 Error Detection Switch Threshold: Bit Error Detection Resume Threshold:Primary LSP ID LSP StateSetup Priority IncludeAll IncludeAny ExcludeAnyAffinity Prop/Mask1.1.1.1:1UP70x00x00x0OxO/OxOLSP Type : PrimaryHold Priority:7Resv Style : SECTOBandwidth(Kbit/sec)0CT1Bandwidth(Kbit/sec)0CT2Bandwidth(Kbit
38、/sec)0CT3Bandwidth(Kbit/sec)0CT4Bandwidth(Kbit/sec)0CT5Bandwidth(Kbit/sec)0CT6Bandwidth(Kbit/sec)0CT7Bandwidth(Kbit/sec)0Actual Bandwidth InformationCTOBandwidth(Kbit/sec)0CT1Bandwidth(Kbit/sec)0CT2Bandwidth(Kbit/sec)0CT3Bandwidth(Kbit/sec)0CT4Bandwidth(Kbit/sec)0CT5Bandwidth(Kbit/sec)0CT6Bandwidth(
39、Kbit/sec)0CT7Bandwidth(Kbit/sec)0Configured Bandwidth InformationHop Limit :32Explicit Path Name Record Route Route Pinning FRR Flag IdleTime RemaintestDisabledDisabledDisabledRecord Label : DisabledBFD Status2.执行测试过程8之后,可以看至U隧道TunnelO/1/1的路径为选定的路径。 RouterA tracert isp te Tunnel 0/1/1LSP Trace Route
40、 FEC: TE TUNNEL IPV4 SESSION QUERY TunnelO/1/1 , press CTRL_C to break.TTLReplierTimeTypeDownstream0Ingress 12.12.2.2/3 116 msEgress测试说明1、设置MPLSLSR-ID时,注意采用LoopbackO的IP地址。内部编号T09-02012.2 ISISTE基本功能验收验收目的IS-ISTE基本功能正常验收连接图编号LoopbackOLoopbackO1. 1. 1. 1/322. 2. 2. 2/32|GE1/0/0GE1/0/0 |15. 1. 1. 1/2415
41、. 1. 1_RouterARouterB预置条件无测试过程1. RouterA和RouterB上配置全局MPLSTE,并使能接口下的MPLSTE功能; # 配置 RouterARouterA mpls lsr-id 1.1.1.1 -RouterA mpls Info: Mpls starting, please wait. OK! RouterA-mpls mpls te-RouterA-mpls mpls rsvp-te RouterA-mpls mpls te cspf RouterA-mplscommit Committing please wait done . Commit su
42、ccess.-RouterA-mplsquit -RouterA interface GigabitEthernet 1/0/0 RouterA-GigabitEthernetl/0/0 mpls RouterA-GigabitEthernet1/0/0 mpls te -RouterA-GigabitEthernet1/0/0 mpls rsvp-te RouterA-GigabitEthernetl/0/0commit Committing, please wait done . Commit success.-RouterA-GigabitEthernet1/0/0quit # 配置 R
43、outerBRouterB mpls lsr-id 2.2.2.2 -RouterB mpls试运行网络设备实际运行的质量是检验设备最直接的标志,因此试运行期间所发生的硬件和软 件故障都要有记录,以便考核网络设备的工作是否稳定可靠。试运行期一般为三个月。工程终验工程终验是在设备试运行三个月期间,检验工程初验阶段的遗留问题是否得到解决,检 查试运行期是否有新的问题出现,如工程终验不合格,由双方商定重新确定试运行时限,并 重新进行工程终验,终验合格后,填写终验报告,并发给工程竣工验收证书。工程终验后设 备即可投入正式运营。Info: Mpls starting, please wait. OK!
44、RouterB-mpls mpls te RouterB-mpls mpls rsvp-te -RouterB-mpls mpls te cspf -RouterB-mplscommit Committing, please wait done . Commit success. -RouterB-mplsquit -RouterB interface GigabitEthernet 1/0/0 -RouterB-GigabitEthernetl/0/0 mpls -RouterB-GigabitEthernetl/0/0 mpls te RouterB-GigabitEthernetl/0/
45、0 mpls rsvp-te RouterB-GigabitEthernetl/0/0commit Committing please wait done . Commit success.RouterB-GigabitEthernetl/0/0quit在RouterA和RouterB上均创建ISIS进程1,配置不同的Network-Entity, 配置 Cost-Style 为 Wide,配置 Traffic-Eng 为 Level-1-2;# 配置 RouterARouterA isis 1 RouterA-isis-l network-entity 10.0000.0000.0001.00 -RouterA-isis-lcost-style wide Info: Cost style Changed. IS-IS process 1 will be reset. -RouterA-isis-l traffic-eng level-1-2 RouterA-isisTc
限制150内