【正文】
例如,輸入命令executeon slot 9 show ip cache verbose flow,輸出結(jié)果的部分內(nèi)容如下所示:SrcIf SrcIPaddress DstIf DstIPaddress Pr TOS Flgs PktsPort Msk AS Port Msk AS NextHop B/Pk ActiveGi9/0 AT3/ 06 88 10 1 01BB /24 0 0A91 /8 0 40 這表示有這樣一個數(shù)據(jù)流從Gi9/0口流入,從ATM3/,:源地址源端口目的地址目的端口TOS值dscp值是TOS值2進制的前6位01BB(16進制)443(10進制)0A91(16進制)2705(10進制)88(16進制)10001000(2進制)100010(2進制)34(10進制)show。其中slot number為連接數(shù)據(jù)中心Intranet接入交換機的端口所在槽位號。 配置ACL、classmap和policymap//實施時請確認以下的ACL是否包括了所有需要QoS保障的應(yīng)用//對于票據(jù)中心訪問票據(jù)分部的數(shù)據(jù)流也要進行分類和標(biāo)識ip accesslist extended Keypermit tcp any any eq 2065permit tcp any eq 2065 anyip accesslist extended Voice//對于電話銀行掛接分行的配置permit ip G700地址 any//對于非托管分行且沒有自己獨立關(guān)守的配置permit ip 分行漫游網(wǎng)關(guān)地址 any//對于非托管分行且有自己獨立關(guān)守的配置permit ip 分行漫游網(wǎng)關(guān)地址 anypermit ip 分行獨立關(guān)守地址 anyip accesslist extended Videopermit ip ……ip accesslist extended Interactivepermit ip any permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any host permit ip any host permit ip any host permit ip any host permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any //實時的監(jiān)控事件permit ip any 目的IP地址 ip accesslist extended Batchpermit ip any permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any permit ip any ip accesslist extended OApermit ip any permit ip any permit ip any permit tcp any any eq 1352permit tcp any eq 1352 anypermit ip any any permit ip any any permit ip any any classmap matchany Keyapplicationmatch accessgroup Keyclassmap matchany Voiceapplicationmatch accessgroup Voiceclassmap matchany Videoapplicationmatch accessgroup Videoclassmap matchany Interactiveapplicationmatch accessgroup Interactiveclassmap matchany Batchapplicationmatch accessgroup Batch classmap matchany OAapplicationmatch accessgroup OApolicymap SETDSCPclass Keyapplicationset dscp 46class Voiceapplicationset dscp 34class Videoapplicationset dscp 36class Interactiveapplicationset dscp 26class Batchapplicationset dscp 18class OAapplicationset dscp 10class classdefaultset dscp 0216。 啟用QoSmls qos或qos216。 將定義的Policy應(yīng)用到連接票據(jù)中心路由器的端口上:interface GigabitEthernet7/19 //連接票據(jù)中心路由器 servicepolicy output SETDSCP216。216。使用Native IOS版本的交換機在數(shù)據(jù)中心數(shù)據(jù)流離開Intranet接入交換機時設(shè)置dscp值。 配置ACL://實施時請確認以下的ACL是否包括了所有需要QoS保障的應(yīng)用set qos acl ip SETDSCP dscp 36 ip anyset qos acl ip SETDSCP dscp 38 ip any……set qos acl ip SETDSCP dscp 26 ip any set qos acl ip SETDSCP dscp 26 ip any //實時的監(jiān)控事件set qos acl ip SETDSCP dscp 26 ip any 目的IP地址 set qos acl ip SETDSCP dscp 10 ip any host set qos acl ip SETDSCP dscp 10 ip any host set qos acl ip SETDSCP dscp 10 ip any host set qos acl ip SETDSCP dscp 10 ip any host 216。 在Intranet接入交換機其余端口上配置命令:set port qos mod/port vlanbased216。 啟用QoS:set qos enable216。使用CatOS版本的交換機在數(shù)據(jù)中心數(shù)據(jù)流進入Intranet接入交換機時設(shè)置dscp值,使用Native IOS版本的交換機在數(shù)據(jù)中心數(shù)據(jù)流離開Intranet接入交換機時設(shè)置dscp值。 配置ACL://實施時請確認以下的ACL是否包括了所有需要QoS保障的應(yīng)用set qos acl ip SETDSCP dscp 34 ip anyset qos acl ip SETDSCP dscp 36 ip anyset qos acl ip SETDSCP dscp 38 ip any……set qos acl ip SETDSCP dscp 26 ip any set qos acl ip SETDSCP dscp 26 ip any //實時的監(jiān)控事件set qos acl ip SETDSCP dscp 26 ip any 目的IP地址 set qos acl ip SETDSCP dscp 10 ip host anyset qos acl ip SETDSCP dscp 10 ip host anyset qos acl ip SETDSCP dscp 10 ip host anyset qos acl ip SETDSCP dscp 10 ip host any216。 在Intranet接入交換機其余端口上配置命令:set port qos mod/port vlanbased216。 啟用QoS:set qos enable216。使用CatOS版本的交換機在數(shù)據(jù)中心數(shù)據(jù)流進入Intranet接入交換機時設(shè)置dscp值,使用Native IOS版本的交換機在數(shù)據(jù)中心數(shù)據(jù)流離開Intranet接入交換機時設(shè)置dscp值。 將定義的Policy應(yīng)用到連接Intranet接入路由器的端口上:interface GigabitEthernet1/4 //連接NF12WA01 servicepolicy output SETDSCPinterface GigabitEthernet1/5 //連接NF12WA02 servicepolicy output SETDSCP 數(shù)據(jù)中心Intranet接入路由器由于Intranet接入交換機已經(jīng)將數(shù)據(jù)流進行了分類和染色,因此Intranet接入路由器就可以根據(jù)染色的結(jié)果使用MDRR隊列技術(shù)為不同類別的數(shù)據(jù)流配置不同的帶寬。 啟用定義的ACL:mit qos acl allset qos acl map SETDSCP 1821n 數(shù)據(jù)中心(上海)Native IOS版本216。數(shù)據(jù)流的分類和設(shè)置的dscp值如下表所示:所屬類別所包含的業(yè)務(wù)特征和類型dscp值關(guān)鍵業(yè)務(wù)類Dlsw(dscp 46)、網(wǎng)管、實時的監(jiān)控事件(dscp 26)語音業(yè)務(wù)類VoIP34視頻會議類視頻會議36OA業(yè)務(wù)類AD、Notes application、Notes mail10缺省業(yè)務(wù)類其他業(yè)務(wù)0n 數(shù)據(jù)中心(北京)CatOS版本216。 數(shù)據(jù)中心Intranet接入交換機Intranet接入交換機根據(jù)數(shù)據(jù)流的IP地址或服務(wù)端口號將數(shù)據(jù)流分為五類,對每一類設(shè)置不同的dscp值。 中小規(guī)模分行//啟用ip cef distributedip cef distributedip accesslist extended Key permit tcp any any eq 2065 permit tcp any eq 2065 anyclassmap matchany Keyapplication match ip dscp cs6 match accessgroup name Key match ip dscp efclassmap matchany Voiceapplication match ip dscp af41classmap matchany Videoapplication match ip dscp af42classmap matchany Interactiveapplication match ip dscp af31classmap matchany Batchapplication match ip dscp af21classmap matchany OAapplication match ip dscp af11policymap QoS_DC class Keyapplication priority bandwidth class Voiceapplication priority bandwidth class Videoapplication priority bandwidth class Interactiveapplication priority bandwidth class Batchapplication bandwidth percent value randomdetect dscpbased class OAapplication bandwidth percent value randomdetect dscpbased class classdefault randomdetect dscpbasedinterface ATM interface name pointtopointpvc name vpi/vciclassvc vcclass nameservicepolicy out QoS_DC由于一級分行上聯(lián)路由器都是思科的7507路由器,因此我們在一級分行上聯(lián)路由器連接數(shù)