1、办公楼网络项目实施方案办公楼网络项目设计实施方案文件目的:深化设计方案备忘录作为WBS的扩充,以利于确保WBS的完整,但同时不包含任何本项目范围中不必要求的活动。文件版本历史:版本号改动记录影响作者改动者Version 0.1初始版本All1 方案概述1.1 方案编写目的撰写此文的主要目的是为了保障“办工网络新建工程”的顺利实施,根据项目实际应用需求,制定出网络实施方案。在实际实施工作前,将所有实施步骤、方法和各方需完成的任务明确。1.2 方案编写背景根据办工网络新建工程安装工作的时间安排,将在2012年11月底开始进行此次网络安装工作。由于此次网络安装调试在新的办工环境下开展,涉及到安装、加
2、电环境是否满足等。这就需要我们在实施以前充分作好诸如现状调研、技术分析、规范流程等准备工作,为了保证工作的优质高效的完成,我们编写了这份安装切换实施方案。2 项目工作描述2.1 项目背景随着工程项目的开展,经与维护部门沟通确定,整个网络采用双核心、接入二层构架方式,每个核心点以逻辑双链路方式上联至两台思科7609核心节点,每台接入交换机以双物理链路方式上联至双核心,接点提供百兆接入。改造后的骨干网络将完全是一个具有超级性能的综合承载传输平台。2.2 项目实施目的保证此次网络安装项目的顺利实施,同时规范网络结构,建设高速、冗余、安全的骨干网,提高网络可靠性,为各种应用提供高速、冗余、安全的数据传
3、输平台。2.3 项目参与人员及其职责单位、部门名称职责主要负责人综合部、信息化部审定项目实施小组提交的网络实施方案,控制网络改造的整体进度,调度相关人员、设备资源,协调相应的测试工作。XXXX广州铠源、施工单位进行网络调研,提交设备安装方案给专家审定,负责根据专家小组的意见对方案进行修改。专家小组对方案进行审核后,根据该方案进行实施工作,并进行相应的测试。铠源方:苏东光、莫景志、梁智豪2.4 项目实施范围本次网络结构的实施,主要包括以下内容: 在中心机机房安装两台LS-7610,作为各接入的汇聚和网络出口。 在15-18F共安装3台H3C 3528、9台H3C 3552交换机,提供Layer2
4、的网络接入,通过VLAN划分实现接入的隔离。2.5 项目实施原则1. 实施步骤的完整性,对于每一个实施步骤各方所需要执行的动作有明确的规定,有精确的时间顺序安排,对每一个动作有详细的操作步骤,对每一个执行的动作都有相应的检查是否完成的步骤,达到任何一个只要具有实际实施经验的工程师都能按实施方案实施。2. 详细描述实施方案的风险和局限性,明确使用实施方案所应承担的风险和将导致的后果。3. 在实施前需要各参与单位和人员最终确认实施方案的正确性、明确各方所执行的动作和担负的责任。4. 对于检查实施方案的每一个阶段是否达到方案要求,需要有每一阶段的测试内容,明确哪些测试在指定时间点不能完成或完成后测试
5、结果不正确的情况。5. 网络调试完后,维护部门工程师在场,负责对设备配置、网络使用质量进行验证,并得出结论。2.6 项目实施环境要求1. 场地要求:为网络设备提供足够的场地空间、机架。温度、湿度条件要满足设备的需要。改造的工具要齐全,比如做线工具、网线、地板起子。2. 电源要求:为改造新增的网络设备提供稳定的电源,足够的插座数量。如果设备是双电源,要提供两路独立的电源,设备的每一个电源都是独立供电。并确保能够提供足够的功率负载。3. 根据设备的摆放位置和设备接口的类型提供足够长度、合格的光纤跳线、双绞线跳线。光纤跳线外面要增加塑料软管进行保护。4. 设备标签,用于对设备进行标识。同时还要准备标
6、签用来给设备端口连接进行标识。3 网络系统设计3.1 网络拓扑设备端口互联:楼层设备型号设备名称网管IP上联端口端口描述15楼H3C S3528TP-EAGZ_YLSB_S3528_15F_AG1/0/27to dcn-s1-gdgz-ylsb_g0/0/2G1/0/28to dcn-s2-gdgz-ylsb_g0/0/2H3C S3552TP-EAGZ_YLSB_S3552_15F_AG1/0/51to dcn-s1-gdgz-ylsb_g0/0/3G1/0/52to dcn-s2-gdgz-ylsb_g0/0/3H3C S3552TP-EAGZ_YLSB_S3552_15F_BG1/0/5
7、1to dcn-s1-gdgz-ylsb_g0/0/4G1/0/52to dcn-s2-gdgz-ylsb_g0/0/416楼H3C 7610dcn-s1-gdgz-ylsbG0/0/1To:dcn-r1-a-gdgz-xsk;Gi6/1:1GEH3C 7610dcn-s2-gdgz-ylsbG0/0/1To:dcn-r2-a-gdgz-xsk;Gi6/1:1GEH3C S3552TP-EAGZ_YLSB_S3552_16F_AG1/0/51to dcn-s1-gdgz-ylsb_g0/0/5G1/0/52to dcn-s2-gdgz-ylsb_g0/0/5H3C S3552TP-EAGZ_Y
8、LSB_S3552_16F_BG1/0/51to dcn-s1-gdgz-ylsb_g0/0/6G1/0/52to dcn-s2-gdgz-ylsb_g0/0/6H3C S3552TP-EAGZ_YLSB_S3552_16F_CG1/0/51to dcn-s1-gdgz-ylsb_g0/0/7G1/0/52to dcn-s2-gdgz-ylsb_g0/0/717楼H3C S3528TP-EAGZ_YLSB_S3528_17F_AG1/0/27to dcn-s1-gdgz-ylsb_g0/0/8G1/0/28to dcn-s2-gdgz-ylsb_g0/0/8H3C S3552TP-EAGZ_Y
9、LSB_S3552_17F_AG1/0/51to dcn-s1-gdgz-ylsb_g0/0/9G1/0/52to dcn-s2-gdgz-ylsb_g0/0/9H3C S3552TP-EAGZ_YLSB_S3552_17F_BG1/0/51to dcn-s1-gdgz-ylsb_g0/0/10G1/0/52to dcn-s2-gdgz-ylsb_g0/0/1018楼H3C S3528TP-EAGZ_YLSB_S3528_18F_AG1/0/27to dcn-s1-gdgz-ylsb_g0/0/11G1/0/28to dcn-s2-gdgz-ylsb_g0/0/11H3C S3552TP-EA
10、GZ_YLSB_S3552_18F_AG1/0/51to dcn-s1-gdgz-ylsb_g0/0/12G1/0/52to dcn-s2-gdgz-ylsb_g0/0/12H3C S3552TP-EAGZ_YLSB_S3552_18F_BG1/0/51to dcn-s1-gdgz-ylsb_g0/0/13G1/0/52to dcn-s2-gdgz-ylsb_g0/0/13核心机房H3C 7610与思科7609互联:序号本端本端端口对端对端端口所属域vlan互联地址1H3C 7610-1G0/0/1dcn-r1-a-gdgz-xskGi6/1MSS310132.96.251.140/30BSS
11、210132.96.253.160/30VC410132.96.250.148/302H3C 7610-1G0/0/1dcn-r2-a-gdgz-xskGi6/1MSS311132.96.251.144/30BSS211132.96.253.164/30VC411132.96.250.152/30核心机房H3C 7610与H3C 7610间互联:序号本端本端端口对端对端端口所属域vlan互联地址1H3C 7610-1G0/0/24H3C 7610-2G0/0/24MSS306132.96.251.148/30BSS206132.96.253.168/30VC406132.96.250.160/
12、30DHCP分配:核心交换机两台H3C 7610上开启:楼层设备名称业务VLAN ID用户IP地址用户网关15楼H3C S3528TP-EA50H3C S3552TP-EA50H3C S3552TP-EA5016楼H3C S3552TP-EA50、51H3C S3552TP-EA51H3C S3552TP-EA5117楼H3C S3528TP-EA52H3C S3552TP-EA52H3C S3552TP-EA5218楼H3C S3528TP-EA53H3C S3552TP-EA53H3C S3552TP-EA53其它业务BSS150VC993.2 路由规划路由协议的规划: 整个骨干网络采用B
13、GP协议承载业务路由,有利于网络的健壮性和路由策略控制。 在汇聚与核心交换机之间采用二层VLAN 802.1Q透传,不涉及三层路由问题。3.2.1 BGP模板:dcn-r1-a-gdgz-xsk:interface GigabitEthernet6/1 description To_YunLaiSiBao_H3C_S7610_01 mtu 1526 no ip address wrr-queue queue-limit 10 90 wrr-queue cos-map 1 1 0 wrr-queue cos-map 2 1 1 4 wrr-queue cos-map 2 2 2 3 priori
14、ty-queue cos-map 1 5 6 7 rcv-queue cos-map 1 3 4interface GigabitEthernet6/1.210 description To_YunLaiSiBao_BSS_H3C_S7610 encapsulation dot1Q 210 ip vrf forwarding BSS ip address 132.96.253.161 255.255.255.252interface GigabitEthernet6/1.310 description To_YunLaiSiBao_MSS_H3C_S7610 encapsulation dot
15、1Q 310 ip vrf forwarding MSS ip address 132.96.251.141 255.255.255.252interface GigabitEthernet6/1.410 description To_YunLaiSiBao_VC_H3C_S7610 encapsulation dot1Q 410 ip vrf forwarding VC ip address 132.96.250.149 255.255.255.252router bgp 5102 address-family ipv4 vrf BSS neighbor 132.96.253.162 rem
16、ote-as 200 neighbor 132.96.253.162 description gd-r2-s-gdgz-xsk,BSS neighbor 132.96.253.162 activate neighbor 132.96.253.162 send-community both neighbor 132.96.253.162 default-originate neighbor 132.96.253.162 as-override neighbor 132.96.253.162 prefix-list BSS_YunLaiSiBao_7610-1_In in neighbor 132
17、.96.253.162 prefix-list default out exit-address-familyaddress-family ipv4 vrf MSS neighbor 132.96.251.142 remote-as 200 neighbor 132.96.251.142 description gd-r2-s-gdgz-xsk,MSS neighbor 132.96.251.142 activate neighbor 132.96.251.142 send-community both neighbor 132.96.251.142 default-originate nei
18、ghbor 132.96.251.142 as-override neighbor 132.96.251.142 prefix-list MSS_YunLaiSiBao_7610-1_In in neighbor 132.96.251.142 prefix-list default out exit-address-family address-family ipv4 vrf VC neighbor 132.96.250.150 remote-as 200 neighbor 132.96.250.150 description ,VC neighbor 132.96.250.150 activ
19、ate neighbor 132.96.250.150 send-community both neighbor 132.96.250.150 default-originate neighbor 132.96.250.150 as-override neighbor 132.96.250.150 prefix-list VC_YunLaiSiBao_7610-1_In in neighbor 132.96.250.150 prefix-list default out exit-address-familyip prefix-list BSS_YunLaiSiBao_7610-1_In se
20、q 5 permit 132.121.72.0/24ip prefix-list MSS_YunLaiSiBao_7610-1_In seq 5 permit 10.118.26.0/23 le 25ip prefix-list VC_YunLaiSiBao_7610-1_In seq 5 permit 132.97.17.0/24dcn-r2-a-gdgz-xsk:interface GigabitEthernet6/1 description To_YunLaiSiBao_H3C_S7610_02 mtu 1526 no ip address wrr-queue queue-limit 1
21、0 90 wrr-queue cos-map 1 1 0 wrr-queue cos-map 2 1 1 4 wrr-queue cos-map 2 2 2 3 priority-queue cos-map 1 5 6 7 rcv-queue cos-map 1 3 4interface GigabitEthernet6/1.211 description To_YunLaiSiBao_BSS_H3C_S7610 encapsulation dot1Q 211 ip vrf forwarding BSS ip address 132.96.253.165 255.255.255.252inte
22、rface GigabitEthernet6/1.311 description To_YunLaiSiBao_MSS_H3C_S7610 encapsulation dot1Q 311 ip vrf forwarding MSS ip address 132.96.251.145 255.255.255.252interface GigabitEthernet6/1.411 description To_YunLaiSiBao_VC_H3C_S7610 encapsulation dot1Q 411 ip vrf forwarding VC ip address 132.96.250.153
23、 255.255.255.252router bgp 5102 address-family ipv4 vrf BSS neighbor 132.96.253.166 remote-as 200 neighbor 132.96.253.166 description ,BSS neighbor 132.96.253.166 activate neighbor 132.96.253.166 send-community both neighbor 132.96.253.166 default-originate neighbor 132.96.253.166 as-override neighb
24、or 132.96.253.166 prefix-list BSS_YunLaiSiBao_7610-2_In in neighbor 132.96.253.166 prefix-list default out exit-address-familyaddress-family ipv4 vrf MSS neighbor 132.96.251.146 remote-as 200 neighbor 132.96.251.146 description ,MSS neighbor 132.96.251.146 activate neighbor 132.96.251.146 send-commu
25、nity both neighbor 132.96.251.146 default-originate neighbor 132.96.251.146 as-override neighbor 132.96.251.146 prefix-list MSS_YunLaiSiBao_7610-2_In in neighbor 132.96.251.146 prefix-list default out exit-address-family address-family ipv4 vrf VC neighbor 132.96.250.154 remote-as 200 neighbor 132.9
26、6.250.154 description ,VC neighbor 132.96.250.154 activate neighbor 132.96.250.154 send-community both neighbor 132.96.250.154 default-originate neighbor 132.96.250.154 as-override neighbor 132.96.250.154 prefix-list VC_YunLaiSiBao_7610-2_In in neighbor 132.96.250.154 prefix-list default out exit-ad
27、dress-familyip prefix-list BSS_YunLaiSiBao_7610-1_In seq 5 permit 132.121.72.0/24ip prefix-list MSS_YunLaiSiBao_7610-1_In seq 5 permit 10.118.26.0/23 le 25ip prefix-list VC_YunLaiSiBao_7610-1_In seq 5 permit 132.97.17.0/24dcn-s1-gdgz-ylsb:#interface GigabitEthernet0/0/1 port link-mode bridge descrip
28、tion To:dcn-r1-a-gdgz-xsk;Gi6/1:1GE:1 port link-type trunk undo port trunk permit vlan 1 port trunk permit vlan 210 310 410#interface Bridge-Aggregation1 description To:DCN-S2-YLSB-dglt:2*1GE port link-type trunk undo port trunk permit vlan 1 port trunk permit vlan 50 to 53 150 206 306 406#interface
29、 GigabitEthernet0/0/24 port link-mode bridge description dcn-s2-gdgz-ylsb,G0/0/24;1GE:1 port link-type trunk undo port trunk permit vlan 1 port trunk permit vlan 50 to 53 150 206 306 406 port link-aggregation group 1#interface Vlan-interface206 description DCN-S2-YLSB-gdlt/BSS ip binding vpn-instance BSS ip address 132.96.253.169 255.255.255.252#interface Vlan-interface210 description to r1-a-gdgz-xsk/BSS ip binding vpn-instance BSS ip address 132.96.253.162 255.255.255.252#interface Vlan-interface306 description DCN-S2-YLSB-gdlt/MSS ip binding vpn-in