


!vlan 210name Servers1!vlan 220name Servers2!vlan 230name Servers3!vlan 240name Servers4!vlan 250name In-mgmt!interface GigabitEthernet0/1switchport mode trunkswitchport trunk encapsulation dot1q!interface GigabitEthernet0/2switchport mode trunkswitchport trunk encapsulation dot1q!interface vlan 250ip address 192.168.10.11 255.255.255.128!ip default-gateway 192.168.10.1!vlan 210name Servers1!vlan 220name Servers2!vlan 230name Servers3!vlan 240name Servers4!vlan 250name In-mgmt!interface GigabitEthernet0/1switchport mode trunkswitchport trunk encapsulation dot1q!interface GigabitEthernet0/2switchport mode trunkswitchport trunk encapsulation dot1q!interface vlan 250ip address 192.168.10.12 255.255.255.128!ip default-gateway 192.168.10.1!vlan 210name Servers1!vlan 220name Servers2!vlan 230name Servers3!vlan 240name Servers4!vlan 250name In-mgmt!interface GigabitEthernet0/1switchport mode trunkswitchport trunk encapsulation dot1q!interface GigabitEthernet0/2switchport mode trunkswitchport trunk encapsulation dot1q!interface vlan 250ip address 192.168.10.13 255.255.255.128!ip default-gateway 192.168.10.1!vlan 200name in-transit!vlan 210name Servers1!vlan 220name Servers2!vlan 230name Servers3!vlan 240name Servers4!vlan 250name In-mgmt!interface GigabitEthernet0/1switchport mode trunkswitchport trunk encapsulation dot1q!interface GigabitEthernet0/2switchport mode trunkswitchport trunk encapsulation dot1qchannel-group 1 mode active!interface GigabitEthernet0/3switchport mode trunkswitchport trunk encapsulation dot1qchannel-group 1 mode active!interface GigabitEthernet0/4switchport mode trunkswitchport trunk encapsulation dot1q!interface GigabitEthernet0/5switchport mode trunkswitchport trunk encapsulation dot1q!interface GigabitEthernet0/6switchport mode trunkswitchport trunk encapsulation dot1q!interface Port-channel 1switchport mode trunkswitchport trunk encapsulation dot1q!interface vlan 200ip address 10.0.0.29 255.255.255.240standby 1 ip 10.0.0.28!interface vlan 210ip address 192.168.0.2 255.255.255.128standby 2 ip 192.168.0.1!interface vlan 220ip address 192.168.0.130 255.255.255.128standby 3 ip 192.168.0.129!interface vlan 230ip address 192.168.1.2 255.255.255.128standby 4 ip 192.168.1.1!interface vlan 240ip address 192.168.1.130 255.255.255.128standby 5 ip 192.168.1.129!interface vlan 250ip address 192.168.10.2 255.255.255.128standby 6 ip 192.168.10.1!ip route 0.0.0.0 0.0.0.0 10.0.0.17!vlan 200name in-transit!vlan 210name Servers1!vlan 220name Servers2!vlan 230name Servers3!vlan 240name Servers4!vlan 250name In-mgmt!interface GigabitEthernet0/1switchport mode trunkswitchport trunk encapsulation dot1q!interface GigabitEthernet0/2switchport mode trunkswitchport trunk encapsulation dot1qchannel-group 1 mode active!interface GigabitEthernet0/3switchport mode trunkswitchport trunk encapsulation dot1qchannel-group 1 mode active!interface GigabitEthernet0/4switchport mode trunkswitchport trunk encapsulation dot1q!interface GigabitEthernet0/5switchport mode trunkswitchport trunk encapsulation dot1q!interface GigabitEthernet0/6switchport mode trunkswitchport trunk encapsulation dot1q!interface Port-channel 1switchport mode trunkswitchport trunk encapsulation dot1q!interface vlan 200ip address 10.0.0.30 255.255.255.240standby 1 ip 10.0.0.28!interface vlan 210ip address 192.168.0.3 255.255.255.128standby 2 ip 192.168.0.1!interface vlan 220ip address 192.168.0.131 255.255.255.128standby 3 ip 192.168.0.129!interface vlan 230ip address 192.168.1.3 255.255.255.128standby 4 ip 192.168.1.1!interface vlan 240ip address 192.168.1.131 255.255.255.128standby 5 ip 192.168.1.129!interface vlan 250ip address 192.168.10.3 255.255.255.128standby 6 ip 192.168.10.1!ip route 0.0.0.0 0.0.0.0 10.0.0.17set interface ethernet0/1 zone untrustset interface ethernet0/1.101 tag 101 zone dmzset interface ethernet0/1.102 tag 102 zone mgmtset interface ethernet0/2 zone trustset interface ethernet0/1 ip 10.0.0.1/28set interface ethernet0/1 manage-ip 10.0.0.2set interface ethernet0/1.101 ip 10.0.0.33/28set interface ethernet0/1.102 ip 10.0.0.49/28set interface ethernet0/2 ip 10.0.0.17/28set interface ethernet0/2 manage-ip 10.0.0.18set vrouter trust-vr route 0.0.0.0/0 interface ethernet0/1 gateway 10.0.0.12set interface ethernet0/1 zone untrustset interface ethernet0/1.101 tag 101 zone dmzset interface ethernet0/1.102 tag 102 zone mgmtset interface ethernet0/2 zone trustset interface ethernet0/1 ip 10.0.0.1/28set interface ethernet0/1 manage-ip 10.0.0.3set interface ethernet0/1.101 ip 10.0.0.33/28set interface ethernet0/1.102 ip 10.0.0.49/28set interface ethernet0/2 ip 10.0.0.17/28set interface ethernet0/2 manage-ip 10.0.0.19set vrouter trust-vr route 0.0.0.0/0 interface ethernet0/1 gateway 10.0.0.12!vlan 100name Outside!vlan 101name DMZ!vlan 102name Mgmt!interface GigabitEthernet1/0description To-Inet-rtr1switchport mode accessswitchport access vlan 100!interface GigabitEthernet1/1switchport mode trunkswitchport trunk encapsulation dot1q!interface GigabitEthernet1/3switchport mode trunkswitchport trunk encapsulation dot1qchannel-group 1 mode active!interface GigabitEthernet1/4switchport mode trunkswitchport trunk encapsulation dot1qchannel-group 1 mode active!interface Port-channel 1switchport mode trunkswitchport trunk encapsulation dot1q!interface vlan 102ip address 10.0.0.50 255.255.255.240!ip default-gateway 10.0.0.49!vlan 100name Outside!vlan 101name DMZ!vlan 102name Mgmt!interface GigabitEthernet1/0description To-Inet-rtr2switchport mode accessswitchport access vlan 100!interface GigabitEthernet1/1switchport mode trunkswitchport trunk encapsulation dot1q!interface GigabitEthernet1/3switchport mode trunkswitchport trunk encapsulation dot1qchannel-group 1 mode active!interface GigabitEthernet1/4switchport mode trunkswitchport trunk encapsulation dot1qchannel-group 1 mode active!interface Port-channel 1switchport mode trunkswitchport trunk encapsulation dot1q!interface vlan 102ip address 10.0.0.51 255.255.255.240!ip default-gateway 10.0.0.49

Source: https://habr.com/ru/post/230439/
All Articles