One point about AVAYA P333R is to configure a user to buy AVAYA P333R as the access switch, Gigabit Optical Fiber access, configure an X330G2 module, and connect a GBIC and a single-mode module for access, A Multimode module connects the local network to the central switch. The remote IP address is 10.10.10.1/255.255.255.0, the local access address is 10.10.10.2/255.255.255.0, the Local intranet address is 192.168.0.253, the center switch address is 192.168.0.254, and the center switch has N VLANs, the AVAYA P333R vswitch address is 192.168.0.252. Requirement: as an access switch, implement local routing and access control. Www.2cto.com solution: 1. VLAN division in switch mode: it is not difficult to configure AVAYA P333R. Switch Mode: config; Switch Mode: set vlan 2 name v2; create a vlan 2 and name it v2 set port vlan 2 1/1-51; set port 1-51 as vlan 2 member set interface inband 2 192.168.0.252 255.255.255.0; configure the vswitch address and specify it to belong to vlan 2. Note: 1/52 is the lx gbic module for access and uses VLAN 1. In addition, after set interface inband, you must reset 1 to make it valid for www.2cto.com 2, VLAN division and interface creation in routing mode: Enter the routing mode in switch mode: session router config; enter the configuration mode set vlan 1 name v1; configure vl The name of an 1 is v1 set vlan 2 name v2; Establish and configure vlan 2 and name it v2 set interface internet; Establish an interface named internet ip vlan 1; the specified interface belongs to vlan 1 ip address 10.10.10.2 255.255.255.0; specify the internet address set interface lan; create an interface named lan ip vlan 2; specify the interface belongs to vlan 2 ip address 192.168.0.253 255.255.255.0; specify the lan address exit; exit to the configuration mode ip route 0.0.0.0 0.0.0 10.10.10.1; create a default static route ip route 192.168.0.0 255.255.255.240.0 192.168.0.254; create a static route to the Intranet description: After creating an interface, you must specify the vlan to which it belongs. The two static routes are indispensable. Do not use dynamic routing on AVAYA P333R, it seems that there is a problem with the route distribution of CISCO routers or route switches. 3. create and apply control lists in routing mode: The create control list is similar to that of CISCO, but I feel better than CISCO in configuration mode: set qos policy-soure local; use the local policy ip access-list 101 1 permit ip 10.10.10.2 any; first, put your access address out of ip access-list 101 50 permit ip 192.168.0.0 0.0.255 any; put a segment of the address and so on; you can create a long control list, AVAYA said it is 512, you can also apply your control list ip access-group 101 default-action-deny. Specify the Control List mode as deny. The default value is permit. Note: AVAYA P333R can only create two control lists, in addition, its control list cannot be applied to interfaces, but can only be applied to the entire route switch. Be careful. In addition, her control column The table number is from 101-149, and once the control list is applied, it cannot be changed. Only no ip access-group can remove it and then change it, however, there can be a better method that should be appropriate. After applying 101, you can use ip access-list-copy 101 111, use copy of the Control List to create a 101 with the same value as 111. After you change the control list of 111, you can use ip access-group 111 without disabling the control list, then, no access-list 101 Deletes your useless list. Description of the configuration list: ip access-list 101 50 permit ip 192.168.0.0 0.0.255 any; ip access-list 101 is to create a 101 control list and 50 is an index number, which is more practical, the control list is arranged according to the size of the index number. You can add a policy smaller than 50 so that it will be placed at the top of 50, which is convenient to delete, no ip access-list 101 50 is enough. Others are the same as those of cisco. According to AVAYA, he does not have good control over ICMP. 4. Check that the control list and route are set up and enter the test. The test of the route is ping and traceroute. Check that the control table can use validate-group 101 to check whether your control list is valid, use ip simulate 101 192.168.0.1 xxx. xxx. xxx. xxx: Check whether your control list is valid. Note: After configuration, the disk is forgotten. copy run star. At this point, the configuration of an AVAYA P333R with access control is complete, you can set the VLAN and ACL according to your situation. Here I am relatively simple, just two VLANs.