H3C虚拟实验室实验命令汇总Word文件下载.docx
《H3C虚拟实验室实验命令汇总Word文件下载.docx》由会员分享,可在线阅读,更多相关《H3C虚拟实验室实验命令汇总Word文件下载.docx(9页珍藏版)》请在冰豆网上搜索。
#ping<
发ECHO包
----------------------------------------
交换机命令
[Quidway]discur ;
显示当前配置
[Quidway]displaycurrent-configuration ;
[Quidway]displayinterfaces ;
显示接口信息
[Quidway]displayvlanall ;
显示路由信息
[Quidway]displayversion ;
显示版本信息
[Quidway]superpasswordsimple<
password>
修改特权用户密码
[Quidway]sysname<
name>
交换机命名
[Quidway]interfaceethernet0/1;
进入接口视图
[Quidway]inte0/1;
简写方式
[Quidway]interfacevlan-interface<
n>
[Quidway]intvlan<
简写方式,n<
6
[Quidway-Vlan-interfacen]ipaddress10.65.1.1255.255.0.0;
配置VLAN的IP地址
[Quidway]iproute-static0.0.0.00.0.0.010.65.1.2;
静态路由=网关
[Quidway]rip;
三层交换支持
[Quidway]local-userftp;
建立ftp用户
[Quidway]user-interfacevty04;
进入虚拟终端
[S3026-ui-vty0-4]authentication-modepassword;
设置口令模式
[S3026-ui-vty0-4]setauthentication-modepasswordsimple222;
设置口令
[S3026-ui-vty0-4]userprivilegelevel3;
用户级不
进入端口模式
[Quidway-Ethernet0/1]duplex{half|full|auto};
配置端口工作状态
[Quidway-Ethernet0/1]speed{10|100|auto};
配置端口工作速率
[Quidway-Ethernet0/1]flow-control;
配置端口流控
[Quidway-Ethernet0/1]mdi{across|auto|normal};
配置端口平接扭接
[Quidway-Ethernet0/1]portlink-type{trunk|access|hybrid};
设置端口工作模式
[Quidway-Ethernet0/1]portaccessvlan3 ;
当前端口加入到VLAN
[Quidway-Ethernet0/1]porttrunkpermitvlan{ID|All} ;
设trunk承诺的VLAN
[Quidway-Ethernet0/1]porttrunkpvidvlan3 ;
设置trunk端口的PVID
[Quidway-Ethernet0/1]undoshutdown;
激活端口
[Quidway-Ethernet0/1]shutdown;
关闭端口
[Quidway-Ethernet0/1]quit;
返回
[Quidway]vlan3 ;
创建VLAN
[Quidway-vlan3]portethernet0/1 ;
在VLAN中增加端口
[Quidway-vlan3]porte0/1 ;
[Quidway-vlan3]portethernet0/1toethernet0/4 ;
[Quidway-vlan3]porte0/1toe0/4 ;
[Quidway]monitor-port<
interface>
;
指定镜像端口
[Quidway]portmirror<
;
指定被镜像端口
if_list>
observing-port<
ifterface>
指定镜像和被镜像
例如:
[Quidway]portmirrore0/1toe0/4observing-porte0/7;
[Quidway]descriptionstring ;
指定VLAN描述字符
[Quidway]description ;
删除VLAN描述字符
[Quidway]displayvlan[vlan_id];
查看VLAN设置
[Quidway]stp{enable|disable};
设置生成树,默认关闭
[Quidway]stppriority4096 ;
设置交换机的优先级
[Quidway]stproot{primary|secondary} ;
设置为根或根的备份
[Quidway-Ethernet0/1]stpcost200 ;
设置交换机端口的花费
[Quidway]link-aggregatione0/1toe0/4ingress|both;
端口的聚合
[Quidway]undolink-aggregatione0/1|all;
始端口为通道号
[SwitchA-vlanx]isolate-user-vlanenable ;
设置主vlan
[SwitchA]isolate-user-vlan<
secondary<
list>
;
设主vlan包括的子vlan
[Quidway-Ethernet0/2]porthybridpvidvlan<
id>
设置vlan的pvid
[Quidway-Ethernet0/2]undoporthybridpvid ;
删除vlan的pvid
[Quidway-Ethernet0/2]porthybridvlanvlan_id_listuntagged ;
设置无标识的vlan
如果数据包的vlanid与PVId一致,则去掉vlan信息.默认PVID=1。
因此设置PVID为所属vlanid,设置能够互通的vlan为untagged。
路由器命令
[Quidway]displayiproute ;
hostname>
;
更换主机名
[Quidway]superpasswrod<
[Quidway]ints0/0 ;
进入接口
[Quidway-serial0/0]clockrate64000 ;
设置同步时钟
[Quidway-serial0/0]ipaddress<
<
mask|mask_len>
配置端口IP地址
例:
[Quidway-serial0/0]ipaddress10.65.1.1255.255.0.0 ;
或
[Quidway-serial0/0]ipaddress10.65.1.116 ;
[Quidway-serial0/0]undoshutdown ;
[Quidway]link-protocolhdlc ;
绑定hdlc协议
[Quidway]user-interfacevty04
[Quidway-ui-vty0-4]authentication-modepassword
[Quidway-ui-vty0-4]setauthentication-modepasswordsimple222
[Quidway-ui-vty0-4]userprivilegelevel3
[Quidway-ui-vty0-4]quit
[Quidway]debugginghdlcallserial0 ;
显示所有信息
[Quidway]debugginghdlceventserial0 ;
调试事件信息
[Quidway]debugginghdlcpacketserial0 ;
显示包的信息
静态路由:
[Quidway]iproute-static<
<
mask>
{interfacenumber|nexthop}[value][reject|blackhole]
[Quidway]iproute-static129.1.0.01610.0.0.2
[Quidway]iproute-static129.1.0.0255.255.0.010.0.0.2
[Quidway]iproute-static129.1.0.016Serial2
[Quidway]iproute-static0.0.0.00.0.0.010.0.0.2
动态路由:
设置动态路由
[Quidway]ripwork;
设置工作承诺
[Quidway]ripinput;
设置入口承诺
[Quidway]ripoutput;
设置出口承诺
[Quidway-rip]network10.0.0.0 ;
设置交换路由网络
[Quidway-rip]networkall;
设置与所有网络交换
[Quidway-rip]peerip-address;
指定交换点
[Quidway-rip]summary;
路由聚合
[Quidway]ripversion1;
设置工作在版本1
[Quidway]ripversion2multicast;
设版本2,多播方式
[Quidway-Ethernet0/0]ripsplit-horizon;
水平分隔
[Quidway]routeridA.B.C.D;
配置路由器的ID
[Quidway]ospfenable;
启动OSPF协议
[Quidway-ospf]import-routedirect;
引入直联路由
[Quidway-Serial0/0]ospfenablearea<
area_id>
配置OSPF区域
标准访咨询列表命令格式如下:
aclnumber<
acl-number>
[match-orderconfig|auto];
默认前者顺序匹配。
rule[normal|special]{permit|deny}source<
s_ip>
s-wildcard|any]
[Quidway]aclnumber2001
[Quidway-acl-basic-2001]rulenormalpermitsource10.0.0.00.0.0.255
[Quidway-acl-basic-2001]rulenormaldenysourceany
扩展访咨询操纵列表配置命令
配置TCP/UDP协议的扩展访咨询列表:
rule{normal|special}{permit|deny}{tcp|udp}source{<
ipwild>
|any}destination<
|any}
[operate]
配置ICMP协议的扩展访咨询列表:
rule{normal|special}{permit|deny}icmpsource{<
|any]destination{<
|any]
[icmp-code][logging]
扩展访咨询操纵列表操作符的含义
equalportnumber;
等于
greater-thanportnumber;
大于
less-thanportnumber;
小于
not-equalportnumber;
不等
rangeportnumber1portnumber2;
区间
扩展访咨询操纵列表举例
[Quidway]aclnumber3001
[Quidway-acl-3001]ruledenysouceanydestinationany
[Quidway-acl-3001]rulepermiticmpsourceanydestinationanyicmp-typeecho
[Quidway-acl-3001]rulepermiticmpsourceanydestinationanyicmp-typeecho-reply
[Quidway]aclnumber3002
[Quidway-acl-3002]rulepermitipsource10.0.0.10.0.0.0destination202.0.0.10.0.0.0
[Quidway-acl-3002]ruledenyipsourceanydestinationany
[Quidway]aclnumber103
[Quidway-acl-103]rulepermittcpsourceanydestination10.0.0.10.0.0.0destination-portequalftp
[Quidway-acl-103]rulepermittcpsourceanydestination10.0.0.20.0.0.0destination-portequalwww
[Quidway]firewallenable
[Quidway]firewalldefaultpermit|deny
[Quidway]inte0/0
[Quidway-Ethernet0/0]firewallpacket-filter2001inbound|outbound
地址转换配置举例
[Quidway]firewalldefaultpermit
[Quidway]acl2001;
内部指定主机能够进入e0
[Quidway-acl-basic-2001]ruledenyipsourceanydestinationany
[Quidway-acl-basic-2001]rulepermitipsource129.38.1.10destinationany
[Quidway-acl-basic-2001]rulepermitipsource129.38.1.20destinationany
[Quidway-acl-basic-2001]rulepermitipsource129.38.1.30destinationany
[Quidway-acl-basic-2001]rulepermitipsource129.38.1.40destinationany
[Quidway-acl-basic-2001]quit
[Quidway-Ethernet0]firewallpacket-filter2001inbound
[Quidway]acl3002;
外部特定主机和大于1024端口的数据包承诺进入S0
[Quidway-acl-adv-3002]ruledenyipsourceanydestinationany
[Quidway-acl-adv-3002]rulepermittcpsource202.39.2.30destination202.38.160.10
[Quidway-acl-adv-3002]rulepermittcpsourceanydestination202.38.160.10destination-port
great-than
1024
[Quidway-acl-adv-3002]quit
[Quidway]ints0/0
[Quidway-Serial0/0]firewallpacket-filter102inbound
[Quidway-Serial0/0]natoutbound3002interface;
是Easyip,将acl承诺的IP从本接口出时变换源地址。
内部服务器地址转换配置命令(静态nat):
natserverglobal<
[port]inside<
port[protocol]
[Quidway-Serial0/0]natserverglobal202.38.160.1inside129.38.1.1ftptcp
[Quidway-Serial0/0]natserverglobal202.38.160.1inside129.38.1.3wwwtcp
设有公网IP:
202.38.160.101~202.38.160.103;
对外访咨询
[Quidway]nataddress-group202.38.160.101202.38.160.103pool1;
建立地址池
[Quidway]acl2001
[Quidway-acl-basic-2001]rulepermitsource10.110.10.00.0.0.255;
指定承诺的内部网络
[Quidway-acl-basic-2001]ruledenysourceany
[Quidway-acl-basic-2001]ints0/0
[Quidway-Serial0/0]natoutbound2001address-grouppool1;
在s0口从地址池取出IP对外访咨询
[Quidway-Serial0/0]natserverglobal202.38.160.101inside10.110.10.1ftptcp
[Quidway-Serial0/0]natserverglobal202.38.160.102inside10.110.10.2wwwtcp
[Quidway-Serial0/0]natserverglobal202.38.160.1028080inside10.110.10.3wwwtcp
[Quidway-Serial0/0]natserverglobal202.38.160.103inside10.110.10.4smtpudp
PPP设置:
[Quidway-Serial0/0]link-protocolppp;
默认的协议
PPP验证:
主验方:
pap|chap
[Quidway]local-userq2password{simple|cipher}hello;
路由器1
[Quidway]interfaces0/0
[Quidway-serial0/0]pppauthentication-mode{pap|chap}
[Quidway-serial0/0]pppchapuserq1;
pap时,没有此句
pap被验方:
[Quidway]interfaces0/0;
路由器2
[Quidway-serial0/0]ppppaplocal-userq2password{simple|cipher}hello
chap被验方:
[Quidway-serial0/0]pppchapuserq2;
自己路由器名
[Quidway-serial0/0]local-userq1password{simple|cipher}hello;
对方路由器名
帧中继frame-relay(二分册6-61)
[q1]frswitching
[q1]ints0/1
[q1-Serial0/1]ipaddress192.168.34.51255.255.255.0
[q1-Serial0/1]link-protocolfr;
封装帧中继协议
[q1-Serial0/1]frinterface-typedce
[q1-Serial0/1]frdlci100
[q1-Serial0/1]frinarp
[q1-Serial0/1]frmapip192.168.34.52dlci100
[q2]ints0/1
[q2-Serial0/1]ipaddress192.168.34.52255.255.255.0
[q2-Serial0/1]link-protocolfr
[q2-Serial0/1]frinterface-typedte
[q2-Serial0/1]frdlci100
[q2-Serial0/1]frinarp
[q2-Serial0/1]frmapip192.168.34.51dlci100
帧中继监测
[q1]displayfrlmi-info[]interfacetypenumber]
[q1]displayfrmap
[q1]displayfrpvc-info[serialinterface-numb