aruba交换机配置实战篇Word下载.docx
《aruba交换机配置实战篇Word下载.docx》由会员分享,可在线阅读,更多相关《aruba交换机配置实战篇Word下载.docx(15页珍藏版)》请在冰豆网上搜索。
InvokeQuick-setup(y|n)[y]:
y
*****************WelcometotheArubaS2500-24Psetupdialog*****************
Thisdialogwillhelpyoutosetthebasicconfigurationfortheswitch.
Thesesettings,exceptfortheCountryCode,canlaterbechangedfromthe
CommandLineInterfaceorGraphicalUserInterface.
Commands:
<
Enter>
Submitinputoruse[defaultvalue],<
ctrl-I>
Help
ctrl-B>
Back,<
ctrl-F>
Forward,<
ctrl-A>
Linebegin,<
ctrl-E>
Lineend
ctrl-D>
Delete,<
BackSpace>
Deleteback,<
ctrl-K>
Deletetoendofline
ctrl-P>
Previousquestion<
ctrl-X>
Restartbeginning,<
ctrl-C>
toexit
EnterSystemname[ArubaS2500-24P]:
aruba2500-xmu-2f
ConfigureinbandmanagementVLAN[yes|no]:
yes是否开启管理VLAN
Inbandmanagementvlanid[1]:
711管理VLAN段
EnterthememberinterfacesformanagementVLAN(Example0/0/0,0/0/1):
0/0/23,0/1/1添加需要trunk的端口
EntermanagementVLANIPaddress[172.16.0.254]:
172.31.11.2管理ip
EntermgmtVLANinterfacesubnetmask[255.255.255.0]:
回车
EnterOutofbandmanagementinterfaceIPaddress[none]:
EnterIPDefaultgateway[none]:
172.31.11.1网关
EnterCountrycode(ISO-3166),<
forsupportedlist:
CN中国
YouhavechosenCountrycodeCNforChina(yes|no)?
:
yes
EnterTimeZone[PST-8:
0]:
CST+8:
EnterTimeinUTC[03:
48:
15]:
EnterDate(MM/DD/YYYY)[7/4/2013]:
EnterPasswordforadminlogin(upto32chars):
*********//admin123!
Re-typePasswordforadminlogin:
EnterPasswordforenablemode(upto15chars):
******//enablle
Re-typePasswordforenablemode:
******//enable
Currentchoicesare:
Systemname:
ConfigureinbandmanagementVLAN:
vlanidforinbandmanagement[1-4094]:
711
MembersinterfacesofmanagementVLAN:
0/0/23,0/1/1
IPaddressofmanagementVLAN:
172.31.11.2
ManagementVLANinterfacesubnetmask:
255.255.255.0
IPDefaultgateway:
172.31.11.1
Countrycode:
CN
TimeZone:
Type<
togobackandchangeanswerforanyquestion
Doyouwishtoacceptthechanges(yes|no|abort):
Creatingconfiguration...
Done.
Configuring...
SavingConfiguration...
ConfigurationSaved.
(aruba2500-xmu-2f)#configureter
EnterConfigurationcommands,oneperline.EndwithCNTL/Z
(aruba2500-xmu-2f)(config)#telnetcli//开启telnet功能
(aruba2500-xmu-2f)(config)#end
(aruba2500-xmu-2f)#showipinterfacebrief
InterfaceIPAddress/IPNetmaskAdminProtocol
vlan711172.31.11.2/255.255.255.0UpUp
mgmtunassigned/unassignedUpDown
(aruba2500-xmu-2f)#ping172.31.11.1
Press'
q'
toabort.
Sending5,100-byteICMPEchosto172.31.11.1,timeoutis2seconds:
.....
Successrateis0percent(0/5)
(aruba2500-xmu-2f)#ping172.31.11.1
(aruba2500-xmu-2f)#configureter
(aruba2500-xmu-2f)(config)#interface-groupgigabitethernetap创建端口组
(aruba2500-xmu-2f)(gigabitethernet"
ap"
)#apply-to0/0/0-0/0/23把0/0/0-0/0/23加入组中
)#exit
(aruba2500-xmu-2f)(switchingprofile"
)#vlan712创建vlan712(我给AP用的)
(aruba2500-xmu-2f)(VLAN"
712"
(aruba2500-xmu-2f)(config)#interface-profileswitching-profileap
)#access-vlan712关联
(aruba2500-xmu-2f)(config)#interface-profilepoe-profileap
(aruba2500-xmhu-2f)(PoweroverEthernetprofile"
)#enable开启POE供电功能
(aruba2500-xmu-2f)(PoweroverEthernetprofile"
(aruba2500-xmu-2f)(config)#interface-groupgigabitethernetap
)#switching-profileap应用到端口
)#poe-profileap应用到端口
)#end
如果想把那个端口trunk,可以这样
(aruba2500-xmu-2f)(config)#interfaceg0/0/2
(aruba2500-xmu-2f)#switching-profileUpstream-profile
删除的话就加no
(aruba2500-xmu-2f)#noswitching-profileUpstream-profile
如果要把那个端口加入vlan20
(aruba2500-xmu-2f)#vlan20
20"
(aruba2500-xmu-2f)(config)#interface-profileswitching-profile20
)#access-vlan20
(aruba2500-xmu-2f)#switching-profile20
删除就加no
(aruba2500-xmu-2f)#noswitching-profile20或者
(aruba2500-xmu-2f)#noswitching-profile
三,升级配置把网线接到23口,电脑开启tftp服务器软件
ArubaS2500-24P)(config)#interface-profileswitching-profileftp//--创建模板FTP
(ArubaS2500-24P)(switchingprofile"
ftp"
)#access-vlan1关联vlan1
(ArubaS2500-24P)(config)#interfacegigabitethernet0/0/23
(ArubaS2500-24P)(gigabitethernet"
0/0/23"
)#switching-profileftp//启用ftp
(ArubaS2500-24P)(config)#interfacevlan1
(ArubaS2500-24P)(vlan"
1"
)#ipaddress10.0.0.1255.0.0.0
(ArubaS2500-24P)#ping10.0.0.5
(ArubaS2500-24P)#
(ArubaS2500-24P)#copyftp:
10.0.0.5adminArubaOS_MAS_7.2.2.1_38712system:
partition0
******//---admin和密码是ftp的用户名和没密码,10.0.0.5是电脑的ip
Copyingfile:
............................................................
Filecopiedsuccessfully.
Savingfiletoflash:
...
Member-0:
Thesystemwillbootfrompartition0duringthenextreboot.
(ArubaS2500-24P)#re?
reloadColdstarttheswitch
renamerenameafile
restorerestorefileorconfiguration
(ArubaS2500-24P)#reload
Doyouwanttosavetheconfiguration(y/n):
n
Doyoureallywanttorestartthesystem(y/n):
y
Systemwillnowrestart!
Shutdownprocessingstarted
(aruba2500-xmu-2f)#writememory保存
(aruba2500-xmu-2f)#showrunning-config
BuildingConfiguration...
#
#ConfigurationfileforArubaOS
version7.2
enablesecret"
******"
telnetcli
hostname"
aruba2500-xmu-2f"
clocktimezoneCST8
location"
Building1.floor1"
controllerconfig3
ipaccess-listethvaliduserethacl
permitany
ipaccess-liststatelessdns-acl-stateless
anyanysvc-dnspermit
ipaccess-liststatelesshttp-acl-stateless
anyanysvc-httppermit
ipaccess-liststatelesshttps-acl-stateless
anyanysvc-httpspermit
ipaccess-liststatelessicmp-acl-stateless
anyanysvc-icmppermit
ipaccess-liststatelesslogon-control-stateless
anyanysvc-dhcppermit
anyanysvc-nattpermit
ipaccess-listsessionvaliduser
network169.254.0.0255.255.0.0anyanydeny
anyanyanypermit
ipv6aliasany6aliasany6anypermit
user-roleauthenticated
access-liststatelessallowall-stateless
user-roledenyall
user-roleguest
access-liststatelesshttp-acl-stateless
access-liststatelesshttps-acl-stateless
access-liststatelessdhcp-acl-stateless
access-liststatelessicmp-acl-stateless
access-liststatelessdns-acl-stateless
user-rolelogon
access-liststatelesslogon-control-stateless
cryptoipsectransform-setdefault-boc-bm-transformesp-3desesp-sha-hmac
cryptoipsectransform-setdefault-rap-transformesp-aes256esp-sha-hmac
cryptoisakmpeap-passthrougheap-tls
cryptoisakmpeap-passthrougheap-peap
cryptoisakmpeap-passthrougheap-mschapv2
mgmt-useradminroot9a05893a01941ea9fadbe8f7f92075bc5b5c8189ef96622520
nofirewallattack-ratecp1024
ipv6firewallext-hdr-parse-len100
firewallcp
packet-capture-defaultstcpdisableudpdisablesysmsgdisableotherdisable
ipdomainlookup
countryCN
aaaauthenticationmac"
default"
aaaauthenticationdot1x"
aaaserver-group"
auth-serverInternal
setroleconditionrolevalue-of
aaaprofile"
aaaauthenticationcaptive-portal"
aaaauthenticationvpn"
aaaauthenticationmgmt
aaaauthenticationwired
web-server
aaapassword-policymgmt
traceoptions
qos-profile"
policer-profile"
ip-profile
default-gateway172.31.11.1
lcd-menu
interface-profileospf-profile"
area0.0.0.0
interface-profilepim-profile"
interface-profileigmp-profile"
stack-profile
ipv6-profile
interface-profileswitching-profile"
access-vlan712
Upstream-profile"
switchport-modetrunk
interface-profilepoe-profile"
enable
poe-factory-initial"
interface-profileenet-link-profile"
interface-profilelldp-profile"
lldp-factory-initial"
lldptransmit
lldpreceive
medenable
interface-profilemstp-profile"
interface-profilepvst-port-profile"
vlan-profilemld-snooping-profile"
vlan-profileigmp-snooping-profile"
igmp-snooping-factory-initial"
spanning-tree
modemstp
gvrp
mstp
lacp
vlan"
igmp-snooping-profile"
igmp-snooping-factory-i