1、# ping 发ECHO包交换机命令Quidwaydis cur ;显示当前配置Quidwaydisplay current-configuration ;Quidwaydisplay interfaces ;显示接口信息Quidwaydisplay vlan all ;显示路由信息Quidwaydisplay version ;显示版本信息Quidwaysuper password simple 修改特权用户密码Quidwaysysname 交换机命名Quidwayinterface ethernet0/1 ;进入接口视图Quidwayint e0/1 ;简写方式Quidwayinterfa
2、ce vlan-interface Quidwayint vlan 简写方式,n6Quidway-Vlan-interfacenip address 10.65.1.1 255.255.0.0 ;配置VLAN的IP地址Quidwayip route-static 0.0.0.0 0.0.0.0 10.65.1.2 ;静态路由网关Quidwayrip ;三层交换支持Quidwaylocal-user ftp ;建立ftp用户Quidwayuser-interface vty 0 4 ;进入虚拟终端S3026-ui-vty0-4authentication-mode password ;设置口令模
3、式S3026-ui-vty0-4set authentication-mode password simple 222 ;设置口令S3026-ui-vty0-4user privilege level 3 ;用户级不进入端口模式Quidway-Ethernet0/1duplex half|full|auto ;配置端口工作状态Quidway-Ethernet0/1speed 10|100|auto ;配置端口工作速率Quidway-Ethernet0/1flow-control ;配置端口流控Quidway-Ethernet0/1mdi across|auto|normal ;配置端口平接扭接
4、Quidway-Ethernet0/1port link-type trunk|access|hybrid ;设置端口工作模式Quidway-Ethernet0/1port access vlan 3 ;当前端口加入到VLANQuidway-Ethernet0/1port trunk permit vlan ID|All ;设trunk承诺的VLANQuidway-Ethernet0/1port trunk pvid vlan 3 ;设置trunk端口的PVIDQuidway-Ethernet0/1undo shutdown ;激活端口Quidway-Ethernet0/1shutdown ;
5、关闭端口Quidway-Ethernet0/1quit ;返回Quidwayvlan 3 ;创建VLANQuidway-vlan3port ethernet 0/1 ;在VLAN中增加端口Quidway-vlan3port e0/1 ;Quidway-vlan3port ethernet 0/1 to ethernet 0/4 ;Quidway-vlan3port e0/1 to e0/4 ;Quidwaymonitor-port ;指定镜像端口Quidwayport mirror observing-port 指定镜像和被镜像例如:Quidwayport mirror e0/1 to e0/
6、4 observing-port e0/7 ;Quidwaydescription string ;指定VLAN描述字符Quidwaydescription ;删除VLAN描述字符Quidwaydisplay vlan vlan_id ;查看VLAN设置Quidwaystp enable|disable ;设置生成树,默认关闭Quidwaystp priority 4096 ;设置交换机的优先级Quidwaystp root primary|secondary ;设置为根或根的备份Quidway-Ethernet0/1stp cost 200 ;设置交换机端口的花费Quidwaylink-ag
7、gregation e0/1 to e0/4 ingress|both ;端口的聚合Quidwayundo link-aggregation e0/1|all ; 始端口为通道号SwitchA-vlanxisolate-user-vlan enable ;设置主vlanSwitchAisolate-user-vlan secondary ;设主vlan包括的子vlanQuidway-Ethernet0/2port hybrid pvid vlan 设置vlan的pvidQuidway-Ethernet0/2undo port hybrid pvid ;删除vlan的pvidQuidway-Et
8、hernet0/2port hybrid vlan vlan_id_list untagged ;设置无标识的vlan如果数据包的vlan id与PVId一致,则去掉vlan信息. 默认PVID=1。因此设置PVID为所属vlan id, 设置能够互通的vlan为untagged。路由器命令Quidwaydisplay ip route ;hostname ;更换主机名Quidwaysuper passwrod Quidwayint s0/0 ;进入接口Quidway-serial0/0clock rate 64000 ;设置同步时钟Quidway-serial0/0ip address 配置
9、端口IP地址例:Quidway-serial0/0ip address 10.65.1.1 255.255.0.0 ;或Quidway-serial0/0ip address 10.65.1.1 16 ;Quidway-serial0/0undo shutdown ;Quidwaylink-protocol hdlc ;绑定hdlc协议Quidwayuser-interface vty 0 4Quidway-ui-vty0-4authentication-mode passwordQuidway-ui-vty0-4set authentication-mode password simple
10、222Quidway-ui-vty0-4user privilege level 3Quidway-ui-vty0-4quitQuidwaydebugging hdlc all serial0 ;显示所有信息Quidwaydebugging hdlc event serial0 ;调试事件信息Quidwaydebugging hdlc packet serial0 ;显示包的信息静态路由:Quidwayip route-static interface number|nexthopvaluereject|blackholeQuidwayip route-static 129.1.0.0 16
11、10.0.0.2Quidwayip route-static 129.1.0.0 255.255.0.0 10.0.0.2Quidwayip route-static 129.1.0.0 16 Serial 2Quidwayip route-static 0.0.0.0 0.0.0.0 10.0.0.2动态路由:设置动态路由Quidwayrip work ;设置工作承诺Quidwayrip input ;设置入口承诺Quidwayrip output ;设置出口承诺Quidway-ripnetwork 10.0.0.0 ;设置交换路由网络Quidway-ripnetwork all ;设置与所
12、有网络交换Quidway-rippeer ip-address ;指定交换点Quidway-ripsummary ;路由聚合Quidwayrip version 1 ;设置工作在版本1Quidwayrip version 2 multicast ;设版本2,多播方式Quidway-Ethernet0/0rip split-horizon ;水平分隔Quidwayrouter id A.B.C.D ;配置路由器的IDQuidwayospf enable ;启动OSPF协议Quidway-ospfimport-route direct ;引入直联路由Quidway-Serial0/0ospf en
13、able area 配置OSPF区域标准访咨询列表命令格式如下:acl number match-order config|auto ;默认前者顺序匹配。rule normal|specialpermit|deny source s-wildcard|anyQuidwayacl number 2001Quidway-acl-basic-2001rule normal permit source 10.0.0.0 0.0.0.255Quidway-acl-basic-2001rule normal deny source any扩展访咨询操纵列表配置命令配置TCP/UDP协议的扩展访咨询列表:r
14、ule normal|specialpermit|denytcp|udpsource |anydestination |anyoperate配置ICMP协议的扩展访咨询列表:rule normal|specialpermit|denyicmp source |anydestination |anyicmp-code logging扩展访咨询操纵列表操作符的含义equal portnumber ;等于greater-than portnumber ;大于less-than portnumber ;小于not-equal portnumber ;不等range portnumber1 portnu
15、mber2 ;区间扩展访咨询操纵列表举例Quidwayacl number 3001Quidway-acl-3001rule deny souce any destination anyQuidway-acl-3001rule permit icmp source any destination any icmp-type echoQuidway-acl-3001rule permit icmp source any destination any icmp-type echo-replyQuidwayacl number 3002Quidway-acl-3002rule permit ip
16、source 10.0.0.1 0.0.0.0 destination 202.0.0.1 0.0.0.0Quidway-acl-3002rule deny ip source any destination anyQuidwayacl number 103Quidway-acl-103rule permit tcp source any destination 10.0.0.1 0.0.0.0 destination-port equal ftpQuidway-acl-103rule permit tcp source any destination 10.0.0.2 0.0.0.0 des
17、tination-port equal wwwQuidwayfirewall enableQuidwayfirewall default permit|denyQuidwayint e0/0Quidway-Ethernet0/0firewall packet-filter 2001 inbound|outbound地址转换配置举例Quidwayfirewall default permitQuidwayacl 2001 ;内部指定主机能够进入e0Quidway-acl-basic-2001rule deny ip source any destination anyQuidway-acl-ba
18、sic-2001rule permit ip source 129.38.1.1 0 destination anyQuidway-acl-basic-2001rule permit ip source 129.38.1.2 0 destination anyQuidway-acl-basic-2001rule permit ip source 129.38.1.3 0 destination anyQuidway-acl-basic-2001rule permit ip source 129.38.1.4 0 destination anyQuidway-acl-basic-2001quit
19、Quidway-Ethernet0firewall packet-filter 2001 inboundQuidwayacl 3002 ;外部特定主机和大于1024端口的数据包承诺进入S0Quidway-acl-adv-3002rule deny ip source any destination anyQuidway-acl-adv-3002rule permit tcp source 202.39.2.3 0 destination 202.38.160.1 0Quidway-acl-adv-3002rule permit tcp source any destination 202.38
20、.160.1 0 destination-port great-than1024Quidway-acl-adv-3002quitQuidwayint s0/0Quidway-Serial0/0firewall packet-filter 102 inboundQuidway-Serial0/0nat outbound 3002 interface ;是Easy ip,将acl承诺的IP从本接口出时变换源地址。内部服务器地址转换配置命令(静态nat):nat server global port inside port protocolQuidway-Serial0/0nat server gl
21、obal 202.38.160.1 inside 129.38.1.1 ftp tcpQuidway-Serial0/0nat server global 202.38.160.1 inside 129.38.1.3 www tcp设有公网IP:202.38.160.101202.38.160.103 ;对外访咨询Quidwaynat address-group 202.38.160.101 202.38.160.103 pool1 ;建立地址池Quidwayacl 2001Quidway-acl-basic-2001rule permit source 10.110.10.0 0.0.0.2
22、55 ;指定承诺的内部网络Quidway-acl-basic-2001rule deny source anyQuidway-acl-basic-2001int s0/0Quidway-Serial0/0nat outbound 2001 address-group pool1 ;在s0口从地址池取出IP对外访咨询Quidway-Serial0/0nat server global 202.38.160.101 inside 10.110.10.1 ftp tcpQuidway-Serial0/0nat server global 202.38.160.102 inside 10.110.10
23、.2 www tcpQuidway-Serial0/0nat server global 202.38.160.102 8080 inside 10.110.10.3 www tcpQuidway-Serial0/0nat server global 202.38.160.103 inside 10.110.10.4 smtp udpPPP设置:Quidway-Serial0/0link-protocol ppp ;默认的协议PPP验证:主验方:pap|chapQuidwaylocal-user q2 password simple|cipher hello ;路由器1Quidwayinter
24、face s0/0Quidway-serial0/0ppp authentication-mode pap|chapQuidway-serial0/0ppp chap user q1 ;pap时,没有此句pap被验方:Quidwayinterface s0/0 ;路由器2Quidway-serial0/0ppp pap local-user q2 password simple|cipher hellochap被验方:Quidway-serial0/0ppp chap user q2 ;自己路由器名Quidway-serial0/0local-user q1 password simple|c
25、ipher hello ;对方路由器名帧中继frame-relay (二分册6-61)q1fr switchingq1int s0/1q1-Serial0/1ip address 192.168.34.51 255.255.255.0q1-Serial0/1link-protocol fr ;封装帧中继协议q1-Serial0/1fr interface-type dceq1-Serial0/1fr dlci 100q1-Serial0/1fr inarpq1-Serial0/1fr map ip 192.168.34.52 dlci 100q2int s0/1q2-Serial0/1ip address 192.168.34.52 255.255.255.0q2-Serial0/1link-protocol frq2-Serial0/1fr interface-type dteq2-Serial0/1fr dlci 100q2-Serial0/1fr inarpq2-Serial0/1fr map ip 192.168.34.51 dlci 100帧中继监测q1display fr lmi-infointerface type numberq1display fr mapq1display fr pvc-infoserial interface-numb
copyright@ 2008-2022 冰豆网网站版权所有
经营许可证编号:鄂ICP备2022015515号-1