1、telnetserverenable#配置telnet服务local-useradmin#配置telnet用户名passwordsimpleadmin888#配置明文密码为admin888server-typetelnet#配置用户telnet服务类型authorization-attributeuser-rolelevel-3#配置用户级别quituserinterfacevty04#线程模式authorization-modescheme#用户名+密码先配LoopBack地址再配置ospfxianBBBintLoopBack10地址#配置路由idospf1#进程号1area0#骨干区域VL
2、AN10/创建VLANintvlan10配置VLAN10的IP地址intg0/7portlink-typeaccess#交换机模式ospf1importroutedirect/引入直连路由5interfaceVlan-interface1interfaceGigabitEthernet0/5portlink-moderoute/设置接口为路由模式# interfaceGigabitEthernet0/7配置静态目的网段(多个目的路由需配多条)和下一条的出口地址配置缺省路由只需配和下一跳设置优先级为60,数字越小越优先iphttpenableH3C-ospf-1import-routedirec
3、t/ospf加入直连H3C-ospf-1import-routestatic/ospf加入静态路由ipunreachablesenable显示跟踪ipttl-expiresenable显示跟踪# 双链路路由器设置:#市路由器:acladvanced3300/创建访问控制列表ACL3300配置允许目的ip地址或网段(反掩码)访问acladvanced3333/创建访问控制列表ACL3333配置允许目的ip网段或固定地址(反掩码)policy-based-routexxxpermitnode1/创建策略路xxx,节点1if-matchacl3000/如果是ACL3000指定下一跳ip地址路由器po
4、licy-based-routexxxpermitnode11/创建策略路xxx,节点11if-matchacl3333/如果是ACL3333在内网口应用策略路由interfaceGigabitEthernet0/5portlink-moderouteippolicy-based-routexxxacladvanced3500/创建ACL3500允许指定目的地址通过,反掩码拒绝目的网段通过,反掩码在外网接口应用上网策略(outbound是出,inbound是进)interfaceGigabitEthernet0/10portlink-moderoutepacket-filter3500outb
5、ound#县路由器:acladvanced3300/创建ACL3300访问配置允许源ip固定地址,反掩码acladvanced3333/创建ACL3333访问配置允许源ip段地址,反掩码if-matchacl3300/如果是ACL3300H3CinterfaceVlan-interface1H3C-Vlan-interface1ippolicy-based-routexxxquitpacket-filter3300outbound市A静态配置:shiAAAdiscutelnetserverenable#ospf1import-routedirecimport-routestaticipunre
6、achablesenableipttl-expiresenablepolicy-based-routexxxpermitnode1if-matchacl3300policy-based-routexxxpermitnode11if-matchacl3333interfaceGigabitEthernet0/1portlink-moderouteinterfaceGigabitEthernet0/3、acladvanced3300acladvanced3333local-useradminclassmanageservice-typetelnethttphttpsauthorization-at
7、tributeuser-rolelevel-12authorization-attributeuser-rolelevel-15authorization-attributeuser-rolenetwork-operatoriphttpsenable县B动态ospfxianBBB#ipunreachablesenableipttl-expiresenablepolicy-based-routeyyypermitnode1policy-based-routeyyypermitnode11ippolicy-based-routeyyyinterfaceGigabitEthernet0/3portl
8、ink-moderouteospfcost2interfaceGigabitEthernet0/11portlink-moderoutelocal-useradminclassmanageservice-typetelnethttphttpsiphttpenableiphttpsenable#县A静态xianAAAipunreachablesenablipttl-expiresenablepolicy-based-routexxxpermitnode2linevty04authentication-modeschemeuser-rolenetwork-operatorlinevty563user-rolenetwork-operator#acladvanced3300#acladvanced3333
copyright@ 2008-2022 冰豆网网站版权所有
经营许可证编号:鄂ICP备2022015515号-1