免费预览已结束,剩余7页可下载查看
下载本文档
版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
华为5624交换机配置规范文档5624核心交换机规范配置文档进入交换机配置命令行后,须作如下配置:进入系统视图systemview设置主机名,用于区别其他交换机。主机名最好包括交换机型号,以及交换机在网络中所起的作用等信息。 Quidwaysysname Center-5624配置Vlan时须对Vlan描述,帮助网络管理员确认该Vlan的用途与连接网络的范围。防止长时间后难于正确识别Vlan用途。Center-5624vlan 2Center-5624-vlan2description menzhen-lowCenter-5624-vlan2quitCenter-5624vlan 3Center-5624-vlan3description zhuyuan-lowCenter-5624-vlan3quitCenter-5624vlan 4Center-5624-vlan4description xingdai-lowCenter-5624-vlan4quitCenter-5624vlan 5Center-5624-vlan5description fengyuanCenter-5624-vlan5quitCenter-5624vlan 6Center-5624-vlan6description mengzhendianCenter-5624-vlan6quit配置VLAN的3层虚拟接口时,注意3层接口的地址与Vlan号最好要有对应关系。比如Vlan2接口对应地址为192.168.2.1,Vlan3接口对应地址为192.168.3.1.其他应如此类推。Center-5624interface vlan 1Center-5624-vlan-interface1ip address 192.168.1.1 255.255.255.0Center-5624-vlan-interface1quitCenter-5624interface vlan 2Center-5624-vlan-interface2ip address 192.168.2.1 255.255.255.0Center-5624-vlan-interface2quitCenter-5624interface vlan 3Center-5624-vlan-interface3ip address 192.168.3.1 255.255.255.0Center-5624-vlan-interface3quitCenter-5624interface vlan 4Center-5624-vlan-interface4ip address 192.168.4.1 255.255.255.0Center-5624-vlan-interface4quitCenter-5624interface vlan 5Center-5624-vlan-interface5ip address 192.168.5.1 255.255.255.0Center-5624-vlan-interface5quitCenter-5624interface vlan 6Center-5624-vlan-interface6ip address 192.168.6.1 255.255.255.0Center-5624-vlan-interface5quit如果是将多个接口批量加入某个VLAN中,如下命令将相关接口加入对应VLAN2、VLAN3、VLAN4。Center-5624vlan 2Center-5624-vlan2port GigabitEthernet 1/0/1 to GigabitEthernet 1/0/3Center-5624vlan 3Center-5624-vlan3port GigabitEthernet 1/0/4 to GigabitEthernet 1/0/6Center-5624vlan 4Center-5624-vlan4port GigabitEthernet 1/0/7 to GigabitEthernet 1/0/8配置将个别特定物理接口加入某个Vlan中。可采用如下命令:Center-5624interface GigabitEthernet 1/0/9Center-5624-GigabitEthernet1/0/9port access vlan 5Center-5624interface GigabitEthernet 1/0/10Center-5624-GigabitEthernet1/0/9port access vlan 6创建交换机访问控制列表,控制所有VLAN只能与VLAN1互访,而不能与VLAN1已外的VLAN互访。Center-5624acl number 3000Center-5624-acl-adv-3000rule 100 permit ip source 192.168.1.0 0.0.0.255 destion any上述访问控制列表规则让VLAN1的IP地址可以访问所以其他所有VLAN。Center-5624-acl-adv-3000rule 90 permit ip source 192.168.0.0 0.0.255.255 destination 192.168.1.0 0.0.0.255上述访问控制列表规则让所有VLAN的IP地址可以访问VLAN1。Center-5624-acl-adv-3000rule 80 permit ip source 192.168.0.0 0.0.255.255 destination 192.168.0.1 0.0.255.0上述访问控制列表规则让所有VLAN的IP地址可以访问网关IP地址:192.168.X.1Center-5624-acl-adv-3000rule 70 deny ip source 192.168.0.0 0.0.255.255 destination 192.168.0.0 0.0.255.255上述访问控制列表规则让所有VLAN的IP地址都不能互访。Center-5624-acl-adv-3000quitCenter-5624创建的访问控制列表要真正起作用,必须在交换机接口上启用该访问控制列表。以下命令将访问控制列表在交换机所有接口使用。center-5624interface GigabitEthernet 1/0/1center-5624-GigabitEthernet1/0/1packet-filter inbound ip-group 3000center-5624-GigabitEthernet1/0/1quitcenter-5624interface GigabitEthernet 1/0/2center-5624-GigabitEthernet1/0/2packet-filter inbound ip-group 3000center-5624-GigabitEthernet1/0/2quitcenter-5624interface GigabitEthernet 1/0/24center-5624-GigabitEthernet1/0/24packet-filter inbound ip-group 3000center-5624-GigabitEthernet1/0/24quit下列命令用于配置telnet用户的相关信息,包括用户名,用户口令,用户类型,用户级别。Center-5624local-user gzyyadminCenter-5624-luser-adminservice-type telnetCenter-5624-luser-adminpassord simple new2006Center-5624-luser-adminlevel 3在telnet的用户接口中指定登陆验证方式是交换机本地的用户数据库验证,并指定登陆的用户级别是最高级别:3级。Center-5624user-interface vty 0 4Center-5624-ui-vty0-4authentication-mode schemeCenter-5624-ui-vty0-4user privilege level 3保存配置。Center-5624saveCenter-5624quit以下是桂洲医院5624交换机完整配置文件。# sysname center-5624#radius scheme system#domain system #local-user gzyyadmin password simple new2006 service-type telnet level 3#acl number 3000 rule 70 deny ip source 192.168.0.0 0.0.255.255 destination 192.168.0.0 0.0.255.255 rule 80 permit ip source 192.168.0.0 0.0.255.255 destination 192.168.0.1 0.0.255.0 rule 90 permit ip source 192.168.0.0 0.0.255.255 destination 192.168.1.0 0.0.0.255 rule 100 permit ip source 192.168.1.0 0.0.0.255 #vlan 1#vlan 2 description menzhen-low#vlan 3 description zhuyuan-low#vlan 4 description xingdai-low#vlan 5 description fengyuan#vlan 6 description mengzhendian#interface Vlan-interface1 ip address 192.168.1.1 255.255.255.0 #interface Vlan-interface2 ip address 192.168.2.1 255.255.255.0 #interface Vlan-interface3 ip address 192.168.3.1 255.255.255.0 #interface Vlan-interface4 ip address 192.168.4.1 255.255.255.0 #interface Vlan-interface5 ip address 192.168.5.1 255.255.255.0 #interface Vlan-interface6 ip address 192.168.6.1 255.255.255.0 #LOCCFG. MUST NOT DELETE#interface Aux1/0/0#interface GigabitEthernet1/0/1 port access vlan 2 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/2 port access vlan 2 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/3 port access vlan 2 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/4 port access vlan 3 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/5 port access vlan 3 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/6 port access vlan 3 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/7 port access vlan 4 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/8 port access vlan 4 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/9 port access vlan 5 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/10 port access vlan 6 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/11 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/12 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/13 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/14 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/15 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/16 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/17 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/18 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/19 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/20 packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/21 shutdown packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/22 shutdown packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/23 shutdown packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rule 90 packet-filter inbound ip-group 3000 rule 100#interface GigabitEthernet1/0/24 shutdown packet-filter inbound ip-group 3000 rule 70 packet-filter inbound ip-group 3000 rule 80 packet-filter inbound ip-group 3000 rul
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- (2025年)采购专员考试试题及答案
- 2026年浦东新区公办学校教师招聘考核通过人员备考题库(第一批)及一套答案详解
- 2026吉林大学白求恩第一医院教学部招聘备考题库有完整答案详解
- 2025年财经法规习题+答案
- 2025福建厦门市杏南中学产假顶岗教师招聘1人备考题库及1套完整答案详解
- 2025年监控室考试试题及答案
- 2025年牙科门诊考试试题及答案
- (2025年)南宁市武鸣区网格员考试试题及答案
- 2025年成人大专试卷及答案
- 2025年辽宁专升本试题及答案
- 福建省网络安全事件应急预案
- 五育融合课件
- 意识障碍的判断及护理
- 储能电站安全管理与操作规程
- 2025年宿迁市泗阳县保安员招聘考试题库附答案解析
- 交通安全企业培训课件
- 2025年广东省中考物理试卷及答案
- 皮革项目商业计划书
- 主管护师护理学考试历年真题试卷及答案
- 华文慕课《刑法学》总论课后作业答案
- 公路护栏波型梁施工方案
评论
0/150
提交评论