Chinaunix首页 | 论坛 | 博客
  • 博客访问: 325256
  • 博文数量: 77
  • 博客积分: 1925
  • 博客等级: 上尉
  • 技术积分: 1065
  • 用 户 组: 普通用户
  • 注册时间: 2012-03-13 17:26
文章分类
文章存档

2012年(77)

我的朋友

分类: 网络与安全

2012-03-13 18:02:47

CISCO3560#show run 查看交换没什么运行信息
CISCO3560#config terminal 进入配置子模式
CISCO3560(config)#enable passowrd cisco 设置PASSWORD密码
CISCO3560(config)#enable secret cisco1 设置SECRET密码
CISCO3560(config)#hostname CISCO3560 设置主机名
CISCO3560(config)#ip domain name heady 设置域名
CISCO3560(config)#ip name-server 10.10.60.100 设置域名服务器
CISCO3560(config)#exit

CISCO3560#show vlan 查看VLAN信息
CISCO3560#show vtp status 查看VTP信息
CISCO3560#vlan database 进入VLAN配置模式
CISCO3560(vlan)#vtp server (client) 设置为VTP SERVER(client)
CISCO3560(vlan)#vtp domain heady 设置vtp域名
CISCO3560#vtp domian password cisco 设置vtp密码
CISCO3560(vlan)#vtp pruning 启动修剪功能 server时
CISCO3560(vlan)#exit

CISCO3560#vlan database 进入VLAN子模式
CISCO3560(vlan)#vlan 2 创建VLAN2,系统会自动命名
CISCO3560(vlan)#vlan 3 name vlan_003 创建VLAN3,命名为LAN_003


配置IP,给某一VLAN,一般为DEFAULT
CISCO3560(config)#interface vlan8
CISCO3560(config-if)#ip address 10.10.60.233 255.255.255.0 设置交换机IP
CISCO3560(config-if)#ip default-gateway 192.168.0.254 设置默认网关

CISCO3560(config)#interface fastethernet0/48 进入48口
CISCO3560(config-if)switchport trunk encapsulation dot1q
CISCO3560(config-if)#switchport mode trunk 设成TRUNK口
CISCO3560(config-if)#switchport allowed vlan all 允许所有VLAN从此口通过

CISCO3560(config)#interface fastethernet0/2 进入F0/2
CISCO3560(config-if)#switchport mode access 设成静态VLAN访问模式
CISCO3560(config-if)#switchport access vlan 3     3是最前面的编号,将此口分给VLAN3

CISCO3560#show interface fastethernet0/1 查看配置结果
CISCO3560#show interface fastethernet0/1 status 查看状态
CISCO3560#c onfig terminal 进入配置子模式
CISCO3560(config)#interface fastethernet0/1
CISCO3560(config-if)speed ?
CISCO3560(config-if)speed 100 设置端口速率100Mb/S
CISCO3560(config-if)duplex ?
CISCO3560(config-if)duplex full 设置为全双工
CISCO3560(config-if)description PortA 端口描述为PORTA


CISCO3560#show mac-address-table
CISCO3560(config)#mac-address-table ?
CISCO3560(config)#mac-address-table aging-time 100 设置超时时间为100S
CISCO3560(config)#mac-address-table permanent 0000.0c01.bbcc f0/3 加入永久地址
CISCO3560(config)#mac-address-table restricted static 0000.0c02.bbcc f0/6 f0/7 加入静态地址
CISCO3560(config)#exit
CISCO3560#clear mac-address-table restricted static 清除限制性地址


CISCO3560(config)#interface fastethernet0/47
CISCO3560(config-if)#spanning-tree vlan 2 port-priority 10 将VLAN2的端口权值设成10
VLAN3没设,默认128
CISCO3560(config)#interface fastethernet0/48
CISCO3560(config-if)#spanning-tree vlan 3 port-priority 10 将VLAN3的端口权值设成10
VLAN2没设,默认128


CISCO3560(config)#interface fastethernet0/47
CISCO3560(config-if)#spanning-tree vlan 2 cost 10 VLAN2生成树路径值10
CISCO3560(config-if)#spanning-tree vlan 3 cost 30 VLAN3生成树路径值30
CISCO3560(config-if)#exit
CISCO3560(config)#interface fastethernet0/48
CISCO3560(config-if)#spanning-tree vlan 2 cost 30 VLAN2生成树路径值30
CISCO3560(config-if)#spanning-tree vlan 3 cost 10 VLAN3生成树路径值10
这样,在有两条TRUNK时会走路径值小的

cisco-12805(config)#no switchport trunk encapsulation dot1q      802.1q
cisco-12805(config)#no switchport mode trunk
cisco-12805(config)#switchport trunk encapsulation dot1q
cisco-12805(config)#switc trunk allowed vlan 1-6,8-630,633-4094
cisco-12805(config)#switchport mode trunk
cisco-12805(config)#no ip address
cisco-12805(config)#ip classless
cisco-12805(config)#ip http server
cisco-12805(config)#int fa0/48
cisco-12805(config-if)#no shutdown
cisco-12805(vlan)#vtp password                         
cisco-12805(vlan)#exit
cisco-12805#show vtp password


设置可以远程登陆,同时五个
cisco-12805(config)#line vty 0 4
cisco-12805(config-line)#pass
cisco-12805(config-line)#password cisco
cisco-12805(config-line)#login


conf t 下加入以下
interface vlan1
no ip address
shutdown
interface vlan8
ip address 10.10.60.233 255.255.255.0
ip default-gateway 10.10.60.254
ip classless
ip http server
logging history notifications
logging trap notifications
logging 10.10.60.100
snmp-server community heady RO
snmp-server community asezj RW
snmp-server system-shutdown
snmp-server enable traps snmp authentication warmstart linkdown linkup coldstart
snmp-server enable traps config
snmp-server enable traps entity
snmp-server enable traps flash insertion removal
snmp-server enable traps bridge
snmp-server enable traps stpx
snmp-server enable traps rtr
snmp-server enable traps port-security
snmp-server enable traps vtp
snmp-server enable traps vlancreate
snmp-server enable traps vlandelete
snmp-server enable traps envmon fan shutdown supply temperature status
snmp-server enable traps MAC-Notification
snmp-server enable traps hsrp
snmp-server enable traps cluster
snmp-server enable traps copy-config
snmp-server enable traps syslog
snmp-server enable traps vlan-membership
snmp-server host 10.10.60.100 heady

无线AP

ap#sh run
Building configuration...

Current configuration : 2156 bytes
!
version 12.3
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname ap
!
enable secret 5 $1$g3jV$5H523EPucg2x9PKZ7iwtz.
!
ip subnet-zero
no ip domain lookup
!
ip dhcp pool test
network 192.168.0.0 255.255.255.0
dns-server 192.168.0.1
!
!
no aaa new-model
!
dot11 ssid XXXXXX(设置用户名)
authentication open (开启无线标准)
!
power inline negotiation prestandard source
!
!
username Cisco privilege 15 password 7 030752180500
!
bridge irb
!
!
interface Dot11Radio0
no ip address
no ip route-cache
delay 16000000
!
encryption key 1 size 128bit/40bit 7 XXXXXXXXXXXXXXXXXXXXXXXXXXXX transmit-key
(密码认证,最多4个,128/40位的密码128位为26个字符,40位13个字符)
encryption mode wep mandatory (WEP认证模式)
!
ssid XXXXX(用户名)
!
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root
antenna receive left
antenna transmit left
antenna gain 3
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled
!
interface Dot11Radio1(Dot11Radio0 设置一样,但是没必要设置)
no ip address
no ip route-cache
!
ssid XXXXX(用户名)
!
speed basic-6.0 9.0 basic-12.0 18.0 basic-24.0 36.0 48.0 54.0
station-role root
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled
!
interface FastEthernet0
ip address X.X.X.X X.X.X.X.X(以后好telnet管理,掩码一定要设置正确,否则延时会很大的)
no ip route-cache
duplex auto
speed auto
bridge-group 1
no bridge-group 1 source-learning
bridge-group 1 spanning-disabled
!
interface BVI1(虚端口,上面设置成功以后自己自动UP)
ip address DHCP (没有DHCP服务器的,需要手工设置)
no ip route-cache
!
ip http server
no ip http secure-server
ip http help-path
ip radius source-interface BVI1
!
!
control-plane
!
bridge 1 route ip
!
!
!
line con 0
logging synchronous
transport preferred all
transport output all
line vty 0 4
login local
transport preferred all
transport input all
transport output all
line vty 5 15
login
transport preferred all
transport input all
transport output all
!
end

阅读(2042) | 评论(1) | 转发(0) |
给主人留下些什么吧!~~

哇哦哇2012-03-19 02:07:00

好复杂的基本配置⊙﹏⊙b汗