Cisco2950交换机配置.doc_第1页
Cisco2950交换机配置.doc_第2页
Cisco2950交换机配置.doc_第3页
Cisco2950交换机配置.doc_第4页
Cisco2950交换机配置.doc_第5页
已阅读5页,还剩5页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

百度空间|百度首页 | 登录 零度空间我的空间,我的世界.主页博客相册|个人档案 |好友 查看文章思科2950交换机相关配置2009-04-27 14:22基本操作2950(config)#int vlan12950(config-if)#ip address 00 (VLAN1里面设置IP地址)2950(config)#ip default-gateway (设置默认网关)2950(config)#ip name-server (设置域名服务器)2950(config)#ip domain-name (设置域名)端口配置2950(config)#int f0/1 (进入接口)2950(config-if)#speed 100 (设置该接口速率为100Mb/s)2950(config-if)#duplex ?auto Enable AUTO duplex configurationfull Force full duplex operationhalf Force half-duplex operation2950(config-if)#description to_router1 (设置端口描述)2950#show interfaces fastethernet1 status (查看端口配置结果和状态)MAC地址表相关命令2950(config)#mac-address-table aging-time 100 (设置超时时间为100S)2950(config)#mac-address-table permanent 000.0c01.bbcc f0/3 (加入永久地址)2950(config)#mac-address-table restricted static 0000.0c02.bbcc f0/6 f0/7 (加入静态地址)2950#show mac-address-table (查看整个MAC地址表)2950#clear mac-address-table restricted static (清除限制性MAC址表)VTP的配置2950#vlan database (进入VLAN配置模式)2950(vlan)#vtp ? (查看VTP的子命令)domain Set the name of the VTP administrative domain.client Set the device to client mode.server Set the device to server mode.transparent Set the device to transparent mode.password Set the password for the VTP administrative domain.2950(vlan)#vtp domain server (设置本交换机为SEVER模式)2950(vlan)#vtp domain wqs (设置域名)2950(vlan)#vtp pruning (启动修剪模式)2950#show vtp status (查看VTP设置信息)配置VLAN TRUNK端口2950(config)#int f0/11 (进入F端口)2950(config-if)#switchport mode trunk (设置该端口为TRUNK模式)2950(config-if)#switchport trunk encapsulation dot1q | isl | negotiate (设置TRUNK封装)创建VLAN2950#vlan database (进入VLAN配置模式)2950(vlan)#vlan 2 (创建VLAN 2)VLAN 2 added:Name:VLAN0002 (系统默认名)2950(vlan)#vlan 3 name wg_bisheng (创建VLAN 3,名为网工必胜)VLAN 3 added:Name:wg_bisheng2950(config)#int f0/9 (进入接口配置模式)2950(config-if)#switchport mode access (设置该接口为ACCESS模式)2950(config-if)#switchport access vlan 2 (把端口9分配给VLAN2)2950(config-if)#int f0/82950(config-if)#switchport mode access2950(config-if)#switchport access vlan 32950(config-if)#end生成树协议的配置生成树负载均衡实现方法(感谢黑客天使提醒)1 使用STP端口权值实现。2 使用STP路径值实现2950(config)#int f0/112950(config-if)#spanning-tree vlan 2 port-priority 10 (将VLAN2的端口权值设为10)2950(config-if)#spanning-tree vlan 2 cost 30 (设置VLAN2生成树路径值为30)路由器的一些设置静态路由:Router(config)#ip route destination-network network-mask next-hop-ip | interface distanceRouter(config)#ip route 其中:192。168。1。0代表目标网络。2552552550代表目标网络的子网掩码;10111代表下一跳地址。next-hop-ip:到达目的网络所经由的下一跳路由器接口的IP地址。Interface:到达目标网络的本机接口(仅限P2P线路)Distance:为该路由人工指定管理距离默认路由:Router(config)#ip route next-hop-ip | interface distanceRouter(config)#ip route 其中:0。0。0。0 0。0。0。0代表任意地址和任意掩码,即所有网络,其它参数同静态路由。选择性通告路由:如在RIP设置中,让S0端口只收不发RIP通告。Router(config)#router ripRouter(config-router)#passive-interface serial 0常见路由协议的管理距离:TABLE 5 . 2 Default Administrative DistancesRoute Source Default ADConnected interface 0Static route 1EIGRP 90IGRP 100OSPF 110RIP 120External EIGRP 170Unknown 255 (this route will never be used)ISDN(DDR,PRI,BRI,PPP)相关命令r1(config)#isdn switch-type ? (设置ISDN交换类型)basic-1tr6 1TR6 switch type for Germanybasic-5ess AT&T 5ESS switch type for the U.S.basic-dms100 Northern DMS-100 switch typebasic-net3 NET3 switch type for UK and Europebasic-ni National ISDN switch typebasic-ts013 TS013 switch type for Australiantt NTT switch type for Japanvn3 VN3 and VN4 switch types for Franceprimary-5essbasic-ni1 Basic-Ni1r1(config)#username name password secret (指定口令)r1(config)#interface bri0 (接口BRI设置)r1(config-if)#encapsulation ppp (设置PPP封装)r1(config-if)#ppp authentication chap|chap pap |pap chap|papcallin(设置认证方式)r1(config-if)# dialer map ip name router1 broadcast 7782001 (设置协议地址与电话号码的映射)r1(config-if)#ppp multilink (启动PPP多连接)r1(config-if)#dialer load-threshold load(设置启动另一个B通道的阈值)r1(config-if)#clock rate speed (设置DCE端的线速度)r1#sh isdn ? (查看ISDN相关信息)active ISDN active callshistory ISDN call historymemory ISDN memory informationstatus ISDN Line Statustimers ISDN Timer values一般需要配置的信息有ISDN交换机类型,IP地址,封装类型,拨号串,拨号组,拨号列表等信息。r2(config)#isdn switch-type basic-net3 (设置ISDN交换类型)r2(config)#int bri0 (进入BRI接口配置模式)r2(config-if)#ip address (设置接口IP地址)r2(config-if)#encapsulation ppp (封装协议为PPP)r2(config-if)#dialer string 88888888 (设置拨号串,R1的ISDN号码)r2(config-if)#dialer-group 1 (设置拨号组号码为1,把BRI0接口与拨号列表1相关联)r2(config-if)#no sh (激活接口)%LINK-3-UPDOWN: Interface Bri0, changed state to upr2(config-if)#exitr2(config)#dialer-list 1 protocol ip permit (设置拨号列表1)r1(config-if)#dialer idle-timeout 30r1(config-if)#dilaer load-threshold 128r1(config-if)#ppp authentication chapr1(config)#dialer-list 1 protocol ip permit上面整理得有点乱,详细实例见以下三个实验,建议大家用模拟器实践以强化记忆。LAB 17 ISDN BRI-BRI using Legacy DDRRouter IP Address Mask SPID1 Local Tel# ISDN Switchrouter1 /24 32177820010100 7782001 basic-nirouter2 /24 32177820020100 7782002 basic-nirouter1(config)# isdn switch-type basic-nirouter1(config)# dialer-list 1 protocol ip permitrouter1(config)# username router2 password ciscorouter1(config)# interface bri0router1(config-if)# encap ppprouter1(config-if)# ip address router1(config-if)# isdn spid1 32177820010100router1(config-if)# dialer-group 1router1(config-if)# dialer map ip name router2 broadcast 7782002router1(config-if)# ppp authentication chaprouter1(config-if)# no shutrouter2(config)# isdn switch-type basic-nirouter2(config)# dialer-list 1 protocol ip permitrouter2(config)# username router1 password ciscorouter2(config)# interface bri0/0router2(config-if)# encap ppprouter2(config-if)# ip address router2(config-if)# isdn spid1 32177820020100router2(config-if)# dialer-group 1router2(config-if)# dialer map ip name router1 broadcast 7782001router2(config-if)# ppp authentication chaprouter2(config-if)# no shutLAB 18 ISDN BRI-BRI using Dialer ProfilesRouter IP Address Mask SPID1 Local Tel# ISDN Switchrouter1 /24 32177820010100 7782001 basic-nirouter2 /24 32177820020100 7782002 basic-nirouter1(config)# isdn switch-type basic-nirouter1(config)# dialer-list 1 protocol ip permitrouter1(config)# username router2 password ciscorouter1(config)# interface bri0router1(config-if)# encap ppprouter1(config-if)# ppp authentication chaprouter1(config-if)# isdn spid1 32177820010100router1(config-if)# dialer pool-member 1router1(config-if)# no shutrouter1(config-if)# interface dialer 1router1(config-if)# no shutrouter1(config-if)# ip address router1(config-if)# encap ppprouter1(config-if)# dialer-group 1router1(config-if)# dialer pool 1router1(config-if)# dialer remote-name router2router1(config-if)# dialer string 7782002router1(config-if)# ppp authentication chaprouter2(config)# isdn switch-type basic-nirouter2(config)# dialer-list 1 protocol ip permitrouter2(config)# username router1 password ciscorouter2(config)# interface bri0/0router2(config-if)# encap ppprouter2(config-if)# ppp authentication chaprouter2(config-if)# isdn spid1 32177820020100router2(config-if)# dialer pool-member 1router2(config-if)# no shutrouter2(config-if)# interface dialer 1router2(config-if)# no shutrouter2(config-if)# ip address router2(config-if)# encap ppprouter2(config-if)# dialer-group 1router2(config-if)# dialer pool 1router2(config-if)# dialer remote-name router1router2(config-if)# dialer string 7782001router2(config-if)# ppp authentication chapLAB 19 ISDN PRI using Dialer ProfilesRouter IP Address Mask SPID1 Local Tel# ISDN Switchrouter1 /24 32177820010100 7782001 basic-nirouter2 /24 - 7782002 primary-5essrouter1(config)# isdn switch-type basic-nirouter1(config)# dialer-list 1 protocol ip permitrouter1(config)# username router2 password ciscorouter1(config)# interface bri0/0router1(config-if)# encap ppprouter1(config-if)# ppp authentication chaprouter1(config-if)# isdn spid1 32177820010100router1(config-if)# dialer pool-member 1router1(config-if)# no shutrouter1(config-if)# interface dialer 2router1(config-if)# no shutrouter1(config-if)# ip address router1(config-if)# encap ppprouter1(config-if)# dialer-group 1router1(config-if)# dialer pool 1router1(config-if)# dialer remote-name router2router1(config-if)# dialer string 7782002router1(config-if)# ppp authentication chaprouter2(config)# isdn switch-type primary-5esssrouter2(config)# dialer-list 1 protocol ip permitrouter2(config)# username router1 password ciscorouter2(config)# controller t1 0/0router2(config-controller)# framing esfrouter2(config-controller)# linecode b8zsrouter2(config-controller)# pri-group timeslots 1-24router2(config-controller)# exitrouter2(config)# interface serial0/0:23router2(config-if)# encapsulation ppprouter2(config-if)# ppp authentication chaprouter2(config-if)# dialer pool-member 2router2(config-if)# no shutrouter2(config-if)# interface dialer 2router2(config-if)# ip address router2(config-if)# encapsulation ppprouter2(config-if)# dialer-group 1router2(config-if)# dialer pool 2router2(config-if)# dialer remote-name router1router2(config-if)# dialer string 7782001router2(config-if)# ppp authentication chaprouter2(config-if)# no shutFR的配置Router(config-if)#encapsulation frame-relay ietf|cisco (在相关接口上封装FR)Router(config-if)#frame-relay lmi-type ? (设置LMI类型)ciscoansiq933aRouter(config-if)#frame-relay interface-dlci 100 (设置FR DLCL编号)Router(config-if)#frame-relay map ip 100 broadcast(映射协议地址与DLCL)Router(config)#interface serial 0/0.1 point-to-point | multipoint (设置子接口)Router#sh frame-relay ? (查看FR状态)map Frame-Relay map tablepvc show frame relay pvc statisticslmi show frame relay lmi statisticsroute show frame relay routesvc show frame relay SVC stufftraffic Frame-Relay protocol statisticsLAB 20 FRAME RELAYRouter Interface IP Address Local DLCIrouter1 serial 1 /24 105router5 serial 0 /24 501router1(config)# interface serial1router1(config-if)# encapsulation frame-relayrouter1(config-if)# ip address router1(config-if)# frame-relay map ip 105 broadcastrouter1(config-if)# frame-relay lmi-type ansirouter1(config-if)# no shutrouter5(config)# interface serial0router5(config-if)# encapsulation frame-relayrouter5(config-if)# ip address router5(config-if)# frame-relay map ip 501 broadcastrouter5(config-if)# frame-relay lmi-type ansirouter5(config-if)# no shutrouter1(config)# interface serial1router1(config-if)# no ip address router1(config-if)# no frame map ip 105 broadcastrouter1(config-if)# interface serial1.1 point-to-pointrouter1(config-subif)# ip address router1(config-subif)# frame-relay interface-dlci 105router5(config)# interface serial0router5(config-if)# no ip address router5(config-if)# no frame map ip 501 broadcastrouter5(config-if)# interface serial0.1 point-to-pointrouter5(config-subif)# ip address router5(config-subif)# frame-relay interface-dlci 501配置NAT静态NAT:Router(config-if)#ip nat outside | inside 定义外部接口和内部接口。Router(config)#ip nat inside | outside source static source_address translate_address定义源地址翻译。router1(config)# ip nat inside source static router1(config)# interface ethernet0router1(config-if)# ip address router1(config-if)# ip nat insiderouter1(config-if)# interface serial0router1(config-if)# ip address router1(config-if)# ip nat outsiderouter1(config-if)# no shut动态NATRouter(config)#ip nat pool netmask | prefix-length router1(config)# no ip nat inside source static router1(config)# ip nat pool pool1 0 00 netmask router1(config)# ip nat inside source list 1 pool pool1router1(config)# access-list 1 permit 55OVERLOAD:router1(config)# ip nat inside source list 1 interface serial0 overloadrouter1(config)# interface Ethernet 0router1(config-if)# ip address router1(config-if)# ip nat insiderouter1(config-if)# interface serial 0router1(config-if)# ip address router1(config-if)# ip nat outsiderouter1(config-if)# exitrouter1(config)# access-list 1 permit 55VPN的基本配置作者:yc_liang2003-4-24VPN的基本配置工作原理:一边服务器的网络子网为/24路由器为另一边的服务器为/24路由器为。执行下列步骤:1. 确定一个预先共享的密钥(保密密码)(以下例子保密密码假设为noIP4u)2. 为SA协商过程配置IKE。3. 配置IPSec。配置IKE:Shelby(config)#crypto isakmp policy 1注释:policy 1表示策略1,假如想多配几个VPN,可以写成policy 2、policy3Shelby(config-isakmp)#group 1注释:除非购买高端路由器,或是VPN通信比较少,否则最好使用group 1长度的密钥,group命令有两个参数值:1和2。参数值1表示密钥使用768位密钥,参数值2表示密钥使用1024位密钥,显然后

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论