用户登录
用户注册

分享至

removevtypassword 交换机配置命令

  • 作者: 苏晴儿说我特别能干
  • 来源: 51数据库
  • 2020-04-21

请问你是什么牌?H3C Switch命令:

一、模式命令:

1. 用户模式:Switch>

2. 特权模式:Switch>enable

Switch#

3. 全局配置模式:Switch#config terminal

Switch(config)#

4. 接口配置模式:Switch(config)#interface fastethernet0/1

Switch(config-if)#

5. Line模式:Switch(config)#line console 0

Switch(config-line)#

二、特权模式下的命令:

1. 查看机MAC地址:Switch#show mac-address-table

2. 发现(CDP):

Switch#show cdp

Switch#show cdp interface fastethernet0/1

Switch#show cdp neighbors

Switch#show cdp neighbors detail

Switch#show cdp entry

3. 保存机配置:

Switch#copy running-config startup-config或者Switch#write

4. 恢复交换机出厂值:

Switch#erase startup-config

Switch#reload

三、全局配置模式下的命令:

1. 配置主机名:Switch(config)#hostname Sw1

Sw1(config)#

2、 设置登陆台密码:Switch(config)#line console 0

Switch(config-line)#password 密码

Switch(config-line)#login

3. 使能口令:Switch(config)#enable Password 密码

4. 加密保存的使能口令:Switch(config)#enable secret 密码

5. 配置IP地址:

Switch(config)#interface vlan 1

Switch(config-if)#ip address IP地址 网关

Switch(config-if)#no shutdown

6. 配置交换机网关:Switch(config)#ip default-gateway 网关

四、VLAN配置命令:

1. 创建vlan命令:

a) 全局配置模式下:

Switch(config)#vlan 2

Switch(config)#name v2

Switch(config)#mtu 数值

Switch(config)#end

b) Vlan数据库下:

Switch#vlan database

Switch#vlan 2 name v2

Switch#vlan 2 mut 数值

Switch#exit

2. 删除vlan命令:

a) 全局配置模式下:

Switch(config)#no vlan 2

Switch(config)#end

b) Vlan数据库下:

Switch#no vlan 2 name v2

Switch#exit

3. 在vlan中添加端口:

Switch#config terminal

Switch(config)#interface f0/1(端口)

Switch(config-if)#Switchport mode access

Switch(config-if)#switchport access vlan 2

Switch(config-if)#end

一次将多个端口添加到vlan中:

Switch#config terminal

Switch(config)#interface range f0/1 - 5(端口)

Switch(config-if)#switchport access vlan 2

Switch(config-if)#end

注:switch#show vlan biref(查看vlan信息)

4. 配置vlan trunk:

1. 配置接口为trunk命令:

Switch(config)# interface f0/1(端口)

Switch(config-if)#Switchport mode trunk

2. 配置接口为动态协商模式的命令:

Switch(config)# interface f0/1(端口)

Switch(config-if)#switchport mode dynamic desirable/auto

3. 从trunk中删除vlan:

Switch(config)# interface f0/1(端口)

Switch(config-if)#Switchport trunk allowed vlan remove 2

4. 在trunk中添加vlan:

Switch(config)# interface f0/1(端口)

Switch(config-if)#Switchport trunk allowed vlan add 2

-----------------------------------------------------------

Catalyst 2950交换机密码恢复

(1)拔下交换机的电源。

(2)用手按再交换机的MODE按键上,插上电源线。

(3)看到控制台出现如下提示,松开MODE建。

switch:

(4)再switch:后执行flash_init命令。

(5)查看Flash中的文件。

(6)把config.text文件改名为config.old文件。

(7)执行boot命令,启动交换机。

(8)进入特权模式查看flash里的文件。

(9)把文件config.old改为config.text文件。

(10)把config.text复制为系统的running-config.

(11)进入配置模式重新设置密码并存盘,密码恢复完成。

普通交换机常用配置命令?

  a、更改远程TELNNET密码

  Switch#configure terminal

  Switch(config)#line vty 0 4

  Switch(config-line)#password qycx123

  Switch(config-line)#login

  Switch(config-line)#exit

  b、更改进入全局配置模式时的密码

  Switch#configure terminal

  Switch(config)#enable secret qycx123

  思科交换机常用命令——创建并划分VLAN

  a、创建VLAN

  Switch#vlan database

  Switch(vlan)#vlan 99 name office (创建vlan 99 并命名为office)

  b、将端口划分至vlan

  Switch(config)#interface fastEthernet 0/8

  Switch(config-if)#switchport mode access

  Switch(config-if)#switchport access vlan 99 (将8号快速以太口划分至vlan 99)

  思科交换机常用命令——调试命令

  a、显示所有配置命令:Switch#show run

  b、显示所有接口状态:Switch#show ip int brief

  c、显示所有VLAN的信息:Switch#show vlan brief

  cisco交换机还是比较常用的,于是我研究了一下Cisco交换机命令的大总结,在这里拿出来和大家分享一下,希望对大家有用。我所针对的都是Cisco的设备而言的,华为的可以跟据手册来查,配置都是差不多的,这里华子就不多写华为的设备了,了解的也不是很多。

  Cisco交换机命令之使用Telnet远程式管理

  switch(config)#interface vlan 1 进入vlan 1

  switch(config-if)#ip address 设置IP地址

  switch(config-if)#ip default-gateway 设置默认网关

  switch(config)#line vty 0 4 进入虚拟终端

  switch(config-line)#login 允许登录

  switch(config-line)#password xx 设置登录口令

  switch#exit 返回命令

  Cisco交换机命令之控制台口令

  switch(config)#line console 0 进入控制台口

  switch(config-line)#login 允许登录

  switch(config-line)#password xx 设置登录口令

  switch#exit 返回命令

  Cisco交换机命令之基本接口配置

  switch(config)#interface f0/1 进入f0/1接口

  switch(config-if)#duplex full 配置全双工模式

  switch(config-if)#speed 100 配置速率

  switch(config-if)#description to ***** 接口描述

  switch(config)#ip domain-name ***.com 设置或名服务器

  switch(config)#mac-address-table aging-time 设置mac表超时时间

  switch#write 保存配置信息

  switch#copy running-config startup-config 保存当前配置nvram

  switch#erase startup-config 清除配置文件

  Cisco交换机命令之交换机VLAN设置:

  switch#vlan database 进入VLAN设置

  switch(vlan)#vlan 2 建VLAN 2

  switch(vlan)#name 名字 建VLAN 2的名称

  switch(vlan)#no vlan 2 删vlan 2

  注:删除vlan时原属于此vlan的端口处于非激活状态,直到重新分配为止。

  switch(config)#int f0/1 进入端口1

  switch(config-if)#switchport mode access 当前端口工作莫试

  switch(config-if)#switchport access vlan 2 当前端口加入vlan 2

  switch(config-if)#switchport mode trunk 设置为干线

  switch(config-if)#switchport trunk encapsulation dot1q 设置vlan 中继协议

  switch(config-if)#no switchport mode 或 ( switchport mode access) 禁用干线

  switch(config-if)#switchport trunk allowed vlan add 1,2 ; 从Trunk中添加vlans

  switch(config-if)#switchport trunk allowed vlan remove 1,2 ;从Trunk中删除vlans

  switch(config-if)#switchport trunk pruning vlan remove 1,2 ;从Trunk中关闭局部修剪

  Cisco交换机命令之以太网通道配置

  switch(config)#interface range fasternet0/1 - 2 将fasternet0/1和0/2 口捆绑

  switch(config-if)#channel-group 1 mode on 配置以太通道模式

  switch(config-if)#port-channel load-balance {dst-mac | src-mac}在链路间实现负载均衡

  switch#show etherchannel 1 summary 查看通道信息

  switch#show etherchannel load-balance 查看通道信息

  Cisco交换机命令之vtp配置

  switch(config)#vtp domain 设置vtp域名

  switch(config)#vtp password 设置vtp密码

  switch(config)#vtp mode server 设置vtp服务器模式

  switch(config)#vtp mode client 设置vtp客户机模式

  switch(config)#vtp mode transparent 设置vtp 透明模式

  switch(config)#vtp version 设置vtp版本

  switch(config)#vtp pruning 启用vtp修解

  switch(config)#no vtp pruning 关闭vtp修解

  注:要想从vtp中减少一台交换机只需将该交换机vtp 名更改

  Cisco交换机命令之生成树stp:

  switch(config)#spanning-tree vlan 启用stp生成树(基于vlan)

  switch(config)#spanning-tree vlan root primary 指定根交换机(基于vlan)

  switch(config)#spanning-tree vlan root secondary 指定备用根交换机(基于vlan)

  switch(config)#spanning-tree vlan priority 指定交换机优先级(基于vlan)

  switch(config)#no spanning-tree vlan priority 将交换机的优先级恢复默认值(基于vlan)

  switch(config-if)#spanning-tree vlan cost 指定端口成本(起用trunk的端口模式下)

  switch(config-if)#spanning-tree vlan port-prioty 指定交换机端口优先级(基于vlan)

  switch(config-if)#spanning-tree portfast 配置速端口(连接终端设备的端口状态)如pc机

  switch(config)#spanning-tree uplinkfast 配置上行速端口

  switch(config)#spanning-tree vlan hello-time 配置交换机hello时间(基于vlan)

  switch(config)#spanning-tree vlan forward-time 修改转发延迟计时器(基于vlan)

  switch(config)#spanning-tree vlan max-time 修改最大老化时间(基于vlan)

  switch#show spanning-tree summery 检测vlan生成树配置

  switch#show spanning-tree vlan detail 浏览详细生成树配置信息

  switch#show spanning-tree interface detail 浏览详细生成树端口配置信息

  Cisco交换机命令之交换机显示命令:

  switch#show vtp status 查看vtp配置信息

  switch#show running-config 查看当前配置信息

  switch#show vlan 查看vlan配置信息

  switch#show interface 查看端口信息

  switch#show int f0/0 查看指定端口信息

  switch#dir flash: 查看闪存

  switch#show version 查看当前版本信息

  switch#show mac-address-table aging-time 查看mac超时时间

  switch#show cdp cisco设备发现协议 (可以查看聆接设备)

  switch#show cdp traffic 杳看接收和发送的cdp包统计信息

  switch#show cdp neighbors 查看与该设备相邻的cisco设备

  switch#show interface f0/1 switchport 查看有关switchport的配置

  switch#show cdp neighbors 查看与该设备相邻的cisco设备

二层交换机为什么要配置IP地址

首先回答你第一个问题,交换机和PC是二层通信,因此他们之间靠的是MAC地址来通信,不会应用到ARP广播,它是三层的信息,就是在有路由的情况下才会用到它。

原理也很简单,因为你设置的IP和你绑定的IP冲突了,但是你在子网内通信也是属于二层通信。但是你要到达路由器的话,就要看你是怎样设置的了。

我跟你说以下路由器与PC得工作原理。

假如说有两台主机A B,它两也不再同一网段中,那么就要有三层的设备路由器来转发了。当主机A要与B通信时,A主机的数据包先到达自己的网关,然后主机A会通过ARP请求得知自己网关的MAC地址。在数据链路层A将IP数据包写入到以太网帧的数据包中。帧中的源MAC和目的MAC,分别是主机A 和网关的MAC地址。那么这个数据包就会到达A相连的路由器,路由器会重新打开以太网的数据帧,查看里面的信息。它会匹配路由表的条目,如果有在写入自己去B主机的接口的MAC,然后就这样依次类推。当到了对方是做的相反的动作。

怎样在锐捷交换机上配置vrrp、arp和mstp..

慢慢研究 、。。。。。。老师留的问题别老找枪手

交换机

密码

1234(config)#enable secret level 1 0 100

1234(config)#enable secret level 15 0 100

远程登入密码

1234(config)#line vty 0 4

1234(config-line)#password 100

1234(config-line)#end

交换机管理IP

1234(config)#interface vlan 1

1234(config-if)#ip address 192.168.1.10 255.255.255.0

1234(config-if)#no shutdown

修改交换机老化时间

1234(config)#mac-address-table aging-time 20

1234(config)#end

添删vlan

1234(config)#vlan 888

1234(config-vlan)#name a888

1234(config)#no vlan 888

添加access口

1234(config)#interface gigabitEthernet 0/10

1234(config-if)#switchport mode access

1234(config-if)#switchport access vlan 10

切换assess trunk

1234(config-if)#switchport mode access

1234(config-if)#switchport mode trunk

指定特定一个native vlan

1234(config-if)#switchport trunk native vlan 10

配置trunk口的许可vlan列表

1234(config-if)#switchport trunk allowed vlan ?

add Add VLANs to the current list

all All VLANs

except All VLANs except the following

remove Remove VLANs from the current list

速成树协议

1234(config)#spanning-tree

1234(config)#spanning-tree mode rstp/stp

配置网关:

switch(config)#ip default-gateway 192.168.1.254

交换机基本配置-常见查看命令

查看CPU利用率

show cpu

查看交换机时钟

show clock

查看交换机日志

show logging

查看交换机动态学习到的MAC地址表

show mac-address-table dynamic

查看当前交换机运行的配置文件

show running-config

查看交换机硬件、软件信息

show version

查看交换机的arp表

show arp

显示接口详细信息的命令

show interfaces gigabitEthernet 4/1 counters

接口配置

Switch(config)#interface gigabitethernet 0/1

把接口工作模式改为光口。

Switch(config-if)#medium-type fiber

把接口工作模式改为电口。

Switch(config-if)#medium-type copper

速度/双工配置

进入接口配置模式。

Switch(config)#interface interface-id

设置接口的速率参数,或者设置为auto。

Switch(config-if)#speed {10 | 100 | 1000 | auto }

设置接口的双工模式。

Switch(config-if)#duplex {auto | full | half}

例子

Switch(config)#interface gigabitethernet 0/1

Switch(config-if)#speed 1000

Switch(config-if)#duplex full

光口不能修改速度和双工配置,只能auto。

在故障处理的时候,如果遇到规律性的时断时续或掉包,在排除其他原因后,可以考虑是否和对端设备的速率和双工模式不匹配,尤其是两端设备为不同厂商的时候。

VLAN

建立VLAN 100

Switch (config)#vlan 100

该VLAN名称为ruijie

Switch (config)#name ruijie

将交换机接口划入VLAN 中:

range表示选取了系列端口1-48,这个对多个端口进行相同配置时非常有用。

Switch (config)#interface range f 0/1-48

将接口划到VLAN 100中。

Switch (config-if-range)#switchport access vlan 100

将接口划回到默认VLAN 1中,即端口初始配置。

Switch (config-if-range)#no switchport access vlan

Switch(config)#interface fastEthernet 0/1

该端口工作在access模式下

Switch(config-if)#switchport mode access

该端口工作在trunk模式下

Switch(config-if)#switchport mode trunk

Switch(config)#interface fastEthernet 0/2

设定VLAN要修剪的VLAN。

Switch(config-if)#switchport trunk allowed vlan remove 2-9,11-19,21-4094

取消端口下的VLAN修剪。

Switch(config-if)#no switchport trunk allowed vlan

生成树

开启生成树协议。

Switch(config)#spanning-tree

禁止生成树协议。

Switch(config)#no spanning-tree

配置生成树优先级:

配置设备优先级为4096。

Switch(config)#spanning-tree priority 4096

数值越低,优先级别越高。

端口镜像

配置G0/2为镜像端口。

Switch (config)# monitor session 1 destination interface G 0/2

配置G0/1为被镜像端口,且出入双向数据均被镜像。

Switch (config)# monitor session 1 source interface G 0/1 both

去掉镜像1。

Switch (config)# no monitor session 1

端口聚合

Switch(config)#interface fastEthernet 0/1

把端口f0/1加入到聚合组1中。

Switch (config-if)#port-group 1

把端口f0/1从聚合组1中去掉

Switch (config-if)#no port-group 1

建立ACL:

建立ACL访问控制列表名为ruijie,extend表示建立的是扩展访

Switch(config)# Ip access-list exten ruijie

问控制列表。

添加ACL的规则:

禁止PING IP地址为192.168.1.1的设备。

Switch (config-ext-nacl)#deny icmp any 192.168.1.1 255.255.255.0

禁止端口号为135的应用。

Switch (config-ext-nacl)# deny tcp any any eq 135

禁止协议为www的应用。

Switch (config-ext-nacl)#deny udp any any eq www

允许所有行为。

Switch(config-ext-nacl)# permit ip any any

将ACL应用到具体的接口上:

Switch (config)#interface range f 0/1

把名为ruijie的ACL应用到端口f 0/1上。

Switch (config-if)#ip access-group ruijie in

从接口去除ACL。

Switch (config-if)#no ip access-group ruijie in

删除ACL:

删除名为ruijie的ACL。

Switch(config)#no Ip access-list exten ruijie

增加ACE项后,是增加到ACL最后,不可以中间插入,如果要调整ACE的顺序,必须整个删除ACL后再重新配置。

端口安全

Switch (config)#interface range f 0/1

开启端口安全。

Switch(config-if)# switchport port-security

关闭端口安全。

Switch(config-if)# no switchport port-security

设置端口能包含的最大安全地址数为8。

Switch(config-if)# switchport port-security maximum 8

在接口fastethernet0/1配置一个安全地址00d0.f800.073c,并为其绑定一个IP地址192.168.1.1

Switch(config-if)# switchport port-security mac-address 00d0.f800.073c ip-address 192.168.1.1

删除接口上配置的安全地址。

Switch(config-if)#no switchport port-security mac-address 00d0.f800.073c ip-address 192.168.1.1

防ARP攻击

IP和MAC地址的绑定

Switch(config)#arp ip-address hardware-address [type] interface-id

Switch(config)#arp 192.168.12.111 00d0.f800.073c arpa g 0/1

绑定网关

进入指定端口进行配置。

Switch(config)#Interface interface-id

配置防止ip-address的ARP欺骗。

Switch(config-if)#Anti-ARP-Spoofing ip ip-address

防STP攻击

进入端口Fa0/1。

Switch(config)# inter fastEthernet 0/1

打开该端口的的BPDU guard功能。

Switch(config-if)# spanning-tree bpduguard enable

关闭该端口的的BPDU guard功能。

Switch(config-if)# spanning-tree bpduguard diaable

端口关闭后只能shutdown然后再no shutdown

或者重新启动交换机才能恢复!

防DOS/DDOS攻击

进入端口Fa0/1。

Switch(config)# inter fastEthernet 0/1

预防伪造源IP的DOS攻击的入口过滤功能。

Switch(config-if)#ip deny spoofing-source

关闭入口过滤功能只能在三层接口上配置。

Switch(config-if)#no ip deny spoofing-source

和ACL不能同时存在。

端口关闭后只能shutdown然后再no shutdown

或者重新启动交换机才能恢复!

防IP扫描攻击配置:

打开系统保护。

Switch(config)#system-guard enable

关闭系统保护功能。

Switch(config)#no system-guard

DHCP配置

打开DHCP Relay Agent:

Switch(config)#service dhcp

配置DHCP Server的IP地址:

Switch(config)#ip helper-address address

VRRP配置

Switch(config)#Interface interface-id

Switch(config-if)#Standby [group-number] ip ip-address

设置虚拟机的优先级。

standby [group-number] priority priority

三层交换机配置

SVI:

把VLAN 10配置成SVI。

switch (config)#interface vlan 10

给该SVI接口配置一个IP地址

switch (config-if)#ip address 192.168.1.1 255.255.255.0

Routed Port:

switch (config)#interface fa 0/1

把f 0/1变成路由口。

switch (config-if)#no switch

路由配置:

添加一条路由。

switch (config)#ip route 目的地址 掩码 下一跳

switch (config)#ip route 210.10.10.0 255.255.255.0 218.8.8.8

思科路由器和交换机的配置命令全集

1. switch配置命令

(1)模式转换命令

用户模式----特权模式,使用命令"enable"

特权模式----全局配置模式,使用命令"config t"

全局配置模式----接口模式,使用命令"interface+接口类型+接口号"

全局配置模式----线控模式,使用命令"line+接口类型+接口号"

注:

用户模式:查看初始化的信息.

特权模式:查看所有信息、调试、保存配置信息

全局模式:配置所有信息、针对整个路由器或交换机的所有接口

接口模式:针对某一个接口的配置

线控模式:对路由器进行控制的接口配置

(2)配置命令

show running config 显示所有的配置

show versin 显示版本号和寄存器值

shut down 关闭接口

no shutdown 打开接口

ip add +ip地址 配置IP地址

secondary+IP地址 为接口配置第二个IP地址

show interface+接口类型+接口号 查看接口管理性

show controllers interface 查看接口是否有DCE电缆

show history 查看历史记录

show terminal 查看终端记录大小

hostname+主机名 配置路由器或交换机的标识

config memory 修改保存在NVRAM中的启动配置

exec timeout 0 0 设置控制台会话超时为0

service password-encryptin 手工加密所有密码

enable password +密码 配置明文密码

ena sec +密码 配置密文密码

line vty 0 4/15 进入telnet接口

password +密码 配置telnet密码

line aux 0 进入AUX接口

password +密码 配置密码

line con 0 进入CON接口

password +密码 配置密码

bandwidth+数字 配置带宽

no ip address 删除已配置的IP地址

show startup config 查看NVRAM中的配置信息

copy run-config atartup config 保存信息到NVRAM

write 保存信息到NVRAM

erase startup-config 清除NVRAM中的配置信息

show ip interface brief 查看接口的谪要信息

banner motd # +信息 + # 配置路由器或交换机的描素信息

description+信息 配置接口听描素信息

vlan database 进入VLAN数据库模式

vlan +vlan号+ 名称 创建VLAN

switchport access vlan +vlan号 为VLAN为配接口

interface vlan +vlan号 进入VLAN接口模式

ip add +ip地址 为VLAN配置管理IP地址

vtp+service/tracsparent/client 配置SW的VTP工作模式

vtp +domain+域名 配置SW的VTP域名

vtp +password +密码 配置SW的密码

switchport mode trunk 启用中继

no vlan +vlan号 删除VLAN

show spamming-tree vlan +vlan号 查看VLA怕生成树议

2. 路由器配置命令

ip route+非直连网段+子网掩码+下一跳地址 配置静态/默认路由

show ip route 查看路由表

show protocols 显示出所有的被动路由协议和接口上哪些协议被设置

show ip protocols 显示了被配置在路由器上的路由选择协议,同时给出了在路由选择协议中使用

的定时器

等信息

router rip 激活RIP协议

network +直连网段 发布直连网段

interface lookback 0 激活逻辑接口

passive-interface +接口类型+接口号 配置接口为被动模式

debug ip +协议 动态查看路由更新信息

undebug all 关闭所有DEBUG信息

router eigrp +as号 激活EIGRP路由协议

network +网段+子网掩码 发布直连网段

show ip eigrp neighbors 查看邻居表

show ip eigrp topology 查看拓扑表

show ip eigrp traffic 查看发送包数量

router ospf +process-ID 激活OSPF协议

network+直连网段+area+区域号 发布直连网段

show ip ospf 显示OSPF的进程号和ROUTER-ID

encapsulation+封装格式 更改封装格式

no ip admain-lookup 关闭路由器的域名查找

ip routing 在三层交换机上启用路由功能

show user 查看SW的在线用户

clear line +线路号 清除线路

3. 三层交换机配置命令

配置一组二层端口

configure terminal 进入配置状态

nterface range {port-range} 进入组配置状态

配置三层端口

configure terminal 进入配置状态

interface {{fastethernet | gigabitethernet} interface-id} | {vlan vlan-id} | {port-

channel port-channel-number} 进入端口配置状态

no switchport 把物理端口变成三层口

ip address ip_address subnet_mask 配置IP地址和掩码

no shutdown 激活端口

例:

Switch(config)# interface gigabitethernet0/2

Switch(config-if)# no switchport

Switch(config-if)# ip address 192.20.135.21 255.255.255.0

Switch(config-if)# no shutdown

配置VLAN

configure terminal 进入配置状态

vlan vlan-id 输入一个VLAN号, 然后进入vlan配态,可以输入一个新的VLAN号或旧的来进行修改

。

name vlan-name 可选)输入一个VLAN名,如果没有配置VLAN名,缺省的名字是VLAN号前面用0填满

的4位数,如VLAN0004是VLAN4的缺省名字

mtu mtu-size (可选) 改变MTU大小

例

Switch# configure terminal

Switch(config)# vlan 20

Switch(config-vlan)# name test20

Switch(config-vlan)# end

或

Switch# vlan database

Switch(vlan)# vlan 20 name test20

Switch(vlan)# exit

将端口分配给一个VLAN

configure terminal 进入配置状态

interface interface-id 进入要分配的端口

switchport mode access 定义二层口

switchport access vlan vlan-id 把端口分配给某一VLAN

例

Switch# configure terminal

Enter configuration commands, one per line. End with CNTL/Z.

Switch(config)# interface fastethernet0/1

Switch(config-if)# switchport mode access

Switch(config-if)# switchport access vlan 2

Switch(config-if)# end

Switch#

配置VLAN trunk

configure terminal 进入配置状态

interface interface-Id 进入端口配置状态

switchport trunk encapsulation {isl | dot1q | negotiate}配置trunk封装ISL 或 802.1Q 或

自动协商

switchport mode {dynamic {auto | desirable} | trunk} 配置二层trunk模式。

dynamic auto—自动协商是否成为trunk

dynamic desirable—把端口设置为trunk如果对方端口是trunk, desirable, 配置Native VLAN

(802.1q)

或自动模式,trunk—设置端口为强制的trunk方式,而不理会对方端口是否为trunk

switchport access vlan vlan-id 可选) 指定一个缺省VLAN, 如果此端口不再是trunk

switchport trunk native vlan vlan-id 指定802.1Q native VLAN号

例:

Switch# configure terminal

Enter configuration commands, one per line. End with CNTL/Z.

Switch(config)# interface fastethernet0/4

Switch(config-if)# switchport mode trunk

Switch(config-if)# switchport trunk encapsulation dot1q

Switch(config-if)# end

定义TRUNK允许的VLAN

configure terminal子 进入配置状态

interface interface-id 进入端口配置

switchport mode trunk 配置二层口为trunk

switchport trunk allowed vlan {add | all | except | remove} vlan-list可选) 配置trunk允

许的VLAN.使用add, all, except, remove关健字

no switchport trunk allowed vlan 允许所有VLAN通过

例

Switch(config)# interface fastethernet0/1

Switch(config-if)# switchport trunk allowed vlan remove 2

Switch(config-if)# end

配置Native VLAN(802.1q)

configure terminal 进入配置状态

interface interface-id 进入配置成802.1qtrunk的端口

switchport trunk native vlan vlan-Id 配置native VLAN号

no switchport trunk native vlan 端口配置命令回到缺省的状态

配置基于端口权值的负载均衡

configure terminal 进入Switch 1配置状态

vtp domain domain-name 配置VTP域

vtp mode server 将Switch 1配置成VTP server.

show vtp status 验证VTP的配置

show vlan 验证VLAN

configure terminal 进入配置状态

interface fastethernet 0/1 进入F0/1端口

switchport trunk encapsulation {isl | dot1q | negotiate}配置trunk封装

switchport mode trunk 配置成trunk

show interfaces fastethernet0/1 switchport 验证VLAN配置

按以上步骤对想要负载均衡的接口进行配置

在另一个交换机上进行此配置

show vlan 当trunk已经起来,在switch2上验证已经学到相的vlan配置

configure terminal 在Switch 1上进入配置状态

interface fastethernet0/1 进入要配置的端口

spanning-tree vlan 8 port-priority 10 将端口权值10赋与VLAN 8.

spanning-tree vlan 9 port-priority 10 将端口权值10赋与VLAN 9.

spanning-tree vlan 10 port-priority 10 将端口权值10赋与VLAN 10.

interface fastethernet0/2 进入F0/2

spanning-tree vlan 3 port-priority 10 将端口权值10赋与VLAN 3.

spanning-tree vlan 4 port-priority 10 将端口权值10赋与VLAN 4

spanning-tree vlan 5 port-priority 10 将端口权值10赋与VLAN 5

spanning-tree vlan 6 port-priority 10 将端口权值10赋与VLAN 10

end 退出

show running-config 验证配置

copy running-config startup-config 保存配置

配置STP路径值的负载均衡

Trunk1走VLAN8-10,Trunk2走VLAN2-4

configure terminal 进入 Switch 1配置状态

interface fastethernet 0/1 进入F0/1

switchport trunk encapsulation {isl | dot1q | negotiate}配置封装

switchport mode trunk 配置Trunk,缺省是ISL封装

exit 退回

在F0/2口上重复2-4步骤

exit 退回

show running-config 验证配置

show vlan验证switch1 已经学到Vlan

configure terminal 进入配置状态

interface fastethernet 0/1 进入F0/1

spanning-tree vlan 2 cost 30 设置Vlan2生成树路径值为30

spanning-tree vlan 3 cost 30 设置Vlan3生成树路径值为30

spanning-tree vlan 4 cost 30 设置Vlan4生成树路径值为30

end 退出

在switch1的F0/2上重复9-11步骤设置VLAN8,9,10生成树路径值为30

end 退出

show running-config 验证配置

copy running-config startup-config 保存配置

补充:CISCO命令集——路由选择协议及排障

*ip route命令

Router(config)# ip route <目录网络或子网号> [子网掩码] <下一路由器IP地址 | 从本地出口

的地址> [管理距离0~255,默认为1]

(注:静态地址配置)

*ip default-network命令

Router(config)# ip default-network <目标网络号>

(注:配合路由协使用,用其中的一个动态路由号作默认路由配置)

Router(config)# ip route 0.0.0.0 0.0.0.0 <下一路由器IP地址 | 从本地出口的地址>

(注:只有一个公网地址时,在出口路由器上的配置)

*内部路由选择协议

*使用router和network命令

Router(config)# router <路由协议rip | igrp | eigrp | ospf | is-is等> [自主系统号]

Router(config-router)# network <直接相连的要用此路由协议的网络号>

Router(config-router)# network <直接相连的要用此路由协议的网络号>

*路由信息协议RIP

Router(config)# router rip

Router(config-router)# network <直接相连的要用rip协议的有类别网络号>

Router# show ip protocols

Router# show ip route

Router# debug ip rip

*内部网关路由协议IGRP

Router(config)# router igrp <自主系统号>

Router(config-router)# network <直接相连的要用igrp协议的有类别网络号>

Router# show ip interface

Router# show ip protocols

Router# show ip route

Router# debug ip rip

*排除网络故障

排除网络故障的一个总体模型

Router# ping <有故障的主机 | 有故障的IP地址>

Router# show ip route

Router# show interface <有故障的接口>

Router# show run

*IP的故故障排除

检查可用的路由

Router# show ip route <有故障的IP地址>

27.4.4 跟踪路由(Tracing the Route)

SUN-A> traceroute <有故障的主机 | 有故障的IP地址>

C:\windows\> winipcfg

C:\windows\> ipconfig

C:\windows\> ipconfig / all

C:\windows\> tracert <有故障的主机 | 有故障的IP地址>

使用扩展的ping来跟踪连接性

Router# ping

*其它可能的故障

一个地址解析(ARP)的故障

Router# show arp

Router# show interface <有故障的接口>

C:\windows\> arp -a

SUN-A> arp –a

验证终端系统的路由表

C:\windows\> netstat –rn

C:\windows\> route –f add 0.0.0.0 mask 0.0.0.0 <需要添加入的网关地址>

C:\windows\> route [–f ] [[print | add | delete | change] [destination] [mask

netmask] [gateway]]

C:\windows\> route add mask <网络掩码> <网关ip地址>

C:\windows\> route delete mask <网络掩码> <网关ip地址>

C:\windows\> nbtstat <相应的参数>

SUN-A> netstat -rn路由器

华为3600交换机配置问题

#

local-user admin

password simple admin

service-type telnet

level 3

#

user-interface vty 0 4

authentication-mode scheme

#用户部分

#

vlan 2

#

interface e1/0/1

...

int e1/0/20

默认都属于vlan1

int e1/0/20

port access vlan 2 加入到vlan2 也就是连接主线的。

#

int vlan 1

IP address 10.20.9.1 255.255.255.0 本地用户vlan

#

int vlan 2

IP address 172.30.0.37 255.255.255.252 很明显这是互联vlan。

#

ip rou 0.0.0.0 0.0.0.0 172.30.0.38

#

snmp-agent

snmp-agent community read public

snmp-agent community write private

snmp-agent sys-info version all

#

vlan3 没起作用。这个相当于最后显示出来的效果。一步步实施就不用写了吧。其实很简单的一个配置,做2个vlan一个本地用户接入vlan。一个连接上级的互联vlan,掩码都掩到30位了,就2个可用ip地址。指个路由就行了。上级还应该把本地用户段的路由在指回来。既然是替换就不用管了。

想学学交换机配置?

思科交换机配置

switch> 用户模式

1:进入特权模式 enable

switch> enable

switch#

2:进入全局配置模式 configure terminal

switch> enable

switch#c onfigure terminal

switch(conf)#

3:交换机命名 hostname aptech2950 以aptech2950为例

switch> enable

switch#c onfigure terminal

switch(conf)#hostname aptch-2950

aptech2950(conf)#

4:配置使能口令 enable password cisco 以cisco为例

switch> enable

switch#c onfigure terminal

switch(conf)#hostname aptch2950

aptech2950(conf)# enable password cisco

5:配置使能密码 enable secret ciscolab 以cicsolab为例

switch> enable

switch#c onfigure terminal

switch(conf)#hostname aptch2950

aptech2950(conf)# enable secret ciscolab

6:设置虚拟局域网vlan 1 interface vlan 1

switch> enable

switch#c onfigure terminal

switch(conf)#hostname aptch2950

aptech2950(conf)# interface vlan 1

aptech2950(conf-if)#ip address 192.168.1.1 255.255.255.0 配置交换机端口ip和子网掩码

aptech2950(conf-if)#no shut 是配置处于运行中

aptech2950(conf-if)#exit

aptech2950(conf)#ip default-gateway 192.168.254 设置网关地址

7:进入交换机某一端口 interface fastehernet 0/17 以17端口为例

switch> enable

switch#c onfigure terminal

switch(conf)#hostname aptch2950

aptech2950(conf)# interface fastehernet 0/17

aptech2950(conf-if)#

8:查看命令 show

switch> enable

switch# show version 察看系统中的所有版本信息

show interface vlan 1 查看交换机有关ip 协议的配置信息

show running-configure 查看交换机当前起作用的配置信息

show interface fastethernet 0/1 察看交换机1接口具体配置和统计信息

show mac-address-table 查看mac地址表

show mac-address-table aging-time 查看mac地址表自动老化时间

9:交换机恢复出厂默认恢复命令

switch> enable

switch# erase startup-configure

switch# reload

10:双工模式设置

switch> enable

switch#c onfigure terminal

switch2950(conf)#hostname aptch-2950

aptech2950(conf)# interface fastehernet 0/17 以17端口为例

aptech2950(conf-if)#duplex full/half/auto 有full , half, auto 三个可选项

11:cdp相关命令

switch> enable

switch# show cdp 查看设备的cdp全局配置信息

show cdp interface fastethernet 0/17 查看17端口的cdp配置信息

show cdp traffic 查看有关cdp包的统计信息

show cdp nerghbors 列出与设备相连的cisco设备

12:csico2950的密码恢复

拔下交换机电源线。

用手按着交换机的MODE键,插上电源线

在switch:后执行flash_ini命令:switch: flash_ini

查看flash中的文件: switch: dir flash:

把“config.text”文件改名为“config.old”: switch: rename flash: config.text flash: config.old

执行boot: switch: boot

交换机进入是否进入配置的对话,执行no :

进入特权模式察看flash里的文件: show flash :

把“config.old”文件改名为 “config.text”: switch: rename flash: config.old flash: config.text

把“config.text”拷入系统的“running-configure”: copy flash: config.text system : running-configure

把配置模式重新设置密码存盘,密码恢复成功。

13:交换机telnet远程登录设置:

switch>en

switch#c onfigure terminal

switch(conf)#hostname aptech-2950

aptech2950(conf)#enable password cisco 以cisco为特权模式密码

aptech2950(conf)#interface fastethernet 0/1 以17端口为telnet远程登录端口

aptech2950(conf-if)#ip address 192.168.1.1 255.255.255.0

aptech2950(conf-if)#no shut

aptech2950(conf-if)#exit

aptech2950(conf)line vty 0 4 设置0-4 个用户可以telnet远程登陆

aptech2950(conf-line)#login

aptech2950(conf-line)#password edge 以edge为远程登录的用户密码

主机设置:

ip 192.168.1.2 主机的ip必须和交换机端口的地址在同一网络段

netmask 255.255.255.0

gate-way 192.168.1.1 网关地址是交换机端口地址

运行:

telnet 192.168.1.1

进入telnet远程登录界面

password : edge

aptech2950>en

password: cisco

aptech#

14:交换机配置的重新载入和保存

设置完成交换机的配置后:

aptech2950(conf)#reload

是否保存(y/n) y: 保存设置信息 n:不保存设置信息1.在基于IOS的交换机上设置主机名/系统名:

switch(config)# hostname hostname

在基于CLI的交换机上设置主机名/系统名:

switch(enable) set system name name-string2.在基于IOS的交换机上设置登录口令:

switch(config)# enable password level 1 password

在基于CLI的交换机上设置登录口令:

switch(enable) set password

switch(enable) set enalbepass3.在基于IOS的交换机上设置远程访问:

switch(config)# interface vlan 1

switch(config-if)# ip address ip-address netmask

switch(config-if)# ip default-gateway ip-address

在基于CLI的交换机上设置远程访问:

switch(enable) set interface sc0 ip-address netmask broadcast-address

switch(enable) set interface sc0 vlan

switch(enable) set ip route default gateway4.在基于IOS的交换机上启用和浏览CDP信息:

switch(config-if)# cdp enable

switch(config-if)# no cdp enable

为了查看Cisco邻接设备的CDP通告信息:

switch# show cdp interface [type modle/port]

switch# show cdp neighbors [type module/port] [detail]

在基于CLI的交换机上启用和浏览CDP信息:

switch(enable) set cdp {enable|disable} module/port

为了查看Cisco邻接设备的CDP通告信息:

switch(enable) show cdp neighbors[module/port] [vlan|duplex|capabilities|detail]5.基于IOS的交换机的端口描述:

switch(config-if)# description description-string

基于CLI的交换机的端口描述:

switch(enable)set port name module/number description-string6.在基于IOS的交换机上设置端口速度:

switch(config-if)# speed{10|100|auto}

在基于CLI的交换机上设置端口速度:

switch(enable) set port speed moudle/number {10|100|auto}

switch(enable) set port speed moudle/number {4|16|auto}7.在基于IOS的交换机上设置以太网的链路模式:

switch(config-if)# duplex {auto|full|half}

在基于CLI的交换机上设置以太网的链路模式:

switch(enable) set port duplex module/number {full|half}8.在基于IOS的交换机上配置静态VLAN:

switch# vlan database

switch(vlan)# vlan vlan-num name vlaswitch(vlan)# exit

switch# configure teriminal

switch(config)# interface interface module/number

switch(config-if)# switchport mode access

switch(config-if)# switchport access vlan vlan-num

switch(config-if)# end

在基于CLI的交换机上配置静态VLAN:

switch(enable) set vlan vlan-num [name name]

switch(enable) set vlan vlan-num mod-num/port-list9. 在基于IOS的交换机上配置VLAN中继线:

switch(config)# interface interface mod/port

switch(config-if)# switchport mode trunk

switch(config-if)# switchport trunk encapsulation {isl|dotlq}

switch(config-if)# switchport trunk allowed vlan remove vlan-list

switch(config-if)# switchport trunk allowed vlan add vlan-list

在基于CLI的交换机上配置VLAN中继线:

switch(enable) set trunk module/port [on|off|desirable|auto|nonegotiate]

Vlan-range [isl|dotlq|dotl0|lane|negotiate]10.在基于IOS的交换机上配置VTP管理域:

switch# vlan database

switch(vlan)# vtp domain domain-name

在基于CLI的交换机上配置VTP管理域:

switch(enable) set vtp [domain domain-name]

。。。 。。。

PacketTracer5模拟器,

转载请注明出处51数据库 » removevtypassword 交换机配置命令

软件
前端设计
程序设计
Java相关