cisco常见应用场景和配置.ppt

上传人:sccc 文档编号:5344119 上传时间:2023-06-28 格式:PPT 页数:33 大小:1.07MB
返回 下载 相关 举报
cisco常见应用场景和配置.ppt_第1页
第1页 / 共33页
cisco常见应用场景和配置.ppt_第2页
第2页 / 共33页
cisco常见应用场景和配置.ppt_第3页
第3页 / 共33页
cisco常见应用场景和配置.ppt_第4页
第4页 / 共33页
cisco常见应用场景和配置.ppt_第5页
第5页 / 共33页
点击查看更多>>
资源描述

《cisco常见应用场景和配置.ppt》由会员分享,可在线阅读,更多相关《cisco常见应用场景和配置.ppt(33页珍藏版)》请在三一办公上搜索。

1、方剑锋浙大快威 工程师13819459599,内容安排,Cisco交换设备介绍常见应用场景和配置常见故障诊断,基本配置(一),更改主机名,Switch(config)#hostname S2-C-HZXH-7609-1,设置时钟和NTP时钟同步,Switch(config)#clock timezone Beijing 8Switch(config)#ntp server 61.174.64.11,时间戳设置,Switch(config)#service timestamps debug datetime msec localtimeSwitch(config)#service timesta

2、mps log datetime msec localtime,基本配置(二),AAA认证配置,ip tacacs source-interface Loopback0tacacs-server host 202.96.96.86tacacs-server key hzdxaaa new-modelaaa authentication login default group tacacs+line enableaaa authentication enable default group tacacs+enableaaa accounting commands 15 default start

3、-stop group tacacs+,telnet参数设置,line vty 0 4 access-class 9 in exec-timeout 3 0 password wyzx2008,基本配置(三),Log日志设置,logging trap notifications logging source-interface Loopback0logging 202.96.96.34,SNMP设置,Switch(config)#snmp-server community sjzx2004 RO 9,VLAN配置,创建和删除VLAN,Switch(config)#vlan 1200Switch

4、(config-vlan)#name testSwitch(config)#no vlan 1200,创建SVI,interface Vlan1200 description test ip address 60.190.36.177 255.255.255.252 no ip redirects no ip unreachables no ip proxy-arp,定义VTP模式和使用扩展VLAN,Switch(config)#vtp mode transparent Switch(config)#spanning-tree extend system-id,接口配置(一),Access接口

5、,interface FastEthernet6/3 description L1212628 switchport(45和35系列交换机上不需要此命令)switchport access vlan 3103 switchport mode access speed 10 duplex full,trunk接口,interface GigabitEthernet1/1 description to 7609-3/2 switchport(45和35系列交换机上不需要此命令)switchport trunk encapsulation dot1q switchport trunk allowed

6、 vlan 700,810,821,842,849,859,868,974 switchport trunk allowed vlan add 11201-1244,3101-3148 switchport mode trunk,接口配置(二),路由接口配置,interface GigabitEthernet1/1 description to 7609-3/2 no switchport(65/76上不需要此命令)ip address 60.190.36.177 255.255.255.252 no ip redirects no ip unreachables no ip proxy-ar

7、p,QINQ接口配置,interface GigabitEthernet7/22 description GuDang-OLT-C200-1-port 2 mtu 1538 switchport(35系列交换机上不需要此命令)switchport access vlan 702 switchport mode dot1q-tunnel no cdp enable spanning-tree bpdufilter enable,接口配置(三),接口限速配置(45系列交换机),policy-map 4M class class-default police 4 mbps 400 kbyte con

8、form-action transmit exceed-action drop interface FastEthernet6/11 service-policy input 4M service-policy output 4M,接口限速配置(35系列交换机),class-map match-all IPclass match ip dscp 0policy-map rate-4M class IPclass police 4200000 300000 exceed-action dropinterface FastEthernet6/11 service-policy input rate

9、-4M,EtherChannel Technology,Load sharing and redundancy providedIncremental way to scale link bandwidthSwitches,routers,and servers,EtherChannel,100/1000 Ethernet 2,A,B,EtherChannel,Etherchannel-What supports it?,Catalyst 2900XL,Catalyst 3500XL,Catalyst 5000,Catalyst 6000,Catalyst 4000,Bandwidth Opt

10、ions,Ethernet/Fast Ethernet,Fast EtherChannel,10,100 Mbps,200,400 Mbps,Gigabit EtherChannel,2,4 Gbps,Gigabit Ethernet,1 Gbps,Smooth migration to higher bandwidthsGain resiliency at same timeConsidered as one link to STP,Routing ProtocolsFeatured on Catalyst family and Cisco IOS,Catalyst 6000 Additio

11、nal Options,Fast EtherChannel,200800 Mbps,Gigabit EtherChannel,28 Gbps,Bundle formed with 28 linksBundle members can exist on different cardsMaximum bandwidth of 16 Gbps(FDX)possibleOdd combinations also valid(3,5,6,7),How does it work,Take the source and destination MAC address-convert to Binary,Ta

12、ke last 2 bits of both addresses and perform XOR,Results determine which link to use00-Link 101-Link 202-Link 303-Link 4,Catalyst 6000 uses a polynomial equation in the Earl5 to calculate etherchannel path,Configuring Etherchannel on the 6000,Catalyst 6000 supports a maximum of 128 Etherchannel Grou

13、ps,1.All ports must be in same VLAN2.If channel is configured as trunk,then trunk mode must be same on all ports3.All ports in channel must be same speed and duplex setting4.Broadcast limit MUST be same on all ports in channel5.Port security on ports stops the etherchannel group being created6.If on

14、e of the ports has SPAN enabled,etherchannel group will not form7.Protocol filtering must be same on all ports in channel group,Etherchannel Restrictions,端口聚合配置,interface Port-channel7 description to_liuxia4506 switchport switchport trunk encapsulation dot1q switchport trunk allowed vlan 17,18,105,1

15、84,326,358,361,365-367 switchport trunk allowed vlan add 369-373,501-599,700,801 switchport mode trunkinterface GigabitEthernet3/14 description to_liuxia4506 switchport switchport trunk encapsulation dot1q switchport trunk allowed vlan 17,18,105,184,326,358,361,365-367 switchport trunk allowed vlan

16、add 369-373,501-599,700,801 switchport mode trunk channel-group 7 mode desirableinterface GigabitEthernet4/3 description to_liuxia4506-1/1 switchport switchport trunk encapsulation dot1q switchport trunk allowed vlan 17,18,105,184,326,358,361,365-367 switchport trunk allowed vlan add 369-373,501-599

17、,700,801 switchport mode trunk channel-group 7 mode desirableport-channel load-balance src-dst-port,查看命令,Show interfaceshow ip interface briefshow interface statusshow interface descriptionshow interface trunkshow mac-address-tableshow spanning-tree,StandardChecks Source addressGenerally permits or

18、denies entire protocol suiteExtendedChecks Source and Destination addressGenerally permits or denies specific protocolsInbound or Outbound,What Are Access Lists?,OutgoingPacket,E0,S0,IncomingPacket,Access List Processes,Permit?,Protocol,A List of Tests:Deny or Permit,Packets to Interface(s)in the Ac

19、cess Group,Packet Discard Bucket,Y,Interface(s),Destination,Deny,Y,MatchFirstTest?,Permit,N,Deny,Permit,MatchNextTest(s)?,Deny,MatchLastTest?,Y,Y,N,Y,Y,Permit,Implicit Deny,If no matchdeny all,Deny,N,0 means check corresponding address bit value1 means ignore value of corresponding address bit,do no

20、t check address(ignore bits in octet),=,0,0,0,0,0,0,0,0,Octet bit position and address value for bit,ignore last 6 address bits,check all address bits(match all),ignore last 4 address bits,check last 2 address bits,Examples,Wildcard Bits:How to Check the Corresponding Address Bits,Example 172.30.16.

21、29 0.0.0.0 checks all the address bits Abbreviate this wildcard mask using the IP address preceded by the keyword host(host 172.30.16.29),Test conditions:Check all the address bits(match all),172.30.16.29,0.0.0.0,(checks all bits),An IP host address,for example:,Wildcard mask:,Wildcard Bits to Match

22、 a Specific IP Host Address,Accept any address:0.0.0.0 255.255.255.255Abbreviate the expression using the keyword any,Test conditions:Ignore all the address bits(match any),0.0.0.0,255.255.255.255,(ignore all),Any IP address,Wildcard mask:,Wildcard Bits to Match Any IP Address,Check for IP subnets 1

23、72.30.16.0/24 to 172.30.31.0/24,Network.host 172.30.16.0,Wildcard mask:0 0 0 0 1 1 1 1|0 0 0 1 0 0 0 0=16 0 0 0 1 0 0 0 1=17 0 0 0 1 0 0 1 0=18:0 0 0 1 1 1 1 1=31,Address and wildcard mask:172.30.16.0 0.0.15.255,Wildcard Bits to Match IP Subnets,ACL配置,标准ACL,扩展ACL,access-list 9 permit 218.0.5.32 0.0.

24、0.31access-list 9 permit 218.75.80.64 0.0.0.31access-list 9 permit 218.75.80.32 0.0.0.31access-list 9 deny any,access-list 101 deny tcp 172.16.4.0 0.0.0.255 172.16.3.0 0.0.0.255 eq 21access-list 101 deny tcp 172.16.4.0 0.0.0.255 172.16.3.0 0.0.0.255 eq 20access-list 101 permit ip any any,应用到接口,inter

25、face Vlan27 ip access-group 101 in,VACL介绍,传统的access list(RACL)只有当数据包经过三层端口,才能对数据包起过虑作用。有些数据包,它可能只是在某一个vlan内部,即不经过三层端口,也不夸过vlan,要对这些数据包做过虑的话,则可以用vlan access list(VACL),VACL配置命令,定义一个VACL:vlan access-map map-name sequence-numbermatch ip address acl-number|acl-name|ipx address acl-number|acl-name|mac ad

26、dress acl-nameaction drop|forward capture|redirect interface type mod/num把VACL应用在vlan上:Switch(config)#vlan filter map-name vlan-list vlan-list,VACL EXAMPLE,ip access-list extended match_all permit ip any anyip access-list extended virus permit udp any any eq 135 permit tcp any any eq 135 permit tcp

27、any any eq 139 permit tcp any any eq 4444 permit tcp any any eq 1434 permit udp any any eq 1434 permit tcp any any eq 445vlan access-map vacl 10 match ip address virus action dropvlan access-map vacl 20 match ip address match_all action forwardvlan filter vacl vlan-list 821,1105,1174,路由协议分类,距离向量:用于根

28、据距离(distance)来判断最佳路径,当1 个数据包每经过1 个router 时,被称之为经过1 跳.经过跳数最少的则作为最佳路径.这类协议的例子有RIP 和IGRP,它们将整个路由表向与它们直接相连的相邻routers。链路状态:也叫最短路径优先(shortest-path-first)协议.每个router 创建3 张单独的表,1 张用来跟踪与它直接相连的相邻router;1 张用来决定网络的整个拓扑结构;另外1 张作为路由表.所以这种协议对网络的了解程度要比距离向量高.这类协议例子有OSPF。混合型:综合了前2 者的特征,这类协议的例子有EIGRP。,Ospf路由协议,OSPF能够把

29、网络设计为层次化,这样就把1 个大的网络分割成几个小的网络,叫做区域(area).这是OSPF 最好的设计方法.把OSPF 设计成层次化的好处是:1、减少路由成本(overhead)2、加速汇聚3、把大网络分割成小的区域,典型的OSPF 设计图,如下:,Area 0,Area 1,Area 2,Autonomous System,Configuring OSPF,Enabling OSPF启用OSPF 在全局配置模式下使用router ospf 进程ID命令,进程ID 范围是1 到65535。可以在同1 个router 上使用不止1 个的OSPF 进程,但是这并不等于多域(multi-area

30、)的OSPF.第二个进程保持完整的拓扑数据库的拷贝,而且独立于第一个进程进行管理通信。Configuring OSPF AreasOSPF 使用wildmask 来进行配置,如下:RouterA(config)#router ospf 1RouterA(config-router)#network 10.0.0.0 0.255.255.255 area 0如上,0.255.255.255 为wildmask,0 的部分表示必须精确匹配,255 表示为任意匹配。network10.0.0.0 0.255.255.255 area 0 这个命令的作用是:鉴定OSPF 操作的接口,而且也会加进OSP

31、FLSA通告的范围。OSPF 使用这个命令查找所有处在10.0.0.0 的网络里的接口,然后把它们放进区域0。,Verifying OSPF Configuration,show ip route RouterA#sh ip route O 192.168.30.0/24 110/65 via 192.168.20.2,00:01:07,Serial0/0(略)注意上面的O 代表OSPF,AD 为110,度为65show ip ospf:显示每条或所有ODPF 进程的相关信息,包括RID,区域信息,SPF 信息和LAS 计时器信息等,如下:RouterA#sh ip ospfRouting P

32、rocess“ospf 132”with ID 192.168.20.1(略)如上可知道RID 为192.168.20.1.即router 的最高的那个IP 地址,典型的OSPF配置,router ospf 100 router-id 61.174.90.60 log-adjacency-changes auto-cost reference-bandwidth 10000 redistribute connected metric-type 1 subnets redistribute static metric-type 1 subnets network 61.174.91.146 0.0.0.0 area 0 network 61.174.91.150 0.0.0.0 area 0 network 61.174.91.190 0.0.0.0 area 0 network 220.185.62.49 0.0.0.0 area 290 network 220.185.62.53 0.0.0.0 area 290,

展开阅读全文
相关资源
猜你喜欢
相关搜索

当前位置:首页 > 建筑/施工/环境 > 农业报告


备案号:宁ICP备20000045号-2

经营许可证:宁B2-20210002

宁公网安备 64010402000987号