aaa authentication default local #开启所有服务,默认是关需要console进去设置
aaa authentication http local #开启http服务,默认是关需要console进去设置
aaa authentication telnet local #开启telnet服务,默认是关需要console进去设置
aaa authentication ftp local #开启ftp服务,默认是关需要console进去设置
设置时区、时制、时间、日期、主机名、标书等:***************************************************
system timezone pst
system timezone zp8 (中国)
system daylight savings time enable
system time 18:35:00
system date 06/27/2002
system contact "JSmith X477 js@company.com"
system name "Engineering Switch 3"
system location "NMS Lab--NE Corner Rack"
*********************************************************
重新启动:
***********************************************************
reload working no rollback-timeout(立即重新启动)
reload primary in 3:03(定时重新启动主模块)
reload primary at 20:00 june 30(定时重新启动主模块)
reload primary cancel (取消重新启动主模块)
reload secondary (重新启动备管理模块)
reload cancel(取消重新启动)
************************************************************
保存配置:
************************************************************
copy running-config working or write memory(保存到主模块内存)
copy working certified(保存到备配置文件)
copy certified working(恢复配置文件)
copy flash-synchro(把配置文件同步到备管理模块)
*************************************************************
VLAN配置:
*************************************************************
vlan 10 创建vlan 10
vlan 10 name bangonglou 给为vlan 10取名
vlan 10 router ip 172.16.32.1 mask 255.255.255.0 给vlan配Router ip
vlan 10 prot default 1/1 1/1端口分配到vlan 10
vlan 2 802.1q 8/1 8/1端口打上vlan 2的802.1q tag
vlan 2 no port default 3/1-5 从vlan 2 删除3/1-5的
ip interface "vlan-1" address 192.168.0.254 mask 255.255.255.0 vlan 1 给vlan1配置route ip
*************************************************************
常用维护命令:
*************************************************************
show micrcode 查看软件信息
show running-directory 查看交换机运行模式
show configuration snapshot all 查看所有配置
show history parameters 查看history参数
show history 查看历史信息
show vlan 查看vlan信息
show chassis 查看交换机机箱信息
show module 查看模块信息
show ni 查看ni信息
show cmm 查看管理模块信息
show system 查看系统信息
show seesion config
show dns
show ntp server status
show ntp client server-list
show ntp client
show reload
show reload status
show user
show hardware info
***********************************************************
文件操作命令:
**********************************************************
rm *.img
install *.img
cd
pwd
ls
cp
mkdir
rm
vi
move
chmod
delete
freespace
fsck
newfs
*****************************************************************
ACL配置:
****************************************************************
只允许192.168.10.0/24网段可以访问任意,而192.168.10.0/24不让任意网络访问:
-> policy condition source1 source ip 192.168.10.0 mask 255.255.255.0
-> policy condition dest1 destination ip 192.168.10.0 mask 255.255.255.0
-> policy action No disposition deny
-> policy action Yes disposition accept
-> policy rule permitRule precedence 300 condition source1 action Yes reflexive
-> policy rule denyRule condition dest1 action No
-> qos apply
******************************************************************
Avlan配置:
****************************************************************
system name os6600
vlan 1 router ip 192.168.1.1
vlan 2 router ip 192.168.2.1
vlan 2 enable
vlan 2 authentication enable
vlan port mobile 8/3
vlan port 8/3 authentication enable
aaa radius-server “rad1” host 192.168.1.254 key switch auth-port 1812 acct-port 1813
aaa authentication vlan single-mode “rad1”
aaa accounting vlan rad1
ip helpr address 192.168.1.254
aaa avlan default dhcp 192.168.1.1
ip helper avlan only
avlan auth-ip 3 10.10.2.80
no aaa radius-server rad1
aaa vlan no
no aaa authentication vlan
no aaa accounting
********************************************************
SLB配置:
*******************************************************
ip slb admin enable
ip slb cluster zbslb vip 192.168.0.234
ip slb server ip 192.168.0.236 cluster zbslb
ip slb server ip 192.168.0.237 cluster zbslb
ip slb probe zbslb_probe1 ping
ip slb cluster zbslb probe zbslb_probe1
ip slb server ip 192.168.0.236 cluster zbslb probe zbslb_probe1
ip slb server ip 192.168.0.237 cluster zbslb probe zbslb_probe1
**********************************************************
dhcp relay配置
**********************************************************
ip udp relay
ip helper address 192.168.1.1
ip helper no address 192.168.1.1 (deletes one address)
ip helper no address (delete all address)
ip helper address 192.168.3.1 vlan 3
ip helper address 192.168.4.1 192.168.4.2 vlan 4
ip helper forward delay 15 (set forward delay timer for the bootip/dhcp relay)1-65535
ip helper maximum hops 3 (set the maximum hop count value)1-16
show ip helper
ip helper boot-up enable dhcp
ip helper boot-up enable bootp
show ip helper stats
show ip udp relay service
show ip udp relay statistics
show ip udp relay destination
**********************************************************