糯米文學吧

位置:首頁 > IT認證 > H3C認證

H3C路由器交換機配置命令大全

H3C認證4.23K

H3C路由器交換機怎麼配置?配置命令有哪些?下面一起來看看最新H3C路由器交換機配置命令詳解吧!

H3C路由器交換機配置命令大全

  交換機命令

[Quidway]super password ;修改特權用户密碼

[Quidway]sysname ;交換機命名

[Quidway]interface ethernet 0/1 ;進入接口視圖

[Quidway]interface vlan x ;進入接口視圖

[Quidway-Vlan-interfacex]ip address ;配置VLAN的IP地址

[Quidway]ip route-static ;靜態路由=網關

[Quidway]user-interface vty 0 4 ;進入虛擬終端

[S3026-ui-vty0-4]authentication-mode password ;設置口令模式

[S3026-ui-vty0-4]set authentication-mode password simple 222 ;設置口令

[S3026-ui-vty0-4]user privilege level 3 ;用户級別

[Quidway-Ethernet0/1]duplex {half|full|auto} ;配置端口工作狀態

[Quidway-Ethernet0/1]speed {10|100|auto} ;配置端口工作速率

[Quidway-Ethernet0/1]flow-control ;配置端口流控

[Quidway-Ethernet0/1]mdi {across|auto|normal} ;配置端口平接扭接

[Quidway-Ethernet0/1]port link-type {trunk|access|hybrid} ;設置端口工作模式

[Quidway-Ethernet0/1]undo shutdown ;激活端口

[Quidway-Ethernet0/2]quit ;退出系統視圖

[Quidway]vlan 3       ;創建VLAN

[Quidway-vlan3]port ethernet 0/1 to ethernet 0/4      ;在VLAN中增加端口

[Quidway-Ethernet0/2]port access vlan 3      ;當前端口加入到VLAN

[Quidway-Ethernet0/2]port trunk permit vlan {ID|All}   ;設trunk允許的VLAN

[Quidway-Ethernet0/2]port trunk pvid vlan 3      ;設置trunk端口的PVID

[Quidway]monitor-port  ;指定鏡像端口

[Quidway]port mirror   ;指定被鏡像端口

[Quidway]port mirror int_list observing-port int_type int_num ;指定鏡像和被鏡像

[Quidway]description string      ;指定VLAN描述字符

[Quidway]description  ;刪除VLAN描述字符

[Quidway]display vlan [vlan_id] ;查看VLAN設置

[Quidway]stp {enable|disable} ;設置生成樹,默認關閉

[Quidway]stp priority 4096      ;設置交換機的優先級

[Quidway]stp root {primary|secondary}      ;設置為根或根的備份

[Quidway-Ethernet0/1]stp cost 200      ;設置交換機端口的花費

[SwitchA-vlanx]isolate-user-vlan enable      ;設置主vlan

[SwitchA]Isolate-user-vlan secondary      ;設置主vlan包括的'子vlan

[Quidway-Ethernet0/2]port hybrid pvid vlan      ;設置vlan的pvid

[Quidway-Ethernet0/2]port hybrid pvid      ;刪除vlan的pvid

[Quidway-Ethernet0/2]port hybrid vlan vlan_id_list untagged  ;設置無標識的vlan

如果包的vlan id與PVId一致,則去掉vlan信息. 默認PVID=1。

所以設置PVID為所屬vlan id, 設置可以互通的vlan為untagged.

----------------------------------------

  路由器命令

[Quidway]display version       ;顯示版本信息

[Quidway]display current-configuration       ;顯示當前配置

[Quidway]display interfaces       ;顯示接口信息

[Quidway]display ip route       ;顯示路由信息

[Quidway]sysname aabbcc       ;更改主機名

[Quidway]super passwrod 123456       ;設置口令

[Quidway]interface serial0       ;進入接口

[Quidway-serial0]ip address       ;配置端口IP地址

[Quidway-serial0]undo shutdown       ;激活端口

[Quidway]link-protocol hdlc       ;綁定hdlc協議

[Quidway]user-interface vty 0 4

[Quidway-ui-vty0-4]authentication-mode password

[Quidway-ui-vty0-4]set authentication-mode password simple 222

[Quidway-ui-vty0-4]user privilege level 3

[Quidway-ui-vty0-4]quit

[Quidway]debugging hdlc all serial0       ;顯示所有信息

[Quidway]debugging hdlc event serial0       ;調試事件信息

[Quidway]debugging hdlc packet serial0       ;顯示包的信息

  靜態路由:

[Quidway]ip route-static {interface number|nexthop}[value][reject|blackhole]

例如:

[Quidway]ip route-static 16

[Quidway]ip route-static

[Quidway]ip route-static 16 Serial 2

[Quidway]ip route-static

  動態路由:

[Quidway]rip ;設置動態路由

[Quidway]rip work ;設置工作允許

[Quidway]rip input ;設置入口允許

[Quidway]rip output ;設置出口允許

[Quidway-rip]network       ;設置交換路由網絡

[Quidway-rip]network all ;設置與所有網絡交換

[Quidway-rip]peer ip-address ;

[Quidway-rip]summary ;路由聚合

[Quidway]rip version 1 ;設置工作在版本1

[Quidway]rip version 2 multicast ;設置工作在版本2,多播方式

[Quidway-Ethernet0]rip split-horizon ;水平分隔

[Quidway]router id A.B.C.D ;配置路由器的ID

[Quidway]ospf enable ;啟動OSPF協議

[Quidway-ospf]import-route direct ;引入直聯路由

[Quidway-Serial0]ospf enable area ;配置OSPF區域

  標準訪問列表命令格式如下:

acl [match-order config|auto] ;默認前者順序匹配。

rule [normal|special]{permit|deny} [source source-addr source-wildcard|any]

例:

[Quidway]acl 10

[Quidway-acl-10]rule normal permit source

[Quidway-acl-10]rule normal deny source any

  擴展訪問控制列表配置命令

配置TCP/UDP協議的擴展訪問列表:

rule {normal|special}{permit|deny}{tcp|udp}source {|any}destination |any}

[operate]

配置ICMP協議的擴展訪問列表:

rule {normal|special}{permit|deny}icmp source {|any]destination {|any]

[icmp-code] [logging]

  擴展訪問控制列表操作符的含義

equal portnumber ;等於

greater-than portnumber ;大於

less-than portnumber ;小於

not-equal portnumber ;不等

range portnumber1 portnumber2 ;區間

  擴展訪問控制列表舉例

[Quidway]acl 101

[Quidway-acl-101]rule deny souce any destination any

[Quidway-acl-101]rule permit icmp source any destination any icmp-type echo

[Quidway-acl-101]rule permit icmp source any destination any icmp-type echo-reply

[Quidway]acl 102

[Quidway-acl-102]rule permit ip source destination

[Quidway-acl-102]rule deny ip source any destination any

[Quidway]acl 103

[Quidway-acl-103]rule permit tcp source any destination destination-port equal ftp

[Quidway-acl-103]rule permit tcp source any destination destination-port equal www

[Quidway]firewall enable

[Quidway]firewall default permit|deny

[Quidway]int e0

[Quidway-Ethernet0]firewall packet-filter 101 inbound|outbound

  地址轉換配置舉例

[Quidway]firewall enable

[Quidway]firewall default permit

[Quidway]acl 101

[Quidway-acl-101]rule deny ip source any destination any

[Quidway-acl-101]rule permit ip source 0 destination any

[Quidway-acl-101]rule permit ip source 0 destination any

[Quidway-acl-101]rule permit ip source 0 destination any

[Quidway-acl-101]rule permit ip source 0 destination any

[Quidway]acl 102

[Quidway-acl-102]rule permit tcp source 0 destination 0

[Quidway-acl-102]rule permit tcp source any destination 0 destination-port great-than

1024

[Quidway-Ethernet0]firewall packet-filter 101 inbound

[Quidway-Serial0]firewall packet-filter 102 inbound

[Quidway]nat address-group pool1

[Quidway]acl 1

[Quidway-acl-1]rule permit source

[Quidway-acl-1]rule deny source any

[Quidway-acl-1]int serial 0

[Quidway-Serial0]nat outbound 1 address-group pool1

[Quidway-Serial0]nat server global inside ftp tcp

[Quidway-Serial0]nat server global inside www tcp

[Quidway-Serial0]nat server global 8080 inside www tcp

[Quidway-Serial0]nat server global inside smtp udp

  PPP驗證:

主驗方:pap|chap

[Quidway]local-user u2 password {simple|cipher} aaa

[Quidway]interface serial 0

[Quidway-serial0]ppp authentication-mode {pap|chap}

[Quidway-serial0]ppp chap user u1 //pap時,不用此句

pap被驗方:

[Quidway]interface serial 0

[Quidway-serial0]ppp pap local-user u2 password {simple|cipher} aaa

chap被驗方:

[Quidway]interface serial 0

[Quidway-serial0]ppp chap user u1

[Quidway-serial0]local-user u2 password {simple|cipher} aaa