H3C_3600及3100交换机配置方法
- 格式:doc
- 大小:42.00 KB
- 文档页数:8
华为3600交换机命令说明及资料整理一.基本命令1.基本设置命令display current-configuration 显示当前配置system-view 进入系统视图sysname XXXXX 设置交换机名称2.IP地址配置命令Display ip interface 显示接口的详细信息ip address 192.168.1.1 255.255.255.0 设置IP地址和子网掩码3.Vlan设置命令vlan X 创建vlan接口并进入vlan视图 vlan X to Y 创建X到Y多个vlanshutdown 关闭vlan接口undo vlan X 初始化vlan xdisplay vlan x 查看vlan x配置信息display vlan all 查看所有vlan配置信息port Ethernet 1/0/x 向vlan中加入ethernet 1/0/xport Ethernet 1/0/x to Ethernet 1/0/y 向vlan中加入ethernet 1/0/x到ethernet 1/ 0/y(只对access端口类型有效,将Trunk端口和Hybrid端口加入VLAN,只能通过以太网端口视图下的port trunk permit vlan和port hybrid vlan命令实现)Dis cu 查看命令(yangxiaojun)Quit 退出Save 保存4.端口设置命令copy configuration source ethernet 1/0/1 destination ethernet 1/0/2 ethernet 1/ 0/3将端口1的配置信息拷贝到端口2和端口3Description XXXXX 对端口进行描述display brief interface ethernet 1/0/1 显示端口1的简要配置信息display interface ethernet1/0/1 显示端口1的配置信息port link-type XXXXX 设置端口类型access:设置端口为Access端口。
超级终端设置:超级终端的文件选项里的‘属性’设置:当超级终端配置好以后,就打开交换机的电源。
终端配置界面里就会显示出交换机的启动过程,启动完成以后按下enter键进入命令配置界面,具体配置命令如下:<H3C>sys -----------------------------进入命令配置模式[H3C]interface GigabitEthernet 1/0/1 --------------------------- 进入前兆以太网端口[H3C-GigabitEthernet1/0/1]speed 1000 ----------------------------设置端口速度为1000Mbps[H3C-GigabitEthernet1/0/1]duplex full -----------------------------设置端口工作模式为全双工[H3C-GigabitEthernet1/0/1]dis th -----------------------------查看端口的配置#interface GigabitEthernet1/0/1speed 1000duplex full#[H3C-GigabitEthernet1/0/1]quit -------------------------返回上一级[H3C]save ------------------------保存配置首先进入需要关闭的接口,命令为:interface ethernet(百兆口) 1/0/2(例如2号口)interface gigabitethernet(千兆口) 1/0/2(例如2号口)然后输入关闭命令:shutdown 就可以了。
如果以后需要打开就进入需要打开的接口下(命令同上)输入打开命令:undo shutdown 就可以了。
SNMP-RMON 目录目录第1章 SNMP配置命令...........................................................................................................1-11.1 SNMP配置命令..................................................................................................................1-11.1.1 display snmp-agent.................................................................................................1-11.1.2 display snmp-agent community...............................................................................1-11.1.3 display snmp-agent group.......................................................................................1-21.1.4 display snmp-agent mib-view..................................................................................1-31.1.5 display snmp-agent statistics..................................................................................1-51.1.6 display snmp-agent sys-info....................................................................................1-61.1.7 display snmp-agent trap-list....................................................................................1-61.1.8 display snmp-agent usm-user.................................................................................1-71.1.9 enable snmp trap updown.......................................................................................1-81.1.10 snmp-agent...........................................................................................................1-91.1.11 snmp-agent community.......................................................................................1-101.1.12 snmp-agent group...............................................................................................1-111.1.13 snmp-agent local-engineid..................................................................................1-121.1.14 snmp-agent log...................................................................................................1-131.1.15 snmp-agent mib-view..........................................................................................1-131.1.16 snmp-agent packet max-size..............................................................................1-141.1.17 snmp-agent sys-info............................................................................................1-151.1.18 snmp-agent target-host.......................................................................................1-161.1.19 snmp-agent trap enable......................................................................................1-171.1.20 snmp-agent trap life............................................................................................1-181.1.21 snmp-agent trap queue-size...............................................................................1-191.1.22 snmp-agent trap source......................................................................................1-201.1.23 snmp-agent usm-user.........................................................................................1-20第2章 RMON配置命令...........................................................................................................2-12.1 RMON配置命令..................................................................................................................2-12.1.1 display rmon alarm..................................................................................................2-12.1.2 display rmon event..................................................................................................2-22.1.3 display rmon eventlog.............................................................................................2-32.1.4 display rmon history................................................................................................2-42.1.5 display rmon prialarm..............................................................................................2-52.1.6 display rmon statistics.............................................................................................2-72.1.7 rmon alarm..............................................................................................................2-82.1.8 rmon event............................................................................................................2-102.1.9 rmon history...........................................................................................................2-112.1.10 rmon prialarm......................................................................................................2-122.1.11 rmon statistics.....................................................................................................2-14第1章 SNMP配置命令1.1 SNMP配置命令1.1.1 display snmp-agent【命令】display snmp-agent { local-engineid | remote-engineid }【视图】任意视图【参数】local-engineid:本地SNMP实体引擎ID。
进入管理模式<H3C>system-view显示正在运行的配置信息[H3C] dis cur保存配置信息[H3C]quit<H3C>save配置telnet 管理的用户和口令[H3C]local-user admin[H3C-]password simple password123[H3C-]service-type telnet[H3C-]level 3[H3C-]quit[H3C]user-interface vty 0 4[H3C-]authentication-mode scheme一、H3C 3600交换机1、划分VLAN,并对VLAN进行IP路由创建vlan 1[H3C]vlan 1[H3C]int vlan 1[H3C-Vlan-interface1]ip add 192.168.1.253 255.255.255.0 [H3C-Vlan-interface1]quit[H3C]int e1/0/1[H3C-Ethernet1/0/1]port access vlan 1[H3C-Ethernet1/0/1]quit[H3C]int e1/0/2[H3C-Ethernet1/0/2]port access vlan 1[H3C-Ethernet1/0/2]quit创建vlan 2[H3C]vlan 2[H3C]int vlan 2[H3C-Vlan-interface1]ip add 192.168.2.253 255.255.255.0 [H3C-Vlan-interface1]quit[H3C]int e1/0/3[H3C-Ethernet1/0/3]port access vlan 2[H3C-Ethernet1/0/3]quit[H3C]int e1/0/4[H3C-Ethernet1/0/4]port access vlan 2[H3C-Ethernet1/0/4]quit[H3C]int g1/0/1[H3C-G1/0/1]port access vlan 2[H3C-G1/0/1]quit3100及3600交换机TRUNK口应用:两台交换机级联SwitchA与SwitchB用trunk互连,相同VLAN的PC 之间可以互访,不同VLAN的PC之间禁止互访l 配置方法:# 进入GigabitEthernet 1/1 以太网端口视图。
办公局域网组建H3C 3100、H3C 3600交换机配置常州市北郊高级中学信息技术组蔡国********************************************************************************************任务1 交换机初始化(需几分钟)<H3C3100>res savy ******问题:保存的配置文件将被删除。
你确定吗?The saved configuration file will be erased. Are you sure?< H3C3100>reboot ******重启n ******问题:这个命令将重新启动设备。
当前的配置将丢失,保存C,目前的配置?【Y / N ]: This command will reboot the device.Current configuration will be lost, save c urrent configuration? [Y/N]:Y ******问题:这个命令将重新启动设备。
继续吗?【Y / N ]:This command will reboot the device. Continue? [Y/N]:<H3C3100>sys *****进入配置[H3C3100]dis vlan *查看当前vlan[H3C3100]dis cur *查看当前配置********************************************************************************************测试:Ping操作开始---运行---cmd---Ipconfig /all *查看本机地址Ping -t *连续ping对方地址(如果不带-t,ping不连续操作)。
H3C 3100交换机IP设置步骤1、使用随机带的串口线串口端连接计算机串口,RJ45端连接交换机CONSOLE口,设置超级终端连接计算机串口。
2、设置交换机系统时间<H3C>disp clock ――显示交换机时间06:42:23 UTC Sun 04/02/2000Time Zone : add 00:00:00<H3C>clock datetime 18:15:00 2007/06/02 ――设置时间<H3C>disp clock ――检查时间是否设置正确18:16:38 UTC Sat 06/02/2007Time Zone : add 00:00:00<H3C>设置交换机时间完毕3、进入系统视图,设置登陆帐号、口令、管理级别以及交换机名<H3C>sysSystem View: return to User View with Ctrl+Z.[H3C]user-interface vty 0 4H3C-ui-vty0-4]authentication-mode password[H3C-ui-vty0-4]set authentication password simple xtyz201[H3C-ui-vty0-4]user privilege level 3[H3C-ui-vty0-4]quit[H3C]sysname xtyz201[xtyz201]4、设置管理IP地址和路由信息:[xtyz201]interface Vlan-interface 1[xtyz201-Vlan-interface1]%Jun 2 18:21:03:663 2007 xtyz201 L2INF/5/VLANIF LINK STA TUS CHANGE:- 1 -Vlan-interface1: is UP[xtyz201-Vlan-interface1]ip address 10.5.16.201 255.255.255.0[xtyz201-Vlan-interface1]%Jun 2 18:29:28:617 2007 xtyz201 IFNET/5/UPDOWN:- 1 -Line protocol on the interface Vlan-interface1 is UP[xtyz201-Vlan-interface1]quit[xtyz201]ip route-static 0.0.0.0 0.0.0.0 10.5.16.254 preference 60[xtyz201]5、设置网管相关参数[xtyz201]snmp-agent community read init.r[xtyz201]snmp-agent community write init.w[xtyz201]snmp-agent sys-info version all[xtyz201]6、设置WEB登陆方式:[xtyz201]local-user admin[xtyz201-luser-admin]password simple xtyz201[xtyz201-luser-admin]service-type telnet level 3[xtyz201-luser-admin]quit<xtyz201>7、存储刚才的设置:<xtyz201>saveThe configuration will be written to the device.Are you sure?[Y/N]yPlease input the file name(*.cfg)(To leave the existing filenameunchanged press the enter key):Now saving current configuration to the device.Saving configuration. Please wait.........Unit1 save configuration flash:/config.cfg successfully%Jun 2 18:32:15:647 2007 xtyz201 CFM/3/CFM_LOG:- 1 -Unit1 save configuration su ccessfully.<xtyz201>8、以后可以使用telnet和WEB方式管理该交换机。
进入管理模式<H3C>system-view显示正在运行的配置信息[H3C] dis cur保存配置信息[H3C]quit<H3C>save配置telnet 管理的用户和口令[H3C]local-user admin[H3C-]password simple password123[H3C-]service-type telnet[H3C-]level 3[H3C-]quit[H3C]user-interface vty 0 4[H3C-]authentication-mode scheme一、H3C 3600交换机1、划分VLAN,并对VLAN进行IP路由创建vlan 1[H3C]vlan 1[H3C]int vlan 1[H3C-Vlan-interface1]ip add 192.168.1.253 255.255.255.0 [H3C-Vlan-interface1]quit[H3C]int e1/0/1[H3C-Ethernet1/0/1]port access vlan 1[H3C-Ethernet1/0/1]quit[H3C]int e1/0/2[H3C-Ethernet1/0/2]port access vlan 1[H3C-Ethernet1/0/2]quit创建vlan 2[H3C]vlan 2[H3C]int vlan 2[H3C-Vlan-interface1]ip add 192.168.2.253 255.255.255.0 [H3C-Vlan-interface1]quit[H3C]int e1/0/3[H3C-Ethernet1/0/3]port access vlan 2[H3C-Ethernet1/0/3]quit[H3C]int e1/0/4[H3C-Ethernet1/0/4]port access vlan 2[H3C-Ethernet1/0/4]quit[H3C]int g1/0/1[H3C-G1/0/1]port access vlan 2[H3C-G1/0/1]quit3100及3600交换机TRUNK口应用:两台交换机级联SwitchA与SwitchB用trunk互连,相同VLAN的PC 之间可以互访,不同VLAN的PC之间禁止互访l 配置方法:# 进入GigabitEthernet 1/1 以太网端口视图。
[SW A] interface GigabitEthernet 1/1# 配置端口GigabitEthernet 1/1为Trunk端口并允许VLAN10、VLAN 20的报文通过。
[SW A-Gthernet1/0/1] port link-type trunk[SW A-Gthernet1/0/1] port trunk permit vlan 10 20[SW A]int e10/1[SW A-E1/0/1]port acc vlan 10[SW A-E1/0/2]port acc vlan 20注:SWB交换机配置相同增加路由[H3C]ip route 0.0.0.0 0.0.0.0 192.168.1.254[H3C]quit<H3C>save端口映像:[H3C]mirroring-group 1 local[H3C]mirroring-group 1 monitor-port GigabitEthernet 1/1/4[H3C]mirroring-group 1 mirroring-port GigabitEthernet 1/1/1 both端口汇聚:<H3C>system-view[H3C]link-aggregation group 1 mode manual[H3C]interface ethernet1/0/1[H3C-Ethernet1/0/1] port link-aggregation group 1[H3C-Ethernet1/0/1] interface ethernet1/0/2[H3C-Ethernet1/0/2] port link-aggregation group 1[H3C-Ethernet1/0/2] interface ethernet1/0/3[H3C-Ethernet1/0/3] port link-aggregation group 1<<在互联网出口的路由器上需要配置返回路由192.168.2.0 255.255.255.0 192.168.1.253 >>2、IP MAC端口绑定[H3C]interface Ethernet1/0/1[H3C-Ethernet1/0/1]am user-bind mac-addr 0001-0002-0003 ip-addr 10.12.1.13、IP MAC绑定arp static ip-address mac-address [ vlan-id interface-typeinterface-number ]4、ACL访问控制列表公司企业网通过Switch的端口实现各部门之间的互连。
研发部门由GigabitEthernet1/1/1接入交换机,工资查询服务器的地址为192.168.1.2。
要求正确配置ACL,禁止研发部门在工作日8:00至18:00访问工资服务器。
配置步骤(1)定义时间段# 定义8:00至18:00的周期时间段。
<H3C> system-view[H3C] time-range test 8:00 to 18:00 working-day(2) 定义到工资服务器的ACL# 进入ACL3000视图。
[H3C] acl number 3000# 定义其它部门到工资服务器的访问规则。
[H3C-acl-adv-3000] rule 1 deny ip destination 192.168.1.2 0 time-range test[H3C-acl-adv-3000] quit(3) 在端口上应用ACL# 在端口上应用ACL 3000。
[H3C] interface gigabitethernet1/1/1[H3C-GigabitEthernet1/1/1] packet-filter inbound ip-group 3000二、H3C 3100交换机1、广播抑制[H3C]int e1/0/1[H3C]broadcast-suppression 5[H3C]int e1/0/2[H3C]broadcast-suppression 52、配置web管理[H3C]int vlan 1[H3C-]ip add 192.168.1.253 255.255.255.0 [H3C-]quit[H3C]undo ip http shutdown[H3C]local-user admin[H3C-]password simple password123 [H3C-]service-type telnet[H3C-]level 3[H3C-]quit[H3C]user-interface vty 0 4[H3C-]authentication-mode scheme[H3C-]quit[H3C]quit<H3C>save华为(H3C)交换机常用配置命令S5000 交换机192.168.0.233用户名:admin删除设备配置reset saved-configuration重启reboot看当前配置文件display current-configuration改设备名sysname保存配置save进入特权模式sysview华为只有2层模式不像cisco enale之后还要conf t定义aclacl nubmere XXXX(3000以上)进入以后rule permit/deny IP/TCP/UDP等 source XXX.XXX.XXX.XXX XXX.XXX.XXX.XXX(反向)destination XXX.XXX.XXX.XXX XXX.XXX.XXX.XXX(反向) eq注意华为默认没有deny any any防火墙上端口加载ACL[Quidway-Ethernet0/0]firewall packet-filter 3000 inbound防火墙上新增加用户local-user XXX(用户名) password simple XXX(密码)local-user XXX service-type ppp删除某条命令undo(类似与cisco的no)静态路由ip route-static 0.0.0.0 0.0.0.0 XXX.XXX.XXX.XXX对vpdn用户设置acl的接口inte***ce Virtual-Template1查看路由表display ip routing-table设定telnet密码user-inte***ce vty 0 4user privilege level 3set authentication password simple XXX启动/关闭启动 un shut关闭 shut动态nat设置acl number 3000rule 0 permit ip source XXX.XXX.XXX.XXXrule 1 permit ip source XXX.XXX.XXX.XXXrule 2 permit ip source XXX.XXX.XXX.XXXinte***ce Ethernet1/0description ====To-Internet(WAN)====ip address XXX.XXX.XXX.XXX XXX.XXX.XXX.XXXnat outbound 3000ipsec policy policy1利用acl来做符合acl的IP地址可以出去(注意此处的ACL隐含了deny any any)不符合的IP地址不可以出去创建vlan[shzb-crsw-s6506-1]vlan 100华为vlan不支持name将port放入vlan创建了vlan后进入vlan模式[shzb-crsw-s6506-1-vlan100]port GigabitEthernet 1/0/1 to GigabitEthernet 1/0/8表示从G1/0/1 到1/0/8放入VLAN 100创建trunkinte***ce GigabitEthernet1/0/1duplex fullspeed 1000* port link-type trunk* port trunk permit vlan allport link-aggregation group 1带*号的是创建trunk链路的语句vlan地址指定inte***ce Vlan-inte***ce2description serverip address XXX.XXX.XXX.XXX XXX.XXX.XXX.XXXvrrp vrid 2 virtual-ip XXX.XXX.XXX.XXXvrrp vrid 2 priority 120vrrp vrid 2 preempt-mode timer delay 10其中vrrp语句指定vrrp 类似与hsrp使用vrrp要注意的是华为不支持pvst只能一台完全是主,一台完全是备份在主vrrp设备上要指定stp instance 0 root primarystp TC-protection enablestp enable在从vrrp设备上要指定stp instance 0 root secondarystp TC-protection enablestp enable交换机下面绑acl首先进入接口模式,输入qos命令[shzb-crsw-s6506-1-GigabitEthernet1/0/1]qos在输入如下命令[shzb-crsw-s6506-1-qoss-GigabitEthernet1/0/1]packet-filter inbound ip-group 3000华为交换机只能指定inbound方向启用ospf[shzb-crsw-s6506-1]ospf 100[shzb-crsw-s6506-1-ospf-100]area 0[shzb-crsw-s6506-1-ospf-100-area-0.0.0.0]network XXX.XXX.XXX.XXX XXX.XXX.XXX.XXX配置ospf重发布[shzb-crsw-s6506-1-ospf-100-area-0.0.0.0]quit[shzb-crsw-s6506-1-ospf-100]import-route static建立link-group(类似与cisco的channel-group)link-aggregation group 1 mode manual然后进入接口port link-aggregation group 1启用VRRP之前必须输入vrrp ping-enable使得客户能ping网关inte***ce M-Ethernet0/0/0是CPU板的管理口。