本帖最后由 宅男女神 于 2015-10-7 21:16 编辑
H3C华三攻城狮笔记交换机最常用配置整理
认证为None时Telnet登录方式的配置# telnet server enable # user-interface vty 0 authentication-mode none user privilege level 2 history-command max-size 20 idle-timeout 6 0 screen-length 30 protocol inbound telnet 认证为Password时Telnet登录方式的配置# telnet server enable # user-interface vty 0 authentication-mode password user privilege level 2 set authentication password simple 123456 history-command max-size 20 idle-timeout 6 0 screen-length 30 protocol inbound telnet 认证为Scheme时Telnet登录方式的配置# domain system authentication default local # 指定system域为缺省域,并设置该域Scheme认证方式local telnet server enable # local-user admin service-type telnet level 3 password cipher 123456 # user-interface vty 0 4 authentication-mode scheme user privilege level 3 history-command max-size 20 idle-timeout 6 0 screen-length 30 protocol inbound telnet 登录用户的控制对Telnet用户进行控制# aclnumber 2000 rule 1 permit source 10.110.100.52 0 rule 2 permit source 10.110.100.46 0 rule 3 deny # user-interfacevty 0 4 acl 2000 inbound 通过源IP对网管用户进行控制# aclnumber 2000 rule 1 permit source 10.110.100.52 0 rule 2 permit source 10.110.100.46 0 rule 3 deny # snmp-agent community read aaa acl 2000 snmp-agent group v2c groupa acl 2000 snmp-agent usm-user v2c usera groupa acl 2000 通过源IP对WEB用户进行控制# ip http acl 2000 # aclnumber 2000 rule 1 permit source 10.110.100.52 0 rule 2 permit source 10.110.100.46 0 rule 3 deny 端口的VLAN典型配置vlan100 description dept1 # vlan200 description dept2 # interfaceVlan-interface 100 ip address 192.168.1.1 255.255.255.0 # interfaceVlan-interface 200 ip address 192.168.2.1 255.255.255.0 # interfaceGigabitEthernet1/0/1 port access vlan 100 # interfaceGigabitEthernet1/0/2 port link-type trunk port trunk permit vlan 1 100 200 Voice VLAN典型配置 interface GigabitEthernet1/0/42 port link-type hybrid
|