Академический Документы
Профессиональный Документы
Культура Документы
Interconnecting Cisco
Networking Devices
Part 1
1
1.0
: 97-2504-01
: .
CISCO ,
,
CISCO. CISCO
, ,
, ,
, .
, Cisco , .
Cisco
Lifecycle Services
Cisco Lifecycle Services
1
1
1
2
4
5
5
6
7
8
10
1-1
1-1
1-1
1-3
1-3
1-3
1-4
1-6
1-7
1-8
1-10
1-12
1-14
1-16
1-16
1-17
1-18
1-19
1-19
1-20
1-21
1-21
1-22
1-23
1-23
1-24
1-25
1-26
1-29
1-29
1-29
1-30
1-33
1-35
1-36
1-37
1-37
1-39
1-39
1-39
1-41
1-42
1-43
OSI
OSI
1:
2:
3:
4:
5:
6:
7:
:
TCP/IP
1-43
1-43
1-44
1-45
1-47
1-47
1-48
1-49
1-50
1-51
1-52
1-53
1-54
1-54
1-55
1-56
1-56
1-57
1-59
1-62
TCP/IP
1-65
:
IP-
IP
IP-
A
B
C
IP-
IP-
IP-
IP-
IP-
DHCP (Dynamic Host Configuration Protocol)
(DNS)
IP-
TCP/IP
: UDP
: TCP
( )
ii
1-65
1-65
1-67
1-68
1-69
1-70
1-72
1-72
1-72
1-73
1-74
1-74
1-74
1-75
1-75
1-75
1-75
1-75
1-76
1-76
1-77
1-78
1-79
1-80
1-83
1-85
1-85
1-86
1-87
1-87
1-88
1-88
1-89
1-89
1-89
1-89
2007 Cisco Systems, Inc.
( )
( )
UDP
:
TCP
:
TCP
TCP/IP
3 4
4
UDP
TCP
-
TCP
:
TCP
TCP
1-113
1
2
2
3
3
2 3
ARP
Ethernet
1-113
1-113
1-114
1-115
1-116
1-117
1-118
1-119
1-120
1-121
134
1-135
1-139
1-141
:
?
Ethernet
Ethernet
LLC
MAC
CSMA/CD Ethernet
Ethernet
Ethernet
2007 Cisco Systems, Inc.
1-90
1-90
1-90
1-91
1-92
1-93
1-94
1-95
1-96
1-97
1-98
1-99
1-99
1-99
1-99
1-99
1-100
1-101
1-102
1-103
1-103
1-104
1-106
1-106
1-107
1-108
1-109
1-109
1-110
1-111
1-141
1-141
1-142
1-142
1-143
1-145
1-146
1-147
1-148
1-148
1-148
1-149
1-151
1-153
iii
Ethernet
MAC-
1-154
1-155
1-156
Ethernet
1-159
Ethernet
Ethernet
UTP
1-159
1-159
1-160
1-161
1-162
1-167
1-173
1-175
1-176
1-175
1-186
Ethernet
2-1
2-1
2-1
2-3
Ethernet
2-3
2-3
2-4
2-6
2-7
2-8
2-9
Ethernet
2
3
Cisco IOS
Cisco IOS
Cisco IOS
EXEC
iv
2-11
2-11
2-11
2-12
2-13
2-14
2-16
2-18
2-19
2-20
2-22
2-25
2-25
2-25
2-26
2-27
2-28
2-35
2-37
2-37
2-37
2-38
2-39
2-41
2-43
2-44
2-46
2-50
2-53
2-56
2007 Cisco Systems, Inc.
2-57
Catalyst
-
Telnet SSH
:
:
:
Ethernet
:
STP
2-57
2-57
2-58
2-59
2-61
2-65
2-66
2-71
2-74
2-75
2-77
2-77
2-77
2-78
2-79
2-81
2-82
2-84
2-88
2-90
2-91
2-91
2-91
2-92
2-92
2-93
2-94
2-94
2-95
2-96
2-97
2-98
2-99
2-100
2-101
2-103
2-103
2-103
2-104
2-105
2-110
2-112
2-113
2-115
2-116
2-125
-
-
,
, ITU-R FCC
802.11
Wi-Fi
3-1
3-1
3-3
3-3
3-3
3-4
3-7
3-8
3-9
3-11
3-13
3-14
3-15
802.1X
WPA WPA2
3-15
3-15
3-16
3-18
3-19
3-21
3-22
3-23
3-23
3-23
3-24
802.11
BSA
vi
3-1
3-25
3-25
3-25
3-26
3-28
3-30
3-31
3-33
3-34
3-36
3-38
3-39
3-40
3-44
ICND1
?
. ,
, .
.
,
.
, ,
. ,
Cisco , ,
.
Windows
ICND1 v1 .03
,
,
ICND1 v1 .04
, ,
OSI;
, ,
Ethernet,
Ethernet;
,
, ,
-;
,
,
TCP/IP;
(WAN),
PPP, ,
PAT RIP;
(CLI)
, .
,
ICND1 v1 .05
,
, :
, ;
, ;
A
M
2
4
5
Ethernet
(WAN)
5
6
1
P
M
2
Ethernet
3
4
5
(WAN)
ICND1 v1 .06
.
, ,
.
, .
Cisco, ,
, .
Cisco
I P-
: Ethernet
ICND1 v1 .07
Cisco
Cisco .
Cisco http://www.cisco.com/univercd/cc/td/doc/cisintwk/ita/index.htm.
Cisco
Cisco
www.cisco.com/go/certifications
200 7 Cisco Syst ems , Inc. .
ICND1 v1 .08
Cisco,
Cisco ( Cisco CCIE, CCNA,
CCDA, CCNP, CCDP, CCIP, CCVP CCSP).
Cisco,
,
Cisco , . .
www.cisco.com/go/certifications.
Cisco
Cis co Certified Net work Assoc ia te
CCIE
Expert
Cisco
Inter connecting Cisco Networking Devices Part 1
CCNP
CCNA
CCENT
Professional
Inter connecting Cisco Networking Devices Part 2
Associate
Entr y Technician
www.cisco.com/go/certifications
Cis co
Inter connecting Cisco N etworking Devices Part 1
ICND1 v1 .09
.
http://www.cisco.com/go/certifications.
CCNA
www.cisco.com/go/prepcenter
200 7 Cisco Syst ems , Inc. .
ICND1 v1.0 10
. http://www.cisco.com/go/prepcenter.
Lifecycle Services
Cisco Lifecycle Services.
. ,
.
ICND1 v1.0 11
: .
-.
:
.
: , .
: .
: .
, -,
.
: , , .
.
, ,
, , ,
.
:
,
, , ,
(WLAN) ;
,
;
,
.
CCNA:
Lifecycle Services
,
,
.
,
.
, -
.
,
,
.
ICND1 v1.0 12
10
,
.
, .
,
.
Cisco Lifec ycle Servic es ,
.
200 7 Cisco Syst ems , Inc. .
ICND1 v1.0 13
,
.
,
.
, .
Cisco Lifecycle Services ,
.
11
,
ICND1 v1.0 14
12
, .
. :
,
, , ,
. ,
(OSI), ,
. ,
Ethernet.
,
. ,
:
,
;
IP- IP- ;
, TCP
;
Ethernet 1- 2- OSI;
Ethernet.
1-2
.
,
.
, . ,
:
,
, ;
,
;
c ;
?
.
(
),
. ,
, .
,
. ( ,
) .
. ,
, .
,
.
,
().
. ,
.
1-4
.
.
, ,
(, ),
.
. ,
. ,
,
( ).
.
, ,
.
, .
,
. ,
, .
,
,
, , ,
.
1-5
, ,
, .
,
.
1-6
().
, .
. ,
.
:
(NIC),
, ;
c ( ),
;
, .
. ,
.
.
.
,
, .
.
. , ,
.
.
.
.
Ethernet.
.
. ,
: s0/0/0
fa0/0 Fast Ethernet.
10.1.1.0/24, 10.1.1.0
, /24 .
2007 Cisco Systems, Inc.
1-7
, .
, .
,
.
. ,
,
.
1-8
. (,
), (, ).
.
.
(Direct Attached Storage - DAS)
.
(Network Attached Storage - NAS)
. , ,
(Storage Aria Networks - SAN)
.
. ,
(,
), .
,
.
, ,
,
( ,
).
.
, -
, .
,
, .
,
.
1-9
,
.
.
1-10
.
.
( )
, (
, ).
: Microsoft Outlook, Qualcomm
Eudora.
.
.
,
, .
,
. , ,
,
.
Microsoft Internet Explorer, Netscape Navigator, Mozilla Firefox
.
,
.
(, AOL
Yahoo), ,
.
.
. , ,
-,
,
.
Lotus Notes.
.
(
),
, .
1-11
,
.
.
FTP, TFTP,
,
,
.
.
,
,
,
.
Vo IP ,
200 7 Cisco Syst ems , Inc. .
,
, .
, FTP, TFTP ,
,
.
, ,
. ,
,
. - ,
. ,
.
,
, .
QoS ,
,
.
1-12
,
(, VoIP -) .
. ,
, (
). .
, QoS. VoIP -
.
, ,
, VoIP,
,
VoIP. , ,
,
. VoIP
, QoS.
, , -
, .
.
1-13
,
.
,
:
. ,
. .
. ,
.
. ,
, .
. , ,
.
. ,
, . ,
24 , 7 , 365 ,
, , ,
, 100,
.
, 15 - ,
:
([ ] / [ ])
* 100 =
([525 600 15] / [525 600]) * 100 = 99,9971
1-14
. ,
.
,
,
.
.
(, , . .), .
(mean time between failures - MTBF).
. :
( , ,
) , ,
.
1-15
,
.
, .
.
( , ,
. .). ,
,
. .
1-16
.
.
, .
. ,
.
.
.
.
.
.
, , .
ICND1 v1 .01- 10
,
, . .
.
. ,
, .
,
.
,
. ,
,
, .
,
,
, .
.
. Ethernet
,
. Ethernet
.
1-17
.
.
.
.
ICND1 v1 .01- 11
,
, , .
, ,
. ,
, , ,
.
1-18
Ethernet.
.
.
.
200 7 Cisco Syst ems , Inc. .
ICND1 v1 .01- 12
. (,
), .
.
,
,
.
,
,
.
, Ethernet,
,
.
1-19
, .
200 7 Cisco Syst ems , Inc. .
ICND1 v1 .01- 13
,
, .
:
.
1-20
,
. .
.
.
200 7 Cisco Syst ems , Inc. .
ICND1 v1 .01- 14
, .
, .
, ,
.
. ,
, .
. :
.
, .
.
,
.
1-21
.
, , .
200 7 Cisco Syst ems , Inc. .
ICND1 v1 .01- 15
.
(). ,
.
1-22
.
.
200 7 Cisco Syst ems , Inc. .
ICND1 v1 .01- 16
( ) ,
.
. ,
.
1-23
200 7 Cisco Syst ems , Inc. .
ICND1 v1 .01- 17
, ,
, .
, ,
, ,
.
1-24
ICND1 v1 .01- 18
. DSL (Digital Subscriber Line)
.
.
. DSL
,
Ethernet.
CSU/DSU (Channel Service Unit/Data Service
Unit). (DSL, )
Ethernet ,
(CPE-Customer Permises Equipment).
1-25
,
.
,
.
, ,
.
,
: ,
, .
.
,
, ,
,
.
, ,
,
.
, . .
.
200 7 Cisco Syst ems , Inc. .
ICND1 v1 .01- 19
(.)
,
: ,
, , , ,
.
,
.
.
.
.
.
200 7 Cisco Syst ems , Inc. .
1-26
ICND1 v1 .01- 20
(.)
.
,
.
,
, ,
.
: DSL
,
.
ICND1 v1 .01- 21
1-27
1-28
? 2005
2005 .,
.
-. ,
700 ,
, ,
. ,
,
.
,
.
.
. ,
:
,
;
,
;
, ;
Cisco.
,
.
.
200 7 Cisco Syst ems , Inc. .
,
.
.
.
, ,
, . .
-, ,
60 80
.
1-30
.
.
.
1-31
,
.
20
. ,
.
,
. ,
, ,
.
1-32
,
.
;
200 7 Cisco Syst ems , Inc. .
:
, .
.
, .
.
.
, , .
.
,
, , .
, ,
.
1-33
, .
.
.
,
. ,
, ,
.
1-34
,
, ,
.
-
200 7 Cisco Syst ems , Inc. .
, ,
.
. 1980- ,
, .
,
. ,
, ,
.
(
),
. -
-.
, , , ,
, .
. ,
, ,
(DoS),
.
. , ,
, (
),
.
1-35
,
,
.
.
1-36
. ,
,
(, ).
.
.
: (
).
.
, ,
. ,
,
,
.
,
.
.
,
,
.
, .
. .
,
,
.
,
.
.
.
( )
.
,
.
. ,
Cisco.
:
:
:
:
200 7 Cisco Syst ems , Inc. .
:
.
.
Cisco, ,
,
.
,
.
, ,
, , .
,
.
1-37
1-38
. ,
( )
( ).
Cisco
.
.
Cisco ,
.
. ,
( ),
() .
, .
Cisco.
, ,
,
.
.
,
, , . .
, .
,
.
,
.
,
. ,
.
,
. ,
.
,
Cisco.
,
.
DoS-.
- IP-.
IP-.
, .
- ,
(, ,
). ,
,
.
, FTP
,
.
, .
.
, , ,
IP- .
, .
.
,
-.
. :
-.
, -.
- -, .
, , .
, .
, .
,
, .
.
, .
2007 Cisco Systems, Inc.
1-39
:
.
.
.
(, mY8!Rthd8y
mybirthday).
1-40
.
,
.
. .
. ,
.
.
, .
.
, .
-
,
, .
,
.
.
,
.
(.)
.
.
.
.
.
ICND1 v1 .01- 10
1-41
. .
1-42
,
.
,
(IATFF) ,
,
, .
- IATFF http://www.iatf.net.
(OSI) ,
,
.
, OSI.
OSI .
OSI
OSI.
, :
OSI;
, OSI;
TCP/IP
.
.
,
. .
, .
,
200 7 Cisco Syst ems , Inc. .
.
,
. , ,
, .
.
. ,
,
.
,
.
(, Ethernet, Token Ring, Frame
Relay . .),
, .
1-44
OSI
OSI .
, .
OSI.
?
. 1980-
. ,
,
,
,
.
1980-
. ,
, . ,
, ,
, .
,
. ,
.
, .
.
,
, .
1-45
OSI, 1984 , ,
.
,
, .
,
OSI,
. , OSI
.
OSI .
.
OSI ,
. OSI
, . ,
OSI . , OSI
, (, )
,
,
.
OSI
, :
1-46
. OSI
, .
. OSI
,
.
. OSI
.
. OSI
.
.
. OSI
,
.
. OSI
, .
OSI
OSI
.
.
OSI
1:
, ,
,
.
, ,
, ,
,
.
1-47
OSI (.)
2:
.
.
1-48
OSI (.)
3:
,
, .
,
-, ,
.
1-49
OSI (.)
4:
. ,
-
.
,
,
.
.
,
,
.
.
, ,
.
,
. ,
, .
1-50
OSI (.)
,
5:
,
, . ,
. ,
- ,
.
, .
,
(CoS)
,
.
1-51
OSI (.)
6:
, ,
,
. ,
,
(EBCDIC),
(ASCII).
,
.
1-52
OSI (.)
ICND1 v1 .01- 10
7:
OSI .
,
, .
,
OSI, OSI.
,
.
1-53
, ,
, .
.
.
FCS
ICND1 v1 .01- 11
, , .
. .
.
OSI (
, ), .
,
.
. ,
.
.
1-54
( 7).
7
.
( 6).
.
( 5).
.
( 4).
.
( 3).
.
( 2).
2
,
.
.
:
.
.
, .
.
1-55
ICND1 v1 .01- 12
,
.
.
1
( ), ,
.
, ,
.
,
.
.
.
:
, ,
. ,
.
1-56
,
OSI
.
.
ICND1 v1 .01- 13
,
(Packet Data Unit - PDU).
,
.
OSI.
PDU
. ,
.
7 2 OSI
.
,
.
,
( PDU 3). ,
(, ).
1-57
,
( PDU 2).
, ,
.
,
(1 0)
( ) 1.
1-58
TCP/IP
TCP/IP,
(TCP) (IP), ,
.
, TCP/IP .
TCP/IP
1 3
5 7
ICND1 v1 .01- 14
TCP/IP ,
OSI. OSI TCP/IP
,
. TCP/IP
.
. ,
OSI.
.
, ,
,
.
,
, ,
, ,
.
.
.
1-59
.
.
, ,
,
.
.
TCP/IP. ,
.
.
,
.
(API), ,
, .
TCP/IP,
IP.
1-60
TCP/IP
OSI
ICND1 v1 .01- 15
OSI TCP/IP
, . TCP/IP
OSI.
TCP/IP
OSI , ,
.
TCP/IP ,
OSI, TCP/IP
.
.
TCP/IP
OSI
.
TCP/IP, OSI,
, .
TCP/IP ,
,
,
OSI. OSI
, .
1-61
,
.
OSI ,
.
,
,
,
.
.
, ,
.
ICND1 v1 .01- 16
(.)
.
,
,
.
, ,
,
.
, ,
.
1-62
ICND1 v1 .01- 17
(.)
, ,
.
. .
,
.
.
ICND1 v1 .01- 18
(.)
TCP/IP.
,
,
.
TCP/IP ,
, .
OSI TCP/IP
,
, .
OSI TCP/IP
.
ICND1 v1 .01- 19
1-63
1-64
TCP/IP
IP- ,
IP-, IP-, ,
IP-. IP-: IP 4 (IPv4)
IP 6 (IPv6).
32- IPv4, 128- IPv6
, , IP-.
32- IPv4, , IPv6.
IP-?
IP- ,
.
IP-,
.
IP-.
IP- MAC-. ,
:
;
IPv4;
IPv4;
IP-;
IP-;
IP-;
DHCP IP-;
1-66
DNS IP-;
IP- .
(Internet Protocol - IP), TCP/IP,
, .
.
OSI
IP .
,
, ,
.
IP :
IP 3 OSI ( ) 3
TCP/IP ( );
IP ,
; ;
IP ,
,
;
IP " "
;
, ;
IP
;
.
1-67
; ,
, ,
.
:
IP- .
, -,
. .
,
, .
.
. , .
,
. , , ,
, .
1-68
IP-
, TCP/IP
, IP-.
32- IPv4.
IP-?
IP-.
(,
) .
:
.
200 7 Cisco Syst ems , Inc. .
,
, IP-
IP-, .
, , ,
, - 32- IP-.
IP-.
IP-
IP- TCP/IP.
IPv4 ,
. IPv4 32- ,
.
IP- :
( ) ,
IP-. .
( ) .
, , .
1-69
IP
IP IP
(Protocol Data Unit - PDU).
IP (IP-)
" ",
.
PDU ( "").
.
:
1-70
IP-:
.
200 7 Cisco Syst ems , Inc. .
IP- 32- , .
,
,
.
IP- 10101100000100001000000000010001.
32- 4 ,
(1 8 ).
0 255, . "
". IP-
172.16.128.17 "172 16 128 17".
1-71
IP-
,
IP- , .
IP- .
IP-:
IP- (classful) .
IANA (Internet Assigned Numbers Authority).
IP- . ,
.
IP-.
A
A
(8 ) 32- . 32-
. A "0".
0,
, 00000000 ( 0), 01111111 (
127). , 0 127,
. , 1 126
32- , A.
B
B
(16 ). . 2
B 10. 10
1-72
, B
A. 6
1 0. , ,
B, 10000000 ( 128), 10111111
( 191). ,
128 191 , B.
C
C (24 ) IP- ,
. C
110. , ,
C, 11000000 ( 192), 11011111
( 223).
192 223, C.
IP-
IP- (
) IP- AC,
.
1-73
IP-
IP-
. ,
, ,
.
IP-
.
IP-
. , A IP- 10.0.0.0 ,
10.1.2.3. IP- 172.16.0.0
B, 192.16.1.0 C. IP-
IP- .
,
B. , 16
, . IP 172.16.0.0 ;
. ,
172.16.0.0 IP- 172.16.16.1. 172.16
, 16.1 .
(Directed Broadcast Address).
IP- .
(172.16.0.0), 16 - ,
172.16.255.255.
1-74
.
Cisco IOS
.
IP- ,
(255.255.255.255). ,
,
.
.
. IP- 127.0.0.1.
IP-
,
IP-, IPv4-
(RFC 3927) 169.254/16.
,
. , ,
DHCP.
IP-
,
.
, ,
,
. ,
.
. 2-
.
IP- MAC-,
2 .
. A
, .
( ) ,
( ) .
A 224 2 (
), 16 777 214.
B , .
B 216 2, 65 534.
C .
, , 28 2, 254.
2007 Cisco Systems,
1-75
IP-
,
. , , , ,
.
(Public), (Private) IP-.
IP-.
IP-
IP-
. , .
InterNIC- Internet
Network Information Center ( Internet). InterNIC
IANA (Internet Assigned Numbers Autority -
Internet). IANA IP-,
.
, .
IP-
(ISP).
:
IP, ,
NAT Network Address Translation,
(CIDR Classless Interdomain Routing) IPv6.
1-76
IP-
10.0.0.0 - 10.255.255.255
172.16.0.0 - 172.31.255.255
192.168.0.0 - 192.168.255.255
ICND1 v1 .01- 10
IP-
, IP-,
, ,
.
, "
" .
1994 IETF RFC 1597,
, , TCP/IP IP-,
. RFC 1597
RFC 1918,
IP- . , IP
, ,
.
, IP-
( A, 16 B 256 C).
(.
). .
,
.
, , ,
.
NAT. ,
NAT, , .
1-77
DHCP
ICND1 v1 .01- 11
DHCP IP-
TCP/IP, ,
DNS-. DHCP
, , .
DHCP :
DHCP- .
DHCP IP- .
IP- DHCP.
DHCP-
. DHCP- . ""
DHCP- .
.
DHCP- .
1-78
(DNS)
(DNS)
IP- IP-,
. DNS.
DNS
TCP/IP
IP-
200 7 Cisco Syst ems , Inc. .
ICND1 v1 .01- 12
1-79
IP-
. ,
.
ICND1 v1 .01- 13
" "
IP-, .
DHCP-.
1-80
TCP/IP
DHCP DNS IPCONFIG.
ipconfig IP-,
.
1-81
/flushdns: DNS-.
DNS ,
.
/displaydns: DNS-, ,
Hosts,
.
DNS-
DNS-.
/registerdns: DNS
IP-, .
DNS
,
DNS- , . DNS
TCP/IP ,
DNS.
/showclassid Adapter: DHCP .
DHCP
Adapter (*).
,
IP-.
/setclassid Adapter [ClassID]: DHCP
. DHCP
Adapter (*).
,
IP-. DHCP ,
.
/?: .
1-82
, .
IP- :
.
IPv4 32 , ,
(, 192.168.54.18).
A 0, 2 B
10, 3 C
110.
ICND1 v1 .01- 16
(.)
IP- ( )
.
IP-,
, .
DHCP
IP-
TCP/IP, ,
DNS-.
DNS ,
TCP/IP
IP-.
ICND1 v1 .01- 17
1-83
(.)
IP- :
IPCONFIG
1-84
ICND1 v1 .01- 18
TCP/IP
,
, .
TCP/IP.
TCP/IP
.
IP
TCP/IP,
. IP
TCP/IP
. , , , ,
, .
IP-,
, ,
. ,
.
.
,
. OSI TCP/TP
.
,
. UDP TCP TCP/IP
,
. ,
UDP TCP
TCP/IP.
UDP TCP.
TCP/IP
OSI. , :
1-86
;
;
UDP;
TCP;
TCP/IP;
3 4 ;
4 ;
TCP-;
,
;
,
TCP/IP.
.
( )
( ),
( ).
,
, .
, UDP TCP,
,
. "" ,
, ,
UDP TCP. ""
, TCP.
,
UDP TCP. TCP
,
,
.
: UDP
UDP ,
.
, .
, ,
.
, .
2007 Cisco Systems, Inc.
1-87
, UDP ,
.
: TCP
TCP
. ,
- . ,
.
. ,
, .
.
, , ,
.
,
.
.
.
,
.
. TCP
,
.
,
IP-
. ,
.
, .
IP-,
OSI 5- 7-.
(best-effort) .
UDP.
IP- .
,
.
TCP
. TCP
.
TCP
.
, Yahoo Internet Explorer
- Yahoo, URL-.
Yahoo,
URL- (, Google).
URL- Cisco.com. ,
1-88
IP- -,
.
TCP
. ,
(MTU Maximum Transmission
Unit) . UDP
, ,
.
, ,
, .
,
.
TCP
;
. ,
(RTT Round-Trip Time) ,
.
. , ,
-.
,
TCP,
.
.
" ".
( )
TCP :
. ,
.
. , ,
,
, .
2007 Cisco Systems, Inc.
1-89
" " " "
(best-effort) .
.
.
( )
TCP .
TCP
.
.
,
.
- ,
. ,
.
, . TCP
.
TCP.
(
)
UDP .
. UDP
" ".
,
, .
,
.
1-90
UDP
TCP/IP ,
. UDP
TCP/IP .
UDP.
UDP
OSI TCP/IP
.
UDP .
UDP 4 () OSI
TCP/IP.
UDP
.
UDP, IP, ,
.
UDP .
UDP ,
. , UDP ,
. ,
, ,
.
UDP " "
,
,
.
UDP
.
.
1-91
:
UDP
, .
,
.
, .
.
, ,
.
UDP
UDP 64 . UDP (. )
:
Checksum ( ).
(16 ).
1-92
TCP
TCP Transmission Control Protocol (
). ,
. TCP
, .
TCP.
TCP
TCP/IP
TCP TCP/IP.
.
TCP .
TCP, UDP, 4
() OSI TCP/IP.
UDP, TCP
.
TCP
.
.
TCP ,
, .
TCP ,
, ,
TCP .
TCP ,
.
1-93
TCP
.
,
, ,
.
TCP ,
. ,
.
, , ,
, ,
. TCP
, , UDP
.
:
TCP
. ,
- ,
.
. ,
,
.
.
.
.
,
.
.
. ,
.
.
1-94
TCP
TCP TCP .
TCP.
TCP
TCP IP . TCP
IP ,
TCP.
, TCP. TCP :
1-95
TCP/IP
IP, TCP UDP TCP/IP ,
,
.
TCP/IP.
TCP/IP
:
FTP
TFTP
NFS.
:
SMTP (Simple Mail Transfer Protocol)
:
Telnet
rlogin
:
SNMP (Simple Network Management
Protocol)
:
DNS
Cis co System s. In c., 2 007. .
TCP/IP .
1-96
Telnet. Telnet .
Telnet
.
3 4
IP , .
3 4
.
3 4
,
IP-. IP
, ,
.
.
,
. ,
6, IP TCP.
17, IP UDP.
TCP UDP,
IP ,
, IP .
100
,
IP .
1-97
4
UDP TCP
. ,
UDP TCP.
ICND1 v1 .01- 10
.
, .
.
.
,
.
Internet Assigned Numbers Authority
(IANA).
. "-".
, Telnet 23.
,
.
, -
-. , ,
49152
65535.
1-98
UDP
, UDP .
TCP
, TCP .
FTP. FTP
. ,
FTP .
.
Telnet. Telnet ,
UNIX, .
,
. Telnet
,
. Telnet
(GUI). Telnet
,
SSH
.
-
- IANA
0 1023. .
1024 49151 ,
IANA.
, Lotus Mail.
1-99
49152
65535. .
1-100
.
.
ICND1 v1 .01- 11
,
,
. ,
. ,
,
, ,
.
, .
.
1-101
TCP
.
CTL = TCP
1.
Cis co System s. In c., 2 007. .
ICND1 v1 .01- 12
TCP ,
" ".
(SYN) (ACK)
.
, ,
(ISN
Initial Sequence Number),
.
.
TCP
1-102
1.
, ,
(
SYN), .
,
.
ISN,
.
2.
SYN
ACK,
.
,
.
ISN 1.
3.
SYN TCP ,
.
.
.
ICND1 v1 .01- 13
. ,
, . ,
,
.
,
, .
() , ,
, , .
,
.
" ".
, - , 0.
"". -
,
"".
, .
1-103
TCP ,
, ,
.
-
.
.
1-104
TCP
TCP
.
,
.
TCP.
TCP
ICND1 v1 .01- 14
, TCP.
,
. TCP ,
.
, -
.
, (
, ).
TCP .
- ,
.
1-105
1-106
1.
,
.
1.
2.
1.
3.
1
ACK = 2.
,
.
4.
ACK = 2
2.
5.
2
ACK = 3.
6.
ACK = 3
3.
,
.
TCP ,
.
.
ICND1 v1 .01- 15
,
, .
,
(RTT Round-Trip Time)
.
. ,
.
,
,
. ,
(. ).
, .
,
.
2007 Cisco Systems, Inc.
1-107
:
, 15 .
,
3 . ,
3 . 6 .
18 . ,
.
.
, ,
3 . 6 .
(, . .)
TCP.
, = 3
1.
,
.
2.
1, 2 3.
,
.
3.
1, 2 3
ACK = 4.
4.
ACK = 4
4, 5 6.
,
.
5.
4, 5 6
ACK = 7.
. ()
,
TCP, .
1-108
TCP
TCP
, ,
.
TCP.
TCP
ICND1 v1 .01- 16
.
TCP.
,
. ,
0,
, ,
.
3.
. .
,
.
, ,
.
, ,
, .
.
TCP (CWS
Congestion Window Size),
2007 Cisco Systems, Inc.
1-109
, .
. TCP
, .
1.
.
3
.
2.
1, 2 3.
3
.
3.
1 2,
, 2.
, , - ,
.
ACK = 3 WS = 2
4.
3 4.
5
,
.
5.
3 4, -
, 2.
3 4,
5.
ACK = 5 WS = 2
.
, , .
, ,
, ,
TCP.
,
.
. ,
,
, .
1-110
TCP
TCP ,
TCP.
TCP.
TCP
ICND1 v1 .01- 17
( ),
( ),
.
TCP
.
.
ACK. TCP
-. ,
, , .
1-111
,
.
.
;
.
UDP
, TCP. UDP
,
.
TCP
.
TCP ,
,
.
Cis co System s. In c., 2 007. .
ICND1 v1 .01- 18
(.)
TCP/IP ,
FTP (
ASCII-), TFTP (
Cisco IOS) Telnet (
).
IP
, ,
.
4
.
1-112
ICND1 v1 .01- 19
(.)
.
TCP
.
,
.
ICND1 v1 .01- 20
(.)
TCP
,
. TCP
.
,
.
TCP ,
.
TCP ,
TCP.
ICND1 v1 .01- 21
1-113
,
. ,
.
.
. ,
:
1 ;
2 ;
2;
3 ;
3;
2 3;
ARP;
1
1 .
1 .
:
Ethernet
200 7 Cisco Syst ems , Inc. .
1 , ,
,
.
Ethernet ,
Frame Relay T1. 1
, .
1
(NIC Network Interface Card).
1-114
2
2 .
2
.
:
2
. ,
.
(NIC Network Interface Card),
, .
1-115
2
2 .
2 .
MAC-
,
(NOS Network Operating System).
Netware, IP, Open Systems Interconnection
(OSI) Banyan-Vines. ,
2, NOS,
Media Access Control (MAC).
MAC- , .
2,
, MAC- .
.
.
1-116
3
3
.
.
.
.
,
, .
NOS.
.
1-117
3
3
.
3.
OSI
(NSAP).
TCP/IP IP-.
3. , OSI
(NSAP), TCP/IP IP-.
TCP/IP.
1-118
2 3
IP Ethernet (IP)
(MAC) .
Address Resolution Protocol (ARP).
ARP.
ARP
, Ethernet,
(MAC) . ARP ,
IP- .
" " IP-
MAC- .
"" ( ), ARP
(IP-
IP-).
Ethernet.
, ARP,
ARP MAC-.
,
( MAC-)
, . ( ,
ARP ARP-.) ARP
IP- MAC-.
. 300
(5 ), ,
.
1-119
ARP
ARP, IP-
MAC-. ARP.
ARP
IP-
ARP. IP-
(MAC) .
, ARP.
, ; ,
ARP.
ARP ,
. ARP
, 300 ;
ARP
ARP.
1-120
(1 22)
, 3-
192.168.3.1, 3-
192.168.3.2. .
.
TCP.
TCP , TCP
SYN 3- (192.168.3.2) IP.
1-121
(2 22)
ICND1 v1 .01- 10
IP SYN TCP 2
3 3,
IP TCP. IP 2.
1-122
(3 22)
ICND1 v1 .01- 11
2 3 2.
2 3
MAC-. ARP.
ARP . ,
,
ARP .
2, ARP .
1-123
(4 22)
ICND1 v1 .01- 12
ARP ARP- 2
(F ). 2
ARP 2, MAC-
,
MAC-.
(5 22)
1-124
ICND1 v1 .01- 13
(6 22)
ICND1 v1 .01- 14
192.168.3.2 ,
2.
(7 22)
ICND1 v1 .01- 15
ARP ARP.
1-125
(8 22)
ICND1 v1 .01- 16
ARP , ARP.
(9 22)
ICND1 v1 .01- 17
ARP 2 MAC-
0800:0222:2222 ( 192.168.3.1).
1-126
(10 22)
ICND1 v1 .01- 18
2 ARP 2
MAC- , ARP,
MAC- .
(11 22)
ICND1 v1 .01- 19
192.168.3.1 , , MAC-
, 2.
1-127
(12 22)
ICND1 v1 .01- 20
ARP ARP.
(13 22)
ICND1 v1 .01- 21
ARP 2.
1-128
(14 22)
ICND1 v1 .01- 22
2 2.
(15 22)
ICND1 v1 .01- 23
192.168.3.2 , .
(PDU) TCP.
1-129
(16 22)
ICND1 v1 .01- 24
(17 22)
1-130
ICND1 v1 .01- 25
(18 22)
ICND1 v1 .01- 26
(19 22)
ICND1 v1 .01- 27
TCP
, .
1-131
(20 22)
ICND1 v1 .01- 28
,
TCP .
(21 22)
ICND1 v1 .01- 29
,
.
1-132
(22 22)
ICND1 v1 .01- 30
1-133
ICND1 v1 .01- 31
MAC- IP-
ARP.
, .
, - ,
.
1-134
Ping ,
IP-.
- ICMP ("Ping?"),
"-" ICMP.
, -
(RTT Round-Trip Time) ( )
.
ping [-t] [-a] [-n Count] [-l Size] [-f] [-i TTL] [-v TOS]
[-r Count] [-s Count] [{-j HostList | -k HostList}] [-w
Timeout] [TargetName]
-t. - ,
.
Ctrl-Break. -
Ctrl-C.
-a. IP-
. ,
.
-n Count. -. 4.
1-135
1-136
-l Size. - ( ).
32. 65 527.
-f. , -
IP- 1, . . -
.
(PMTU Path MTU).
-w Timeout. -
-.
- , "Request timed
out". 4000 ( ).
TargetName. , IP-
.
/?: .
ARP
arp ARP,
, IP-
Ethernet.
Ethernet Token Ring, ,
. arp
.
1-137
TRACERT ,
- ICMP.
TRACERT (IP TTL).
TTL 1, TTL .
TTL (0),
ICMP "Time Exceeded".
TRACERT - TTL, 1,
TTL 1,
.
ICMP "Time Exceeded", ,
. ,
TTL , TRACERT.
TRACERT
, ICMP "Time Exceeded".
tracert -d TRACERT
DNS IP-,
TRACERT IP- .
-d. .
-h maximum_hops.
.
-j host-list. .
-w timeout. ( ) .
1-138
target_host. IP- .
1-139
,
.
1 .
2
.
2 MAC-.
.
3 IP-.
ICND1 v1 .01- 37
(.)
MAC-
.
MAC- ,
2 3 ARP.
TCP.
.
, ,
.
:
ping
tracert
arp
1-140
ICND1 v1 .01- 38
Ethernet
,
, .
, , , Ethernet
,
.
, . ,
Ethernet
.
, . ,
:
Ethernet;
CSMA/CD;
Ethernet ;
Ethernet;
Ethernet;
MAC-
Ethernet.
,
.
.
,
.
,
, .
,
, ,
.
1-142
,
, .
.
Ethernet
IP
ARP
DHCP
200 7 Cisco Syst ems , Inc. .
.
. ,
.
.
.
:
(NIC).
, .
. (,
),
.
.
:
. ,
1 OSI.
.
Ethernet. Ethernet
. Ethernet 2
OSI
.
1-143
1-144
. , ,
.
3- OSI.
. ,
, :
Ethernet;
(IP);
.
.
.
.
. (,
), (, ).
.
, , ,
.
1-145
?
.
.
, :
1-146
.
, , .
.
.
.
Ethernet
Ethernet.
Ethernet.
Ethernet
1-147
Ethernet
Ethernet
OSI.
Ethernet .
OSI.
IEEE OSI
:
Logical Link Control (LLC)
,
Media Access Control (MAC)
,
LLC
LLC IEEE,
.
MAC 1,
. LLC .
LLC ,
. , ,
IP , .
MAC
MAC .
IEEE 802.3 MAC MAC-,
. MAC MAC-
( ) .
MAC-.
1-148
CSMA/CD Ethernet
Ethernet , ,
, ,
.
.
CSMA/CD
Ethernet
(CSMA/CD), Ethernet.
CSMA/CD.
Ethernet ""
. , .
. ,
.
CSMA/CD
. CSMA/CD ""
, , . , CSMA/CD
. , .
, , ,
(. ).
- . CSMA/CD
, .
, , .
.
, .
.
2007 Cisco Systems, Inc.
1-149
, , .
, , ,
.
CSMA/CD ,
.
" ". ,
.
,
.
.
.
.
1-150
Ethernet
, Ethernet, .
Ethernet.
Ethernet
Ethernet ,
. ,
.
MAC- Ethernet, :
Preamble (). ,
,
, .
Destination Address ( ).
, .
Source Address ( ).
-.
1-151
1-152
Ethernet
: ,
. Ethernet
.
Ethernet .
ICND1 v1 .01- 10
.
. ,
.
.
.
. ,
. ,
.
.
. ,
.
.
1-153
Ethernet
, Ethernet
.
Ethernet.
MAC-
ICND1 v1 .01- 11
MAC-,
BIA- (Base Interface Address);
. 48- MAC- Ethernet
.
1-154
.
,
.
- . OUI
24- ,
1.
24- , .
Ethernet.
MAC-
MAC- Ethernet.
MAC- .
MAC-
ICND1 v1 .01- 12
MAC OSI ,
48- ,
, , "" .
MAC- ,
:
00:00:0c:43:2e:08 0000:0c43:2e08
MAC-,
. MAC-
. , , MAC-
.
1-155
, .
,
.
, ,
,
.
.
.
ICND1 v1 .01- 13
(.)
Ethernet 1970-
DEC, Intel Xerox DIX
Ethernet. 1980-
IEEE 802.3
, Ethernet, Ethernet 802.3 802.2.
Ethernet
OSI
CSMA/CD
.
CSMA/CD "" , ,
. ,
. ,
. , ,
,
.
200 7 Cisco Syst ems , Inc. .
1-156
ICND1 v1 .01- 14
(.)
Ethernet ,
, ,
, /, ,
.
:
,
;
; ,
.
, Ethernet,
.
ICND1 v1 .01- 15
(.)
MAC ,
48- ,
.
ICND1 v1 .01- 16
1-157
1-158
Ethernet
Ethernet ,
,
Ethernet.
Ethernet, (NIC) .
Ethernet. ,
:
Ethernet;
Ethernet;
Ethernet;
(straight-through) (crossover)
.
Ethernet
(NIC Network Interface Card) ,
.
.
, ,
.
.
,
.
(IRQ) -,
(, DOS Windows)
( ), .
, , .
. IRQ
,
. -
,
.
MAC-
.
1-160
Ethernet
Ethernet .
,
Ethernet.
Ethernet
, Ethernet,
EIA/TIA. , Ethernet,
EIA/TIA-568 (SP-2840). EIA/TIA
(UTP) RJ-45.
Ethernet. ,
Ethernet 10-/, Ethernet 100-/.
10- 100-/,
5- Fast Ethernet.
1-161
Ethernet .
.
RJ-45 (. ). "RJ" " " (registred jack),
"45" .
1-162
1000BASE-T GBIC
Gigabit (GBIC) -
, Gigabit Ethernet
. GBIC
,
1000BASE-X
. GBIC
Gigabit Ethernet.
GBIC
, . , GBIC
.
1-163
GBIC Cisco
(1000BASE-SX);
/ (1000BASE-LX/LH)
(1000BASE-ZX)
GBIC ,
,
.
GBIC:
(1000BASE-SX);
/ (1000BASE-LX/LH);
(1000BASE-ZX);
,
.
(UTP).
.
1-164
: 10 1000 /
:
:
:
200 7 Cisco Syst ems , Inc. .
UTP .
. ,
.
- .
UTP
. ,
(UTP) (STP) .
UTP .
22 24 AWG, 0,64 0,51 .
100 .
, , .
UTP 0,43 (0,17 ),
. ,
UTP ,
.
1-165
:
1.
.
2. 4 /.
3. 10BASE-T
10 /.
5. 100 /.
5e. , 1000 /
(1 /)
6. 24 AWG (0,51 ),
1000 /.
1
(, , ), 5, 5e 6.
1-166
UTP
UTP
EIA/TIA .
, ,
UTP .
RJ-45
RJ-45,
, . ( )
(true) "tip" (T1 - T4);
(false) "ring" (R1 - R4).
"tip" "ring" .
.
T1 R1, T2 R2 . .
RJ-45 ("") .
, ,
8 1.
1-167
RJ-45
("") , ,
. , ,
1 8.
1-168
UTP ()
10BASE-T/
100BASE-TX ()
1
2
3
4
5
6
7
8
TX+
TXRX+
NC
NC
RXNC
NC
1
2
3
4
5
6
7
8
TX+
TXRX+
NC
NC
RXNC
NC
ICND1 v1 .01- 10
,
, EIA/TIA (
) :
RJ-45
. RJ-45
, ( ).
,
(. ).
TX+
TX+
TX-
TX-
RX+
RX+
RX-
RX-
1-169
UTP ()
10BASE-T
100BASE-TX
EIA/TIA T568A
1
2
3
4
5
6
7
8
TX+
TXRX+
NC
NC
RXNC
NC
TX+
TXRX+
NC
NC
RXNC
NC
1
2
3
4
5
6
7
8
EIA/TIA T568B
ICND1 v1 .01- 11
RJ-45
. , Ethernet, 1 RJ-45
3 . 2
6 , .
1-170
TX+
RX+
TX-
RX-
RX+
TX+
RX-
TX-
UTP: c
ICND1 v1 .01- 12
,
Cisco.
: .
:
- ;
- ( );
- ( );
:
- ;
- ;
- ;
- ;
Ethernet
- .
1-171
UTP
ICND1 v1 .01- 13
UTP, .
, UTP Ethernet, .
1-172
, .
, ,
.
MAC-
,
.
,
Ethernet,
EIA/TIA.
, Ethernet,
EIA/TIA-568 (SP-2840).
200 7 Cisco Syst ems , Inc. .
ICND1 v1 .01- 14
(.)
UTP .
.
(,
, ,
).
(, ,
,
).
ICND1 v1 .01- 15
1-173
1-174
, .
(,
, ),
,
.
.
Ethernet,
. Ethernet
OSI.
, Ethernet,
. Ethernet
CSMA/CD.
200 7 Cisco Syst ems , Inc. .
1-175
(.)
OSI
TCP/IP.
OSI ,
,
.
TCP/IP 32- ,
4 , .
DHCP-.
. .
1-176
,
.
,
(IATFF) ,
,
, .
- IATFF http://www.iatf.net.
, , .
"
".
B1
?
( .) (: )
)
)
)
)
)
)
B2
? (: )
)
)
)
)
B3
)
)
)
,
,
? (: )
)
)
)
)
B5
? (: )
)
B4
,
, .
,
.
,
.
.
.
.
? (:
)
)
)
)
)
1-175
B6
? ( .) (: )
)
)
)
)
)
)
B7
. (:
)
_____ 1.
_____ 2.
_____ 3.
_____ 4.
_____ 5.
_____ 6.
_____ 7.
)
,
)
)
)
)
,
)
)
,
B8
?
(: )
)
)
)
)
B9
?
(: )
)
)
)
)
1-176
,
, .
:
.
,
.
.
,
, .
,
.
,
.
.
B10
. (:
)
_____ 1.
_____ 2.
_____ 3.
_____ 4.
_____ 5.
_____ 6. .
)
.
)
)
)
)
)
B11
? ( .) (: )
)
)
)
)
B12
B13
.
.
, .
.
? (:
)
)
;
)
)
)
? ( .) (: )
)
)
)
)
.
.
.
.
1-177
B14
? (: )
)
)
)
)
B15
OSI ? (
.) (: )
)
)
)
)
B16
DDoS;
" ";
Love Bug
OSI ,
.
OSI .
, OSI,
.
OSI
.
OSI . (:
)
_____ 1.
_____ 2.
_____ 3.
_____ 4.
_____ 5.
_____ 6.
_____ 7.
)
,
, .
)
, ,
, .
)
)
.
)
, ,
,
.
)
,
, .
)
,
.
1-178
B17
.
(: )
_____
_____
_____
_____
_____
_____
_____
_____
)
)
)
)
B18
? (:
)
)
)
)
)
B19
1. 1.
2. 2.
3. 3.
4. 4.
5. 5.
6. 6.
7. 7.
8. 8.
( 6).
.
( 5).
.
( 7).
7
.
( 3).
.
( 4).
.
.
( 2).
2
,
.
.
.
.
(: )
_____ 1.
_____ 2.
_____ 3.
1-179
)
)
)
B20
? (:
)
)
)
)
)
B21
.
,
.
(1 0)
( ).
, ,
.
.
.
.
TCP/IP .
(: )
_____ 1.
_____
_____
_____
_____
)
)
)
)
)
B22
OSI TCP/IP
? (: )
)
)
)
)
B23
IPv4-? (:
TCP/IP
)
)
)
)
)
1-180
,
. .
2.
3. , ,
,
.
4.
.
,
,
, .
5. ,
.
16
32
48
64
128
B24
B? (: TCP/IP)
)
)
)
)
B25
B26
B27
B28
B29
.
.
.
.
172.16.128.17? (:
TCP/IP)
)
A
)
B
)
C
)
D
? (:
TCP/IP)
)
,
.
)
IP- .
)
,
.
)
.
IP-?
( .) (:
TCP/IP)
)
10.215.34.124
)
127.16.71.43
)
172.17.10.10
)
225.200.15.10
IP ? (
.) (:
TCP/IP)
)
IP .
)
IP .
)
IP .
)
IP 2 TCP/IP
OSI.
)
IP .
)
IP .
TCP ? (
.) (:
TCP/IP)
)
TCP 3 TCP/IP.
)
TCP .
)
TCP .
)
TCP
.
)
TCP .
)
TCP
.
1-181
B30
TCP UDP?
(: TCP/IP)
)
4 () OSI
TCP/IP.
)
.
)
" "
.
)
.
B31
IP- , _____. (:
TCP/IP)
)
)
)
)
B32
TCP?
( .)
TCP/IP)
)
)
)
)
B33
.
.
.
TCP
.
?
(: TCP/IP)
)
)
)
1-182
.
.
.
.
TCP?
( .) (:
TCP/IP)
)
)
)
)
B35
UDP?
( .) (:
TCP/IP)
)
)
)
)
B34
B36
, , _____.
(: TCP/IP)
)
)
)
B37
B38
TCP
TCP
?
(: TCP/IP)
)
)
)
)
B42
ACK
SYN
SYN
_____. (:
TCP/IP)
)
)
)
)
B41
TCP? (:
TCP/IP)
)
)
)
B40
16-
16-
16-
16-
TCP
? (:
TCP/IP)
)
)
)
)
B39
.
.
.
.
? (:
TCP/IP)
)
)
)
)
UDP
TCP
1-183
B43
Ethernet? (:
Ethernet)
)
)
)
)
B44
Ethernet 802.3?
( .) (: Ethernet)
)
)
)
)
)
)
B45
)
)
)
)
)
)
MAC- ,
.
MAC- ,
.
MAC-, .
MAC- .
?
(: Ethernet)
)
)
)
)
1-184
, Ethernet,
.
4-
, .
8-
, .
6-
.
MAC- ? (:
Ethernet)
)
B47
CSMA/CD.
, Ethernet II.
( 1).
1970- .
MAC ( 2).
"" Ethernet.
Ethernet ?
(: Ethernet)
)
B46
ISO
IEEE
EIA
IEC
USB
.
, .
, .
.
B48
B49
3
4
5
5e
UTP ,
. (: Ethernet)
_____ 1.
_____ 2.
_____ 3.
_____ 4.
_____ 5.
_____ 6.
5e
_____ 7. 6
)
100 /.
)
, 1000 / (1
/).
)
24 AWG (0,51 ),
1000
/.
)
.
)
Token Ring ( 16 /).
)
4 /.
)
10BASE-T
10 /.
B50
UTP? ( .) (:
Ethernet)
)
)
)
)
)
UTP .
UTP .
.
.
UTP.
1-185
1-186
B1
, ,
B2
B3
B4
B5
B6
, ,
B7
1 = , 2 = , 3 = , 4 = , 5 = , 6 = , 7 =
B8
B9
B10
1 = , 2 = , 3 = , 4 = , 5 = , 6 =
B11
B12
B13
B14
B15
B16
1 = , 2 = , 3 = , 4 = , 5 = , 6 = , 7 =
B17
1 = , 2 = , 3 = , 4 = , 5 = , 7 = , 7 = , 8 =
B18
B19
1 = , 2 = , 3 =
B20
B21
1 = , 2 = , 3 = , 4 = , 5 =
B22
B23
B24
B25
B26
B27
B28
, ,
B29
, ,
B30
B31
B32
B33
, ,
B34
B35
B36
B37
B38
B39
B40
B41
B42
B43
B44
, ,
B45
B46
B47
B48
B49
1 = , 2 = , 3 = , 4 = , 5 = , 6 = , 7 =
B50
, ,
1-187
1-188
Ethernet
, ,
,
,
.
Ethernet
. , :
, Ethernet;
Ethernet
;
Cisco IOS;
,
;
Ethernet;
, .
2-2
() ,
.
, , .
,
. ,
.
,
Ethernet. , :
Ethernet ;
Ethernet;
, ;
Ethernet.
Ethernet
Ethernet
. .
.
Ethernet
.
.
Ethernet ,
- ,
(CSMA/CD) . ,
.
, 1
(OSI), Ethernet , 1
.
2-4
Ethernet ,
,
, .
10BASE-T (Ethernet ):
10 , 10 /.
BASE () , Ethernet
.
T .
FL - .
Ethernet
Ethernet
10BASE-T
Ethernet, 10 /,
100
10BASE-FL
Ethernet, 10 /,
-
2 000
100BASE-TX
Ethernet, 100 /,
100
100BASE-FX
Fast Ethernet, .
400
1000BASE-T
Gigabit Ethernet,
100
1000BASE-LX
Gigabit Ethernet,
-
.
550 62,5
( -
50-; 10
- 10-)
1000BASE-SX
Gigabit Ethernet,
-
.
1000BASE-CX
Gigabit Ethernet
25
Ethernet
2-5
Ethernet .
Ethernet
.
/
,
.
.
,
.
, , .
, .
.
, .
. ,
.
, Ethernet.
.
, ,
Ethernet .
2-6
Ethernet, ,
.
.
CSMA/CD, Ethernet.
Ethernet .
, ,
.
, , .
, jam
, ,
, .
, .
( )
, ,
, . ,
,
.
Ethernet
, ,
.
Ethernet
2-7
Ethernet
, .
.
.
Ethernet
. , ,
,
- .
, 2
, .
.
, ,
.
.
MAC-
.
,
. 3, ,
2.
2-8
, .
. Ethernet
,
.
,
,
.
, .
(.)
,
, ,
.
, ,
2 ( ) OSI
,
.
.
Ethernet
2-9
2-10
,
.
5 000 (MIPS),
50 000 MIPS.
.
. .
.
. ,
.
Ethernet
. ,
:
Ethernet;
, ;
c ;
, .
,
, .
.
200 7 Cisco Syst ems , Inc. .
2-12
.
,
, , ,
.
.
,
. ,
, TCP/IP, ,
.
.
.
, ,
(VoD),
.
.
2 (OSI)
, .
, .
2 OSI
,
Ethernet Ethernet
. ,
.
:
2 OSI;
, ,
( )
;
,
, ;
MAC-.
, :
Ethernet
2-13
,
,
. .
:
,
-, ,
.
, ,
.
2-14
.
.
24 48 10 / 100 /.
.
.
,
, .
.
.
10 / 100 /, 1 / 10 /
.
.
10 /, 100 /
1 000 /.
,
.
.
.
, ,
. ,
,
, .
,
, .
,
,
.
.
,
. ,
.
.
.
.
.
, .
, ,
.
.
,
( )
.
Ethernet
2-15
,
,
.
.
.
, .
, -
, .
, .
,
.
2-16
.
.
.
. .
.
,
.
, 1 2,
5 6. -
- .
,
, ,
,
. ,
.
.
, ( ).
,
. . ,
100 / -
100 / 100 /,
200 / .
. ( ,
.)
.
10 100 /
100 1 000 /,
.
.
Ethernet
2-17
Ethernet
.
Ethernet: ,
. .
2 OSI
,
200 7 Cisco Syst ems , Inc. .
-,
. -
,
.
, .
Ethernet
2-18
1.
, -
.
2.
, -
, , .
,
.
3.
, -
, .
4.
, ,
, .
(flooding).
, , -.
-,
.
, ,
.
.
1.
1.
2.
- ,
, -.
3.
,
, , .
4.
-
A.
5.
-
, , -.
- .
6.
,
-, .
Ethernet
2-19
. ,
.
, .
200 7 Cisco Syst ems , Inc. .
. , ,
, ,
,
.
, ,
.
,
.
.
.
2-20
VLAN
VLAN = = ()
200 7 Cisco Syst ems , Inc. .
VLAN ,
.
VLAN- .
VLAN,
, ,
.
VLAN,
. VLAN ,
VLAN, VLAN
.
VLAN .
VLAN
. VLAN
, ,
, ,
,
.
VLAN
. VLAN
, . , VLAN
(WAN).
Ethernet
2-21
,
.
Ethernet
, ,
, ,
.
Ethernet
Ethernet.
,
,
.
,
,
. ,
:
.
200 7 Cisco Syst ems , Inc. .
ICND1 v1 .02- 10
(.)
, ,
, ,
.
2 OSI,
, ,
.
,
.
MAC-
. MAC-
.
2-22
ICND1 v1 .02- 11
(.)
. ,
, ,
.
.
ICND1 v1 .02- 12
Ethernet
2-23
2-24
.
, .
. , :
2;
3;
2
2.
2 .
MAC-
, -
, .
2, , - .
, -.
.
2-26
3
3
.
3.
OSI
(NSAP).
TCP/IP IP-.
(NOS)
3. , OSI (NSAP),
TCP/IP IP-.
Ethernet
2-27
(1 10)
192.168.3.1 192.168.3.2.
. UDP.
2-28
(2 10)
, .
UDP UDP (PDU)
IP ( 3) PDU 192.168.3.2.
IP PDU 3 2.
(3 10)
, ,
ARP .
Ethernet
2-29
(4 10)
192.168.3.1 ARP. ,
, ( ).
2-30
(5 10)
, .
-
MAC- .
- , .
(0800:0222:2222 = 1).
,
.
Ethernet
2-31
(6 10)
(7 10)
ICND1 v1 .02- 10
ARP .
2-32
(8 10)
ICND1 v1 .02- 11
- .
,
(0800:0222:1111 = 2).
MAC- ,
1.
Ethernet
2-33
(9 10)
ICND1 v1 .02- 12
(10 10)
ICND1 v1 .02- 13
.
.
2-34
, .
2 MAC-.
3 IP-.
MAC- ,
2 3 ARP.
MAC- ,
.
,
2 ( ).
ICND1 v1 .02- 14
Ethernet
2-35
2-36
Cisco IOS
,
, . Cisco IOS
,
.
(SOHO)
Cisco IOS.
Cisco . ,
:
Cisco IOS
;
Cisco;
Cisco;
Cisco IOS;
EXEC EXEC;
,
;
Cisco IOS;
Cisco IOS
Cisco IOS
.
Cisco IOS.
Cisco IOS
.
.
.
.
.
200 7 Cisco Syst ems , Inc. .
c
;
Cisco IOS
, Telnet.
Cisco IOS EXEC.
2-38
Cisco IOS
, .
Cisco.
2.
Cisco
, .
:
Cisco IOS ,
, 2
. Cisco,
,
3,
IP-,
.
:
, IP-
;
, . .
.
.
Ethernet
2-39
Cisco
Cisco .
1. . ,
,
(POST Power-On Self-Test).
2. ,
.
.
3.
,
.
, ,
,
.
2-40
,
.
Cisco.
.
.
200 7 Cisco Syst ems , Inc. .
,
,
. , ,
,
.
.
.
,
. Cisco
:
RJ-45-EIA/TIA-232
()
:
: 9 600 /
: 8
: 1
Ethernet
2-41
.
,
.
.
Cisco :
14,4 /
:
Telnet;
TFTP- .
,
CiscoWorks.
2-42
,
. , Cisco SOHO
.
Cisco IOS
Cisco IOS
. Cisco IOS
, ,
.
Cisco IOS.
Cisco IOS
.
.
.
.
Enter
.
EXEC
,
.
. Enter ()
.
Cisco IOS .
Cisco IOS,
.
Cisco IOS EXEC
.
Ethernet
2-43
EXEC
Cisco IOS EXEC:
.
EXEC EXEC.
EXEC ()
Cisco IOS
EXEC
.
EXEC
Cisco.
1.
,
(
).
EXEC.
,
EXEC. (>)
,
EXEC.
?
EXEC,
,
EXEC.
? EXEC
, .
.
2.
hostname>
exit,
EXEC.
EXEC
. EXEC
.
2-44
EXEC ()
Cisco IOS
Enabled
, ,
EXEC.
EXEC
EXEC, enable hostname>.
enable password enable secret password, .
hostname#. ,
EXEC. ? EXEC
, EXEC.
EXEC, disable
hostname#.
Cisco
.
Telnet, .
Telnet .
SSH, Cisco,
.
SSH Cisco IOS.
Ethernet
2-45
Cisco Cisco IOS,
,
. ,
Cisco.
.
.
. ,
. , sh?,
, sh.
. ?,
, .
.
.
, <cr> . ,
show ?, show.
Ctrl Escape
. Cisco IOS
,
2-46
, .
.
,
. ,
, .
% Ambiguous
command
(
):
show con
,
.
(?)
.
% Incomplete
command
(
)
,
.
(?)
.
% Invalid input
detected at
^ marker
(
^)
. (^)
.
(?),
.
,
.
.
, Cisco IOS show history.
Ethernet
2-47
ICND1 v1 .02- 10
,
. , ,
,
.
clock () ,
Cisco IOS.
, , .
Cisco IOS , ,
IP-, Telnet .
,
, , cl?.
clock, ,
, ? ( ? ), ,
. clock?,
, clock set.
clock set, ,
, Ctrl-P ( ),
.
(?), .
,
?, ,
, .
2-48
(.)
ICND1 v1 .02- 11
, .
Cisco IOS
, , ,
(?), ,
. ,
, , Return,
.
(^)
.
, , .
.
(^) , .
.
Ethernet
2-49
Cisco IOS
,
.
.
,
.
ICND1 v1 .02- 12
,
. ,
, ,
.
EXEC terminal editing,
EXEC terminal no editing, .
,
. ,
. ,
,
.
2-50
(.)
ICND1 v1 .02- 13
. ($)
, . ,
Ctrl-B ,
, Ctrl-A, .
, ,
.
.
, ,
.
Ctrl-A
Ctrl-E
Esc-B
Esc-F
Ctrl-B
Ctrl-F
Ctrl-D
Backspace
Ctrl-R
Ctrl-U
Ethernet
2-51
Ctrl-W
Ctrl-Z
EXEC.
Tab
,
.
2-52
Escape .
Cisco .
.
.
ICND1 v1 .02- 14
:
;
, ;
c EXEC .
,
.
,
, terminal history
EXEC.
, , Ctrl-P
.
, .
Ctrl-P , Ctrl-N
.
, .
.
,
Return.
2007 Cisco Systems, Inc.
Ethernet
2-53
ICND1 v1 .02- 15
Cisco :
RAM ( , ): ,
, . .
NVRAM ( ):
.
-: Cisco IOS,
.
show startup-config ,
NVRAM. show running-config RAM.
2-54
ICND1 v1 .02- 16
Ethernet
2-55
,
.
Cisco IOS
Cisco,
Cisco Catalyst.
, ,
, .
IOS
,
,
.
Cisco IOS.
,
.
200 7 Cisco Syst ems , Inc. .
ICND1 v1 .02- 17
(.)
EXEC: .
EXEC
, EXEC.
Cisco IOS Cisco IOS,
, .
Cisco IOS
,
.
Cisco
() . ,
,
.
2-56
ICND1 v1 .02- 18
Cisco Catalyst .
, .
, ,
Catalyst.
.
.
(CLI)
Cisco IOS. , :
Cisco IOS;
,
Cisco IOS;
Cisco IOS;
Cisco IOS;
Cisco IOS ;
show
-.
Catalyst
Catalyst ,
Cisco IOS
. Catalyst.
Catalyst
.
.
Catalyst ,
.
1
:
,
HyperTerminal.
.
. Catalyst
./., Cisco Catalyst 2960.
:
Cisco IOS
.
Catalyst 2960.
, ,
Catalyst 2960. .
2-58
Catalyst ,
, ,
.
Catalyst 2960.
Catalyst 2960
: .
: .
: ; POST
.
: .
: .
: ,
, .
: , .
: ,
.
Ethernet
2-59
(
STAT )
: .
: , .
: , .
: .
.
(CRC),
.
: ,
, -
Spanning
Tree (STP) - .
( UTL
)
:
.
:
.
: :
( FDUP )
2-60
Catalyst 2960G-12-EI: ,
50%
. 2 GBIC ,
25%, 50%
.
GBIC ,
25% , .
2 GBI: ,
25%, 50%
.
GBIC ,
25% , .
Catalyst 2960G-48-EI: ,
50%
. 2 GBIC
, 25%,
50% .
GBIC ,
25% , .
: .
: .
POST ,
. POST ,
.
Catalyst.
Catalyst 2960
Ethernet
2-61
, ,
.
--- System Configuration Dialog --Would you like to enter the initial configuration dialog? [yes/no]: y
At any point you may enter a question mark '?' for help.
Use ctrl-c to abort configuration dialog at any prompt.
Default settings are in square brackets '[]'.
Basic management setup configures only enough connectivity for
management of the system, extended setup will ask you to configure
each interface on the system
Would you like to enter basic management setup? [yes/no]: no
First, would you like to see the current interface summary? [yes]: no
Configuring global parameters:
Enter host name [Switch]: SwitchX
The enable secret is a password used to protect access to privileged
EXEC and configuration modes. This password, after entered, becomes
encrypted in the configuration.
Enter enable secret: secret_password
The enable password is used when you do not specify an enable secret
password, with some older software versions, and some boot images.
Enter enable password: enable_password
The virtual terminal password is used to protect access to the
router over a network interface.
Enter virtual terminal password: vty_password
Configure SNMP Network Management? [no]: no
Configuring interface parameters:
Do you want to configure Vlan1
interface? [yes]: n
..text omitted ..
Do you want to configure FastEthernet0/24
interface? [yes]: n
2-62
Catalyst
2960
, :
The following configuration command script was created:
hostname SwitchX
enable secret 5 $1$oV63$8z7cBuveTibpCn1Rf5uI01
enable password enable_password
line vty 0 15
password vty_password
no snmp-server
!
!
interface Vlan1
ip address 10.1.1.140 255.255.255.0
!
interface FastEthernet0/1
..text omitted..
interface FastEthernet0/24
!
end
Ethernet
2-63
2, .
2-64
Catalyst
, Cisco IOS
, .
, .
Catalyst .
EXEC
:
:
.
:
. enable.
EXEC ,
enable. enable password,
. . enable password
.
.
Telnet, . Telnet
.
SSH.
Ethernet
2-65
Catalyst
,
.
.
:
SwitchX#configure terminal
SwitchX(config)#
SwitchX(config)#interface fa0/1
SwitchX(config-if)#
, IP-,
,
. (),
.
. ,
.
2-66
.
. ,
, .
.
SwitchX.
Ethernet
2-67
IP-
SwitchX(config)#interface vlan 1
SwitchX(config-if)#ip address {ip } {}
:
SwitchX(config)#interface vlan 1
SwitchX(config-if)#ip address 10.5.5.11 255.255.255.0
SwitchX(config-if)#no shutdown
. no
shutdown, .
200 7 Cisco Syst ems , Inc. .
3
2.
3 TCP/IP.
3 .
VLAN 1, IP- VLAN 1.
IP-
VLAN 1, ip
address. IP- .
IP- , Telnet
SNMP.
no shutdown,
.
2-68
:
SwitchX(config)#ip default-gateway 172.20.137.1
ICND1 v1 .02- 10
ip default-gateway. IP- ,
,
. IP- IP .
, .
Ethernet
2-69
SwitchX
SwitchX copy running-config startup-config
Destination filename [startup-config]?
Building configuration
SwitchX
NVRAM
ICND1 v1 .02- 11
NVRAM copy running-config startup-config.
NVRAM ,
, , NVRAM.
2-70
Catalyst,
show version, show running-config
show interfaces. ,
.
SwitchX#show version
,
,
, .
SwitchX#show running-config
.
SwitchX#show interfaces
,
.
200 7 Cisco Syst ems , Inc. .
ICND1 v1 .02- 12
:
show version:
.
show running-config: ()
. EXEC.
IP-, .
show interfaces:
. ,
. ,
. type () slot/number
(/), type Ethernet Fast Ethernet, slot/number
0 (, e0/1).
Ethernet
2-71
show version
Swi tch# sho w v ersi on
Cisc o I OS S oft war e, C 296 0 So ftw are (C2 960- LAN BASE K9- M), Ver sio n 12 .2( 25)S EE2 , R ELEA SE
SOF TWAR E ( fc1 )
Cop yrig ht (c) 198 6-20 06 by Cisc o S yste ms, In c.
Com pile d F ri 28-J ul-0 6 1 1:5 7 by ye nanh
Ima ge t ext -ba se: 0x00 003 000 , da ta- base : 0 x00 BB79 44
ROM : Bo ots tra p pr ogra m i s C 2960 bo ot l oad er
BOO TLDR : C 296 0 Bo ot L oad er (C29 60- HBOO T-M ) V ersi on 12.2 (25 r)SE E1, RE LEAS E S OFTW ARE (fc 1)
Swit ch upti me is 24 m inu tes
Sys tem ret urn ed t o RO M b y p ower -on
Sys tem ima ge file is "fl ash :c29 60- lanb ase k9- mz.1 22- 25.S EE2 /c29 60- lan base k9- mz.1 2225. SEE2 .bi n"
cisc o W S-C2 960 -24 TT-L (P ower PC4 05) pro cess or (rev isi on B0) wit h 61 440 K/40 88K by tes of
memo ry.
Pro cess or boa rd I D FO C10 52W 3XC
Las t re set fr om p ower -on
1 V irtu al Eth erne t in ter fac e
24 Fast Eth ern et i nter fac es
2 G igab it Eth erne t in ter fac es
The pas swo rd- reco very me cha nism is ena ble d.
! T ext omi tte d
Swi tch#
200 7 Cisco Syst ems , Inc. .
ICND1 v1 .02- 13
.
,
.
Cisco IOS 12.2(25)SEE2.
Switch uptime
,
.
24 .
Switch platform
,
.
2-72
show interfaces
Swit chX #sho w i nter fac es F ast Eth erne t0/2
Fast Eth erne t0/ 2 is up , li ne pro toco l is up (c onne cte d)
Hard
Fa st Et
Ethe
rne
t, ad
a ddr
ess
is 00
0008
45.c
ia 0
008
.a44
e82)
Ha
rdwwar
aree is Fast
hern
et,
dres
s is
08..a4
a445
.cee82
82 ((b
bia
000
8.a
4455.c
.ce8
2)
MT U 1 500 byt es, BW 1000 0 K bit , DL Y 10 00 use c,
re liab ili ty 2 55/ 255, tx loa d 1/ 255, rx loa d 1/ 255
En cap sula tio n AR PA, loo pba ck not set
Ke epa live se t (1 0 s ec)
Half
plex
1 0Mb
/s
Ha
lf--du
dupl
ex,, 10M
b/s
in put flo w-c ontr ol is u nsu ppo rted out put fl ow-c ont rol is unsu ppo rte d
AR P t ype: AR PA, ARP Tim eou t 0 4:00 :00
La st inpu t 4 w6d, ou tput 00 :00 :01, out put ha ng n eve r
La st clea rin g of "s how int erf ace" cou nte rs neve r
In put que ue: 0/7 5/0 /0 ( siz e/m ax/d rops /fl ush es); To tal out put dro ps: 0
Qu eue ing str ateg y: fifo
Ou tpu t qu eue : 0/ 40 (siz e/m ax)
5 min ute inp ut r ate 0 b its /se c, 0 pac ket s/s ec
5 min ute out put rat e 0 bit s/s ec, 0 pa cke ts/ sec
18 2979 pa cket s i nput , 1 680 2150 byt es, 0 no b uff er
Re ceiv ed 4995 4 b road cas ts (0 m ulti cas t)
0 runt s, 0 gi ant s, 0 th rot tles
CRCC,
, 0 f rame , 0 ove rru n, 8 ig nore d
0 inpu t e rror s, 00 CR
0 watc hdo g, 2 011 5 mu lti cas t, 0 pau se inp ut
0 inpu t p acke ts with dr ibb le c ondi tio n d etec ted
37 4747 3 p acke ts outp ut, 35 3656 347 byt es, 0 u nde rrun s
--M ore - 200 7 Cisco Syst ems , Inc. .
ICND1 v1 .02- 14
show interfaces
. ,
.
FastEthernet0/2 is up
.
.
,
.
address is
0008.a445.ce82
-,
.
Half-duplex, 10 Mb/s
. : full duplex,
100 Mb/s.
CRC
, 0
.
Ethernet .
show interfaces
.
Ethernet
2-73
-
-.
MAC-
Catalyst 2960 Series
SwitchX#show mac-address-table
Mac Address Table
------------------------------------------Vlan
Mac Address
Type
Ports
------------------------All
0008.a445.9b40
STATIC
CPU
All
0100.0ccc.cccc
STATIC
CPU
All
0100.0ccc.cccd
STATIC
CPU
All
0100.0cdd.dddd
STATIC
CPU
1
0008.e3e8.0440
DYNAMIC
Fa0/2
Total Mac Addresses for this criterion: 5
SwitchX#
ICND1 v1 .02- 15
- .
MAC- , .
-
, , .
, - ,
, -
-. ,
-,
, .
.
.
-
. , Catalyst 2960 8 192
-. - ,
.
2-74
, .
Cisco IOS
,
Cisco IOS .
Cisco IOS
,
,
,
.
Cisco Catalyst POST
.
POST
, .
POST ,
.
ICND1 v1 .02- 16
(.)
Cisco IOS
EXEC.
.
Catalyst IOS
,
.
IP-,
Cisco IOS .
Catalyst,
show version, show
running-config show interfaces.
ICND1 v1 .02- 17
Ethernet
2-75
2-76
VTY. ,
.
Cisco. , :
, ,
, ,
Cisco;
Telnet SSH ;
,
.
. ,
, ,
, ,
Cisco.
,
.
2-78
.
.
. ,
( )
( ).
. ,
( ),
() .
.
( ),
, ,
..
(CLI)
.
.
. ,
, .
,
.
.
,
, EXEC.
.
Telnet VTY.
,
Telnet.
0 15.
line console 0 password login,
VTY.
VTY.
line vty 0 4 password login
Telnet.
2007 Cisco Systems, Inc.
Ethernet
2-79
login local
,
username. username
.
enable password
EXEC.
enable secret.
enable secret
. enable secret ,
, .
,
, TFTP-.
Cisco .
, service password-encryption
.
, service
password-encryption, .
, no . ,
no service password-encryption,
.
2-80
.
, .
,
SwitchX# banner login " Access for authorized users only. Please enter your
username and password. "
banner login
,
. , no
.
banner login
- . (").
-.
, .
, ,
.
Ethernet
2-81
Telnet SSH
.
Telnet SSH
Telnet
SSH
! T he user nam e c omma nd crea te the use rna me a nd p ass wor d fo r t he S SH sess ion
User nam e ci sco pa sswo rd cis co
ip d oma in-n ame my doma in. com
cryp to key gen era te r sa
ip s sh vers ion 2
line vt y 0 4
l ogi n lo cal
t ran spor t i npu t ss h
Telnet .
Telnet ,
. SSH Telnet,
.
SSHv1, SSHv2.
SSHv2,
.
SSH, ,
.
, (AAA) TACACS +
RADIUS. (
SSH.) ,
Telnet
cisco cisco.
!--- The username command create the username and password for
the SSH session
username cisco password 0 cisco
ip domain-name mydomain.com
crypto key generate rsa
ip ssh version 2
line vty 0 4
login local
transport input telnet
2-82
SSH,
SSH.
SSH PC UNIX.
, SSH,
transport input ssh ,
SSH. Telnet-
( SSH) .
line vty 0 4
, ,
( SSH) Telnet
.
Ethernet
2-83
Cisco Catalyst 2960
SwitchX(config-if)#switchport port-security [ mac-address
mac-address | mac-address sticky [mac-address] | maximum
value | violation {restrict | shutdown}]
SwitchX(config)#interface fa0/5
SwitchX(config-if)#switchport mode access
SwitchX(config-if)#switchport port-security
SwitchX(config-if)#switchport port-security maximum 1
SwitchX(config-if)#switchport port-security mac-address sticky
SwitchX(config-if)#switchport port-security violation shutdown
,
-
, . ,
, .
, ,
switchport mode access.
,
-,
. :
(switchport port-security mac-address
0008.eeee.eeee).
2-84
-
-
, sticky learning. sticky
learning, switchport port-security
mac-address sticky. ,
- , ,
sticky learning,
-.
-
( ).
- ,
.
, - .
sticky learning , -
.
1 132 .
, 1 024.
:
-,
, - ,
.
, ,
VLAN.
Ethernet
2-85
Catalyst 2960
SwitchX#show port-security [ interface ]
[address] [ | {begin | exclude | include} expression]
SwitchX#show port-security
Port Security
Port Status
Violation Mode
Aging Time
Aging Type
SecureStatic Address Aging
Maximum MAC Addresses
Total MAC Addresses
Configured MAC Addresses
Sticky MAC Addresses
Last Source Address
Security Violation Count
2-86
interface
()
.
address
() .
begin
() ,
, .
exclude
() , ,
, .
include
() , ,
, .
expression
,
.
Catalyst 2960 (.)
SwitchX#sh port-security address
Secure Mac Address Table
------------------------------------------------------------------Vlan
Mac Address
Type
Ports
Remaining Age
(mins)
--------------------------------1
0008.dddd.eeee
SecureConfigured
Fa0/5
------------------------------------------------------------------Total Addresses in System (excluding one mac per port)
: 0
Max Addresses limit in System (excluding one mac per port) : 1024
SwitchX#sh port-security
Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action
(Count)
(Count)
(Count)
-------------------------------------------------------------------------Fa0/5
1
1
0
Shutdown
--------------------------------------------------------------------------Total Addresses in System (excluding one mac per port)
: 0
Max Addresses limit in System (excluding one mac per port) : 1024
Ethernet
2-87
.
, ,
.
().
.
.
, , .
. ,
(), .
2-88
()
SwitchX(config-int)#
shutdown
, shutdown
.
, no
.
ICND1 v1 .02- 10
, shutdown
. ,
no : no shutdown.
Ethernet
2-89
,
.
.
,
.
.
Telnet
; SSH .
MAC-, .
.
2-90
ICND1 v1 .02- 11
,
.
Ethernet
.
,
,
Spanning Tree.
Ethernet.
, :
c Ethernet;
,
Ethernet;
, STP -
Ethernet.
,
, .
.
.
,
.
,
.
:
,
. ,
, ,
. ,
,
, ().
,
, . ,
,
,
.
2-92
,
.
.
,
.
(CSMA/CD)
-
200 7 Cisco Syst ems , Inc. .
Ethernet CSMA/CD.
.
Ethernet
.
Ethernet -, Fast
Ethernet Gigabit Ethernet. . ,
, ,
5
3. .
-
, . ,
, ,
, .
Ethernet, Fast Ethernet Gigabit Ethernet
.
.
Ethernet
2-93
, ,
, ,
.
Ethernet
50 60% 10 /. Ethernet
100- (
10 /).
,
-.
,
. ,
, ,
.
, ,
.
.
:
, ,
. , ,
.
:
, .
Cisco Catalyst 2960
SwitchX(config)#interface Gi0/1
SwitchX(config-if)#duplex {auto | full | half}
2-94
.
duplex,
.
Cisco Catalyst 2960:
auto ;
,
;
full ;
half .
Sw itch X#s how int erfa ces fas tet her net0 /2
Fa stEt her net0 /2 is u p, line pr oto col is up ( con nect ed)
Hard war e is Fa st E the rnet , a ddr ess is 0008 .a4 45.9 b42 (bi a 0 008 .a44 5.9b 42)
MTU 150 0 by tes , BW 10 000 Kbi t, DLY 100 0 us ec,
r eli abil ity 255 /25 5, t xlo ad 1/25 5, rxlo ad 1/25 5
Enca psu lati on ARPA , l oopb ack no t se t
Keep ali ve s et (10 sec )
Half -du plex , 1 0Mb/ s
inpu t f low- con trol is uns upp ort ed o utp ut f low -con tro l is un sup port ed
ARP typ e: A RPA , AR P T imeo ut 04: 00:0 0
Last in put 00: 00:5 7, outp ut 00: 00:0 1, outp ut hang ne ver
Last cl eari ng of " sho w in ter fac e" c oun ters ne ver
Inpu t q ueue : 0 /75/ 0/0 (si ze/ max /dro ps/ flus hes ); T ota l ou tpu t d rops : 0
Queu ein g st rat egy: fi fo
Outp ut queu e: 0/40 (s ize/ max )
5 mi nut e in put rat e 0 bit s/s ec, 0 p ack ets/ sec
5 mi nut e ou tpu t ra te 0 bi ts/ sec , 0 pac kets /se c
3 234 79 p ack ets inp ut, 449 310 71 b yte s, 0 no buf fer
R ece ived 98 960 bro adca sts (0 mul tic ast)
1 ru nts, 0 gian ts, 0 t hro ttl es
1 in put err ors, 0 CRC, 0 fra me, 0 o verr un, 0 i gno red
0 wa tchd og, 363 74 mult ica st, 0 p aus e in put
0 in put pac kets wi th d rib ble con dit ion det ecte d
1 284 934 pac kets ou tput , 1 031 2170 7 b ytes , 0 und err uns
0 ou tput er rors , 2 col lis ion s, 6 in terf ace res ets
0 ba bble s, 0 la te coll isi on, 29 def erre d
0 lo st c arr ier, 0 no c arr ier , 0 PAU SE o utp ut
0 ou tput bu ffer fa ilur es, 0 outp ut buff ers swa ppe d ou t
Ethernet
2-95
:
show interfaces
Catalyst 2960. show interfaces
EXEC .
.
. ,
, Catalyst
. ,
.
,
. ,
.
. ,
.
,
, (FCS)
.
FCS show interfaces.
2-96
,
, .
,
.
Ethernet
2-97
Ethernet
,
.
,
.
.
,
.
.
.
, ,
.
, .
, ,
. , -
, .
,
.
, ,
,
. ,
.
2-98
:
, London Rome. London
A, Rome B.
.
, .
1 , ,
2 3. 2, 3 London (
1) , London 1 2 .
4.
4 London: 2
3. , 2
. 4 , 3.
4 Rome, 2
Rome 3. 3 4,
4 , London
4. Rome 2.
2 3 ,
London 3 4 . London
, ,
. .
Ethernet
2-99
STP
STP ,
. STP.
STP
STP,
. STP
, .
Catalyst STP .
STP :
STP ,
, .
.
, STP
( ).
2-100
, .
.
,
.
c
.
Ethernet
( , );
.
.
Ethernet, ,
, Fast
Ethernet Gigabit Ethernet
.
200 7 Cisco Syst ems , Inc. .
(.)
, ,
,
.
, ,
MAC-.
STP,
.
STP Ethernet
.
ICND1 v1 .02- 10
Ethernet
2-101
2-102
.
, .
. ; , ,
,
. .
. , :
2 OSI
.
1 2.
3
.
1 (OSI),
. 2
OSI, -. ,
, 1 2. 3
, IP
.
2-104
3
.
:
.
.
.
.
. ,
. ,
:
, 3,
,
;
, 5,
;
RJ-45,
;
,
, .
Ethernet
2-105
show interface
Swit chX #sho w i nter fac e fa ste the rnet 0/ 0
Fas teth
/0 is
pr oto
Ethe
rne tern
0 et
is 0up,
linuep,prlin
otoecol
is col
up is up [1]
Hard war e is MC I Et her net, ad dre ss i s a a00. 040 0.01 34 (vi a 00 00.0 c00 .43 69
Inte rne t ad dre ss i s 1 31.1 08. 1.1 , su bne t ma sk is 2 55. 255 .255 .0
.
.
O utpu t Om itt ed
.
.
2295 197 pac ket s in put , 30 553 999 2 by tes , 0 no buff er
Rece ive d 19 255 00 b roa dcas ts, 0 runt s, 0 gi ant s
input
put err
errors
ors,, 33 CRC
CRC,, 00 fra
frame,
me, 00 oover
verrun,
run, 00 igno
ignored
red,, 00 abo
abort
rt [ 2]
33 in
0 in put pac ket s wi th drib ble co ndit ion det ect ed
3594 664 pac ket s ou tpu t, 4 365 498 43 b yte s, 0 un derr uns
88 ou
outpu
tputt er
error
rors,
s, [ 3]
1790
1790 co
collis
llision
ions,
s, [ 4]
10 i nte rfac e r eset s,
00 re
sta
rtss [ 5]
res
tart
.
.
show interface.
, .
2-106
,
.
disabled,
5 000 Keepalive,
10 .
down administratively down, ,
,
( Keepalive ),
.
(CRC)
,
, ,
,
, , ,
.
,
.
,
- ,
.
, -
Ethernet. -
. , Ethernet
.
Ethernet - .
:
EXEC show interface,
Ethernet- .
CRC,
.
.
100Base-TX, ,
5.
, ,
.
100Base-TX, ,
5.
Ethernet
2-107
:
show interface,
.
0,1% .
TDR
Ethernet. TDR ,
,
.
, .
.
, ,
,
() .
200 7 Cisco Syst ems , Inc. .
, ,
.
2-108
show interface,
.
0,1% .
, ,
, ()
. ,
.
.
:
.
Ethernet. ,
, Ethernet
.
.
.
, ,
.
.
Ethernet.
, , Ethernet
.
.
.
Ethernet
2-109
(,
: ).
.
.
.
2-110
:
,
, .
,
:
,
.
.
,
:
,
.
;
.
:
,
.
: Gigabit Ethernet
, 10/100
.
:
,
.
;
.
200 7 Cisco Syst ems , Inc. .
show interface, .
:
,
.
,
.
,
.
.
:
,
.
200 7 Cisco Syst ems , Inc. .
ICND1 v1 .02- 10
show interface, .
Ethernet
2-111
, , .
TFTP-
.
,
.
.
copy running-config start-config
.
.
VTY .
EXEC .
200 7 Cisco Syst ems , Inc. .
ICND1 v1 .02- 11
,
. , . ,
, : PC
TFTP-.
, , ,
, ,
.
, , ,
. ,
VTY . ,
EXEC.
2-112
, .
.
show interface:
.
ICND1 v1 .02- 12
Ethernet
2-113
2-114
, .
Ethernet
, ,
,
Ethernet .
.
,
Ethernet:
, .
Ethernet,
.
,
STP.
(.)
Cisco IOS
,
.
Cisco Catalyst
,
Cisco IOS .
,
,
IP-.
show interface.
Ethernet
2-115
, , .
.
1)
? (
.) (:
)
)
)
)
)
)
2)
? (
.) (:
)
)
)
)
)
)
)
3)
? ( .)
(:
)
)
)
)
)
)
2-116
,
,
? (:
)
)
)
)
)
5)
,
.
.
,
,
.
.
.
.
? (:
)
)
)
)
)
4)
Ethernet.
.
.
.
.
)
6)
. ( .) (:
)
)
)
)
)
)
)
7)
, .
MAC-.
, .
.
.
2 OSI.
? (
.) (:
)
)
)
)
)
)
8)
, ,
. (:
)
_____ 1.
, -
, ,
.
_____ 2.
, -
,
.
_____ 3.
)
)
)
9)
,
, , .
? ( .)
(:
)
)
)
)
)
)
-, ,
Ethernet
2-117
10)
? (
.) (:
)
)
)
)
)
)
11)
? ( .) (:
)
)
)
)
)
)
)
12)
, .
, .
.
.
.
.
? ( .)
(: )
)
)
)
)
)
)
13)
-, ,
.
.
.
.
.
.
. (: )
_____ 1.
,
.
_____ 2.
_____ 3. .
)
)
2-118
14)
Ethernet.
(: )
_____ 1.
,
,
100 M/
_____ 2.
;
;
_____ 3.
_____ 4.
_____ 5.
_____ 6.
)
)
)
15)
Cisco ,
? (: Cisco IOS)
)
)
)
)
16)
-
RAM
POST
TFTP
Catalyst Cisco
? (: Cisco IOS)
)
)
)
)
17)
Ethernet 10BASE-T
Fast Ethernet
Gigabit Ethernet
.
.
.
.
Cisco
, , _____. (:
Cisco IOS)
)
)
)
)
CD-ROM
TFTP-
Ethernet
2-119
18)
,
_____
. (: Cisco IOS)
)
)
)
)
19)
,
?
(: Cisco IOS)
)
)
)
)
20)
hostname#
hostname>
hostname-exec>
hostname-config
EXEC,
? (:
Cisco IOS)
)
)
)
)
2-120
Send.
Enter.
.
5 .
CLI
EXEC? (:
Cisco IOS)
)
)
)
)
22)
EXEC
EXEC
enable EXEC
EXEC
Cisco
? (: Cisco IOS)
)
)
)
)
21)
?
init
help
login
23)
Catalyst
. (: )
_____ 1.
_____ 2.
_____ 3. 3
)
.
)
,
Cisco IOS .
)
, ,
,
.
24)
Catalyst 2950? (: )
)
)
)
)
25)
POST Catalyst ,
? (: )
)
)
)
)
26)
?
?
help c
help c*
,
,
, config? (: )
)
)
)
)
28)
>
EXEC
,
,
Catalyst,
c? (: )
)
)
)
)
27)
./..
.
.
.
onfig?
onfig ?
help config
help config*
ip address
ip address 196.125.243.10
196.125.243.10 ip address
ip address 196.125.243.10 255.255.255.0
Ethernet
2-121
29)
? (: )
)
)
)
)
30)
show interface,
, Catalyst,
-, ?
(: )
)
)
)
)
31)
)
)
, .
, ,
.
, .
, .
? (
.) (: )
)
)
)
)
)
2-122
Reset.
.
- .
.
? (
.) (: )
)
)
34)
show ip
show version
show running
show interfaces
Cisco? (: )
)
)
)
)
33)
show EXEC?
(: )
)
)
)
)
32)
VTY
TTY
Exec
35)
,
?
(: )
)
)
)
)
)
36)
?
(: )
)
)
)
)
)
37)
shutdown
port security
mac-secure
firewall
Cisco IOS
? (:
)
)
)
)
)
40)
Cisco IOS
-? (:
)
)
)
)
)
39)
HTTP
Telnet
SSH
RMON
SNMP
Cisco IOS
VTY? (: )
)
)
)
)
38)
shutdown
port security
mac-secure
firewall
?
(: )
)
)
)
)
Ethernet
2-123
41)
? (: )
)
)
)
)
42)
STP? (:
)
)
)
)
)
43)
show controller
show run
show interface
show counters
?
( .) (: ,
)
)
)
)
)
2-124
show controller
show run
show interface
show counters
Cisco IOS ?
(: , )
)
)
)
)
45)
STP ,
.
STP .
STP .
STP ,
.
Cisco IOS
? (: , )
)
)
)
)
44)
, .
,
.
-, .
.
.
.
.
.
1)
2)
3)
4)
5)
6)
7)
8)
9)
10)
11)
12)
13)
14)
15)
16)
17)
18)
19)
20)
21)
22)
23)
24)
25)
26)
27)
28)
29)
30)
31)
32)
33)
34)
35)
36)
37)
38)
39)
40)
41)
A,
A, ,
A, ,
, ,
A,
1 = , 2 = , 3 = A
A, ,
A, ,
A, ,
, ,
1 = , 2 = A, 3 = A
1 = , 2 = , 3 = , 4 = , 5 = A, 6 =
A
A
A, ,
A
A
,
A, , ,
Ethernet
2-125
42)
43)
44)
45)
2-126
, ,
.
, () ()
,
. ,
,
, -.
. , :
- ,
;
, .
3-2
,
,
.
,
. ,
.
,
, , .
, :
-
(WLAN);
,
;
,
;
,
FCC ITU-R ;
IEEE 802.11;
Wi-Fi.
-
-
.
ICND1 v1.03-2
.
, .
.
,
- ()
.
.
.
(DSL) ,
. 2005
, .
. .
,
.
375 . ,
15 .
, ,
.
3-4
,
, .
, .
,
.
.
, .
OSI.
WLAN CSMA/CA,
CSMA/CD.
() .
, .
:
,
,
Ethernet
.
.
2007 Cisco Systems, Inc. .
ICND1 v1.03-3
.
(CSMA/CA)
(CSMA/CD), .
,
, ,
.
(RTS Ready to Send)
(CTS Clear to Send), .
Ethernet
.
2007 Cisco Systems, Inc.
3-5
2-
.
, .
-
, -, , ,
, -
.
- ,
.
, Ethernet.
, .
-.
.
-,
.
.
3-6
-
AM ,
.
, .
,
.
,
, .
ICND1 v1.03-4
,
.
(, ) (,
).
.
.
: ,
(, ).
: ,
(, )
.
: ,
(, ).
.
,
/ .
.
4 .
.
.
3-7
3-8
- .
.
,
(WLAN).
, .
,
ITU-R:
IEEE:
802.11
Wi-Fi Alliance:
ICND1 v1.03-5
. 900-
ISM ( ,
) 1985
. ,
.
.
(FCC) (http://www.fcc.gov)
(ETSI) (http://www.etsi.org).
(IEEE). IEEE 802.11
802.
- IEEE (http://standards.ieee.org/getieee802).
Wi-Fi Alliance
802.11 .
.
. - 802.11
(WPA), ,
2003 . 2004 .
IEEE 802.11i, 2004 .
Wi-Fi Alliance
.
- (http://www.wi-fi.org).
2007 Cisco Systems, Inc.
3-9
,
ITU-R FCC
- .
,
, ITU-R FCC.
ITU-R FCC
ISM:
,
ICND1 v1.03-6
900 : 902928 .
2,4 : 2,4002,483 (
2,495 ).
5 : 51505350 , 57255825 ,
53505725 .
IEEE 802.11a,
. , 802.11a,
.
,
.
, ,
(NPCS).
3-10
, ,
ISM.
. -
. , 2,4
, , Bluetooth,
.
, .
, .
, ,
( ),
, .
(EIRP) ,
.
,
,
. ,
.
= +
,
.
,
.
3-11
802.11
IEEE 802.11.
IEEE 802.11
802.11b
802.11a
802.11g
2,4
2,4
23
(DSSS)
(OFDM)
(DSSS)
(OFDM)
(/)
1, 2, 5.5, 11
6, 9, 12, 18,
24, 36, 48, 54
ICND1 v1.03-7
IEEE MAC
OSI. 802.11
1997 . 1999 . IEEE
802.11a/b, 2003 .
IEEE 802.11g.
OSI. IEEE 802.11b
DSSS ( ).
DSSS ,
, .
IEEE 802.11 ISM 2,4- 14 ,
,
FCC, , 111 . ISM
2,4- 22 5 ,
.
, . ,
11 , FCC, :
1, 6 11.
, ,
.
IEEE 802.11b
ISM 2,4-
3-12
.
802.11b DSSS
CCK (Complementary Code Keying)
- 5,5 11 /,
1 2 /. 802.11b
ISM 2,4-,
802.11, 802.11
1 2 /.
802.11b IEEE ,
802.11a.
OFDM ( )
, UNII 5 .
ISM 2,4-
, Bluetooth, , ,
. ,
. 802.11a
, ,
802.11a, ,
.
802.11b.
IEEE
802.11 MAC ISM
2,4 . IEEE 802.11g , 802.11a,
OFDM ,
802.11b DSSS,
ISM. DSSS 1, 2, 5,5
11 /, OFDM 6, 9, 12, 18, 24, 48
54 /. IEEE
6, 12 24 / ,
802.11a 802.11g OFDM.
3-13
Wi-Fi
802.11
802.11. ,
Wi-Fi .
Wi-Fi
Wi-Fi Alliance
.
802.11a,
802.11b, 802.11g,
.
.
ICND1 v1.03-8
Wi-Fi Alliance
,
.
Wi-Fi Alliance
802.11, , .
. - IEEE 802.1,
IEEE,
. Wi-Fi Alliance
IEEE 802.11i
(WPA),
WPA2 IEEE 802.11i.
3-14
,
.
.
.
CSMA.
, .
.
,
.
802.11 IEEE.
ICND1 v1.03-9
(.)
, ITU-R
FCC, .
802.11 ,
.
Wi-Fi Alliance
802.11.
ICND1 v1.03-10
3-15
3-16
.
(WLAN)
.
, ,
.
.
,
. , :
, IEEE 802.1X
;
IEEE 802.11b/g ,
.
IEEE 802.11 (Wired Equivalent
Privacy, WEP).
,
.
.
( )
.
802.11b/g
802.11b/g .
.
WEP,
. WEP- (, , )
3-16
, ,
.
,
,
, (DoS).
WEP-,
.
, MAC-
( , ),
, , .
,
. ,
,
, .
3-17
(IPS)
.
.
.
,
.
, .
(IDS)
(IPS) .
.
,
, .
,
IPS. IPS
,
. IPS
,
,
.
3-18
.
.
.
WLAN
1997
2001
2003
2004
.
WEP
802.1x EAP
WPA
802.11i / WPA2
,
WE P
MA C-
S SID
802 .1 X E AP
(LE AP, PEAP )
( ,
L EAP , PEA P,
E AP-FAS T)
AES
RADIUS
.
802.11 64-
WEP- , .
64- 40- 24-
. , ,
, . ,
.
, (SSID) MAC.
SSID ,
.
SSID,
, SSID,
.
SSID ( SSID), . ,
, .
SSID ,
802.11 (
SSID),
2007 Cisco Systems, Inc.
3-19
SSID. , ,
, ,
. MAC. ,
.
MAC- , MAC-
.
802.11
,
,
. , Cisco
WEP-, RC4. WEP-
Cisco
Temporal Key Integrity Protocol (TKIP)
Cisco (Cisco MIC). , Cisco
802.1X
Cisco Lightweight Extensible Authentication Protocol (Cisco LEAP)
.
Cisco Wi-Fi
WPA .
IEEE 802.11i
,
802.1X WEP-. TKIP
,
Cisco KIP MIC, .
802.11i (AES)
WEP .
IDS
. Wi-Fi Alliance
802.11i
WPA2.
3-20
-,
SSID,
.
.
-
.
.
-
().
SSID, MAC-
,
.
200 7 Cisco Syst ems , Inc. .
-,
SSID,
. -
. .
, ,
( ).
SSID, MAC-
, .
. ,
, 802.11
.
( ).
( )
,
. 802.11 :
.
,
.
WEP-,
.
.
3-21
802.1X
, IEEE 802.1X
.
802.1X
, ,
.
802.1X
. , . .
.
RADIUS-
.
, ,
.
,
.
3-22
WPA WPA2
(WPA).
WPA WPA2
WPA
:
IEEE 802.1X/EAP
WPA2
:
IEEE 802.1X/EAP
(, , :
)
TKIP/MIC
:
AES-CCMP
:
PSK
(
:
PSK
,
)
:
TKIP/MIC
:
AES-CCMP
WPA 802.1X
(PSK). ( 802.1X
.) WPA
TKIP. TKIP
(MIC) (PPK)
.
WPA WPA2 ,
AES-Counter CBC MAC (AES-CCMP).
, ,
PSK 802.1X/EAP.
802.1X ,
(AAA) ( RADIUS
,
). .
, ,
PSK.
.
PSK
, .
.
.
2007 Cisco Systems, Inc.
3-23
, .
.
.
.
WEP
802.1x EAP
WPA
802.11i/WPA2
-,
SSID, .
(.)
,
,
.
WPA IEEE
802.1X PSK.
,
,
PSK 802.1X/EAP.
,
,
PSK.
3-24
.
, . , ,
,
.
,
. ,
:
IEEE 802.11;
BSA;
,
;
-
;
802.11
802.11.
802.11
Ad hoc.
(IBSS)
.
.
(BSS)
.
(ESS).
BS S.
802.11 (),
.
3-26
Ad hoc. Ad hoc
(IBSS).
. , Windows,
.
( )
,
. .
. .
.
.
.
.
(BSS). , BSS,
,
.
(BSSID) MAC-
2- BSS. BSS
, BSS
BSSID,
(SSID),
. SSID
,
32 .
(ESS).
,
.
ESS SSID,
.
802.11,
, ,
, .
3-27
BSA
(BSA)
(ESA) .
BSA
(BSA)
-, BSS.
, ,
,
. . BSS
, BSA
.
Ethernet
.
, .
;
. -
SSID .
-
SSID. -
, . SSID
.
. SSID
( SSID),
SSID - .
,
Wireless Zero Configuration (WZC)
.
. SSID
, ,
SSID -.
3-28
ESA
,
.
(ESA).
,
1015 %,
-.
1520 %.
.
3-29
.
.
802.11b
. ,
11 /, 5,5 /,
2 /, 1 /.
. ,
,
.
.
.
. IEEE 802.11b,
802.11a 802.11g.
3-30
,
.
:
IP- ( DHCP),
( 802.11g, 802.11a/b/g, 802.11a)
1,6 11,
:
(SSID)
WPA WPA2 PSK
TKIP AES,
200 7 Cisco Syst ems , Inc. .
(CLI) , ,
.
.
SSID,
- ,
(),
. ,
(NIC)
(, IEEE 802.11b/g
5 ), -, , ,
SSID,
SSID. 802.11
plug-and-play.
(PSK)
(WEP WPA )
, .
,
(ISM 2,4 UNII 5 )
IEEE 802.11a/b/g. , ,
, ,
IEEE, .
3-31
802.11b 802.11g
,
/ (RTS/CTS).
,
IEEE , .
DHCP-.
DHCP- IP- ,
. DHCP-
IP-
. - ,
IP- DHCP
.
, ,
.
3-32
1:
DHCP ISP.
2: .
3: SSID , .
4:
.
5: .
6:
WPA PSK.
7: .
200 7 Cisco Syst ems , Inc. .
(
) .
.
. , IP-
DHCP- -
, . ,
WPA. WEP
, WPA.
3-33
-
.
Wireless Zero Configuration (WZC):
Windows XP
PSK
,
-
.
USB-
,
.
.
. Microsoft Windows
(WZC),
plug-and-play.
SSID
, , WEP WPA.
WZC .
, .
2000 Cisco
. 95 %
Cisco.
-
http://www.cisco.com. .
3-34
v1
v2
WPA,
v3
v4
(CAC),
v5
(Management
Frame Protection),
(IPS)
, Cisco
, ,
Cisco Secure Services Client,
.
.
.
http://www.cisco.com/go/ciscocompatible/wireless.
3-35
:
,
.
. 1,
6 11.
,
.
:
-
200 7 Cisco Syst ems , Inc. .
,
.
:
SSID
( SSID),
( );
(EAP PSK) (TKIP AES).
, :
3-36
-
(ISM 2,4 UNII 5 )?
( 6 )?
,
?
.
.
,
PSK.
-
( , , ).
.
,
,
.
ICND1 v1 .03- 10
.
, .
. , , Ethernet,
DHCP- .
,
.
.
.
.
, ,
. .
, .
,
SSID, -. ,
. 2,4
(, 5 ), , .
, 2,4 .
, ,
- . ,
,
, .
- 11,
-.
-, , ,
(FHSS),
. ,
, , .
, ,
.
2007 Cisco Systems, Inc.
3-37
,
.
802.11
ad hoc
.
. ,
(BSS)
(ESS).
BSS
(BSA)
(ESA).
ICND1 v1 .03- 11
(.)
(CLI) ,
,
.
( )
.
-
.
Wireless Zero Configuration
Cisco Compatible Extensions
Cisco Secure Services Client
.
WLAN ,
.
200 7 Cisco Syst ems , Inc. .
3-38
ICND1 v1 .03- 12
, .
802.11
,
.
,
802.1x WPA.
,
-.
3-39
, , .
.
B1
?
(: )
)
)
)
)
B2
?
(: )
)
)
)
)
B3
CSMA/CA (
)
CSMA/CA (
)
CSMA/CR (
)
CSMA/CW (
)
, ,
. (: )
_____ 1.
_____ 2.
_____ 3.
)
)
)
B4
801.11,
? (: )
)
)
)
)
B5
Wi-Fi Alliance
IEEE
EMA
WISC
802.11
? (: )
)
)
)
)
3-40
Wi-Fi
IEEE
EMA
WISC
B6
B7
B8
B9
B10
B11
? ( .) (: )
)
2,4
)
900
)
2,4
)
5
)
900
802.11
? ( .) (: )
)
802.11
)
802,11a
)
802.11b
)
802.11d
)
802.11g
802.11 5 ? (:
)
)
802.11
)
802,11a
)
802.11b
)
802.11d
)
802.11g
Wi-Fi Alliance ? (:
)
)
,
.
)
.
)
,
.
)
,
.
? (:
)
)
WEP
)
, SSID
)
,
)
, ,
SSID
? ( .) (:
)
)
)
,
)
,
)
3-41
B12
? (: )
)
EAP
)
WEP
)
WPA
)
802.11i/WPA2
B13
,
? (: )
)
SSID
)
SSID
)
, SSID
)
B14
802.1X? (:
)
)
,
.
)
,
.
)
802.1X
.
)
802.1X
. .
B15
WPA WPA2 ? (:
)
)
WPA , WPA 2 PSK.
)
WPA EAP, WPA 2 802.11X.
)
WPA , WPA 2 .
)
WPA TKIP/MIC, WPA 2
AES-CCMP.
B16
802.11 . (:
)
_____ 1.
_____ 2.
_____ 3.
)
)
)
B17
3-42
,
.
Ad hoc
(BSS)
(ESS)
? (:
)
)
)
)
ad hoc
)
B18
? (: )
)
)
)
)
B19
?
(: )
)
)
)
)
B20
SSID
WEP ?
(: )
)
)
)
)
B22
? ( .) (:
)
)
)
)
)
)
B21
510 %
1015 %
1520 %
2530 %
AAA-
, WEP
802.11x
WPA
. (:
)
_____ 1.
_____ 2.
Windows
_____ 3.
)
)
)
,
WZC
Cisco Compatible Extensions
Cisco Secure Services Client
3-43
3-44
B1
B2
B3
1 = , 2 = A, 3 = B
B4
B5
B6
, B,
B7
B8
B9
B10
B11
A, ,
B12
B13
B14
B15
B16
1 = A, 2 = , 3 = B
B17
B18
B19
B20
A, ,
B21
B22
1 = B, 2 = A, 3 =