Вы находитесь на странице: 1из 6

Encapsulaciones WAN

-------------------------encapsulation hdlc
encapsulation ppp
encapsulation frame-relay
-------------------------PPP con autentacin PAP
-------------------------------------------------------------------------username [nombre del router al otro extremo] password [contrasea]
interface s0/0/0
encapsulation ppp
ppp authentication pap
ppp pap sent-username [nombre del propio router] password [contrasea]
-------------------------------------------------------------------------PPP con autentacin CHAP
-------------------------------------------------------------------------username [nombre del router al otro extremo] password [contrasea]
username [nombre del router al otro extremo] secret [contrasea]
interface s0/0/0
encapsulation ppp
ppp authentication chap
-------------------------------------------------------------------------FRAME-RELAY
-------------------------------------------------------------------------frame-relay switching
interface serial 0/0/0
clock rate 64000
encapsulation frame-relay
frame-relay intf-type dce
frame-relay route [DLCI] interface serial 0/0/1 [DLCI]
interface serial 0/0/0
encapsulation frame-relay
no frame-relay inverse-arp
frame-relay map ip [direccin IP] [DLCI] broadcast [ietf | cisco]
frame-relay interface-dlci [DLCI]
frame-relay lmi-type [ ansi | cisco | q933a ]
show
show
show
show

frame-relay
frame-relay
frame-relay
frame-relay

map
lmi
pvc
route

-------------------------------------------------------------------------SSH

-------------------------------------------------------------------------hostname [nombre del router]


ip domain-name [nombre de dominio]
crypto key generate rsa
ip ssh time-out 15
ip ssh authentication-retries 2
username [usuario] secret [contrasea]
line vty 0 4
transport input ssh
login local
------------------------------------------------------------------------Autenticacin de RIP
------------------------------------------------------------------------key chain [nombre de llave]
key [nmero de llave]
key-string [llave]
interface s0/0/0
ip rip authentication mode md5
ip rip authentication key-chain [nombre de llave]
------------------------------------------------------------------------Autenticacin de EIGRP
------------------------------------------------------------------------key chain [nombre de clave]
key [nmero de clave]
key-string [contrasea]
interface s0/0/0
ip authentication mode eigrp [id de sistema autnomo] md5
ip authentication key-chain eigrp [id de sistema autnomo] [contrasea]
----------------------------------------------------------------------------Autenticacin de OSPF
----------------------------------------------------------------------------router ospf [id de nmero de proceso]
area 0 authentication
interface s0/0/0
ip ospf authentication-key [contrasea]
interface s0/0/0
ip ospf authentication
ip ospf authentication-key [contrasea]
----------------------------------------------------------------------------Autenticacin de OSPF con MD5
----------------------------------------------------------------------------router ospf [id de nmero de proceso]
area 0 authentication message-digest

interface s0/0/0
ip ospf message-digest-key [nmero de clave] md5 [contrasea]
interface s0/0/0
ip ospf authentication message-digest
ip ospf message-digest-key [nmero de clave] md5 [contrasea]
---------------------------------------------------------------------------Autenticacin AAA
---------------------------------------------------------------------------enable secret [contrasea]
username [usuario] secret [contrasea]
aaa new-model
aaa authentication login [base de datos de usuarios] local
line console
login authentication [base de datos de usuarios]
exec-timeout 5 0
line vty 0 4
login authentication [base de datos de usuarios]
exec-timeout 5 0
login block-for 300 attempt 2 within 120
security authentication failure rate 5 log
---------------------------------------------------------------------------SNMP
---------------------------------------------------------------------------logging 192.168.10.10
logging trap warnings
---------------------------------------------------------------------------Cargar IOS por TFTP
---------------------------------------------------------------------------Router#copy tftp flash
Address or name of remote host []? 192.168.20.254
Source filename []? c1841-ipbasek9-mz.124-12.bin
Destination filename [c1841-ipbasek9-mz.124-12.bin]?
Router#Conf t
Router(config)#boot system flash c1841-ipbasek9-mz.124-12.bin
---------------------------------------------------------------------------Configurar router como tftp server
---------------------------------------------------------------------------tftp-server nvram: [nombre de archivo1] alias [nombre de archivo2]
Router(config)#tftp-server nvram:startup-config alias test
---------------------------------------------------------------------------COMANDOS FILE SYSTEM

---------------------------------------------------------------------------show file system


dir flash
dir all
cd nvram:
pwd
---------------------------------------------------------------------------ACCESS LIST NOMBRADAS
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------Router(config)#ip access-list standard [nombre]
Router(config-std-nacl)#[permit | deny | remark] [IP ADDRESS ORIGEN][WILDCARD]
Router(config)#ip access-list extended [nombre]
Router(config-std-nacl)#[permit | deny | remark] [permit | deny | remark][PROTOC
OLO][IP ADDRESS ORIGEN][WILDCARD][OPERADOR][Puerto ORIGEN][IP ADDRESS DESTINO][W
ILDCARD][OPERADOR][Puerto DESTINO][ESTABLISHED]
Router(config-if)#ip access-group [nombre] [in | out]
show ip access-list [nmero de ACL | nombre de ACL]
show access-list [nmero de ACL | nombre de ACL]
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ACCESS LIST NUMERADAS EXTENDIDAS
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------Router(config)#access-list [nmero de ACL(>100)][permit | deny | remark][PROTOCOLO
][IP ADDRESS ORIGEN][WILDCARD][OPERADOR][Puerto ORIGEN][IP ADDRESS DESTINO][WILD
CARD][OPERADOR][Puerto DESTINO][ESTABLISHED]
Router(config-if)#ip access-group [nombre] [in | out]
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ACCESS LIST NUMERADAS STANDARD
-------------------------------------------------------------------------------------------------------------------------------Router(config)#access-list [nmero de ACL] [permit | deny | remark] [IP ADDRESS OR
IGEN] [WILCARD] [log]
Router(config-if)#ip access-group [nombre] [in | out]
--------------------------------------------------------------------------------------------------------------------------------

DHCP
-------------------------------------------------------------------------------------------------------------------------------Para router con DHCP-SERVER:
Router(config)#ip dhcp excluded-address [ip address inicial] [ip address final]
Router(config)#ip dhcp pool [nombre de pool]
Router(dhcp-config)#network [ip de red] [mscara]
Router(dhcp-config)#dns-server[ip de DNS-SERVER]
Router(dhcp-config)#default-router [ip de default-gateway]
Para router con hosts conectados:
Router(config)#interface fa0/0
Router(config-if)#ip helper-address [ip de interfaz del DHCP-SERVER]
show ip dhcp pool
show ip dhcp binding
debug ip dhcp server events
Comandos para PC:
ipconfig /release
ipconfig /renew
-------------------------------------------------------------------------------------------------------------------------------NATeo esttico
-------------------------------------------------------------------------------------------------------------------------------Router(config)#ip nat inside source static [ip local][ip global]
Router(config-if)#interface s0/0/0
Router(config-if)#ip nat outside
Router(config-if)#interface fa0/0
Router(config-if)#ip nat inside
show ip nat translations
show ip nat statistics
debug ip nat
-------------------------------------------------------------------------------------------------------------------------------NATeo dinmico
-------------------------------------------------------------------------------------------------------------------------------R2(config)#ip nat pool [nombre de pool] [ip de inicio][ip final] [netmask | pref
ix-length] [mscara de subred]
R2(config)#ip access-list extended [nombre de ACL]
R2(config-ext-nacl)#permit ip [ip de red local] [mscara de subred] any
R2(config)#ip nat inside source list [nombre de ACL] pool [nombre de pool]

Router(config-if)#interface s0/0/0
Router(config-if)#ip nat outside
Router(config-if)#interface fa0/0
Router(config-if)#ip nat inside
clear ip nat translation *
-------------------------------------------------------------------------------------------------------------------------------PAT (NATeo por sobrecarga)
-------------------------------------------------------------------------------------------------------------------------------R2(config)#ip access-list extended [nombre de ACL]
R2(config-ext-nacl)#permit ip [ip de red local] [mscara de subred] any
R2(config)#ip nat inside source list [nombre de ACL] interface S0/0/0 overload
Router(config-if)#interface s0/0/0
Router(config-if)#ip nat outside
Router(config-if)#interface fa0/0
Router(config-if)#ip nat inside
-------------------------------------------------------------------------------------------------------------------------------PAT con pool de ip pblicas
-------------------------------------------------------------------------------------------------------------------------------R2(config)#ip nat pool [nombre de pool] [ip de inicio][ip final] [netmask | pref
ix-length] [mscara de subred]
R2(config)#ip access-list extended [nombre de ACL]
R2(config-ext-nacl)#permit ip [ip de red local] [mscara de subred] any
R2(config)#ip nat inside source list [nombre de ACL] pool [nombre de pool] overl
oad
Router(config-if)#interface s0/0/0
Router(config-if)#ip nat outside
Router(config-if)#interface fa0/0
Router(config-if)#ip nat inside
--------------------------------------------------------------------------------------------------------------------------------

Вам также может понравиться