Открыть Электронные книги
Категории
Открыть Аудиокниги
Категории
Открыть Журналы
Категории
Открыть Документы
Категории
012-324
. ______
: 403530 _____________________
: .466534.012-324
NETXPERT
L3
NetXpert NX-5124-G10
NetXpert NX-5124-G10F
. .
. .
. .
2
.466534.012-324
.
.
.
. . . . . .
.466534.012-324
.466534.012-324 -
NX-5124-G10 (NX-5124-G10F) -
.
:
.466534.012-324 ;
.466534.012-324 .
. .
. .
.466534.012-324
. . .
. . .
. .
. . NX-5124G-10 3 182
NX-5124G-10F
.. .
. .
1 .................................................................................................................................. 9
1.1 ............................................................................................................................. 9
1.2 ....................................................................................................................... 9
1.3 ........................................................................................................................................ 9
1.4 ..................................................................................................................................... 9
1.5 ............................................................................................................................................. 10
1.6 .................................................................................................................................. 10
2 ......................................................................................................................................... 11
2.1 ................................................................................................................. 11
2.1.1 ................................................................................... 11
2.1.2 ..................................................................................... 13
2.1.3 HTTP............................................................................................................................. 14
2.2 .................................................................................................................................. 15
2.2.1 VTY. ................................................................................................................... 15
2.2.2 ........................................................................................................................... 15
2.2.3 ......................................................................................................... 15
2.2.4 VTY.................................................................................................................. 15
2.3 ...................................................................................................................... 15
2.3.1 SNMP............................................................................................................................ 15
2.3.2 RMON ........................................................................................................................... 19
2.4 SSH ............................................................................................................................. 21
2.4.1 SSH...................................................................................................................................... 21
2.4.2 ........................................................................................................................... 22
2.4.3 Ssh.................................................................................................... 22
3 .................................................................................................................................. 23
3.1 ............................................................................................................................................................ 23
3.1.1 ........................................................................................... 23
3.1.2 .............................................................................................. 23
3.2 ................................................................................................................................ 24
3.2.1 ........................................................................................ 24
3.2.2 .................................................................................... 24
3.2.3 ............................................................................... 25
3.3 .................................................................................................................. 27
3.3.1 ........................................................................................ 27
4 ...................................................................................................... 28
4.1 ............................................................................................................................................................ 28
4.1.1 ........................................................................................... 28
4.1.2 .............................................................................................. 28
4.2 ................................................................................................................................ 29
4.2.1 Ethernet ................................................................................................... 29
5 ................................................................................ 31
. .
5.1 .................................................................................................................. 31
5.1.1 Ethernet ................................................................................................... 31
5.2 ................................................................................................................... 31
5.2.1 .............................................................................................................................................. 31
5.2.2 ................................................................... 32
5.2.3 ............................................................................... 32
5.3 .................................................................................................................. 33
. .
5.3.1 .................................................................................................... 33
6 ........................................................................................................... 34
6.1 ................................................................................................. 34
6.1.1 ....................................................................................... 34
6.1.2 ........................................................................ 34
7 ............................................................................................................ 35
7.1 ................................................................................. 35
7.2 ............................................................................................. 35
7.2.1 ................................................................................................ 35
7.2.2 .................................................................. 35
8 VLAN.................................................................................................................................................. 36
8.1 VLAN .................................................................................................................................................. 36
8.2 VLAN ............................................................................................................. 36
8.3 VLAN ....................................................................................................................... 36
. .
4
.466534.012-324
. . .
8.3.1 / VLAN ......................................................................................................... 36
8.3.2 ...................................................................................... 36
8.3.3 / VLAN ........................................................................................ 37
8.3.4 Super-VLAN ............................................................................................. 37
8.3.5 VLAN .......................................................................................... 38
8.4 ........................................................................................................................................ 38
9 STP .................................................................................................................................................... 39
9.1 (STP) ....................................................................................... 39
9.1.1 STP. ...............................................................................................................................39
9.1.2 STP .......................................................... 39
9.1.3 RSTP...................................................................................................... 39
9.1.4 SSTP ................................................................................................................ 40
9.1.5 vLAN............................................................................................ 41
9.1.6 RSTP...................................................................................................... 42
9.1.7 RSTP ................................................................................................................ 42
9.2 MSTP .......................................................................................................................................... 44
9.2.1 MSTP ................................................................................................................................... 44
9.2.2 MSTP ..................................................................................................... 49
9.2.3 MSTP................................................................................................................ 50
10 STP ................................................................................ 56
10.1 STP ....................................................................................... 56
10.1.1 STP. ....................................................................... 56
10.1.2 STP ......................................................................... 59
11 MAC- .............................................................................................................. 63
11.1 MAC- ........................................................................................................ 63
11.2 MAC-................................................................................................................... 63
11.2.1 Mac- ............................................................................................ 63
11.2.2 MAC-.................................................................................. 63
11.2.3 - VLAN....................................................................................................... 63
11.2.4 MAC-........................................................................................... 63
11.2.5 MAC- ........................................................................................ 64
12 ......................................................................................................................... 65
12.1 ............................................................................................................................................................ 65
12.2 ........................................................................................... 65
12.3 ............................................................................................................. 65
12.3.1 , ........................................... 65
12.3.2 ....................................................................................................... 65
12.3.3 ............................................................ 66
12.3.4 ....................................................................................................... 66
13 GVRP ................................................................................................................................................. 67
13.1 ............................................................................................................................................................ 67
13.2 .............................................................................................................................. 67
. .
.466534.012-324 5
. . .
15.2.3 802.1.................................. 74
15.2.4 802.1............................................................................ 74
15.2.5 802.1 ........................................................................................... 74
15.2.6 802.1................................................................................. 74
15.2.7 802.1....................................................................... 74
15.2.8 802.1 ........................................................................... 74
15.2.9 802.1............................................................................................... 75
15.2.10 VLAN 802.1................................................................................................. 75
15.2.11 ........................................................... 75
15.2.12 802.1 ........................................................................ 76
15.2.13 802.1 ......................................................... 76
15.3 802.1x ............................................................................................................................ 76
16 -............................................................................................... 77
16.1 - ........................................................................................ 77
16.1.1 MAC- ...................................................................................... 77
16.1.2 -....................................................................... 77
16.1.3 -.................................................................................. 77
17 IP- .......................................................... 78
17.1 IP- ....................................................................... 78
17.1.1 IP .................................................................................................................. 78
17.1.2 IP-........................................ 78
17.1.3 IP- ....................................................................... 78
17.1.4 ........................................................................................ 79
18 ................................................................................................................ 80
18.1 IP-.............................................................................................................................. 80
18.1.1 .............................................................................................................................................. 80
18.1.2 IP-............................................................................................... 81
18.1.3 IP-................................................................................................................ 81
18.1.4 IP- .................................................................................................................... 84
18.2 NAT ...................................................................................................................................... 84
18.2.1 .............................................................................................................................................. 84
18.2.2 NAT ........................................................................................................ 86
18.2.3 NAT .................................................................................................................. 86
18.2.4 NAT ............................................................................................................... 91
18.3 DHCP .......................................................................................................................................... 93
18.3.1 .............................................................................................................................................. 93
18.3.2 DHCP- ............................................................................................................. 93
18.3.3 DHCP- ............................................................................................................. 94
18.4 IP ................................................................................................................................ 96
18.4.1 IP- .................................................................................................................... 96
18.4.2 ......................................................................................................... 100
18.4.3 IP- ....................................................... 101
19 ........................................................................................................................ 104
. .
19.1 RIP ............................................................................................................................................ 104
19.1.1 ............................................................................................................................................ 104
19.1.2 RIP ..................................................................................................... 104
19.1.3 RIP.................................................................................................................. 104
19.2 BEIGRP..................................................................................................................................... 108
19.2.1 ............................................................................................................................................ 108
19.2.2 BEIGRP................................................................................................ 108
. .
6
.466534.012-324
. . .
20.3.1 / VRRP ................................................................................... 133
20.3.2 VRRP.............................................................................................. 133
20.3.3 VRRP............................................................................. 133
20.3.4 VRRP ...................................................................................................... 134
20.3.5 VRRP ........................................................................... 134
20.3.6 VRRP ............................................................................................ 134
20.3.7 VRRP .......................................................................................................... 134
21 IP MULTICAST ................................................................................................................................ 136
21.1 ..................................................................................... 136
21.1.1 ............................................................................. 136
21.1.2 .......................................................... 136
21.2 ........................................................................ 137
21.2.1 IP .......................................................................... 137
21.2.2 .......................................................................... 137
21.2.3 TTL.................................................................................................................. 138
21.2.4 .............................................. 138
21.2.5 ............................................. 138
21.2.6 IP Multicast................................................................................................... 139
21.2.7 IP Multicast............................................................................... 139
21.2.8 IP Multicast Helper ...................................................................................................... 139
21.2.9 ........................................................................ 140
21.2.10 ......................................................... 141
21.3 IGMP ......................................................................................................................................... 141
21.3.1 ......................................................................................................................... 141
21.3.2 IGMP ........................................................................................................................... 141
21.3.3 IGMP ( VLAN)................................. 144
21.4 PIM-DM ..................................................................................................................................... 145
21.4.1 PIM-DM ....................................................................................... 145
21.4.2 PIM-DM ....................................................................................................................... 146
21.4.3 PIM-DM................................................................... 147
21.5 PIM-SM ..................................................................................................................................... 147
21.5.1 PIM-SM........................................................................................ 147
21.5.2 PIM-SM ....................................................................................................................... 148
21.5.3 ..................................................................................................................... 149
22 QOS ................................................................................................................................................. 151
.466534.012-324 7
. . .
25.2 .................................................................................................. 159
25.3 ......................................................................................................................... 159
25.3.1 ................................................................................. 159
25.3.2 ............................................................................................. 159
25.3.3 ......................................................................................................... 159
25.3.4 ....................................................................... 159
25.4 ........................................................................................................... 159
26 ........................................................................................................................... 161
26.1 AAA ........................................................................................................................................... 161
26.1.1 AAA .................................................................................................................................... 161
26.1.2 AAA .............................................................................................................. 162
26.1.3 AAA.......................................................................... 163
26.1.4 AAA.................................................................................... 163
26.1.5 AAA ................................................................................... 166
26.1.6 AAA ................................................................................ 166
26.1.7 AAA .......................................................................................... 166
26.1.8 AAA ......................................................................................................... 167
26.1.9 AAA ................................................................................. 168
26.1.10 AAA ............................................................................................ 168
26.2 RADIUS..................................................................................................................................... 169
26.2.1 ...................................................................................................................................... 169
26.2.2 RADIUS................................................................................................ 170
26.2.3 RADIUS................................................................................................ 170
26.2.4 RADIUS .......................................................................................................... 170
26.2.5 RADIUS....................................................................................................... 171
26.3 - ............................................................................................................... 172
26.3.1 ............................................................................................................................................ 172
26.3.2 ................................................................................ 174
26.3.3 - ................................................................... 175
26.3.4 ................................................................ 176
27 ......................................................................................................... 178
27.1 .......................................................................................................................................................... 178
27.2 ..................................................................................... 178
27.3 ................................................................................................ 178
27.3.1 .............................................................................................................. 178
27.3.2 ...................................................................................................................... 178
27.3.3 ..................................................................................................................... 179
27.3.4 .................................................................................. 179
27.3.5 SNMP ................................................................... 179
27.3.6 Web ...................................................................... 179
28 PBR.................................................................................................................................................. 180
28.1 PBR.................................................................................................................................................. 180
28.2 PBR .................................................................................................................... 180
28.3 PBR .............................................................................................................................. 180
. .
28.3.1 ............................................................................................................ 180
28.3.2 ........................................................................................................ 180
28.3.3 PBR ............................................................................................... 180
28.3.4 PBR............................................................................................................................ 180
28.4 PBR........................................................................................................................... 180
........................................................................................................................... 182
. .
. .
8
.466534.012-324
. . .
1
,
, .. ,
.
1.1
0.
, 1.
<type><slot>/<port>; -
:
10M Ethernet Ethernet E
100M FastEthernet Ethernet F
1000M Ethernet Ethernet G
, 1.
, 1.
: .
1.2
:
, .
.
IP- IP.
1.3
(?) :
,
.
Switch> ?
( ),
. .
, ( ).
Switch> s?
,
.
Switch> show?
,
. , -
. .
. -
, .
1.4
.
. ,
, . -
(?).
:
System Supervision Mode ( Ctrl-p
monitor# quit
)
. .
.466534.012-324 9
. . .
User Mode ( ) Switch> exit quit
input
Administration Mode (
enable Switch# exit quit
)
exit quit
config
Global Configuraton Mode ( Ctrl-Z , -
Switch_config#
) -
inter- exit quit
Interface Configuration Mode
face Ctrl-Z , -
( Switch_config_f0/1#
, , in- -
)
terface f0/1 .
. -
, (?) .
.
:
Switch> enter
Password: <enter password>
Switch# config
Switch_config# interface f0/1
Switch_config
_f0/1# quit
Switch_config# quit
Switch#
1.5
, no -
.
, no ip routing
1.6
-
, . -
write.
. .
. .
. .
10
.466534.012-324
. . .
2
2.1
2.1.1
2.1.1.1
- 20 .
2.1.1.2
, . -
. [ ] .
Format .
. [ ]
, .
dir [filename] :
Index number Filename <FILE> Size of the file Establishment time (
<FILE> )
delete filename . , .
md directory .
. , -
rd dirname
.
.
more filename
, .
cd .
pwd .
2.1.1.3
monitor#boot flash <local_filename>
-,
.
local_filename , -
2.1.1.4
. .
-
( ).
1. TFTP
monitor#copy tftp flash [ip_addr]
. .
tftp -.
.
IP- Tftp. , IP- -
ip_addr
copy
main.bin switch.bin.
monitor#copy tftp flash
: Source file name[]?main.bin
: Remote-server ip address[]?192.168.20.1
: Destination file name[main.bin]?switch.bin
please wait ...
. .
.466534.012-324 11
. . .
######################################################################
######################################################################
######################################################################
######################################################################
######################################################################
#############################################
TFTP:successfully receive 3377 blocks ,1728902 bytes
monitor#
2. zmodem
download . download ? -
.
monitor#download c0 <local_filename>
- -
zmodem. .
local_filename , -.
Hyper Terminal WINDOWS 95, NT 4.0 -
WINDOWS 3.X.
monitor#download c0 switch.bin
: speed[9600]?115200
115200 send file
Send - ( ). send file:
2.1-1 Send
main.bin, -
, , Zmodem. Send -
.
:
ZMODEM: successfully receive 36 blocks, 18370 bytes
, .
. .
- 9600.
:
NX-5124G 10 zmodem -
, 38400.
2.1.1.5
. .
startup-config. -
, , .
1. TFTP
monitor#copy tftp flash startup-config
2. zmodem
monitor#download c0 startup-config
2.1.1.6 ftp
config #copy ftp flash [ip_addr|option]
ftp -
. copy ftp .
-
ftp. .
. .
12
.466534.012-324
. . .
copy{ftp:[[[//login-name:[login-password]@]location]/directory]/filename}|flash:
filename>}{flash<:filename>|ftp:[[[//login-name:[login-password]@]location]
/directory]/filename}<blksize><mode><type>
Login-nam FTP . ,
copy.
login-password ftp ,
copy.
nchecksize .
Vrf vrf , MPLS.
blksize ( 512)
ip_addr IP- ftp. ,
copy.
Active ftp .
passive ftp .
"main.bin", "switch.bin"
.
config#copy ftp flash
: ftp user name [anonymous]? login-nam
: ftp user password [anonymous]? login-password
: Source file name []? main. bin
: Remote-server ip address []? 192.168.20.1
: Destination file name [main. bin]? switch. bin or
config#copy ftp://login-nam:login-password@192.168.20.1/main.bin flash:switch.bin
######################################################################
######################################################################
FTP:successfully receive 3377 blocks, 1728902 bytes
config#
:
ftp - tcp (75 ), -
2.1.2
. .
:
monitor#ip address 192.168.1.1 255.255.255.0
2.1.2.2
. .
.466534.012-324 13
. . .
monitor#ip route default 192.168.1.1
2.1.2.3 PING
monitor#ping <ip_address>
.
ip_address IP-
monitor#ping 192.168.20.100
PING 192.168.20.100:56 data bytes
64 bytes from 192.168.20.100:icmp_seq=0. time=0. ms
64 bytes from 192.168.20.100:icmp_seq=1. time=0. m
64 bytes from 192.168.20.100:icmp_seq=2. time=0. ms
64 bytes from 192.168.20.100:icmp_seq=3. time=0. ms
----192.168.20.100 PING Statistics----
4 packets transmitted, 4 packets received, 0% packet loss
round-trip (ms) min/avg/max = 0/0/0
2.1.3 HTTP
2.1.3.1 HTTP
http
http
http
http
1. http
: http .
http:
Ip http server http
2. http
: http - 80.
http:
Ip http port number http
3. http
Http enables .
. .
http.
http:
Enable password {0|7} line enable.
4. http
http, -
. .
http :
http access-class STRING http
2.1.3.2 http
(80) http.
192.168.20.0/24.
ip :
p access-list standard http-acl
permit 192.168.20.0 255.255.255.0
:
ip http access-class http-acl
ip http server
. .
14
.466534.012-324
. . .
2.2
2.2.1 VTY.
line; -
. line
, .
2.2.2
: (console), (AUX), -
(asynchronous) (virtual terminal).
. -
.
CON(CTY) - 0.
Telnet, X.25 PAD, HTTP
VTY Rlogin (, - 1 32.
Ethernet ).
2.2.2.1
VTY
.
VTY, .
.
, Telnet (Ethernet -
).
VTY :
(1).
(2). .
VTY
VTY".
2.2.3
2.2.4 VTY
VTY
more.
config#line vty 0 32
config_line#length 0
. .
2.3
2.3.1 SNMP
2.3.1.1
SNMP , :
SNMP (NMS)
. .
SNMP (AGENT)
(Management Information Base - MIB)
, SNMP -
SNMP .
SNMP (NMS), CiscoWorks.
MIB . SNMP , -
.
SNMP MIB, SNMP .
SNMP
. (MIB),
. -
. SNMP , -
. -
, , ( ), TCP, -
.
. .
.466534.012-324 15
. . .
1. SNMP
SNMP ( ) -
SNMP . , ,
SNMP .
SNMP . -
, , ,
, . , SNMP -
, , PDU, . -
, . ,
, . , -
.
,
. , ,
.
, .
. ,
. , SNMP
, . -
, -
.
.
2. SNMP
SNMP:
SNMPv1 - , ,
RFC1157.
SNMPv2C - SNMPv2, -, -
RFC1901.
(Layer 3) SNMP:
SNMPv3 - , 3, RFC3410.
SNMPv1 . (community) ,
MIB , IP- .
SNMPv3 -
; SNMPv3 :
, .
, .
-
.
SNMPv3 .
, ( ), -
.
. SNMPv3 , :
, , . -
MD5 SHA ( ) -
. .
MD5 SHA -
. DES
. -,
.
. , -
.
SNMP SNMP, -
. .
. -
.
3. MIB
SNMP MIBII ( RFC 1213)
SNMP ( RFC 1215).
MIB .
2.3.1.2 SNMP
SNMP :
SNMP
SNMP
SNMP
. .
16
.466534.012-324
. . .
SNMP
SNMP
SNMPv3
SNMPv3
SNMPv3 Engine ID
1. SNMP
SNMP MIB (
). SNMP:
OID MIB name
snmp-server view name oid] SNMP
[exclude | include] SNMP. Exclude , ; include ,
.
, SNMP MIB -
.
.
SNMP, SNMP
SNMP.
2. SNMP
SNMP -
SNMP . , -
. , -
:
IP- SNMP.
MIB MIB, -
.
MIB.
, -
:
snmp-server community string [view
. -
, no snmp-server community.
, SNMP.
3.
SysContact sysLocation MIB,
.
. .
.
:
snmp-server contact text
snmp-server location text
. .
4. SNMP
SNMP ,
. :
snmp-server packetsize byte-count
5. SNMP
SNMP, -
,
.
show snmp SNMP
6. SNMP
. .
.466534.012-324 17
. . .
SNMP ( -
):
SNMP
,
:
snmp-server host host community-
SNMP
string [trap-type]
snmp-server host host , , ..
[traps|informs]{version {v1 | v2c | : SNMPv3
v3 {auth | noauth | priv } }}commu- eybrfkmysq SNMP ,
nity-string [trap-type] .
SNMP
. snmp-server host , -
.
. ,
snmp trap link-status, ,
SNMP . -no snmp trap link-stat -
.
, snmp-server host.
, .
.
:
snmp-server trap-source interface , .
IP- .
snmp-server queue-length length .
- 10.
snmp-server trap-timeout seconds .
- 30 .
7. SNMP
,
SNMP.
snmp source-addr ipaddress SNMP
8. SNMPv3 SNMP:
. .
snmp-server group [groupname {v1 | v2c
|v3 [auth | noauth | priv]}][read read- SNMPv3.
view][write writeview] [notify notify-
view] [access access-list]
9. SNMPv3
. .
. -
, , -
. ,
; , .
snmp-server user username groupname {v1
| v2c | v3 [encrypted] [auth {md5 | sha} SNMPv3
. -
-
; . -
; , .
. .
18
.466534.012-324
. . .
SNMPv3.
snmp-server user username groupname re-
mote ip-address [udp-port port] {v1 | :
v2c | v3 [encrypted] [auth {md5 | sha}
auth-password ]} [access access-list] SNMP IP-
.
2.3.1.3
1. 1:
snmp-server community public RO
snmp-server community private RW
snmp-server host 192.168.10.2 public
public -
MIB private MIB.
public private MIB private
MIB . , public -
192.168.20.2. ,
down, link down 192.168.20.2.
2. 2:
snmp-server engineID remote 90.0.0.3 80000523015a000003
snmp-server group getter v3 auth
snmp-server group setter v3 priv write v-write
snmp-server user get-user getter v3 auth sha 12345678
snmp-server user set-user setter v3 encrypted auth md5 12345678
snmp-server user notifier getter remote 90.0.0.3 v3 auth md5 abcdefghi
snmp-server host 90.0.0.3 informs version v3 auth notifier
snmp-server view v-write internet included
SNMPv3 . getter
, setter .
get-user getter,
sha 12345678. set-user
setter,
md5 12345678.
notifier inform
90.0.0.3.
. .
2.3.2 RMON
2.3.2.1 RMON
RMON :
RMON
RMON
. .
RMON
RMON
RMON
1. RMON
rMon
SNMP NMS. SNMP -
. rMon .
rMon :
Configure
rmon alarm index variable in- rMon.
terval {absolute | delta} ris-
ing-threshold value [eventnum- index . 1
ber] falling-threshold value 65535.
. .
.466534.012-324 19
. . .
[eventnumber] [owner string] variable MIB,
MIB INTEGER, Counter Gauge
Time Ticks.
interval -
. 1 4294967295.
absolute -
MIB; delta -
MIB .
value ,
. event
number , -
. event number -
.
owner string -
.
exit .
write .
scription string] log -
2. [log] [owner string] .
[trap community] trap , -
. community .
owner string .
3. exit .
4. write .
. .
rMon, eventLastTimeSent field -
sysUpTime rMon. log ,
log. trap , trap
community. rmon event -
. -
no rmon event index , in-
dex.
. .
3. RMON
rMon -
. rMon :
1. configure
20
.466534.012-324
. . .
5. exit .
6. write .
,
, second. -
. rmon eventcollection stat -
-
. no rmon collection stats index
, index. , bucket-number
interval second , -
.
5. RMON
show RMON.
rmon.
Alarm .
Event ,
. .
2.4 SSH
2.4.1 SSH
2.4.1.1 SH
SSH ,
, SSH . , -
telnet. SSH , Data Encryption Standard (DES),
the Triple DES (3DES) blowfish.
2.4.1.2 SSH
SSH , ssh.
,
SSH, ,, -
SSH. SSH :
des, 3des blowfish.
. .
.466534.012-324 21
. . .
2.4.1.3
sh ssh 1.5 ssh shell.
2.4.2
2.4.2.1
ssh .
.
:
Ip sshd auth_method STRING
2.4.2.2
ssh , -
.
-
:
Ip sshd access-class STRING
2.4.2.3
,
, .
:
Ip sshd timeout <60-65535>
2.4.2.4
,
SSH , . -
3 .
-
:
Ip sshd auth-retries <0-65535>
2.4.2.5 ssh
SSH . SSH- -
. .
ras (client). -
- .
SSH-:
Ip sshd enable
. .
2.4.3 Ssh
, , IP- 192.16.20.40 ssh.
.
2.4.3.1
ip access-list standard ssh-acl
permit 192.168.20.40
2.4.3.2
aaa authentication login ssh-auth local
ip sshd auth-method ssh-auth
ip sshd access-class ssh-acl
ip sshd enable
. .
22
.466534.012-324
. . .
3
3.1
, -
.
, ,
. ,
, .
, .
3.1.1
.
Ethernet
Ethernet Ethernet
Ethernet
Ethernet
VLAN
: Ethernet -
. Ethernet -
, . -
, .
Ethernet :
Ethernet
Ethernet
Ethernet
:
VLAN
3.1.2
.
:
1) interface ; -
config_ , -
. .
. .
. show in-
terface . , -
, :
Switch#show interface
GigaEthernet1/1 is down, line protocol is down
Hardware is Fast Ethernet, Address is 0009.7cf7.7dc1
. .
.466534.012-324 23
. . .
0 watchdog, 0 multicast, 0 pause input
0 input packets with dribble condition detected
1 packets output, 64 bytes, 0 underruns
0 output errors, 0 collisions, 1 interface resets
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier, 0 PAUSE output
0 output buffer failures, 0 output buffers swapped out
Gigabit Ethernet g1/1, :
interface GigaEthernet0/1
config_g1/1 .
:
. -
, g 1/1, g 1/1.
2) .
, ;
,
.
3) show, -
, .
3.2
3.2.1
, .
.
:
3.2.1.1
, -
. , -
. show interface
running-config . -
.
description string
-
.
3.2.1.2
. .
. bandwidth -
.
bandwidth kilobps
, -
.
. .
3.2.1.3
. bandwidth
.
delay tensofmicroseconds
. delay -
.
3.2.2
:
. .
24
.466534.012-324
. . .
3.2.2.1
,
, . -
, , : -
:
show interface [type [slot|port]] .
show running-config .
-
show version , , ,
.
3.2.2.2
.
- . , -
, . -
:
no interface type [slotport]
3.2.2.3
, . -
-
. -
. .
DTR .
shutdown no shutdown -
.
shutdown
no shutdown
show interface show running-
config. administratively down.
.
. .
3.2.3
, ,
:
VLAN
. .
3.2.3.1
. -
, . ,
. no ip unreachable
. -
, , -
; -
.
-
:
interface null 0
. .
.466534.012-324 25
. . .
,
. IP-
192.168.20.0.
ip route 192.168.20.0 255.255.255.0 null 0
3.2.3.2
. -
BGP .
BGP. -
,
. , , -
. ,
, .
.
, -
:
interface loopback number
3.2.3.3
Ethernet.
, .
:
Interface port-aggregator number
3.2.3.4 VLAN
Vlan - . VLAN -
2 VLAN . -
, VLAN. VLAN -
, .
VLAN :
Interface vlan number VLAN
3.2.3.5 Super-VLAN
Super VLAN : VLAN
Ipv4 .
IP-. Super VLAN VLAN ,
. IPv4 .
. .
VLAN, Super VLAN, SubVLAN. SubVLAN -
IP-. Ip- Super
VLAN.
Super VLAN :
super VLAN.
. .
26
.466534.012-324
. . .
Super VLAN ,
.
3.3
3.3.1
3.3.1.1
, ;
.
interface vlan 1interface vlan 1
ip address 192.168.1.23 255.255.255.0ip address 192.168.1.23 255.255.255.0
3.3.1.2
Ethernet 1.
interface GigaEthernet0/1
shutdown
.
interface GigaEthernet0/1
no shutdown
. .
. .
. .
.466534.012-324 27
. . .
4
4.1
, ,
.
, ,
. ,
, .
, .
4.1.1
.
Ethernet
Ethernet Ethernet Ethernet
Ethernet
VLAN
: Ethernet -
. Ethernet -
, . -
, .
Ethernet :
Ethernet
Ethernet
Ethernet
:
VLAN
4.1.2
.
:
1) interface ; -
config_ , .
.
. show interface
. , , -
. .
:
Switch#show interface
GigaEthernet1/1 is down, line protocol is down
Hardware is Fast Ethernet, Address is 0009.7cf7.7dc1
MTU 1500 bytes, BW 10000 Kbit, DLY 1000 usec,
reliability 255/255, txload 1/255, rxload 1/255
. .
28
.466534.012-324
. . .
0 watchdog, 0 multicast, 0 pause input
0 input packets with dribble condition detected
1 packets output, 64 bytes, 0 underruns
0 output errors, 0 collisions, 1 interface resets
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier, 0 PAUSE output
0 output buffer failures, 0 output buffers swapped out
Gigabit Ethernet g0/1, :
interface GigaEthernet0/1
config_g0/1 .
:
. -
, g 1/1, g 1/1.
2) .
, ;
,
.
3) show, -
, .
4.2
4.2.1 Ethernet
Ethernet . Ethernet
: 10 / 100 /. :
, - .
4.2.1.1 Ethernet
Ethernet:
interface fastethernet [slot\port ] Ethernet
interface gigaethernet [slot\port ] Ethernet
show interface fastEthernet
Fast Ethernet show interface gigaEthernet Gigabit
Ethernet.
4.2.1.2 Ethernet
. .
Ethernet
.
Ethernet 10, 100
Speed {10|100|1000|auto}
No speed ()
. .
:
. , GBIC GE-FX 1000M,
FE-FX - 100M. speed auto,
. .
4.2.1.3
,
. Ethernet
. Ethernet
.
duplex {full|half|auto} Ethernet
No duplex ()
. .
.466534.012-324 29
. . .
4.2.1.4
PAUSE ( 802.3).
flow-control on/off /
no flow-control
. .
. .
. .
30
.466534.012-324
. . .
5
5.1
5.1.1 Ethernet
Ethernet . proce-
dures . Ethernet : 10 / 100
/. : , - -
.
5.1.1.1
keepalive,
.
keepalive .
keepalive period Period , -
.
no keepalive keepalive
5.1.1.2
. -
.
Configure
interface f0/0 , .
.
band , .
[no] switchport rate- ingress , -
limit band ingress } .
egress , -
.
exit .
exit .
5.1.1.3
PAUSE ( 802.3).
flow-control on/off /
no flow-control
. .
5.1.1.4 -
, -
( MAC )
, .
.
. .
5.2
5.2.1
,
, . -
MAC , MAC
. MAC- -
, . -
.
. .
.466534.012-324 31
. . .
: -
-. MAC- -
MAC , ,
MAC-.
, , .
.
5.2.2
/
-
-
-
MAC- IP-
5.2.3
5.2.3.1 /
:
, -
.
:
configure
interface f0/1 , .
[no] switchport port-security /
exit .
exit .
write
5.2.3.2
, -
.
: protect.
-
:
configure
interface f0/1 , .
. .
[no] switchport port-security viola-
protect:
tion [protect\restrict]
restrict:
exit .
exit .
write
. .
5.2.3.3 -
-
-.
-:
configure
interface f0/1 , .
32
.466534.012-324
. . .
5.2.3.4
show, -
, , MAC-
, MAC- , -.
show -
:
show port-security [interface inter-
face-id] interface-id: ID
5.2.3.5 -
show, -
, MAC- MAC- -
.
show -
-:
show mac address-table [interface in- -
terface-id] interface-id: ID
5.3
5.3.1
5.3.1.1
, ;
.
interface vlan 1
ip address 192.168.1.23 255.255.255.0
. .
5.3.1.2
Ethernet 1.
interface fastEthernet 0/1
flow-control on
. .
.
interface fastEthernet 0/1
flow-control off
. .
.466534.012-324 33
. . .
6
6.1
6.1.1
,
.
, interface range,
. interface range,
, , .
6.1.2
:
interface range, , -
, :
interface range type slot/<port1 - (1) slot
port2 | port3>[ , <port1 - (2) 1 2
port2|port3>] 3.
(3) 2 , 1
(4) /
fast Ethernet,
Ethernet 1, 2, 3, 6, 8, 10, 11, 12, 0.
switch_config#interface range 1 - 3 , 6 , 8 , 10 - 12
switch_config_if_range#
. .
. .
. .
34
.466534.012-324
. . .
7
7.1
7.2
7.2.1
, -
.
-
:
Configure
Session-number -
.
mirror session session_number {desti-
Destination -
nation {interface interface-id} |
source {interface interface-id [, | - .
]rx ] } Source .
rx .
-
.
exit .
write .
7.2.2
show.
.
show mirror [session session_number]
Session-number
. .
. .
. .
.466534.012-324 35
. . .
8 VLAN
8.1 VLAN
(Virtual Local Area Network) ,
, . 1999 . IEEE -
IEEE 802.1Q, VLAN. -
, . -
VLAN ,
. VLAN , -
, , -
; -
,
, , ,
.
:
VLAN
, 802.1Q
Visiting port
Vlan , VLAN,
. ,
; VLAN , -
. vlan , -
vlan , vlan id vlan (PVID).
VLAN
Vlan-allowed vlan,
. Vlan-untagged
vlan vlan.
8.2 VLAN
/ VLAN
/ VLAN
superVLAN
VLAN
8.3 VLAN
8.3.1 / VLAN
- , -
, . VLAN
, LAN,
LAN. VLAN -
, -
. VLAN .
. .
VLAN, .
VLAN:
vlan vlan-id VLAN
name str VLAN
Exit vlan vlan.
. .
8.3.2
, ,
VLAN.
, VLAN
Ethernet .
,
Ethernet .
VLAN , -
, , . -
. .
36
.466534.012-324
. . .
port pvid,
VLAN. ,
. .
VLAN PVID. VLAN
.
.
VLAN, , -
, , VLAN, -
.
:
switchport pvid vlan-id PVID .
switchport mode access|trunk|dot1q-tunnel .
switchport trunk vlan-allowed ... vlan-allowed .
switchport trunk vlan-untagged ... vlan-untagged .
:
dot1q-tunnel.
/ ,
.
dot1q-tunnel:
double-tagging double-tagging
dot1q-tunnel :
dot1q-
tunnel
2116 / 2224 / 2224M / 2226 / 2448B / 3224 / 3224M / 3424 / 6508
2224D
2448 / 2516 / 2524 / 3448 / 3512
, , , -
.
8.3.3 / VLAN
Vlan -
3. vlan :
[no] interface vlan vlan-id / VLAN
8.3.4 Super-VLAN
. .
Super VLAN : -
, VLAN Ipv4; -
, IP-. Super VLAN -
. VLAN -
IPv4 . , Super VLAN,
IP-.
. .
Super VLAN. -
, .
[no] interface supervlan index Index Super VLAN. 1
32.
no , Super VLAN.
Super VLAN. Sub
VLAN -
.466534.012-324 37
. . .
Remove VLAN
Sub VLAN. remstr
.
No SubVLAN SuperVLAN. -
no
VLAN interface , Ip-.
Super VLAN , -
.
8.3.5 VLAN
VLAN -
:
show vlan [ id x | interface intf ] VLAN
show interface {vlan | supervlan} x /supervlan
8.4
, :
2. 1-3 VLAN1,
4-6 - VLAN2. VLAN1 VLAN2 SuperVlan.
SuperVla :
. .
switchport pvid 2
!
interface fastethernet 0/6
switchport pvid 2
!
interface supervlan 1
. .
subvlan 1,2
ip address 192.168.1.100 255.255.255.0
ip proxy-arp subvlan
!
. .
38
.466534.012-324
. . .
9 STP
9.1 (STP)
9.1.1 STP.
(Spanning Tree Protocol - STP)
IEEE 802.1D; , -
, .
-
-
. ,
. -
. , ,
.
STP
. LAN -
. ,
, , , LAN.
, .
.
( ) . ,
, .
:
(1) .
(2) .
(3) .
( )
. Root Path Cost, ,
.
, .
, (
LAN) . LAN
-
.
, -
.
STP ,
Ethernet. STP -
.
(Rapid Spanning Tree) -
802.1D ST. RSTP
, LAN.
. -
.
802.1D STP 802.1w RSTP. -
. .
9.1.2 STP
Single STP PVST RSTP MSTP
NX-5124G 10
9.1.3 RSTP
STP
/ STP
. .
.466534.012-324 39
. . .
STP
9.1.4 SSTP
9.1.4.1 STP
STP :
spanning-tree mode {sstp | rstp} STP
9.1.4.2 / STP
.
, .
:
no spanning-tree STP
, :
spanning-tree STP (SSTP)
spanning-tree mode {sstp | rstp} STP
9.1.4.3
-
.
:
spanning-tree sstp priority value sstp
no spanning-tree sstp priority sstp -
(32768)
9.1.4.4
STP -
, .
SSTP :
spanning-tree sstp hello-time value sstp
. .
no spanning-tree sstp hello-time sstp -
(4 )
9.1.4.5
,
, .
-
. .
:
spanning-tree sstp max-age value sstp
no spanning-tree sstp max-age
(20 )
9.1.4.6
sstp ,
, learning listening
(forwarding).
sstp :
spanning-tree sstp forward-time sstp
. .
40
.466534.012-324
. . .
no spanning-tree sstp forward time
(15 )
9.1.4.7
.
.
:
spanning-tree port-priority value
spanning-tree sstp port-priority value sstp
no spanning-tree sstp port-priority
(128)
9.1.4.8
:
spanning-tree cost value
spanning-tree sstp cost value sstp
no spanning-tree sstp cost
9.1.4.9
6500.
BPDU -
, MSU.
STP.
,
6500 :
spanning-tree designated-auto
no spanning-tree designated-auto
9.1.4.10 STP
STP, -
:
show spanning-tree
show spanning-tree detail
show spanning-tree interface
. .
9.1.5 vLAN
9.1.5.1
SSTP .
vLAN. vLAN, -
SSTP vLAN .
. .
vLAN,
.
,
30 ; -
STP.
NX-5124G10 -
vLAN. , , -
.
.466534.012-324 41
. . .
STP VLAN.
spanning-tree vlan vlan-list vlan-list: vLAN ( )
SSTP 30 -
.
no spanning-tree vlan vlan-list
vLAN.
spanning-tree vlan vlan-list prior-
ity value vLAN.
no spanning-tree vlan-list priority .
spanning-tree vlan vlan-list for-
ward-time value VLAN.
no spanning-tree vlan vlan-list for-
ward-time VLAN.
spanning-tree vlan vlan-list max-age
VALN
value
no spanning-tree vlan vlan-list max-
age VLAN.
spanning-tree vlan vlan-list hello-
time value VLAN.
no spanning-tree vlan vlan-list
hello-time VLAN.
:
spanning-tree vlan vlan-list cost VLAN.
no spanning-tree vlan vlan-list cost VLAN.
spanning-tree vlan vlan-list port-
priority VLAN.
no spanning-tree vlan vlan-list
port-priority VLAN.
-
vLAN:
show spanning-tree vlan vlan-list VLAN
9.1.6 RSTP
/ RSTP
. .
9.1.7 RSTP
9.1.7.1 / RSTP
:
. .
spanning-tree mode rstp RSTP
no spanning-tree mode STP (SSTP)
9.1.7.2
,
. , -
.
:
spanning-tree rstp priority value
no spanning-tree rstp priority
. .
42
.466534.012-324
. . .
, MAC-
. , RSTP,
, .
32768.
9.1.7.3
,
. -
, . -
, . -
. -
, , ;
. -
. , , -
.
:
spanning-tree rstp forward-time value
no spanning-tree rstp forward-time (15)
, -
. , -
. -
.
(Forward Delay Time) 15
.
9.1.7.4
, -
, .
:
spanning-tree rstp hello-time value
no spanning-tree rstp hello-time
,
. , -
. ,
,
. .
4 .
9.1.7.5
. .
,
. -
.
:
spanning-tree rstp max-age value
. .
9.1.7.6
Ethernet . -
, . RST
Ethernet
.
. .
.466534.012-324 43
. . .
-
:
spanning-tree rstp cost value
no spanning-tree rstp cost
, Ethernet
. RSTP -
Ethernet.
, Ethernet 2000000, -
10 / 200000, 100/.
9.1.7.7
Ethernet , -
. , ,
. Ethernet , -
.
:
spanning-tree rstp port-priority value
no spanning-tree rstp port-priority
, Ethernet
.
Ethernet 128.
9.1.7.8
RST
802.1D STP, . STP,
STP, .
STP, RSTP
802.1D STP BPDU. span-
ning-tree rstp migration-check
RSTP.
:
, IEEE 802.1D 2004 RSTP, -
migration-check.
RSTP:
spanning-tree rstp migration-check
-
. .
:
spanning-tree rstp migration-check
9.2 MSTP
. .
9.2.1 MSTP
9.2.1.1
Multiple Spanning Tree Protocol (MSTP) -
LAN. MSTP (Spanning
Tree Protocol (STP)) (Rapid Spanning Tree Protocol (RSTP)).
STP
RSTP vLAN . STP -
. RSTP
.
MSTP RSTP
VLAN STP,
. , MSTP, VLAN
VLAN.
. .
44
.466534.012-324
. . .
PvSTP, MSTP VLAN STP,
STP, VLAN.
NX-5124G10 MSTP. , -
, .
9.2.1.2 MST
MSTP VLAN STP MSTP. -
MSTP, MST.
, MST -
, MST. MST
VLAN, VLAN MST.
9.2-1 MSTP
1. CIST
Common and Internal Spanning Tree (CIST) , -
LAN.
MST STP RSTP;
. .
.
, CIST CIST. -
CIST ,
CIST.
2. CST
(Common Spanning Tree). MST
. .
.466534.012-324 45
. . .
, . MSTI00, CIST, -
, .
9.2.1.4
MSTP , RSTP.
1.
9.2-2
,
.
2.
9.2-3
. -
,
, .
3.
. .
. .
9.2-4
LAN .
LAN .
. .
46
.466534.012-324
. . .
4.
9.2-5
LAN,
, . -
, .
5.
9.2-6
MST CIST.
CIST.
6.
CIST MSTI. CIST -
, MST. MSTI,
, .
7.
. .
RSTP MSTP, ,
. ,
.
. .
9.2-7
. .
.466534.012-324 47
. . .
, MTSP RSTP ,
. , BPDU ,
. 802.1D STP BPDU,
.
MSTI (MSTI Configuration Messages) 103~
9.2-2 MST
MSTI (MSTI FLAGS) 1
MSTI (MSTI Regional Root Identifier) 2-9
MSTI (MSTI Internal Root Path Cost) 10 - 13
MSTI (MSTI Bridge Priority) 14
. .
MSTI (MSTI Port Priority) 15
MSTI (MSTI Remaining Hops) 16
9.2.1.6
MSTP
BPDU, .
. .
1) CIST .
2) LAN
CIST, .
3) , CIST -
.
4) MSTI MSTI.
5) LAN
MSTI.
6) CIST
CIST CIST.
7) CIST LAN
CIST.
8) , ,
LAN .
9) MSTI MSTI.
. .
48
.466534.012-324
. . .
10) MSTI MSTI.
11) CIST. -
CIST MSTI .
9.2.1.7
STP RSTP, MSTP STP (Hop Count)
Message Age Max Age BPDU.
, MSTP
. BPDU -
CIST MSTI .
0, .
9.2.1.8 STP
MSTP STP
. STP, -
STP. , , STP,
.
:
, STP, -
MSTP, STP. , -
spanning-tree mstp migration-check STP, ,
the MSTP.
, RSTP,
MSTP. , MSTP -
RSTP.
9.2.2 MSTP
MSTP
MSTP
MSTP
STP
MST
9.2.2.1 MST
MSTP, , IEEE 802.1s.
. .
MST -
, MSTP. ,
. ,
MSTP, CIST, -
.
. .
.466534.012-324 49
. . .
MST , -
BPDU RSTP BPDU.
, MST, .
-
MST BPDU, .
migration-check.
MSTP
9.2.3 MSTP
9.2.3.1 MSTP
STP SSTP (PVST, RSTP MSTP )
MAC-
0
MST VLANs CIST (MST00)
(CIST MSTI) 32768
(CIST MSTI) 128
1000 /: 20000
(CIST MSTI) 100 /: 200000
10 /: 2000000
(Hello Time) 2
15
20
20
9.2.3.2 MSTP
STP PVST SSTP . -
, .
STP MSTP :
spanning-tree STP
spanning-tree mode mstp MSTP
STP :
no spanning-tree STP
9.2.3.3 MST
MST, , : ,
. .
, VLAN MSTI. -
. ,
, .
MST -
MAC- . VLANs CIST (MST00). 0 VLAN
CIST (MST00). MAC-,
MSTP . span-
. .
.
MAC-
no spanning-tree mstp name MST
MST.
spanning-tree mstp revision value value , 0 65535.
0.
No spanning-tree mstp revision MST
. .
50
.466534.012-324
. . .
instance-id -
, MSTI. 1 15.
spanning-tree mstp instance in- vlan-list vlan,
stance-id vlan vlan-list 1 4094. instance-id -
, ;
vlan-list vlan,
1,2,3, 1-5, 1,2,5-10 ..
VLAN MSTI
no spanning-tree mstp instance in- . instance-id -
stance-id , MSTI. 1
15.
MSTP :
show spanning-tree mstp region MSTP
9.2.3.4
MSTP ID ,
MAC- .
ID .
MSTP . -
32768..
,
, Spanning-tree mstp in-
stance-id root.
, ID
ID 24576, 24576 ,
.
24576, MSTP
4096 , . -
, 4096 .
, diameter -
. ID 0.
, MSTP
STP , ,
. Hello-time
.
:
-
instance-id
spanning-tree mstp instance-id root
primary [diameter net- , 0 15.
. .
MSTP :
show spanning-tree mstp[instance in-
stance-id] MSTP
9.2.3.5
, spanning-tree mstp instance-id
root secondary,
.
, .
, MSTP -
28672. ,
32768, .
. .
.466534.012-324 51
. . .
diameter hello-
time STP. -
, .
:
spanning-tree mstp instance-id root
secondary instance-id -
[diameter net-diameter [hello-time sec- , 0 15
onds]] net-diameter (-
), instance-id
0; 2 7.
No spanning-tree mstp instance-id root instance-id -
, 0 15.
MSTP :
show spanning-tree mstp
[instance instance-id] MSTP
9.2.3.6
, , -
root. -
.
:
instance-id -
spanning-tree mstp instance-id pri- , 0 15; value -
ority value ; -
: 0, 4096, 8192, 12288, 16384, 20480, 24576, 28672, 32768,
36864, 40960, 45056, 49152, 53248, 57344, 61440
no spanning-tree mstp instance-id .
priority instance-id
, 0 15.
9.2.3.7 STP
STP:
Hello Time ( )
,
. .
.
Forward Delay ( )
, , Blocking learning for-
warding STP.
Max Age ( )
-
. .
:
2 x (fwd_delay 1.0) >= max_age
max_age >= (hello_time + 1) x 2
, MSTP:
:
52
.466534.012-324
. . .
:
spanning-tree mstp max-age seconds 6 40 ; - 20
.
no spanning-tree mstp max-age -
.
STP -
.
-
.
.
9.2.3.8
.
.
MSTP, spanning-tree mstp diameter net-
diameter. CIST.
STP .
:
spanning-tree mstp diameter net- .
net diameter 2 7;
diameter
7.
no spanning-tree mstp diameter net diameter
.
.
9.2.3.9
(maximum hops) .
spanning-tree mstp max-hops hop- .
count hop count 1 40; -
20.
9.2.3.10
, -
(forwarding), -
. ,
. .
forwarding.
, MSTP:
STP
instance-id
spanning-tree mstp instance-id port-priority , 0 15.
. .
priority ; -
priority
:
0, 16, 32, 48, 64, 80, 96, 112
128, 144, 160, 176, 192, 208, 224, 240
-
.
spanning-tree port-priority value value -
:0, 16, 32, 48, 64, 80, 96, 112
.466534.012-324 53
. . .
show spanning-tree mstp interface MSTP
interface-id ,
interface-id
F0/1, FastEtnernet0/3 ..
9.2.3.11
MSTP . -
, -
. , . -
, .
:
spanning-tree mstp instance-id cost cost instance-id -
, 0 15.
-
spanning-tree cost value .
value .
1 200000000.
no spanning-tree mstp instance-id cost -
no spanning-tree cost -
9.2.3.12
, MSTP -
-,
(handshake mechanism). ,
-.
, -
. , -
-. ,
.
, , RSTP MSTP, -
point-to-point, -
.
, :
spanning-tree mstp point-to-point force-true -.
spanning-tree mstp point-to-point force-
false (shared)
spanning-tree mstp point-to-point auto
. .
no spanning-tree mstp point-to-point
9.2.3.13 MST
MSTP, , IEEE 802.1s.
MSTPs, MSTP, Cisco,
. .
MSTP , MST. , , -
MSTP, MSTP, -
MST MST.
, MST, , STP, -
MSTP. BPDU ,
BPDU .
MST, spanning-tree mstp migration-check.
, MST,
:
spanning-tree mstp mst-compatible MST
no spanning-tree mstp mst-compatible MST
:
. .
54
.466534.012-324
. . .
MST -
, MSTP. ,
. ,
MSTP, CIST, -
.
MST , -
BPDU RSTP BPDU.
, MST, .
-
MST BPDU, .
migration-check.
9.2.3.14
MSTP STP -
. STP,
STP. STP . -
, STP, .
:
, STP,
MSTP, STP; STP,
, MSTP, spanning-tree
mstp migration-check .
RSTP,
MSTP. , MSTP -
RSTP.
STP, , -
:
spanning-tree mstp migration-check STP,
STP, ,
:
spanning-tree mstp migration-check STP,
9.2.3.15 MSTP
MSTP, ,
:
show spanning-tree MSTP ( SSTP, PVST,
. .
RSTP MSTP)
show spanning-tree detail STP (
SSTP, PVST, RSTP MSTP)
show spanning-tree interface interface-id STP ( SSTP,
PVST, RSTP MSTP)
show spanning-tree mstp MST
show spanning-tree mstp region MST
. .
.466534.012-324 55
. . .
10 STP
10.1 STP
10.1.1 STP.
( ); .
:
-
Single STP PVST RSTP MSTP
Port Fast
BPDU Guard
BPDU Filter
Uplink Fast
Backbone Fast
Root Guard
Loop Guard
. .
. .
56
.466534.012-324
. . .
.
BPDU guard Port Fast. STP
BPDU Guard BPDU , -
BPDU. RSTP/MSTP BPDU Guard
, , , , BPDU.
BPDU Guard -
. spanning-tree portfast bpduguard -
, BPDU . , -
BPDU guard .
10.1-2
. .
( Direct Link
Failure), STP ,
Forwarding, Listening Learning.
Uplink Fast spanning-tree uplinkfast
, , -
.
10.1-3 Uplink Fast. -
C B , .
C A, -
, .
. .
.466534.012-324 57
. . .
10.1-3 Uplink Fast
:
Uplink Fast SSTP PVST.
RSTP MSTP, Uplink
Fast.
c ; Uplink
Fast. L1 A B C.
L1 ,
backbone fast.
Backbone Fast 10.1-4.
. .
. .
58
.466534.012-324
. . .
, C , B.
L1, B bpdu C, -
. C , bpdu -
. Backbone Fast ,
C B
. . -
spanning-tree backbonefast,
C BPDU , C -
, indirect-link root-switch-reachable ; C
, .
Backbone Fast, BPDU -
, . ,
. -
, .
, Backbone Fast . -
: listening,
learning forwarding.
Uplink Fast, Backbone Fast SSTP PVST.
.
PVST MSTP Loop Guard
. MSTP, Loop Guard CIST,
MSTI.
:
Loop Guard SSTP/PVST RSTP/MSTP. SSTP/PVST,
Loop Guard, RSTP/MSTP,
10.1.2 STP
10.1.2.1 STP
Port Fast
. .
.466534.012-324 59
. . .
BPDU Guard
BPDU Filter
Uplink Fast
Backbone Fast
Root Guard
Loop Guard
BPDU Guard :
spanning-tree portfast bpduguard bpdu guard,
no spanning-tree portfast bpduguard bpdu guard
:
port fast . BPDU
. .
Guard BPDU Filter .
BPDU guard :
spanning-tree bpduguard enable bpdu guard
spanning-tree bpduguard disable bpdu guard
. .
Filter:
spanning-tree portfast bpdufilter BPDU Filter,
no spanning-tree portfast bpdufilter bpdu filter
:
port fast . BPDU
. .
60
.466534.012-324
. . .
Guard BPDU Filter .
BPDU filter :
spanning-tree bpdufilter enable bpdu filter
spanning-tree bpdufilter disable bpdu filter
no spanning-tree bpdufilter bpdu filter
.
Loop Guard SSTP/PVST RSTP/MSTP. SSTP/PVST,
Loop Guard, RSTP/MSTP,
- BPDU. Loop Guard ,
- BPDU .
Loop
Guard:
spanning-tree loopguard default Loop Guard, -
.
no spanning-tree loopguard default loop guard.
loop guard :
. .
.466534.012-324 61
. . .
spanning-tree guard loop loop guard .
no spanning-tree guard root guard loop guard .
spanning-tree guard none root guard loop guard .
. .
. .
. .
62
.466534.012-324
. . .
11 MAC-
11.1 MAC-
- :
-
-
-
-
11.2 MAC-
11.2.1 Mac-
MAC- , .
. ,
MAC-. MAC-
.
Configure
/ MAC-
[no] mac address-table static mac- mac-addr MAC-;
addr vlan vlan-id interface inter- Vlan-id VLAN; -
face-id 1 4094;
interface-id .
exit .
write .
11.2.2 MAC-
MAC- , -
MAC- MAC-. MAC-
; 300
.
MAC- -
:
configure
-.
mac address-table aging-time [0 | 0 , MAC- .
10-1000000] -: 10
1000000 .
exit .
write .
. .
11.2.3 - VLAN
- VALN, - VALN - -
VLAN. VLAN -.
- VALN :
. .
configure
interface f0/1 ,
switchport shared-learning - VALN
exit .
exit .
write .
11.2.4 MAC-
, -
MAC- . MAC-
show.
. .
.466534.012-324 63
. . .
MAC-
dynamic -, -
.
show mac address-table {dynamic [inter-
face interface-id | vlan vlan-id] | Vlan-id VLAN; -
static} 1 4094.
Interface-id .
Static MAC-
11.2.5 MAC-
MAC- .
MAC-
:
MAC-
dynamic -, -
clear mac address-table dynamic [address .
mac-addr | interface interface-id | vlan Mac-addr MAC-;
vlan-id] Interface-id .
Vlan-id VLAN; -
1 4094.
. .
. .
. .
64
.466534.012-324
. . .
12
.
12.1
- -
. -
. -
, , LACP.
:
, , ,
, -
.
LACP
, LACP,
. .
-
.
12.2
,
12.3
12.3.1 ,
, -
.
:
interface port-aggregator id
12.3.2
-
LACP .
,
, VLAN , , -
. .
, .
, , -
, LACP.
, -
( ). -
, , -
-
. .
. vlan
.
LACP .
, -
. , -
, , .
VLAN: PVID, , VLAN (vlan-
allowed) VLAN (vlan-untagged).
:
aggregator-group agg-id mode { lacp | static }
. .
.466534.012-324 65
. . .
12.3.3
,
.
.
src-mac
MAC-,
MAC- .
dst-mac
MAC- ,
, MAC- .
both-mac
MAC- MAC-
, MAC-
.
src-ip
IP-,
IP- .
dst-ip
IP- , ,
IP- .
both-ip
IP- IP-
, IP-
.
:
aggregator-group load-balance
:
,
. , ,
, . -
, :
src-mac dst-mac both-mac src-ip dst-ip both-ip
NX-5124G 10
12.3.4
-
:
show aggregator-group
. .
. .
. .
66
.466534.012-324
. . .
13 GVRP
13.1
GVRP ( , , -
vlan (garp vlan registration protocol GARP VLAN) -
GARP ( ). GVRP GARP
VLAN . GVRP -
VLAN -
VLAN, VLAN, .
GVRP
VLAN ( VLAN VLAN )
, VLAN
GVRP .
13.2
13.2.1 GVPR
/ GVPR
/ GVPR
GVRP
13.3 GVPR
13.3.1 / GVPR
:
[no] gvrp / GVRP
: GVRP .
13.3.2 / GVPR
:
[no] gvrp / GVPR
GVRP , ; GVRP
. GVRP
; GVRP .
: GVRP .
13.3.3 GVRP
.
. .
GVRP.
switch#show gvrp statistics interface Tthernet0/1
GVRP statistics on port Ethernet0/1
GVRP Status: Enabled
GVRP Failed Registrations: 0
GVRP Last Pdu Origin: 0000.0000.0000
GVRP Registration Type: Normal
GVRP.
switch#show gvrp status gvrp is enabled!
13.4
:
VLAN A B, GVRP A -
B.
. .
.466534.012-324 67
. . .
8 :
Switch_config_f0/8# switchport mode trunk
GVRP A
Switch_config#gvrp
GVRP 8 A
Switch_config_f0/8#gvrp
VLAN 10, VLAN 20 VLAN 30 A
Switch_config#vlan 10
Switch_config#vlan 20
Switch_config#vlan 30
9 :
Switch_config_f0/9# switchport mode trunk
GVRP
Switch_config#gvrp
GVRP 9
Switch_config_f0/9#gvrp
VLAN 40, VLAN 50 VLAN 60
Switch_config#vlan 40
Switch_config#vlan 50
Switch_config#vlan 60
, VLAN
A B. VLAN10, VLAN20, VLAN30, VLAN40, VLAN50 VLAN60
.
. .
. .
. .
68
.466534.012-324
. . .
14 IGMP-SNOOPING
14.1 IGMP-snooping
IGMP VLAN -
VLAN.
. -
IGMP ,
VLAN, IGMP IGMP
.
, IGMP , -
, IGMP-
, ,
IGMP . , IGMP-
-
. show ip igmp-snooping -
VLAN igmp-snooping.
/ IGMP-snooping VALN
/ VLAN
VLAN
IGMP-snooping
IGMP-snooping
IGMP-snooping
IGMP-snooping
IGMP-snooping
: IGMP-snooping 16 VLAN.
IGMP-snooping VLAN3, no ip IGMP-
snooping, IGMP-snooping VLAN, ip IGMP-snooping VLAN 3
.
14.1.2 / VLAN
, IGMP,
.
. .
:
ip igmp-snooping vlan vlan_id static
A.B.C.D interface intf VLAN
no ip igmp-snooping vlan vlan_id static
A.B.C.D interface intf VLAN
. .
14.1.3 VLAN
(immediate-leave),
leave; , -
, , -
.
, ;
, immediate-leave .
:
ip igmp-snooping vlan vlan_id immediate-leave VLAN
no ip igmp-snooping vlan vlan_id immediate- VLAN
leave
VLA
. .
.466534.012-324 69
. . .
14.1.4
, (DHL,
igmp-snooping),
VLAN.
, ,
.
ip igmp-snooping dlf-frames filter ,
no ip igmp-snooping dlf-frames ()
:
VLAN.
(
VLAN).
14.1.5 IGMP-snooping
(Router Age) IGMP.
IGMP -
. IGMP .
:
ip igmp-snooping timer router-age IGMP-
timer_value snooping
no ip igmp-snooping timer router-age IGMP-
snooping
:
IGMP inquirer. -
.
260 .
14.1.6 IGMP-snooping
(response time)
IGMP inquirer . -
, .
:
ip igmp-snooping timer response-time
timer_value IGMP-snooping
. .
:
; , -
. 10 .
14.1.7 IGMP-snooping
VLAN,
. .
IGMP-snooping, IGMP-snooping
IGMP query.( ,
VLAN, IGMP-snooping ).
LAN
, IGMP
snooping, IGMP snooping.
:
[no] ip igmp-snooping querier [address IGMP-snooping -
[ip_addr] address Ip- -
IGMP-snooping .
(Pseudo Query packet) - 10.0.0.200.
:
. .
70
.466534.012-324
. . .
, -
VLAN.
.
14.1.8 IGMP-snooping
:
show ip igmp-snooping IGMP-snooping
show ip igmp-snooping timer IGMP-snooping
show ip igmp-snooping groups IGMP-snooping
show ip igmp-snooping statistics IGMP-snooping
/ IGMP-
[ no ] debug ip igmp-snooping [ packet | snooping ////.
timer | event | error ] ,
/.
VLAN IGMP-snooping:
IGMP-snooping:
IGMP-snooping:
IGMP-snooping:
. .
. .
IGMP-snooping:
. .
.466534.012-324 71
. . .
IGMP-snooping:
14.1.9 IGMP-snooping
:
(1) IGMP-snooping VLAN 1,
Switch_config#ip igmp-snooping vlan 1
(2) IGMP-snooping VLAN 2,
Switch_config#ip igmp-snooping vlan 2
. .
. .
. .
72
.466534.012-324
. . .
15 802.1
15.1 802.1
802.1
802.1
802.1
802.1
802.1
802.1
802.1
802.1
802.1
VLAN
802.1
802.1
15.2 802.1
15.2.1 802.1
802.1x : , -
802.1x.
, -
. .
.
, ,
.
.
802.1x , 802.1x
.
. 802.1x ,
AAA.
802.1x :
dotlx enable 802.1
802.1:
dotlx port-control auto 802.1
aaa authentication dotlx {default |list
802.1
name} method
802.1
. .
:
dot1x port-control auto 802.1x
dot1x port-control force-authorized
dot1x port-control force-unauthorized
. .
15.2.2 802.1
802.1x . -
.
, -
.
, 802.1 (, 1108).
-
.
802.1x,
. , ( -
MAC- ). , 802.1x ,
- . -
- , MAC- .
802.1 -
:
. .
.466534.012-324 73
. . .
()
dot1x multiple-hosts
802.1
15.2.3 802.1
802.1x 802.1x, -
. - -
, - . -
, 802.1x , -
.
, .
:
,
dot1x max-req count EAP-
request/identity
15.2.4 802.1
-
. -
.
-
.
:
( -
dot1x re-authentication
)
dot1x timeout re-authperiod time
-
dot1x reauth-max time
15.2.5 802.1
802.1 .
802.1x ,
.
:
dot1x timeout tx-period time 802.1
. .
15.2.6 802.1
802.1 ,
. 802.1
:
dot1x user-permit xxxz
. .
15.2.7 802.1
802.1 -
. default 802.1.
802.1
:
dot1x authentication method yyy 802.1
15.2.8 802.1
802.1;
Chap Eap (eap md5-challenge eap-tls), .
Challenge, MD5, Chap,
. .
74
.466534.012-324
. . .
challenge eap. -
-
. ,
, No .
Eap-tls
handshake Translation Layer Security (tls),
.
802.1
:
dot1x authen-type {chapjeap} chap eap
:
dot1x authentication type {chapjeap} chap, eap
15.2.9 802.1
802.1 .
dot1x 802.1 , .
,
.
. -
.
, dot1x AAA -
update . ,
.
dot1x, , -
- (supplicant).
dot1x -
:
dot1x accounting enable 802.1
; -
dot1x accounting method {method name}
default
VLAN, -
:
Dot1x guest-vlan guest-vlan
0. -
, .
. .
guest-vlan id .
guest-vlan id:
VLAN VLAN
Dot1x guest-vlan {id(1-4094)}
802.1. 1 4094
15.2.11
(Supplicant) .
:
dot1x forbid multi-network-adapter
. .
.466534.012-324 75
. . .
15.2.12 802.1
. -
:
dot1x default 802.1
15.2.13 802.1
802.1 -
:
show dot1x {interface ....} 802.1
15.3 802.1x
:
aaa authentication dot1x TST-F0/10 radius
aaa authentication dot1x TST-F0/12 local
interface VLAN1
ip address 192.168.20.24 255.255.255.0
radius-server host 192.168.20.2 auth-port 1812 acct-port 1813
radius-server key TST
2. F0/10
interface FastEthernet0/10
. .
dot1x port-control auto
dot1x authentication method TST-F0/10
dot1x user-permit radius-TST
3. F0/12
interface FastEthernet0/12
dot1x Multiple-host dot1x port-control auto
. .
76
.466534.012-324
. . .
16 -
:
MAC-
-
MAC-
16.1 -
16.1.1 MAC-
.
- .
MAC-
.
Configure
/ -
[no] mac access-list name
16.1.2 -
permit/deny , -
. -
-. -
.
-
.
-
permit deny
[no] {deny | permit} {any | host src-mac-
- - -
addr} {any | host dsf-mac-addr} [ether-
- .
type]
ethertype
Ethernet
-
exit
-
exit
write
Switch_config#mac acce 1
Switch-config-macl#permit host 1.1.1 any
Switch-config-macl#permit host 2.2.2 any
- -
. .
. .
16.1.3 -
- -
. - -
.
. .
Configure
-
.
[no] mac access-group name
name -
.
exit .
exit .
write .
. .
.466534.012-324 77
. . .
17 IP-
17.1 IP-
17.1.1 IP
,
.
. :
-
, IP- .
IP- , -
. ROS
. , : . -
, -
. , .
:
(1) .
(2) .
17.1.2 IP-
IP-. :
, .
:
ip access-list standard name name -
IP
deny {source [source-mask] | any} or per-
mit {source [source-mask] | any}
exit
:
ip access-list extended name name -
IP
{deny | permit} protocol source source-
mask destination destination-mask [prece-
dence precedence] [tos tos] . ( precedence -
{deny | permit} protocol any any IP ; TOS )
. .
exit
, ( ) -
. , add access list -
. no permit no deny -
.
:
,
. .
deny. IP-
, 255.255.255.255 .
,
IP- .
17.1.3 IP-
.
:
ip access-group name
,
. ,
. , -
. .
78
.466534.012-324
. . .
. ICMP, ,
-.
, .
17.1.4
,
SMTP 130.2.1.2.
ip access-list extended aaa
permit tcp any 130.2.1.2 255.255.255.255 eq 25
interface g0/10
ip access-group aaa
. .
. .
. .
.466534.012-324 79
. . .
18
18.1 IP-
18.1.1
18.1.1.1 IP-
(Internet protocol - IP) - ,
. IP , -
. IP- (-
IP ). , IP -
, .
(Transmission Control Protocol (TCP)) IP. TCP -
, , ,
. ,
, . TCP
, -
.
IP-, (Address Resolution Protocol (ARP)),
IP-. IP-, ICMP, HSRP, IP- -
IP-.
18.1.1.2 IP-
IP- , -
.
IP 2 : Interior Gateway Protocol (IGP) Exterior
Gateway Protocol (EGP). RIP,
OSPF, BGP BEIGRP. RIP, OSPF, BGP BEIGRP -
. , ,
,
OSOF ( ), BGP, RIP, BEIGRP.
redistribute, -
,
.
,
, . -
, , -
.
1.
.
.
. .
, , -
.
. .
2.
IGP . IP
(, ) -
. -
, .
IGRP:
RIP
OSPF
BEIGRP
3.
EGP -
. , , -
, . EGRP,
BGP.
. .
80
.466534.012-324
. . .
18.1.2 IP-
IP IP -
. -
, IP. IP
.
IP- . , -
.
, IP- , IP .
IP-:
IP-
IP-
IP-
18.1.3 IP-
18.1.3.1 IP-
IP- IP . IP- -
. -
IP 1, IP-
.
0.0.0.0
1.0.0.0 126.0.0.0
127.0.0.0
128.0.0.0 191.254.0.0
191.255.0.0
192.0.0.0
192.0.1.0 223.255.254
223.255.255.0
D 224.0.0.0 239.255.255.255
240.0.0.0 255.255.255.254
E
255.255.255.255
IP-.
: ,
.
18.1.3.2 IP-
IP-, IP- -
. .
IP-. IP-
:
IP . ,
254 IP-,
300 . IP-
.
2 , -
. IP-
.
, IP.
, -
IP-, -
.
:
,
IP- .
. .
.466534.012-324 81
. . .
,
:
ip address ip-address mask secondary IP-
:
IP -
.
18.1.3.3
IP IP- . -
, :
1.
IP- ( -
), ( , -
). , -
, .
MAC- , MAC
.
, Ethernet ,
48- MAC- .
IP- . IP-
.
: (Ad-
dress Resolution Protocol (ARP)) -ARP. RFC 826 1027.
ARP IP- MAC-. IP-
ARP -. MAC-
, IP- MAC- ARP . IP-
.
ARP
ARP
IP- . -
, ARP. , -
ARP.
, 32- IP- 48 .
, , ARP -
.
ARP , ARP.
, IP / .
:
arp ip-address hardware-address IP- ARP
. .
arp ip-address hardware-address alias
ARP- IP-
:
arp timeout seconds ARP
show interfaces - ARP -
. Use show arp, ARP. -
. .
, . -ARP .
-ARP, -
:
ip proxy-arp ARP
Free ARP
. .
82
.466534.012-324
. . .
, IP- , -
ARP. IP- ARP
. - MAC- .
ARP . -
ARP, IP- IP-,
ARP , ARP -
IP-. , .
ARP . Free
ARP , .
arp send-gratuitous ARP
arp send-gratuitous interval value ARP -
; : 120 .
2. IP-
IP- , .
Telnet, Ping .
IP-,
:
ip host name address IP
18.1.3.4
. -
-. IP- , BGP, RIP OSPF, , -
.
18.1.3.5
-
. . -
, -
. IP
. ,
. .
IP -
. , . -
, .
1. -
IP- -
. "Deny of Service" IP-
. .
.
-
. ,
, ,
, .
. , IP- -
. .
-
.
IP, -
:
ip directed-broadcast [access-list-name]
2. UDP
UDP , -
. , , UDP -
, . , -
-
. .
UDP, , UDP
. .
.466534.012-324 83
. . .
. , UDP, -
NetBIOS ( 137).
,
:
ip helper-address address
UDP
, , -
:
ip forward-protocol udp [port] ,
18.1.3.6 IP-
, :
1. ,
, . -
, ,
.
, , EXEC,
:
clear arp-cache IP ARP
2.
, IP-
, . -
.
, .
.
" IP-". :
show arp ARP
,
show hosts ,
show ip interface [type number]
show ip route [protocol]
ping {host | address} (
)
. .
18.1.4 IP-
IP VLAN 11.
interface vlan 11
ip address 202.96.2.3 255.255.255.0
. .
18.2 NAT
18.2.1
, -
IP . NAT - , IP-
IP- , -
. , NAT -
-
. NAT ,
-
(CIDR). NAT RFC 1631.
18.2.1.1 NAT
(NAT) -
. .
84
.466534.012-324
. . .
:
, -
. NAT IP , -
IP , . NAT
( ) , -
( ). NAT -
IP .
. ,
, NAT.
TCP.
IP- IP- TCP.
, NAT -
-
. , IP
IP-, .
.
18.2.1.2 NAT
NAT ,
. , NAT ,
. -
, , IP-,
NAT. ( -
) NAT. NAT , , -
.
NAT
. NAT
. NAT -
, . NAT -
, .
, NAT . -
, ,
ICMP .
NAT .
, , NAT , ,
, .
18.2.1.3 NAT
, (inside) , -
. , -
; ,
NAT. , -
.
, (outside) , -
. .
. ,
/ -
.
, NAT :
: IP-, . ,
, IP- (NIC)
.
. .
IP- ( NIC ), -
IP .
: IP- .
, -
.
: IP-, .
.
18.2.1.4 NAT
NAT NAT -
. NAT : ,
. -
. -
, NAT- :
. .
.466534.012-324 85
. . .
TCP/UDP
PAT
, -
, , , .
show running NAT.
18.2.2 NAT
NAT, -
. , NAT -
:
TCP
NAT
18.2.3 NAT
18.2.3.1
, IP-
IP-. -
.
-
. -
, .
.
, -
.
18.2-1 NAT
. .
, .
1.1.1.1 B.
. .
, 1.1.1.1, -
NAT .
, 3.
,
(SA) 1.1.1.1. -
, , , , .
, -
1.1.1.1 .
86
.466534.012-324
. . .
.
1.
,
:
ip nat inside source static local-ip -
global-ip
interface type number
ip nat inside ,
interface type number
ip nat outside ,
. -
.
2.
, -
:
ip nat pool name start-ip end-ip netmask , -
ip access-list standard access-list-name
permit source [source-mask]
ip nat inside source list
access-list-name pool name ,
interface type number
ip nat inside ,
interface type number
ip nat outside ,
:
, . (-
, deny all .) ,
, .
"
" .
18.2.3.2
, -
. -
(, TCP UDP)
. -
. .
, TCP UDP -
.
NAT, -
.
. .
18.2-2 NAT
.
. .
.466534.012-324 87
. . .
B C , 2.2.2.2. -
, . ,
IP- .
1.1.1.1 B.
, 1.1.1.1,
NAT. , , -
1.1.1.1
1.1.1.1 . , -
. -
, . -
.
,
1.1.1.1 .
B 1.1.1.1, IP-
2.2.2.2.
IP-, -
NAT, , ,
, -
1.1.1.1 1.1.1.1.
1.1.1.1 . -
.
overloadeding ,
:
ip nat pool name start-ip end-ip netmask , -
ip access-list standard access-list-name
permit source [source-mask]
:
, . (-
, deny all .) ,
, .
.
18.2.3.3
. .
, -
, . , NAT -
.
. .
18.2-3 NAT
. .
88
.466534.012-324
. . .
, :
1.1.1.1 C, -
, DNS.
DNS- C 1.1.1.1. DNS -
.
1.1.1.1 3.3.3.3.
.
,
.
IP- , 1.1.1.1 C, -
3.3.3.3.
, ,
.
C .
1.
, -
:
ip nat outside source static global-ip -
local-ip
interface type number
ip nat inside
interface type number
ip nat outside ,
2.
,
:
ip nat pool name start-ip end-ip netmask
ip access-list standard access-list-name
:
, . (-
, deny all .) ,
, .
-
.
. .
18.2.3.4 TCP
NAT -. -
, . -
NAT , -
. , ,
. ,
.
( ). -
.
. .
.466534.012-324 89
. . .
18.2-4 NAT TCP
, :
B (9.6.7.3)
1.1.1.127.
,
(1.1.1.1) IP-.
.
1.1.1.1 .
NAT ,
, .
.
1.1.1.2
. ,
.
. TCP -
.
ip nat pool name start-ip end-ip netmask ,
ip access-list standard access-list-name
permit source [source-mask]
. .
ip nat inside destination list access-
list-name pool name , ,
interface type number
ip nat inside ,
interface type number
. .
ip nat outside ,
:
, . (-
, deny all .) ,
, .
TCP -
.
18.2.3.5
, , -
. , . -
, 1 . ,
:
. .
90
.466534.012-324
. . .
ip nat translation timeout seconds
, ,
. , -
.
ip nat translation udp-timeout seconds UPD ( 5 )
ip nat translation dns-timeout seconds DNS ( 1 )
ip nat translation tcp-timeout seconds - TCP ( 1 )
ip nat translation icmp-timeout seconds NAT ICMP ( 60 )
ip nat translation syn-timeout seconds NAT TCP SYN ( 60 -
)
ip nat translation finrst-timeout seconds TCP FIN RST ( 1 -
)
NAT.
:
ip nat translation max-entries numbers NAT (
4000)
ip nat translation max-links A.B.C.D num- IP-,
ber NAT
IP-
IP-, -
ip nat translation max-links all numbers NAT
IP-;
Max-
18.2.3.6 NAT
-
NAT . .
18.2.4 NAT
NAT.
18.2.4.1
, 1
(192.168.1.0/24), Net-208. NAT
171.69.233.208 171.69.233.233.
ip nat pool net-208 171.69.233.208 171.69.233.233 255.255.255.240
ip nat inside source list a1 pool net-208
!
interface vlan10
ip address 171.69.232.182 255.255.255.240
. .
.466534.012-324 91
. . .
ip nat outside
!
interface vlan11
ip address 192.168.1.94 255.255.255.0
ip nat inside
!
ip access-list standard a1
permit 192.168.1.0 255.255.255.0
!
18.2.4.2
net-208, 171.69.233.208 171.69.233.233.
1 192.168.1.0 192.168.1.255. -
, 1
. ( 192.168.1.0 192.168.1.255),
. ,
.
ip nat pool net-208 171.69.233.208 171.69.233.233 255.255.255.240
ip nat inside source list a1 pool net-208 overload
!
interface vlan10
ip address 171.69.232.182 255.255.255.240
ip nat outside
!
interface vlan11
ip address 192.168.1.94 255.255.255.0
ip nat inside
!
ip access-list standard a1
permit 192.168.1.0 255.255.255.0
!
18.2.4.3
, -
. , .
Net-10 IP-. ip nat outside source list 1 pool
net-10 .
ip nat pool net-208 171.69.233.208 171.69.233.223 255.2555.255.240
ip nat pool net-10 10.0.1.0 10.0.1.255 255.255.255.0
ip nat inside source list a1 pool net-208
ip nat outside source list a1 pool net-10
!
interface vlan10
ip address 171.69.232.192 255.255.255.240
ip nat outside
!
. .
interface vlan11
ip address 192.168.1.94 255.255.255.0
ip nat inside
!
ip access-list standard a1
permit 192.168.1.0 255.255.255.0
!
. .
18.2.4.4 TCP
, , -
. .
. 1/0 ( -
) TCP .
ip nat pool real-hosts 192.168.15.2 192.168.15.15 255.255.255.240
92
.466534.012-324
. . .
ip nat inside
!
ip access-list standard a2
permit 192.168.15.1 255.255.255.0
18.3 DHCP
18.3.1
(DHCP (Dynamic Host Configuration Protocol)) -
, IP- ,
TCP/IP. DHCP RFC 2131. DHCP -
IP- . DHCP IP-:
DHCP- IP- . -
DHCP- IP-
.
DHCP- IP- DHCP
.
18.3.1.1 DHCP
DHCP. DHCP .
DHCP IP-, -
(, ) -
Ethernet.
, DHCP, DHCP -
, IP DHCP -
.
18.3.1.2 DHCP
, DHCP -
Ethernet. :
IP DHCP -
18.3.1.3 DHCP
DHCP /, , DHCP- DHCP-
DHCP .
. .
DHCP-
(, IP-, -
..) DHCP.
DHCP-
IP- DHCP- -
.
, -
. .
DHCP.
- , , -
IP-. IP- DHCP-
. ,
DHCP- .
18.3.2 DHCP-
18.3.2.1 DHCP-
IP-
DHCP-
DHCP
DHCP
. .
.466534.012-324 93
. . .
18.3.2.2 DHCP-
1. IP-
IP- DHCP. -
VLAN.
ip address dhcp IP- Ethernet DHCP
2. DHCP-
DHCP- , ,
. -
:
ip dhcp-server ip-address IP- DHCP
get an IP address.
3. DHCP
, DHCP . -
.
ip dhcp client minlease seconds
ip dhcp client retransmit count
ip dhcp client select seconds SELECT
, , get an IP ad-
dress.
4. DHCP
DHCP- ( ),
, . -
:
Show dhcp server DHCP-, -
DHCP-, , -
. :
Show dhcp lease IP- , -
, show interface : IP-
Ethernet DHCP IP-
Ethernet.
. .
18.3.2.3 DHCP-
NAT. IP-
IP Ethernet 1/1
DHCP.
interface vlan 11 ip address dhcp
. .
18.3.3 DHCP-
18.3.3.1 DHCP
DHCP-
DHCP-
ICMP
DHCP-
DHCP-
DHCP-
DHCP-
18.3.3.2 DHCP-
1. DHCP-
IP- DHCP- DHCP- -
. .
94
.466534.012-324
. . .
(DHCP- .
, , -
ip helper-address DHCP ):
ip dhcpd enable DHCP-
2. DHCP-
IP- DHCP-, DHCP-
, :
ip dhcpd disable DHCP-
3. ICMP
ICMP, -
.
ICMP , -
:
ip dhcpd ping packets pkgs ICMP
ICMP , -
:
ip dhcpd ping timeout timeout ICMP
4.
,
. :
ip dhcpd write-time time -
5. DHCP-
DHCP-, -
:
ip dhcpd pool name DHCP-
DHCP
6. DHCP-
DHCP, -
. , , -
. .
.
network ip-addr netsubnet
, ,
.
. .
range low-addr high-addr , -
DNS-, -
default-router ip-addr... , -
, -
dns-server ip-addr... DNS- .
. .
.466534.012-324 95
. . .
domain-name name ,
,
lease {days [hours][minutes] | infi- , -
nite}
NetBIOS,
netbios-name-server ip-addr... NetBIOS, -
, : IP-
, Mac- - " ".
hw-access deny hardware-address IP , Mac-
- " "
7.