您好,欢迎访问三七文档
当前位置:首页 > 商业/管理/HR > 质量控制/管理 > H3C路由器配置命令
H3C路由器配置命令一、路由器基本配置命令1、system-view进入系统视图模式2、sysnameR1为设备命名为R3、displayiprouting-table显示当前路由表4、language-modeChinese|English中英文切换5、interfaceEthernet0/0进入以太网端口视图6、ipaddress192.168.1.1255.255.255.0配置IP地址和子网掩码7、undoshutdown打开以太网端口8、shutdown关闭以太网端口9、quit退出当前视图模式10、iproute-static192.168.2.0255.255.255.0192.168.12.2descriptionTo.R2配置静态路由11、iproute-static0.0.0.00.0.0.0192.168.12.2descriptionTo.R2配置默认的路由基本配置案例[Quidway]displayversion显示版本信息[Quidway]displaycurrent-configuration显示当前配置[Quidway]displayinterfaces显示接口信息[Quidway]displayiproute显示路由信息[Quidway]sysnameaabbcc更改主机名[Quidway]superpasswrod123456设置口令[Quidway]interfaceserial0进入接口[Quidway-serial0]ipaddressipmask[Quidway-serial0]undoshutdown激活端口[Quidway]link-protocolhdlc绑定hdlc协议[Quidway]user-interfacevty04[Quidway-ui-vty0-4]authentication-modepassword[Quidway-ui-vty0-4]setauthentication-modepasswordsimple2[Quidway-ui-vty0-4]userprivilegelevel3[Quidway-ui-vty0-4]quit[Quidway]debugginghdlcallserial0显示所有信息[Quidway]debugginghdlceventserial0调试事件信息[Quidway]debugginghdlcpacketserial0显示包的信息静态路由配置案例:[Quidway]iproute-staticipmask{interfacenumber|nexthop}[value][reject|blackhole]例如:[Quidway]iproute-static129.1.0.01610.0.0.[Quidway]iproute-static129.1.0.0255.255.0.010.0.0.[Quidway]iproute-static129.1.0.016Serial[Quidway]iproute-static0.0.0.00.0.0.010.0.0.动态路由配置案例(RIP):[Quidway]rip[Quidway]ripwork[Quidway]ripinput[Quidway]ripoutput[Quidway-rip]network1.0.0.0;可以all[Quidway-rip]network2.0.0.0[Quidway-rip]peerip-address[Quidway-rip]summary[Quidway]ripversion[Quidway]ripversion2multicast[Quidway-Ethernet0]ripsplit-horizon;水平分隔动态路由配置案例(OSPF):[Quidway]routeridA.B.C.D配置路由器的ID[Quidway]ospfenable启动OSPF协议[Quidway-ospf]import-routedirect引入直联路由[Quidway-Serial0]ospfenableareaarea_id配置OSPF区域标准访问列表命令格式如下:aclacl-number[match-orderconfig|auto]默认前者顺序匹配。rule[normal|special]{permit|deny}[sourcesource-addrsource-wildcard|any]例:[Quidway]acl10[Quidway-acl-10]rulenormalpermitsource10.0.0.00.0.0.25[Quidway-acl-10]rulenormaldenysourceany二、ACL配置扩展访问控制列表配置命令1.配置TCP/UDP协议的扩展访问列表:rule{normal|special}{permit|deny}{tcp|udp}source{ipwild|any}destinationipwild|any}[operate]2.配置ICMP协议的扩展访问列表:rule{normal|special}{permit|deny}icmpsource{ipwild|any]destination{ipwild|any][icmp-code][logging]扩展访问控制列表操作符的含义equalportnumber等于greater-thanportnumber大于less-thanportnumber小于not-equalportnumber不等rangeportnumber1portnumber区间3.扩展访问控制列表案例[Quidway]acl10[Quidway-acl-101]ruledenysouceanydestinationany[Quidway-acl-101]rulepermiticmpsourceanydestinationanyicmp-typeecho[Quidway-acl-101]rulepermiticmpsourceanydestinationanyicmp-typeecho-reply[Quidway]acl10[Quidway-acl-102]rulepermitipsource10.0.0.10.0.0.0destination202.0.0.10.0.0.0[Quidway-acl-102]ruledenyipsourceanydestinationany[Quidway]acl103[Quidway-acl-103]rulepermittcpsourceanydestination10.0.0.10.0.0.0destination-portequalftp[Quidway-acl-103]rulepermittcpsourceanydestination10.0.0.20.0.0.0destination-portequal[Quidway]firewallenable[Quidway]firewalldefaultpermit|deny[Quidway]inte0[Quidway-Ethernet0]firewallpacket-filter101inbound|outbound4.NAT的配置地址转换配置案例[Quidway]firewallenable[Quidway]firewalldefaultpermit[Quidway]acl10[Quidway-acl-101]ruledenyipsourceanydestinationany[Quidway-acl-101]rulepermitipsource129.38.1.40destinationany[Quidway-acl-101]rulepermitipsource129.38.1.10destinationany[Quidway-acl-101]rulepermitipsource129.38.1.20destinationany[Quidway-acl-101]rulepermitipsource129.38.1.30destinationany[Quidway]acl10[Quidway-acl-102]rulepermittcpsource202.39.2.30destination202.38.160.10[Quidway-acl-102]rulepermittcpsourceanydestination202.38.160.10destination-portgreat-than1024[Quidway-Ethernet0]firewallpacket-filter101inbound[Quidway-Serial0]firewallpacket-filter102inbound[Quidway]nataddress-group202.38.160.101202.38.160.103pool[Quidway]acl[Quidway-acl-1]rulepermitsource10.110.10.00.0.0.25[Quidway-acl-1]ruledenysourceany[Quidway-acl-1]intserial0[Quidway-Serial0]natoutbound1address-grouppool[Quidway-Serial0]natserverglobal202.38.160.101inside10.110.10.1ftptcp[Quidway-Serial0]natserverglobal202.38.160.102inside10.110.10.2[Quidway-Serial0]natserverglobal202.38.160.1028080inside10.110.10.3[Quidway-Serial0]natserverglobal202.38.160.103inside10.110.10.4smtpudp5.PPP验证配置:主验方:pap|chap[Quidway]local-useru2password{simple|cipher}aaa[Quidway]interfaceserial0[Quidway-serial0]pppauthentication-mode{pap|chap}[Quidway-serial0]pppchapuseru1//pap时,不用此句pap被验方:[Quidway]interfaceserial0[Quidway-serial0]ppppaplocal-useru2password{simple|cipher}aaachap被验方:[Quidway]interfaceserial0[Quidway-serial0]pppchapuseru1[Quidway-serial0]local-useru2password{simple|cipher}aaa
本文标题:H3C路由器配置命令
链接地址:https://www.777doc.com/doc-1781307 .html