1、配置交换机的名称和密码:
<Huawei> //用户视图 <Huawei>system-view //进入系统视图配置 [Huawei] //系统视图 [Huawei]quit/return //退出系统视图 [Huawei]sysname AIY //设置主机名 [Huawei]user-intface console 0 //进入控制台 [Huawei-ui-console0]authentication-mode password //验证 [Huawei-ui-console0]set authentication password cipher huwei //配置密文密码
2、配置交换机的远程管理IP地址:
[Huawei]interface vlanif 1 //进入vlan 1 [Huawei-vlanif]ip add 192.168.1.254 24 //配置IP [Huawei-vlanif]undo shotdown //开启接口 [Huawei]dns domain AIY.com //设置域名 [Huawei]dns server 192.168.254.254 //设置域名IP <Huawei>undo terminal monitor //取消提示信息 dis vlan 显示vlan save 保存配置 dis curr 显示当前配置 reboot 重启设备
3、配置交换机端口速率、双工、ARP:
[Huawei]int g 0/0/1 //进入接口 [Huawei-G0/0/1]description AIY //端口描述 [Huawei-g 0/0/1]undo negotiation auto //取消协商 [Huawei-GigabitEthernet 0/0/1]duplex full //全双工 [Huawei-GigobitEthernet 0/0/1]auto duplex full //自动 [Huawei-GigabitEthernet 0/0/1]speed 10 //速率 10M [Huawei-GigabitEthernet 0/0/1]auto speed 100 //自动 [Huawei]arp static 192.168.1.8 5489-98cf-2603 //绑定 IP、MAC [Huawei]dis arp /[Huawei]dis arp all //查看ARP
4、配置路由器接口IP和静态路由:
[Huawei]int g 0/0/1 //进入接口 [Huawei]ip add 192.168.1.6 24 //配IP地址 [Huawei-GigabitEthernet 0/0/1]undo shoutdown //开启 <Huawei>dis cur //查看ARP [Huawei]ip route-static 192.168.20.0 24 10.0.12.2 //配置静态路由 [Huawei]ip route-static 0.0.0.0 0 192.168.1.5 //默认 [Huawei]display ip routing-able //查看路由表
5、配置交换机VLAN相关命令:
[Huawei]vlan 10 或 [Huawei]vlan 20 //创建vlan [Huawei-vlan 10]description AIY //vlan描述 [Huawei]vlan batch 30 40 //创建多个vlan [Huawei]int g 0/0/1 //进入接口 [Huawei-g 0/0/1]port link-type access //访问口 [Huawei-g 0/0/1]port default vlan 10 //加入vlan [Huawei-g 0/0/2]port link-type trunk //干道口 [Huawei-g 0/0/2]port trunk allow-pass vlan 10 20 //允许10 20 [Huawei-g 0/0/2]port trunk allow-pass vlan all //所有 [Huawei]int e 0/0/2 //进入接口 [Huawei-E 0/0/2]port link-type hybrid //混合口模式 [Huawei-E 0/0/2]undo port default vlan //删除默认vlan [Huawei-E 0/0/2]port hybrid untagged vlan 20 //去标签 [Huawei-E 0/0/2]port hybrid pvid vlan 2 //设置默认vlan [Huawei-E 0/0/2]port trunk allow pass vlan 10 to 100 //允许10~100 [Huawei]dis port vlan / display vlan //查看vlan
6、配置路由RIP协议:RIPV1 RIPV2
[Huawei]rip //启用RIP,默认RIPV1 [Huawei-riop-1]network 192.168.1.0 //发布直连网段 [Huawei-rip-1]version 2 //配置RIPV2banb [Huawei]dis rip //查看RIP [Huawei]dis rip database //查看RIP数据库 [Huawei]dis ip routing-table //查看路由表
7、配置路由器OSPF协议:
[Huawei]ospf //启用OSPF,默认进程为1 [Huawei-ospf-1]area 0 //进入区域0 [Huawei-ospf-1-area-0.0.0.0]network 192.168.3.0 0.0.0.255 //发布直连网段 [Huawei-ospf-1]silent-intface g 0/0/2 //被动接口 [Huawei]dis ospf interface //查看OSPF通告 [Huawei]dis ospf peer //查看OSPF邻居 [Huawei]dis ospf ip routing-table //查看路由表 [Huawei]dis ospf routing //查看OSPF路由表
8、配置基于全局的DHCP协议:
[Huawei]dhcp enabel //开启DHCP [Huawei]ip pool AIY // 地址池名 [Huawei-ip-pool-AIY]network 192.168.1.0 //地址池 [Huawei-ip-pool-AIY]lease day 2 //租约默认1 [Huawei-ip-pool-AIY]gateway-list 192.168.1.254 //网关 [Huawei-ip-pool-AAI]excluded -ip-address 192.168.1.250 192.168.1.253 //排除IP范围 [Huaweiip-pool-AIY]dns-list 8.8.8.8 //DNS服务器 [Huawei-G 0/0/0]dhcp select global //基于全局
9、配置基于接口的DHCP协议:
[Huawei]dhcp enable //开启DHCP [Huawei]int g 0/0/1 //进入接口 [Huawei-G 0/0/1]dhcp select interface //基于接口 [Huawei-G 0/0/1]dhcp server lease day 2 //租约默认1 [Huawei-G 0/0/1]dhcp server exclude-ip-adress 192.168.1.1 192.168.1.10 //排除IP范围 [Huawei-G 0/0/1]dhcp server dns-list 8.8.8.8 //DNS [Huawei]dis ip pool //查看DHCP
10、配置路由器基本ACL:2000~2999
[Huawei]acl 2000 //配置基本ACL [Huawei-acl-basic-2000]rule 5 permit source 1.1.1.1 0 //允许源IP [Huawei-acl-basic-2000]rule 10 deny any //拒绝任意 [Huawei]user-interface vty 0 4 //进入接口 [Huawei-ui-vty0-4]alc 2000 inbound //应用ACL [Huawei]dis acl all //查看所有ACL [Huawei]dis acl 2000 //查看ACL2000
11、配置路由器高级ACL:3000~3999
[Huawei]acl 3000 //配置高级ACL [Huawei-acl-adv-3000]rule permit ip source 1.1.1.1 0 destination 4.4.4.4 0 //允许访问 [Huawei]user-interface vty 0 4 //进入虚拟接口 [Huawei-ui-vty0-4]acl 3000 outbount //应用ACL [Huawei]int g 0.0.1 //进入接口 [Huawei-g 0/0/1]traffic-filter inbound acl 3000 //应用
12、配置路由器动态NAT(多对少):
[Huawei]nataddress-group 1 202.169.10.50 202.169.10.60 //外部IP [Huawei]acl 2001 //配置ACL [Huawei-acl-basic-2001]rule 5 permit source 172.17.1.0 0.0.0.255 //内部IP [Huawei]int g 0/0/1 //进入接口 [Huawei-GigabitEthernet 0/0/0]nat outbound 2001 address-group 1 no-pat //应用NAT [Huawei]dis nat outbound //查看NAT
13、配置路由器静态NAT(一对一):
[Huawei]int g 0/0/1 //进入接口 [Huawei-GigabitEthernet 0/0/1]nat static global 202.169.10.5 inside 172.16.1.1 //一对一转换
14、配置路由器动态NAPT(多对一):
[Huawei]int g 0/0/0 //进入接口 [Huawei-G 0/0/0]nat outbound 2001 //多对一转换 [Huawei]dis nat static //查看静态NAT
15、配置三层交换机VLAN间路由:
[Huawei]int vlanif 10 //进入接口 [Huawei-vlanif 10]ip add 192.168.1.254 24 //配置IP [Huawei]int vlanif 20 //进入接口 [Huawei-vlanif 20]ip add 192.168.2.254 24 //配IP [Huawei]dis ip interface brief //接口简略信息 [Huawei]dis port vlan //接口vlan信息 [Huawei]dis vlan //查看vlan信息
16、配置单臂路由VLAN间通信:
[Huawei-G0/0/1]ip add 192.168.1.254 24 //配置IP [Huawei-G 0/0/1]dot1q termination vid 10 //封装 [Huawei-G 0/0/1]arp broad case enable //查看接口 [Huawei]dis ip interface brief //查看路由表 [Huawei]display current-configuration //查看配置