顯示具有 CISCO 相關 標籤的文章。 顯示所有文章
顯示具有 CISCO 相關 標籤的文章。 顯示所有文章

2008年6月21日 星期六

CISCO Router&Switch 操作小技巧

前言:
這篇文章主要要表達就是CISCO Router和CISCO Switch 於指令操作的小技巧,方便網管朋友在管理CISCO設備的時候可以更容易由螢幕輸出的訊息中找到需要的關鍵資訊。
再看這篇文章的同時建議使用者可以順便複習一下CCNA課程中基本的指令。
若您要練習本篇所提及的技巧建議手上要有一顆CISCO Router(ISO 12.x)或是Dynamips模擬器。


CISCO Router&Switch 操作小技巧

發佈日期: 2008/06/13
版本:Version1
發佈網址:http://WWW.ITPro.tw
作者:呂堃楠 Email:Mark@mail.itpro.tw MSN : Mark.ITPro@hotmail.com
文章歡迎轉貼,轉貼時請註名出處。

前言:
這篇文章主要要表達就是CISCO Router和CISCO Switch 於指令操作的小技巧,方便網管朋友在管理CISCO設備的時候可以更容易由螢幕輸出的訊息中找到需要的關鍵資訊。
再看這篇文章的同時建議使用者可以順便複習一下CCNA課程中基本的指令。
若您要練習本篇所提及的技巧建議手上要有一顆CISCO Router(ISO 12.x)或是Dynamips模擬器。

在本文中堃哥將文章分成兩個部份:
第一部份是(一)基本命令講解。
第二部份是(二)技巧練習。

(一)基本命令講解1.1 Show Running-configure Current operating configuration 使用sh run顯示當前設定檔

輸出範例如下:
ITPro-Labs#sh run
Building configuration...
Current configuration : 2153 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
hostname ITPro-Labs
boot-start-marker
boot-end-marker
enable secret 5 $1$9hCY$O3nRYLpuYDXPaSLh95uTA.
aaa new-model
ip cef
ip sla monitor 10
type tcpConnect dest-ipaddr 1.1.1.2 dest-port 23 source-ipaddr 1.1.1.1 source-port 22392
frequency 3600
ip sla monitor schedule 10 life forever start-time now
frame-relay de-list 1 protocol ip
frame-relay de-list 1 protocol ip list 101
...(後省略)

上面顯示目前Router的設定,倘若要由眾多設定資訊中找到特定的關鍵可以使用下面參數

1.1.1 Show Running-configure 加上參數 | include [關鍵字]這句話的意思是有眾多顯示畫面的設定檔中找到我們輸入"特定"的關鍵字,例如我們要於上面的設定檔中找到
Router啟用sla則我們可以輸入 sh run | i sla 顯示結果如下
ip sla monitor 10
ip sla monitor schedule 10 life forever start-time now
系統會將Running-Configure中關於sla的關鍵字給找出來。
◎有使用Linux或是UnIX的朋友對上述的命令應該不陌生其實這就是管線的概念將螢幕輸出的資訊透過 | 管線然後使用 include其實也就是 unix 中的 grep 找到特定的資訊。

1.1.2 Show Running-configure 加上參數 | begin [關鍵字]
這句話的意思是找尋設定檔中將我們輸入的關鍵字"之後"的資訊都顯示出來,
簡單的說如果我們要找sla之後的訊息我們可以輸入sh run | b sla 顯示結果如下
ip sla monitor 10 ----sla之後均顯示出來
type tcpConnect dest-ipaddr 1.1.1.2 dest-port 23 source-ipaddr 1.1.1.1 source-port
22392 frequency 3600
ip sla monitor schedule 10 life forever start-time now
frame-relay de-list 1 protocol ip
frame-relay de-list 1 protocol ip list 101
比對前面的輸出範例會發現 sla關鍵字之前的訊息都消失了,系統只會顯示sla之後的訊息,這是一個相當有用的命令,例如我們要找尋Running-Configure中關於eigrp的資訊我們可以輸入,Sh run | b router eigrp 如此系統就只會顯示出eigrp之後的命令,可以很方便的找到關於EIGRP的訊息。

1.1.3 Show Running-configure 加上參數 | exclude [關鍵字]
這句話的意思是找尋設定檔中將我們輸入的關鍵字以外的資訊都顯示出來,
簡單的說如果我們"排除"sla所有的訊息我們可以輸入sh run | e sla 顯示結果如下

Building configuration...
Current configuration : 2153 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
hostname ITPro-Labs
boot-start-marker
boot-end-marker
enable secret 5 $1$9hCY$O3nRYLpuYDXPaSLh95uTA.
aaa new-model
ip cef
type tcpConnect dest-ipaddr 1.1.1.2 dest-port 23 source-ipaddr 1.1.1.1 source-port 22392
frame-relay de-list 1 protocol ip
frame-relay de-list 1 protocol ip
由上述範例輸出我們可以清楚看見關於 sla的命令已經被排除了。

1.4 Show Running-configure 加上參數 /[關鍵字] 符號這句話的意思是找尋設定檔中將我們輸入的關鍵字之後的資訊都顯示出來用法和 include類似差別在於當我們使用Show Running-configure在看設定檔時如果設定檔過長通常底下會出現 --More-- 的訊息要我們進行換頁此時我們可以輸入 /[關鍵字]
直接由 Show Running-configure找到我們要的資訊十分的方便大家可以練習一下使用/[關鍵字]和include [關鍵字]兩者之間有什麼不同。

重點整理
使用 參數 | include [關鍵字]
找尋螢幕中特定關鍵字

使用 參數 | begin [關鍵字]
顯示螢幕中特定關鍵字之後的字串

使用 參數 | exclude [關鍵字]
排除螢幕中特定關鍵字

使用 參數 /[關鍵字]
找尋螢幕中特定關鍵字

(二)技巧練習
熟悉上面技巧之後我們可以立刻將它用於我們實務環境中

Q2.1找出所有Router介面哪些介面是顯示 Down的 ??
A2.1我們可以輸入 ITPro-Labs#sh int | i down
顯示如下:
FastEthernet0/1 is administratively down, line protocol is down
Serial1/0 is up, line protocol is down
Serial1/1 is up, line protocol is down
LMI enq sent 175, LMI stat recvd 0, LMI upd recvd 0, DTE LMI down
0 carrier transitions DCD=down DSR=down DTR=up RTS=up CTS=down
Serial1/2 is administratively down, line protocol is down
LMI enq sent 0, LMI stat recvd 0, LMI upd recvd 0, DTE LMI down
0 carrier transitions DCD=down DSR=down DTR=up RTS=up CTS=down
Serial1/3 is administratively down, line protocol is down
1 carrier transitions DCD=down DSR=down DTR=up RTS=up CTS=down

可以將所有介面關於Down的資訊全部找出來。

Q2.2利用 sh ip route找出所以關於 5.5.5.0 的路由 ??
A2.2我們可以輸入 sh ip route | i 5.5.5.0
顯示如下:
ITPro-Labs#sh ip route | i 5.5.5.0
C 5.5.5.0 is directly connected, Loopback5

如此則可以再上萬條路由中輕鬆找到我們想知道的路由資訊。

結語!
上述簡單的小技巧可方便於眾多資訊中找到我們需要的,熟悉上述資訊對於我們日常Debug 網路有很大的幫助,希望上述資訊對正在學習CISCO相關知識的使用者有幫助,若對文章有任何問題請寫Email告訴我,謝謝。

2008年6月20日 星期五

IP與MAC綁定交換機上支持

網絡管理員︰現在用戶真是不省心,自己改個IP地址;私接AP、忘關DHCP,還有的下個小黑客程序,就想在你內網里試試。單靠交換機能管嗎?

測試工程師︰能!很多交換機上的小功能都可幫大忙。

測試實況︰

IP與MAC綁定

思科的Catalyst 3560交換機支持DHCP Snooping功能,交換機會監听DHCP的過程,交換機會生成一個IP和MAC地址對應表。思科的交換機更進一步的支持IP source guard和Dynamic ARP Inspection功能,這兩個功能任啟一個都可以自動的根據DHCP Snooping監听獲得的IP和MAC地址對應表,進行綁定,防止私自更改地址。

Dynamic ARP Inspection功能還有一個好處是可以防範在2層網絡的中間人攻擊(見圖4)。

思科在DHCP Snooping上還做了一些非常有益的擴展功能,比如Catalyst 3560交換機可以限制端口通過的DHCP數據包的速率,粒度是pps,這樣可以防止對DHCP服務器的進行地址請求的DoS攻擊。另外Catalyst 3560交換機還支持DHCP Tracker,在DHCP請求中插入交換機端口的ID,從而限制每個端口申請的IP地址數目,防止黑客程序對DHCP服務器進行目的為耗盡IP地址池的 攻擊。華碩雖然不能調整速率,但是也會限制DHCP請求的數量。

DHCP(動態主機配置協議)是一種簡化主機IP地址配置管理的TCP/IP標準。該標準為DHCP服務器的使用提供了一種有效的方法︰即管理網絡中客戶機IP地址的動態分配以及啟用網絡上DHCP客戶機的其它相關配置信息。

在基于TCP/IP協議的網絡中,每台計算機都必須有唯一的IP地址才能訪問網絡上的資源,網絡中計算機之間的通信是通過IP地址來實現的,並且通過IP 地址和子網掩碼來標識主計算機及其所連接的子網。在局域網中如果計算機的數量比較少,當然可以手動設置其IP地址,但是如果在計算機的數量較多並且劃分了 多個子網的情況下,為計算機配置IP地址所涉及的管理員工作量和復雜性就會相當繁重,而且容易出錯,如在實際使用過程中,我們經常會遇到因IP地址沖突、 網關或DNS服務器地址的設置錯誤導致無法訪問網絡、機器經常變動位置而不得不頻繁地更換IP地址等問題。

DHCP則很好地解決了上述的問題,通過在網絡上安裝和配置DHCP服務器,啟用了DHCP的客戶機可在每次啟動並加入網絡時自動地獲得其上網所需的IP地址和相關的配置參數。從而減少了配置管理,提供了安全而可靠的配置。

配置DHCP服務的服務器可以為每一個網絡客戶提供一個IP地址、子網掩碼、缺省網關,以及DNS服務器的地址。DHCP避免了因手工設置IP地址及子網 掩碼所產生的錯誤,也避免了把一個IP地址分配給多台主機所造成的地址沖突。降低了IP地址管理員的設置負擔,使用DHCP服務器可以大大地縮短配置網絡 中主機所花費的時間。

但是,隨著DHCP服務的廣泛應用,也產生了一些問題。首先,DHCP服務允許在一個子網內存在多台DHCP服務器,這就意味著管理員無法保證客戶端只能 從管理員所設置的DHCP服務器中獲取合法的IP地址,而不從一些用戶自建的非法DHCP服務器中取得IP地址;其次,在部署DHCP服務的子網中,指定 了合法的IP地址、掩碼和網關的主機也可以正常地訪問網絡,而DHCP服務器卻仍然會有可能將該地址分配給其他主機,這樣就會造成地址沖突,影響IP地址 的正常分配。

針對上述問題,本文給出了一個解決方案,即通過使用Cisco提供的DHCP Snooping技術和Dynamic ARP Inspection技術,可以有效地防止以上問題的發生。

這里首先對兩種技術做一個簡要的介紹,然後將給出一個應用實例加以說明。

二、DHCP Snooping技術DHCP Snooping是一種通過建立DHCP Snooping Binding數據庫,過濾非信任的DHCP消息,從而保證網絡安全的特性。DHCP Snooping就像是非信任的主機和DHCP服務器之間的防火牆。通過DHCP Snooping來區分連接到末端客戶的非信任接口和連接到DHCP服務器或者其他交換機的受信任接口。

DHCP Snooping Binding數據庫包括如下信息︰MAC地址、IP地址、租約時間、binding類型、VLAN ID以及來自本地非信任端口的接口信息,但不包含通過受信任端口互相連接的接口信息。在啟用了DHCP Snooping的VLAN中,如果交換機收到來自非信任端口的DHCP包,交換機將對目的MAC地址和DHCP客戶端的地址進行對比,如果符合則該包可 以通過,否則將被丟棄掉。

在下述情況中,DHCP包將同樣被丟棄︰

l 來自外網或者防火牆的DHCP服務器,包括DHCPOFFER、DHCPACK、DHCPNAK、DHCPLEASEQUERY.

l 來自非信任端口,且目的MAC地址和DHCP客戶端的硬件地址不匹配。

l 交換機收到DHCPRELEASE或者DHCPDECLINE的廣播信息,其MAC地址包含在DHCP snooping binding 數據庫中,但與數據庫中的接口信息不匹配

l 通過DHCP中繼代理轉發的包不包括在內

三、Dynamic ARP Inspection技術Dynamic ARP inspection是一種驗證網絡中ARP包的安全特性,可以阻止、記錄並丟棄非法IP和MAC地址綁定的ARP包。

Dynamic ARP inspection保證只有合法的ARP請求和響應可以傳播。交換機會完成如下工作,截取所有來自非信任端口ARP請求和響應,在更新ARP緩存或傳播數據包之前驗證所截取的數據包IP-MAC地址綁定是否合法,丟棄非法的ARP包。

前面提到,DHCP Snooping會建立一個包含合法IP-MAC地址綁定信息的數據庫,Dynamic ARP inspection基于該數據庫檢驗所截取ARP包的合法性。如果ARP包來自非信任接口,那麼只有合法的可以通過。如果來自受信任端口,將可以直接通 過。


DHCP SNOOPING

Switch(config)#dhcp service 預設是開啟的
Switch(config)#ip dhcp snooping 開啟dhcp snooping的功能
Switch(config)#ip dhcp snooping vlan X 將dhcp snooping套用在那個vlan
Switch(config-if)#ip dhcp snooping trust 設在要往dhcp server上的介面上
Swtich(config-if)#no ip dhcp snooping trust 設在dhcp client 的介面上
此用途是用來阻斷非法的DHCP SERVER的架設。

參考: Cisco 網站

http://www.cisco.com/en/US/products/hw/switches/ps4324/products_configuration_guide_chapter09186a008019d0c8.html

使用的方法是採用DHCP方式為用戶分配IP,然後限定這些用戶隻能使用動態IP的方式,如果改成靜態IP的方式則不能連接上網路;也就是使用了DHCP SNOOPING功能。
  例子:
  version 12.1
  no service pad
  service timestamps debug uptime
  service timestamps log uptime
  no service password-encryption
  service compress-config
  !
  hostname C4-2_4506
  !
  enable password xxxxxxx!
  clock timezone GMT 8
  ip subnet-zero


  no ip domain-lookup
  !
  ip dhcp snooping vlan 180-181 // 對哪些VLAN 進行限制
  ip dhcp snooping
  ip arp inspection vlan 180-181
  ip arp inspection validate src-mac dst-mac ip


  errdisable recovery cause udld
  errdisable recovery cause bpduguard
  errdisable recovery cause security-violation
  errdisable recovery cause channel-misconfig
  errdisable recovery cause pagp-flap
  errdisable recovery cause dtp-flap
  errdisable recovery cause link-flap
  errdisable recovery cause l2ptguard
  errdisable recovery cause psecure-violation
  errdisable recovery cause gbic-invalid
  errdisable recovery cause dhcp-rate-limit
  errdisable recovery cause unicast-flood
  errdisable recovery cause vmps
  errdisable recovery cause arp-inspection
  errdisable recovery interval 30
  spanning-tree extend system-id
  !
  !

  interface GigabitEthernet2/1 // 對該連接埠接入的用戶進行限制,可以下聯交換機
  ip arp inspection limit rate 100
  arp timeout 2
  ip dhcp snooping limit rate 100
  !


  interface GigabitEthernet2/2
  ip arp inspection limit rate 100
  arp timeout 2
  ip dhcp snooping limit rate 100
  !
  interface GigabitEthernet2/3
  ip arp inspection limit rate 100
  arp timeout 2
  ip dhcp snooping limit rate 100
  !
  interface GigabitEthernet2/4
  ip arp inspection limit rate 100
  arp timeout 2
  ip dhcp snooping limit rate 100
  --More--

  編者注:對不需要明確地址的所有人的時候是一個很好的解決辦法。另外,可以查看www.cisco.com的
  IP Source Guard
   Similar to DHCP snooping, this feature is enabled on a DHCP snooping untrusted Layer 2 port. Initially, all IP traffic on the port is blocked except for DHCP packets that are captured by the DHCP snooping process. When a client receives a valid IP address from the DHCP server, or when a static IP source binding is configured by the user, a per-port and VLAN Access Control List (PACL) is installed on the port. This process restricts the client IP traffic to those source IP addresses configured in the binding; any IP traffic with a source IP address other than that in the IP source binding will be filtered out. This filtering limits a host's ability to attack the network by claiming neighbor host's IP address.

2008年4月26日 星期六

Password Recovery

Password Recovery


Step 1 : 連接 Console 埠
Step 2 : 開啟路由器電源,60 秒內按中斷鍵,進入 ROM monitor 模式
Step 3 : 使用 confreg 0x2142 指令
Step 4 : 重新開機 ( reset )
Step 5 : 進入 Setup 模式後,請回答 NO
if you want to enter the initial configuration dialog.[yes/no] : no
Step 6 : 直接進入 privileged 模式 (enable command)
Step 7 : 取回原參數
Router# copy startup-config running-config
Step 8 : 修改密碼
Router# config term
Router(config)# enable secret
Step 9 : 修正 Configurate Register Number
Router(config)# config-reg 0x2102
Router(config)# end
Step 10 : 存參數
Router# copy running-config startup-config
Step 11 : 重新開機
Router# reload

2008年4月20日 星期日

路由器配置命令詳細列表

Cisco路由配置語句匯總

  啟動介面,分配IP地址:

  router>

  router> enable

  router#

  router# configure terminal

  router(config)#

  router(config)# interface Type Port

  router(config-if)# no shutdown

  router(config-if)# ip address IP-Address Subnet-Mask

  router(config-if)# ︿z

  配置RIP路由協議:30秒更新一次

  router(config)# router rip

  router(config-if)# network Network-Number <——通告標準A,B,C類網——>

  router(config-if)# ︿z

  配置IGRP路由協議:90秒更新一次

  router(config)# router igrp AS-Number <—— AS-Number範圍1~65535——>

  router(config-if)# network Network-Number <——通告標準A,B,C類網——>

  router(config-if)# ︿z

  配置Novell IPX路由協議:Novell RIP 60秒更新一次

  router(config)# ipx routing [node address]

  router(config)# ipx maximum-paths Paths <——設置負載平衡,範圍1~512——>

  router(config)# interface Type Port

  router(config-if)# ipx network Network-Number [encapsulation encapsulation-type] [secondary] <——通告標準A,B,C類網——>

  router(config-if)# ︿z

  配置DDR:

  router(config)# dialer-list Group-Number protocol Protocol-Type permit [list ACL-Number]

  router(config)# interface bri 0

  router(config-if)# dialer-group Group-Number

  router(config-if)# dialer map Protocol-Type Next-Hop-Address name Hostname Telphone-Number

  router(config-if)# ︿z

  配置ISDN:

  router(config)# isdnth-typeth-Type <——配置ISDN交換機類型,中國使用basic-net3——>

  router(config-if)# ︿z

  配置Frame Relay:

  router(config-if)# encapsulation frame-relay [cisco | ietf ]

  router(config-if)# frame-relay lmi-type [ansi | cisco | q933a ]

  router(config-if)# bandwidth kilobits

  router(config-if)# frame-relay invers-arp [ Protocol ] [dlci ]

  <——配置靜態Invers ARP表:

  router(config)# frame-relay Protocol Protocol-Address DLCI [ Broadcast ] [ ietf | cisco ] [ payload-compress | packet-by-packet ]

  ——>

  <——設置Keepalive間隔:

  router(config-if)# keepalive Number

  ——>

  <——為本地介面指定DLCI:

  router(config-if)# frame-lelay local-dlci Number

  ——>

  <——子介面配置:

  router(config-if)# interface Type Port.Subininterface-Number [ multipoint | point-to-point ]

  router(config-subif)# ip unnumbered Interface

  router(config-subif)# frame-lelay local-dlci Number

  ——>

  router(config-if)# ︿z

  配置標準ACL:

  router(config)# access-list Access-List-Number [ permit | deny ] source [ source-mask ] <—— Access-List-Number 範圍:1~99標準ACL;100~199擴展ACL;800~899標準IPX ACL;900~999擴展IPX ACL;1000~1099 IPX SAP ACL;600~699Apple Talk ACL——>

  router(config)# interface Type Port

  router(config-if)# ip access-group Access-List-Number [ in | out ]

  router(config-if)# ︿z

  配置擴展ACL:

  router(config)# access-list Access-List-Number [ permit | deny ] [ Protocol | Protocol-Number ] source source-wildcard [ Source-Port ] destination destination-wildcard [ Destination-Port ] [ established ]

  router(config)# interface Type Port

  router(config-if)# ip access-group Access-List-Number [ in | out ]

  router(config-if)# ︿z

  配置命名ACL:

  router(config)# ip access-list [ standard | extended ] ACL-Name

  router(config [ std- | ext- ] nacl)# [ permit | deny ] [ IP-Access-List-Test-Conditions ]

  router(config [ std- | ext- ] nacl)# no [ permit | deny ] [ IP-Access-List-Test-Conditions ]

  router(config [ std- | ext- ] nacl)# ︿z

  router(config)# interface Type Port

  router(config-if)# ip access-group [ACL-Name | 1~199 ] [ in | out ]

  router(config-if)# ︿z



配置DCE時鐘:

  router# show controllers Type Port <——確定DCE介面——>

  router(confin-if)# clock rate 64000 <——進入DCE介面設置時鐘速率——>

  router(config-if)# ︿z

  配置PPP協議:

  router(config)# username Name password Set-Password-Here <——驗證方建立數據庫——>

  router(config)# interface Type Port

  router(config-if)# encapsulation ppp <——啟動PPP協議——>

  router(config-if)# ppp outhentication [ chap | chap pap | pap chap | pap ] <——選擇PPP認證——>

  router(config-if)# ppp pap sent-username Name password Password <——發送驗證資訊——>

  router(config-if)# ︿z

  PAP單向認證配置實例:

  驗證方:

  router-server(config)# username Client password 12345 <——驗證方建立數據庫——>

  router-server(config)# interface serial 0

  router-server(config-if)# encapsulation ppp

  router-server(config-if)# ppp authentication pap <——選擇使用PAP實現PPP認證——>

  router-server(config-if)# ︿z

  被驗證方:

  router-client(config-if)# encapsulation ppp

  router-client(config-if)# ppp pap sent-username Client password 12345 <——發送驗證資訊——>

  router-client(config-if)# ︿z

PAP雙向認證配置實例:

  路由器 A:

  routerA(config)# username B password 12345

  routerA(config)# interface serial 0

  routerA(config-if)# encapsulation ppp

  routerA(config-if)# ppp authentication pap

  routerA(config-if)# ppp pap sent-username A password 54321

  routerA(config-if)# ︿z

  路由器 B:

  routerB(config)# username A password 54321

  routerB(config)# interface serial 1

  routerB(config-if)# encapsulation ppp

  routerB(config-if)# ppp authentication pap

  routerB(config-if)# ppp pap sent-username B password 12345

  routerB(config-if)# ︿z

  CHAP單向認證配置實例:

  驗證方:

  router-server(config)# username router-client password 12345

  router-server(config)# interface serial 0

  router-server(config-if)# encapsulation ppp

  router-server(config-if)# ppp authentication chap

  router-server(config-if)# ︿z

  被驗證方:

  router-client(config-if)# encapsulation ppp

  router-client(config-if)# ppp authentication chap

  router-client(config-if)# ppp chap hostname router-client

  router-client(config-if)# ppp chap password 12345

  router-client(config-if)# ︿z CHAP雙向認證配置實例:

  路由器 A:

  routerA(config)# username routerB password 12345

  routerA(config)# interface serial 0

  routerA(config-if)# encapsulation ppp

  routerA(config-if)# ppp authentication chap

  routerA(config-if)# ppp chap hostname routerA

  routerA(config-if)# ppp chap password 54321

  routerA(config-if)# ︿z

  路由器 B:

  routerB(config)# username routerA password 54321

  routerB(config)# interface serial 1

  routerB(config-if)# encapsulation ppp

  routerB(config-if)# ppp authentication chap

  routerB(config-if)# ppp chap hostname routerB

  routerB(config-if)# ppp chap password 12345

  routerB(config-if)# ︿z



Telnet使用:

  routerA# terminal monitor <——可以傳回在遠端主機執行Debug命令的結果——>

  routerA# telnet IP-Address [ Router-Name ] <——Telnet到指定的地址或名字的主機——>

  routerB# [ exit | logout ] <——退出Telnet——>

  routerB# ++<6>再按 <——挂起Telnet——>

  routerA# show sessions <——顯示當前所有Telnet的資訊,包括Connect-Number ——>

  routerA# Connect-Number <——返回指定的Telnet連接——>

  routerA# disconnect IP-Address [ Router-Name ] <——斷開指定地址或名字的主機的連接——>

  routerA# show user <——顯示Telnet到本機的連接資訊——>

  routerA# clear line [ 0 | 1 | 2 | 3 | 4 ] <——斷開指定Telnet到本機的連接——>

  禁止任何Telnet到本機:

  router(config)# line vty 0 4

  router(config-line)# access-class ACL-Number

  router(config)# ︿z

  設置主機名:

  router(config)# hostname Set-Hostname

  router(config)# ︿z

  router(config)# ︿z

  設置用戶模式密碼:

  router(config)# line console 0

  router(config-line)# login

  router(config-line)# password Set-Password

  router(config-line)# ︿z

設置Telnet密碼:

  router(config)# line vty 0 4

  router(config-line)# login

  router(config-line)# password Set-Password

  router(config-line)# ︿z

  設置特權模式密碼:

  router(config)# enable password Set-Password <——不加密的密碼,明碼——>

  router(config)# enable secret Set-Password <——經過加密的密碼——>

  router(config)# ︿z

  給所有密碼加密:

  router(config)# service password-ancryption Set-Password-Here

  router(config)# no service password-ancryption <——取消加密——>

  router(config)# ︿z

  設置登錄Banner:

  router(config)# banner motd 分隔符 Set-Banner-InFORMation-Here 分隔符 <——前後分隔符一定要一致——>

  設置介面的描述資訊:

  router(config-if)# description Set-Port-InFORMation-Here

  router(config)# ︿z

  CDP的控制:

  router(config-if)# cdp enable <——在指定端口啟用CDP,缺省——>

  router(config-if)# no cdp enable <——在指定端口關閉CDP——>

  router(config)# cdp run <——使所有端口啟用CDP——>

  router(config)# no cdp run <——使所有端口關閉CDP——>

  Ping的使用:

  router# ping IP-Address

  router# ping <——擴展Ping命令——>

  Protocol [ip]:[ Protocol-Type ] <——選擇協議類型——>

  Target IP address:IP-Address <——輸入測試地址——>

  Repeat count [5]: <——選擇發送的ICMP包數量——>

  Datagram size [100]: <——選擇每個包的大小——>

  Timeout in seconds [2]: <——設置每個包的超時時間——>

  Extended commands [n]:y <——使用擴展Ping命令——>

  Sweep range of sizes [n]:

Tracke的使用:

  router# trace IP-Address [ Host-Name ]

  為Cisco 4000路由器指定媒體類型:

  router(config-if)# media-type 10baset <——使AUI(默認)失效,改為使用RJ-45——>

  router(config-if)# ︿z

  更改路由器啟動順序:

  router(config)# boot system flash IOS-FileName

  router(config)# boot system tftp IOS-FileName TFTP-IP-Address

  router(config)# boot system rom

  router(config)# ︿z

  修改寄存器數值:

  router(config)# config-register value <——Cisco出廠默認value=0x2102,value範圍:0x2100(進入ROM監視器),0x2101(使系統從ROM啟動),0x2102~0x210F(使系統從NVRAM啟動)。0x1=0x2101,從最小位開始改變——>

  在ROM監視器中更改寄存器數值:

  > o/r value

  路由器密碼的恢復:

  冷關機,然後再開機並在60秒內按<>+進入ROM監視器模式

  > o/r 0x2142 <--25xx型路由器--> 或 > confreg 0x2142 <--16xx型路由器-->

  router> I

  router> n

  router> enable

  router# copy startup-config running-config

  router# configure terminal

  router(config)# enable secret New-Password

  router(config)# config-register 0x2102

  router(config)# ︿z

  router# copy running-config startup-config

  router# reload

配置名稱-主機入口:

  router(config)# ip host Set-Name [ TCP-Port-Number ] IP-Address [ IP-Address 2 ].。。

  router(config)# ︿z

  定義DNS主機:

  router(config)# ip name-server Server-Address [ Server-Address 2 ].。。

  router(config)# ︿z

  禁用DNS:

  router(config)# no ip domain-lookup

  router(config)# ︿z配置水準分割:

  router(config-if)# ip split-horizon

  router(config-if)# no ip split-horizon

  router(config-if)# ︿z

  配置靜態路由:

  router(config)# ip route IP-Address Subnet-Mask [ Next-Hop-Address | Local-Out-Port ] [Distace ]

  <——Distance範圍:1~255,相當於優先權,越小越好。RIP=120;DSPF=110;IGRP=100;EIGRP=90——>

  router(config)# ︿z

配置缺省路由:

  router(config)# ip defoult-network IP-Address <——動態缺省路由——>

  router(config)# ip route 0.0.0.0 0.0.0.0 [ Next-Hop-Address | Local-Out-Port ] [Distace ] <——靜態缺省路由——>

  router(config)# ︿z

  其他命令:

  router# show version

  router# show running-config

  router# show startup-config

  router# show flash

  router# show interface [ Type Port ]

  router# show buffers

  router# show protocol

  router# show mem

  router# show stacks

  router# show processes

  router# show cdp entry [ Device-Name ] <——顯示指定鄰居三層資訊——>

  router# show cdp neighbors

  router# show cdp neighbors detail <——顯示所有鄰居三層資訊->

  router# show ip router

  router# show ipx router

  router# show host

  router# show ip protocol

  router# show ip interface Type Port

  router# show ipx interface Type Port

  router# show ipx servers

  router# show ipx traffic

  router# show access-lists [ ACL-Number ]

  router# show isdn status

  router# show dialer <——查看ISDN撥號資訊——>

  router# show isdn active

  router# show frame-relay pvc

  router# show frame-relay map

  router# show frame-relay lmi

  router# erase startup-config

  router# reload

  router# setup

  router# copy running-config startup-config

  router# copy startup-config running-config

  router# copy tftp running-config

  router# copy running-config tftp

  router# debug ipx routing activity

  router# debug ipx sap

  router# debug isdn q921

  router# debug isdn q931

  router# debug dialer

  router# debug ip rip

  router# clear interface bri







Router之設定與管理

學習目標:Router是一般網管人員較少有機會,也較不願去修改其設定的設備,但
如果能充分控制Router對於網路安全會有莫大幫助,本章將以網路上佔有率最高之
Router品牌-Cisco之產品來實作Router之設定與管理。
一、Router 的功用
1. 找出Packet 接下來應該要怎麼走(找出Routing 路徑)
2. 隔絕Broadcast
3. 過濾封包
二、選擇Router 時須注意事項
1. 所欲申請之線路
2. 界面(LAN Port 及WAN 之數量)
3. 與上游Router 之相容性
三、基本觀念
1. 記憶體相關: Cisco Router 內部共有三種記憶體:
(1) EEPROM,或稱為Flash,係用來存放Cisco Router
所用之作業系統(IOS)。
(2) NVRAM,用來存放開機時之設定檔(Startupconfig),
NVRAM 內之資料在電源切斷時並不會
流失。
(3) RAM,用來存放執行中的設定(Running-config)。
如果想將執行中的設定檔變為開機時設定檔,須執行
copy running-config startup-config
反之,若修改設定檔後欲將之還原為開機時設定,須執行
copy startup-conf running-config
2. TFTP: 由於Router 之記憶體有限,故僅提供行編輯器,並不提供全螢
幕之編輯工具,因此在修改時十分不便,因此建議在
UNIX 架設TFTP Server 將設定檔存放在TFTP Server
上,修改時先在UNIX 上編輯完畢,再透過TFTP Server
下載設定檔。另外,如果要升級Router 所使用之IOS
也必須透過TFTP Server。TFTP Server 為簡易之FTP
Server,不提供身分認證,通常用來作網路開機等。有
關TFTP Server 之架設及管理,將在稍後說明。
四、Router 之基本設定
1.初次設定: 一般在購買Router 時都會由廠商先行設定,故在此不作
詳細說明,簡言之,在初次設定時,因為Router 本身未
經設定,沒有網路位址,必須使用RS-232 線(通常購買時會附)及TELIX 等終端機模擬軟體來連線進入Router
內部執行設定,在連線進入Router 後,會出現對話式的
初次設定程式,通常只要一一回答問題即可。有關使用
RS-232 線及終端及模擬軟體連線之方式,請參照購買
Router 時所附之手冊。
2. 後續設定: 在初步設定之後,Router 本身應該有一個IP 位址,這時
候,我們只要使用Netterm 之類的TELNET 軟體,就可
以連線進入Router,在連線進入後,會出現如下的提示:
User Access Verification
Password:
這時候鍵入Router 的第一層密碼(如果不知道密碼的話,
請向購買的廠商查詢。在通過第一層認證後,在提示符號
後鍵入? ,可以看到命令說明。舉例來說,我們可以鍵
入
show version
來查看IOS 版本及Router 硬體,我們也可以鍵入
show flash
來查看Flash ROM 狀況。另外,我們可以鍵入
show interface
來查看網路界面狀況。
IOS 的認證分為兩層,在通過第一層認證後,可以查看系
統情形,但無法作設定,如果要進行設定,必須通過第二
層認證,進入Privileged Mode。要進入Privileged Mode,
請鍵入
enable
在鍵入第二層密碼後(同樣的,如果不知道密碼的話,
請向購買的廠商查詢),會進入Privileged Mode。這時候,
系統的提示符號也會從 > 變為 #
在提示符號之後鍵入
setup
會出現
--- System Configuration Dialog ---
At any point you may enter a question mark '?' for help.
Use ctrl-c to abort configuration dialog at any prompt.
Default settings are in square brackets '[]'.
Continue with configuration dialog? [yes]:
接著只要依序回答問題即可,只是要注意到,在
Configure IP 時會問到是否要Configre IGRP 以及RIP 時,
應該要回答NO,因為一般而言。各校都是直接連接縣網,
只要使用Static Route 即可。
在設定完畢之後,系統會顯示出設定檔,問您是否要採用,
此時,回達Yes 即可。
此外,您也可以鍵入
configure
進行設定。在鍵入configure 後,會出現
Configuring from terminal, memory, or network [terminal]?
的選項,問您要從terminal、memory或是network 進行
configure。從terminal 就是您一行一行的鍵入IOS 指令,
而從memory進行configure 就等於執行copy startup-config
running-config。此外, 選擇從Network 執行configure 就
等於是執行copy tftp running- config。
五、TFTP Server 的架設與管理
一般的UNIX 系統都內建有TFTP Server,只是預設是不啟動的。以
FreeBSD 而言,TFTP Server 的程式應該是在/usr//libexec/tftpd。tftpd 是由inetd
所啟動,所以,請您編輯/etc/inetd,會看到
#tftp dgram udp wait nobody /usr/libexec/tftpd tftpd /tftpboot
請您將行首的# 拿掉,然後在/usr//libexec/tftpd 之後加入-s 路徑名稱,以指
定tftpd 將存放檔案的目錄。在編輯完inetd.conf 後,請重新執行inetd 或是乾脆
將電腦reboot。另外,要注意到,tftpd 只接受上傳已經存在的檔案,如果您要
上傳某個檔案,請先到目錄中touch 該檔案名稱,先將檔案製造出來,然後將
該檔案權限設定好後,再上傳該檔案。詳細資料請
man tftpd
六、Access List
Cisco 的IOS 提供了相當完整的存取控制功能。對於我們只用到其中的
IP Access List 功能,其餘協定的存取控制功能則不在討論範圍。IOS 的Access
List 又可分為standard access list 及extend access list。Standard ip access list 只
能就來源的ip 位址加以限制,而extend ip access list 則可以就來源及目的ip 位
址、協定以及port 來作限制。另外IOS 使用數字編號來區分access list 的類
別。Standard ip access list 的編號是0 -99,而編號100-199 則為extend ip access
list。在使用access list 功能時我們必須先定義access list,定義Standard ip access
list 的語法是:
access-list 編號permit/deny 來源位址(網路遮罩)
舉例來說,假使我們想要拒絕來自192.168.1.0 這個class ip 的主機連線,我們
就可以這樣定義:
access-list 1 deny 192.168.1.0 0.0.0.255
要注意的是在定義access list 時使用的netmask 與我們一般切割子網域的
netmask 不同,在這裡0代表must match,1 代表don't care。也就是說設定0.0.0.255 代
表IP 位址第四個數字可以為0 到255 間的任何數。如果設定0.0.3.255 則代表第三
個數字可以為1、2、3 三個數字,而第四個數字則可以為0 到255 間的任何數。
而定義Extend ip access list 的語法則是:
access-list 編號permit/deny 協定來源位址(網路遮罩) [port] 目的位
址(網路遮罩)[port]
IP 協定包含了TCP、UDP 以及ICMP 協定﹐所以在使用前您必須了解您所要過濾的功能是使用哪一種協定。
Access list 可以做到一些基本的網路防護功能﹐﹐以下將舉以一些實例來說
明。要注意到﹐Access list 的功能隨著IOS 的改版一直在做加強﹐也就是說﹐
如果您的IOS 版本太舊﹐可能無法做到某些功能。
例一:
在網路上﹐駭客們要入侵一部網路主機時﹐為了怕被追查出來源﹐常常會
使用IP 偽裝的技術﹐也就是使用假的IP﹐通常駭客們最常使用的假IP 有兩種﹐
一是被攻擊端的IP﹐另一種則是在RFC1918 裡定義用來作Private IP 的三段IP
位址﹐分別是
10.0.0.0 -10.255.255.255
172.16.0.0 - 172.36.255.255
192.168.0.0 - 192.168.255.255
以本校為例﹐本校所使用的IP 是203.68.238.0 這一段Class C 的IP。我們可以
在Internet 的入口處將上述各段IP 攔截下來﹐因為在理論上﹐這些IP 是不會
從Internet 上進入本校的。所以我們可以定義這樣的Access List
access-list 101 deny ip 203.68.238.0 0.0.0.255 any
access-list 101 deny ip 10.0.0.0 0.255.255.255 any
access-list 101 deny ip 172.16.0.0 0.15.255.255 any
access-list 101 deny ip 192.168.0.0 0.0.255.255 any
access-list 101 permit ip any any
.在定義完Access List 後﹐我們必須指定在哪個界面上使用這個Access list ﹐在
本例中應該是用在serial0 上面﹐而且是不讓來自上述IP 的封包往內傳﹐所以
語法應該如下:
interface serial0
ip access-group 101 in
例二:
在網路上有一種攻擊手法叫做Ping to death﹐他的原理很簡單﹐只要找幾部
MS-Windows 的機器﹐開一個DOS 視窗﹐然後執行
ping –t 目標位址
MS-Windows 機器就會不停的向該主機送出echo request﹐直到指令被人為中斷
為止。而如果發出echo request 的機器夠多的話﹐該部主機就會因為忙於回覆echo
request,而耗盡資源。防止這樣的攻擊也很簡單﹐以本校為例只要設定下列access
list 即可:
access-list 101 deny icmp any 203.68.238.0 0.0.0.255 echo
定義這樣的access list 並將它使用在由internet 往內的界面會使得外界機器
無法對內部機器作ping 的動作﹐也就無法使用ping to death 的攻擊。
例三:
前一陣子網路上很流行SYN flooding 的攻擊手法﹐它的原理是:當我們要
和網路上某部主機連線時﹐首先兩部主機會進行handshake 的動作﹐甲方會先
送出設定SYN bit 的封包﹐而乙方在收到封包之後﹐會回應設定SYN 以及ACK
bit 的封包﹐然後等待甲方在一定的時間內回應設定ACK 的封包。如果甲方一
直沒有回應﹐乙方就會將這個連接設定為逾時。但是在等待甲方回應的過程中﹐這些連線還是會耗費乙方的資源﹐如果甲方惡意的送出大量這樣的封包﹐乙方
的資源很快就會被耗盡。也就導致所謂的DoS (Denial of Service)。在IOS 11.3
版之後提供了TCP Intercept 的功能﹐可以有效防止這樣的攻擊。TCP Intercept
的運作原理是Router 會介入並檢查TCP 連線﹐這個功能有兩種模式: intercept
及watch。在intercept 模式中﹐Router 會介入往內的連線要求﹐並且以模擬Server
的動作和Client 端建立連線﹐並模擬Client 端和Server 建立連線。如果兩邊都
沒有問題﹐Router 就將兩端連接起來。而為了防止本身的資源被耗盡﹐Router
上可以設定同時存在未完成連線的上限。而在watch 模式中Router 只是被動的
監視未完成的連線﹐然後在一定的時間到達後將其關閉。啟動TCP Intercept 要
兩道手續﹐首先﹐定義一個access list 允許連接到所要保護的主機﹐語法如下:
access-list 編號 permit tcp any 目標(網路遮罩)
然後使用ip tcp intercept 指令來啟動TCP Intercept﹐語法如下:
ip tcp intercept list 編號
舉例而言﹐如果您要保護的SERVER IP 為198.78.46.20﹐您應該下這樣的指令:
ip tcp intercept list 101
access-list 101 permit tcp any host 198.78.46.0
例四:
前幾個例子都是防止外人入侵內部網路﹐這一個例子則是要強迫內部網路
使用者都透過我們的Proxy Server 上網﹐以節省網路頻寬﹐並可透過Proxy Server
來達到過濾網站的功能﹐以本校為例﹐本校的Proxy Server IP 為203.68.238.6﹐
設定如下:
access-list 100 permit tcp host 203.68.238.6 any eq www
#准許Proxy Server 存取外界WWW
access-list 100 permit tcp host 203.68.238.6 any eq 3128
#准許Proxy Server 存取外界其它Proxy Server
access-list 100 permit udp host 203.68.238.6 any eq 3130
#准許Proxy Server 存取外界其他Proxy Server
access-list 100 deny tcp 203.68.238.0 0.0.0.255 any eq www
#禁止內部網路機器直接存取外界WWW
access-list 100 deny tcp 203.68.238.0 0.0.0.255 any eq 3128
#禁止內部網路機器存取外界其它Proxy Server
access-list 100 deny udp 203.68.238.0 0.0.0.255 any eq 3130
#防止內部網路有人架設Proxy Server 存取外界Proxy Server
access-list 100 permit ip any any
允許其他類型連線。
iterface serial 0
acess-list 100 out
要注意到﹐當Router 在檢查封包時﹐使用的是First Match 的方法﹐也就是
說﹐會就Access list 中所訂定之過濾條件由上往下過濾﹐當一發現適用的條件
就直接決定放行或丟棄該封包。而以下的條件就不在檢查。因此訂立過濾條件
的順序很重要﹐一個不小心就會讓網路出錯。另外﹐Access list 的預設是---除非
在list 中明定放行﹐否則一律丟棄﹐因此﹐建議在最後要加上permit ip any any 的設定﹐以免網路全面癱瘓。
最後介紹一個不是Access List﹐但是非常有用的指令。在網路上有一種攻
擊的手法是對某一網域的廣播位址作ping 的動作﹐這樣的動作會使得該網域的
所有機器都收到Echo request﹐而所有的機器也都會回應Echo reply﹐這樣很容
易會造成網路癱瘓﹐如果有駭客冒用A 網域IP 對B 網域作上述動作的話﹐會
造成A、B 兩網域都癱瘓(B 網域會因為收到太多的Echo Reply 而癱瘓)。要
防止這樣的攻擊﹐只要在Router 對每一界面下:
no ip directed broadcasts
即可。
參考書目
CISCO ROUTER CONFIGURATION:Allan Leniwand﹐Bruce Pinsky﹐Mark
Culpepper﹐Macmillan Technical Publishing
Sys Admin, November 1999 P29-34, Router Access Lists, by Gilbert Held
Sys Admin, March 2000, P61-65, Router-Based Network Defense, by Gilbert Held

轉載自

Cisco 2600 系列 IOS 災難回復與 IOS 更新

所需軟體:1.Cisco 2600 IOS 2.TFTP Server
所需硬體:1.Cisco Console線 2.PC一台

IOS災難回復的方式有2種:
------------------------------------------------------------------------
1.使用 TFTP
在一台PC上安裝TFTP Server,將IOS文件放置在TFTP Server預設的根目錄下,
Run TFTP Server,用Console線將這台PC與ROUTER連接起來,另外用網路線(跳線)
連接PC的網卡和ROUTER的 Ethernet0/0(當然如果透過HUB,SWITCH就不用跳線了!)
做好以上動作後,打開PC上的超級終端機程式,連接上ROUTER,此時視窗中出現的
命令提示字元為: ROMMON 1 > (其中「1」代表命令列的行數)。

在提示字元後輸入命令:
ROMMON 1 >IP_ADDRESS= x.x.x.x (ROUTER的IP Address,要和TFTP Server在同一網段內)
ROMMON 2 >IP_SUBNET_MASK= x.x.x.x (ROUTER的 Subnet Mask)
ROMMON 3 >DEFAUT_GATEWAY= x.x.x.x (可以不設,也可以是TFTP Server的IP)
ROMMON 4 >TFTP_SERVER= x.x.x.x (TFTP Server 的IP Address)
ROMMON 5 >TFTP_FILE= c2600-d-mz.120-5 (IOS檔案名稱,只給檔案名稱,不需要路徑)
ROMMON 6 >tftpdnld (按下Enter)

注意:前面的幾條命令必須使用大寫,而最後的tftpdnld則要用小寫

在tftpdnld命令執行後,只要根據提示選擇,就可完成IOS的傳輸
當IOS傳輸完畢後,將自動回到命令行,輸入reset重開ROUTER
重開機完成後就可以回到熟悉的IOS模式下~~~~



2.用Console線直接安裝IOS
該種方式下載不需要用到網路,只需超級終端機即可。缺點是花費時間太多,速度太慢
ROMMON 1 >
ROMMON 2 >xmodem -r (xmodem -cx 也可以)
接下來回答 y 即可
最後在超級終端機的 傳送 功能表內選則 傳送檔案
選好檔案後,用Xmodem的通訊協定傳送檔案,等10~20分鐘後即可完成!



IOS更新的方式:
------------------------------------------------------------------------
非常簡單,只需進入enable模式,執行copy指令即可

Route#copy tftp: flash:

接著依序輸入 tftp的ip即可,重開機完成後就升級完成了

基礎入門︰Cisco配置手記

現有設備︰CISCO路由器2620XM(4台)和2621XM(5台),3750三層交換機,PIX-515E防火牆,CISCO2950二層交換機(9台)
重點命令︰有安全,控制,監控,監測和檢測功能的命令集合和命令組合

一、兩層交換機

1、基本配置
(1)設置VLAN1的IP地址,掩碼︰

配置︰
sw itch#config terminal
(config)#interface vlan1 !進入到要配置IP的接口
(config-if)#ip address 10.1.10.253(ip) 255.255.255.0(mask) !設置參數
驗證︰
(config-if)#exit
switch#show interface vlan1
保存設置︰
switch#copy running-config startup-config

(2)劃分VLAN
配置︰
switch#vlan database(還有一種方法) !創建一個VLAN
switch#vlan 2
switch#exit
switch#config terminal
one port:
(config)#interface fastethernet0/0 !進入到要被劃分的端口
(config-if)#switchport access vlan 2 !劃分到一個VLAN
multiports:
(config)#interface range fastethernet0/0 -7 !進入到要被集體劃分的端口
(config-if)#switchport access vlan 2 !劃分到一個VLAN
驗證︰
switch#show vlan
保存︰
switch#copy running-config startup-config

(3)設置trunk
配置︰
switch#config terminal
(config)#interface gigabitethernet0/1 !進入要配置成干道的接口
(config-if)#switchport mode trunk !設置成干道
驗證︰
switch#show interface trunk
保存︰
switch#copy running-config startup-config

(4)連接路由器
如果交換機上有多個VLAN,則所連的路由器接口就必須有多個IP地址。要用子接口設置多IP地址。連接到路由器上的接口要被設置成trunk,並且要封裝干道協議︰ISL,或者802.1Q。
配置交換機︰
switch#config terminal
(config)#interface gigabitethernet0/1
(config-if)#switchport mode trunk !配置成干道,將自動封裝802.1q協議
配置路由器︰
router#config terminal
(config)#interface fastethernet0/0.2 !進入子接口2
(config-subif)#encapsulation dot1q 2 !子接口對應VLAN2,並封裝dot1q協議
(config-subif)#ip address 10.1.20.1 255.255.255.0 !配置了10.1.20.0/24網段的網關
確認︰
router#show interface fastethernet0/0
不同VLAN下的主機可以相互ping通,則配置成功。
保存配置

(5)連接交換機
同種類型的網絡設備相連要使用交叉線。交換機使用交叉線相連後,將會自動將兩端設置成干道。

2、VTP(VLAN Trunk Protocol)
(1) 作用︰
允許用戶集中管理網絡中交換機的配。VTP是一種消息協議,可以對整個網絡內的VLAN的添加、刪除和重命名操作進行管理,以此維護VLAN配置的一致性。
(2) 工作方式
確定一條交換機為VTP服務器。
可以在服務器上更改VLAN的配置,並把該配置傳播到網絡中的所有VTP客戶機。
當交換機配置成VTP客戶機之後,就不能物理地改變該交換機的VLAN配置。
唯一可以更改VLAN配置的方法是當且僅當VTP客戶端交換機接收到來自其VTP服務器的VTP更新信息時,才能更改。
多台VTP服務器管理不同的VTP客戶機,必須指定一個VTP域。服務器和客戶機在各自的域內。

二、路由器
1、基本配置

(1)以太網口配置
注︰路由器以太網口直接接主機用交叉線。
(2)串口配置
(3)配置靜態路由
(4)配置動態路由協議
(5)配置訪問控制列表(ACL)**
(6)路由器互聯

2、問題
(1)無法配置靜態路由,出現“Default gateway is not set ….. ICMP redirect cache is empty”
原因︰IP路由被禁用
解決︰(config)#ip routing

(2)與其他設備的接口狀態上,”protocol down”
可能的原因︰雙絞線的接線類型不對
解決︰換成直通線或者交叉線。

三、三層交換機
1、基本配置

(1)配置IP
手工配置︰
(config)#interface vlan vlan-id
(config-if)#ip address ip-address subnet-mask
(config-if)#exit
(config)#ip default-gateway ip-address
確認配置︰
#show interface vlan vlan-id
#show ip redirects !確認默認網關配置
保存︰#copy running-config startup-config
使用DHCP配置

(2)使不同VLAN互聯

(3)配置某個端口為trunk
(config)#interface fastethernet1/0/23
(config-if)#switchport encapsultion dot1q
(config-if)#switchport mode trunk

(4)默認路由及路由協議的設定
問題
(1)多個子網連接到三層交換機,交換機上設定了每個子網對應的網關地址,交換機通過router連接到其他的網絡或者區域。三層switch和router上相同網段的地址無法相互ping 通。如︰3750上有192.168.8.254(VLAN1),192.168.16.254(VLAN2),192.168.24.254(VLAN3);router上有192.168.8.1,192.168.16.1,192.168.24.1。
現象︰192.168.8.254 可以ping通192.168.8.1,但是.16.和.24.網段的無法ping通。
原因︰router接到switch上的接口沒有設置成trunk。

四、防火牆
CISCO PIX系列屬于狀態檢測防火牆。
Note:ASA(Adaptive Security Algorithm) allows one way (inside to outside) connections without an explicit configuration in memory.

1、特點
(1)自適應安全算法(ASA)
創建狀態會話流表(state table)。各種連接信息都被記錄進表中。
ASA吤B桓 凶刺  嫦蛄 擁墓蹋 謐刺 碇形 只嶧靶畔  τ枚宰刺 淼陌踩 唄岳純僕 闌鵯降乃辛髁俊BR>連接狀態包括︰源/目的IP,源/目的端口,TCP順序信息,附加的TCP/UDP標記。應用一個隨機產生的TCP順序號。總稱為“會話對象”。

內部不主動發出數據,要求響應,外部的數據就無法進入內部了嗎。
PIX中ASA和狀態過濾的工作機制︰
a、 內部主機開始一個對外部資源的連接
b、 PIX在狀態表中寫入一個會話(連接)對象
c、 會話對象同安全策略相比較。如果連接不被允許,此會話對象被刪除,並且連接被取消
h、 如果安全策略認可這個連接,此連接繼續向外部資源發送
j、 外部資源響應這個請求
k、 響應信息到達防火牆,與會話對象比較。匹配則響應信息被發送到內部主機,不匹配則連接就會被取消。

(2)貫穿式代理
認證和授權一個防火牆上輸入/輸出的連接。
它在應用層完成用戶認證,依照安全策略檢驗授權。當安全策略授權時打開這個連接。這個連接後面的流量不再在應用層處理,而是進行狀態檢測。

(3)冗余

2、基本配置

配置完基本參數後,發現從PIX上可以ping通內網和外網的地址。但是內外網的主機無法相互ping通。內網主機無法ping通PIX外口。但是,內網主機可以訪問外網的服務器。(可能原因︰PIX默認關閉ICMP響應??)

基本配置命令︰interface , nameif , ip address , nat , global , route


(1)激活以太端口
firewell#config terminal
(config)#interface ethernet0 auto
(config)#interface ethernet1 auto !外口必須用命令激活

(2)命名端口和安全級別
(config)#nameif ethernet1 inside security0
(config)#nameif ethernet0 outside security100

(3)配置內外口
firewell#config terminal
(config)#ip address inside 192.168.1.1 255.255.255.0
(config)#ip address outside 222.20.16.1 255.255.255.0

(4)配置NAT和PAT
(config)#nat (inside) 1 0 0 !所有的內口地址都
(config)#nat (inside) 2 192.168.8.0 255.255.255.0
(config)#global (outside) 2 10.1.30.150-10.1.30.160 netmask 255.255.0.0
測試配置︰
ping
debug

(5)DMZ的訪問

(6)轉換表的操作
show xlate 顯示轉換表的信息
clear xlate 每次重建轉換表要運行,以清除原有的轉換槽,否則原信息將在超時(3小時)後才被丟棄
show conn 查找連接故障,為選擇的特定選項顯示所有活動的TCP連接的數量和狀態
可以更改轉換表的操作︰
nat ,global ,static ,route,alias,conduit

(7)配置網絡時間協議(NTP)
NTP server與PIX的關系

(8)訪問配置
經由PIX的入站訪問

step1︰靜態網絡地址轉換
靜態網絡地址轉換,不節省已經分配的IP地址
static [( prenat_interface,postnat_interface)] {mapped_address | interface} real_address [dns] [netmask mask] [norandomseq] [ max_cons [em_limit]]
設定一個內部地址到一個外部地址的映射
(config)#static (inside,outside) 211.70.96.10 10.1.100.10 netmask 255.255.255.255
或者一個內部網絡到一個外部網絡的映射
(config)#static (inside,outside) 211.70.96.0 10.1.100.0 netmask 255.255.255.0
靜態端口地址轉換,不支持H.323或者多媒體應用流量
static [(internal_if_name,external_if_name)] {tcp|udp} {global_ip | interface} global local_ip local_port [netmask mask] [ max_cons [emb_limit [norandomseq]]]

Cisco PIX/ASA 中的一個設定上的專有名詞,叫做『 Security Level 』

The primary rule for security levels is that an interface with a higher security level can access an interface with a lower security level

Conversely, an interface with a lower security level cannot access an interface with a higher security level without an access control list (ACL).

Security levels range from 0 to 100

(1) Higher security level interface to a lower security level interface
- For traffic originating from the inside interface of the PIX with a security level of 100 to the outside interface of the PIX with a security level of 0, all IP-based traffic is allowed unless it is restricted by ACLs, authentication, or authorization

(2) Lower security level interface to a higher security level interface
- For traffic originating from the outside interface of the PIX with a security level of 0 to the inside interface of the PIX with a security level of 100,all packets are dropped unless specifically allowed by an access-list command. The traffic can be restricted further if authentication and authorization is used

(3) Same secure interface to a same secure interface
- No traffic flows between two Interfaces with the same security level

介紹一下 Cisco PIX/ASA 中的一個設定上的專有名詞,叫做『 Security Level 』,其設定值為 0 到 100 間的任一整數,數字越小代表由其連接的網路所進來封包資料,越不可靠、越危險,安全性 (security) 越低。因此,通常我們會設定連接到 Internet 的介面的『 Security Level 』設為 0 ,而連接內部或是可靠網路介面的『 Security Level 』設為 100 , DMZ 的『 Security Level 』則設為 0 到 100 中間的任一值;不同『 Security Level 』之間的資料流量有其規定,從『 Security Level 』大傳到『 Security Level 』小的資料不會被阻擋,從『 Security Level 』小傳到『 Security Level 』大的資料則會被阻擋,如過要讓其資料可以通過的話,則需要額外下達防火牆規則來檢驗,通過檢驗才可通過

使用cisco pix 防火牆

1.interface command
在配置用戶介面的時候我們經常聽到關於介面的專有名詞
hardware_id指ethernet 0,e1,e2
interface_name指outside,inside,dmz
hardware_speed,通產設置為自動,但是cisco推薦我們手動配置速度.關於速度和你選擇的網路傳輸介質有關.
no shutdown在router上用戶激活這個端口 ,在pix中,沒有no shutdown命令,只有使用到shutdown這個參數,主要用於管理關閉介面.
interface hardware_id hardware_speed [shutdown]
interface e0 auto
interface e1 auto
interface e2 auto

2.nameif command
nameif 主要用於命令一個介面,並且給它分配一個從1到99的安全值,因為外部介面和內部介面都是默認的,分別是0和100,同時默認情況下e0是外部介面,e1是指內部介面.
nameif hardware_id if_name security_level
nameif e0 outside 0
nameif e1 inside 100
nameif e2 dmz 50
使用show nameif來查看配置情況
關於security_level值得區別,請都看看我前面寫的.從高安全段的流量到低安全段的流量怎麼走,放過又怎麼走,需要什麼條件才能流進流出.

3.ip address command
cisco pix介面的ip 地址可以從兩個地方來獲得,分別是 manual 和dhcp
ip address用於手動配置一個介面上的ip address,通過將一個邏輯地址添加到一個硬體ID上.
ip address if_name ip_address [netmask]
ip address inside 192.168.6.0 255.255.255.0
Remove the currently configured ip address pix(config)#clear ip address (全部清除ip address)
pix(config)#no ip address inside 192.168.6.0 255.255.255.0(清除這個介面的ip address)

4.Nat command
用於一組ip 地址轉換成另外一組ip 地址,昨天我看到6.2版本支援nat outside ip address,不知道這個究竟在什麼環境才用到,呵呵
在用nat命令的時候,有個特別的注意點:nat 0有特殊含義,其次nat 總是和global一起使用.
nat (if_name) nat_id local_ip [netmas]
nat (inside) 1 192.168.6.0 255.255.255.0

5.Global command
global命令用於定義用nat命令轉換成的地址或者地址範圍,注意global命令中的nat_id需要和你配置的nat命令中的nat_id相同.
global (if_name) nat_id global_ipglobal_ip-global_ip [netmask]
global (outside) 1 10.0.0.1 255.0.0.0 (PAT轉換,當你用這個命令,CLI會給你一個警告資訊指出pix要PAT的所有地址)
global (outside) 1 10.0.0.1~10.0.0.254 255.0.0.0

這裡有這樣一個命令可以在pix檢測轉換表中查看你是否有這個特定ip的入口.show xlate,一般一個被轉換的ip address保存在轉換表中的默認時間是3個小時.你可以通過timeout xlate hh:ss來更改這個設置.

這裡你也同樣需要了解PAT是怎麼工作的,同樣你要知道PAT也有局限,不能支援H.323和高速緩存使用的名稱伺服器,老實說我也不知道這兩個是什麼東東:(

6.route command,very important!!!
route告訴我們要在那個特定的介面轉發,並指定那個特定的網路地址.使用route命令向pix增加一個靜態路由.
route if_name ip_address netmask gateway_ip [metric]
說明一下if_name指你數據要離開處的那個端口
ip_address被路由的ip address
netmask被路由的ip address的網路掩碼
gateway_ip 下一跳的ip address
metric到下一個設備的跳數

在pix上用的最多的是配置一個默認路由
route outside 0 0 192.168.1.3 1 其中0 0 表示網段內所有的ip address從outside ip address是192.168.1.3齣去
如果你想要測試新的路由配置,在這之前用clear arp清除pix firewall的arp高速緩存is a good idea.

7.RIP command
不講,不想了解,也不知道,沒有見過那個人在配置PIX用過RIP協議的
需要了解的人查書吧,如果你有這方面的經驗,可以寫出來大家share一下:)

8.測試你的配置,一般有幾種,首先查看一下你的配置命令是否正確,show xxxxx來查看。show interface,show nameif,show ip address,show route,show nat,show global 等等.其次使用ping命令,前提是你需要使用icmp permit any any outside,因為默認情況下pix是拒絕所有來自於外部介面的輸入流量的,除非你使用conduit permit icmp any any ,但是這個命令使你不能ping通外部介面的ip address.最後是用debug命令,debug icmp trace,建議大家可以看看,但是看了之後最好關掉,以便影響pix的performance.

9.配置每一個pix命令是在pix立刻反應出來的,所以你可以嘗試配置,但是不要配置,等你有把握時在保存wr m,但你配置錯誤,你可以reload一下就可以了.

10.pix對dhcp支援
10.1首先是可以將pix配置為dhcp server.PIX dhcp伺服器只能在pix的內部介面上激活,同時你需要搜尋資料,因為個別的如506/506e,由於OS版本不同,對client ip address支援數目也不同.
dhcpd enable inside
dhcpd address 192.168.10.0-192.168.10.200 255.255.255.0
dhcpd lease 2700 (授權用戶的租借長度,默認時間是3600s)
dhcpd dns 61.177.7.1
dhcpd wins 61.177.7.1
dhcpd domain testing.cn
10.2可以將pix的外部介面配置為從ISP處接收地址
ip address outside dhcp [setroute] [retry retry_cnt]
setroute告訴pix防火牆使用默認網關參數設置的DHCP伺服器返回的默認路由,當使用setroute選項時不再配置默認路由
同樣可以使用ip address dhcp來釋放和重建一個外部介面的ip address
通過show ip address dhcp來查看當前的租借資訊.

11.時間設置和NTP支援
手動配置和通過NTP伺服器獲得系統時間.
手動配置clock set hh:mm:ss month day year

Cisco 交換機命令全集

1.在基於IOS的交換機上設置主機名/系統名:
switch(config)# hostname hostname
在基於CLI的交換機上設置主機名/系統名:
switch(enable) set system name name-string

2.在基於IOS的交換機上設置登錄口令:
switch(config)# enable password level 1 password
在基於CLI的交換機上設置登錄口令:
switch(enable) set password
switch(enable) set enalbepass

3.在基於IOS的交換機上設置遠程訪問:
switch(config)# interface vlan 1
switch(config-if)# ip address ip-address netmask
switch(config-if)# ip default-gateway ip-address
在基於CLI的交換機上設置遠程訪問:
switch(enable) set interface sc0 ip-address netmask broadcast-address
switch(enable) set interface sc0 vlan
switch(enable) set ip route default gateway

4.在基於IOS的交換機上啟用和瀏覽CDP信息:
switch(config-if)# cdp enable
switch(config-if)# no cdp enable
為了查看Cisco鄰接設備的CDP通告信息:
switch# show cdp interface [type modle/port]
switch# show cdp neighbors [type module/port] [detail]
在基於CLI的交換機上啟用和瀏覽CDP信息:
switch(enable) set cdp {enable|disable} module/port
為了查看Cisco鄰接設備的CDP通告信息:
switch(enable) show cdp neighbors[module/port] [vlan|duplex|capabilities|detail]

5.基於IOS的交換機的端口描述:
switch(config-if)# description description-string
基於CLI的交換機的端口描述:
switch(enable)set port name module/number description-string

6.在基於IOS的交換機上設置端口速度:
switch(config-if)# speed{10|100|auto}
在基於CLI的交換機上設置端口速度:
switch(enable) set port speed moudle/number {10|100|auto}
switch(enable) set port speed moudle/number {4|16|auto}

7.在基於IOS的交換機上設置以太網的鏈路模式:
switch(config-if)# duplex {auto|full|half}
在基於CLI的交換機上設置以太網的鏈路模式:
switch(enable) set port duplex module/number {full|half}

8.在基於IOS的交換機上配置靜態VLAN:
switch# vlan database
switch(vlan)# vlan vlan-num name vla
switch(vlan)# exit
switch# configure teriminal
switch(config)# interface interface module/number
switch(config-if)# switchport mode access
switch(config-if)# switchport access vlan vlan-num
switch(config-if)# end
在基於CLI的交換機上配置靜態VLAN:
switch(enable) set vlan vlan-num [name name]
switch(enable) set vlan vlan-num mod-num/port-list

9. 在基於IOS的交換機上配置VLAN中繼線:
switch(config)# interface interface mod/port
switch(config-if)# switchport mode trunk
switch(config-if)# switchport trunk encapsulation {isl|dotlq}
switch(config-if)# switchport trunk allowed vlan remove vlan-list
switch(config-if)# switchport trunk allowed vlan add vlan-list
在基於CLI的交換機上配置VLAN中繼線:
switch(enable) set trunk module/port [on|off|desirable|auto|nonegotiate]
Vlan-range [isl|dotlq|dotl0|lane|negotiate]

10.在基於IOS的交換機上配置VTP管理域:
switch# vlan database
switch(vlan)# vtp domain domain-name
在基於CLI的交換機上配置VTP管理域:
switch(enable) set vtp [domain domain-name]

11.在基於IOS的交換機上配置VTP 模式:
switch# vlan database
switch(vlan)# vtp domain domain-name
switch(vlan)# vtp {sever|cilent|transparent}
switch(vlan)# vtp password password
在基於CLI的交換機上配置VTP 模式:
switch(enable) set vtp [domain domain-name] [mode{ sever|cilent|transparent }][password password]

12. 在基於IOS的交換機上配置VTP版本:
switch# vlan database
switch(vlan)# vtp v2-mode
在基於CLI的交換機上配置VTP版本:
switch(enable) set vtp v2 enable

13. 在基於IOS的交換機上啟動VTP剪裁:
switch# vlan database
switch(vlan)# vtp pruning
在基於CL I 的交換機上啟動VTP剪裁:
switch(enable) set vtp pruning enable

14.在基於IOS的交換機上配置以太信道:
switch(config-if)# port group group-number [distribution {source|destination}]
在基於CLI的交換機上配置以太信道:
switch(enable) set port channel moudle/port-range mode{on|off|desirable|auto}

15.在基於IOS的交換機上調整根路徑成本:
switch(config-if)# spanning-tree [vlan vlan-list] cost cost
在基於CLI的交換機上調整根路徑成本:
switch(enable) set spantree portcost moudle/port cost
switch(enable) set spantree portvlancost moudle/port [cost cost][vlan-list]

16.在基於IOS的交換機上調整端口ID:
switch(config-if)# spanning-tree[vlan vlan-list]port-priority port-priority
在基於CLI的交換機上調整端口ID:
switch(enable) set spantree portpri {mldule/port}priority
switch(enable) set spantree portvlanpri {module/port}priority [vlans]

17. 在基於IOS的交換機上修改STP時鐘:
switch(config)# spanning-tree [vlan vlan-list] hello-time seconds
switch(config)# spanning-tree [vlan vlan-list] forward-time seconds
switch(config)# spanning-tree [vlan vlan-list] max-age seconds

在基於CLI的交換機上修改STP時鐘:
switch(enable) set spantree hello interval[vlan]
switch(enable) set spantree fwddelay delay [vlan]
switch(enable) set spantree maxage agingtiame[vlan]

18. 在基於IOS的交換機端口上啟用或禁用Port Fast 特徵:
switch(config-if)#spanning-tree portfast
在基於CLI的交換機端口上啟用或禁用Port Fast 特徵:
switch(enable) set spantree portfast {module/port}{enable|disable}

19. 在基於IOS的交換機端口上啟用或禁用UplinkFast 特徵:
switch(config)# spanning-tree uplinkfast [max-update-rate pkts-per-second]
在基於CLI的交換機端口上啟用或禁用UplinkFast 特徵:
switch(enable) set spantree uplinkfast {enable|disable}[rate update-rate] [all-protocols off|on]

20. 為了將交換機配置成一個集群的命令交換機,首先要給管理接口分配一個IP地址,然後使用下列命令: switch(config)# cluster enable cluster-name

21. 為了從一條中繼鏈路上刪除VLAN,可使用下列命令:
switch(enable) clear trunk module/port vlan-range

22. 用show vtp domain 顯示管理域的VTP參數.

23. 用show vtp statistics顯示管理域的VTP參數.

24. 在Catalyst交換機上定義TrBRF的命令如下:
switch(enable) set vlan vlan-name [name name] type trbrf bridge bridge-num[stp {ieee|ibm}]

25. 在Catalyst交換機上定義TrCRF的命令如下:
switch (enable) set vlan vlan-num [name name] type trcrf
{ring hex-ring-num|decring decimal-ring-num} parent vlan-num

26. 在創建好TrBRF VLAN之後,就可以給它分配交換機端口.對於以太網交換,可以採用如下命令給VLAN分配端口:
switch(enable) set vlan vlan-num mod-num/port-num

27. 命令show spantree顯示一個交換機端口的STP狀態.

28. 配置一個ELAN的LES和BUS,可以使用下列命令:
ATM (config)# interface atm number.subint multioint
ATM(config-subif)# lane serber-bus ethernet elan-name

29. 配置LECS:
ATM(config)# lane database database-name
ATM(lane-config-databade)# name elan1-name server-atm-address les1-nsap-address
ATM(lane-config-databade)# name elan2-name server-atm-address les2-nsap-address
ATM(lane-config-databade)# name …

30. 創建完數據庫後,必須在主接口上啟動LECS.命令如下:
ATM(config)# interface atm number
ATM(config-if)# lane config database database-name
ATM(config-if)# lane config auto-config-atm-address

31. 將每個LEC配置到一個不同的ATM子接口上.命令如下:
ATM(config)# interface atm number.subint multipoint
ATM(config)# lane client ethernet vlan-num elan-num

32. 用show lane server 顯示LES的狀態.

33. 用show lane bus顯示bus的狀態.

34. 用show lane database顯示LECS數據庫可內容.

35. 用show lane client顯示LEC的狀態.

36. 用show module顯示已安裝的模塊列表.

37. 用物理接口建立與VLAN的連接:
router# configure terminal
router(config)# interface media module/port
router(config-if)# description description-string
router(config-if)# ip address ip-addr subnet-mask
router(config-if)# no shutdown

38. 用中繼鏈路來建立與VLAN的連接:
router(config)# interface module/port.subinterface
router(config-ig)# encapsulation[isl|dotlq] vlan-number
router(config-if)# ip address ip-address subnet-mask

39. 用LANE 來建立與VLAN的連接:
router(config)# interface atm module/port
router(config-if)# no ip address
router(config-if)# atm pvc 1 0 5 qsaal
router(config-if)# atm pvc 2 0 16 ilni
router(config-if)# interface atm module/port.subinterface multipoint
router(config-if)# ip address ip-address subnet-mask
router(config-if)# lane client ethernet elan-num
router(config-if)# interface atm module/port.subinterface multipoint
router(config-if)# ip address ip-address subnet-name
router(config-if)# lane client ethernet elan-name
router(config-if)# …

40. 為了在路由處理器上進行動態路由配置,可以用下列IOS命令來進行:
router(config)# ip routing
router(config)# router ip-routing-protocol
router(config-router)# network ip-network-number
router(config-router)# network ip-network-number

41. 配置默認路由:
switch(enable) set ip route default gateway

42. 為一個路由處理器分配VLANID,可在接口模式下使用下列命令:
router(config)# interface interface number
router(config-if)# mls rp vlan-id vlan-id-num

43. 在路由處理器啟用MLSP:
router(config)# mls rp ip

44. 為了把一個外置的路由處理器接口和交換機安置在同一個VTP域中:
router(config)# interface interface number
router(config-if)# mls rp vtp-domain domain-name

45. 查看指定的VTP域的信息:
router# show mls rp vtp-domain vtp domain name

46. 要確定RSM或路由器上的管理接口,可以在接口模式下輸入下列命令:
router(config-if)#mls rp management-interface

47. 要檢驗MLS-RP的配置情況:
router# show mls rp

48. 檢驗特定接口上的MLS配置:
router# show mls rp interface interface number

49. 為了在MLS-SE上設置流掩碼而又不想在任一個路由處理器接口上設置訪問列表:
set mls flow [destination|destination-source|full]

50. 為使MLS和輸入訪問列表可以兼容,可以在全局模式下使用下列命令:
router(config)# mls rp ip input-acl

51. 當某個交換機的第3層交換失效時,可在交換機的特權模式下輸入下列命令:
switch(enable) set mls enable

52. 若想改變老化時間的值,可在特權模式下輸入以下命令:
switch(enable) set mls agingtime agingtime

53. 設置快速老化:
switch(enable) set mls agingtime fast fastagingtime pkt_threshold

54. 確定那些MLS-RP和MLS-SE參與了MLS,可先顯示交換機引用列表中的內容再確定:
switch(enable) show mls include

55. 顯示MLS高速緩存記錄:
switch(enable) show mls entry

56. 用命令show in arp顯示ARP高速緩存區的內容。

57. 要把路由器配置為HSRP備份組的成員,可以在接口配置模式下使用下面的命令:
router(config-if)# standby group-number ip ip-address

58. 為了使一個路由器重新恢復轉發路由器的角色,在接口配置模式下:
router(config-if)# standy group-number preempt

59. 訪問時間和保持時間參數是可配置的:
router(config-if)# standy group-number timers hellotime holdtime

60. 配置HSRP跟蹤:
router(config-if)# standy group-number track type-number interface-priority

61. 要顯示HSRP路由器的狀態:
router# show standby type-number group brief

62. 用命令show ip igmp確定當選的查詢器。

63. 啟動IP組播路由選擇:
router(config)# ip muticast-routing

64. 啟動接口上的PIM:
dalllasr1>(config-if)# ip pim {dense-mode|sparse-mode|sparse-dense-mode}

65. 啟動稀疏-稠密模式下的PIM:
router# ip multicast-routing
router# interface type number
router# ip pim sparse-dense-mode

66. 核實PIM的配置:
dallasr1># show ip pim interface[type number] [count]

67. 顯示PIM鄰居:
dallasr1># show ip neighbor type number

68. 為了配置RP的地址,命令如下:
dallasr1># ip pim rp-address ip-address [group-access-list-number][override]

69. 選擇一個默認的RP:
dallasr1># ip pim rp-address
通告RP和它所服務的組範圍:
dallasr1># ip pim send-rp-announce type number scope ttl group-list access-list-number
為管理範圍組通告RP的地址:
dallasr1># ip pim send-rp-announce ethernet0 scope 16 group-list1
dallasr1># access-list 1 permit 266.0.0.0 0.255.255.255
設定一個RP映像代理:
dallasr1># ip pim send-rp-discovery scope ttl
核實組到RP的映像:
dallasr1># show ip pim rp mapping
dallasr1># show ip pim rp [group-name|group-address] [mapping]

70. 在路由器接口上用命令ip multicast ttl-threshold ttl-value設定TTL閥值:
dallasr1>(config-if)# ip multicast ttl-threshold ttl-value

71. 用show ip pim neighbor顯示PIM鄰居表。

72. 顯示組播通信路由表中的各條記錄:
dallasr1>show ip mroute [group-name|group-address][scoure][summary][count][active kbps]

73. 要記錄一個路由器接受和發送的全部IP組播包:
dallasr1> #debug ip mpacket [detail] [access-list][group]

74. 要在CISCO路由器上配置CGMP:
dallasr1>(config-if)# ip cgmp

75.配置一個組播路由器,使之加入某一個特定的組播組:
dallasr1>(config-if)# ip igmp join-group group-address

76. 關閉 CGMP:
dallasr1>(config-if)# no ip cgmp

77. 啟動交換機上的CGMP:
dallasr1>(enable) set cgmp enable

78. 核實Catalyst交換機上CGMP的配置情況:
catalystla1>(enable) show config
set prompt catalystla1>
set interface sc0 192.168.1.1 255.255.255.0
set cgmp enable

79. CGMP離開的設置:
Dallas_SW(enable) set cgmp leave

80. 在Cisco設備上修改控制端口密碼:
R1(config)# line console 0
R1(config-line)# login
R1(config-line)# password Lisbon
R1(config)# enable password Lilbao
R1(config)# login local
R1(config)# username student password cisco

81. 在Cisco設備上設置控制台及vty端口的會話超時:
R1(config)# line console 0
R1(config-line)# exec-timeout 5 10
R1(config)# line vty 0 4
R1(config-line)# exec-timeout 5 2

82. 在Cisco設備上設定特權級:
R1(config)# privilege configure level 3 username
R1(config)# privilege configure level 3 copy run start
R1(config)# privilege configure level 3 ping
R1(config)# privilege configure level 3 show run
R1(config)# enable secret level 3 cisco

83. 使用命令privilege 可定義在該特權級下使用的命令:
router(config)# privilege mode level level command

84. 設定用戶特權級:
router(config)# enable secret level 3 dallas
router(config)# enable secret san-fran
router(config)# username student password cisco

85. 標誌設置與顯示:
R1(config)# banner motd 『unauthorized access will be prosecuted!』

86. 設置vty訪問:
R1(config)# access-list 1 permit 192.168.2.5
R1(config)# line vty 0 4
R1(config)# access-class 1 in

87. 配置HTTP訪問:
Router3(config)# access-list 1 permit 192.168.10.7
Router3(config)# ip http sever
Router3(config)# ip http access-class 1
Router3(config)# ip http authentication local
Router3(config)# username student password cisco

88. 要啟用HTTP訪問,請鍵入以下命令:
switch(config)# ip http sever

89. 在基於set命令的交換機上用setCL1啟動和核實端口安全:
switch(enable) set port security mod_num/port_num…enable mac address
switch(enable) show port mod_num/port_num
在基於CiscoIOS命令的交換機上啟動和核實端口安全:
switch(config-if)# port secure [mac-mac-count maximum-MAC-count]
switch# show mac-address-table security [type module/port]

90. 用命令access-list在標準通信量過濾表中創建一條記錄:
Router(config)# access-list access-list-number {permit|deny} source-address [source-address]

91. 用命令access-list在擴展通信量過濾表中創建一條記錄:
Router(config)# access-list access-list-number {permit|deny{protocol|protocol-keyword}}{source source-wildcard|any}{destination destination-wildcard|any}[protocol-specific options][log]

92. 對於帶內路由更新,配置路由更新的最基本的命令格式是:
R1(config-router)#distribute-list access-list-number|name in [type number]

93. 對於帶外路由更新,配置路由更新的最基本的命令格式是:
R1(config-router)#distribute-list access-list-number|name out [interface-name] routing-process| autonomous-system-number

94. set snmp命令選項:
set snmp community {read-only|ready-write|read-write-all}[community_string]

95. set snmp trap 命令格式如下:
set snmp trap {enable|disable}
[all|moudle|classis|bridge|repeater| auth|vtp|ippermit|vmps|config|entity|stpx]
set snmp trap rvcr_addr rcvr_community

96. 啟用SNMP chassis 陷阱:
Console>(enable) set snmp trap enable chassis

97. 啟用所有SNMP chassis 陷阱:
Console>(enable) set snmp trap enable

98. 禁用SNMP chassis 陷阱:
Console>(enable) set snmp trap disable chassis

99. 給SNMP陷阱接收表加一條記錄:
Console>(enable) set snmp trap 192.122.173.42 public

100. show snmp 輸出結果。

101. 命令set snmp rmon enable 的輸出結果。

102. 顯示SPAN信息:

Consile> show span



轉載來源

PIX Firewall 的簡易基本設定

Cisco PIX Firewall 是一套業界整體效能表現最佳與硬體架構的防火牆,無論是安裝與設定均相當簡易, 得使用圖形介面或指令模式操作與設定,而且PIX Firewall 通過ICSA 防火牆安全專業認證,完全保障 企業網路安全。

現在就指令模式設定PIX Firewall 步驟介紹如下:

1. 定義PIX Firewall 網路卡的名稱 :
PIX Firewall 兩片網路卡的初始設定值
nameif ethernet0 outside security0
nameif ethernet1 inside security100
當PIX Firewall 有三片網路卡以上時,使用者必須以指令設定。
nameif ethernet2 dmz1 security40
nameif ethernet3 dmz2 security60
其中nameif 語法為:nameif hardware_id interface security_level
- hardware_id 代表PIX Firewall 網路卡的種類 (乙太網路卡或環狀網路卡)
- interface 代表PIX Firewall 網路卡名稱
- security_level 代表安全權限等級;等級可以自Level 0(outside)到Level 100(inside)
其中level 0(outside)及level 100(inside)是唯一的且不能重覆,
第三片網卡以上可以自level 1 到level 99 選擇適合的安全權限等級。

除此之外,我們還必須瞭解安全權限等級背後的代表意義:
●TCP/IP 服務自較高安全等級的網路卡至較低安全等級的網路卡;所有服務基本上均允許通過;除非設定拒絕TCP/IP 服務通過的條件,
舉例:Level 100 (inside)網段至Level 0 (outside)網段,所有TCP/IP 服務均允許通過。
●TCP/IP 服務自較低安全等級的網路卡至較高安全等級的網路卡;所有服務基本上均拒絕通過;除非設定允許TCP/IP 服務通過的條件,
舉例:Level 0 (outside)網段至Level 100 (inside)網段,所有TCP/IP 服務均拒絕通過。

2. 設定PIX Firewall 各個網路卡的IP 位址:
ip address inside 192.168.3.1 255.255.255.0
ip address outside 204.31.17.1 255.255.255.0
ip address dmz1 192.168.1.1 255.255.255.0
ip address dmz2 192.168.2.1 255.255.255.0
其中IP address 語法為:
ip address interface ip_address netmask
- ip_address 代表網路上唯一的網路IP 位址
- netmask 代表子網路遮罩

3. PIX Firewall 企業網路安全建置案例 :
PIX Firewall:
outside (level 0) ip address 204.31.17.1 netmask 255.255.255.0
dmz1 (level 40) ip address 192.168.1.1. netmask 255.255.255.0
dmz2 (level 60) ip address 192.168.2.1. netmask 255.255.255.0
inside (level 100) ip address 192.168.3.1. netmask 255.255.255.0
以上四片網路IP 位址,只有outside 網路卡使用合法IP 位址,其餘網路卡均使用非法IP 位址。

4. 建立PIX Firewall 各個網卡(網段)對外的透通聯結 :
●NAT(Network Address Translation) : IP 位址的對應轉換設定
nat (inside) 1 0 0
nat (dmz1) 1 0 0
nat (dmz2) 1 0 0
表示inside 網段的非法IP 位址均作IP 位址轉換
其中nat 語法為:nat (interface) NAT_ID ip_address netmask
- nat 表示Network Address Translation
- NAT-ID 表示nat 群組編號,此編號必須與global 指令中之群組編號配合使用
-當nat 指令中之群組編號為0 時,代表此interface 所有網段不須作NAT 位址轉換。
●相應NAT 之Global 設定
Global 網段的設定在相應NAT 網段做IP 位址轉換後的對應IP 位址。
global (outside) 1 204.31.17.9 netmask 255.255.255.0
global (outside) 1 204.31.17.10~204.31.17.20 netmask 255.255.255.0
global (dmz1) 1 192.168.1.10~192.168.1.100 netmask 255.255.255.0
global (dmz2) 1 192.168.2.10~192.168.2.100 netmask 255.255.255.0
以上指令說明如下:
- 第一條指令表示採用PAT(Port Address Translation)方式,總共inside 網段最大允許有6500 個主機以相
同IP 位址不同Port 的方式對外產生聯結。
- 第二條指令採用IP Pool 方式,允許inside 網段之主機允許自204.31.17.20 至204.31.17.10 依序取得IP
位址,總共inside 網段只有11 個主機可對外聯結。

5. 建立PIX Firewall 網路路由繞徑:
route outside 0 0 204.31.17.2 1
其中route 語法為:
route interface source_ip_address source.netmask desk_ip_address dest_netmask metric
設定方式與一般Router 相同。

6. 開放TCP/IP 中之ping 服務 :
Conduit permit icmp any any
此conduit 指令將在第9 步驟中介紹。

7. 將前幾個步驟設定儲存在Flash 記憶體並重新開機 :
write memory
reload
設定方式與一般Router 相同。

8. 初步檢驗PIX Firewall 的設定 :
利用PIX Firewall Console port 直接聯結後,再以以下之指令測試之:
show ip address
show global
show nat
show route
ping inside 192.168.3.2
ping dmz2 192.168.2.2
ping dmz1 192.168.1.2
ping outside 204.31.17.2

9. 建立可供internet 主機存取企業內之開放之伺服器 :
static (dmz1, outside) 204.31.17.5 192.168.1.5 netmask 255.255.255.255
conduit permit tcp host 204.31.17.5 eq www any
其中
static 語法為:static (high, low) low high
conduit 語法為:conduit permit/deny protocol
global_ip global_netmask [operator port [port]]
foreign_ip foreign_netmask [operator, port [port]]
舉例:
static (inside, outside) 204.31.17.0 192.168.10 netmask 255.255.255.0
conduit permit tcp 204.31.17.0 255.255.255.0 eq h323 any
conduit permit tcp 204.31.17.0 255.255.255.0 eq 113 192.150.50.0 255.255.255.0
以上指令說明如下:
- 第一條指令代表internet 中任一主機可以透過tcp/h323 服務存取204.31.17.0 之網段。
- 第二條指令代表在Internet 中之192.150.50.0 網段上主機可透過tcp/113 服務存取204.31.17.0 網段。

10. 啟動PIX Firewall 日誌記錄 :
logging host outside 204.31.17.5
目的在記錄PIX Firewall 進出服務的所有活動記錄,做為未來安全稽核的參考。

11. 進一步設定 - 限制企業內部存取internet 服務 :
outbound 10 deny 0 0 www tcp
outbound 10 permit 192.168.1.2 255.255.255.255 www tcp
apply (dmz1) 10 outgoing_src
以上三條指令代表只允許企業內部為192.168.1.2 IP 位址之主機可透過tcp/80 服務存取internet Web 伺服
器
outbound 20 deny 204.31.17.42 255.255.255.255 www tcp
apply (dmz1) 20 outgoing_dest
以上二條指令代表限制dmz1 網段之任一主機無法以tcp/80 服務存取IP 為20.31.17.42 位址之主機。

12. 進一步設定 - 建立網路使用者認證機制 :
tacacs-server (inside) host 192.168.3.3 key cisco
aaa authentication any inbound 0 0 0 0 tacacs+
aaa authentication any outbound 0 0 0 0 tacacs+
以上三條指令定義使用者認證伺服器IP 位址,並對進出PIX Firewall 之FTP, TELNET 與HTTP 三種TCP/IP 服務進行人員認證作業。

13. 利用以下指令做偵錯動作 :
logging console debugging
debug icmp trace
此指令的目的在方便PIX Firewall 做設定時, 能及時利用此偵測工具, 做出快速及正確的設定。

cisco指令檔案說明

Au04Cisco 路由器常用命令
1 Exec commands:
<1-99> 恢復一個會話
bfe 手工應急模式設置
clear 復位功能
clock 管理系統時鐘
configure 進入設置模式
connect 打開一個終端
copy 從tftp伺服器拷貝設置文件或把設置文件拷貝到tftp伺服器上
debug 調試功能disable 退出優先命令狀態
disconnect 斷開一個網路連接
enable 進入優先命令狀態
erase 擦除快閃內存
exit 退出
exce模式
help 交互幫助系統的描述
lat 打開一個本地傳輸連接
lock 鎖定終端
login 以一個用戶名登錄
logout 退出終端
mbranch 向樹形下端分支跟蹤多路由廣播
mrbranch 向樹形上端分支跟蹤反向多路由廣播
name-connection 給一個存在的網路連接命名
no 關閉調試功能
pad 打開X.29 PAD連接
ping 發送回顯資訊
ppp 開始點到點的連接協議
reload 停機並執行冷啟動
resume 恢復一個活動的網路連接
rlogin 打開遠程註冊連接
rsh 執行一個遠端命令
send 發送資訊到另外的終端行
setup 運行setup命令
show 顯示正在運行系統資訊
slip 開始SLIP協議
start-chat 在命令行上執行對話描述
systat 顯示終端行的資訊
telnet 遠程登錄
terminal 終端行參數
test 測試子系統內存和端口
tn3270 打開一個tin3270連接
trace 跟蹤路由到目的地
undebug 退出調試功能
verify 驗證檢查閃爍文件的總數
where 顯示活動的連接
which-route 執行OSI路由表查找並顯示結果
write 把正在運行的設置寫入內存、網路、或終端
x3 在PAD上設置X.3參數
xremote 進入xremote模式

2 #show ?
access-expression 顯示訪問控制表達式
access-lists 顯示訪問控制表
apollo Apollo 網路資訊appletalk Apple Talk 資訊
arap 顯示Appletalk 遠端通道統計arp 地址解析協議表
async 訪問路由接口的終端行上的資訊
bridge 前向網路數據庫
buffers 緩衝池統計
clns CLNS網路資訊
clock 顯示系統時鐘
cmns 連接模式網路服務資訊
compress 顯示壓縮狀態
configuration 非易失性內存的內容
controllers 端口控制狀態
debugging 調試選項狀態
decnet DEC網路資訊
dialer 撥號參數和統計
dnsix 顯示Dnsix/DMPP資訊
entry 排隊終端入口
extended 擴展端口資訊
flash 系統閃爍資訊
flh-log 閃爍裝載幫助日誌緩衝區
frame-relay 幀中繼資訊
history 顯示對話層歷史命令
hosts IP域名,查找方式,名字服務,主機表
interfaces 端口狀態和設置
ip IP資訊
ipx Novell IPX資訊
isis IS-IS路由資訊
keymap 終端鍵盤映射
lat DEC LAT資訊
line 終端行資訊
llc2 IBM LLC2 環路資訊
lnm IBM 局網管理
local-ack 本地認知虛環路
memory 內存統計
netbios-cache NetBios命名緩衝存貯器內存
node 顯示已知LAT節點
ntp 網路時間協議
processes 活動進程統計
protocols 活動網路路由協議
queue 顯示隊列內容
queueing 顯示隊列設置
registry 功能註冊資訊
rhosts 遠程主機文件
rif RIF存貯器入口
route-map 路由器資訊
sdlle 顯示sdlc-llc2轉換資訊
services 已知LAT服務
sessions 遠程連接資訊
smds SMDS資訊
source-bridge 源網橋參數和統計
spanning-tree 跨越樹形拓樸
stacks 進程堆棧應用
standby 熱支持協議資訊
stun STUN狀態和設置
subsystem 顯示子系統
tcp TCP連接狀態
terminal 顯示終端設置
tn3270 TN3270 設置
translate 協議轉換資訊
ttycap 終端容易表
users 顯示終端行的資訊
version 系統硬、軟體狀態
vines VINES資訊
whoami 當前終端行資訊
x25 X.25資訊
xns XNS資訊
xermote Xremote統計

3 #config ?
Memory 從非易失性內存設置
Network 從TFTP網路主機設置
Overwrite-network 從TFTP網路主機設置覆蓋非易失性內存
Terminal 從終端設置

4 Configure commads:
Access-list 增加一個訪問控制域
Apollo Apollo全局設置命令
appletalk Appletalk 全局設置命令
arap Appletalk遠程進出協議
arp 設置一個靜態ARP入口
async-bootp 修改系統啟動參數
autonomous-system 本地所擁有的特殊自治系統成員
banner 定義註冊顯示資訊
boot 修改系統啟動時參數
bridge 透明網橋
buffers 調整系統緩衝池參數
busy-message 定義當連接主機失敗時顯示資訊
chat-s cript 定義一個調制解調器對話文本
clns 全局CLNS設置子命令
clock 設置時間時鐘
config-register 定義設置寄存器
decnet 全局DEC網路設置子命令
default-value 缺省字符位值
dialer-list 創建一個撥號清單入口
dnsix-nat 為審計提供DMDM服務
enable 修改優先命令口令
end 從設置模式退出
exit 從設置模式退出
frame-relay 全局幀中繼設置命令
help 交互幫助系統的描述
hostname 設置系統網路名
iterface 選擇設置的端口
ip 全局地址設置子命令
ipx Novell/IPX全局設置命令
keymap 定義一個新的鍵盤映射
lat DEC本地傳輸協議
line 設置終端行
lnm IBM局網管理
locaddr-priority-list 在LU地址上建立優先隊列
logging 修改註冊(設備)資訊
login-string 定義主機指定的註冊字符串
map-class 設置靜態表類
map-list 設置靜態表清單
menu 定義用戶接口菜單
mop 設置DEC MOP伺服器
netbios NETBIOS通道控制過濾
no 否定一個命令或改為缺省設置
ntp 設置NTPpriority-list 建立特權列表
prompt 設置系統提示符
queue-list 建立常規隊列列表
rcmd 遠程命令設置命令
rcp-enable 打開Rep服務
rif 源路由進程
router-map 建立路由表或進入路由表命令模式
router 打開一個路由進程
rsh-enable 打開一個RSH服務
sap-priority-list 在SAP或MAC地址上建立一個優先隊列
service 修改網路基本服務
snmp-server 修改SNMP參數
state-machine 定義一個TCP分配狀態的機器
stun STUN全局設置命令
tacacs-server 修改TACACS隊列參數
terminal-queue 終端隊列命令
tftp-server 為網路裝載請求提供TFTP服務
tn3270 tn3270設置命令
translate 解釋全局設置命令
username 建立一個用戶名及其權限
vines VINES全局設置命令
x25 X.25 的第三級x29 X.29 命令
xns XNS 全局設置命令
xremote 設置Xremote


5 (config)#ip
Global IP configuration subcommands:
Accounting-list 選擇保存IP記帳資訊的主機
Accounting-threshold 設置記帳入口的最大數
accounting-transits 設置通過入口的最大數
alias TCP端口的IP地址取別名
as-path BGP自治系統路徑過濾
cache-invalidate-delay 延遲IP路由存貯池的無效
classless 跟隨無類前向路由規則
default-network 標誌網路作為缺省網關候選
default-gateway 指定缺省網(如果沒有路由IP)
domain-list 完成無資格主機的域名
domain-lookup 打開IP域名服務系統主機轉換
domain-name 定義缺省域名
forward-protocol 控制前向的、物理的、直接的IP廣播
host 為IP主機表增加一個入口
host-routing 打開基於主機的路由(代理ARP和再定向)
hp-host 打開HP代理探測服務
mobile-host 移動主機數據庫
multicast-routing 打開前向
IPname-server 指定所用名字伺服器的地址
ospf-name-lookup 把OSPF路由作為DNS名顯示
pim PIM 全局命令
route 建立靜態路由
routing 打開IP路由
security 指定系統安全資訊
source-route 根據源路由頭的選擇處理包
subnet-zero 允許子網0子網
tcp 全局TCP參數

pix防火墻透明模式配置工作在透明模式

pix防火墻透明模式配置工作在透明模式下時,pix相當于一條網綫,故障切换由其它的三層設
所以不用設置彆的網絡地址,只要加一個ip用于以後配置就可以了.
一、升級系統
由于一般的PIX系列的防火墻出場時候預裝的IOS是6.X的版本,而只有7.0以上才支持透明模式.
所以第一步是升級IOS
准備工作:
找一台和防火墻在一個交换機機上的計算機安裝ciscotftp軟件.
去www.skycn.com上面就有.很簡單漢化版.
然後去cisco網站上下載一個7.0的bin文件(我下載的是pix701.bin)放到tftp服務器的根目録下
正式開始:
防火墻通電,按ESC進入monitor> 狀態下。
monitor> address 192.1.1.1 --設置防火墻IP
address 192.1.1.1
monitor> server 192.1.1.2 --設置tftp服務器的IP
server 192.1.1.2
monitor> ping 192.1.1.2 --檢測一下是否能ping通
Sending 5, 100-byte 0x7970 ICMP Echoes to 10.32.2.78, timeout is 4 seconds:
!!!!!
Success rate is 100 percent (5/5)
monitor> file pix701.bin --聲明你下載的那個bin文件的全稱
file pix704.bin
monitor> tftp --開始灌入
tftp pix704.bin@192.168.1.80...........................
耐心等待.一直到出現非特權模式的那個">"符號.下面要吧bin文件考到flash裏面去,以後啓動的時候才能正常使用
pixfirewall> en
Password:
pixfirewall# con t
pixfirewall(config)# interface ethernet1 --進入端口模式
pixfirewall(config-if)# ip address 192.1.11 255.255.255.0 --配置e1口的IP
pixfirewall(config-if)# nameif inside --配置e1口為防火墻的inside口
INFO: Security level for "inside" set to 100 by default.
pixfirewall(config-if)# no shutdown --激活inside口
pixfirewall(config-if)# ping 192.1.1.2 --測試一下
Sending 5, 100-byte ICMP Echos to 192.1.1.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
pixfirewall(config-if)# exit --退出端口模式
pixfirewall(config)# copy tftp flash: --copybin文件
Address or name of remote host []? 192.1.1.2 --tftp服務器IP
Source filename []? pix701.bin --文件名
Destination filename [pix701.bin]? pix701.bin --確認
Accessing tftp://192.1.1.2/pix701.bin...!! --開始copy 耐心等待
Writing file flash:pix701.bin...!!!!!!!!!!!!!
5124096 bytes copied in 82.80 secs (62488 bytes/sec)
pixfirewall(config)# reload --升級完成.重啓!!!!!!!ps.第一次啓動時間會稍長不要着急
二、PIX防問控制一般用ACL就能實現
1、用access-list寫建立一個列表.
2、access-group (access-list name) interface (interface name ) in/out應用上去就可以了
三、例子
pixfirewall> en
Password:
pixfirewall# con t
pixfirewall(config)# interface ethernet0
pixfirewall(config-if)# nameif outside
INFO: Security level for "outside" set to 0 by default.
pixfirewall(config-if)# no shutdown
pixfirewall(config-if)# exit
pixfirewall(config)# interface ethernet1
pixfirewall(config-if)# nameif inside
INFO: Security level for "inside" set to 100 by default.
pixfirewall(config-if)# no shutdown
pixfirewall(config-if)# exit
配置透明模式
pixfirewall(config)# firewall transparent --設置防火墻為透明模式
pixfirewall(config)# access-list out-list extended permit icmp any any --設置允許通過所有的協議
pixfirewall(config)# access-list out-list extended permit ip any any --設置允許通過所有的IP
pixfirewall(config)# access-group out-list in interface outside --把剛才的訪問列表綁在outside口
pixfirewall(config)# access-group out-list out interface outside --把剛才的訪問列表綁在outside口
pixfirewall(config)# ip address 192.168.11.1 255.255.255.0 --設置一個以後配置防火墻的IP
access-list goout permit tcp any any eq 7411 --允許打開的端口7411
access-list goout permit tcp any any eq 7412 --允許打開的端口7412
.....
在後面加一句
access-list goout deny tcp any any --關閉除7411和7412外的所有端口
access-group goout in interface outside --把acl規則應用到outside的入口端上
access-group goout out interface outside --把acl規則應用到outside的出口端上
開啓telnet
telnet 192.168.11.0 255.255.255.0 inside
添加用户
username cisco password cisco123456
四、acl中in和out的區彆
in和out是相對的,比如:
A(s0)-----(s0)B(s1)--------(s1)C
假設你現在想拒絶A訪問C,并且假設要求你是在B上面做ACL(當然C上也可以),我們把這個拓撲换成一個例子:
B的s0口是前門,s1口是後門,整個B是你家客廳,前門外連的是A,客廳後門連接的是你家金庫(C)
現在要拒絶小偷從A進來,那麽你在你家客廳做個設置,就有2種辦法:
1.在你家客廳(B)前門(B的s0)安個鐵門(ACL),不讓小偷進來(in),這様可以達到目的
2.在你家客廳後門安個鐵門(B的s1),小偷雖然進到你家客廳,但是仍然不能從後門出去(out)到達你家金庫(C)
雖然這2種辦法(in/out)都可以達到功效,但是從性能角度上來説還是有區彆的,
實際上最好的辦法,就是選辦法1,就像雖然小偷没進到金庫,至少進到你家客廳(B),
把你客廳的地毯給搞贜了(B要消耗些額外的不必要的處理)
假設你要把鐵門(ACL)安在C,那時候應該用in還是out呢?
這個問題留給你自己回答了,呵呵
相對于路由器的,穿過路由器的是out 即將進入的是in
擴展acl,要靠近源,標准acl靠近目標地址
實際上in和out的應用是很靈活的

fixup命令作用

fixup命令作用是啟用,禁止,改變一個服務或協定通過pix防火牆,由fixup命令指定的埠是pix防火牆要偵聽的服務。見下面例子:
  例1. Pix525(config)#fixup protocol ftp 21   啟用ftp協議,並指定ftp的埠號為21   例2. Pix525(config)#fixup protocol http 80   Pix525(config)#fixup protocol http 1080   為http協議指定80和1080兩個埠。   例3. Pix525(config)#no fixup protocol smtp 80   禁用smtp協議。PIX能夠進行Application Layer Inspection, 就像FTP, 它能檢查到在FTP connection中傳送的指令是否符合標準, 會否有惡意或有危險性的命令, 從而保護你的FTP server免受攻擊, fixup指令就是命令pix要處理哪些協定的指令, 若no fixup protocol ftp執行了, 則PIX不再監控所有FTP協定。

asdm的安裝和配置

ASDM是思科提供的自適應安全設備管理器 
一、ASDM的按裝
1、登録到PIX并且進入啓用模式:“pix> enable”
  
2、進入啓用模式之後,輸入命令“copy tftp flash”,你現在可以看到彈出如下信息:
  
3、“Address or name of remote host [x.x.x.x]? ”。你需要在這裏輸入托管ASDM圖像的TFTP服務器的IP地址。
4、“Source file name [cdisk]? ”。輸入ASDM圖像的文件名,例如:asdm502.bin for ASDM version 5.0(2)。
  
5、“Destination file name [asdm502.bin]?”。這裏實際上没有任何事情可做,除非你要重新命名你正在傳輸的圖像。
所以,這裏按回車鍵。
  
6、我們需要告訴PIX軟件ASDM在什麽地方。因此,我們要要以配置模式發出下列命令。
如果你喜歡這種長的方式,你可以在CLI輸入“conf t”或者“configure terminal”。
一旦進入設置模式“pix(config)#”,然後輸入“asdm image flash:asdm502.bin”,
然後按回車鍵。可以用show flash查看asdm文件名
  
7、由于我們已經讓我們的PIX知道了ASDM在什麽地方,現在可以向PIX發出“write mem”或者“write memory”指令。
你將得到一個信息,説正在構建配置,然後將返回到“pix(config)#”。這個時候,我們就安裝完了ASDM。
二、ASDM的配置
  為了訪問ASDM,我們需要做幾件事情。否則,這個PIX軟件將拒絶通信并且切斷連接。
為了允許這個連接,我們需要以config(配置)模式發布如下指令:
  
  1、http server enable:這個指令要首先發布并且啓動http/https服務器。
  
  2、http 0 0 inside:這個指令能够啓動來自PIX内部設置的任何主機/網絡的通信。
如果你僅允許你的工作站通信,這個工作站的地址是192.168.89.44,
那麽,這個指令就是“http 192.168.89.44 255.255.255.255 inside”。
你還可以允許一個子網或者多個子網連接。如果你需要在任何時候撤銷任何入口,
簡單地使用這個指令就可以了“no http x.x.x.x z.z.z.z inside”。這裏的x代表IP地址,z代表子網。
  
3、如果没有添加用户可以用username命令添加一個用户:name cisco password cisco123456
  4、現在,你可以實驗一下,使用https://x.x.x.x/admin連接ASDM。在這裏,x代表在PIX接口内部的IP地址。
  
5、登陸成功後用可以用ie直接運行,或下載登陸界面上的Cisco ASDM Launcher桌面程序管理。
如果用ie管理,則要裝java虚擬機。
  請注意,也可以配置成從接口外部訪問ASDM。你需要確認,當你添加“http x.x.x.x z.z.z.z ”指令的時候,
你是在指定這個接口為外部接口,用一台安全的計算機可以訪問那個接口。然而,這種方法不推薦使用,
由于ASDM的强大功能,把ASDM放在可以公開訪問的網絡上是不明智的。