V7版本交换机SSH配置
1、生成RSA和DSA密钥对
[H3C]public-key local create rsa
[H3C]public-key local create dsa
说明:可以通过命令显示生成的RSA密钥对的公钥部分(dis public-key local rsa public)
2、开启ssh服务 并设置用户接口上的认证模式为AAA,并让用户接口支持SSH协议
[H3C]ssh server enable
[H3C]user-interface vty 0 63
[H3C-ui-vty0-15]authentication-mode scheme
[H3C-ui-vty0-15] protocol inbound ssh
注意:如果在该用户界面上配置支持的协议是SSH,为确保登录成功,请务必配置登录用户界面的认 证方式为authentication-mode scheme(采用AAA认证)。
3、创建用户
创建用户admin,设置认证密码admin,登录协议为SSH,能访问的命令级别为network-admin。
[H3C]local-user xmpjxxb
[H3C-luser-admin]password simple xushaokai
注意:如果忘记密码,可以通过console端口连接,然后通过该命令来修改密码
4、定义登录协议
[H3C-luser-admin]service-type ssh
5、创建用户级别
[H3C-luser-admin]authorization-attribute user-role network-admin
[H3C-luser-admin]quit
[H3C]save //保存退出
-------------------------------
1、两台核心交换机 两台防火墙 一台linux PC
配置:irf 堆叠 聚合端口 mad检测端口
vlan 4090 mad检测端口
vlan 101 PC端口 192.168.56.254
vlan 192 可管理交换机 192.168.0.0 24
配置命令:
--------------------------------------
配置堆叠
sw 1
sys
sysnam xsk
irf member 1 prio 10
inter rang t 1/0/50 t 1/0/51
shutdown
quit
irf-port 1/1
port group inter t 1/0/50
port group inter t 1/0/51
quit
inter rang t 1/0/50 t 1/0/51
undo shutdown
quit
sav f
irf-port-config active
-------------------------------------------
sw2:
irf member 1 renumber 2
y
sav f
quit
reboot
y
inter rang t 2/0/50 to t 2/0/51
shutdown
quit
irf-port 2/2
port group inter t 2/0/50
port group inter t 2/0/51
quit
sav f
inter rang t 2/0/50 to t 2/0/51
undo shutdown
quit
sav f
irf-port-config active
quit
-------------------------------------------
dis irf configurtion
dis irf link
dis inter br
-------------------------------------------
配置MAD流量检测
sw 1
vlan 4090
port t 1/0/49 t 2/0/49
quit
inter vlan- 4090
mad bfd enable
mad ip address 1.1.1.1 24 member 1
mad ip address 1.1.1.2 24 member 2
quit
inter rang t 1/0/49 t 2/0/49
undo stp enable
quit
--------------------------------------------
配置聚合口
sw1
inter b52
quit
inter range t 1/0/52 t 2/0/52
port link-typ trunk
port trunk permit vlan all
port link-agg group 52
quit
---------------------------------------
sw 3
inter b52
quit
inter rang t 1/0/52 to t 1/0/53
port link-typ trunk
port trunk permit vlan all
port link-agg group 52
quit
---------------------------------------