思科配置文件解释

hostname Switch   //主机名,此处用的默认的
!
boot-start-marker   //启动开始标记
boot-end-marker     //启动结束标记,这个不用配
!
!
!
!
no aaa new-model  //去掉AAA接入控制模式
system mtu routing 1500  //设置路由时的MTU大小
!
!
!
!
crypto pki trustpoint TP-self-signed-1869362816   
 enrollment selfsigned   //设置申请证书的方式
 subject-name cn=IOS-Self-Signed-Certificate-1869362816  //证书的名称分发者信息
 revocation-check none   //是否返回查询证书服务器
 rsakeypair TP-self-signed-1869362816   //在验证和申请证书之前需要的钥匙对
!         
! 
##这里没有什么好纠结的,是设备自己根证书。        
crypto pki certificate chain TP-self-signed-1869362816
 certificate self-signed 01
  3082023F 308201A8 A0030201 02020101 300D0609 2A864886 F70D0101 04050030 
  31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274 
  69666963 6174652D 31383639 33363238 3136301E 170D3933 30333031 30303031 
  30365A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649 
  4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 38363933 
  36323831 3630819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281 
  8100C3B3 6E1E063E 988E60A0 439A9D25 31467AD1 4462816C BB16E878 776BF1F0 
  D1A9CCC2 59E952B0 B6193F4F 7FD032BC 450D47C0 1318D71D D75046E3 380C72CF 
  B817DCE9 726E732B F5BEA0BF D68996F6 8A952402 E3840551 2AFB05B3 F0F85E87 
  0C4C01C4 A13CF98D B5D5EDBD 67EEAAF6 1C82523C DDAA3424 8F80DC56 758AD202 
  10290203 010001A3 67306530 0F060355 1D130101 FF040530 030101FF 30120603 
  551D1104 0B300982 07537769 7463682E 301F0603 551D2304 18301680 145225C6 
  C75CD3BD C0B5FD7D 1C81DFE5 2C71DA51 78301D06 03551D0E 04160414 5225C6C7 
  5CD3BDC0 B5FD7D1C 81DFE52C 71DA5178 300D0609 2A864886 F70D0101 04050003 
  81810008 F21A5E76 7290F5AA 76E84652 25A7EE99 CC9FE785 F2C4B5C2 A48A40A0 
  7E84FEA1 040FA9A7 0FA2B6F5 6A72B1F6 59FA2B26 CDA8C2FB 10BCFA82 6EE7E31E 
  341F535F 0C875980 521A5EC8 8196B6C0 0F369695 FEF934EF 5336E78E F8EECE28 
  A34E60C0 FA8A7603 79085C12 1F8BAF9E A2A0EACD 8CA4AC84 9A4864C9 2088FEC0 AED95C
  quit    
!         
!         
!         
spanning-tree mode pvst   //设置生成树模式为PVST格式
spanning-tree extend system-id   //扩展生成树的系统ID,为了能够在一个机框里支持1024个MAC地址
!         
vlan internal allocation policy ascending //cisco交换机指定内部vlan号分配是使用升序(ascending:从低到高)或者降序(descending:从高到低);内部vlan号是交换机内部用来标识用,对用户配置没有什么影响
!         
!         
!         
interface FastEthernet0/1
 switchport access vlan 210
 switchport mode access
!         
interface FastEthernet0/2
 switchport access vlan 210
 switchport mode access
!         
interface FastEthernet0/3
 switchport access vlan 210
 switchport mode access
!         
interface FastEthernet0/4
 switchport access vlan 210
 switchport mode access
!         
interface FastEthernet0/5
 switchport access vlan 200
 switchport mode access
!         
interface FastEthernet0/6
 switchport access vlan 200
 switchport mode access
!         
interface FastEthernet0/7
 switchport access vlan 200
 switchport mode access
!         
interface FastEthernet0/8
 switchport access vlan 200
 switchport mode access
!         
interface FastEthernet0/9
 switchport access vlan 200
 switchport mode access
!         
interface FastEthernet0/10
 switchport access vlan 200
 switchport mode access
!         
interface FastEthernet0/11
 switchport access vlan 200
 switchport mode access
!         
interface FastEthernet0/12
 switchport access vlan 200
 switchport mode access
!         
interface FastEthernet0/13
 switchport access vlan 220
 switchport mode access
!         
interface FastEthernet0/14
 switchport access vlan 220
 switchport mode access
!         
interface FastEthernet0/15
 switchport access vlan 220
!         
interface FastEthernet0/16
 switchport access vlan 220
!         
interface FastEthernet0/17
 switchport access vlan 200
 switchport mode access
!         
interface FastEthernet0/18
 switchport access vlan 200
 switchport mode access
!         
interface FastEthernet0/19
 switchport access vlan 200
 switchport mode access
!         
interface FastEthernet0/20
 switchport access vlan 200
 switchport mode access
!         
interface FastEthernet0/21
 switchport access vlan 200
 switchport mode access
!         
interface FastEthernet0/22
 switchport access vlan 200
 switchport mode access
!         
interface FastEthernet0/23
!         
interface FastEthernet0/24
!         
interface GigabitEthernet0/1
 switchport trunk encapsulation dot1q   //定义此接口的协议
 switchport mode trunk    //定义此接口模式为trunk口
!         
interface GigabitEthernet0/2
!         
interface Vlan1
 no ip address
!         
interface Vlan200
 no ip address   //没有分配 IP地址
!         
ip classless  //作用于路由转发进程的,告诉路由器工作在无类环境下
ip http server  //允许http登录
ip http secure-server
!         
!         
! 
##line vty 0 4,该命令是允许用户远程登陆,即不用用户插Console线缆,只要设备连接网络,配置了接口IP地址即可远程使用Telnet、或者ssh的方式登陆到设备上,,CISCO设备一般支持16个并行的远程虚拟终端,按照编号就是:0 - 15., Line vty 0 4 就是指同时允许5个虚拟终端登陆进行配置,需注意这里配置完成后一定要注意配置enable的密码,要不Telnet是上不去的。
line con 0
line vty 0 4
 login    
line vty 5 15
 login    
!         
end       

 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值