华为交换机vlan划分、telnet 管理地址配置

------1---
1台核心交换时s5700
2台汇聚交换机S3700
6台PC
-----2------
创建vlan 10 20 30
s3700下PC1,PC2,PC3
S3700下PC4,PC5,PC6
VLAN10 PC1,PC2
VLAN20 PC3,PC4
VLAN30 PC5,PC6
-------3-----
要求实现:
PC1,PC2互通;
 PC3,PC4互通;
  PC5,PC6互通;
------------4-----s5700配置----
<s5700-Core>undo terminal monitor   //关闭终端模拟
<s5700-Core>dis cur  //查看配置
#
sysname s5700-Core  //重命名
#
vlan batch 10 to 30   //批量创建vlan
#

#
dhcp enable     //启用dhcp
#

#
ip pool 10                  //配置地址池
 gateway-list 192.168.10.1
 network 192.168.10.0 mask 255.255.255.0
 lease day 5 hour 0 minute 0
#
aaa
 authentication-scheme default
 authorization-scheme default
 accounting-scheme default
 domain default
 domain default_admin
 local-user admin password simple admin
 local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif10   //进入vlan 10
 ip address 192.168.10.1 255.255.255.0  //设置网关 掩码
 dhcp select global
#
interface Vlanif20
 ip address 192.168.20.1 255.255.255.0
#
interface Vlanif30
 ip address 192.168.30.1 255.255.255.0
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1    //进入接口
 port link-type trunk                   //设置端口访问模式
 port trunk allow-pass vlan 10 20   //允许vlan 10 20 通过
#
interface GigabitEthernet0/0/2
 port link-type trunk
 port trunk allow-pass vlan 20 30
#

#
user-interface con 0
user-interface vty 0 4
#
return

----------s3700-h2------配置telnet------
1.使能服务器功能。
<s3700-h2>system-view              //进入用户视图模式
[s3700-h2]telnet server enable     //使能telnet
Info: The Telnet server has been enabled.
[s3700-h2]

2•配置VTY用户界面的认证方式为AAA:

选择AAA认证,需要配置AAA用户的认证信息、接入类型和用户级别。
[s3700-h2]aaa         //进入3a模式

[s3700-h2-aaa]local-user huawei password simple huawei123  //设置明文用户名、密码
Info: Add a new user.
[s3700-h2-aaa]local-user  huawei privilege level 15       //设置用户权限    
[s3700-h2-aaa]local-user huawei service-type telnet       //设置用户访问类型
[s3700-h2-aaa]q
[s3700-h2]
3.配置VTY用户界面的认证方式和用户级别。配置VTY用户界面的支持协议类型。
[s3700-h2]user-interface vty 0 4

[s3700-h2-ui-vty0-4]authentication-mode aaa    //配置认证方式为AAA
[s3700-h2-ui-vty0-4]protocol inbound telnet  //指定VTY用户界面所支持的协议为Telnet
[s3700-h2-ui-vty0-4]q
[s3700-h2]
4.管理地址配置
[s3700-h2]vlan 100           //创建vlan100
[s3700-h2]interface Vlanif 100            //进入vlan100逻辑接口
[s3700-h2-Vlanif100]ip address 10.10.100.3 24   //配置该虚接口下的ip\掩码
[s3700-h2-Vlanif100]q

[s3700-h2]interface GigabitEthernet 0/0/1
[s3700-h2-GigabitEthernet0/0/1]dis this
#
interface GigabitEthernet0/0/1
 port link-type trunk
 port trunk allow-pass vlan 20 30
[s3700-h2-GigabitEthernet0/0/1]port trunk allow-pass vlan 20 30 100
[s3700-h2-GigabitEthernet0/0/1]

-----------s5700----配置trunk--
<s5700-Core>system-view 
[s5700-Core]interface GigabitEthernet 0/0/2  //进入2接口
[s5700-Core-GigabitEthernet0/0/2]dis this    //查看接口配置
#
interface GigabitEthernet0/0/2
 port link-type trunk
 port trunk allow-pass vlan 20 30
#
[s5700-Core-GigabitEthernet0/0/2]port trunk allow-pass vlan 20 30 100  //允许vlan通过
[s5700-Core-GigabitEthernet0/0/2]q
[s5700-Core]ping 10.10.100.3                 //ping 通测试;
  PING 10.10.100.3: 56  data bytes, press CTRL_C to break
    Reply from 10.10.100.3: bytes=56 Sequence=1 ttl=255 time=100 ms
    Reply from 10.10.100.3: bytes=56 Sequence=2 ttl=255 time=10 ms
    Reply from 10.10.100.3: bytes=56 Sequence=3 ttl=255 time=50 ms
    Reply from 10.10.100.3: bytes=56 Sequence=4 ttl=255 time=50 ms
    Reply from 10.10.100.3: bytes=56 Sequence=5 ttl=255 time=30 ms

  --- 10.10.100.3 ping statistics ---
    5 packet(s) transmitted
    5 packet(s) received
    0.00% packet loss
    round-trip min/avg/max = 10/48/100 ms

<s5700-Core>telnet 10.10.100.3      //telnet 测试
Trying 10.10.100.3 ...
Press CTRL+K to abort
Connected to 10.10.100.3 ...
Login authentication


Username:

附件:三台交换机具体配置如下:


#
sysname s5700-Core
#
vlan batch 10 to 30 100
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
dhcp enable
#
diffserv domain default
#
drop-profile default
#
ip pool 10
 gateway-list 192.168.10.1 
 network 192.168.10.0 mask 255.255.255.0 
 lease day 5 hour 0 minute 0 
#
aaa 
 authentication-scheme default
 authorization-scheme default
 accounting-scheme default
 domain default 
 domain default_admin 
 local-user admin password simple admin
 local-user admin service-type http
 local-user huawei password cipher -J&7(SW'E2AI>,Z,88J\:Q!!
 local-user huawei privilege level 15
 local-user huawei service-type telnet
#
interface Vlanif1
#
interface Vlanif10
 ip address 192.168.10.1 255.255.255.0 
 dhcp select global
#
interface Vlanif20
 ip address 192.168.20.1 255.255.255.0 
#
interface Vlanif30
 ip address 192.168.30.1 255.255.255.0 
#
interface Vlanif100
 ip address 10.10.100.1 255.255.255.0 
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
 port link-type trunk
 port trunk allow-pass vlan 10 20 100
#
interface GigabitEthernet0/0/2
 port link-type trunk
 port trunk allow-pass vlan 20 30 100
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
 authentication-mode aaa
#
return 

#
sysname s3700-h1
#
vlan batch 10 20 100
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa 
 authentication-scheme default
 authorization-scheme default
 accounting-scheme default
 domain default 
 domain default_admin 
 local-user admin password simple admin
 local-user admin service-type http
 local-user huawei password simple huawei123
 local-user huawei privilege level 15
 local-user huawei service-type telnet
#
interface Vlanif1
#
interface Vlanif100
 ip address 10.10.100.2 255.255.255.0 
#
interface MEth0/0/1
#
interface Ethernet0/0/1
#
interface Ethernet0/0/2
 port link-type access
 port default vlan 10
#
interface Ethernet0/0/3
 port link-type access
 port default vlan 10
#
interface Ethernet0/0/4
 port link-type access
 port default vlan 20
#
interface Ethernet0/0/5
#
interface Ethernet0/0/6
#
interface Ethernet0/0/7
#
interface Ethernet0/0/8
#
interface Ethernet0/0/9
#
interface Ethernet0/0/10
#
interface Ethernet0/0/11
#
interface Ethernet0/0/12
#
interface Ethernet0/0/13
#
interface Ethernet0/0/14
#
interface Ethernet0/0/15
#
interface Ethernet0/0/16
#
interface Ethernet0/0/17
#
interface Ethernet0/0/18
#
interface Ethernet0/0/19
#
interface Ethernet0/0/20
#
interface Ethernet0/0/21
#
interface Ethernet0/0/22
#
interface GigabitEthernet0/0/1
 port link-type trunk
 port trunk allow-pass vlan 10 20 100
#
interface GigabitEthernet0/0/2
#
interface NULL0
#
ip route-static 0.0.0.0 0.0.0.0 10.10.100.1
#
user-interface con 0
user-interface vty 0 4
 authentication-mode aaa
#
return 

#
sysname s3700-h2
#
vlan batch 20 to 30 100
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa 
 authentication-scheme default
 authorization-scheme default
 accounting-scheme default
 domain default 
 domain default_admin 
 local-user admin password simple admin
 local-user admin service-type http
 local-user huawei password simple huawei123
 local-user huawei privilege level 15
 local-user huawei service-type telnet
#
interface Vlanif1
#
interface Vlanif100
 ip address 10.10.100.3 255.255.255.0 
#
interface MEth0/0/1
#
interface Ethernet0/0/1
#
interface Ethernet0/0/2
 port link-type access
 port default vlan 20
#
interface Ethernet0/0/3
 port link-type access
 port default vlan 30
#
interface Ethernet0/0/4
 port link-type access
 port default vlan 30
#
interface Ethernet0/0/5
#
interface Ethernet0/0/6
#
interface Ethernet0/0/7
#
interface Ethernet0/0/8
#
interface Ethernet0/0/9
#
interface Ethernet0/0/10
#
interface Ethernet0/0/11
#
interface Ethernet0/0/12
#
interface Ethernet0/0/13
#
interface Ethernet0/0/14
#
interface Ethernet0/0/15
#
interface Ethernet0/0/16
#
interface Ethernet0/0/17
#
interface Ethernet0/0/18
#
interface Ethernet0/0/19
#
interface Ethernet0/0/20
#
interface Ethernet0/0/21
#
interface Ethernet0/0/22
#
interface GigabitEthernet0/0/1
 port link-type trunk
 port trunk allow-pass vlan 20 30 100
#
interface GigabitEthernet0/0/2
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
 authentication-mode aaa
#
return 

  • 1
    点赞
  • 11
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值