ccna 交换机路由器学习笔记
操作方法
- 01
vlan 的划分 en conf t vlan {vlan_id} name vlan-name intferface {intterface } switchport mode access switchport access vlan {vlan-id} sweitchport ruunk encapsulation {isl| dotlq|negotiate} 跨交换机trunk模 式 switchport mode {dynamic auto | dynamic desirable |trunk} trunk 常用 vtp 的启用和管理 conf t 模式下 vtp mode server | client |transparent vtp domain domain-name vtp password password 设置vtp密码时候 同一个域中密码必须一致8-64个字符 ------------------------------------------------ 访问控制列表 access-list 1 permit 172.20.0.0 0.0.255.255 interface ethemet 1 ip access-group 1 out | in access-list 1 deny 172.20.0.0 0.0.255.255 access-list 1 permit 0.0.0.0 255.255.255.255 访问控制列表控制vty 访问 access-list 12 permit ip 通配符掩码 conf t 下 line vty 4(号码) access-class 12 in ------------------------------------------------------ 扩展访问列表 基于原地址 目标地址 指定的协议检查 进入接口后 ip access-group access-list-number {in | out} access-list 101(大于100 小于199) deny tcp 172.16.4.0 0.0.0.255 (源ip)172.16.3.0 0.0.0.255 (目的ip)eq 21(端口) access-list 101 deny tcp 172.16.4.0 0.0.0.255 (源ip)172.16.3.0 0.0.0.255 (目的ip)eq 20(端口) access-list 101 permit any any interface eth 0 ip access-group 101 out 查看访问列表 sh ip int e1 e1端口的 show {protocol} access-lists {access-list-number} --------------------------------------- hdlc config-if encapsulation hdlc ppp 分为ncp 和lcp link 和network chap pap 两种验证 一般选chap ppp 配置命令 路由器1的配置 hostname rt1 username rt0 password sameone int async 0 encapsulation ppp ppp authentication CHAP 路由器0的配置 hostname rt0 username rt1 password sanmeone 注意 password 必须一致 否则建立不起链接 int async 0 异步口 encapsulation ppp ppp authentication CHAP ------------------------------------------------------------------------- fr网络 启用子接口 点到点的配置 interface serial 0/0 no ip address encasulation frame-relay ! interface serial 0.2 point-to-point ip address ip mask bandwidth 32 frame-relay interface-dlci 110 ! interface ser 0.3 point-to-point ip address ip mask bandwidth 32 frame-relay interface-dhci 120 ! 点到多点的配置 interface serial0/1 no ip address encapsulation frame-relay ! interface serial 0/1.1 ip address ip mask bandwidth 64 frame-relay map ip ip1 120 broadcast frame-relay map ip ip2 130 broadcast frame-relay map ip ip3 140 broadcast --------------------------------------------------------------------- NAT技术 interface eth 0 ip address 内网ip mask ip nat inside ! interface serial 0 ip address 外网ip mask ip nat outside 是定外部接口 ! ip nat inside source static 172.16.1.2 200.1.1.1 建立静态ip映射 ip classless ip route 0.0.0.0 0.0.0.0 200.1.1.2 动态nat技术 ip nat pool 名字 192.16.2.1 192.16.2.254 netmask 255.255.255.0 ip nat inside source list 1 pool 名字 ! interface eth0 ip address 10.1.1.1 255.255.255.0 ip nat inside ! interface ser 0 ip addresss 192.16.2.1 255.255.255.0 ip nat outsice ! access-list 1 permit 10.1.1.0 0.0.0.255 !