设为首页 收藏本站
查看: 839|回复: 0

[经验分享] Cisco Catalyst 4006交换机的配置实例

[复制链接]

尚未签到

发表于 2018-7-20 06:42:29 | 显示全部楼层 |阅读模式
  一、CAT4006引擎模块WS-X4013的配置清单
  (其中包括:基本设置、VLAN的配置、通道配置、以及端口镜像口的1/2设置连接千兆IDS)
  Cisco Systems, Inc. Console
  Enter password:
  CAT4006> enable
  Enter password:
  CAT40
  06> (enable)
  .......
  ..................
  ..................
  ....................
  ....................
  ..
  begin
  !
  # ***** NON-DEFAULT CONFIGURATION *****
  !
  !
  #time: Mon Apr 11 2005, 22:02:13
  !
  #version 6.1(1)
  !
  !
  #system web interface version(s)
  set password *********************
  set enablepass *********************
  !
  #test
  !
  #system
  set system name CAT4006
  !
  #frame distribution method
  set port channel all distribution mac both
  !
  #vtp
  set vtp domain hngazk
  set vlan 1 name default type ethernet mtu 1500 said 100001 state active
  set vlan 16 name Old_Bangong type ethernet mtu 1500 said 100016 state active
  set vlan 17 name Server_Manage type ethernet mtu 1500 said 100017 state active
  set vlan 18 name New_Bangong type ethernet mtu 1500 said 100018 state active
  set vlan 19 name Library type ethernet mtu 1500 said 100019 state active
  set vlan 20 name New_Shiyanzhongxin type ethernet mtu 1500 said 100020 state active
  set vlan 22 name Old_Shiyanzhongxin type ethernet mtu 1500 said 100022 state active
  set vlan 23 name CaiZhuan_Jiashuyuan type ethernet mtu 1500 said 100023 state active
  set vlan 1002 name fddi-default type fddi mtu 1500 said 101002 state active
  set vlan 1004 name fddinet-default type fddinet mtu 1500 said 101004 state active stp ieee
  set vlan 1005 name trnet-default type trbrf mtu 1500 said 101005 state active stp ibm
  set vlan 1003 name token-ring-default type trcrf mtu 1500 said 101003  state active mode srb aremaxhop 0 stemaxhop 0 backupcrf off
  !
  #ip
  set interface sc0 17 21x.xxx.17.253/255.255.255.0 21x.xxx.xxx.255
  set interface sl0 down
  set interface me1 down
  set ip route 0.0.0.0/0.0.0.0 21x.xxx.xxx.254
  !
  #dns
  set ip dns server 21x.xxx.xxx.2 primary
  set ip dns enable
  !
  #syslog
  set logging level cops 2 default
  !
  #set boot command
  set boot config-register 0x2
  set boot system flash bootflash:cat4000.6-1-1.bin
  !
  #mls
  set mls nde disable
  !
  #port channel
  set port channel 3/1-4 636
  !
  #module 1 : 2-port 1000BaseX Supervisor
  set udld enable 1/1
  set trunk 1/1 nonegotiate dot1q 1-1005
  set trunk 1/2 nonegotiate dot1q 1-1005
  !
  #module 2 : 6-port 1000BaseX Ethernet
  set vlan 20 2/3
  set port name 2/1 Old_Shiyanzhongxin
  set port name 2/2 Library
  set port name 2/3 New_Shiyanzhongxin
  set port name 2/4 New_Bangong
  set port name 2/5 CaiZhuan_Jiashuyuan
  set port name 2/6 Old_Shiyanzhongxin
  set udld enable 2/6
  set udld disable 2/3
  set trunk 2/1 nonegotiate dot1q 1-1005
  set trunk 2/2 nonegotiate dot1q 1-1005
  set trunk 2/3 nonegotiate dot1q 1-1005
  set trunk 2/4 nonegotiate dot1q 1-1005
  set trunk 2/5 nonegotiate dot1q 1-1005
  set trunk 2/6 nonegotiate dot1q 1-1005
  !
  #module 3 : 34-port Router Switch Card
  set vlan 16 3/3-9,3/11-19,3/26-34
  set vlan 17 3/10,3/20
  set vlan 18 3/21
  set vlan 19 3/22
  set vlan 20 3/23
  set vlan 22 3/24
  set vlan 23 3/25
  set port name 3/1 Firewall_Talent
  set trunk 3/1 nonegotiate dot1q 1-1005
  set trunk 3/2 nonegotiate dot1q 1-1005
  set port channel 3/1-2 mode on
  !
  #module 4 : 34-port 10/100/1000 Ethernet
  set vlan 16 4/5-9,4/11,4/15-34
  set vlan 17 4/3-4,4/10,4/12-14
  set trunk 4/1 nonegotiate dot1q 1-1005
  set trunk 4/2 nonegotiate dot1q 1-1005
  !
  #module 5 empty
  !
  #module 6 empty
  !
  #switch port analyzer
  set span 2/1-6,3/1-34,4/1-34 1/2 both inpkts disable learning enable create
  end
  CAT4006> (enable)
  二、WS-X4232-L3三层路由模块的配置清单
  (其中包括:VLAN路由、访问控制列表、三层模块与交换机背板通道的配置等等)
  WS-X4232-L3#
  Using 4055 out of 126968 bytes
  !
  version 12.0
  no service pad
  service timestamps debug uptime
  service timestamps log uptime
  no service password-encryption
  !
  hostname WS-X4232-L3
  !
  enable secret 5 *****************
  enable password **********
  !
  ip subnet-zero
  !
  !
  !
  interface Port-channel1
  no ip address
  no ip directed-broadcast
  hold-queue 300 in
  !
  interface Port-channel1.1
  encapsulation dot1Q 1 native
  ip address 10.10.1.254 255.255.255.0
  ip access-group 110 in
  ip access-group 110 out
  no ip redirects
  no ip directed-broadcast
  !
  interface Port-channel1.16
  encapsulation dot1Q 16
  ip address 21x.xxx.16.254 255.255.255.0
  ip access-group 110 in
  ip access-group 110 out
  no ip redirects
  no ip directed-broadcast
  !
  interface Port-channel1.17
  encapsulation dot1Q 17
  ip address 21x.xxx.17.254 255.255.255.0
  ip access-group 110 in
  ip access-group 110 out
  no ip redirects
  no ip directed-broadcast
  !
  interface Port-channel1.18
  encapsulation dot1Q 18
  ip address 21x.xxx.18.254 255.255.255.0
  ip access-group 110 in
  ip access-group 110 out
  no ip redirects
  no ip directed-broadcast
  !
  interface Port-channel1.19
  encapsulation dot1Q 19
  ip address 21x.xxx.19.254 255.255.255.0
  ip access-group 110 in
  ip access-group 110 out
  no ip redirects
  no ip directed-broadcast
  !
  interface Port-channel1.20
  encapsulation dot1Q 20
  ip address 21x.xxx.21.254 255.255.254.0 secondary
  ip address 21x.xxx.20.254 255.255.254.0
  ip access-group 110 in
  ip access-group 110 out
  no ip redirects
  no ip directed-broadcast
  !
  interface Port-channel1.22
  encapsulation dot1Q 22
  ip address 21x.xxx.22.254 255.255.255.0
  ip access-group 110 in
  ip access-group 110 out
  no ip redirects
  no ip directed-broadcast
  !
  interface Port-channel1.23
  encapsulation dot1Q 23
  ip address 21x.xxx.23.254 255.255.255.0
  ip access-group 110 in
  ip access-group 110 out
  no ip redirects
  no ip directed-broadcast
  !
  interface FastEthernet1
  no ip address
  no ip directed-broadcast
  shutdown
  !
  interface GigabitEthernet1
  ip address 21x.xxx.xxx.xxx 255.255.255.240
  ip access-group 110 in
  ip access-group 110 out
  no ip directed-broadcast
  !
  interface GigabitEthernet2
  no ip address
  no ip directed-broadcast
  !
  interface GigabitEthernet3
  no ip address
  no ip directed-broadcast
  no negotiation auto
  channel-group 1
  !
  interface GigabitEthernet4
  no ip address
  no ip directed-broadcast
  no negotiation auto
  channel-group 1
  !

  ip>  ip route 0.0.0.0 0.0.0.0 2xx.xxx.xxx.xxx
  !
  access-list 110 deny tcp any any eq echo
  access-list 110 deny tcp any any eq chargen
  access-list 110 deny tcp any any eq 135
  access-list 110 deny tcp any any eq 136
  access-list 110 deny tcp any any eq 137
  access-list 110 deny tcp any any eq 138
  access-list 110 deny tcp any any eq 139
  access-list 110 deny tcp any any eq 389
  access-list 110 deny tcp any any eq 445
  access-list 110 deny tcp any any eq 4444
  access-list 110 deny udp any any eq tftp
  access-list 110 deny udp any any eq 135
  access-list 110 deny udp any any eq 136
  access-list 110 deny udp any any eq netbios-ns
  access-list 110 deny udp any any eq netbios-dgm
  access-list 110 deny udp any any eq netbios-ss
  access-list 110 deny udp any any eq 389
  access-list 110 deny udp any any eq 445
  access-list 110 deny udp any any eq 1434
  access-list 110 deny udp any any eq 1433
  access-list 110 deny udp any any eq 1025
  access-list 110 deny udp any any eq 455
  access-list 110 deny udp any any eq 5554
  access-list 110 deny udp any any eq 9996
  access-list 110 deny udp any any eq 6129
  access-list 110 deny udp any any eq 3127
  access-list 110 deny udp any any eq 2745
  access-list 110 deny tcp any any eq 6669
  access-list 110 deny tcp any any eq 1023
  access-list 110 deny tcp any any eq 1024
  access-list 110 deny tcp any any eq 3332
  access-list 110 deny tcp any any eq 69
  access-list 110 deny udp any any eq 593
  access-list 110 deny tcp any any eq 593
  access-list 110 permit ip any any
  arp 127.0.0.2 0005.5e73.9300 ARPA
  !
  line con 0
  transport input none
  line aux 0
  line vty 0 4
  password **********
  login
  !
  end
  WS-X4332-L3#

运维网声明 1、欢迎大家加入本站运维交流群:群②:261659950 群⑤:202807635 群⑦870801961 群⑧679858003
2、本站所有主题由该帖子作者发表,该帖子作者与运维网享有帖子相关版权
3、所有作品的著作权均归原作者享有,请您和我们一样尊重他人的著作权等合法权益。如果您对作品感到满意,请购买正版
4、禁止制作、复制、发布和传播具有反动、淫秽、色情、暴力、凶杀等内容的信息,一经发现立即删除。若您因此触犯法律,一切后果自负,我们对此不承担任何责任
5、所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其内容的准确性、可靠性、正当性、安全性、合法性等负责,亦不承担任何法律责任
6、所有作品仅供您个人学习、研究或欣赏,不得用于商业或者其他用途,否则,一切后果均由您自己承担,我们对此不承担任何法律责任
7、如涉及侵犯版权等问题,请您及时通知我们,我们将立即采取措施予以解决
8、联系人Email:admin@iyunv.com 网址:www.yunweiku.com

所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其承担任何法律责任,如涉及侵犯版权等问题,请您及时通知我们,我们将立即处理,联系人Email:kefu@iyunv.com,QQ:1061981298 本贴地址:https://www.yunweiku.com/thread-538878-1-1.html 上篇帖子: CISCO交换机基础配置 下篇帖子: Cisco ACL 访问列表学习总结
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

扫码加入运维网微信交流群X

扫码加入运维网微信交流群

扫描二维码加入运维网微信交流群,最新一手资源尽在官方微信交流群!快快加入我们吧...

扫描微信二维码查看详情

客服E-mail:kefu@iyunv.com 客服QQ:1061981298


QQ群⑦:运维网交流群⑦ QQ群⑧:运维网交流群⑧ k8s群:运维网kubernetes交流群


提醒:禁止发布任何违反国家法律、法规的言论与图片等内容;本站内容均来自个人观点与网络等信息,非本站认同之观点.


本站大部分资源是网友从网上搜集分享而来,其版权均归原作者及其网站所有,我们尊重他人的合法权益,如有内容侵犯您的合法权益,请及时与我们联系进行核实删除!



合作伙伴: 青云cloud

快速回复 返回顶部 返回列表