当前位置:网站首页>Huawei switch configuration
Huawei switch configuration
2022-04-22 21:58:00 【qq_ thirty-three million eight hundred and eight thousand four 】
Huawei switch configuration
-
Reset console password
a. Press on startup 【Ctrl】+【B】 key , Get into BOOTROM Catalog
b. Input bootrom password
By default :V200R001 Previous version , The default password is “huawei”;V200R001 And later , The default password is “[email protected]”
c. Input 7, eliminate console password
d. Input 1, Enter the system in default mode
e. Enter a new password to enter the system

-
Change of name

-
see
display ip interface brief see ip
display interface brief View interface status -
Delete vlan Of vlanif ip Address

- establish vlan And delete vlan( First delete this vlan Of ip)
establish vlan40 and 50
[huawei3700]vlan batch 40 50
Info: This operation may take a few seconds. Please wait for a moment...done.
[huawei3700]

- Set the port to access Mode and specify vlan
[SwitchA] interface ethernet 0/0/1 // Access port 0/0/1
[SwitchA-Ethernet0/0/1] port link-type access // Set the port mode to access
[SwitchA-Ethernet0/0/1] port default vlan 2 // Add ports to vlan2 in
[SwitchA-Ethernet0/0/1] quit // sign out
-
Join multiple ports vlan
a. Establish port group
b. Add ports to the port group
c. Operate on the port group -
To configure trunk

-
Configure the mirror port
a. Configure the observation port
hold 24 This port is configured as an observation port
b. Enter the port to be the mirror port , Carry out orders
c. View the completed configuration

-
To configure snmp
a. snmp-agent sys-info contact Specific identification
Set the identification and contact method of the Administrator
b. snmp-agent sys-info location Specific location
Set the location information of the switch , This item is not initially set .
c. snmp-agent community read public
Set up a SNMP Community, Use this Community When connecting the switch , Only its... Can be read SNMP Information . You can put... In the instruction public Replace it with the string you want .
d. snmp-agent community write private
Set up a SNMP Community, Use this Community When connecting the switch , You can not only read its SNMP Information , You can also write values to SNMP Of MIB object , Realize the configuration of equipment . You can put... In the instruction private Replace it with the string you want .
e. snmp-agent sys-info version all
Set the switch support SNMP agreement , Yes v1,v2c,v3 this 3 A version , If you're not sure , It is better to set it to all, Will also support this 3 Agreements
f. Setting allows to send data to the network management workstation (NMS)192.168.1.1 send out Trap message , The group name used is tangseng
snmp-agent target-host trap address udp-domain 192.168.1.1 params securityname tangseng
g. Startup and shutdown snmp
snmp-agent
undo snmp-agent
h. see snmp Configuration of
[huawei3700]display current-configuration
i. see snmp Working condition of

- To configure telnet
a. Turn on telnet
b. To configure Telnet User interface for user login :
Include VTY The user level of the user interface 、 Verification mode 、 Call in and call out restrictions and other basic attributes
Use three a Verification mode

allow telnet Access

Set up aaa Verified user name and password

Set user root The type of telnet user

Set user level

-
Check which versions of... Are enabled on the switch snmp

-
To configure snmp v3
a. Create an accessible view
[huawei3700]snmp-agent mib-view included
b. Create group mygroup
c. Create a user name and join the group , And set authentication mode and encryption mode
d. Turn on v3 Of trap

-
To configure dhcp snooping
a. start-up dhcp function
b. In all vlan Upper opening snooping· function
c. On the trust port trust

- dhcp Relay configuration
a. Build a dhcp Server groups , Name the group casually , Such as andy
b. hold dhcp Server's ip Add the address to the group just established andy

c. start-up dhcp service
d. Enter to use dhcp Relay interface , Enable relay , This step is divided into two situations , Physical interfaces and vlan Virtual interface .
d-1. If it's a router
d-2. If it's a layer 3 switch
Get into vlanif, choice relay
Select the just created dhcp Server groups andy

-
see dhcp snooping surface

-
Restore factory settings
reset saved-configuration / Reset switch configuration -
To configure snmp v3
snmp-agent // Turn on snmp
snmp-agent sys-info version v3 // To configure snmp Version is V3
snmp-agent mib-view included myview iso // Add a new one mib View of object , myview Is the view name ,iso Is the of this view mib Tree node
snmp-agent group v3 testers privacy read-view myview write-view myview // Add a new group ,testers Group name ,privacy Means both authentication and encryption ( If it is authenticatio Just verify without encryption ),read-view myview Is to authorize this group to read views ,write-view myview Is to authorize this group to write views
snmp-agent usm-user v3 tester testers authentication-mode md5 tangseng123 privacy-mode des56 tangseng123 // Add a user (tester), And specify the group to which this user belongs (testers), And specify the user's authentication algorithm (MD5) And password (tangseng124), And specify the encryption algorithm of this user (des56) And password (tangseng123)

- Port security
18.1MAC The address list is divided into three
1、 static state MAC Address table , Manual binding , Priority over dynamic MAC Address table
2、 dynamic MAC Address table , After receiving the data frame, the switch will send the source message mac Learning to MAC In the address table
3、 Black holes MAC Address table , Manual binding or automatic learning , Used to discard the specified MAC Address
18.2 see mac Electronic watch
18.3 Configure static mac Address table
take mac Address 5C80-B698-B65B Bind to port Ethernet 0/0/10 stay vlan 20 Effective in

18.4 Configure black holes mac Address table
stay vlan30 Source or destination received in mac The address is 5C80-B698-B651 The frame is discarded

18.5 Configure port security
1) In the port 10 Enable port security on
2) Limit ports mac The number of addresses is 1
3) Configure other non secure devices mac Frame processing action
4) Configure security MAC Aging time of address 300s, No aging by default

5) Delete port security
[huawei-Ethernet0/0/16]undo port-security enable
6) delete a port sticky
huawei-Ethernet0/0/9]undo port-security mac-address sticky
版权声明
本文为[qq_ thirty-three million eight hundred and eight thousand four ]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204221554431461.html
边栏推荐
- PlatoFarm几大创新经济模型,给予当下元宇宙市场的启发
- 云原生虚拟化:基于 Kubevirt 构建边缘计算实例
- go每日新闻(2021-03-28)——Golang 语言中的非类型安全指针
- Online yaml to XML tool
- Markdown advanced usage
- 难以置信!网易首席架构师竟用了500页笔记,把网络协议给趣谈了
- 逆向入门(三) CE自动汇编后保存CT表并生成exe修改器
- Tan Xiang, CEO of Kechuang · Pera software: the essence of zero trust is digital security. To B should also deeply study the user's mind
- MySQL configuration parameters and commands
- Summary of problems encountered in ffmpeg audio decoding
猜你喜欢

图像预训练模型的起源解说和使用示例

Embedded design and development project - digital tube static display program design
![[advanced level of C language] an article takes you to recognize structure, enumeration and union](/img/13/f8cf77530427afd113bef02832f01a.png)
[advanced level of C language] an article takes you to recognize structure, enumeration and union
![[operation tutorial] how to turn on the voice intercom function on the national standard gb28181 platform easygbs?](/img/73/7f3e4f391c42cc1d69cce0afed18f5.png)
[operation tutorial] how to turn on the voice intercom function on the national standard gb28181 platform easygbs?

Interview: artificial intelligence job interview - Framework of necessary knowledge for machine learning algorithm engineers in artificial intelligence job hunting

PlatoFarm几大创新经济模型,给予当下元宇宙市场的启发

The national standard gb28181 video platform easygbs has closed the video recording plan. Why are there video files generated?

短视频内容理解与生成技术在美团的创新实践

逆向入门(三) CE自动汇编后保存CT表并生成exe修改器

Penetration test & Network & CTF interview questions sorting
随机推荐
Penetration test & Network & CTF interview questions sorting
每日一练(47):找不同
unbelievable! The chief architect of Netease used 500 pages of notes to talk about the network protocol
Brief introduction of Microsoft testers
使用charles抓app包
Ampere Computing释放观测云“芯”算力,强强联合推动可观测性发展
8.1 sequence model
Online yaml to XML tool
Use the model of pytorch to predict
Linux MySQL compilation and installation
5个程序员常用的接单平台推荐
如何在项目中引入SPI
摆脱 AI 生产“小作坊”:如何基于 Kubernetes 构建云原生 AI 平台
paho.mqtt.c使用的总结
[weekly] April 17
一个线程获取内存另一个线程释放内存造成内存泄漏
蚂蚁集团三项技术方案入选“2021年信息技术应用创新典型解决方案”
[csnote] paradigm
paho. mqtt. C. summary of use
MySQL configuration SQL_ mode