这里使用的H3C交换机是H126A,仅仅只做了最基本的配置以满足使用。 配置中可以通过display current-configura命令来显示当前使用的配置内容。 # 配置VLAN 1 <Sysname>system-view System View: return to User View with Ctrl+Z. [Sysname]vlan 1 [Sysname-vlan1] quit [Sysname]management-vlan 1 [Sysname]interface Vlan-interface 1 [Sysname-Vlan-interface1] ip address 10.0.1.201 255.255.255.0 # 显示VLAN 接口1 的相关信息。 <Sysname> display ip interface Vlan-interface 1 # 创建VLAN(H3C不支持cisco的VTP,所以只能添加静态VLAN) <H3C_TEST>system-view System View: return to User View with Ctrl+Z. [H3C_TEST]vlan 99 [H3C_TEST-vlan99]name seicoffice [H3C_TEST-vlan99]quit # 把交换机的端端口划分到相应的Vlan中 [H3C_TEST]interface ethernet1/0/2 //进入端口模式 [H3C_TEST-Ethernet1/0/2]port link-type access //设置端口的类型为access [H3C_TEST-Ethernet1/0/2]port access vlan 99 //把当前端口划到vlan 99 [H3C_TEST]vlan 99 [H3C_TEST-vlan99]port ethernet1/0/1 to ethernet1/0/24 //把以及网端口1/0/1到1/0/24划到vlan99 [H3C_TEST-vlan99]quit [H3C_TEST-GigabitEthernet1/2/1]port trunk permit vlan 1 99 // {ID|All} 设置trunk端口允许通过的VLAN ------------------------------------------------------------------------------------------------------- # 配置本地用户 <Sysname>system-view System View: return to User View with Ctrl+Z. [Sysname]local-user h3c New local user added. [Sysname-luser-h3c]service-type telnet level 3 [Sysname-luser-h3c]password simple h3c # 配置欢迎信息 [H3C_TEST]header login %Welcome to login h3c!% # 配置用户认证方式telnet(vty 0-4) [H3C_TEST]user-interface vty 0 4 [H3C_TEST-ui-vty0-4]authentication-mode scheme [H3C_TEST-ui-vty0-4]protocol inbound telnet [H3C_TEST-ui-vty0-4]super authentication-mode super-password [H3C_TEST-ui-vty0-4]quit [H3C_TEST]super password level 3 simple h3c //用户登陆后提升权限的密码 # 配置Radius策略 [H3C_TEST]radius scheme radius1 New Radius scheme [H3C_TEST-radius-radius1]primary authentication 10.0.1.253 1645 [H3C_TEST-radius-radius1]primary accounting 10.0.1.253 1646 [H3C_TEST-radius-radius1]secondary authentication 127.0.0.1 1645 [H3C_TEST-radius-radius1]secondary accounting 127.0.0.1 1646 [H3C_TEST-radius-radius1]timer 5 [H3C_TEST-radius-radius1]key authentication h3c [H3C_TEST-radius-radius1]key accounting h3c [H3C_TEST-radius-radius1]server-type extended [H3C_TEST-radius-radius1]user-name-format without-domain # 配置域 [H3C_TEST]domain h3c [H3C_TEST-isp-h3c]authentication radius-scheme radius1 local [H3C_TEST-isp-h3c]scheme radius-scheme radius1 local [H3C_TEST]domain default enable h3c # 配置在远程认证失败时,本地认证的key [H3C_TEST]local-server nas-ip 127.0.0.1 key h3c |
级别说明 Level 名称 命令 0 参观 ping、tracert、telnet 1 监控 display、debugging 2 配置 所有配置命令(管理级的命令除外) 3 管理 文件系统命令、FTP命令、TFTP命令、XMODEM命令 telnet仅用密码登录,管理员权限 [Router]user-interface vty 0 4[Router-ui-vty0-4]user privilege level 3[Router-ui-vty0-4]set authentication password simple abc telnet仅用密码登录,非管理员权限 [Router]super password level 3 simple super [Router]user-interface vty 0 4[Router-ui-vty0-4]user privilege level 1[Router-ui-vty0-4]set authentication password simple abc telnet使用路由器上配置的用户名密码登录,管理员权限 [Router]local-user admin password simple admin[Router]local-user admin service-type telnet[Router]local-user admin level 3 [Router]user-interface vty 0 4[Router-ui-vty0-4]authentication-mode local telnet使用路由器上配置的用户名密码登录,非管理员权限 [Router]super password level 3 simple super [Router]local-user manage password simple manage[Router]local-user manage service-type telnet[Router]local-user manage level 2 [Router]user-interface vty 0 4[Router-ui-vty0-4]authentication-mode local 对console口设置密码,登录后使用管理员权限 [Router]user-interface con 0[Router-ui-console0]user privilege level 3[Router-ui-console0]set authentication password simple abc 对console口设置密码,登录后使用非管理员权限 [Router]super password level 3 simple super [Router]user-interface con 0[Router-ui-console0]user privilege level 1[Router-ui-console0]set authentication password simple abc 对console口设置用户名和密码,登录后使用管理员权限 [Router]local-user admin password simple admin[Router]local-user admin service-type terminal[Router]local-user admin level 3 [Router]user-interface con 0[Router-ui-console0]authentication-mode local 对console口设置用户名和密码,登录后使用非管理员权限 [Router]super password level 3 simple super [Router]local-user manage password simple manage[Router]local-user manage service-type terminal[Router]local-user manage level 2 [Router]user-interface con 0[Router-ui-console0]authentication-mode local simple 是明文显示,cipher 是加密显示 路由器不设置telnet登录配置时,用户无法通过telnet登录到路由器上 [Router-ui-vty0-4]acl 2000 inbound可以通过acl的规则只允许符合条件的用户远程登录路由器 |
通信人家园 (https://www.txrjy.com/) | Powered by C114 |