华为3928基本配置(现作)
- 1、下载文档前请自行甄别文档内容的完整性,平台不提供额外的编辑、内容补充、找答案等附加服务。
- 2、"仅部分预览"的文档,不可在线预览部分如存在完整性等问题,可反馈申请退款(可完整预览的文档不适用该条件!)。
- 3、如文档侵犯您的权益,请联系客服反馈,我们会尽快为您处理(人工客服工作时间:9:00-18:30)。
华为3928基本配置(现作)
This will reboot device. Continue? [Y/N] y
#Apr 2 00:01:15:484 2000 Quidway COMMONSY/5/REBOOT:- 1 -
Reboot Fabric by command.
<Quidway>
%Apr 2 00:01:19:486 2000 Quidway DEV/5/DEV_LOG:- 1 -
Switch is rebooted.Starting......
***********************************************************
* Quidway S3928TP-SI BOOTROM, Version 223 *
***********************************************************
Copyright(C) 2003-2005, Hangzhou Huawei-3Com Tech. Co., Ltd.
All rights reserved.
Creation date : Sep 14 2005, 21:32:57
CPU type : BCM4704
CPU Clock Speed : 200MHz
BUS Clock Speed : 33MHz
Memory Size : 64MB
Mac Address : 000fe22090ff
Press Ctrl-B to enter Boot Menu... 1 0
Auto-booting...
Decompress Image................................................................................... ............................................................................................ ............................................................................................ ............................................................OK!
Starting at 0x80100000...
Configuration file is not used.
User interface aux0 is available.
Press ENTER to get started.
<Quidway>
%Apr 1 23:55:36:35 2000 Quidway SHELL/5/LOGIN:- 1 - Console(aux0) in unit1 login #Apr 1 23:55:36:205 2000 Quidway L2INF/2/PORT LINK STATUS CHANGE:- 1 -
Trap
1.3.6.1.6.3.1.1.5.4: portIndex is 4227634, ifAdminStatus is 1, ifOperStatus is 1
%Apr 1 23:55:36:400 2000 Quidway L2INF/5/PORT LINK STATUS CHANGE:- 1 -
Ethernet1/0/2: is
UP
<Quidway>sys
System View: return to User View with Ctrl+Z.
1. 首先,建立VLAN
[Quidway]vlan 254
[Quidway-vlan254]quit
2. 进入VLAN接口,进行各种配置
[Quidway]int vlan 254
[Quidway-Vlan-interface254]ip address 192.168.1.100 24
[Quidway-Vlan-interface254]quit
3. 在系统视图下,配置交换机的名字
[Quidway]sysname IDC
4. 进入VLAN,将端口加入VLAN此步基本用不到
[IDC] vLAN 254
[IDC-vlan254]port Ethernet 1/0/24
[IDC-vlan254]
%Apr 2 00:05:16:632 2000 IDC L2INF/5/VLANIF LINK STATUS CHANGE:- 1 -
Vlan-
interface254: is UP
%Apr 2 00:05:16:748 2000 IDC IFNET/5/UPDOWN:- 1 -Line protocol on the interface Vlan-interface254 is UP
[IDC-vlan254]quit
5.进入端口,将端口加入VLAN
[IDC]int Ethernet 1/0/1
[IDC-Ethernet1/0/1]
[IDC-Ethernet1/0/1] port access vlan 254
[IDC-Ethernet1/0/1]quit
6. 设置超级密码
[IDC]super password si
[IDC]super password simple ?
STRING<1-16> Plain text password string
[IDC]super password simple huawei
7. 进行用户配置,这里的是辅助用户和虚拟用户
[IDC]user-interface ?
INTEGER<0-12> First user terminal interface number to be configured
aux Aux user terminal interface
vty Virtual user terminal interface
8. 配置虚拟用户终端接口
[IDC]user-interface vty 0 4
[IDC-ui-vty0-4]set authentication password ?
cipher Display the current password with cipher text
simple Display the current password with plain text
设置认证密码
[IDC-ui-vty0-4]set authentication password simple huawei
设置认证模式
[IDC-ui-vty0-4]authentication-mode ?
none Login without checking
password Authentication use password of user terminal interface
scheme Authentication use RADIUS scheme
[IDC-ui-vty0-4]authentication-mode password
[IDC-ui-vty0-4]quit
9. 端口的相关配置
[IDC]int e1/0/24
[IDC-Ethernet1/0/24]port ?
access Specify current access port's characteristics
hybrid Specify current hybrid port's characteristics
isolate Port isolate
link-aggregation Link aggregation group
link-type Specify port link-type
trunk Specify current trunk port's characteristics
[IDC-Ethernet1/0/24]port link-type ?
access Access link-type
hybrid Hybrid VLAN link-type
irf-fabric Fabric-port link-type
trunk VLAN trunk link-type
[IDC-Ethernet1/0/24]port link-type trunk
[IDC-Ethernet1/0/24]
%Apr 2 00:03:52:358 2000 IDC L2INF/5/VLANIF LINK STATUS CHANGE:- 1 -
Vlan-
interface254: is DOWN
%Apr 2 00:03:52:482 2000 IDC IFNET/5/UPDOWN:- 1 -Line protocol on the interface Vlan-interface254 is DOWN
10.在为TRUNK端口时,允许通过的VLAN设置
[IDC-Ethernet1/0/24]port trunk ?
permit Specify VLAN which can pass trunk port
pvid Specify current trunk port's PVID VLAN characteristics
[IDC-Ethernet1/0/24]port trunk permit vlan ?
INTEGER<1-4094> VLAN ID
all All the VLANs
[IDC-Ethernet1/0/24]port trunk permit vlan 1 2 254
Please wait... Done.
[IDC-Ethernet1/0/24]
%Apr 2 00:04:17:305 2000 IDC L2INF/5/VLANIF LINK STATUS CHANGE:- 1 -
Vlan-
interface254: is UP
%Apr 2 00:04:17:415 2000 IDC IFNET/5/UPDOWN:- 1 -Line protocol on the interface Vlan-interface254 is UP
[IDC-Ethernet1/0/24]quit
11.建立本地用户
[IDC]local-user ?
STRING<1-80> Local user name
password-display-mode Specify password display mode
[IDC]local-user cst ?
<cr>
[IDC]local-user cst
New local user added.
设置次本地用户的服务模式
[IDC-luser-cst]service-type ?
ftp FTP service type
lan-access LAN-ACCESS service type
ssh Secure Shell service type
telnet TELNET service type
terminal TERMINAL service type
[IDC-luser-cst]service-type terminal telnet level 3
配置此本地用户的密码
[IDC-luser-cst]password simple huawei
[IDC-luser-cst]quit
13. 设置SNMP V3
[IDC] snmp-agent sys-info version v3
[IDC] snmp-agent mib-view included wnmview internet
[IDC]snmp-agent ?
community Set a community for the access of SNMPv1&SNMPv2c
group Set an SNMP group based on USM
local-engineid Set the engineID of local SNMP entity
mib-view Set SNMP MIB view information
packet Set SNMP packet's parameters
sys-info Set system information of the node
target-host Set the target hosts to receive SNMP notification/traps
trap Set the parameters of SNMP trap/notification
usm-user Set a new user for access to SNMP entity
<cr>
[IDC]snmp-agent group v3 wnmview ?
acl Set access control list for this group
authentication Specify a securityLevel of AuthNoPriv for this group name
notify-view Set a notify view for this group name
privacy Specify a securityLevel of AuthPriv for this group name
read-view Set a read view for this group name
write-view Set a write view for this group name
<cr>
[IDC] snmp-agent group v3 wnmgroup authentication read-view wnmview write-view wnmview notify-view wnmview
[IDC] snmp-agent usm-user v3 wnm wnmgroup authentication-mode md5 123456 [IDC] snmp-agent trap enable standard
[IDC] snmp-agent target-host trap address udp-domain 192.168.1.1 udp-port 5000 params securityname wnm v3
[IDC]。