思科交换机基本配置实例讲解
目录
1、基本概念介绍....................................................................................................................................1
2、密码、登陆等基本配置....................................................................................................................1
3、CISCO设备端口配置详解..............................................................................................................7
4、VLAN的规划及配置......................................................................................................................12
4.1核心交换机的相关配置.............................................................................................................12
4.2接入交换机的相关配置.............................................................................................................24
5、配置交换机的路由功能..................................................................................................................29
6、配置交换机的DHCP功能.............................................................................................................30
7、常用排错命令..................................................................................................................................31
1、基本概念介绍
IOS:互联网操作系统,也就是交换机和路由器中用的操作系统
VLAN:虚拟lan
VTP:VLANTRUNKPROTOCOL
DHCP:动态主机配置协议
ACL:访问控制列表
三层交换机:具有三层路由转发能力的交换机
本教程中“#”后的蓝色文字为注释内容。
2、密码、登陆等基本配置
本节介绍的内容为cisco路由器或者交换机的基本配置,在目前版本的cisco交换机或
路由器上的这些命令是通用的。本教程用的是cisco的模拟器做的介绍,一些具体的端口显
示或许与你们实际的设备不符,但这并不影响基本配置命令的执行。
Cisco3640(R4700)processor(revision0xFF)with124928K/6144Kbytesofmemory.
ProcessorboardID00000000
R4700CPUat100MHz,Implementation33,Rev1.2
2Ethernetinterfaces
8Serialinterfaces
DRAMconfigurationis64bitswidewithparityenabled.
125KbytesofNVRAM.
8192KbytesofprocessorboardSystemflash(Read/Write)
---SystemConfigurationDialog---
Wouldyouliketoentertheinitialconfigurationdialog?[yes/no]:n
#此处我们选择no,不进入他的初始化配置向导
PressRETURNtogetstarted!
#选择no以后,提示你按回车键开始,此处我们需要按回车键
*Mar100:43:56.591:%IP-5-WEBINST_KILL:TerminatingDNSprocess
*Mar100:43:58.379:%SYS-5-RESTART:Systemrestarted--
CiscoIOSSoftware,3600Software(C3640-JK9O3S-M),Version12.3(14)T7,RELEASE
SOFTWARE(fc2)
精选
TechnicalSupport:/techsupport
Copyright(c)1986-2006byCiscoSystems,Inc.
CompiledWed22-Mar-0621:46bypwade
*Mar100:43:58.411:%SNMP-5-COLDSTART:SNMPagentonhostRouterisundergoinga
coldstart
Router>
#等显示稳定后,出现最初的提示符,注意提示符是“>”,目前所处的状态称为用户模式。
Router>用户模式
Router>
Router>en
#如果在当前状态下没有重复的命令,我们可以用“TAB”键来补齐这条命令,主要目的是
为了便于阅读
Router>enable进入特权模式
#从用户模式(urmode)进入到特权模式(execmode),注意提示符的变化,提示符变为“#”
Router#conft
Router#configureterminal进入全局模式
(说明:#在特权模式下输入configureterminal进入全局配置模式(globalconfigurationmode),
在这之下输入的命令叫做全局命令,一旦输入,将对整个router产生即时影响。如下,注意提示
符的变化:)
Router(config)#exit#请注意提示符发生了改变,当前的模式据叫做全局配置模式。
Router#conf
*Mar100:44:26.491:%SYS-5-CONFIG_I:Configuredfromconsolebyconsolet#在输入命
令的过程中,IOS会出现一些即时提示。
Enterconfigurationcommands,hCNTL/Z.
Router(config)#exit#退出当前的全局配置模式的命令是exit
Router#conft#重新进入到全局配置模式
Enterconfigurationcommands,hCNTL/Z.
Router(config)
#*Mar100:44:35.591:%SYS-5-CONFIG_I:Configuredfromconsolebyconsolehos
#这行是路由器(交换机)出现的一些即时提示。
Router(config)#hostnametest
#这条命令用来更改当前设备的名字(名字中可包含设备的楼层、用途等信息),主要是为
了将来便于区分设备。
test(config)
##回车后我们就会发现,但前的设备的名字已经发生了改变,变成了test了。
test(config)#enablepass
#这条命令用来配置设备的登陆密码,用tab键补齐后,再下一行显示完整命令。
test(config)#enablepasswordcisco#我们输入这台设备的登陆密码为cisco
test(config)#end#我们退回到全局配置模式,校验一下刚才输入的密码
test#shr
#此命令的完整写法是showrunning-start,此处的shr用的是省略的写法,因无其他重复的
命令所以可以被执行。
Buildingconfiguration...
精选
Currentconfiguration:1559bytes
!
version12.3
rvicetimestampsdebugdatetimemc
rvicetimestampslogdatetimemc
norvicepassword-encryption
!
hostnametest#注意此处显示的是我们配置的设备的名字
!
boot-start-marker
boot-end-marker
!
enablepasswordcisco
#此处显示的是刚才我们配置的enable密码,注意此时是用明文显示的,有点不安全。
!
noaaanew-model
!
resourcepolicy
!
memory-sizeiomem5
ipsubnet-zero
!
#到这一行其实并未全部显示完配置的内容,我们可以按键盘上的任意键来终止继续显示。
在显示的过程中通过按回车键可以逐行显示,按空格键可以一页一页的显示。这些操作可在
实际的设备中体会。
test#conft#重新进入到全局配置模式
test(config)#rvicepass
test(config)#rvicepassword-encryption#利用这条命令给密码加密显示。
test(config)#end
test#shr#退出到全局配置模式后,验证刚才的配置。
Buildingconfiguration...
Currentconfiguration:1565bytes
!
version12.3
rvicetimestampsdebugdatetimemc
rvicetimestampslogdatetimemc
rvicepassword-encryption
!
hostnametest
!
精选
boot-start-marker
boot-end-marker
!
enablepassword7070C285F4D06cisco
#注意此处刚才明文显示的密码已经变成加密显示了,这样从一定程度上保证了密码的安
全。
!
noaaanew-model
!
resourcepolicy
!
memory-sizeiomem5
ipsubnet-zero
!
#验证完毕后按任何一个键中断显示,下面的内容说明终端登陆密码的配置。
test#conft
Enterconfigurationcommands,hCNTL/Z.
test(config)#norvicepassword-encryption
#可利用这条命令(前面加no)来去掉密码加密功能,cisco的所有命令都可以通过这种方
式来禁止。
test(config)#linecon
test(config)#lineconsole0#利用这条命令来配置用超级终端登陆时的一些参数。
test(config-line)#pass
test(config-line)#passwordcisco#添加密码,此处我们配置的密码为cisco
test(config-line)#loggi
test(config-line)#logging?
#在任何情况下如果你忘记了命令的相关参数可以用?来获得提示和帮助
synchronousSynchronizedmessageoutput
test(config-line)#loggingsy
test(config-line)#loggingsynchronous
#在我们进行配置时,IOS会产生一些即时的提示信息,而这些信息会冲乱我们的光标显示,
用这条命令可以将光标规矩在下一行,即使出现了一些即时的提示。
test(config-line)#exit#退出当前console口的参数配置
test(config)#linevt?#telnet登陆时相关参数的配置,此处用了?来寻求提示。
<0-134>FirstLinenumber
auxAuxiliaryline
consolePrimaryterminalline
ttyTerminalcontroller
vtyVirtualterminal
x/ySlot/PortforModems
test(config)#linevty04
精选
#我们配置虚拟终端的0到4,也就是同时允许5个用户可以telnet到这台设备上来。
test(config-line)#pass
test(config-line)#passwordcisco
#我们配置telnet时的密码为cisco,如果此处我们不设置密码,那么用telnet来登陆的时候
并不会以空密码登陆,而是会给你提示说:相关密码没有设置,禁止登陆。所以我们为了能
远程telnet到这台设备,此处的密码一定要设置好。
test(config-line)#login#这条命令是允许通过telnet来登录
test(config-line)#exit#退出当前配置模式到全局配置模式。
test(config)
#test(config)
#test#confs
#我们在做配置的时候,会出现输入错误的情况,在这种情况下ios会以为你输入的是一个
域名
Translating"s"...domainrver(255.255.255.255)
#那么ios会做长时间的搜寻,试图找到这个域名对应的ip地址.......
Translating"s"...domainrver(255.255.255.255)
#这段时间是比较长的,那么我们如何禁用它的这个功能呢?
%Unknowncommandorcomputername,orunabletofindcomputeraddress
test#conft
Enterconfigurationcommands,hCNTL/Z.
test(config)#noipdomain-lookup#在全局配置模式下,将ip域名的搜寻功能关闭就可以了。
test(config)#end
test#conf
*Mar101:40:46.895:%SYS-5-CONFIG_I:Configuredfromconsolebyconsole
test#confx#将上述功能关闭以后,再有输入错误的情况会直接提示你输入错误。
^
%Invalidinputdetectedat'^'marker.
test
#test(config)#ipdomain-name202.102.128.68
#如果有必要将设备配置上DNS功能的话就用这条命令。
###基本配置完毕后我们验证一下所有的配置
###test#shrun
Buildingconfiguration...
Currentconfiguration:1693bytes
!
version12.3
rvicetimestampsdebugdatetimemc
rvicetimestampslogdatetimemc
rvicepassword-encryption#密码加密显示功能打开
!
精选
hostnametest
!
boot-start-marker
boot-end-marker
!
enablepassword7070C285F4D06#密码被加密显示了
!
noaaanew-model
!
resourcepolicy
!
memory-sizeiomem5
ipsubnet-zero
!
!
ipcef
noipdomainlookup#关闭了域名查找功能
noipdhcpuvrfconnected
!
!
noipipsdeny-actionips-interface
!
noftp-rverwrite-enable
!
nocryptoisakmpccm
!
(略……)
iphttprver
noiphttpcure-rver
ipclassless
!
control-plane
!
linecon0
exec-timeout00
password7094F471A1A0A#用超级终端登陆的密码,也同样被加密显示
loggingsynchronous
lineaux0
linevty04
password700071A150754#用telnet登陆的密码,也同样被加密显示
login
精选
!
!
end
test
#3、cisco设备端口配置详解
UrAccessVerification
#从dos提示符下运行telnetip地址,就会连接到相应的交换机或者路由器
Password:#输入配置号的telnet密码,也就是上节提到的vtp中的密码
test>en#进入特权模式
Password:#输入特权模式密码,也就是上节提到的enable密码。注意这些密
码在输入的时候屏幕是不显示的。
test
#test
#test#shipintbrief#查看当前所有端口状态,包括vlan和实际的物理接口状态
InterfaceIP-AddressOK?MethodStatusProtocol协议
#这行列示的各种状态的名称
FastEthernet1unassigned未分配YESNVRAMdowndown
Vlan1192.168.113.254YESNVRAMupup
#vlan1的状态是active
Vlan2172.16.0.2YESNVRAMupup
Vlan10192.168.101.254YESNVRAMupup
Vlan20192.168.102.254YESNVRAMupup
Vlan30192.168.103.254YESNVRAMupup
Vlan40192.168.104.254YESNVRAMupup
Vlan50192.168.105.254YESNVRAMupup
Vlan60192.168.106.254YESNVRAMupup
Vlan70192.168.107.254YESNVRAMupup
Vlan80192.168.108.254YESNVRAMupup
Vlan100192.168.110.254YESNVRAMupup
Vlan110192.168.111.254YESNVRAMupup
Vlan120192.168.112.254YESNVRAMupup
Vlan150192.168.100.254YESNVRAMupup
Vlan160192.168.115.254YESNVRAMupup
GigabitEthernet1/1unassignedYESuntupup
#物理接口gi1/1也是active状态
GigabitEthernet1/2unassignedYESuntdowndown
精选
GigabitEthernet1/3unassignedYESuntdowndown
GigabitEthernet1/4unassignedYESuntdowndown
GigabitEthernet1/5unassignedYESuntdowndown
GigabitEthernet1/6unassignedYESuntdowndown
GigabitEthernet1/7unassignedYESuntdowndown
GigabitEthernet1/8unassignedYESuntdowndown
GigabitEthernet1/9unassignedYESuntdowndown
#说明:通过上述命令即可以查看当前设备所有状态的情况也可以查看端口的表示方式。在
此例中我们登陆的是一台cisco4503的三层交换机;其中GigabitEthernet1/1,表示的是这台
交换机上的第1块业务板的第1个端口,并且此端口是个千兆端口;而GigabitEthernet3/19
表示的是这台交换机上的第3块业务版的第19个端口,并且此端口也是一个千兆端口,其
他的端口以此类推。千兆端口的名称为:GigabitEthernet,百兆端口的名称为:FastEthernet。
test#conft
#进入到全局配置模式。要想对端口、vlan、路由等操作一定要到全局配置模式中来。
Enterconfigurationcommands,hCNTL/Z.
test(config)#inter
test(config)#interfacegi1/2进入Gi1/2端口
#通过此命令可进去端口配置模式,此处我们进入的是GigabitEthernet1/2口,gi1/2为简写。
test(config-if)#?
#回车后进入到端口配置模式,注意提示符的变化,输入?寻求在这个模式着那个的帮助。
Interfaceconfigurationcommands:
access-groupAccessgroupconfiguration
arpSetarptype(arpa,probe,snap)ortimeout
autoConfigureAutomation
backupModifybackupparameters
bandwidthSetbandwidthinformationalparameter
bgp-policyApplypolicypropogatedbybgpcommunitystring
carrier-delaySpecifydelayforinterfacetransitions
cdpCDPinterfacesubcommands
channel-groupEtherchannel/portbundlingconfiguration
channel-protocolSelectthechannelprotocol(LACP,PAgP)
dampeningEnableeventdampening
defaultSetacommandtoitsdefaults
delaySpecifyinterfacethroughputdelay
descriptionInterfacespecificdescription
dot1xInterfaceConfigCommandsfor802.1x
duplexConfigureduplexoperation.
exitExitfrominterfaceconfigurationmode
flow-samplerAttachflowsamplertotheinterface
flowcontrolConfigureflowoperation.
helpDescriptionoftheinteractivehelpsystem
精选
ipInterfaceInternetProtocolconfigcommands
isisIS-IScommands
iso-igrpISO-IGRPinterfacesubcommands
keepaliveEnablekeepalive
l2protocol-tunnelTunnelLayer2protocols
lacpLACPinterfacesubcommands
load-intervalSpecifyintervalforloadcalculationforaninterface
loggingConfigureloggingforinterface
loopbackConfigureinternalloopbackonaninterface
macMACinterfacecommands
macroCommandmacro
max-rerved-bandwidthMaximumRervableBandwidthonanInterface
mtuSettheinterfaceMaximumTransmissionUnit(MTU)
noNegateacommandortitsdefaults
pagpPAgPinterfacesubcommands
powerPowerconfiguration
qosQoSconfiguration
rmonConfigureRemoteMonitoringonaninterface
rvice-policyConfigureQoSServicePolicy
shutdownShutdownthelectedinterface
snmpModifySNMPinterfaceparameters
spanning-treeSpanningTreeSubsystem
speedConfigurespeedoperation.
storm-controlstormconfiguration
switchportSetswitchingmodecharacteristics
timeoutDefinetimeoutvaluesforthisinterface
transmit-interfaceAssignatransmitinterfacetoareceive-onlyinterface
tx-queueConfigureinterfacetransmitqueue
udldConfigureUDLDenabledordisabledandignoreglobalUDLD
tting
vlan-rangeconfigvlan
test(config-if)#spe
test(config-if)#speed?
#我们可指定这个端口的速度,比如这个端口接的是一个百兆的收发器,我们就可以强制将
此端口设置成100M
10Force10Mbpsoperation#强制此端口为10M
100Force100Mbpsoperation#强制此端口为100M
1000Force1000Mbpsoperation#强制此端口为1000M
autoEnableAUTOspeedconfiguration#允许速度自动协商
test(config-if)#speed100
#通过此命令就可将此端口强制设成100M,默认的状态下是auto。
test(config-if)#dup
精选
test(config-if)#duplex?#用此命令可配置此端口的双工模式,有3个选项供选择。
autoEnableAUTOduplexconfiguration#自动配置此端口的双工模式
fullForcefullduplexoperation#强制此端口为全双工模式
halfForcehalf-duplexoperation#强制此端口为半双工模式
test(config-if)#duplexauto
test(config-if)#end#用end命令可直接退回到特权模式,用exit是一层一层的退出。
test#ter
test#terminalmoni
test#terminalmonitor
#打开终端监控。当用telnet登陆的时候默认是不显示各端口的实时变化情况的,打开这个
功能就能实时的看到这台交换机上哪个端口up,哪个端口down,这对于排错的时候是很有
帮助的。
test#conft
Enterconfigurationcommands,hCNTL/Z.
test(config)#intgi1/2#重新回到端口配置模式
test(config-if)#shut#此命令可手工关闭此端口
test(config-if)#noshut#此命令为打开此端口
test(config-if)#switchportaccessvlan?
#这条命令可配置此端口属于哪个vlan,当然此vlan要事先建好。
<1-4094>VLANIDoftheVLANwhenthisportisinaccessmode
dynamicWheninaccessmode,thisinterfacesVLANiscontrolledbyVMPS
test(config-if)#switchportaccessvlan100
#我们配置此端口属于vlan100,如果此端口事先属于其他vlan那么,会从其他vlan退出
test(config-if)#exit
test(config)#intrang#亦可成批的配置端口,利用这个命令
test(config)#intrangegi1/1-5
#表示同时对gi1/1到gi1/5这5个端口进行操作,注意命令“1-5”,之间有空格。
test(config-if-range)#switchportaccessvlan100#可同时配置这5个端口属于vlan100
test(config-if-range)#shutdown#可同时关闭这5个端口
test(config-if-range)#noshutdown#可同时启用这5个端口
test(config-if-range)#exit
test(config-if)#end
test
#test#shintgi1/2#在特权模式中,可查看单个端口的状态
GigabitEthernet1/2isdown,lineprotocolisdown(notconnect)
#这行说明此端口当前的状态是down的
HardwareisGigabitEthernetPort,addressis001a.6db4.a3c1(bia001a.6db4.a3c1)
#此端口的MAC地址
MTU1500bytes,BW1000000Kbit,DLY10uc,
reliability255/255,txload1/255,rxload1/255
精选
EncapsulationARPA,loopbacknott
Keepalivet(10c)
Auto-duplex,Auto-speed,linktypeisauto,mediatypeis10/100/1000-TX
#此端口的模式为10/100/1000-TX
inputflow-controlisoff,outputflow-controlisoff
ARPtype:ARPA,ARPTimeout04:00:00
Lastinputnever,outputnever,outputhangnever
Lastclearingof"showinterface"countersnever
Inputqueue:0/2000/0/0(size/max/drops/flushes);Totaloutputdrops:0
Queueingstrategy:fifo
Outputqueue:0/40(size/max)
5minuteinputrate0bits/c,0packets/c
5minuteoutputrate0bits/c,0packets/c
0packetsinput,0bytes,0nobuffer
Received0broadcasts(0multicast)
0runts,0giants,0throttles
0inputerrors,0CRC,0frame,0overrun,0ignored
0inputpacketswithdribbleconditiondetected
0packetsoutput,0bytes,0underruns
0outputerrors,0collisions,0interfacerets
0babbles,0latecollision,0deferred
0lostcarrier,0nocarrier
0outputbufferfailures,0outputbuffersswappedout
test#shintgi1/1
GigabitEthernet1/1isup,lineprotocolisup(connected)
#这行表明此端口是up的,并且连有网线。
HardwareisGigabitEthernetPort,addressis001a.6db4.a3c0(bia001a.6db4.a3c0)
MTU1500bytes,BW1000000Kbit,DLY10uc,
reliability255/255,txload1/255,rxload1/255
EncapsulationARPA,loopbacknott
Keepalivet(10c)
Full-duplex,1000Mb/s,linktypeisauto,mediatypeis10/100/1000-TX
inputflow-controlisoff,outputflow-controlisoff
ARPtype:ARPA,ARPTimeout04:00:00
Lastinputnever,outputnever,outputhangnever
Lastclearingof"showinterface"countersnever
Inputqueue:0/2000/0/0(size/max/drops/flushes);Totaloutputdrops:0
Queueingstrategy:fifo
Outputqueue:0/40(size/max)
5minuteinputrate1293000bits/c,426packets/c
5minuteoutputrate2410000bits/c,528packets/c
273591244packetsinput,9bytes,0nobuffer
Received0broadcasts(0multicast)
0runts,0giants,0throttles
精选
0inputerrors,0CRC,0frame,0overrun,0ignored#没有输入错误,表明链路状态良好
0inputpacketswithdribbleconditiondetected
335026620packetsoutput,223732323465bytes,0underruns#输出数据包统计
0outputerrors,0collisions,0interfacerets
0babbles,0latecollision,0deferred
0lostcarrier,0nocarrier
0outputbufferfailures,0outputbuffersswappedout
test
#test
#test
#test#wr#保存刚才的配置结果
4、vlan的规划及配置
在本节中我们讲解vlan的规划及具体的配置命令。在此例中我们用的是vtp(VLAN
TrunkingProtocol)rver的模式,在这种模式中我们需要配置核心交换机的vtp模式为rver,
各接入交换机的vtp模式为cilent,那么配置完成后接入交换机就会通过trunk口自动从核心
交换机学习到所有的vlan配置信息。在接入交换机中只需要添加相应的端口即可,这样易
于管理与部署。具体的配置命令我们通过两小节来演示:
4.1核心交换机的相关配置
(这是一台已经配置好了的交换机,但这并不会影响我们的演示效果。所有我们新作的配置
会在演示结束后清除。)
TEST#shvlan#显示已经有的vlan信息,并且同时显示了各端口所属的vlan
VLANNameStatusPorts
----------------------------------------------------------------------------
1defaultactiveGi1/2,Gi1/3,Gi1/4,Gi1/5,Gi1/6,Gi1/7,
Gi1/8,Gi1/9,Gi1/10,Gi1/11,Gi1/13,Gi1/14,Gi1/16,Gi1/17,Gi1/18,Gi1/19,Gi1/20,Gi3/12,
Gi3/13,Gi3/16
2firewallactiveGi1/1
10EngineeringactiveGi3/9,Gi3/10
20ProcurementactiveGi3/19
30QAQCactive
40Operationactive
50YardactiveGi3/18
60BMactive
70HRADactive
精选
80Facilityactive
100Financeactive
110GOactive
120Wlanactive
150ServeractiveGi3/1,Gi3/2,Gi3/3,Gi3/4,Gi3/5,Gi3/6,
Gi3/7,Gi3/8
160ClientactiveGi3/11,Gi3/15
#从这行往下是为其他协议预留的vlan号段,这些不必理会。
1002fddi-defaultact/unsup1003token-ring-default
act/unsup
1004fddinet-defaultact/unsup
1005trnet-defaultact/unsup
VLANTypeSAIDMTUParentRingNoBridgeNoStpBrdgModeTrans1Trans2
--------------------------------------------------------------------
1enet1000011500-----00
2enet1000021500-----00
10enet1000101500-----00
20enet1000201500-----00
30enet1000301500-----00
40enet1000401500-----00
50enet1000501500-----00
60enet1000601500-----00
70enet1000701500-----00
80enet1000801500-----00
100enet1001001500-----00
110enet1001101500-----00
120enet1001201500-----00
150enet1001501500-----00
160enet1001601500-----00
1002fddi1010021500-----00
1003tr1010031500-----00
1004fdnet1010041500---ieee-00
TEST#conf
Configuringfromterminal,memory,ornetwork[terminal]?t
Enterconfigurationcommands,hCNTL/Z.
TEST(config)#vlan200#我们新建一个vlan号为200的vlan
TEST(config-vlan)#nametest#给这个vlan命名,这样便于日常的管理。
TEST(config-vlan)#?
VLANconfigurationcommands:
areMaximumnumberofAllRouteExplorerhopsforthisVLAN(orzeroifnone
specified)
backupcrfBackupCRFmodeoftheVLAN
精选
bridgeBridgingcharacteristicsoftheVLAN
exitApplychanges,bumprevisionnumber,andexitmode
mediaMediatypeoftheVLAN
mtuVLANMaximumTransmissionUnit
nameAsciinameoftheVLAN#刚才我们就是用的这条命令
noNegateacommandortitsdefaults
parentIDnumberoftheParentVLANofFDDIorTokenRingtypeVLANs
private-vlanConfigureaprivateVLAN
remote-spanConfigureasRemoteSPANVLAN
ringRingnumberofFDDIorTokenRingtypeVLANs
saidIEEE802.10SAID
shutdownShutdownVLANswitching
stateOperationalstateoftheVLAN
steMaximumnumberofSpanningTreeExplorerhopsforthisVLAN(orzeroif
nonespecified)
stpSpanningtreecharacteristicsoftheVLAN
tb-vlan1IDnumberofthefirsttranslationalVLANforthisVLAN(orzeroifnone)
tb-vlan2IDnumberofthecondtranslationalVLANforthisVLAN(orzeroifnone)
TEST(config-vlan)#END#建好vlan后退出到特权模式中
TEST#showipintbrief
#显示目前有的端口配置状态,我们会发现此时并没有vlan200的相关信息
InterfaceIP-AddressOK?MethodStatusProtocol
FastEthernet1unassignedYESNVRAMdowndown
Vlan1192.168.113.254YESNVRAMupup
Vlan2172.16.0.2YESNVRAMupup
Vlan10192.168.101.254YESNVRAMupup
Vlan20192.168.102.254YESNVRAMupup
Vlan30192.168.103.254YESNVRAMupup
Vlan40192.168.104.254YESNVRAMupup
Vlan50192.168.105.254YESNVRAMupup
Vlan60192.168.106.254YESNVRAMupup
Vlan70192.168.107.254YESNVRAMupup
Vlan80192.168.108.254YESNVRAMupup
Vlan100192.168.110.254YESNVRAMupup
Vlan110192.168.111.254YESNVRAMupup
Vlan120192.168.112.254YESNVRAMupup
Vlan150192.168.100.254YESNVRAMupup
Vlan160192.168.115.254YESNVRAMupup
GigabitEthernet1/1unassignedYESuntupup
GigabitEthernet1/2unassignedYESuntdowndown
GigabitEthernet1/3unassignedYESuntdowndown
GigabitEthernet1/4unassignedYESuntdowndown
GigabitEthernet1/5unassignedYESuntdowndown
精选
GigabitEthernet1/6unassignedYESuntdowndown
GigabitEthernet1/7unassignedYESuntdowndown
GigabitEthernet1/8unassignedYESuntdowndown
GigabitEthernet1/9unassignedYESuntdowndown
GigabitEthernet1/10unassignedYESuntdowndown
GigabitEthernet1/11unassignedYESuntdowndown
GigabitEthernet1/12unassignedYESuntdowndown
GigabitEthernet1/13unassignedYESuntdowndown
GigabitEthernet1/14unassignedYESuntdowndown
GigabitEthernet1/15unassignedYESuntupup
GigabitEthernet1/16unassignedYESuntdowndown
GigabitEthernet1/17unassignedYESuntdowndown
GigabitEthernet1/18unassignedYESuntdowndown
GigabitEthernet1/19unassignedYESuntdowndown
GigabitEthernet1/20unassignedYESuntdowndown
GigabitEthernet3/1unassignedYESuntupup
GigabitEthernet3/2unassignedYESuntupup
GigabitEthernet3/3unassignedYESuntupup
GigabitEthernet3/4unassignedYESuntupup
GigabitEthernet3/5unassignedYESuntupup
GigabitEthernet3/6unassignedYESuntupup
GigabitEthernet3/7unassignedYESuntupup
GigabitEthernet3/8unassignedYESuntdowndown
TEST#shvlan#显示一下vlan信息
VLANNameStatusPorts
----------------------------------------------------------------------------
1defaultactiveGi1/2,Gi1/3,Gi1/4,Gi1/5,Gi1/6,Gi1/7,
Gi1/8,Gi1/9,Gi1/10,Gi1/11,Gi1/13,Gi1/14,Gi1/16,Gi1/17,Gi1/18,Gi1/19,Gi1/20,Gi3/12,
Gi3/13,Gi3/16
2firewallactiveGi1/1
10EngineeringactiveGi3/9,Gi3/10
20ProcurementactiveGi3/19
30QAQCactive
40Operationactive
50YardactiveGi3/18
60BMactive
70HRADactive
80Facilityactive
100Financeactive
110GOactive
120Wlanactive
150ServeractiveGi3/1,Gi3/2,Gi3/3,Gi3/4,Gi3/5,Gi3/6,
精选
Gi3/7,Gi3/8
160ClientactiveGi3/11,Gi3/15
200testactive
#这个是我们新建好的vlan,但是vlan中没有任何端口。
1002fddi-defaultact/unsup
1003token-ring-defaultact/unsup
1004fddinet-defaultact/unsup
1005trnet-defaultact/unsup
VLANTypeSAIDMTUParentRingNoBridgeNoStpBrdgModeTrans1Trans2
--------------------------------------------------------------------
1enet1000011500-----00
2enet1000021500-----00
10enet1000101500-----00
20enet1000201500-----00
30enet1000301500-----00
40enet1000401500-----00
50enet1000501500-----00
60enet1000601500-----00
70enet1000701500-----00
80enet1000801500-----00
100enet1001001500-----00
110enet1001101500-----00
120enet1001201500-----00
150enet1001501500-----00
160enet1001601500-----00
200enet1002001500-----00
1002fddi1010021500-----00
TEST#conft
Enterconfigurationcommands,hCNTL/Z.
TEST(config)#interfacegigabitEthernet1/2
#我们进入端口配置模式,配置gigabitEthernet1/2这个端口
TEST(config-if)#switchportaccessvlan200#将此端口加入到刚才建好的vlan200中
TEST(config-if)#end
TEST#shvlan#退出来验证一下
VLANNameStatusPorts
----------------------------------------------------------------------------
1defaultactiveGi1/3,Gi1/4,Gi1/5,Gi1/6,Gi1/7,Gi1/8,
Gi1/9,Gi1/10,Gi1/11,Gi1/12,Gi1/14,Gi1/16,Gi1/17,Gi1/18,Gi1/19,Gi1/20,Gi3/12,Gi3/13,
Gi3/14
2firewallactiveGi1/1
10EngineeringactiveGi3/9,Gi3/10
精选
20ProcurementactiveGi3/19
30QAQCactive
40Operationactive
50YardactiveGi3/18
60BMactive
70HRADactive
80Facilityactive
100Financeactive
110GOactive
120Wlanactive
150ServeractiveGi3/1,Gi3/2,Gi3/3,Gi3/4,Gi3/5,Gi3/6,
Gi3/7,Gi3/8
160ClientactiveGi3/11,Gi3/15
200testactiveGi1/2
#现在GI1/2这个端口已经属于vlan200了。
1002fddi-defaultact/unsup
1003token-ring-defaultact/unsup
1004fddinet-defaultact/unsup
1005trnet-defaultact/unsup
VLANTypeSAIDMTUParentRingNoBridgeNoStpBrdgModeTrans1Trans2
--------------------------------------------------------------------
1enet1000011500-----00
2enet1000021500-----00
10enet1000101500-----00
20enet1000201500-----00
30enet1000301500-----00
40enet1000401500-----00
50enet1000501500-----00
60enet1000601500-----00
70enet1000701500-----00
80enet1000801500-----00
100enet1001001500-----00
110enet1001101500-----00
120enet1001201500-----00
150enet1001501500-----00
160enet1001601500-----00
200enet1002001500-----00
1002fddi1010021500-----00
1003tr1010031500-----00
TEST#shipintbrief
#再显示一下所有端口的状态,我们会发现同样没有vlan200的相关信息。
InterfaceIP-AddressOK?MethodStatusProtocol
精选
FastEthernet1unassignedYESNVRAMdowndown
Vlan1192.168.113.254YESNVRAMupup
Vlan2172.16.0.2YESNVRAMupup
Vlan10192.168.101.254YESNVRAMupup
Vlan20192.168.102.254YESNVRAMupup
Vlan30192.168.103.254YESNVRAMupup
Vlan40192.168.104.254YESNVRAMupup
Vlan50192.168.105.254YESNVRAMupup
Vlan60192.168.106.254YESNVRAMupup
Vlan70192.168.107.254YESNVRAMupup
Vlan80192.168.108.254YESNVRAMupup
Vlan100192.168.110.254YESNVRAMupup
Vlan110192.168.111.254YESNVRAMupup
Vlan120192.168.112.254YESNVRAMupup
Vlan150192.168.100.254YESNVRAMupup
Vlan160192.168.115.254YESNVRAMupup
GigabitEthernet1/1unassignedYESuntupup
GigabitEthernet1/2unassignedYESuntdowndown
GigabitEthernet1/3unassignedYESuntdowndown
GigabitEthernet1/4unassignedYESuntdowndown
GigabitEthernet1/5unassignedYESuntdowndown
GigabitEthernet1/6unassignedYESuntdowndown
GigabitEthernet1/7unassignedYESuntdowndown
GigabitEthernet1/8unassignedYESuntdowndown
GigabitEthernet1/9unassignedYESuntdowndown
GigabitEthernet1/10unassignedYESuntdowndown
GigabitEthernet1/11unassignedYESuntdowndown
GigabitEthernet1/12unassignedYESuntdowndown
GigabitEthernet1/13unassignedYESuntdowndown
GigabitEthernet1/14unassignedYESuntdowndown
GigabitEthernet1/15unassignedYESuntupup
GigabitEthernet1/16unassignedYESuntdowndown
GigabitEthernet1/17unassignedYESuntdowndown
GigabitEthernet1/18unassignedYESuntdowndown
GigabitEthernet1/19unassignedYESuntdowndown
GigabitEthernet1/20unassignedYESuntdowndown
GigabitEthernet3/1unassignedYESuntupup
GigabitEthernet3/2unassignedYESuntupup
GigabitEthernet3/3unassignedYESuntupup
GigabitEthernet3/4unassignedYESuntupup
GigabitEthernet3/5unassignedYESuntupup
GigabitEthernet3/6unassignedYESuntupup
GigabitEthernet3/7unassignedYESuntupup
GigabitEthernet3/8unassignedYESuntdowndown
精选
TEST#conft
Enterconfigurationcommands,hCNTL/Z.
TEST(config)#intvlan200#给这个vlan添加相应的ip地址,注意此处的语法
TEST(config-if)#ipadd10.10.10.0.1255.255.255.0#添加具体的ip地址
TEST(config-if)#noshut#使能此端口
TEST(config-if)#end
TEST#shipintb
#重新显示一下所有端口的状态,我们会发现已经有了vlan200的端口信息了。
InterfaceIP-AddressOK?MethodStatusProtocol
FastEthernet1unassignedYESNVRAMdowndown
Vlan1192.168.113.254YESNVRAMupup
Vlan2172.16.0.2YESNVRAMupup
Vlan10192.168.101.254YESNVRAMupup
Vlan20192.168.102.254YESNVRAMupup
Vlan30192.168.103.254YESNVRAMupup
Vlan40192.168.104.254YESNVRAMupup
Vlan50192.168.105.254YESNVRAMupup
Vlan60192.168.106.254YESNVRAMupup
Vlan70192.168.107.254YESNVRAMupup
Vlan80192.168.108.254YESNVRAMupup
Vlan100192.168.110.254YESNVRAMupup
Vlan110192.168.111.254YESNVRAMupup
Vlan120192.168.112.254YESNVRAMupup
Vlan150192.168.100.254YESNVRAMupup
Vlan160192.168.115.254YESNVRAMupup
Vlan20010.10.0.1YESmanualupup
GigabitEthernet1/1unassignedYESuntupup
GigabitEthernet1/2unassignedYESuntdowndown
GigabitEthernet1/3unassignedYESuntdowndown
GigabitEthernet1/4unassignedYESuntdowndown
GigabitEthernet1/5unassignedYESuntdowndown
GigabitEthernet1/6unassignedYESuntdowndown
GigabitEthernet1/7unassignedYESuntdowndown
GigabitEthernet1/8unassignedYESuntdowndown
GigabitEthernet1/9unassignedYESuntdowndown
GigabitEthernet1/10unassignedYESuntdowndown
GigabitEthernet1/11unassignedYESuntdowndown
GigabitEthernet1/12unassignedYESuntdowndown
GigabitEthernet1/13unassignedYESuntdowndown
GigabitEthernet1/14unassignedYESuntdowndown
GigabitEthernet1/15unassignedYESuntupup
GigabitEthernet1/16unassignedYESuntdowndown
GigabitEthernet1/17unassignedYESuntdowndown
精选
GigabitEthernet1/18unassignedYESuntdowndown
GigabitEthernet1/19unassignedYESuntdowndown
GigabitEthernet1/20unassignedYESuntdowndown
GigabitEthernet3/1unassignedYESuntupup
GigabitEthernet3/2unassignedYESuntupup
GigabitEthernet3/3unassignedYESuntupup
GigabitEthernet3/4unassignedYESuntupup
GigabitEthernet3/5unassignedYESuntupup
GigabitEthernet3/6unassignedYESuntupup
GigabitEthernet3/7unassignedYESuntupup
##小结一下:在刚才的配置过程中,端口Gi1/2下面所连接的电脑的网关就是vlan200的地
址——10.10.0.1。下面所连的电脑找到相应的网关后在会去找具体的路由,这些我们下节会
讲解。
TEST#showintertrunk
#显示当前交换机中的trunk接口。作为trunk接口的端口下联的是接入层(或者是汇聚层)
的交换机。
PortModeEncapsulationStatusNativevlan
Gi1/15on802.1qtrunking1
Gi3/17on802.1qtrunking1
Gi3/20on802.1qtrunking1
Gi3/21on802.1qtrunking1
Gi3/22on802.1qtrunking1
Gi3/23on802.1qtrunking1
Gi3/24on802.1qtrunking1
PortVlansallowedontrunk
Gi1/151-4094
Gi3/171-4094
Gi3/201-4094
Gi3/211-4094
Gi3/221-4094
Gi3/231-4094
Gi3/241-4094
PortVlansallowedandactiveinmanagementdomain
Gi1/151-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200
Gi3/171-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200
Gi3/201-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200
Gi3/211-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200
Gi3/221-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200
Gi3/231-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200
精选
Gi3/241-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200
PortVlansinspanningtreeforwardingstateandnotpruned
Gi1/151-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200
Gi3/171-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200
Gi3/201-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200
Gi3/211-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200
Gi3/221-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200
Gi3/231-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200
Gi3/241-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200
TEST#conft
Enterconfigurationcommands,hCNTL/Z.
TEST(config)#intgi1/15#我们以gi1/15来说明,如何将此端口配置成trunk接口
TEST(config-if)#switchportmode?#首先定义此接口的模式为trunk
accessSettrunkingmodetoACCESSunconditionally
dynamicSettrunkingmodetodynamicallynegotiateaccessortrunkmode
private-vlanSetthemodetoprivate-vlanhostorpromiscuous
trunkSettrunkingmodetoTRUNKunconditionally
TEST(config-if)#switchportmodetrunk
TEST(config-if)#switchporttrunkencapsulation?
#然后定义trunk口的封装类型,此处选择dot1q也叫802.1q,为通用封装类型
dot1qInterfaceusonly802.1qtrunkingencapsulationwhentrunking
islInterfaceusonlyISLtrunkingencapsulationwhentrunking
negotiateDevicewillnegotiatetrunkingencapsulationwithpeeroninterface
TEST(config-if)#switchporttrunkencapsulationdot1q
#回车后就将此trunk口的封装类型定义成了dot1q
##小结一下:刚才配置的是如何将下联接入层交换机的端口配置成trunk模式,并且如何
将此trunk口封装成特定的类型,接下来我们介绍如何配置此核心交换机的VTP的一些相关
设置。
TEST(config)#vtpmode?
clientSetthedevicetoclientmode.客服端模式
rverSetthedevicetorvermode.服务器模式
transparentSetthedevicetotransparentmode.透明模式
TEST(config)#vtpmoderver
#首先我们在全局配置模式中将vtp的mode设置成rver
TEST(config)#vtpdomainpjoe
#然后配置vtp的domain,所有的交换机应该在一个domain中,此例中我们定义的doamin
为pjoe
TEST(config)#vtppasswordpjoerver
精选
#配置此vtp的介入密码,这样可以防止未授权的交换机随便加入到这个domian中来。
TEST#shvtpstatus#配置完毕后显示一下vtp的状态
VTPVersion:2
ConfigurationRevision:22
MaximumVLANssupportedlocally:1005
NumberofexistingVLANs:20
VTPOperatingMode:Server#vtp的模式为rver模式
VTPDomainName:pjoe#vtp的域名是pjoe
VTPPruningMode:Disabled
VTPV2Mode:Disabled
VTPTrapsGeneration:Enabled
MD5digest:0x000xB30x210xB70x560xD70x060x4F
#此处表示的是vtp的密码(已加密)
Configurationlastmodifiedby192.168.113.254at12-3-0722:52:46
LocalupdaterIDis192.168.113.254oninterfaceVl1(lowestnumberedVLANinterfacefound)
TEST
#TEST
###小结一下:经过以上的配置就将核心交换机的vtp等的配置工作完成了,只需要再配置
好接入交换机的相关vtp参数和对应的trunk接口,接入交换机就能够从核心交换机上获取
到所有的vlan信息,而不需要重新建立各个vlan。
TEST#shvlan#接下来我们去掉新增加的vlan,先显示一下。
VLANNameStatusPorts
----------------------------------------------------------------------------
1defaultactiveGi1/3,Gi1/4,Gi1/5,Gi1/6,Gi1/7,Gi1/8,
Gi1/9,Gi1/10,Gi1/11,Gi1/12,Gi1/14,Gi1/16,Gi1/17,Gi1/18,Gi1/19,Gi1/20,Gi3/12,Gi3/13,
Gi3/14,
2firewallactiveGi1/1
10EngineeringactiveGi3/9,Gi3/10
20ProcurementactiveGi3/19
30QAQCactive
40Operationactive
50YardactiveGi3/18
60BMactive
70HRADactive
80Facilityactive
100Financeactive
110GOactive
120Wlanactive
150ServeractiveGi3/1,Gi3/2,Gi3/3,Gi3/4,Gi3/5,Gi3/6,
Gi3/7,Gi3/8
精选
160ClientactiveGi3/11,Gi3/15
200testactiveGi1/2
1002fddi-defaultact/unsup
1003token-ring-defaultact/unsup
1004fddinet-defaultact/unsup
1005trnet-defaultact/unsup
VLANTypeSAIDMTUParentRingNoBridgeNoStpBrdgModeTrans1Trans2
--------------------------------------------------------------------
1enet1000011500-----00
2enet1000021500-----00
10enet1000101500-----00
20enet1000201500-----00
30enet1000301500-----00
40enet1000401500-----00
50enet1000501500-----00
60enet1000601500-----00
70enet1000701500-----00
80enet1000801500-----00
100enet1001001500-----00
110enet1001101500-----00
120enet1001201500-----00
150enet1001501500-----00
160enet1001601500-----00
200enet1002001500-----00
1002fddi1010021500-----00
1003tr1010031500-----00
TEST#conft
Enterconfigurationcommands,hCNTL/Z.
TEST(config)#novlan200#第一步,删除vlan200
TEST(config)#nointvlan200#第二步,删除intvlan200,经过这两步就可以彻底
的删除vlan200了
TEST(config)intgi1/2#进入到gi1/2这个端口中
TEST(config-if)#switchportaccessvlan1#将这个端口重新划分到vlan1中
TEST(config-if)#end
TEST#shvvlan
#确认一下,我们成功的将gi1/2回归到vlan1中,并且删除掉了vlan200
VLANNameStatusPorts
----------------------------------------------------------------------------
1defaultactiveGi1/2,Gi1/3,Gi1/4,Gi1/5,Gi1/6,Gi1/7,
Gi1/8,Gi1/9,Gi1/10,Gi1/11,Gi1/13,Gi1/14,Gi1/16,Gi1/17,Gi1/18,Gi1/19,Gi1/20,Gi3/12,
精选
Gi3/13,Gi3/16
2firewallactiveGi1/1
10EngineeringactiveGi3/9,Gi3/10
20ProcurementactiveGi3/19
30QAQCactive
40Operationactive
50YardactiveGi3/18
60BMactive
70HRADactive
80Facilityactive
100Financeactive
110GOactive
120Wlanactive
150ServeractiveGi3/1,Gi3/2,Gi3/3,Gi3/4,Gi3/5,Gi3/6,
Gi3/7,Gi3/8
160ClientactiveGi3/11,Gi3/15
1002fddi-defaultact/unsup
1003token-ring-defaultact/unsup
1004fddinet-defaultact/unsup
1005trnet-defaultact/unsup
VLANTypeSAIDMTUParentRingNoBridgeNoStpBrdgModeTrans1Trans2
--------------------------------------------------------------------
1enet1000011500-----00
2enet1000021500-----00
10enet1000101500-----00
20enet1000201500-----00
30enet1000301500-----00
40enet1000401500-----00
50enet1000501500-----00
60enet1000601500-----00
70enet1000701500-----00
80enet1000801500-----00
100enet1001001500-----00
110enet1001101500-----00
120enet1001201500-----00
150enet1001501500-----00
160enet1001601500-----00
1002fddi1010021500-----00
1003tr1010031500-----00
1004fdnet1010041500---ieee-00
4.2接入交换机的相关配置
##在此例中,我们联入的是一台接入交换机,此交换机的gi0/1口上联至核心交换机。也
精选
就意味着我们需要配置gi0/1为trunk口。具体的配置如下:
D-2960-3(config)#intgi0/1
D-2960-3(config-if)#sw
D-2960-3(config-if)#switchportmo
D-2960-3(config-if)#switchportmode?
accessSettrunkingmodetoACCESSunconditionally
dynamicSettrunkingmodetodynamicallynegotiateaccessortrunkmode
trunkSettrunkingmodetoTRUNKunconditionally
D-2960-3(config-if)#switchportmodetrunk
##配置此接口的模式为trunk,在cisoc2960交换机中,配置完接口模式为trunk后就可以了,
不需要进一步配置此trunk口的封装状态,因为其默认的也是唯一的封装类型就是dot1q,
并且此系列交换机并没有专门的封装配置命令。
D-2960-3(config-if)#exit
D-2960-3(config)#exit
D-2960-3#shinttru#退至特权配置模式验证一下刚才的配置
PortModeEncapsulationStatusNativevlan
Gi0/1auto802.1qtrunking1
#这个端口已经配置成trunk模式,并且封装成802.1q了
PortVlansallowedontrunk
Gi0/11-4094
PortVlansallowedandactiveinmanagementdomain
Gi0/11-2,10,20,30,40,50,60,70,80,100,110,120,150,160
PortVlansinspanningtreeforwardingstateandnotpruned
Gi0/11-2,10,20,30,40,50,60,70,80,100,110,120,150,160
D-2960-3#conft#进入到全局配置模式
D-2960-3(config)#vtpmodeclient
#配置vtp模式为client,与核心交换机的rver模式相呼应。
D-2960-3(config)#vtpdomainpjoe
#配置vtp域为pjoe,只有一个域中的交换机才能互传vlan信息。
D-2960-3(config)#vtppasswordpjoerver#配置vtp密码
D-2960-3(config)#end
D-2960-3#shvtpstatus#退出到特权模式验证一下刚才的有关vtp的配置
VTPVersion:2
ConfigurationRevision:23
MaximumVLANssupportedlocally:255
精选
NumberofexistingVLANs:19
VTPOperatingMode:Client#模式已经设置成client
VTPDomainName:pjoe#域名已经设置成pjoe
VTPPruningMode:Disabled
VTPV2Mode:Disabled
VTPTrapsGeneration:Disabled
MD5digest:0xEC0x300xEF0x6F0xA50x9A0x390x7B
#密码已经配置完毕,但是被加密显示了
Configurationlastmodifiedby192.168.113.254at12-3-0722:58:54
##稍等一会后,验证一下是否学习到了核心交换机的vlan信息,它的学习有一小段的过程
30秒的样子。
D-2960-3#shvlan#验证一下vlan信息是否全部学到。
VLANNameStatusPorts
----------------------------------------------------------------------------
1defaultactiveFa0/1,Fa0/2,Fa0/3,Fa0/4,Fa0/5,
Fa0/6,Fa0/7,Fa0/8,Fa0/9,Fa0/10,Fa0/11,Fa0/12,Fa0/13,Fa0/14,Fa0/15,Fa0/16,Fa0/17,
Fa0/18,Fa0/19,Fa0/20,Fa0/21,Fa0/22,Fa0/23,Fa0/24,Fa0/25,Fa0/26,Fa0/27,Fa0/28,Fa0/29,
Fa0/30,Fa0/31,Fa0/32,Fa0/33,Fa0/34,Fa0/35,Fa0/36,Fa0/37,Fa0/38,Fa0/39,Fa0/40,
Fa0/41,a0/42,Fa0/43,Fa0/44,Fa0/45,Fa0/46,Fa0/47,Fa0/48,Gi0/2
2firewallactive
#ok,核心交换机上配置好的vlan信息已经被这台交换机学习到了,剩下的工作仅需要将相
应的端口添加到相应的vlan中就可以了,此处不赘述。
10Engineeringactive
20Procurementactive
30QAQCactive
40Operationactive
50Yardactive
60BMactive
70HRADactive
80Facilityactive
100Financeactive
110GOactive
120Wlanactive
150Serveractive
160Clientactive
1002fddi-defaultact/unsup
1003token-ring-defaultact/unsup
1004fddinet-defaultact/unsup
1005trnet-defaultact/unsup
精选
VLANTypeSAIDMTUParentRingNoBridgeNoStpBrdgModeTrans1Trans2
--------------------------------------------------------------------
1enet1000011500-----00
2enet1000021500-----00
10enet1000101500-----00
20enet1000201500-----00
30enet1000301500-----00
40enet1000401500-----00
50enet1000501500-----00
60enet1000601500-----00
70enet1000701500-----00
80enet1000801500-----00
100enet1001001500-----00
110enet1001101500-----00
120enet1001201500-----00
150enet1001501500-----00
160enet1001601500-----00
1002fddi1010021500-----00
D-2960-3
##配置这台交换机的管理IP
D-2960-3(config)#intvlan1#管理ip地址我们配置在vlan1上
D-2960-3(config-if)#ipaddress192.168.113.222255.255.255.0#设置实际的ip地址
D-2960-3(config-if)#exit
D-2960-3(config)#ipdefault-gateway192.168.113.254
#设置这台交换机的网关,此地址即为核心交换机vlan1的地址。
D-2960-3(config)#end
D-2960-3#shrun#验证一下完整的配置。
Buildingconfiguration...
Currentconfiguration:2087bytes
!
version12.2
norvicepad
rvicetimestampsdebuguptime
rvicetimestampsloguptime
rvicepassword-encryption
!
hostnameD-2960-3
!
enablepassword712090F1817
!
noaaanew-model
精选
systemmturouting1500
ipsubnet-zero
!
nofileverifyauto
spanning-treemodepvst
spanning-treeextendsystem-id
!
vlaninternalallocationpolicyascending
!
interfaceFastEthernet0/1
!
interfaceFastEthernet0/2
!
interfaceFastEthernet0/3
!
(省略……)
interfaceFastEthernet0/45
!
interfaceFastEthernet0/46
!
interfaceFastEthernet0/47
!
interfaceFastEthernet0/48
!
interfaceGigabitEthernet0/1
!
interfaceGigabitEthernet0/2
!
interfaceVlan1
ipaddress192.168.113.222255.255.255.0
noiproute-cache
!
ipdefault-gateway192.168.113.254
iphttprver
!
control-plane
!
!
linecon0
password712090F1817
linevty04
password712090F1817
login
linevty515
精选
login
!
end
D-2960-3
#5、配置交换机的路由功能
说明:只有在三层交换机上才有路由功能,其他的二层接入交换机要想在不同的vlan
之间传送数据需要通过trunk口到核心交换机上进行完路由交换后才可以。
TEST(config)#iprouting#使能三层交换机的路由功能,默认是关闭的
TEST(config)#iproute0.0.0.00.0.0.0172.16.0.1
#配置交换机的默认路由,也就是总的出口路由。
TEST(config)#end#退出验证一下刚才的配置
TEST#shiprouet
Codes:C-connected,S-static,R-RIP,M-mobile,B-BGP
D-EIGRP,EX-EIGRPexternal,O-OSPF,IA-OSPFinterarea
N1-OSPFNSSAexternaltype1,N2-OSPFNSSAexternaltype2
E1-OSPFexternaltype1,E2-OSPFexternaltype2,E-EGP
i-IS-IS,su-IS-ISsummary,L1-IS-ISlevel-1,L2-IS-ISlevel-2
ia-IS-ISinterarea,*-candidatedefault,U-per-urstaticroute
o-ODR,P-periodicdownloadedstaticroute
Gatewayoflastresortis172.16.0.1tonetwork0.0.0.0
C192.168.106.0/24isdirectlyconnected,Vlan60
#这种类型的路由——标志为“C”的路由,为静态直连路由。
C192.168.107.0/24isdirectlyconnected,Vlan70
C192.168.104.0/24isdirectlyconnected,Vlan40
C192.168.105.0/24isdirectlyconnected,Vlan50
C192.168.110.0/24isdirectlyconnected,Vlan100
C192.168.111.0/24isdirectlyconnected,Vlan110
C192.168.108.0/24isdirectlyconnected,Vlan80
172.16.0.0/30issubnetted,1subnets
C172.16.0.0isdirectlyconnected,Vlan2
C192.168.115.0/24isdirectlyconnected,Vlan160
C192.168.113.0/24isdirectlyconnected,Vlan1
C192.168.112.0/24isdirectlyconnected,Vlan120
C192.168.102.0/24isdirectlyconnected,Vlan20
C192.168.103.0/24isdirectlyconnected,Vlan30
精选
C192.168.100.0/24isdirectlyconnected,Vlan150
C192.168.101.0/24isdirectlyconnected,Vlan10
S*0.0.0.0/0[1/0]via172.16.0.1#为配置的默认路由
TEST
#6、配置交换机的DHCP功能
TEST#shipintb#先显示一下所有的端口配置
InterfaceIP-AddressOK?MethodStatusProtocol
FastEthernet1unassignedYESNVRAMdowndown
Vlan1192.168.113.254YESNVRAMupup
Vlan2172.16.0.2YESNVRAMupup
Vlan10192.168.101.254YESNVRAMupup
Vlan20192.168.102.254YESNVRAMupup
Vlan30192.168.103.254YESNVRAMupup
Vlan40192.168.104.254YESNVRAMupup
Vlan50192.168.105.254YESNVRAMupup
Vlan60192.168.106.254YESNVRAMupup
Vlan70192.168.107.254YESNVRAMupup
Vlan80192.168.108.254YESNVRAMupup
Vlan100192.168.110.254YESNVRAMupup
Vlan110192.168.111.254YESNVRAMupup
Vlan120192.168.112.254YESNVRAMupup
#此例中我们想让vlan120提供DHCP功能
Vlan150192.168.100.254YESNVRAMupup
Vlan160192.168.115.254YESNVRAMupup
GigabitEthernet1/1unassignedYESuntupup
GigabitEthernet1/2unassignedYESuntdowndown
GigabitEthernet1/3unassignedYESuntdowndown
GigabitEthernet1/4unassignedYESuntdowndown
GigabitEthernet1/5unassignedYESuntdowndown
GigabitEthernet1/6unassignedYESuntdowndown
GigabitEthernet1/7unassignedYESuntdowndown
GigabitEthernet1/8unassignedYESuntdowndown
GigabitEthernet1/9unassignedYESuntdowndown
GigabitEthernet1/10unassignedYESuntdowndown
GigabitEthernet1/11unassignedYESuntdowndown
GigabitEthernet1/12unassignedYESuntdowndown
GigabitEthernet1/13unassignedYESuntdowndown
GigabitEthernet1/14unassignedYESuntdowndown
GigabitEthernet1/15unassignedYESuntupup
GigabitEthernet1/16unassignedYESuntdowndown
GigabitEthernet1/17unassignedYESuntdowndown
GigabitEthernet1/18unassignedYESuntdowndown
精选
GigabitEthernet1/19unassignedYESuntdowndown
GigabitEthernet1/20unassignedYESuntdowndown
GigabitEthernet3/1unassignedYESuntupup
GigabitEthernet3/2unassignedYESuntupup
GigabitEthernet3/3unassignedYESuntupup
GigabitEthernet3/4unassignedYESuntupup
GigabitEthernet3/5unassignedYESuntupup
GigabitEthernet3/6unassignedYESuntupup
GigabitEthernet3/7unassignedYESuntupup
GigabitEthernet3/8unassignedYESuntupup
TEST
#TEST#conft
Enterconfigurationcommands,hCNTL/Z.
TEST(config)#ipdhcppoolwlan#配置交换机的地址池并命名
TEST(config)#network192.168.112.0255.255.255.0#定义此地址池的网段
TEST(config)#default-router192.168.112.254#定义分发下去的地址的默认网关
TEST(config)#dns-rver202.102.128.68202.102.134.68
#定义分发下去地址的DNS服务器,此处是2个中间用空格分隔。
TEST(config)#ipdhcpexcluded-address192.168.112.200192.168.112.254
#定义保留的ip地址端
TEST(dhcp-config)#end
TEST#shrun
##小结一下:至此所属这个vlan的客户机就可以通过自动获取地址的方式来得到正确的ip、
网关、dns等信息。
7、常用排错命令
TEST#terminalmonitor
#排除网络故障以前,请打开这一命令以便实时的接收到交换机的提示信息。
TEST
#TEST#shrun
#显示所有的配置清单,可将这些配置保存成文本作为交换机的配置备份。
Buildingconfiguration...
Currentconfiguration:9200bytes
!
version12.2
norvicepad
精选
rvicetimestampsdebuguptime
rvicetimestampsloguptime
rvicepassword-encryption
rvicecompress-config
!
hostnameTEST
!
boot-start-marker
bootsystembootflash:
boot-end-marker
!
enablecret5$1$c2Ge$eLS42O.0h04yCn1tDZGsB/
enablepassword71119130A12010E1E122F39
!
noaaanew-model
ipsubnet-zero
ipdhcpexcluded-address192.168.112.200192.168.112.254
ipdhcpexcluded-address192.168.115.200192.168.115.254
!
ipdhcppoolWlan
network192.168.112.0255.255.255.0
default-router192.168.112.254
dns-rver202.102.128.68202.102.134.68
!
ipdhcppoolClient
network192.168.115.0255.255.255.0
default-router192.168.115.254
dns-rver202.102.134.68202.102.128.68
!
ipdhcppooltest
host192.168.112.98255.255.255.0
client-identifier0100.1b77.2fa0.39
default-router192.168.112.254
dns-rver202.102.134.68
!
ipdhcppoollijing
host192.168.112.100255.255.255.0
client-identifier0100.0e35.891b.46
default-router192.168.112.254
dns-rver202.102.128.68202.102.134.68
!
!
nofileverifyauto
精选
errdisablerecoverycauarp-inspection
spanning-treemodepvst
spanning-treeextendsystem-id
powerredundancy-moderedundant
!
!
!
vlaninternalallocationpolicyascending
!
interfaceFastEthernet1
noipaddress
speedauto
duplexauto
!
interfaceGigabitEthernet1/1
switchportaccessvlan2
!
interfaceGigabitEthernet1/2
!
interfaceGigabitEthernet1/3
!
interfaceGigabitEthernet1/4
!
interfaceGigabitEthernet1/5
!
interfaceGigabitEthernet1/6
!
interfaceGigabitEthernet1/7
!
interfaceGigabitEthernet1/8
!
interfaceGigabitEthernet1/9
!
interfaceGigabitEthernet1/10
!
interfaceGigabitEthernet1/11
!
interfaceGigabitEthernet1/12
!
interfaceGigabitEthernet1/13
switchporttrunkencapsulationdot1q
switchportmodetrunk
!
interfaceGigabitEthernet1/14
精选
!
interfaceGigabitEthernet1/15
switchporttrunkencapsulationdot1q
switchportmodetrunk
!
interfaceGigabitEthernet1/16
!
interfaceGigabitEthernet1/17
!
interfaceGigabitEthernet1/18
!
interfaceGigabitEthernet1/19
!
interfaceGigabitEthernet1/20
!
interfaceGigabitEthernet3/1
switchportaccessvlan150
nocdpenable
!
interfaceGigabitEthernet3/2
switchportaccessvlan150
!
interfaceGigabitEthernet3/3
switchportaccessvlan150
!
interfaceGigabitEthernet3/4
switchportaccessvlan150
!
interfaceGigabitEthernet3/5
switchportaccessvlan150
!
interfaceGigabitEthernet3/6
switchportaccessvlan150
!
interfaceGigabitEthernet3/7
switchportaccessvlan150
!
interfaceGigabitEthernet3/8
switchportaccessvlan150
!
interfaceGigabitEthernet3/9
switchportaccessvlan10
!
interfaceGigabitEthernet3/10
精选
switchportaccessvlan10
!
interfaceGigabitEthernet3/11
switchportaccessvlan160
!
interfaceGigabitEthernet3/12
!
interfaceGigabitEthernet3/13
!
interfaceGigabitEthernet3/14
!
interfaceGigabitEthernet3/15
switchportaccessvlan160
!
interfaceGigabitEthernet3/16
!
interfaceGigabitEthernet3/17
switchporttrunkencapsulationdot1q
switchportmodetrunk
!
interfaceGigabitEthernet3/18
switchportaccessvlan50
switchportmodeaccess
!
interfaceGigabitEthernet3/19
switchportaccessvlan20
switchportmodeaccess
nocdpenable
!
interfaceGigabitEthernet3/20
switchporttrunkencapsulationdot1q
switchportmodetrunk
iparpinspectiontrust
!
interfaceGigabitEthernet3/21
switchporttrunkencapsulationdot1q
switchportmodetrunk
!
interfaceGigabitEthernet3/22
switchporttrunkencapsulationdot1q
switchportmodetrunk
!
interfaceGigabitEthernet3/23
switchporttrunkencapsulationdot1q
精选
switchportmodetrunk
!
interfaceGigabitEthernet3/24
switchporttrunkencapsulationdot1q
switchportmodetrunk
!
interfaceVlan1
ipaddress192.168.113.254255.255.255.0
iphelper-address192.168.100.100
noipredirects
!
interfaceVlan2
ipaddress172.16.0.2255.255.255.252
iphelper-address192.168.100.100
noipredirects
noipunreachables
!
interfaceVlan10
ipaddress192.168.101.254255.255.255.0
iphelper-address192.168.100.100
noipredirects
!
interfaceVlan20
ipaddress192.168.102.254255.255.255.0
iphelper-address192.168.100.100
noipredirects
!
interfaceVlan30
ipaddress192.168.103.254255.255.255.0
iphelper-address192.168.100.100
noipredirects
!
interfaceVlan40
ipaddress192.168.104.254255.255.255.0
iphelper-address192.168.100.100
noipredirects
!
interfaceVlan50
ipaddress192.168.105.254255.255.255.0
iphelper-address192.168.100.100
noipredirects
!
interfaceVlan60
ipaddress192.168.106.254255.255.255.0
精选
iphelper-address192.168.100.100
noipredirects
!
interfaceVlan70
ipaddress192.168.107.254255.255.255.0
iphelper-address192.168.100.100
noipredirects
!
interfaceVlan80
ipaddress192.168.108.254255.255.255.0
iphelper-address192.168.100.100
noipredirects
!
interfaceVlan100
ipaddress192.168.110.254255.255.255.0
iphelper-address192.168.100.100
noipredirects
!
interfaceVlan110
ipaddress192.168.111.254255.255.255.0
iphelper-address192.168.100.100
!
interfaceVlan120
ipaddress192.168.112.254255.255.255.0
ipaccess-group101in
iphelper-address192.168.100.100
!
interfaceVlan150
ipaddress192.168.100.254255.255.255.0
iphelper-address192.168.100.100
noipredirects
!
interfaceVlan160
ipaddress192.168.115.254255.255.255.0
ipaccess-group100in
ipaccess-group100out
iphelper-address192.168.100.100
noipredirects
!
iproute0.0.0.00.0.0.0172.16.0.1
iphttprver
!
!
access-list100denyip192.168.115.00.0.0.255192.168.101.00.0.0.255
精选
access-list100denyip192.168.115.00.0.0.255192.168.102.00.0.0.255
access-list100denyip192.168.115.00.0.0.255192.168.103.00.0.0.255
access-list100denyip192.168.115.00.0.0.255192.168.104.00.0.0.255
access-list100denyip192.168.115.00.0.0.255192.168.105.00.0.0.255
access-list100denyip192.168.115.00.0.0.255192.168.106.00.0.0.255
access-list100denyip192.168.115.00.0.0.255192.168.107.00.0.0.255
access-list100denyip192.168.115.00.0.0.255192.168.108.00.0.0.255
access-list100denyip192.168.115.00.0.0.255192.168.110.00.0.0.255
access-list100denyip192.168.115.00.0.0.255192.168.111.00.0.0.255
access-list100denyip192.168.115.00.0.0.255192.168.112.00.0.0.255
access-list100denyip192.168.115.00.0.0.255192.168.113.00.0.0.255
access-list100denyip192.168.115.00.0.0.255192.168.100.00.0.0.255
access-list100permitipanyany
access-list101denyip192.168.112.00.0.0.255192.168.101.00.0.0.255
access-list101denyip192.168.112.00.0.0.255192.168.102.00.0.0.255
access-list101denyip192.168.112.00.0.0.255192.168.103.00.0.0.255
access-list101denyip192.168.112.00.0.0.255192.168.104.00.0.0.255
access-list101denyip192.168.112.00.0.0.255192.168.105.00.0.0.255
access-list101denyip192.168.112.00.0.0.255192.168.106.00.0.0.255
access-list101denyip192.168.112.00.0.0.255192.168.107.00.0.0.255
access-list101denyip192.168.112.00.0.0.255192.168.108.00.0.0.255
access-list101denyip192.168.112.00.0.0.255192.168.110.00.0.0.255
access-list101denyip192.168.112.00.0.0.255192.168.111.00.0.0.255
access-list101denyip192.168.112.00.0.0.255192.168.113.00.0.0.255
access-list101permitiphost192.168.112.100host192.168.100.103
access-list101permitiphost192.168.112.98192.168.100.00.0.0.255
access-list101denyip192.168.112.00.0.0.255192.168.100.00.0.0.255
access-list101permitipanyany
!
snmp-rvercommunitypjoeRW
snmp-rverenabletrapssnmpauthenticationlinkdownlinkupcoldstartwarmstart
snmp-rverenabletrapstty
snmp-rverenabletrapsvtp
snmp-rverenabletrapsvlancreate
snmp-rverenabletrapsvlandelete
snmp-rverenabletrapsstpx
snmp-rverenabletrapsrf
snmp-rverenabletrapsport-curity
snmp-rverenabletrapsconfig
snmp-rverenabletrapntity
snmp-rverenabletrapscputhreshold
snmp-rverenabletrapscopy-config
snmp-rverenabletrapsfru-ctrl
snmp-rverenabletrapsflashinrtionremoval
精选
snmp-rverenabletrapssyslog
snmp-rverenabletrapsbridge
snmp-rverenabletrapnvmonfanshutdownsupplytemperaturestatus
snmp-rverenabletrapshsrp
snmp-rverenabletrapsbgp
snmp-rverenabletrapsospfstate-change
snmp-rverenabletrapsospferrors
snmp-rverenabletrapsospfretransmit
snmp-rverenabletrapsospflsa
snmp-rverenabletrapsospfcisco-specificstate-change
snmp-rverenabletrapsospfcisco-specificerrors
snmp-rverenabletrapsospfcisco-specificretransmit
snmp-rverenabletrapsospfcisco-specificlsa
snmp-rverenabletrapspimneighbor-changerp-mapping-changeinvalid-pim-message
snmp-rverenabletrapsipmulticast
snmp-rverenabletrapsmsdp
snmp-rverenabletrapsrtr
snmp-rverenabletrapsvlan-membership
snmp-rverhost192.168.100.105pjoe
!
!
linecon0
password70E1419245E
stopbits1
linevty04
password7C245E580C0B
login
!
!
end
TEST
#TEST
#TEST
#TEST#shipintb#显示所有端口的状态
InterfaceIP-AddressOK?MethodStatusProtocol
FastEthernet1unassignedYESNVRAMdowndown
Vlan1192.168.113.254YESNVRAMupup
Vlan2172.16.0.2YESNVRAMupup
Vlan10192.168.101.254YESNVRAMupup
Vlan20192.168.102.254YESNVRAMupup
Vlan30192.168.103.254YESNVRAMupup
Vlan40192.168.104.254YESNVRAMupup
Vlan50192.168.105.254YESNVRAMupup
精选
Vlan60192.168.106.254YESNVRAMupup
Vlan70192.168.107.254YESNVRAMupup
Vlan80192.168.108.254YESNVRAMupup
Vlan100192.168.110.254YESNVRAMupup
Vlan110192.168.111.254YESNVRAMupup
Vlan120192.168.112.254YESNVRAMupup
Vlan150192.168.100.254YESNVRAMupup
Vlan160192.168.115.254YESNVRAMupup
GigabitEthernet1/1unassignedYESuntupup
GigabitEthernet1/2unassignedYESuntdowndown
GigabitEthernet1/3unassignedYESuntdowndown
GigabitEthernet1/4unassignedYESuntdowndown
GigabitEthernet1/5unassignedYESuntdowndown
GigabitEthernet1/6unassignedYESuntdowndown
GigabitEthernet1/7unassignedYESuntdowndown
GigabitEthernet1/8unassignedYESuntdowndown
GigabitEthernet1/9unassignedYESuntdowndown
GigabitEthernet1/10unassignedYESuntdowndown
GigabitEthernet1/11unassignedYESuntdowndown
GigabitEthernet1/12unassignedYESuntdowndown
GigabitEthernet1/13unassignedYESuntdowndown
GigabitEthernet1/14unassignedYESuntdowndown
GigabitEthernet1/15unassignedYESuntupup
GigabitEthernet1/16unassignedYESuntdowndown
GigabitEthernet1/17unassignedYESuntdowndown
GigabitEthernet1/18unassignedYESuntdowndown
GigabitEthernet1/19unassignedYESuntdowndown
GigabitEthernet1/20unassignedYESuntdowndown
GigabitEthernet3/1unassignedYESuntupup
GigabitEthernet3/2unassignedYESuntupup
GigabitEthernet3/3unassignedYESuntupup
GigabitEthernet3/4unassignedYESuntupup
GigabitEthernet3/5unassignedYESuntupup
GigabitEthernet3/6unassignedYESuntupup
GigabitEthernet3/7unassignedYESuntupup
GigabitEthernet3/8unassignedYESuntupup
GigabitEthernet3/9unassignedYESuntdowndown
GigabitEthernet3/10unassignedYESuntdowndown
GigabitEthernet3/11unassignedYESuntdowndown
GigabitEthernet3/12unassignedYESuntdowndown
GigabitEthernet3/13unassignedYESuntdowndown
GigabitEthernet3/14unassignedYESuntdowndown
GigabitEthernet3/15unassignedYESuntdowndown
GigabitEthernet3/16unassignedYESuntdowndown
精选
GigabitEthernet3/17unassignedYESuntupup
GigabitEthernet3/18unassignedYESuntupup
GigabitEthernet3/19unassignedYESuntupup
GigabitEthernet3/20unassignedYESuntupup
GigabitEthernet3/21unassignedYESuntupup
GigabitEthernet3/22unassignedYESuntupup
GigabitEthernet3/23unassignedYESuntupup
GigabitEthernet3/24unassignedYESuntupup
TEST
#TEST
#TEST#shvlan#显示所有的vlan信息
VLANNameStatusPorts
----------------------------------------------------------------------------
1defaultactiveGi1/2,Gi1/3,Gi1/4,Gi1/5,Gi1/6,Gi1/7,
Gi1/8,Gi1/9,Gi1/10,Gi1/11,Gi1/12,Gi1/13,Gi1/14,Gi1/16,Gi1/17,Gi1/18,Gi1/19,Gi1/20,
Gi3/12,Gi3/13,Gi3/14,Gi3/16
2firewallactiveGi1/1
10EngineeringactiveGi3/9,Gi3/10
20ProcurementactiveGi3/19
30QAQCactive
40Operationactive
50YardactiveGi3/18
60BMactive
70HRADactive
80Facilityactive
100Financeactive
110GOactive
120Wlanactive
150ServeractiveGi3/1,Gi3/2,Gi3/3,Gi3/4,Gi3/5,Gi3/6,
Gi3/7,Gi3/8
160ClientactiveGi3/11,Gi3/15
1002fddi-defaultact/unsup
1003token-ring-defaultact/unsup
1004fddinet-defaultact/unsup
1005trnet-defaultact/unsup
VLANTypeSAIDMTUParentRingNoBridgeNoStpBrdgModeTrans1Trans2
--------------------------------------------------------------------
1enet1000011500-----00
2enet1000021500-----00
10enet1000101500-----00
20enet1000201500-----00
30enet1000301500-----00
精选
40enet1000401500-----00
50enet1000501500-----00
60enet1000601500-----00
70enet1000701500-----00
80enet1000801500-----00
100enet1001001500-----00
110enet1001101500-----00
120enet1001201500-----00
150enet1001501500-----00
160enet1001601500-----00
1002fddi1010021500-----00
TEST
#TEST#shvtpsta#显示vtp协议的相关配置
VTPVersion:2
ConfigurationRevision:23
MaximumVLANssupportedlocally:1005
NumberofexistingVLANs:19
VTPOperatingMode:Server
VTPDomainName:pjoe
VTPPruningMode:Disabled
VTPV2Mode:Disabled
VTPTrapsGeneration:Enabled
MD5digest:0xEC0x300xEF0x6F0xA50x9A0x390x7B
Configurationlastmodifiedby192.168.113.254at12-3-0722:58:54
LocalupdaterIDis192.168.113.254oninterfaceVl1(lowestnumberedVLANinterfacefound)
TEST
#TEST
#TEST
#TEST
#TEST#shintgi1/2#显示具体物理接口的信息
GigabitEthernet1/2isdown,lineprotocolisdown(notconnect)
HardwareisGigabitEthernetPort,addressis001a.6db4.a3c1(bia001a.6db4.a3c1)
MTU1500bytes,BW1000000Kbit,DLY10uc,
reliability255/255,txload1/255,rxload1/255
EncapsulationARPA,loopbacknott
Keepalivet(10c)
Auto-duplex,Auto-speed,linktypeisauto,mediatypeis10/100/1000-TX
inputflow-controlisoff,outputflow-controlisoff
ARPtype:ARPA,ARPTimeout04:00:00
Lastinputnever,outputnever,outputhangnever
Lastclearingof"showinterface"countersnever
Inputqueue:0/2000/0/0(size/max/drops/flushes);Totaloutputdrops:0
精选
Queueingstrategy:fifo
Outputqueue:0/40(size/max)
5minuteinputrate0bits/c,0packets/c
5minuteoutputrate0bits/c,0packets/c
0packetsinput,0bytes,0nobuffer
Received0broadcasts(0multicast)
0runts,0giants,0throttles
0inputerrors,0CRC,0frame,0overrun,0ignored
0inputpacketswithdribbleconditiondetected
0packetsoutput,0bytes,0underruns
0outputerrors,0collisions,0interfacerets
0babbles,0latecollision,0deferred
0lostcarrier,0nocarrier
0outputbufferfailures,0outputbuffersswappedout
TEST
#TEST
#TEST#shiproute#显示这台交换机的所有路由信息
Codes:C-connected,S-static,R-RIP,M-mobile,B-BGP
D-EIGRP,EX-EIGRPexternal,O-OSPF,IA-OSPFinterarea
N1-OSPFNSSAexternaltype1,N2-OSPFNSSAexternaltype2
E1-OSPFexternaltype1,E2-OSPFexternaltype2,E-EGP
i-IS-IS,su-IS-ISsummary,L1-IS-ISlevel-1,L2-IS-ISlevel-2
ia-IS-ISinterarea,*-candidatedefault,U-per-urstaticroute
o-ODR,P-periodicdownloadedstaticroute
Gatewayoflastresortis172.16.0.1tonetwork0.0.0.0
C192.168.106.0/24isdirectlyconnected,Vlan60
C192.168.107.0/24isdirectlyconnected,Vlan70
C192.168.104.0/24isdirectlyconnected,Vlan40
C192.168.105.0/24isdirectlyconnected,Vlan50
C192.168.110.0/24isdirectlyconnected,Vlan100
C192.168.111.0/24isdirectlyconnected,Vlan110
C192.168.108.0/24isdirectlyconnected,Vlan80
172.16.0.0/30issubnetted,1subnets
C172.16.0.0isdirectlyconnected,Vlan2
C192.168.115.0/24isdirectlyconnected,Vlan160
C192.168.113.0/24isdirectlyconnected,Vlan1
C192.168.112.0/24isdirectlyconnected,Vlan120
C192.168.102.0/24isdirectlyconnected,Vlan20
C192.168.103.0/24isdirectlyconnected,Vlan30
C192.168.100.0/24isdirectlyconnected,Vlan150
C192.168.101.0/24isdirectlyconnected,Vlan10
S*0.0.0.0/0[1/0]via172.16.0.1
精选
TEST
#TEST
#TEST
#TEST#shprocesscpu#显示交换机的cpu利用率。当前是正常的。
CPUutilizationforfiveconds:11%/0%;oneminute:15%;fiveminutes:14%
PIDRuntime(ms)InvokeduSecs5Sec1Min5MinTTYProcess
14331210.00%0.00%0.00%0ChunkManager
23610715700.00%0.00%0.00%0LoadMeter
3761604750.00%0.00%0.00%0SpanTreeHelper
40100.00%0.00%0.00%0DeferredEvents
56793688133383520.00%0.11%0.11%0Checkheaps
60400.00%0.00%0.00%0PoolManager
70200.00%0.00%0.00%0Timers
80200.00%0.00%0.00%0SerialBackgroun
90100.00%0.00%0.00%0AAA_SERVER_DEADT
100200.00%0.00%0.00%0AAAhigh-capacit
110100.00%0.00%0.00%0PolicyManager
124893100.00%0.00%0.00%0IPCDynamicCach
130100.00%0.00%0.00%0IPCZoneManager
00.00%0.00%0.00%0IPCPeriodicTim
00.00%0.00%0.00%0IPCDeferredPor
160100.00%0.00%0.00%0IPCSeatManager
170100.00%0.00%0.00%0IFSAgentManage
18880.00%0.00%0.00%0ARPInput
.00%0.00%0.00%0EntityMIBAPI
200100.00%0.00%0.00%0SERIALA'detect
20.00%0.00%0.00%0DynamicARPInsp
22.00%0.00%0.00%0HCCounterTimer
230100.00%0.00%0.00%0CriticalBkgnd
242049969120.00%0.00%0.00%0NetBackground
2506100.00%0.00%0.00%0Logger
262.00%0.00%0.00%0TTYBackground
2758453657210.00%0.00%0.00%0Per-SecondJobs
28286590.00%0.04%0.00%0Per-minuteJobs
298227772422047441944.07%4.33%4.33%0Cat4kMgmtHiPri
38775612545.91%8.93%8.04%0Cat4kMgmtLoPri
3.00%0.00%0.00%0GaliosReschedul
3201100.00%0.00%0.00%0IOSACLHelper
330200.00%0.00%0.00%0NAMManager
34242120000.00%0.00%0.00%0rftask
3505900.00%0.00%0.00%0BACKCHECK
3610.00%0.00%0.00%0NetInput
3710.00%0.01%0.00%0Computeloadavg
380100.00%0.00%0.00%0chkptmessageha
精选
390200.00%0.00%0.00%0cpf_process_msg_
400100.00%0.00%0.00%0cpf_process_ipcQ
4101200.00%0.00%0.00%0AggMgrProcess
420100.00%0.00%0.00%0SFF8472
430400.00%0.00%0.00%0Collectionproce
PIDRuntime(ms)InvokeduSecs5Sec1Min5MinTTYProcess
440300.00%0.00%0.00%0CEFswitchingba
450200.00%0.00%0.00%0AAADictionaryR
460200.00%0.00%0.00%0AAAServer
470100.00%0.00%0.00%0AAAACCTProc
480100.00%0.00%0.00%0ACCTPeriodicPr
49379548.79%0.73%0.73%0SpanningTree
5200.00%0.01%0.00%0DTPProtocol
5185358000.00%0.00%0.00%0Ethchnl
5222453580200.00%0.00%0.00%0UDLD
534481500.00%0.00%0.00%0DHCPSnooping
544893000.00%0.00%0.00%0Port-Security
55219216.23%0.19%0.20%0IPInput
560100.00%0.00%0.00%0ICMPeventhandl
57159.00%0.02%0.00%0CDPProtocol
590300.00%0.00%0.00%0SNMPTimers
6.00%0.00%0.00%0CEFbackgroundp
620200.00%0.00%0.00%0XDRmcast
630100.00%0.00%0.00%0IPCLCMessageH
640100.00%0.00%0.00%0XDRRPPingBack
650449300.00%0.00%0.00%0XDRRPbackgroun
660100.00%0.00%0.00%0XDRRPTestBack
670100.00%0.00%0.00%0IPIRDP
689692813686110.07%0.07%0.07%0CEF:IPv4proces
6903700.00%0.00%0.00%0ADJbackground
7.00%0.00%0.00%0L2MM
710100.00%0.00%0.00%0MRD
721208981330.00%0.00%0.00%0IGMPSN
730100.00%0.00%0.00%0IGMPSN-HA
740100.00%0.00%0.00%0SocketTimers
750200.00%0.00%0.00%0L2TRACE
SERVER
761762477470.00%0.00%0.00%0TCPTimer
7712363330.00%0.00%0.00%0TCPProtocols
784230.00%0.02%0.00%0HTTPCORE
790100.00%0.00%0.00%0CHKPTEXAMPLE
800100.00%0.00%0.00%0CHKPTDevTest
810200.00%0.00%0.00%0ATIP_UDP_TSK
820100.00%0.00%0.00%0DHCPSnooping
精选
HA
830100.00%0.00%0.00%0ProbeInput
840100.00%0.00%0.00%0RARPInput
8523496788632970.00%0.00%0.00%0DHCPDReceive
8688911590.00%0.00%0.00%0IPBackground
8752893950.00%0.00%0.00%0IPRIBUpdate
880100.00%0.00%0.00%0COPS
890670000.00%0.00%0.00%0ClusterL2
9005358200.00%0.00%0.00%0ClusterRARP
PIDRuntime(ms)InvokeduSecs5Sec1Min5MinTTYProcess
910200.00%0.00%0.00%0LOCALAAA
920200.00%0.00%0.00%0AAACachedServe
930200.00%0.00%0.00%0TPLUS
940300.00%0.00%0.00%0RADIUSTESTCMD
950200.00%0.00%0.00%0AAASENDSTOPEV
9636.00%0.01%0.00%0PMCallback
9758017887320.00%0.00%0.00%0VLANManager
980446500.00%0.00%0.00%0DHCPDTimer
994123330.00%0.00%0.00%0VTPTrapProcess
1000200.00%0.00%0.00%0DHCPSecurityHe
1010100.00%0.00%0.00%0DiagCard1/-1
1020100.00%0.00%0.00%0DiagCard3/-1
1030100.00%0.00%0.00%0SyslogTraps
1040200.00%0.00%0.00%0VTPMIBEDITBUFF
1050500.00%0.00%0.00%0SPANswitch
1.00%0.00%0.00%0IPSNMP
1070700.00%0.00%0.00%0PDUDISPATCHER
1080700.00%0.00%0.00%0SNMPENGINE
1090100.00%0.00%0.00%0SNMPConfCopyPro
11.00%0.00%0.00%0SNMPTraps
1111.00%0.00%0.00%0DHCPDDataba
400.00%0.00%0.00%0Systempolling
5230.39%0.55%0.37%2VirtualExec
TEST
#TEST
#TEST
#TEST#reloa
TEST#reload#这条命令可重新启动交换机
Y#是否保存
回车#确定
TEST
#TEST#shver#显示当前设备的版本信息
CiscoIOSSoftware,Catalyst4000L3SwitchSoftware(cat4000-I9S-M),Version12.2(25)EWA8,
RELEASESOFTWARE(fc1)
精选
TechnicalSupport:/techsupport
Copyright(c)1986-2007byCiscoSystems,Inc.
CompiledWed24-Jan-0714:38bypwade
Imagetext-ba:0x10000000,data-ba:0x114EECF0
ROM:12.2(20r)EW1
DagobahRevision226,SwampRevision4
TESTuptimeis6days,4hours,50minutes
SystemreturnedtoROMbypower-on
Systemimagefileis"bootflash:"
ciscoWS-C4503(MPC8245)processor(revision4)with262144Kbytesofmemory.
ProcessorboardIDFOX104406TX
MPC8245CPUat267Mhz,SupervisorII+TS
LastretfromPowerUp
15VirtualEthernetinterfaces
44GigabitEthernetinterfaces
511Kbytesofnon-volatileconfigurationmemory.
Configurationregisteris0x2102
TEST#
本文发布于:2023-03-11 00:48:04,感谢您对本站的认可!
本文链接:https://www.wtabcd.cn/fanwen/zuowen/1678466885209212.html
版权声明:本站内容均来自互联网,仅供演示用,请勿用于商业和其他非法用途。如果侵犯了您的权益请与我们联系,我们将在24小时内删除。
本文word下载地址:思科交换机配置.doc
本文 PDF 下载地址:思科交换机配置.pdf
留言与评论(共有 0 条评论) |