思科交换机配置

更新时间:2023-03-11 00:48:05 阅读: 评论:0

冬天乌龟怎么养-分担痛苦

思科交换机配置
2023年3月11日发(作者:每天喝柠檬水的好处)

思科交换机基本配置实例讲解

目录

1、基本概念介绍....................................................................................................................................1

2、密码、登陆等基本配置....................................................................................................................1

3、CISCO设备端口配置详解..............................................................................................................7

4、VLAN的规划及配置......................................................................................................................12

4.1核心交换机的相关配置.............................................................................................................12

4.2接入交换机的相关配置.............................................................................................................24

5、配置交换机的路由功能..................................................................................................................29

6、配置交换机的DHCP功能.............................................................................................................30

7、常用排错命令..................................................................................................................................31

1、基本概念介绍

IOS:互联网操作系统,也就是交换机和路由器中用的操作系统

VLAN:虚拟lan

VTP:VLANTRUNKPROTOCOL

DHCP:动态主机配置协议

ACL:访问控制列表

三层交换机:具有三层路由转发能力的交换机

本教程中“#”后的蓝色文字为注释内容。

2、密码、登陆等基本配置

本节介绍的内容为cisco路由器或者交换机的基本配置,在目前版本的cisco交换机或

路由器上的这些命令是通用的。本教程用的是cisco的模拟器做的介绍,一些具体的端口显

示或许与你们实际的设备不符,但这并不影响基本配置命令的执行。

Cisco3640(R4700)processor(revision0xFF)with124928K/6144Kbytesofmemory.

ProcessorboardID00000000

R4700CPUat100MHz,Implementation33,Rev1.2

2Ethernetinterfaces

8Serialinterfaces

DRAMconfigurationis64bitswidewithparityenabled.

125KbytesofNVRAM.

8192KbytesofprocessorboardSystemflash(Read/Write)

---SystemConfigurationDialog---

Wouldyouliketoentertheinitialconfigurationdialog?[yes/no]:n

#此处我们选择no,不进入他的初始化配置向导

PressRETURNtogetstarted!

#选择no以后,提示你按回车键开始,此处我们需要按回车键

*Mar100:43:56.591:%IP-5-WEBINST_KILL:TerminatingDNSprocess

*Mar100:43:58.379:%SYS-5-RESTART:Systemrestarted--

CiscoIOSSoftware,3600Software(C3640-JK9O3S-M),Version12.3(14)T7,RELEASE

SOFTWARE(fc2)

精选

TechnicalSupport:/techsupport

Copyright(c)1986-2006byCiscoSystems,Inc.

CompiledWed22-Mar-0621:46bypwade

*Mar100:43:58.411:%SNMP-5-COLDSTART:SNMPagentonhostRouterisundergoinga

coldstart

Router>

#等显示稳定后,出现最初的提示符,注意提示符是“>”,目前所处的状态称为用户模式。

Router>用户模式

Router>

Router>en

#如果在当前状态下没有重复的命令,我们可以用“TAB”键来补齐这条命令,主要目的是

为了便于阅读

Router>enable进入特权模式

#从用户模式(urmode)进入到特权模式(execmode),注意提示符的变化,提示符变为“#”

Router#conft

Router#configureterminal进入全局模式

(说明:#在特权模式下输入configureterminal进入全局配置模式(globalconfigurationmode),

在这之下输入的命令叫做全局命令,一旦输入,将对整个router产生即时影响。如下,注意提示

符的变化:)

Router(config)#exit#请注意提示符发生了改变,当前的模式据叫做全局配置模式。

Router#conf

*Mar100:44:26.491:%SYS-5-CONFIG_I:Configuredfromconsolebyconsolet#在输入命

令的过程中,IOS会出现一些即时提示。

Enterconfigurationcommands,hCNTL/Z.

Router(config)#exit#退出当前的全局配置模式的命令是exit

Router#conft#重新进入到全局配置模式

Enterconfigurationcommands,hCNTL/Z.

Router(config)

#*Mar100:44:35.591:%SYS-5-CONFIG_I:Configuredfromconsolebyconsolehos

#这行是路由器(交换机)出现的一些即时提示。

Router(config)#hostnametest

#这条命令用来更改当前设备的名字(名字中可包含设备的楼层、用途等信息),主要是为

了将来便于区分设备。

test(config)

##回车后我们就会发现,但前的设备的名字已经发生了改变,变成了test了。

test(config)#enablepass

#这条命令用来配置设备的登陆密码,用tab键补齐后,再下一行显示完整命令。

test(config)#enablepasswordcisco#我们输入这台设备的登陆密码为cisco

test(config)#end#我们退回到全局配置模式,校验一下刚才输入的密码

test#shr

#此命令的完整写法是showrunning-start,此处的shr用的是省略的写法,因无其他重复的

命令所以可以被执行。

Buildingconfiguration...

精选

Currentconfiguration:1559bytes

!

version12.3

rvicetimestampsdebugdatetimemc

rvicetimestampslogdatetimemc

norvicepassword-encryption

!

hostnametest#注意此处显示的是我们配置的设备的名字

!

boot-start-marker

boot-end-marker

!

enablepasswordcisco

#此处显示的是刚才我们配置的enable密码,注意此时是用明文显示的,有点不安全。

!

noaaanew-model

!

resourcepolicy

!

memory-sizeiomem5

ipsubnet-zero

!

#到这一行其实并未全部显示完配置的内容,我们可以按键盘上的任意键来终止继续显示。

在显示的过程中通过按回车键可以逐行显示,按空格键可以一页一页的显示。这些操作可在

实际的设备中体会。

test#conft#重新进入到全局配置模式

test(config)#rvicepass

test(config)#rvicepassword-encryption#利用这条命令给密码加密显示。

test(config)#end

test#shr#退出到全局配置模式后,验证刚才的配置。

Buildingconfiguration...

Currentconfiguration:1565bytes

!

version12.3

rvicetimestampsdebugdatetimemc

rvicetimestampslogdatetimemc

rvicepassword-encryption

!

hostnametest

!

精选

boot-start-marker

boot-end-marker

!

enablepassword7070C285F4D06cisco

#注意此处刚才明文显示的密码已经变成加密显示了,这样从一定程度上保证了密码的安

全。

!

noaaanew-model

!

resourcepolicy

!

memory-sizeiomem5

ipsubnet-zero

!

#验证完毕后按任何一个键中断显示,下面的内容说明终端登陆密码的配置。

test#conft

Enterconfigurationcommands,hCNTL/Z.

test(config)#norvicepassword-encryption

#可利用这条命令(前面加no)来去掉密码加密功能,cisco的所有命令都可以通过这种方

式来禁止。

test(config)#linecon

test(config)#lineconsole0#利用这条命令来配置用超级终端登陆时的一些参数。

test(config-line)#pass

test(config-line)#passwordcisco#添加密码,此处我们配置的密码为cisco

test(config-line)#loggi

test(config-line)#logging?

#在任何情况下如果你忘记了命令的相关参数可以用?来获得提示和帮助

synchronousSynchronizedmessageoutput

test(config-line)#loggingsy

test(config-line)#loggingsynchronous

#在我们进行配置时,IOS会产生一些即时的提示信息,而这些信息会冲乱我们的光标显示,

用这条命令可以将光标规矩在下一行,即使出现了一些即时的提示。

test(config-line)#exit#退出当前console口的参数配置

test(config)#linevt?#telnet登陆时相关参数的配置,此处用了?来寻求提示。

<0-134>FirstLinenumber

auxAuxiliaryline

consolePrimaryterminalline

ttyTerminalcontroller

vtyVirtualterminal

x/ySlot/PortforModems

test(config)#linevty04

精选

#我们配置虚拟终端的0到4,也就是同时允许5个用户可以telnet到这台设备上来。

test(config-line)#pass

test(config-line)#passwordcisco

#我们配置telnet时的密码为cisco,如果此处我们不设置密码,那么用telnet来登陆的时候

并不会以空密码登陆,而是会给你提示说:相关密码没有设置,禁止登陆。所以我们为了能

远程telnet到这台设备,此处的密码一定要设置好。

test(config-line)#login#这条命令是允许通过telnet来登录

test(config-line)#exit#退出当前配置模式到全局配置模式。

test(config)

#test(config)

#test#confs

#我们在做配置的时候,会出现输入错误的情况,在这种情况下ios会以为你输入的是一个

域名

Translating"s"...domainrver(255.255.255.255)

#那么ios会做长时间的搜寻,试图找到这个域名对应的ip地址.......

Translating"s"...domainrver(255.255.255.255)

#这段时间是比较长的,那么我们如何禁用它的这个功能呢?

%Unknowncommandorcomputername,orunabletofindcomputeraddress

test#conft

Enterconfigurationcommands,hCNTL/Z.

test(config)#noipdomain-lookup#在全局配置模式下,将ip域名的搜寻功能关闭就可以了。

test(config)#end

test#conf

*Mar101:40:46.895:%SYS-5-CONFIG_I:Configuredfromconsolebyconsole

test#confx#将上述功能关闭以后,再有输入错误的情况会直接提示你输入错误。

^

%Invalidinputdetectedat'^'marker.

test

#test(config)#ipdomain-name202.102.128.68

#如果有必要将设备配置上DNS功能的话就用这条命令。

###基本配置完毕后我们验证一下所有的配置

###test#shrun

Buildingconfiguration...

Currentconfiguration:1693bytes

!

version12.3

rvicetimestampsdebugdatetimemc

rvicetimestampslogdatetimemc

rvicepassword-encryption#密码加密显示功能打开

!

精选

hostnametest

!

boot-start-marker

boot-end-marker

!

enablepassword7070C285F4D06#密码被加密显示了

!

noaaanew-model

!

resourcepolicy

!

memory-sizeiomem5

ipsubnet-zero

!

!

ipcef

noipdomainlookup#关闭了域名查找功能

noipdhcpuvrfconnected

!

!

noipipsdeny-actionips-interface

!

noftp-rverwrite-enable

!

nocryptoisakmpccm

!

(略……)

iphttprver

noiphttpcure-rver

ipclassless

!

control-plane

!

linecon0

exec-timeout00

password7094F471A1A0A#用超级终端登陆的密码,也同样被加密显示

loggingsynchronous

lineaux0

linevty04

password700071A150754#用telnet登陆的密码,也同样被加密显示

login

精选

!

!

end

test

#3、cisco设备端口配置详解

UrAccessVerification

#从dos提示符下运行telnetip地址,就会连接到相应的交换机或者路由器

Password:#输入配置号的telnet密码,也就是上节提到的vtp中的密码

test>en#进入特权模式

Password:#输入特权模式密码,也就是上节提到的enable密码。注意这些密

码在输入的时候屏幕是不显示的。

test

#test

#test#shipintbrief#查看当前所有端口状态,包括vlan和实际的物理接口状态

InterfaceIP-AddressOK?MethodStatusProtocol协议

#这行列示的各种状态的名称

FastEthernet1unassigned未分配YESNVRAMdowndown

Vlan1192.168.113.254YESNVRAMupup

#vlan1的状态是active

Vlan2172.16.0.2YESNVRAMupup

Vlan10192.168.101.254YESNVRAMupup

Vlan20192.168.102.254YESNVRAMupup

Vlan30192.168.103.254YESNVRAMupup

Vlan40192.168.104.254YESNVRAMupup

Vlan50192.168.105.254YESNVRAMupup

Vlan60192.168.106.254YESNVRAMupup

Vlan70192.168.107.254YESNVRAMupup

Vlan80192.168.108.254YESNVRAMupup

Vlan100192.168.110.254YESNVRAMupup

Vlan110192.168.111.254YESNVRAMupup

Vlan120192.168.112.254YESNVRAMupup

Vlan150192.168.100.254YESNVRAMupup

Vlan160192.168.115.254YESNVRAMupup

GigabitEthernet1/1unassignedYESuntupup

#物理接口gi1/1也是active状态

GigabitEthernet1/2unassignedYESuntdowndown

精选

GigabitEthernet1/3unassignedYESuntdowndown

GigabitEthernet1/4unassignedYESuntdowndown

GigabitEthernet1/5unassignedYESuntdowndown

GigabitEthernet1/6unassignedYESuntdowndown

GigabitEthernet1/7unassignedYESuntdowndown

GigabitEthernet1/8unassignedYESuntdowndown

GigabitEthernet1/9unassignedYESuntdowndown

#说明:通过上述命令即可以查看当前设备所有状态的情况也可以查看端口的表示方式。在

此例中我们登陆的是一台cisco4503的三层交换机;其中GigabitEthernet1/1,表示的是这台

交换机上的第1块业务板的第1个端口,并且此端口是个千兆端口;而GigabitEthernet3/19

表示的是这台交换机上的第3块业务版的第19个端口,并且此端口也是一个千兆端口,其

他的端口以此类推。千兆端口的名称为:GigabitEthernet,百兆端口的名称为:FastEthernet。

test#conft

#进入到全局配置模式。要想对端口、vlan、路由等操作一定要到全局配置模式中来。

Enterconfigurationcommands,hCNTL/Z.

test(config)#inter

test(config)#interfacegi1/2进入Gi1/2端口

#通过此命令可进去端口配置模式,此处我们进入的是GigabitEthernet1/2口,gi1/2为简写。

test(config-if)#?

#回车后进入到端口配置模式,注意提示符的变化,输入?寻求在这个模式着那个的帮助。

Interfaceconfigurationcommands:

access-groupAccessgroupconfiguration

arpSetarptype(arpa,probe,snap)ortimeout

autoConfigureAutomation

backupModifybackupparameters

bandwidthSetbandwidthinformationalparameter

bgp-policyApplypolicypropogatedbybgpcommunitystring

carrier-delaySpecifydelayforinterfacetransitions

cdpCDPinterfacesubcommands

channel-groupEtherchannel/portbundlingconfiguration

channel-protocolSelectthechannelprotocol(LACP,PAgP)

dampeningEnableeventdampening

defaultSetacommandtoitsdefaults

delaySpecifyinterfacethroughputdelay

descriptionInterfacespecificdescription

dot1xInterfaceConfigCommandsfor802.1x

duplexConfigureduplexoperation.

exitExitfrominterfaceconfigurationmode

flow-samplerAttachflowsamplertotheinterface

flowcontrolConfigureflowoperation.

helpDescriptionoftheinteractivehelpsystem

精选

ipInterfaceInternetProtocolconfigcommands

isisIS-IScommands

iso-igrpISO-IGRPinterfacesubcommands

keepaliveEnablekeepalive

l2protocol-tunnelTunnelLayer2protocols

lacpLACPinterfacesubcommands

load-intervalSpecifyintervalforloadcalculationforaninterface

loggingConfigureloggingforinterface

loopbackConfigureinternalloopbackonaninterface

macMACinterfacecommands

macroCommandmacro

max-rerved-bandwidthMaximumRervableBandwidthonanInterface

mtuSettheinterfaceMaximumTransmissionUnit(MTU)

noNegateacommandortitsdefaults

pagpPAgPinterfacesubcommands

powerPowerconfiguration

qosQoSconfiguration

rmonConfigureRemoteMonitoringonaninterface

rvice-policyConfigureQoSServicePolicy

shutdownShutdownthelectedinterface

snmpModifySNMPinterfaceparameters

spanning-treeSpanningTreeSubsystem

speedConfigurespeedoperation.

storm-controlstormconfiguration

switchportSetswitchingmodecharacteristics

timeoutDefinetimeoutvaluesforthisinterface

transmit-interfaceAssignatransmitinterfacetoareceive-onlyinterface

tx-queueConfigureinterfacetransmitqueue

udldConfigureUDLDenabledordisabledandignoreglobalUDLD

tting

vlan-rangeconfigvlan

test(config-if)#spe

test(config-if)#speed?

#我们可指定这个端口的速度,比如这个端口接的是一个百兆的收发器,我们就可以强制将

此端口设置成100M

10Force10Mbpsoperation#强制此端口为10M

100Force100Mbpsoperation#强制此端口为100M

1000Force1000Mbpsoperation#强制此端口为1000M

autoEnableAUTOspeedconfiguration#允许速度自动协商

test(config-if)#speed100

#通过此命令就可将此端口强制设成100M,默认的状态下是auto。

test(config-if)#dup

精选

test(config-if)#duplex?#用此命令可配置此端口的双工模式,有3个选项供选择。

autoEnableAUTOduplexconfiguration#自动配置此端口的双工模式

fullForcefullduplexoperation#强制此端口为全双工模式

halfForcehalf-duplexoperation#强制此端口为半双工模式

test(config-if)#duplexauto

test(config-if)#end#用end命令可直接退回到特权模式,用exit是一层一层的退出。

test#ter

test#terminalmoni

test#terminalmonitor

#打开终端监控。当用telnet登陆的时候默认是不显示各端口的实时变化情况的,打开这个

功能就能实时的看到这台交换机上哪个端口up,哪个端口down,这对于排错的时候是很有

帮助的。

test#conft

Enterconfigurationcommands,hCNTL/Z.

test(config)#intgi1/2#重新回到端口配置模式

test(config-if)#shut#此命令可手工关闭此端口

test(config-if)#noshut#此命令为打开此端口

test(config-if)#switchportaccessvlan?

#这条命令可配置此端口属于哪个vlan,当然此vlan要事先建好。

<1-4094>VLANIDoftheVLANwhenthisportisinaccessmode

dynamicWheninaccessmode,thisinterfacesVLANiscontrolledbyVMPS

test(config-if)#switchportaccessvlan100

#我们配置此端口属于vlan100,如果此端口事先属于其他vlan那么,会从其他vlan退出

test(config-if)#exit

test(config)#intrang#亦可成批的配置端口,利用这个命令

test(config)#intrangegi1/1-5

#表示同时对gi1/1到gi1/5这5个端口进行操作,注意命令“1-5”,之间有空格。

test(config-if-range)#switchportaccessvlan100#可同时配置这5个端口属于vlan100

test(config-if-range)#shutdown#可同时关闭这5个端口

test(config-if-range)#noshutdown#可同时启用这5个端口

test(config-if-range)#exit

test(config-if)#end

test

#test#shintgi1/2#在特权模式中,可查看单个端口的状态

GigabitEthernet1/2isdown,lineprotocolisdown(notconnect)

#这行说明此端口当前的状态是down的

HardwareisGigabitEthernetPort,addressis001a.6db4.a3c1(bia001a.6db4.a3c1)

#此端口的MAC地址

MTU1500bytes,BW1000000Kbit,DLY10uc,

reliability255/255,txload1/255,rxload1/255

精选

EncapsulationARPA,loopbacknott

Keepalivet(10c)

Auto-duplex,Auto-speed,linktypeisauto,mediatypeis10/100/1000-TX

#此端口的模式为10/100/1000-TX

inputflow-controlisoff,outputflow-controlisoff

ARPtype:ARPA,ARPTimeout04:00:00

Lastinputnever,outputnever,outputhangnever

Lastclearingof"showinterface"countersnever

Inputqueue:0/2000/0/0(size/max/drops/flushes);Totaloutputdrops:0

Queueingstrategy:fifo

Outputqueue:0/40(size/max)

5minuteinputrate0bits/c,0packets/c

5minuteoutputrate0bits/c,0packets/c

0packetsinput,0bytes,0nobuffer

Received0broadcasts(0multicast)

0runts,0giants,0throttles

0inputerrors,0CRC,0frame,0overrun,0ignored

0inputpacketswithdribbleconditiondetected

0packetsoutput,0bytes,0underruns

0outputerrors,0collisions,0interfacerets

0babbles,0latecollision,0deferred

0lostcarrier,0nocarrier

0outputbufferfailures,0outputbuffersswappedout

test#shintgi1/1

GigabitEthernet1/1isup,lineprotocolisup(connected)

#这行表明此端口是up的,并且连有网线。

HardwareisGigabitEthernetPort,addressis001a.6db4.a3c0(bia001a.6db4.a3c0)

MTU1500bytes,BW1000000Kbit,DLY10uc,

reliability255/255,txload1/255,rxload1/255

EncapsulationARPA,loopbacknott

Keepalivet(10c)

Full-duplex,1000Mb/s,linktypeisauto,mediatypeis10/100/1000-TX

inputflow-controlisoff,outputflow-controlisoff

ARPtype:ARPA,ARPTimeout04:00:00

Lastinputnever,outputnever,outputhangnever

Lastclearingof"showinterface"countersnever

Inputqueue:0/2000/0/0(size/max/drops/flushes);Totaloutputdrops:0

Queueingstrategy:fifo

Outputqueue:0/40(size/max)

5minuteinputrate1293000bits/c,426packets/c

5minuteoutputrate2410000bits/c,528packets/c

273591244packetsinput,9bytes,0nobuffer

Received0broadcasts(0multicast)

0runts,0giants,0throttles

精选

0inputerrors,0CRC,0frame,0overrun,0ignored#没有输入错误,表明链路状态良好

0inputpacketswithdribbleconditiondetected

335026620packetsoutput,223732323465bytes,0underruns#输出数据包统计

0outputerrors,0collisions,0interfacerets

0babbles,0latecollision,0deferred

0lostcarrier,0nocarrier

0outputbufferfailures,0outputbuffersswappedout

test

#test

#test

#test#wr#保存刚才的配置结果

4、vlan的规划及配置

在本节中我们讲解vlan的规划及具体的配置命令。在此例中我们用的是vtp(VLAN

TrunkingProtocol)rver的模式,在这种模式中我们需要配置核心交换机的vtp模式为rver,

各接入交换机的vtp模式为cilent,那么配置完成后接入交换机就会通过trunk口自动从核心

交换机学习到所有的vlan配置信息。在接入交换机中只需要添加相应的端口即可,这样易

于管理与部署。具体的配置命令我们通过两小节来演示:

4.1核心交换机的相关配置

(这是一台已经配置好了的交换机,但这并不会影响我们的演示效果。所有我们新作的配置

会在演示结束后清除。)

TEST#shvlan#显示已经有的vlan信息,并且同时显示了各端口所属的vlan

VLANNameStatusPorts

----------------------------------------------------------------------------

1defaultactiveGi1/2,Gi1/3,Gi1/4,Gi1/5,Gi1/6,Gi1/7,

Gi1/8,Gi1/9,Gi1/10,Gi1/11,Gi1/13,Gi1/14,Gi1/16,Gi1/17,Gi1/18,Gi1/19,Gi1/20,Gi3/12,

Gi3/13,Gi3/16

2firewallactiveGi1/1

10EngineeringactiveGi3/9,Gi3/10

20ProcurementactiveGi3/19

30QAQCactive

40Operationactive

50YardactiveGi3/18

60BMactive

70HRADactive

精选

80Facilityactive

100Financeactive

110GOactive

120Wlanactive

150ServeractiveGi3/1,Gi3/2,Gi3/3,Gi3/4,Gi3/5,Gi3/6,

Gi3/7,Gi3/8

160ClientactiveGi3/11,Gi3/15

#从这行往下是为其他协议预留的vlan号段,这些不必理会。

1002fddi-defaultact/unsup1003token-ring-default

act/unsup

1004fddinet-defaultact/unsup

1005trnet-defaultact/unsup

VLANTypeSAIDMTUParentRingNoBridgeNoStpBrdgModeTrans1Trans2

--------------------------------------------------------------------

1enet1000011500-----00

2enet1000021500-----00

10enet1000101500-----00

20enet1000201500-----00

30enet1000301500-----00

40enet1000401500-----00

50enet1000501500-----00

60enet1000601500-----00

70enet1000701500-----00

80enet1000801500-----00

100enet1001001500-----00

110enet1001101500-----00

120enet1001201500-----00

150enet1001501500-----00

160enet1001601500-----00

1002fddi1010021500-----00

1003tr1010031500-----00

1004fdnet1010041500---ieee-00

TEST#conf

Configuringfromterminal,memory,ornetwork[terminal]?t

Enterconfigurationcommands,hCNTL/Z.

TEST(config)#vlan200#我们新建一个vlan号为200的vlan

TEST(config-vlan)#nametest#给这个vlan命名,这样便于日常的管理。

TEST(config-vlan)#?

VLANconfigurationcommands:

areMaximumnumberofAllRouteExplorerhopsforthisVLAN(orzeroifnone

specified)

backupcrfBackupCRFmodeoftheVLAN

精选

bridgeBridgingcharacteristicsoftheVLAN

exitApplychanges,bumprevisionnumber,andexitmode

mediaMediatypeoftheVLAN

mtuVLANMaximumTransmissionUnit

nameAsciinameoftheVLAN#刚才我们就是用的这条命令

noNegateacommandortitsdefaults

parentIDnumberoftheParentVLANofFDDIorTokenRingtypeVLANs

private-vlanConfigureaprivateVLAN

remote-spanConfigureasRemoteSPANVLAN

ringRingnumberofFDDIorTokenRingtypeVLANs

saidIEEE802.10SAID

shutdownShutdownVLANswitching

stateOperationalstateoftheVLAN

steMaximumnumberofSpanningTreeExplorerhopsforthisVLAN(orzeroif

nonespecified)

stpSpanningtreecharacteristicsoftheVLAN

tb-vlan1IDnumberofthefirsttranslationalVLANforthisVLAN(orzeroifnone)

tb-vlan2IDnumberofthecondtranslationalVLANforthisVLAN(orzeroifnone)

TEST(config-vlan)#END#建好vlan后退出到特权模式中

TEST#showipintbrief

#显示目前有的端口配置状态,我们会发现此时并没有vlan200的相关信息

InterfaceIP-AddressOK?MethodStatusProtocol

FastEthernet1unassignedYESNVRAMdowndown

Vlan1192.168.113.254YESNVRAMupup

Vlan2172.16.0.2YESNVRAMupup

Vlan10192.168.101.254YESNVRAMupup

Vlan20192.168.102.254YESNVRAMupup

Vlan30192.168.103.254YESNVRAMupup

Vlan40192.168.104.254YESNVRAMupup

Vlan50192.168.105.254YESNVRAMupup

Vlan60192.168.106.254YESNVRAMupup

Vlan70192.168.107.254YESNVRAMupup

Vlan80192.168.108.254YESNVRAMupup

Vlan100192.168.110.254YESNVRAMupup

Vlan110192.168.111.254YESNVRAMupup

Vlan120192.168.112.254YESNVRAMupup

Vlan150192.168.100.254YESNVRAMupup

Vlan160192.168.115.254YESNVRAMupup

GigabitEthernet1/1unassignedYESuntupup

GigabitEthernet1/2unassignedYESuntdowndown

GigabitEthernet1/3unassignedYESuntdowndown

GigabitEthernet1/4unassignedYESuntdowndown

GigabitEthernet1/5unassignedYESuntdowndown

精选

GigabitEthernet1/6unassignedYESuntdowndown

GigabitEthernet1/7unassignedYESuntdowndown

GigabitEthernet1/8unassignedYESuntdowndown

GigabitEthernet1/9unassignedYESuntdowndown

GigabitEthernet1/10unassignedYESuntdowndown

GigabitEthernet1/11unassignedYESuntdowndown

GigabitEthernet1/12unassignedYESuntdowndown

GigabitEthernet1/13unassignedYESuntdowndown

GigabitEthernet1/14unassignedYESuntdowndown

GigabitEthernet1/15unassignedYESuntupup

GigabitEthernet1/16unassignedYESuntdowndown

GigabitEthernet1/17unassignedYESuntdowndown

GigabitEthernet1/18unassignedYESuntdowndown

GigabitEthernet1/19unassignedYESuntdowndown

GigabitEthernet1/20unassignedYESuntdowndown

GigabitEthernet3/1unassignedYESuntupup

GigabitEthernet3/2unassignedYESuntupup

GigabitEthernet3/3unassignedYESuntupup

GigabitEthernet3/4unassignedYESuntupup

GigabitEthernet3/5unassignedYESuntupup

GigabitEthernet3/6unassignedYESuntupup

GigabitEthernet3/7unassignedYESuntupup

GigabitEthernet3/8unassignedYESuntdowndown

TEST#shvlan#显示一下vlan信息

VLANNameStatusPorts

----------------------------------------------------------------------------

1defaultactiveGi1/2,Gi1/3,Gi1/4,Gi1/5,Gi1/6,Gi1/7,

Gi1/8,Gi1/9,Gi1/10,Gi1/11,Gi1/13,Gi1/14,Gi1/16,Gi1/17,Gi1/18,Gi1/19,Gi1/20,Gi3/12,

Gi3/13,Gi3/16

2firewallactiveGi1/1

10EngineeringactiveGi3/9,Gi3/10

20ProcurementactiveGi3/19

30QAQCactive

40Operationactive

50YardactiveGi3/18

60BMactive

70HRADactive

80Facilityactive

100Financeactive

110GOactive

120Wlanactive

150ServeractiveGi3/1,Gi3/2,Gi3/3,Gi3/4,Gi3/5,Gi3/6,

精选

Gi3/7,Gi3/8

160ClientactiveGi3/11,Gi3/15

200testactive

#这个是我们新建好的vlan,但是vlan中没有任何端口。

1002fddi-defaultact/unsup

1003token-ring-defaultact/unsup

1004fddinet-defaultact/unsup

1005trnet-defaultact/unsup

VLANTypeSAIDMTUParentRingNoBridgeNoStpBrdgModeTrans1Trans2

--------------------------------------------------------------------

1enet1000011500-----00

2enet1000021500-----00

10enet1000101500-----00

20enet1000201500-----00

30enet1000301500-----00

40enet1000401500-----00

50enet1000501500-----00

60enet1000601500-----00

70enet1000701500-----00

80enet1000801500-----00

100enet1001001500-----00

110enet1001101500-----00

120enet1001201500-----00

150enet1001501500-----00

160enet1001601500-----00

200enet1002001500-----00

1002fddi1010021500-----00

TEST#conft

Enterconfigurationcommands,hCNTL/Z.

TEST(config)#interfacegigabitEthernet1/2

#我们进入端口配置模式,配置gigabitEthernet1/2这个端口

TEST(config-if)#switchportaccessvlan200#将此端口加入到刚才建好的vlan200中

TEST(config-if)#end

TEST#shvlan#退出来验证一下

VLANNameStatusPorts

----------------------------------------------------------------------------

1defaultactiveGi1/3,Gi1/4,Gi1/5,Gi1/6,Gi1/7,Gi1/8,

Gi1/9,Gi1/10,Gi1/11,Gi1/12,Gi1/14,Gi1/16,Gi1/17,Gi1/18,Gi1/19,Gi1/20,Gi3/12,Gi3/13,

Gi3/14

2firewallactiveGi1/1

10EngineeringactiveGi3/9,Gi3/10

精选

20ProcurementactiveGi3/19

30QAQCactive

40Operationactive

50YardactiveGi3/18

60BMactive

70HRADactive

80Facilityactive

100Financeactive

110GOactive

120Wlanactive

150ServeractiveGi3/1,Gi3/2,Gi3/3,Gi3/4,Gi3/5,Gi3/6,

Gi3/7,Gi3/8

160ClientactiveGi3/11,Gi3/15

200testactiveGi1/2

#现在GI1/2这个端口已经属于vlan200了。

1002fddi-defaultact/unsup

1003token-ring-defaultact/unsup

1004fddinet-defaultact/unsup

1005trnet-defaultact/unsup

VLANTypeSAIDMTUParentRingNoBridgeNoStpBrdgModeTrans1Trans2

--------------------------------------------------------------------

1enet1000011500-----00

2enet1000021500-----00

10enet1000101500-----00

20enet1000201500-----00

30enet1000301500-----00

40enet1000401500-----00

50enet1000501500-----00

60enet1000601500-----00

70enet1000701500-----00

80enet1000801500-----00

100enet1001001500-----00

110enet1001101500-----00

120enet1001201500-----00

150enet1001501500-----00

160enet1001601500-----00

200enet1002001500-----00

1002fddi1010021500-----00

1003tr1010031500-----00

TEST#shipintbrief

#再显示一下所有端口的状态,我们会发现同样没有vlan200的相关信息。

InterfaceIP-AddressOK?MethodStatusProtocol

精选

FastEthernet1unassignedYESNVRAMdowndown

Vlan1192.168.113.254YESNVRAMupup

Vlan2172.16.0.2YESNVRAMupup

Vlan10192.168.101.254YESNVRAMupup

Vlan20192.168.102.254YESNVRAMupup

Vlan30192.168.103.254YESNVRAMupup

Vlan40192.168.104.254YESNVRAMupup

Vlan50192.168.105.254YESNVRAMupup

Vlan60192.168.106.254YESNVRAMupup

Vlan70192.168.107.254YESNVRAMupup

Vlan80192.168.108.254YESNVRAMupup

Vlan100192.168.110.254YESNVRAMupup

Vlan110192.168.111.254YESNVRAMupup

Vlan120192.168.112.254YESNVRAMupup

Vlan150192.168.100.254YESNVRAMupup

Vlan160192.168.115.254YESNVRAMupup

GigabitEthernet1/1unassignedYESuntupup

GigabitEthernet1/2unassignedYESuntdowndown

GigabitEthernet1/3unassignedYESuntdowndown

GigabitEthernet1/4unassignedYESuntdowndown

GigabitEthernet1/5unassignedYESuntdowndown

GigabitEthernet1/6unassignedYESuntdowndown

GigabitEthernet1/7unassignedYESuntdowndown

GigabitEthernet1/8unassignedYESuntdowndown

GigabitEthernet1/9unassignedYESuntdowndown

GigabitEthernet1/10unassignedYESuntdowndown

GigabitEthernet1/11unassignedYESuntdowndown

GigabitEthernet1/12unassignedYESuntdowndown

GigabitEthernet1/13unassignedYESuntdowndown

GigabitEthernet1/14unassignedYESuntdowndown

GigabitEthernet1/15unassignedYESuntupup

GigabitEthernet1/16unassignedYESuntdowndown

GigabitEthernet1/17unassignedYESuntdowndown

GigabitEthernet1/18unassignedYESuntdowndown

GigabitEthernet1/19unassignedYESuntdowndown

GigabitEthernet1/20unassignedYESuntdowndown

GigabitEthernet3/1unassignedYESuntupup

GigabitEthernet3/2unassignedYESuntupup

GigabitEthernet3/3unassignedYESuntupup

GigabitEthernet3/4unassignedYESuntupup

GigabitEthernet3/5unassignedYESuntupup

GigabitEthernet3/6unassignedYESuntupup

GigabitEthernet3/7unassignedYESuntupup

GigabitEthernet3/8unassignedYESuntdowndown

精选

TEST#conft

Enterconfigurationcommands,hCNTL/Z.

TEST(config)#intvlan200#给这个vlan添加相应的ip地址,注意此处的语法

TEST(config-if)#ipadd10.10.10.0.1255.255.255.0#添加具体的ip地址

TEST(config-if)#noshut#使能此端口

TEST(config-if)#end

TEST#shipintb

#重新显示一下所有端口的状态,我们会发现已经有了vlan200的端口信息了。

InterfaceIP-AddressOK?MethodStatusProtocol

FastEthernet1unassignedYESNVRAMdowndown

Vlan1192.168.113.254YESNVRAMupup

Vlan2172.16.0.2YESNVRAMupup

Vlan10192.168.101.254YESNVRAMupup

Vlan20192.168.102.254YESNVRAMupup

Vlan30192.168.103.254YESNVRAMupup

Vlan40192.168.104.254YESNVRAMupup

Vlan50192.168.105.254YESNVRAMupup

Vlan60192.168.106.254YESNVRAMupup

Vlan70192.168.107.254YESNVRAMupup

Vlan80192.168.108.254YESNVRAMupup

Vlan100192.168.110.254YESNVRAMupup

Vlan110192.168.111.254YESNVRAMupup

Vlan120192.168.112.254YESNVRAMupup

Vlan150192.168.100.254YESNVRAMupup

Vlan160192.168.115.254YESNVRAMupup

Vlan20010.10.0.1YESmanualupup

GigabitEthernet1/1unassignedYESuntupup

GigabitEthernet1/2unassignedYESuntdowndown

GigabitEthernet1/3unassignedYESuntdowndown

GigabitEthernet1/4unassignedYESuntdowndown

GigabitEthernet1/5unassignedYESuntdowndown

GigabitEthernet1/6unassignedYESuntdowndown

GigabitEthernet1/7unassignedYESuntdowndown

GigabitEthernet1/8unassignedYESuntdowndown

GigabitEthernet1/9unassignedYESuntdowndown

GigabitEthernet1/10unassignedYESuntdowndown

GigabitEthernet1/11unassignedYESuntdowndown

GigabitEthernet1/12unassignedYESuntdowndown

GigabitEthernet1/13unassignedYESuntdowndown

GigabitEthernet1/14unassignedYESuntdowndown

GigabitEthernet1/15unassignedYESuntupup

GigabitEthernet1/16unassignedYESuntdowndown

GigabitEthernet1/17unassignedYESuntdowndown

精选

GigabitEthernet1/18unassignedYESuntdowndown

GigabitEthernet1/19unassignedYESuntdowndown

GigabitEthernet1/20unassignedYESuntdowndown

GigabitEthernet3/1unassignedYESuntupup

GigabitEthernet3/2unassignedYESuntupup

GigabitEthernet3/3unassignedYESuntupup

GigabitEthernet3/4unassignedYESuntupup

GigabitEthernet3/5unassignedYESuntupup

GigabitEthernet3/6unassignedYESuntupup

GigabitEthernet3/7unassignedYESuntupup

##小结一下:在刚才的配置过程中,端口Gi1/2下面所连接的电脑的网关就是vlan200的地

址——10.10.0.1。下面所连的电脑找到相应的网关后在会去找具体的路由,这些我们下节会

讲解。

TEST#showintertrunk

#显示当前交换机中的trunk接口。作为trunk接口的端口下联的是接入层(或者是汇聚层)

的交换机。

PortModeEncapsulationStatusNativevlan

Gi1/15on802.1qtrunking1

Gi3/17on802.1qtrunking1

Gi3/20on802.1qtrunking1

Gi3/21on802.1qtrunking1

Gi3/22on802.1qtrunking1

Gi3/23on802.1qtrunking1

Gi3/24on802.1qtrunking1

PortVlansallowedontrunk

Gi1/151-4094

Gi3/171-4094

Gi3/201-4094

Gi3/211-4094

Gi3/221-4094

Gi3/231-4094

Gi3/241-4094

PortVlansallowedandactiveinmanagementdomain

Gi1/151-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200

Gi3/171-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200

Gi3/201-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200

Gi3/211-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200

Gi3/221-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200

Gi3/231-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200

精选

Gi3/241-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200

PortVlansinspanningtreeforwardingstateandnotpruned

Gi1/151-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200

Gi3/171-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200

Gi3/201-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200

Gi3/211-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200

Gi3/221-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200

Gi3/231-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200

Gi3/241-2,10,20,30,40,50,60,70,80,100,110,120,150,160,200

TEST#conft

Enterconfigurationcommands,hCNTL/Z.

TEST(config)#intgi1/15#我们以gi1/15来说明,如何将此端口配置成trunk接口

TEST(config-if)#switchportmode?#首先定义此接口的模式为trunk

accessSettrunkingmodetoACCESSunconditionally

dynamicSettrunkingmodetodynamicallynegotiateaccessortrunkmode

private-vlanSetthemodetoprivate-vlanhostorpromiscuous

trunkSettrunkingmodetoTRUNKunconditionally

TEST(config-if)#switchportmodetrunk

TEST(config-if)#switchporttrunkencapsulation?

#然后定义trunk口的封装类型,此处选择dot1q也叫802.1q,为通用封装类型

dot1qInterfaceusonly802.1qtrunkingencapsulationwhentrunking

islInterfaceusonlyISLtrunkingencapsulationwhentrunking

negotiateDevicewillnegotiatetrunkingencapsulationwithpeeroninterface

TEST(config-if)#switchporttrunkencapsulationdot1q

#回车后就将此trunk口的封装类型定义成了dot1q

##小结一下:刚才配置的是如何将下联接入层交换机的端口配置成trunk模式,并且如何

将此trunk口封装成特定的类型,接下来我们介绍如何配置此核心交换机的VTP的一些相关

设置。

TEST(config)#vtpmode?

clientSetthedevicetoclientmode.客服端模式

rverSetthedevicetorvermode.服务器模式

transparentSetthedevicetotransparentmode.透明模式

TEST(config)#vtpmoderver

#首先我们在全局配置模式中将vtp的mode设置成rver

TEST(config)#vtpdomainpjoe

#然后配置vtp的domain,所有的交换机应该在一个domain中,此例中我们定义的doamin

为pjoe

TEST(config)#vtppasswordpjoerver

精选

#配置此vtp的介入密码,这样可以防止未授权的交换机随便加入到这个domian中来。

TEST#shvtpstatus#配置完毕后显示一下vtp的状态

VTPVersion:2

ConfigurationRevision:22

MaximumVLANssupportedlocally:1005

NumberofexistingVLANs:20

VTPOperatingMode:Server#vtp的模式为rver模式

VTPDomainName:pjoe#vtp的域名是pjoe

VTPPruningMode:Disabled

VTPV2Mode:Disabled

VTPTrapsGeneration:Enabled

MD5digest:0x000xB30x210xB70x560xD70x060x4F

#此处表示的是vtp的密码(已加密)

Configurationlastmodifiedby192.168.113.254at12-3-0722:52:46

LocalupdaterIDis192.168.113.254oninterfaceVl1(lowestnumberedVLANinterfacefound)

TEST

#TEST

###小结一下:经过以上的配置就将核心交换机的vtp等的配置工作完成了,只需要再配置

好接入交换机的相关vtp参数和对应的trunk接口,接入交换机就能够从核心交换机上获取

到所有的vlan信息,而不需要重新建立各个vlan。

TEST#shvlan#接下来我们去掉新增加的vlan,先显示一下。

VLANNameStatusPorts

----------------------------------------------------------------------------

1defaultactiveGi1/3,Gi1/4,Gi1/5,Gi1/6,Gi1/7,Gi1/8,

Gi1/9,Gi1/10,Gi1/11,Gi1/12,Gi1/14,Gi1/16,Gi1/17,Gi1/18,Gi1/19,Gi1/20,Gi3/12,Gi3/13,

Gi3/14,

2firewallactiveGi1/1

10EngineeringactiveGi3/9,Gi3/10

20ProcurementactiveGi3/19

30QAQCactive

40Operationactive

50YardactiveGi3/18

60BMactive

70HRADactive

80Facilityactive

100Financeactive

110GOactive

120Wlanactive

150ServeractiveGi3/1,Gi3/2,Gi3/3,Gi3/4,Gi3/5,Gi3/6,

Gi3/7,Gi3/8

精选

160ClientactiveGi3/11,Gi3/15

200testactiveGi1/2

1002fddi-defaultact/unsup

1003token-ring-defaultact/unsup

1004fddinet-defaultact/unsup

1005trnet-defaultact/unsup

VLANTypeSAIDMTUParentRingNoBridgeNoStpBrdgModeTrans1Trans2

--------------------------------------------------------------------

1enet1000011500-----00

2enet1000021500-----00

10enet1000101500-----00

20enet1000201500-----00

30enet1000301500-----00

40enet1000401500-----00

50enet1000501500-----00

60enet1000601500-----00

70enet1000701500-----00

80enet1000801500-----00

100enet1001001500-----00

110enet1001101500-----00

120enet1001201500-----00

150enet1001501500-----00

160enet1001601500-----00

200enet1002001500-----00

1002fddi1010021500-----00

1003tr1010031500-----00

TEST#conft

Enterconfigurationcommands,hCNTL/Z.

TEST(config)#novlan200#第一步,删除vlan200

TEST(config)#nointvlan200#第二步,删除intvlan200,经过这两步就可以彻底

的删除vlan200了

TEST(config)intgi1/2#进入到gi1/2这个端口中

TEST(config-if)#switchportaccessvlan1#将这个端口重新划分到vlan1中

TEST(config-if)#end

TEST#shvvlan

#确认一下,我们成功的将gi1/2回归到vlan1中,并且删除掉了vlan200

VLANNameStatusPorts

----------------------------------------------------------------------------

1defaultactiveGi1/2,Gi1/3,Gi1/4,Gi1/5,Gi1/6,Gi1/7,

Gi1/8,Gi1/9,Gi1/10,Gi1/11,Gi1/13,Gi1/14,Gi1/16,Gi1/17,Gi1/18,Gi1/19,Gi1/20,Gi3/12,

精选

Gi3/13,Gi3/16

2firewallactiveGi1/1

10EngineeringactiveGi3/9,Gi3/10

20ProcurementactiveGi3/19

30QAQCactive

40Operationactive

50YardactiveGi3/18

60BMactive

70HRADactive

80Facilityactive

100Financeactive

110GOactive

120Wlanactive

150ServeractiveGi3/1,Gi3/2,Gi3/3,Gi3/4,Gi3/5,Gi3/6,

Gi3/7,Gi3/8

160ClientactiveGi3/11,Gi3/15

1002fddi-defaultact/unsup

1003token-ring-defaultact/unsup

1004fddinet-defaultact/unsup

1005trnet-defaultact/unsup

VLANTypeSAIDMTUParentRingNoBridgeNoStpBrdgModeTrans1Trans2

--------------------------------------------------------------------

1enet1000011500-----00

2enet1000021500-----00

10enet1000101500-----00

20enet1000201500-----00

30enet1000301500-----00

40enet1000401500-----00

50enet1000501500-----00

60enet1000601500-----00

70enet1000701500-----00

80enet1000801500-----00

100enet1001001500-----00

110enet1001101500-----00

120enet1001201500-----00

150enet1001501500-----00

160enet1001601500-----00

1002fddi1010021500-----00

1003tr1010031500-----00

1004fdnet1010041500---ieee-00

4.2接入交换机的相关配置

##在此例中,我们联入的是一台接入交换机,此交换机的gi0/1口上联至核心交换机。也

精选

就意味着我们需要配置gi0/1为trunk口。具体的配置如下:

D-2960-3(config)#intgi0/1

D-2960-3(config-if)#sw

D-2960-3(config-if)#switchportmo

D-2960-3(config-if)#switchportmode?

accessSettrunkingmodetoACCESSunconditionally

dynamicSettrunkingmodetodynamicallynegotiateaccessortrunkmode

trunkSettrunkingmodetoTRUNKunconditionally

D-2960-3(config-if)#switchportmodetrunk

##配置此接口的模式为trunk,在cisoc2960交换机中,配置完接口模式为trunk后就可以了,

不需要进一步配置此trunk口的封装状态,因为其默认的也是唯一的封装类型就是dot1q,

并且此系列交换机并没有专门的封装配置命令。

D-2960-3(config-if)#exit

D-2960-3(config)#exit

D-2960-3#shinttru#退至特权配置模式验证一下刚才的配置

PortModeEncapsulationStatusNativevlan

Gi0/1auto802.1qtrunking1

#这个端口已经配置成trunk模式,并且封装成802.1q了

PortVlansallowedontrunk

Gi0/11-4094

PortVlansallowedandactiveinmanagementdomain

Gi0/11-2,10,20,30,40,50,60,70,80,100,110,120,150,160

PortVlansinspanningtreeforwardingstateandnotpruned

Gi0/11-2,10,20,30,40,50,60,70,80,100,110,120,150,160

D-2960-3#conft#进入到全局配置模式

D-2960-3(config)#vtpmodeclient

#配置vtp模式为client,与核心交换机的rver模式相呼应。

D-2960-3(config)#vtpdomainpjoe

#配置vtp域为pjoe,只有一个域中的交换机才能互传vlan信息。

D-2960-3(config)#vtppasswordpjoerver#配置vtp密码

D-2960-3(config)#end

D-2960-3#shvtpstatus#退出到特权模式验证一下刚才的有关vtp的配置

VTPVersion:2

ConfigurationRevision:23

MaximumVLANssupportedlocally:255

精选

NumberofexistingVLANs:19

VTPOperatingMode:Client#模式已经设置成client

VTPDomainName:pjoe#域名已经设置成pjoe

VTPPruningMode:Disabled

VTPV2Mode:Disabled

VTPTrapsGeneration:Disabled

MD5digest:0xEC0x300xEF0x6F0xA50x9A0x390x7B

#密码已经配置完毕,但是被加密显示了

Configurationlastmodifiedby192.168.113.254at12-3-0722:58:54

##稍等一会后,验证一下是否学习到了核心交换机的vlan信息,它的学习有一小段的过程

30秒的样子。

D-2960-3#shvlan#验证一下vlan信息是否全部学到。

VLANNameStatusPorts

----------------------------------------------------------------------------

1defaultactiveFa0/1,Fa0/2,Fa0/3,Fa0/4,Fa0/5,

Fa0/6,Fa0/7,Fa0/8,Fa0/9,Fa0/10,Fa0/11,Fa0/12,Fa0/13,Fa0/14,Fa0/15,Fa0/16,Fa0/17,

Fa0/18,Fa0/19,Fa0/20,Fa0/21,Fa0/22,Fa0/23,Fa0/24,Fa0/25,Fa0/26,Fa0/27,Fa0/28,Fa0/29,

Fa0/30,Fa0/31,Fa0/32,Fa0/33,Fa0/34,Fa0/35,Fa0/36,Fa0/37,Fa0/38,Fa0/39,Fa0/40,

Fa0/41,a0/42,Fa0/43,Fa0/44,Fa0/45,Fa0/46,Fa0/47,Fa0/48,Gi0/2

2firewallactive

#ok,核心交换机上配置好的vlan信息已经被这台交换机学习到了,剩下的工作仅需要将相

应的端口添加到相应的vlan中就可以了,此处不赘述。

10Engineeringactive

20Procurementactive

30QAQCactive

40Operationactive

50Yardactive

60BMactive

70HRADactive

80Facilityactive

100Financeactive

110GOactive

120Wlanactive

150Serveractive

160Clientactive

1002fddi-defaultact/unsup

1003token-ring-defaultact/unsup

1004fddinet-defaultact/unsup

1005trnet-defaultact/unsup

精选

VLANTypeSAIDMTUParentRingNoBridgeNoStpBrdgModeTrans1Trans2

--------------------------------------------------------------------

1enet1000011500-----00

2enet1000021500-----00

10enet1000101500-----00

20enet1000201500-----00

30enet1000301500-----00

40enet1000401500-----00

50enet1000501500-----00

60enet1000601500-----00

70enet1000701500-----00

80enet1000801500-----00

100enet1001001500-----00

110enet1001101500-----00

120enet1001201500-----00

150enet1001501500-----00

160enet1001601500-----00

1002fddi1010021500-----00

D-2960-3

##配置这台交换机的管理IP

D-2960-3(config)#intvlan1#管理ip地址我们配置在vlan1上

D-2960-3(config-if)#ipaddress192.168.113.222255.255.255.0#设置实际的ip地址

D-2960-3(config-if)#exit

D-2960-3(config)#ipdefault-gateway192.168.113.254

#设置这台交换机的网关,此地址即为核心交换机vlan1的地址。

D-2960-3(config)#end

D-2960-3#shrun#验证一下完整的配置。

Buildingconfiguration...

Currentconfiguration:2087bytes

!

version12.2

norvicepad

rvicetimestampsdebuguptime

rvicetimestampsloguptime

rvicepassword-encryption

!

hostnameD-2960-3

!

enablepassword712090F1817

!

noaaanew-model

精选

systemmturouting1500

ipsubnet-zero

!

nofileverifyauto

spanning-treemodepvst

spanning-treeextendsystem-id

!

vlaninternalallocationpolicyascending

!

interfaceFastEthernet0/1

!

interfaceFastEthernet0/2

!

interfaceFastEthernet0/3

!

(省略……)

interfaceFastEthernet0/45

!

interfaceFastEthernet0/46

!

interfaceFastEthernet0/47

!

interfaceFastEthernet0/48

!

interfaceGigabitEthernet0/1

!

interfaceGigabitEthernet0/2

!

interfaceVlan1

ipaddress192.168.113.222255.255.255.0

noiproute-cache

!

ipdefault-gateway192.168.113.254

iphttprver

!

control-plane

!

!

linecon0

password712090F1817

linevty04

password712090F1817

login

linevty515

精选

login

!

end

D-2960-3

#5、配置交换机的路由功能

说明:只有在三层交换机上才有路由功能,其他的二层接入交换机要想在不同的vlan

之间传送数据需要通过trunk口到核心交换机上进行完路由交换后才可以。

TEST(config)#iprouting#使能三层交换机的路由功能,默认是关闭的

TEST(config)#iproute0.0.0.00.0.0.0172.16.0.1

#配置交换机的默认路由,也就是总的出口路由。

TEST(config)#end#退出验证一下刚才的配置

TEST#shiprouet

Codes:C-connected,S-static,R-RIP,M-mobile,B-BGP

D-EIGRP,EX-EIGRPexternal,O-OSPF,IA-OSPFinterarea

N1-OSPFNSSAexternaltype1,N2-OSPFNSSAexternaltype2

E1-OSPFexternaltype1,E2-OSPFexternaltype2,E-EGP

i-IS-IS,su-IS-ISsummary,L1-IS-ISlevel-1,L2-IS-ISlevel-2

ia-IS-ISinterarea,*-candidatedefault,U-per-urstaticroute

o-ODR,P-periodicdownloadedstaticroute

Gatewayoflastresortis172.16.0.1tonetwork0.0.0.0

C192.168.106.0/24isdirectlyconnected,Vlan60

#这种类型的路由——标志为“C”的路由,为静态直连路由。

C192.168.107.0/24isdirectlyconnected,Vlan70

C192.168.104.0/24isdirectlyconnected,Vlan40

C192.168.105.0/24isdirectlyconnected,Vlan50

C192.168.110.0/24isdirectlyconnected,Vlan100

C192.168.111.0/24isdirectlyconnected,Vlan110

C192.168.108.0/24isdirectlyconnected,Vlan80

172.16.0.0/30issubnetted,1subnets

C172.16.0.0isdirectlyconnected,Vlan2

C192.168.115.0/24isdirectlyconnected,Vlan160

C192.168.113.0/24isdirectlyconnected,Vlan1

C192.168.112.0/24isdirectlyconnected,Vlan120

C192.168.102.0/24isdirectlyconnected,Vlan20

C192.168.103.0/24isdirectlyconnected,Vlan30

精选

C192.168.100.0/24isdirectlyconnected,Vlan150

C192.168.101.0/24isdirectlyconnected,Vlan10

S*0.0.0.0/0[1/0]via172.16.0.1#为配置的默认路由

TEST

#6、配置交换机的DHCP功能

TEST#shipintb#先显示一下所有的端口配置

InterfaceIP-AddressOK?MethodStatusProtocol

FastEthernet1unassignedYESNVRAMdowndown

Vlan1192.168.113.254YESNVRAMupup

Vlan2172.16.0.2YESNVRAMupup

Vlan10192.168.101.254YESNVRAMupup

Vlan20192.168.102.254YESNVRAMupup

Vlan30192.168.103.254YESNVRAMupup

Vlan40192.168.104.254YESNVRAMupup

Vlan50192.168.105.254YESNVRAMupup

Vlan60192.168.106.254YESNVRAMupup

Vlan70192.168.107.254YESNVRAMupup

Vlan80192.168.108.254YESNVRAMupup

Vlan100192.168.110.254YESNVRAMupup

Vlan110192.168.111.254YESNVRAMupup

Vlan120192.168.112.254YESNVRAMupup

#此例中我们想让vlan120提供DHCP功能

Vlan150192.168.100.254YESNVRAMupup

Vlan160192.168.115.254YESNVRAMupup

GigabitEthernet1/1unassignedYESuntupup

GigabitEthernet1/2unassignedYESuntdowndown

GigabitEthernet1/3unassignedYESuntdowndown

GigabitEthernet1/4unassignedYESuntdowndown

GigabitEthernet1/5unassignedYESuntdowndown

GigabitEthernet1/6unassignedYESuntdowndown

GigabitEthernet1/7unassignedYESuntdowndown

GigabitEthernet1/8unassignedYESuntdowndown

GigabitEthernet1/9unassignedYESuntdowndown

GigabitEthernet1/10unassignedYESuntdowndown

GigabitEthernet1/11unassignedYESuntdowndown

GigabitEthernet1/12unassignedYESuntdowndown

GigabitEthernet1/13unassignedYESuntdowndown

GigabitEthernet1/14unassignedYESuntdowndown

GigabitEthernet1/15unassignedYESuntupup

GigabitEthernet1/16unassignedYESuntdowndown

GigabitEthernet1/17unassignedYESuntdowndown

GigabitEthernet1/18unassignedYESuntdowndown

精选

GigabitEthernet1/19unassignedYESuntdowndown

GigabitEthernet1/20unassignedYESuntdowndown

GigabitEthernet3/1unassignedYESuntupup

GigabitEthernet3/2unassignedYESuntupup

GigabitEthernet3/3unassignedYESuntupup

GigabitEthernet3/4unassignedYESuntupup

GigabitEthernet3/5unassignedYESuntupup

GigabitEthernet3/6unassignedYESuntupup

GigabitEthernet3/7unassignedYESuntupup

GigabitEthernet3/8unassignedYESuntupup

TEST

#TEST#conft

Enterconfigurationcommands,hCNTL/Z.

TEST(config)#ipdhcppoolwlan#配置交换机的地址池并命名

TEST(config)#network192.168.112.0255.255.255.0#定义此地址池的网段

TEST(config)#default-router192.168.112.254#定义分发下去的地址的默认网关

TEST(config)#dns-rver202.102.128.68202.102.134.68

#定义分发下去地址的DNS服务器,此处是2个中间用空格分隔。

TEST(config)#ipdhcpexcluded-address192.168.112.200192.168.112.254

#定义保留的ip地址端

TEST(dhcp-config)#end

TEST#shrun

##小结一下:至此所属这个vlan的客户机就可以通过自动获取地址的方式来得到正确的ip、

网关、dns等信息。

7、常用排错命令

TEST#terminalmonitor

#排除网络故障以前,请打开这一命令以便实时的接收到交换机的提示信息。

TEST

#TEST#shrun

#显示所有的配置清单,可将这些配置保存成文本作为交换机的配置备份。

Buildingconfiguration...

Currentconfiguration:9200bytes

!

version12.2

norvicepad

精选

rvicetimestampsdebuguptime

rvicetimestampsloguptime

rvicepassword-encryption

rvicecompress-config

!

hostnameTEST

!

boot-start-marker

bootsystembootflash:

boot-end-marker

!

enablecret5$1$c2Ge$eLS42O.0h04yCn1tDZGsB/

enablepassword71119130A12010E1E122F39

!

noaaanew-model

ipsubnet-zero

ipdhcpexcluded-address192.168.112.200192.168.112.254

ipdhcpexcluded-address192.168.115.200192.168.115.254

!

ipdhcppoolWlan

network192.168.112.0255.255.255.0

default-router192.168.112.254

dns-rver202.102.128.68202.102.134.68

!

ipdhcppoolClient

network192.168.115.0255.255.255.0

default-router192.168.115.254

dns-rver202.102.134.68202.102.128.68

!

ipdhcppooltest

host192.168.112.98255.255.255.0

client-identifier0100.1b77.2fa0.39

default-router192.168.112.254

dns-rver202.102.134.68

!

ipdhcppoollijing

host192.168.112.100255.255.255.0

client-identifier0100.0e35.891b.46

default-router192.168.112.254

dns-rver202.102.128.68202.102.134.68

!

!

nofileverifyauto

精选

errdisablerecoverycauarp-inspection

spanning-treemodepvst

spanning-treeextendsystem-id

powerredundancy-moderedundant

!

!

!

vlaninternalallocationpolicyascending

!

interfaceFastEthernet1

noipaddress

speedauto

duplexauto

!

interfaceGigabitEthernet1/1

switchportaccessvlan2

!

interfaceGigabitEthernet1/2

!

interfaceGigabitEthernet1/3

!

interfaceGigabitEthernet1/4

!

interfaceGigabitEthernet1/5

!

interfaceGigabitEthernet1/6

!

interfaceGigabitEthernet1/7

!

interfaceGigabitEthernet1/8

!

interfaceGigabitEthernet1/9

!

interfaceGigabitEthernet1/10

!

interfaceGigabitEthernet1/11

!

interfaceGigabitEthernet1/12

!

interfaceGigabitEthernet1/13

switchporttrunkencapsulationdot1q

switchportmodetrunk

!

interfaceGigabitEthernet1/14

精选

!

interfaceGigabitEthernet1/15

switchporttrunkencapsulationdot1q

switchportmodetrunk

!

interfaceGigabitEthernet1/16

!

interfaceGigabitEthernet1/17

!

interfaceGigabitEthernet1/18

!

interfaceGigabitEthernet1/19

!

interfaceGigabitEthernet1/20

!

interfaceGigabitEthernet3/1

switchportaccessvlan150

nocdpenable

!

interfaceGigabitEthernet3/2

switchportaccessvlan150

!

interfaceGigabitEthernet3/3

switchportaccessvlan150

!

interfaceGigabitEthernet3/4

switchportaccessvlan150

!

interfaceGigabitEthernet3/5

switchportaccessvlan150

!

interfaceGigabitEthernet3/6

switchportaccessvlan150

!

interfaceGigabitEthernet3/7

switchportaccessvlan150

!

interfaceGigabitEthernet3/8

switchportaccessvlan150

!

interfaceGigabitEthernet3/9

switchportaccessvlan10

!

interfaceGigabitEthernet3/10

精选

switchportaccessvlan10

!

interfaceGigabitEthernet3/11

switchportaccessvlan160

!

interfaceGigabitEthernet3/12

!

interfaceGigabitEthernet3/13

!

interfaceGigabitEthernet3/14

!

interfaceGigabitEthernet3/15

switchportaccessvlan160

!

interfaceGigabitEthernet3/16

!

interfaceGigabitEthernet3/17

switchporttrunkencapsulationdot1q

switchportmodetrunk

!

interfaceGigabitEthernet3/18

switchportaccessvlan50

switchportmodeaccess

!

interfaceGigabitEthernet3/19

switchportaccessvlan20

switchportmodeaccess

nocdpenable

!

interfaceGigabitEthernet3/20

switchporttrunkencapsulationdot1q

switchportmodetrunk

iparpinspectiontrust

!

interfaceGigabitEthernet3/21

switchporttrunkencapsulationdot1q

switchportmodetrunk

!

interfaceGigabitEthernet3/22

switchporttrunkencapsulationdot1q

switchportmodetrunk

!

interfaceGigabitEthernet3/23

switchporttrunkencapsulationdot1q

精选

switchportmodetrunk

!

interfaceGigabitEthernet3/24

switchporttrunkencapsulationdot1q

switchportmodetrunk

!

interfaceVlan1

ipaddress192.168.113.254255.255.255.0

iphelper-address192.168.100.100

noipredirects

!

interfaceVlan2

ipaddress172.16.0.2255.255.255.252

iphelper-address192.168.100.100

noipredirects

noipunreachables

!

interfaceVlan10

ipaddress192.168.101.254255.255.255.0

iphelper-address192.168.100.100

noipredirects

!

interfaceVlan20

ipaddress192.168.102.254255.255.255.0

iphelper-address192.168.100.100

noipredirects

!

interfaceVlan30

ipaddress192.168.103.254255.255.255.0

iphelper-address192.168.100.100

noipredirects

!

interfaceVlan40

ipaddress192.168.104.254255.255.255.0

iphelper-address192.168.100.100

noipredirects

!

interfaceVlan50

ipaddress192.168.105.254255.255.255.0

iphelper-address192.168.100.100

noipredirects

!

interfaceVlan60

ipaddress192.168.106.254255.255.255.0

精选

iphelper-address192.168.100.100

noipredirects

!

interfaceVlan70

ipaddress192.168.107.254255.255.255.0

iphelper-address192.168.100.100

noipredirects

!

interfaceVlan80

ipaddress192.168.108.254255.255.255.0

iphelper-address192.168.100.100

noipredirects

!

interfaceVlan100

ipaddress192.168.110.254255.255.255.0

iphelper-address192.168.100.100

noipredirects

!

interfaceVlan110

ipaddress192.168.111.254255.255.255.0

iphelper-address192.168.100.100

!

interfaceVlan120

ipaddress192.168.112.254255.255.255.0

ipaccess-group101in

iphelper-address192.168.100.100

!

interfaceVlan150

ipaddress192.168.100.254255.255.255.0

iphelper-address192.168.100.100

noipredirects

!

interfaceVlan160

ipaddress192.168.115.254255.255.255.0

ipaccess-group100in

ipaccess-group100out

iphelper-address192.168.100.100

noipredirects

!

iproute0.0.0.00.0.0.0172.16.0.1

iphttprver

!

!

access-list100denyip192.168.115.00.0.0.255192.168.101.00.0.0.255

精选

access-list100denyip192.168.115.00.0.0.255192.168.102.00.0.0.255

access-list100denyip192.168.115.00.0.0.255192.168.103.00.0.0.255

access-list100denyip192.168.115.00.0.0.255192.168.104.00.0.0.255

access-list100denyip192.168.115.00.0.0.255192.168.105.00.0.0.255

access-list100denyip192.168.115.00.0.0.255192.168.106.00.0.0.255

access-list100denyip192.168.115.00.0.0.255192.168.107.00.0.0.255

access-list100denyip192.168.115.00.0.0.255192.168.108.00.0.0.255

access-list100denyip192.168.115.00.0.0.255192.168.110.00.0.0.255

access-list100denyip192.168.115.00.0.0.255192.168.111.00.0.0.255

access-list100denyip192.168.115.00.0.0.255192.168.112.00.0.0.255

access-list100denyip192.168.115.00.0.0.255192.168.113.00.0.0.255

access-list100denyip192.168.115.00.0.0.255192.168.100.00.0.0.255

access-list100permitipanyany

access-list101denyip192.168.112.00.0.0.255192.168.101.00.0.0.255

access-list101denyip192.168.112.00.0.0.255192.168.102.00.0.0.255

access-list101denyip192.168.112.00.0.0.255192.168.103.00.0.0.255

access-list101denyip192.168.112.00.0.0.255192.168.104.00.0.0.255

access-list101denyip192.168.112.00.0.0.255192.168.105.00.0.0.255

access-list101denyip192.168.112.00.0.0.255192.168.106.00.0.0.255

access-list101denyip192.168.112.00.0.0.255192.168.107.00.0.0.255

access-list101denyip192.168.112.00.0.0.255192.168.108.00.0.0.255

access-list101denyip192.168.112.00.0.0.255192.168.110.00.0.0.255

access-list101denyip192.168.112.00.0.0.255192.168.111.00.0.0.255

access-list101denyip192.168.112.00.0.0.255192.168.113.00.0.0.255

access-list101permitiphost192.168.112.100host192.168.100.103

access-list101permitiphost192.168.112.98192.168.100.00.0.0.255

access-list101denyip192.168.112.00.0.0.255192.168.100.00.0.0.255

access-list101permitipanyany

!

snmp-rvercommunitypjoeRW

snmp-rverenabletrapssnmpauthenticationlinkdownlinkupcoldstartwarmstart

snmp-rverenabletrapstty

snmp-rverenabletrapsvtp

snmp-rverenabletrapsvlancreate

snmp-rverenabletrapsvlandelete

snmp-rverenabletrapsstpx

snmp-rverenabletrapsrf

snmp-rverenabletrapsport-curity

snmp-rverenabletrapsconfig

snmp-rverenabletrapntity

snmp-rverenabletrapscputhreshold

snmp-rverenabletrapscopy-config

snmp-rverenabletrapsfru-ctrl

snmp-rverenabletrapsflashinrtionremoval

精选

snmp-rverenabletrapssyslog

snmp-rverenabletrapsbridge

snmp-rverenabletrapnvmonfanshutdownsupplytemperaturestatus

snmp-rverenabletrapshsrp

snmp-rverenabletrapsbgp

snmp-rverenabletrapsospfstate-change

snmp-rverenabletrapsospferrors

snmp-rverenabletrapsospfretransmit

snmp-rverenabletrapsospflsa

snmp-rverenabletrapsospfcisco-specificstate-change

snmp-rverenabletrapsospfcisco-specificerrors

snmp-rverenabletrapsospfcisco-specificretransmit

snmp-rverenabletrapsospfcisco-specificlsa

snmp-rverenabletrapspimneighbor-changerp-mapping-changeinvalid-pim-message

snmp-rverenabletrapsipmulticast

snmp-rverenabletrapsmsdp

snmp-rverenabletrapsrtr

snmp-rverenabletrapsvlan-membership

snmp-rverhost192.168.100.105pjoe

!

!

linecon0

password70E1419245E

stopbits1

linevty04

password7C245E580C0B

login

!

!

end

TEST

#TEST

#TEST

#TEST#shipintb#显示所有端口的状态

InterfaceIP-AddressOK?MethodStatusProtocol

FastEthernet1unassignedYESNVRAMdowndown

Vlan1192.168.113.254YESNVRAMupup

Vlan2172.16.0.2YESNVRAMupup

Vlan10192.168.101.254YESNVRAMupup

Vlan20192.168.102.254YESNVRAMupup

Vlan30192.168.103.254YESNVRAMupup

Vlan40192.168.104.254YESNVRAMupup

Vlan50192.168.105.254YESNVRAMupup

精选

Vlan60192.168.106.254YESNVRAMupup

Vlan70192.168.107.254YESNVRAMupup

Vlan80192.168.108.254YESNVRAMupup

Vlan100192.168.110.254YESNVRAMupup

Vlan110192.168.111.254YESNVRAMupup

Vlan120192.168.112.254YESNVRAMupup

Vlan150192.168.100.254YESNVRAMupup

Vlan160192.168.115.254YESNVRAMupup

GigabitEthernet1/1unassignedYESuntupup

GigabitEthernet1/2unassignedYESuntdowndown

GigabitEthernet1/3unassignedYESuntdowndown

GigabitEthernet1/4unassignedYESuntdowndown

GigabitEthernet1/5unassignedYESuntdowndown

GigabitEthernet1/6unassignedYESuntdowndown

GigabitEthernet1/7unassignedYESuntdowndown

GigabitEthernet1/8unassignedYESuntdowndown

GigabitEthernet1/9unassignedYESuntdowndown

GigabitEthernet1/10unassignedYESuntdowndown

GigabitEthernet1/11unassignedYESuntdowndown

GigabitEthernet1/12unassignedYESuntdowndown

GigabitEthernet1/13unassignedYESuntdowndown

GigabitEthernet1/14unassignedYESuntdowndown

GigabitEthernet1/15unassignedYESuntupup

GigabitEthernet1/16unassignedYESuntdowndown

GigabitEthernet1/17unassignedYESuntdowndown

GigabitEthernet1/18unassignedYESuntdowndown

GigabitEthernet1/19unassignedYESuntdowndown

GigabitEthernet1/20unassignedYESuntdowndown

GigabitEthernet3/1unassignedYESuntupup

GigabitEthernet3/2unassignedYESuntupup

GigabitEthernet3/3unassignedYESuntupup

GigabitEthernet3/4unassignedYESuntupup

GigabitEthernet3/5unassignedYESuntupup

GigabitEthernet3/6unassignedYESuntupup

GigabitEthernet3/7unassignedYESuntupup

GigabitEthernet3/8unassignedYESuntupup

GigabitEthernet3/9unassignedYESuntdowndown

GigabitEthernet3/10unassignedYESuntdowndown

GigabitEthernet3/11unassignedYESuntdowndown

GigabitEthernet3/12unassignedYESuntdowndown

GigabitEthernet3/13unassignedYESuntdowndown

GigabitEthernet3/14unassignedYESuntdowndown

GigabitEthernet3/15unassignedYESuntdowndown

GigabitEthernet3/16unassignedYESuntdowndown

精选

GigabitEthernet3/17unassignedYESuntupup

GigabitEthernet3/18unassignedYESuntupup

GigabitEthernet3/19unassignedYESuntupup

GigabitEthernet3/20unassignedYESuntupup

GigabitEthernet3/21unassignedYESuntupup

GigabitEthernet3/22unassignedYESuntupup

GigabitEthernet3/23unassignedYESuntupup

GigabitEthernet3/24unassignedYESuntupup

TEST

#TEST

#TEST#shvlan#显示所有的vlan信息

VLANNameStatusPorts

----------------------------------------------------------------------------

1defaultactiveGi1/2,Gi1/3,Gi1/4,Gi1/5,Gi1/6,Gi1/7,

Gi1/8,Gi1/9,Gi1/10,Gi1/11,Gi1/12,Gi1/13,Gi1/14,Gi1/16,Gi1/17,Gi1/18,Gi1/19,Gi1/20,

Gi3/12,Gi3/13,Gi3/14,Gi3/16

2firewallactiveGi1/1

10EngineeringactiveGi3/9,Gi3/10

20ProcurementactiveGi3/19

30QAQCactive

40Operationactive

50YardactiveGi3/18

60BMactive

70HRADactive

80Facilityactive

100Financeactive

110GOactive

120Wlanactive

150ServeractiveGi3/1,Gi3/2,Gi3/3,Gi3/4,Gi3/5,Gi3/6,

Gi3/7,Gi3/8

160ClientactiveGi3/11,Gi3/15

1002fddi-defaultact/unsup

1003token-ring-defaultact/unsup

1004fddinet-defaultact/unsup

1005trnet-defaultact/unsup

VLANTypeSAIDMTUParentRingNoBridgeNoStpBrdgModeTrans1Trans2

--------------------------------------------------------------------

1enet1000011500-----00

2enet1000021500-----00

10enet1000101500-----00

20enet1000201500-----00

30enet1000301500-----00

精选

40enet1000401500-----00

50enet1000501500-----00

60enet1000601500-----00

70enet1000701500-----00

80enet1000801500-----00

100enet1001001500-----00

110enet1001101500-----00

120enet1001201500-----00

150enet1001501500-----00

160enet1001601500-----00

1002fddi1010021500-----00

TEST

#TEST#shvtpsta#显示vtp协议的相关配置

VTPVersion:2

ConfigurationRevision:23

MaximumVLANssupportedlocally:1005

NumberofexistingVLANs:19

VTPOperatingMode:Server

VTPDomainName:pjoe

VTPPruningMode:Disabled

VTPV2Mode:Disabled

VTPTrapsGeneration:Enabled

MD5digest:0xEC0x300xEF0x6F0xA50x9A0x390x7B

Configurationlastmodifiedby192.168.113.254at12-3-0722:58:54

LocalupdaterIDis192.168.113.254oninterfaceVl1(lowestnumberedVLANinterfacefound)

TEST

#TEST

#TEST

#TEST

#TEST#shintgi1/2#显示具体物理接口的信息

GigabitEthernet1/2isdown,lineprotocolisdown(notconnect)

HardwareisGigabitEthernetPort,addressis001a.6db4.a3c1(bia001a.6db4.a3c1)

MTU1500bytes,BW1000000Kbit,DLY10uc,

reliability255/255,txload1/255,rxload1/255

EncapsulationARPA,loopbacknott

Keepalivet(10c)

Auto-duplex,Auto-speed,linktypeisauto,mediatypeis10/100/1000-TX

inputflow-controlisoff,outputflow-controlisoff

ARPtype:ARPA,ARPTimeout04:00:00

Lastinputnever,outputnever,outputhangnever

Lastclearingof"showinterface"countersnever

Inputqueue:0/2000/0/0(size/max/drops/flushes);Totaloutputdrops:0

精选

Queueingstrategy:fifo

Outputqueue:0/40(size/max)

5minuteinputrate0bits/c,0packets/c

5minuteoutputrate0bits/c,0packets/c

0packetsinput,0bytes,0nobuffer

Received0broadcasts(0multicast)

0runts,0giants,0throttles

0inputerrors,0CRC,0frame,0overrun,0ignored

0inputpacketswithdribbleconditiondetected

0packetsoutput,0bytes,0underruns

0outputerrors,0collisions,0interfacerets

0babbles,0latecollision,0deferred

0lostcarrier,0nocarrier

0outputbufferfailures,0outputbuffersswappedout

TEST

#TEST

#TEST#shiproute#显示这台交换机的所有路由信息

Codes:C-connected,S-static,R-RIP,M-mobile,B-BGP

D-EIGRP,EX-EIGRPexternal,O-OSPF,IA-OSPFinterarea

N1-OSPFNSSAexternaltype1,N2-OSPFNSSAexternaltype2

E1-OSPFexternaltype1,E2-OSPFexternaltype2,E-EGP

i-IS-IS,su-IS-ISsummary,L1-IS-ISlevel-1,L2-IS-ISlevel-2

ia-IS-ISinterarea,*-candidatedefault,U-per-urstaticroute

o-ODR,P-periodicdownloadedstaticroute

Gatewayoflastresortis172.16.0.1tonetwork0.0.0.0

C192.168.106.0/24isdirectlyconnected,Vlan60

C192.168.107.0/24isdirectlyconnected,Vlan70

C192.168.104.0/24isdirectlyconnected,Vlan40

C192.168.105.0/24isdirectlyconnected,Vlan50

C192.168.110.0/24isdirectlyconnected,Vlan100

C192.168.111.0/24isdirectlyconnected,Vlan110

C192.168.108.0/24isdirectlyconnected,Vlan80

172.16.0.0/30issubnetted,1subnets

C172.16.0.0isdirectlyconnected,Vlan2

C192.168.115.0/24isdirectlyconnected,Vlan160

C192.168.113.0/24isdirectlyconnected,Vlan1

C192.168.112.0/24isdirectlyconnected,Vlan120

C192.168.102.0/24isdirectlyconnected,Vlan20

C192.168.103.0/24isdirectlyconnected,Vlan30

C192.168.100.0/24isdirectlyconnected,Vlan150

C192.168.101.0/24isdirectlyconnected,Vlan10

S*0.0.0.0/0[1/0]via172.16.0.1

精选

TEST

#TEST

#TEST

#TEST#shprocesscpu#显示交换机的cpu利用率。当前是正常的。

CPUutilizationforfiveconds:11%/0%;oneminute:15%;fiveminutes:14%

PIDRuntime(ms)InvokeduSecs5Sec1Min5MinTTYProcess

14331210.00%0.00%0.00%0ChunkManager

23610715700.00%0.00%0.00%0LoadMeter

3761604750.00%0.00%0.00%0SpanTreeHelper

40100.00%0.00%0.00%0DeferredEvents

56793688133383520.00%0.11%0.11%0Checkheaps

60400.00%0.00%0.00%0PoolManager

70200.00%0.00%0.00%0Timers

80200.00%0.00%0.00%0SerialBackgroun

90100.00%0.00%0.00%0AAA_SERVER_DEADT

100200.00%0.00%0.00%0AAAhigh-capacit

110100.00%0.00%0.00%0PolicyManager

124893100.00%0.00%0.00%0IPCDynamicCach

130100.00%0.00%0.00%0IPCZoneManager

00.00%0.00%0.00%0IPCPeriodicTim

00.00%0.00%0.00%0IPCDeferredPor

160100.00%0.00%0.00%0IPCSeatManager

170100.00%0.00%0.00%0IFSAgentManage

18880.00%0.00%0.00%0ARPInput

.00%0.00%0.00%0EntityMIBAPI

200100.00%0.00%0.00%0SERIALA'detect

20.00%0.00%0.00%0DynamicARPInsp

22.00%0.00%0.00%0HCCounterTimer

230100.00%0.00%0.00%0CriticalBkgnd

242049969120.00%0.00%0.00%0NetBackground

2506100.00%0.00%0.00%0Logger

262.00%0.00%0.00%0TTYBackground

2758453657210.00%0.00%0.00%0Per-SecondJobs

28286590.00%0.04%0.00%0Per-minuteJobs

298227772422047441944.07%4.33%4.33%0Cat4kMgmtHiPri

38775612545.91%8.93%8.04%0Cat4kMgmtLoPri

3.00%0.00%0.00%0GaliosReschedul

3201100.00%0.00%0.00%0IOSACLHelper

330200.00%0.00%0.00%0NAMManager

34242120000.00%0.00%0.00%0rftask

3505900.00%0.00%0.00%0BACKCHECK

3610.00%0.00%0.00%0NetInput

3710.00%0.01%0.00%0Computeloadavg

380100.00%0.00%0.00%0chkptmessageha

精选

390200.00%0.00%0.00%0cpf_process_msg_

400100.00%0.00%0.00%0cpf_process_ipcQ

4101200.00%0.00%0.00%0AggMgrProcess

420100.00%0.00%0.00%0SFF8472

430400.00%0.00%0.00%0Collectionproce

PIDRuntime(ms)InvokeduSecs5Sec1Min5MinTTYProcess

440300.00%0.00%0.00%0CEFswitchingba

450200.00%0.00%0.00%0AAADictionaryR

460200.00%0.00%0.00%0AAAServer

470100.00%0.00%0.00%0AAAACCTProc

480100.00%0.00%0.00%0ACCTPeriodicPr

49379548.79%0.73%0.73%0SpanningTree

5200.00%0.01%0.00%0DTPProtocol

5185358000.00%0.00%0.00%0Ethchnl

5222453580200.00%0.00%0.00%0UDLD

534481500.00%0.00%0.00%0DHCPSnooping

544893000.00%0.00%0.00%0Port-Security

55219216.23%0.19%0.20%0IPInput

560100.00%0.00%0.00%0ICMPeventhandl

57159.00%0.02%0.00%0CDPProtocol

590300.00%0.00%0.00%0SNMPTimers

6.00%0.00%0.00%0CEFbackgroundp

620200.00%0.00%0.00%0XDRmcast

630100.00%0.00%0.00%0IPCLCMessageH

640100.00%0.00%0.00%0XDRRPPingBack

650449300.00%0.00%0.00%0XDRRPbackgroun

660100.00%0.00%0.00%0XDRRPTestBack

670100.00%0.00%0.00%0IPIRDP

689692813686110.07%0.07%0.07%0CEF:IPv4proces

6903700.00%0.00%0.00%0ADJbackground

7.00%0.00%0.00%0L2MM

710100.00%0.00%0.00%0MRD

721208981330.00%0.00%0.00%0IGMPSN

730100.00%0.00%0.00%0IGMPSN-HA

740100.00%0.00%0.00%0SocketTimers

750200.00%0.00%0.00%0L2TRACE

SERVER

761762477470.00%0.00%0.00%0TCPTimer

7712363330.00%0.00%0.00%0TCPProtocols

784230.00%0.02%0.00%0HTTPCORE

790100.00%0.00%0.00%0CHKPTEXAMPLE

800100.00%0.00%0.00%0CHKPTDevTest

810200.00%0.00%0.00%0ATIP_UDP_TSK

820100.00%0.00%0.00%0DHCPSnooping

精选

HA

830100.00%0.00%0.00%0ProbeInput

840100.00%0.00%0.00%0RARPInput

8523496788632970.00%0.00%0.00%0DHCPDReceive

8688911590.00%0.00%0.00%0IPBackground

8752893950.00%0.00%0.00%0IPRIBUpdate

880100.00%0.00%0.00%0COPS

890670000.00%0.00%0.00%0ClusterL2

9005358200.00%0.00%0.00%0ClusterRARP

PIDRuntime(ms)InvokeduSecs5Sec1Min5MinTTYProcess

910200.00%0.00%0.00%0LOCALAAA

920200.00%0.00%0.00%0AAACachedServe

930200.00%0.00%0.00%0TPLUS

940300.00%0.00%0.00%0RADIUSTESTCMD

950200.00%0.00%0.00%0AAASENDSTOPEV

9636.00%0.01%0.00%0PMCallback

9758017887320.00%0.00%0.00%0VLANManager

980446500.00%0.00%0.00%0DHCPDTimer

994123330.00%0.00%0.00%0VTPTrapProcess

1000200.00%0.00%0.00%0DHCPSecurityHe

1010100.00%0.00%0.00%0DiagCard1/-1

1020100.00%0.00%0.00%0DiagCard3/-1

1030100.00%0.00%0.00%0SyslogTraps

1040200.00%0.00%0.00%0VTPMIBEDITBUFF

1050500.00%0.00%0.00%0SPANswitch

1.00%0.00%0.00%0IPSNMP

1070700.00%0.00%0.00%0PDUDISPATCHER

1080700.00%0.00%0.00%0SNMPENGINE

1090100.00%0.00%0.00%0SNMPConfCopyPro

11.00%0.00%0.00%0SNMPTraps

1111.00%0.00%0.00%0DHCPDDataba

400.00%0.00%0.00%0Systempolling

5230.39%0.55%0.37%2VirtualExec

TEST

#TEST

#TEST

#TEST#reloa

TEST#reload#这条命令可重新启动交换机

Y#是否保存

回车#确定

TEST

#TEST#shver#显示当前设备的版本信息

CiscoIOSSoftware,Catalyst4000L3SwitchSoftware(cat4000-I9S-M),Version12.2(25)EWA8,

RELEASESOFTWARE(fc1)

精选

TechnicalSupport:/techsupport

Copyright(c)1986-2007byCiscoSystems,Inc.

CompiledWed24-Jan-0714:38bypwade

Imagetext-ba:0x10000000,data-ba:0x114EECF0

ROM:12.2(20r)EW1

DagobahRevision226,SwampRevision4

TESTuptimeis6days,4hours,50minutes

SystemreturnedtoROMbypower-on

Systemimagefileis"bootflash:"

ciscoWS-C4503(MPC8245)processor(revision4)with262144Kbytesofmemory.

ProcessorboardIDFOX104406TX

MPC8245CPUat267Mhz,SupervisorII+TS

LastretfromPowerUp

15VirtualEthernetinterfaces

44GigabitEthernetinterfaces

511Kbytesofnon-volatileconfigurationmemory.

Configurationregisteris0x2102

TEST#

本文发布于:2023-03-11 00:48:04,感谢您对本站的认可!

本文链接:https://www.wtabcd.cn/fanwen/zuowen/1678466885209212.html

版权声明:本站内容均来自互联网,仅供演示用,请勿用于商业和其他非法用途。如果侵犯了您的权益请与我们联系,我们将在24小时内删除。

本文word下载地址:思科交换机配置.doc

本文 PDF 下载地址:思科交换机配置.pdf

上一篇:治脚气偏方
下一篇:返回列表
相关文章
留言与评论(共有 0 条评论)
   
验证码:
推荐文章
排行榜
Copyright ©2019-2022 Comsenz Inc.Powered by © 专利检索| 网站地图