分布层交换机治理接口的设定步骤 1. 指定治理接口sc0的ip地址; 2. 指定治理接口所属的vlan,缺省为vlan1; 3. 指定治理接口的缺省网关。 sc0是Switch management interface 例如: set interface sc0 202.121.48.2 255.255.255.192 set interface sc0 vlan1 set ip route default 202.121.48.63 set interface sc0 up 可以归并为二条命令 set interface sc0 1 202.121.48.2 255.255.255.192 202.121.48.63 set interface sc0 up
显示sc0和sl0的当前配置 show interface sl1是将console port配置成通过slip可以治理交换,也需要设置ip地址以及目的ip地址。是一种带外治理(共两种:console port, slip-aux)。
流掩码(Flow Mask)模式 用来决定将数据包中多少信息放入MLS缓存中,而不是用来将数据包与MLS缓存中现有条目进行比较的。MLS-SE支持三种流掩码模式: 1. 目的IP(没有访问列表,缺省):最不具体的流掩码(The least specific flow mask mode)。 2. 源-目的IP(标准访问列表) 3. IP流(扩展访问列表):最具体的流掩码(The most specific flow mask mode )。 在mls-se上设置流掩码:set mls flow [destinationdestination-sourcefull]
The MLS-SE supports only one flow mask for all MLS-RP's connected to the MLS-SE. If the MLS-SE receives messages indicating different flow masks from different MLS-RP's the MLS-SE will set it's flow mask to the most specific flow mask. MLS-RP's running IOS 11.3 or later do not automatically support input access lists. To incorporate input access-lists the global configuration command 'mls rp ip input-acl' must be configured.
查看虚拟路由器的IP地址和MAC地址地两种方法: 1. show ip arp 2. show standby Ethernet3 - Group 1 Local state is Standby, priority 100 Hellotime 3 holdtime 10 Next hello sent in 00:00:00.898 Hot standby IP address is 202.121.49.251 configured Active router is 202.121.49.250 eXPires in 00:00:08 Standby router is local Standby virtual mac address is 0000.0c07.ac01 shtu-4500#
PIM DM非常有用的情形: 1. 发送方和接受访彼此接近(Source and receivers close together); 2. 发送方很少,接受方很多(Few sources and many receivers); 3. Multicast数据流的数量很大(High volume of multicast traffic); 4. Multicast数据流是经常性的(Constant multicast data streams)。
PIM SM非常有用的情形: 1. 在一个Multicast组中有较少的接受方(Few receivers in each group);
显示Multicast路由表实例: shtu-4500>sh ip mroute IP Multicast Routing Table Flags: D - Dense, S - Sparse, C - Connected, L - Local, P - Pruned R - RP-bit set, F - Register flag, T - SPT-bit set, J - Join SPT X - Proxy Join Timer Running Timers: Uptime/Expires Interface state: Interface, Next-Hop or VCD, State/Mode
访问控制列表应用In和Out ip access-group:可以应用于进入或外出的数据流上。In访问控制列表在数据包进入接口、选择路由之前,对它进行检查。Out访问控制列表在数据包选择路由之后,离开接口之前,对它进行检查。 Access-class:In指明谁可以Telnet到这台设备。Out指明当用户已登录到网络设备内部时可以Telnet到哪里。
端口安全设置和检查 1. 基于Set/CLI命令:set port security mod_num/port_num enable mac_address show port mod_num/port_num 2. 基于IOS命令: port secure [max-mac-count maxinum_mac_count] show mac-address-table security [type module/port] maxinum_mac_count缺省值132,范围1~132。 端口安全中进行MAC地址锁定有两种方式: 1. MAC地址的静态指定:治理员设置,比动态学习的更安全,但治理工作量大。 2. MAC地址的动态学习:在端口上第一个源MAC地址成为安全MAC地址。
SPAN Cisco switches have a Switched Port Analyzer (SPAN) feature enables you to monitor traffic on any port for analysis by a network analyzer device or RMON probe. 显示SPAN信息 show span
填空题!by default,the catalyst switch software sends error messages to the console terminal enter the command you would use to check for error message if they are redirected to another destination.