H3C路由器基本配置命令大全

发布时间:2019-08-07 05:30:00 编辑:培训基地 手机版

  H3C路由器基本配置命令有哪些?下面跟yjbys小编一起来学习一下吧!

  [Quidway]displayversion 显示版本信息

  [Quidway]displaycurrent-configuration 显示当前配置

  [Quidway]displayinterfaces 显示接口信息

  [Quidway]displayip route 显示路由信息

  [Quidway]sysnameaabbcc 更改主机名

  [Quidway]superpasswrod 123456 设置口令

  [Quidway]interfaceserial0 进入接口

  [Quidway-serial0]ipaddress

  [Quidway-serial0]undoshutdown 激活端口

  [Quidway]link-protocolhdlc 绑定hdlc协议

  [Quidway]user-interfacevty 0 4

  [Quidway-ui-vty0-4]authentication-modepassword

  [Quidway-ui-vty0-4]setauthentication-mode password simple 222

  [Quidway-ui-vty0-4]userprivilege level 3

  [Quidway-ui-vty0-4]quit

  [Quidway]debugginghdlc all serial0 显示所有信息

  [Quidway]debugginghdlc event serial0 调试事件信息

  [Quidway]debugginghdlc packet serial0 显示包的信息

  静态路由:

  [Quidway]iproute-static {interfacenumber|nexthop}[value][reject|blackhole]

  例如:

  [Quidway]iproute-static 129.1.0.0 16 10.0.0.2

  [Quidway]iproute-static 129.1.0.0 255.255.0.0 10.0.0.2

  [Quidway]iproute-static 129.1.0.0 16 Serial 2

  [Quidway]iproute-static 0.0.0.0 0.0.0.0 10.0.0.2

  动态路由:

  [Quidway]rip

  [Quidway]rip work

  [Quidway]rip input

  [Quidway]ripoutput

  [Quidway-rip]network1.0.0.0 ;可以all

  [Quidway-rip]network2.0.0.0

  [Quidway-rip]peerip-address

  [Quidway-rip]summary

  [Quidway]ripversion 1

  [Quidway]ripversion 2 multicast

  [Quidway-Ethernet0]ripsplit-horizon ;水平分隔

  [Quidway]router idA.B.C.D 配置路由器的ID

  [Quidway]ospfenable 启动OSPF协议

  [Quidway-ospf]import-routedirect 引入直联路由

  [Quidway-Serial0]ospfenable area 配置OSPF区域

  标准访问列表命令格式如下:

  acl [match-order config|auto] 默认前者顺序匹配。

  rule[normal|special]{permit|deny} [source source-addr source-wildcard|any]

  例:

  [Quidway]acl 10

  [Quidway-acl-10]rulenormal permit source 10.0.0.0 0.0.0.255

  [Quidway-acl-10]rulenormal deny source any

  扩展访问控制列表配置命令

  配置TCP/UDP协议的扩展访问列表:

  rule{normal|special}{permit|deny}{tcp|udp}source {|any}destination|any}

  [operate]

  配置ICMP协议的扩展访问列表:

  rule{normal|special}{permit|deny}icmp source {|any]destination{|any]

  [icmp-code][logging]

  扩展访问控制列表操作符的含义

  equalportnumber 等于

  greater-thanportnumber 大于

  less-thanportnumber 小于

  not-equalportnumber 不等

  range portnumber1portnumber2 区间

  扩展访问控制列表举例

  [Quidway]acl 101

  [Quidway-acl-101]ruledeny souce any destination any

  [Quidway-acl-101]rulepermit icmp source any destination any icmp-type echo

  [Quidway-acl-101]rulepermit icmp source any destination any icmp-type echo-reply

  [Quidway]acl 102

  [Quidway-acl-102]rulepermit ip source 10.0.0.1 0.0.0.0 destination 202.0.0.1 0.0.0.0

  [Quidway-acl-102]ruledeny ip source any destination any

  [Quidway]acl 103

  [Quidway-acl-103]rulepermit tcp source any destination 10.0.0.1 0.0.0.0 destination-port equal ftp

  [Quidway-acl-103]rulepermit tcp source any destination 10.0.0.2 0.0.0.0 destination-port equal www

  [Quidway]firewallenable

  [Quidway]firewalldefault permit|deny

  [Quidway]int e0

  [Quidway-Ethernet0]firewallpacket-filter 101 inbound|outbound

  地址转换配置举例

  [Quidway]firewallenable

  [Quidway]firewalldefault permit

  [Quidway]acl 101

  [Quidway-acl-101]ruledeny ip source any destination any

  [Quidway-acl-101]rulepermit ip source 129.38.1.4 0 destination any

  [Quidway-acl-101]rulepermit ip source 129.38.1.1 0 destination any

  [Quidway-acl-101]rulepermit ip source 129.38.1.2 0 destination any

  [Quidway-acl-101]rulepermit ip source 129.38.1.3 0 destination any

  [Quidway]acl 102

  [Quidway-acl-102]rulepermit tcp source 202.39.2.3 0 destination 202.38.160.1 0

  [Quidway-acl-102]rulepermit tcp source any destination 202.38.160.1 0 destination-port great-than

  1024

  [Quidway-Ethernet0]firewallpacket-filter 101 inbound

  [Quidway-Serial0]firewallpacket-filter 102 inbound

  [Quidway]nataddress-group 202.38.160.101 202.38.160.103 pool1

  [Quidway]acl 1

  [Quidway-acl-1]rulepermit source 10.110.10.0 0.0.0.255

  [Quidway-acl-1]ruledeny source any

  [Quidway-acl-1]intserial 0

  [Quidway-Serial0]natoutbound 1 address-group pool1

  [Quidway-Serial0]natserver global 202.38.160.101 inside 10.110.10.1 ftp tcp

  [Quidway-Serial0]natserver global 202.38.160.102 inside 10.110.10.2 www tcp

  [Quidway-Serial0]natserver global 202.38.160.102 8080 inside 10.110.10.3 www tcp

  [Quidway-Serial0]natserver global 202.38.160.103 inside 10.110.10.4 smtp udp

  PPP验证:

  主验方:pap|chap

  [Quidway]local-useru2 password {simple|cipher} aaa

  [Quidway]interfaceserial 0

  [Quidway-serial0]pppauthentication-mode {pap|chap}

  [Quidway-serial0]pppchap user u1 //pap时,不用此句

  pap被验方:

  [Quidway]interfaceserial 0

  [Quidway-serial0]ppppap local-user u2 password {simple|cipher} aaa

  chap被验方:

  [Quidway]interfaceserial 0

  [Quidway-serial0]pppchap user u1

  [Quidway-serial0]local-useru2 password {simple|cipher} aaa

本文已影响0
+1
0