1、Cisco 和华为路由器、交换机命令对比建立用户:Router(config)# username aaa password cisco quidwaylocal-user aaa启动 VTY 验证:Router(config)#line vty 0 4quidwayuser-interface vty 0 4选择验证类型:Router(config-line)#login authenticationquidway-ui-vty0-4authentication-modeVLAN:Switch(config)#vlan 10 name salequidwayvlan 10将端口加入 vlan
2、:Switch(config-if)#switchport access vlan 10quidway-ethernet0/10port access vlan 10将端口设置为 trunk,允许所有 vlan 通过:Switch(config-if)#switchport mode trunkSwitch(config-if)#switchport trunk allowed vlan allquidway-ethernet0/20port link-type trunkquidway-ethernet0/20port trunk permit vlan all配置动态 vlan 发现协议:
3、Switch (config)#vtp mode serverSwitch (config)#vtp domain ciscoquidwaygvrp enable配置端口汇聚:Switch(config-range)#interface range fastethernet 0/2quidwaylink-aggregation group 1 mode manual 先建立聚合组,再把端口加里面广域网协议配置:ppp 的 pap 验证:router1(config-if)#encapsulation ppprouter1(config-if)#ppp authentication paprou
4、ter1(config-if)#ppp pap sent-username chen password ciscoquidway-serial0/1link-protocol pppquidway-serial0/1 ppp authentication-mode papquidway-serial0/1 ppp pap local-user chen password simple cisco帧中继配置:router1(config)#frame-relay switchingrouter1(config-if)#frame-relay map ip 215.10.1.2 105 broad
5、castrouter1(config-if)#frame-relay lmi-type ansiquidwayfr switchingquidway-serial0/1fr map ip 215.10.1.1 dlci 501路由协议配置:静态路由:router1(config)#ip route 192.168.1.1 255.255.255.0 s0quidwayip route-static 192.168.1.1 255.255.255.0 s0RIP:router1(config)#router riprouter1(config-router)#version 2router1(c
6、onfig-router)#no auto-summaryrouter1(config-router)#network 192.168.1.0quidwayripquidway-serial0/1rip version 2 华为路由器是在接口模式下开启 V2 版本quidway-ripundo summaryquidway-rip network 192.168.1.0OFPF:router1(config)#router ospf 1-65535router1(config-router)#network 192.168.1.0 0.0.0.255 area 0quidwayospfquid
7、way-ospf-1area 0quidway-ospf-1-area-0.0.0.0 network 192.168.1.0 0.0.0.255NAT:router1(config)#ip nat inside source static 192.168.1.1 10.1.1.1router1(config-if)#ip nat inside/outsidequidway-serial0/1nat server protocol tcp global 202.10.1.150 inside 192.168.1.1 将内部 ip 转成外部 ip 地址访问控制列表:cisco 基本访问列表数字标
8、识:1-99,扩展访问列表是 100199;华为基本访问列表数字标识20002999,扩展访问列表是 30003999基本访问列表:router1(config)#access-list 1 permit 10.1.1.0 0.0.0.255quidwayacl number 2000quidway-acl-2000rule permit source 192.168.1.0 0.0.0.255扩展访问列表:router1(config)#access-list 100 permit tcp 192.168.1.0 0.0.0.255 any eq telnetquidwayacl number 3000quidway-acl-adv-3000rule permit tcp source 192.168.1.0 0.0.0.255 destination any eq telnet应用访问控制列表:router1(config-if)#ip access-group 1 out/inquidwayfirewall enable 开启防火墙quidway-serial0/1firewall packet-filter 3000 inbound/outbound