跳到主要內容

發表文章

Macbook Pro 2014年版本更換1TB SSD

買了幾年的M.2 NGFF轉卡與Intel 660P 1TB SSD終於有時間更換了! 更換方式大致上是先看下方三篇的說明,更換流程簡述如下: 1. 使用Carbon Copy Clone將原硬碟Clone到Intel 660P 1TB的SSD 2. 取下舊的256G SSD 3. 將Intel 660P 1TB裝上M.2 NGFF轉卡後,裝上Macbook Pro 4. 開機後完成 目前是覺得開機有慢一點,其他程式第一次啟動會需要驗證外,大致上都還沒有遇到太多問題.... 以上是這次的更換記錄~ PS:OS的版本為  Catalina https://www.mobile01.com/topicdetail.php?f=481&t=5766510 https://mrmad.com.tw/macbook-pro-2014-nvme-ssd-upgrade https://mrmad.com.tw/carbon-copy-cloner

Unifi Dream Machine Pro手動更新Firmware

更新方式可以參考Unfi官方網頁 https://help.ui.com/hc/en-us/articles/360050974234-UniFi-UDM-UDM-Pro-Firmware-Upgrade-Troubleshooting 使用SSH登入DMP之後,更新指今為方式為ubnt-upgrade 後面再加上Firmware的路徑,例如我從1.9.1更新到1.9.2就是使用以下的指令 ubnt-upgrade https://fw-download.ubnt.com/data/udm/7f12-udmpro-1.9.2-aeebd99ac03645028ec567e5fe4a2238.bin 更新後會自動重開機!! 03.27 後記 睡一覺起來發現除了DMP之外,AP/Switch 會都在Adopting,但終端連線設備皆正常..... 只好等新版的Firmware解決了~ 1.9.x Issue List 04.06 後記 更新到1.9.3 之後,其他設備都回來了,唯獨一台AP一直離線又Adopting,重開AP無效後,下了以下指令就恢復了.... set-inform http://UDP IP:8080/inform https://community.ui.com/releases/UniFi-Dream-Machine-Firmware-1-9-3/c0eef9ce-8bc8-4324-bc5a-dd6ad8520ee0 幾個指令記錄 佈署AP set-inform http://x.x.x.x:8080/inform 重設AP sudo syswrapper.sh restore-default 更新UDM Firmware ubnt-upgrade Firmware網址 重開AP reboot

Draytek Vigor 2927

其實心中一直感覺用了十年的Vigor 2920n會掛掉,因為先前也有一台2920n壞過,所以心中也有個底,但突然壞了也真讓人心驚驚! 其實最近都在用Unifi的設備,但考量目前的工作環境與網路需求,就直接更換最新的Vigor 2927,雖然2920n的備份檔不能直接倒回去,不過之前的設定參數都有抓圖下來,所以很快就把設定設回去,這也算是用習慣Draytek的好處~ 下一篇會說明怎麼建立Unifi Dream Machine Pro與Vigor 2927的Site To Site VPN。

Cisco的網路容錯機制 (Ethernet Channel,HSRP)

架構圖如下 (有空再加說明) 目標: 希望Router故障一台或是Switch故障一台,不會影響Server的正常運作 說明: 沒有時間改設備的設定,就找了幾台實體機來做LAB。 * 2台Cisco 2811/2821 做HSRP, * 2台Switch做Ethernet Channel * Server網卡做Teaming 原本LAB是要用Router撥接PPPOE VDSL測HSRP,不過一直會遇到這2個問題 %IP_VFR-4-FRAG_TABLE_OVERFLOW: Dialer1: the fragment table has reached its maximum threshold 16 %IP_VFR-3-OVERLAP_FRAGMENTS: Dialer1: from the host x.x.x.x destined to x.x.x.x 然後上網一直不正常,後來就放棄使用PPOE撥接,改在Router的前端接了一台DrayTek 2925做撥接的動作,然後2台Router的 FA 0/0設DrayTek Lan網站的IP,並設Default Route到DrayTek 2925的IP上網 Cisco 2821設定 HSRP的Virtual IP為192.168.10.254 hostname R2821 ! boot-start-marker boot-end-marker ! ! ! no aaa new-model ! ! dot11 syslog ip source-route ! ! ip cef ! ! ! no ip domain lookup ! multilink bundle-name authenticated ! ! crypto pki token default removal timeout 0 ! ! ! ! license udi pid CISCO2821 sn FHK1118F2KL ! redundancy ! ! ! ! ! ! ! ! ! interface GigabitEthernet0/0  ip address 192.168.1.119 255.255....

使用Draytek VigorAP 810內建的Radius驗證

VigorAP 810設定 手機連線 Windows 10連線

Hyper-V設定VLAN

~~考題~~ 題目如下: Hyper-V的Server,裡面有2台VM(原本還有做AD Domain,DFS,DNS,在這裡就先略過),分別為Win2012與Win7,都是全新安裝的狀態 ,而Hyper-V的Server接在L2 Switch的FA 0/1,要做以下設定 *VM1: Windows 2012 R2(DHCP) IP:192.168.199.100/24 GW:192.168.199.254 DHCP Server 發放IP範圍 192.168.200.30~192.168.200.100 *VM2: Windows7(自動取得IP) 要取得192.168.200.0/24網段的IP Switch: L3 Switch要做VLAN的Routing 反正最後就是要Win7可以取得IP,並且Ping到Server 解答: L2 Switch設定: 新增VLAN 199,200 要確認Port FA 0/1, FA 0/24 有沒有形成Trunk L3 switch設定: (中間有一些設定已略過) Core-3750# show running-config Building configuration... Current configuration : 4114 bytes ! -----------中間略過-------------------------- ! ! ! ! no aaa new-model switch 1 provision ws-c3750g-24t system mtu routing 1546 ip routing no ip domain-lookup ! vlan internal allocation policy ascending ! ! ! ! interface GigabitEthernet1/0/1  switchport trunk encapsulation dot1q  switchport mode trunk ! -----------中間略過-------------------------- ! interface Vlan1  no ip addres...

Cisco Switch 發生Loopback

User告知網路無法使用,看了Switch的狀況後,發現那個Port的狀態是Error Disable,接著又看了Switch的log Feb  8 12:14:14 TW: %DHCP_SNOOPING-5-DHCP_SNOOPING_UNTRUSTED_PORT: DHCP_SNOOPING drop message on untrusted port, message type: DHCPNAK, MAC sa: 2c56.dc86.xxxx Feb  8 12:15:49 TW: %DHCP_SNOOPING-5-DHCP_SNOOPING_UNTRUSTED_PORT: DHCP_SNOOPING drop message on untrusted port, message type: DHCPNAK, MAC sa: 2c56.dc86.xxxx Feb  8 12:18:00 TW: %ETHCNTR-3-LOOP_BACK_DETECTED: Keepalive packet loop-back detected on FastEthernet0/10. Feb  8 12:18:00 TW: %PM-4-ERR_DISABLE: loopback error detected on Fa0/10, putting Fa0/10 in err-disable state Feb  8 12:18:01 TW: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/10, changed state to down Feb  8 12:18:02 TW: %LINK-3-UPDOWN: Interface FastEthernet0/10, changed state to down 應該是User私接設備,除了造成Loopback之外,又在隨便發放IP....... 不過因為那個User比較特殊,先教育了一下之後,再把那個Port shutdown , no shutdown,接著把Recovery設了上去,下次如果再遇到相同狀況,10分鐘後會自動恢復 xxx...

ASUS AC66U 新增SNMP功能

在官方的Firmware版本中沒有SNMP的功能,若需要開啟SNMP需要刷第三方的Firmware,我是安裝Asuswrt-Merlin的版本,更新方式也很簡單,與更新官方的版本相同,網站如下: http://asuswrt.lostrealm.ca/ 更新完成後除了有SNMP的功能外,也會多出一些不錯用的功能

使用Cisco L3 Switch做VLAN的Routing

目標: 讓VLAN100與VLAN200的電腦透過L3 Swtich做VLAN的Routing,並且可以互相存取資源與上網,另外再使用Windows Server 2012配發VLAN100,VLAN200的IP Firewall: 使用ASUS AP當Firewall,並設兩條Static Route Switch: Core Switch為Cisco 3750切VLAN 10,VLAN100,VLAN200,VLAN10為預設的VLAN,VLAN100為Sales,VLAN200為RD Edge Switch為Cisco 3750與2950,其中2950為VLAN100,3750為VLAN200,如果要By Port切VLAN也可以,這裡只是為了方便說明,所以Edge Switch都直接設為單一VLAN Core Switch的設定 原本我只想Show Running-config其中比較重要的設定,後來想想還是全部列出,用紅色標記重要的設定 Gi 1/0/1接2950 Gi 1/0/2接3750 Gi 1/0/24接Router Core-3750#show running-config Building configuration... Current configuration : 2436 bytes ! version 12.2 no service pad service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption ! hostname Core-3750 ! boot-start-marker boot-end-marker ! ! ! ! no aaa new-model switch 1 provision ws-c3750g-24t system mtu routing 1546 ip routing no ip domain-lookup ! ! ! ! ! ! ! ! spanning-tree mode pvst spanning-tree portfas...

Router on a Stick

目標: PC1為VLAN 66,PC2為VLAN 1,PC3為VLAN88 使用Router on a stick,讓VLAN裡的PC可以互通,同時也可以連到設在Switch VLAN1的IP ====Switch設定==== SW(config)#ip default-gateway 10.1.1.254 SW(config)#interface VLAN 1 SW(config-if)#ip address 10.1.1.1 255.255.255.0 SW(config-if)#no shutdown SW(config)#interface range fastEthernet 0/1-10 SW(config-if-range)#switchport access vlan 66 SW(config)#interface range fastEthernet 0/14-24 SW(config-if-range)#switchport access vlan 88 SW(config)#interface fastEthernet 0/12 SW(config-if)#switchport mode trunk SW(config-if)#^Z SW#show vlan brief VLAN Name                             Status    Ports ---- -------------------------------- --------- ------------------------------- 1    default                   ...

Cisco Router 密碼重設

密碼猜了半天也進不去 CISCO2811> enable Password: Password: Password: % Bad secrets Reload手動重開機,然後按下 Ctrl+Break 鍵,強迫進入Rom Monitor CISCO2811>enable Password: Password: Password: % Bad secrets program load complete, entry point: 0x8000f000, size: 0x3ed1338 Self decompressing the image : ############# monitor: command "boot" aborted due to user interrupt rommon 2 > confreg 0x2142 rommon 3 > reset System Bootstrap, Version 12.1(3r)T2, RELEASE SOFTWARE (fc1) Copyright (c) 2000 by cisco Systems, Inc. Initializing memory for ECC .. c2811 processor with 524288 Kbytes of main memory Main memory is configured to 64 bit mode with ECC enabled Readonly ROMMON initialized program load complete, entry point: 0x8000f000, size: 0xc940 program load complete, entry point: 0x8000f000, size: 0xc940 program load complete, entry point: 0x8000f000, size: 0x3ed1338 Self decompressing the image : ############################...