跳到主要內容

發表文章

目前顯示的是有「網路相關」標籤的文章

使用Draytek VigorAP 810內建的Radius驗證

VigorAP 810設定 手機連線 Windows 10連線

ASUS AC66U 新增SNMP功能

在官方的Firmware版本中沒有SNMP的功能,若需要開啟SNMP需要刷第三方的Firmware,我是安裝Asuswrt-Merlin的版本,更新方式也很簡單,與更新官方的版本相同,網站如下: http://asuswrt.lostrealm.ca/ 更新完成後除了有SNMP的功能外,也會多出一些不錯用的功能

2台 Vigor 2920建立 LAN To LAN VPN (IPsec)

我有兩台Vigor 2920,環境如下: Vigor B 撥出 LAN:192.168.1.0/24 Vigor A 撥入 LAN:172.16.1.0/24 設定如下: Vigor B設定 Vigor A設定 詳細設定請參考官網 http://www.draytek.com/index.php?option=com_k2&view=item&id=2666&Itemid=264&lang=tw

Juniper EX2200 Show Port上面的Mac-address

root@EX2200-113> show ethernet-switching table Ethernet-switching table: 147 entries, 143 learned, 0 persistent entries   VLAN              MAC address       Type         Age Interfaces   default           64:64:9b:34:TT:TT Static         - Router   vlan1             *                 Flood          - All-members   vlan1             ac:a0:16:91TT:TT Learn          0 ge-0/0/47.0   vlan10            *                 Flood          - All-members   vlan10            00:00:1c:d1:TT:TT Learn          0 ge-0/0/47.0   <---以下略過---> ...

Cisco Switch Drop Mac-address

Wiershark在抓封包的時候,一直抓到0x8899的Protocol,查了一下發現這個是Realtek用來偵測Loop的協定 因為我上層已經有開啟STP,所以我就下參數把該Mac-Address給Drop掉 2F-Switch(config)# mac address-table static 2828.5db3.cb39 vlan 1 drop 指令參考來源 註: 如果要新增某Mac-address也可以下這個指令 Switch(config)# mac-address-table static 1111.1111.1111 vlan 1 interface fastEthernet 0/1 Switch#show mac-address-table           Mac Address Table ------------------------------------------- Vlan    Mac Address       Type        Ports ----    -----------       --------    -----    1    1111.1111.1111    STATIC      Fa0/1

Juniper EX2200 消除 Management Ethernet Link Down 告警

公司新買的Juniper EX2200一直出現Alerm的告警,進到Web畫面後出現是Management Ethernet Down,查了一下解決方式 root@EX2200-2> show chassis alarms 1 alarms currently active Alarm time               Class  Description 2014-03-13 09:44:37 UTC  Major  Management Ethernet Link Down {master:0} root@EX2200-2> configure Entering configuration mode {master:0}[edit] root@EX2200-2# set chassis alarm management-ethernet link-down ignore {master:0}[edit] root@EX2200-2# commit configuration check succeeds commit complete {master:0}[edit] root@EX2200-2# exit Exiting configuration mode {master:0} root@EX2200-2> show chassis alarms No alarms currently active 參考資料

Brocade ICX6430 Switch 啟用 DHCP Snooping

Brocade ICX6430 Switch 啟用 DHCP Snooping 假設我的DHCP Server接在24 Port,其他Port不允許有DHCP Server ICX6430-24 Switch> enable No password has been assigned yet... ICX6430-24 Switch# configure terminal ICX6430-24 Switch(config)# ip dhcp snooping vlan 1 ICX6430-24 Switch(config)# interface ethernet 1/1/24 ICX6430-24 Switch(config-if-e1000-1/1/24)# dhcp snooping trust 預設Spanning Tree是開啟的,我把Port 9與Port 11接成Loop ICX6430-24 Switch# show span STP instance owned by VLAN 1 Global STP (IEEE 802.1D) Parameters:      Root             Root Root   Prio Max He- Ho- Fwd Last    Chg Bridge       ID              Cost Port   rity Age llo ld  dly Chang   cnt Address                                   Hex  sec sec sec sec sec      8000cc4e2434dda0 0    Root ...

Cisco Switch EtherChannel

兩個Cisco 2950 Switch , 第一台與第二台的Port 1 與 Port 2 對連,設定EtherChannel 第一台Switch up# configure terminal Enter configuration commands, one per line.  End with CNTL/Z. up(config)# interface range fastEthernet 0/1 - 2 up(config-if-range)# no ip address up(config-if-range)# channel-group 1 mode desirable Creating a port-channel interface Port-channel 1 第二台Switch down# configure terminal Enter configuration commands, one per line.  End with CNTL/Z. down(config)# interface range fastEthernet 0/1 - 2 down(config-if-range)# no ip address down(config-if-range)# channel-group 1 mode desirable Creating a port-channel interface Port-channel 1 down(config-if-range)# 00:34:30: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to down 00:34:30: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/2, changed state to down 00:34:33: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to up 00:34:...

Cisco Switch 啟用 DHCP Snooping

啟動DHCP Snooping 假設我的DHCP Server接在24 Port,其他Port不允許有DHCP Server C3750(config)# ip dhcp snooping C3750(config)# ip dhcp snooping vlan 1 C3750(config)# interface gigabitEthernet 2/0/24 C3750(config-if)# ip dhcp snooping trust C3750(config-if)# do show ip dhcp snooping Switch DHCP snooping is enabled DHCP snooping is configured on following VLANs: 1 DHCP snooping is operational on following VLANs: 1 DHCP snooping is configured on the following L3 Interfaces: Insertion of option 82 is enabled    circuit-id default format: vlan-mod-port    remote-id: 0016.9d99.3e80 (MAC) Option 82 on untrusted port is not allowed Verification of hwaddr field is enabled Verification of giaddr field is enabled DHCP snooping trust/rate is configured on the following Interfaces: Interface                  Trusted    Allow option    Rate limit (pps) -----------------------    -------   ...

HP A5120 Switch 基本設定

沒用過HP的Switch,指令跟Cisco完全不同,花了一些時間熟悉~ 1.啟動Spanning-Tree,預設沒有開啟 (黑色粗體是我敲的指令) <HP> system-view System View: return to User View with Ctrl+Z. [HP] stp enable [HP] %Apr 26 12:03:59:826 2000 HP MSTP/6/MSTP_ENABLE: STP is now enabled on the device. %Apr 26 12:03:59:918 2000 HP MSTP/6/MSTP_FORWARDING: Instance 0's GigabitEthernet1/0/17 has been set to forwarding state. %Apr 26 12:04:00:068 2000 HP MSTP/6/MSTP_DETECTED_TC: Instance 0's GigabitEthernet1/0/17 detected a topology change. #Apr 26 12:04:00:208 2000 HP MSTP/1/PFWD: hwPortMstiStateForwarding: Instance 0's Port 0.9437200 has been set to forwarding state! 2.DHCP Snooping   (黑色粗體是我敲的指令) 假設我的DHCP Server接在24 Port,其他Port不允許有DHCP Server <HP> system-view System View: return to User View with Ctrl+Z. [HP] dhcp-snooping  DHCP Snooping is enabled. [HP] interface GigabitEthernet 1/0/24 [HP-GigabitEthernet1/0/24 ]dhcp-snooping trust 若是沒有Port 設成dhcp-snooping trust,那麼這台Switch就沒有Client可以從DHCP Serv...

國外ISP的SMTP Server

老闆出國兩個禮拜,一大早寄信告知不能寄信,提醒他使用非公司網路寄信要驗證,順便給他一張國外ISP業者的SMTP Server清單 http://www.host45.com/resources/ispsmtps.php 希望他一切順利 ^^

Edge-Core ES4524D

Edge-Core ES4524D的Web 介面 進入CLI介面,居然還有startup-config.... 嚇死我了!!! 還是不要花太多時間看這台,手上還有Cisco ASA和L3的Switch要花點時間摸熟.....

Cisco 修改Register,控制開機流程

Router(config)# config-register 0x2100 可以帶的參數為16進位值 0x2100 進入Rom Monitor 0x2101 進入MiniIOS 0x2102~210F 正常進入IOS 0x2142 忽略Starup-config Show version可以查目前的Register值 ================================================================== Router# show version  Cisco IOS Software, 2800 Software (C2800NM-ADVIPSERVICESK9-M), Version 12.4(15)T1, RELEASE SOFTWARE (fc2) Technical Support: http://www.cisco.com/techsupport Copyright (c) 1986-2007 by Cisco Systems, Inc. Compiled Wed 18-Jul-07 06:21 by pt_rel_team ROM: System Bootstrap, Version 12.1(3r)T2, RELEASE SOFTWARE (fc1) Copyright (c) 2000 by cisco Systems, Inc. System returned to ROM by power-on System image file is "c2800nm-advipservicesk9-mz.124-15.T1.bin" This product contains cryptographic features and is subject to United States and local country laws governing import, export, transfer and use. Delivery of Cisco cryptographic products does not imply third-party authority to import, export, distribute or u...

Cisco 2950 Switchport Protected

Port 設定Protected,將有類似 Port-isolation 的功能(類似切Portbase VLAN),原本想用Packet Tracer試的,但模擬的2950裡沒有這個功能,所以在實體的Switch上設定 Port 1~23 互相都不通,但Port 1~23與Port 24通 ====設定方法==== 進到CLI模式下: Switch# configure terminal Enter configuration commands, one per line.  End with CNTL/Z. Switch(config)# interface range fa 0/1 - 23 Switch(config-if-range)# switchport protected 參考文件 其實我還想實作每個Port限制流量,不過這個就留在下次,有興趣的人可以 參考這篇

Port-Security (暫)

Switch(config-if)#switchport port-security Command rejected: FastEthernet0/2 is a dynamic port. Switch(config-if)#switchport mode access Switch(config-if)#switchport port-security Switch(config-if)#switchport port-security maximum 1 Switch(config-if)#switchport port-security mac-address sticky Switch(config-if)#switchport port-security violation restrict Switch(config-if)#switchport port-security violation ?   protect   Security violation protect mode   restrict  Security violation restrict mode   shutdown  Security violation shutdown mode Switch#show port-security Secure Port  MaxSecureAddr  CurrentAddr  SecurityViolation  Security Action                 (Count)       (Count)          (Count) ---------------------------------------------------------------------------       Fa0/2             ...

設定Console密碼

Switch> enable Switch# configure terminal Enter configuration commands, one per line.  End with CNTL/Z. Switch(config)# line console 0 Switch(config-line)# password cisco Switch(config-line)# login 設定Privileged Mode的密碼 switch(config)# enable password cisco (未加密) switch(config)# enable secret sanjose  (加密) 加密的密碼會蓋過未加密的,所以進入Privileged Mode的密碼要打sanjose 

Cisco ISO(Internet Operating System) CLI (簡)

                      enable                          configure terminal User Mode --------------> Privileged Mode ----------------------> Global Configuration Mode                       Disable                                       exit                      User Mode <-------------- Privileged Mode <---------------------- Global Configuration Mode 大致上有這幾種mode,不過還是有其他Mode ex: Line Configure Mode  ,  Interface Configure Mode...... 官方介紹 Cisco IOS 的檔案格式:IFS(Cisco IOS File System)

TCP/IP 網路協定架構

TCP/IP --------------------------------------------------------------------------------------- Application                              [DATA]      (Data) --------------------------------------------------------------------------------------- Transport                                [TCP][DATA]     (Segment)    (若使用TCP傳輸) --------------------------------------------------------------------------------------- Internet                                   [IP][TCP][DATA]      (Packet) --------------------------------------------------------------------------------------- Network Access                     [Eth.][IP][DATA][Eth.]     (Fr...

Cacti 抓SSG5相關資訊

不是小廠的設備,通常Cacti都有樣版可以抓取,直接套入就可以抓一些資訊! 我下一個想抓的是Cacti Server的一些效能資訊