SlideShare uma empresa Scribd logo
1 de 57
Switch-ийн тохиргоо



© 2004, Cisco Systems, Inc. All rights reserved.   1
Starting the Switch


 Switches:
 • Хостын холбоход зориулагдсан хэд хэдэн
   оролттой
 • Мөн тусгай зориулалтын оролттой
 • Тохиргоо хийлгэхдээ удирдуулахаас гадна
   шууд холболтын console port-той
 • Цахилгаанд залгаагүй тохиолдолд switch нь
   унтраастай буюу холбогдоогүй байна

        © 2004, Cisco Systems, Inc. All rights reserved.   3
Catalyst 2950 series Switches Features


• Бүх оролт нь тэгш хэмийн
  дагуу бэхлэгдсэн.
  FastEthernet or 10/100;
• Оролт нь тэгш бус. Шилэн
  кабелийн 2 эсвэл Gigabit
  Ethernet-ийн зэс
  оролттой.
• Оролт нь тэгш бус.
  Модулийн Gigabit
  Interface Converter (GBIC)
  суурьтай.




            © 2004, Cisco Systems, Inc. All rights reserved.   4
LEDs-гэрэлүүд


 Light-emitting diodes (LEDs)
 • Дэлгэцэн дээр системийн үйл ажиллагаа ба
   гүйцэтгэлийг харуулна.
 • Switch дээр байрлах гэрлүүд:
      - System LED
      - Remote Power Supply (RPS) LED
      - Port Mode LEDs
      - Port Status LEDs


      © 2004, Cisco Systems, Inc. All rights reserved.   5
Mode LED




     © 2004, Cisco Systems, Inc. All rights reserved.   7
Verifying Port LEDs During Switch POST

  Power-On Self Test (POST)
  •Switch-ийг алдаагүй үүргээ биелүүлж байгааг
  шалгах зорилгоор автоматаар ажиллаж эхлэнэ.




       © 2004, Cisco Systems, Inc. All rights reserved.   8
Verifying Port LEDs During Switch POST

 Port Status LEDs during POST:
 turn amber - ойролцоогоор 30 seconds
 • Switch нь сүлжээний топологи ба зангилааг
   хайж олно.
 turn green
 • switch нь компьютер ба оролт нь зөв
   холбогдсон тохиолдолд
 turn off
 • switch-ийн оролтод ямарч холболт байхгүй
   тохиолдолд
            © 2004, Cisco Systems, Inc. All rights reserved.   9
Switch-ээс PC рүү холбох




  © 2004, Cisco Systems, Inc. All rights reserved.   10
Console Connection




      © 2004, Cisco Systems, Inc. All rights reserved.   11
Console Connection




      © 2004, Cisco Systems, Inc. All rights reserved.   12
Console Connection




      Shows information about the switch:
      • details about POST status;
      • data about the switch hardware.
      © 2004, Cisco Systems, Inc. All rights reserved.   13
Switch CLI




© 2004, Cisco Systems, Inc. All rights reserved.   14
Command-Line Interface (CLI) командын
мөрийн интерпайс



 Command-line interface (CLI) Cisco-ийн
  switch-үүд хэрэглэнэ.
 • энэ CLI дээр командууд нь Cisco-ийн
   router-үүд дээр хийгдэх командтай их
   адилхан.



      © 2004, Cisco Systems, Inc. All rights reserved.   15
“Help” command




      © 2004, Cisco Systems, Inc. All rights reserved.   16
Command Modes




    • User EXEC (хэрэглэгчийн)
    • Privileged EXEC (давуу эрхтэй)




      © 2004, Cisco Systems, Inc. All rights reserved.   17
User EXEC mode


  User EXEC mode
  • Өөрчлөх горим;
  • Зөвшөөрөгдсөн командуудын хязгаар:
      - Терминалын тохиргоог өөрчлөх;
      - үндсэн текстийг гүйцэтгэх;
      - дэлгэцэн дээр системийн
           мэдээллийг гаргах.

      © 2004, Cisco Systems, Inc. All rights reserved.   18
Privileged EXEC mode


Privileged EXEC mode
• enable command-ийг өгч хэрэглэчийн EXEC горим
  ажиллагаанд бэлэн болно
• Үүний дараа нэрийн ард (#) тэмдэглэгээтэй болно
• Командуудын хэрэглээ нээлттэй болно.
• Зөвшөөрөлгүй хэрэглэгчийн хандалтаас сэргийлж
  нууц үг хийж хамгаалж болно.
• нууц үг нь дэлгэц нь дээр харагдахгүй



        © 2004, Cisco Systems, Inc. All rights reserved.   19
Default Running Configuration




   © 2004, Cisco Systems, Inc. All rights reserved.   20
Default Running Configuration
  Default Running Configuration
  • Дөнгөж ажиллуулж эхлэхэд switch нь
    ямар нэгэн өгөгдөлгүй тохиргоо хийхэд
    бэлэн байна.
  • Switch-ийн нэрийг өөрчлөх боломжтой.
  • Ямар ч нууц үггүй байх ба нууц үгийг
    цогцоор нь хийж болно. Console эсвэл
    virtual terminal (vty) lines
  • Switch нь IP address хаяггүй.
  (IP address for management purposes is configured on
    the virtual interface VLAN 1)
        © 2004, Cisco Systems, Inc. All rights reserved.   21
Verifying the Catalyst Switch Default
Configuration



               • show running-config
               • show interface
               • show vlan
               • show flash
               • show version


       © 2004, Cisco Systems, Inc. All rights reserved.   22
Default Running Configuration




       © 2004, Cisco Systems, Inc. All rights reserved.   23
Default Port Settings


 Default Running Configuration
 • Switch-ийн оролтууд эсвэл interface нь
   бүгд автомат горимд байна.
 • Switch-ийн бүх оролтууд нь VLAN 1
   байна.
 • VLAN 1 нь VLAN менежемент


       © 2004, Cisco Systems, Inc. All rights reserved.   24
Default Port Settings




       © 2004, Cisco Systems, Inc. All rights reserved.   25
Default Port Settings




       © 2004, Cisco Systems, Inc. All rights reserved.   26
Default Flash Directory Content

                                                          IOS image




                                                          file env_vars


                                                          sub-directory
                                                          html




       © 2004, Cisco Systems, Inc. All rights reserved.                   27
Default Flash Directory Content

 Default Running Configuration
 • by default flash directory агуулна:
      - IOS image;
      - file env_vars;
      - sub-directory html.
 • flash directory агуулахгүй:
      - config.text – switch configuration file;
      - vlan.dat - VLAN database file.
        © 2004, Cisco Systems, Inc. All rights reserved.   28
IOS Version and Config. Register
       show version command – хэрэглэгч шалгах команд:
       • IOS version;
       • configuration register settings.




        © 2004, Cisco Systems, Inc. All rights reserved.   29
Configuring the Switch




© 2004, Cisco Systems, Inc. All rights reserved.   30
Hostname and Passwords Configuration




      © 2004, Cisco Systems, Inc. All rights reserved.   31
IP address and Default Gateway Configuration
      IP address Configuration:
      • switch нь Telnet ба бусад TCP/IP протоколуудыг
      ашиглахыг зөвшөөрдөг ба хэрэглэхэд дөхөм байдаг.




          © 2004, Cisco Systems, Inc. All rights reserved.   32
VLAN1

Management VLAN:
• by default, VLAN 1 is the management
  VLAN;
• Интернетэд холбогдон ажиллаж байгаа
  бүх төхөөрөмжүүд нь менежемент
  VLAN-тай байна.
• Менежементтай workstation нь бусад
  төхөөрөмжүүдрүү хандах, тохиргоо
  хийх, эзэмших эрхтэй.
        © 2004, Cisco Systems, Inc. All rights reserved.   33
Port Speed and Duplex Settings Configuration




        © 2004, Cisco Systems, Inc. All rights reserved.   34
Port Speed and Duplex Settings Configuration


   Fast Ethernet switch ports:
   •by default set to auto-speed and auto-
   duplex (allows the interfaces to
   negotiate these settings);
   •Network administrators can manually
   configure the interface speed and
   duplex values


        © 2004, Cisco Systems, Inc. All rights reserved.   35
HTTP Service and Port Configuration

• Intelligent network devices can provide a web-based
  interface for configuration and management
  purposes;
• Once a switch is configured with an IP address and
  gateway, it can be accessed by a web-based
  interface;
HTTP services:
• can be access by a web browser using:
     - IP address;
     - port 80 - the default port for http.
• can be turned on or off, and the port address for the
  service can be chosen.
         © 2004, Cisco Systems, Inc. All rights reserved.   36
HTTP Service and Port Configuration




       © 2004, Cisco Systems, Inc. All rights reserved.   37
Configuring the Catalyst Switch




                                                             Web Management Interface




  Web Management Interface




          © 2004, Cisco Systems, Inc. All rights reserved.                              38
Managing the MAC Address Table




     © 2004, Cisco Systems, Inc. All rights reserved.   39
MAC Address Table


Switches
• examine the source address of frames that
  are received on the ports;
• learn the MAC addresses of PCs or
  workstations that are connected to their
  switch ports;
• record learned MAC addresses in a MAC
  address table.

       © 2004, Cisco Systems, Inc. All rights reserved.   40
Check Learned MAC Addresses




   show mac-address-table command - Privileged EXEC mode
   • examines the addresses that a switch has learned
         © 2004, Cisco Systems, Inc. All rights reserved.   41
MAC Address Table

Switches:
• dynamically learn and maintain thousands
  of MAC addresses;
• learned entries may be discarded from the
  MAC address table (to preserve memory and
  for optimal operation) ;
• the MAC address entry is automatically
  discarded or aged out after 300 seconds (if
 no frames are seen with a previously learned
 address).
       © 2004, Cisco Systems, Inc. All rights reserved.   42
Check Learned MAC Addresses




  Clear mac-address-table command - Privileged EXEC mode
  • used to remove dynamically learned MAC addresses;
  • used to remove static MAC address entries.
         © 2004, Cisco Systems, Inc. All rights reserved.   43
Managing the MAC Address Table




      © 2004, Cisco Systems, Inc. All rights reserved.   44
Static MAC Addresses


Static MAC address:
• permanently assigned to an interface;
Reasons for use a Static MAC address:
• will not be aged out automatically by the switch;
• a specific server or user workstation must be
  attached to the port and the MAC address is
  known;
• Security is enhanced.
        © 2004, Cisco Systems, Inc. All rights reserved.   45
Configuring Static MAC Addresses




      © 2004, Cisco Systems, Inc. All rights reserved.   46
Configuring Static MAC Addresses




      © 2004, Cisco Systems, Inc. All rights reserved.   47
Static MAC Addresses




  To configure:

  Switch(config)#mac-address-table static <mac-
  address of host > interface FastEthernet <Ethernet
  number > vlan <vlan name >
  To remove:

  Switch(config)# no mac-address-table static <mac-
  address of host > interface FastEthernet <Ethernet
  number > vlan <vlan name >
          © 2004, Cisco Systems, Inc. All rights reserved.   48
Port Security




© 2004, Cisco Systems, Inc. All rights reserved.   49
Port Security

  Port Security
  • It is possible to limit the number of
    addresses that can be learned on an
    interface;
  • the number of MAC addresses per port
    can be limited to 1;
  • the first address dynamically learned by
    the switch becomes the secure address.

       © 2004, Cisco Systems, Inc. All rights reserved.   50
Port Security Configuration




       © 2004, Cisco Systems, Inc. All rights reserved.   51
Configuring Port Security

Catalyst 2950 Series

 wg_sw_2950(config-if)#switchport port-security [mac-address
 mac-address] | [maximum value] | [violation {protect
 |restrict | shutdown}]




wg_sw_2950(config)#interface fa0/1
wg_sw_2950(config-if)#switchport mode access
wg_sw_2950(config-if)#switchport port-security
wg_sw_2950(config-if)#switchport port-security maximum 1
wg_sw_2950(config-if)#switchport port-security mac-address 0008.eeee.eeee
wg_sw_2950(config-if)#switchport port-security violation shutdown




            © 2004, Cisco Systems, Inc. All rights reserved.                52
Verifying Port Security
on the Catalyst 2950 Series

 wg_sw_2950#show port-security [interface interface-id] [address] [ |
 {begin | exclude | include} expression]




   wg_sw_2950#show port-security interface fastethernet 0/5
   Port Security              : Enabled
   Port Status                : Secure-up
   Violation Mode             : Shutdown
   Aging Time                 : 20 mins
   Aging Type                 : Absolute
   SecureStatic Address Aging : Disabled
   Maximum MAC Addresses      : 1
   Total MAC Addresses        : 1
   Configured MAC Addresses   : 0
   Sticky MAC Addresses       : 0
   Last Source Address        : 0000.0000.0000
   Security Violation Count   : 0




           © 2004, Cisco Systems, Inc. All rights reserved.             53
Verifying Port Security
on the Catalyst 2950 Series (Cont.)


wg_sw_2950#sh port-security
Secure Port MaxSecureAddr CurrentAddr SecurityViolation
Security Action
                (Count)       (Count)          (Count)
----------------------------------------------------------------
----------
      Fa0/2        1             1                0
Shutdown
----------------------------------------------------------------
-----------
Total Addresses in System (excluding one mac per port)     : 0
Max Addresses limit in System (excluding one mac per port) :
1024




          © 2004, Cisco Systems, Inc. All rights reserved.         54
Port Security


    To configure port security :
    Switch(config-if)#switchport port-security


    To reverse port security:
    Switch(config-if)# no switchport port-security


    To verify port security status:
    Switch(config)#show port security


        © 2004, Cisco Systems, Inc. All rights reserved.   55
Adding and Moving Switches
      to the Network



   © 2004, Cisco Systems, Inc. All rights reserved.   56
Adding New Switch

     Adding New Switch
     Must be configured:
     • Switch name;
     • IP address for the switch in the
       management VLAN;
     • a default gateway;
     • Line passwords.

      © 2004, Cisco Systems, Inc. All rights reserved.   57
Adding New Switch




      © 2004, Cisco Systems, Inc. All rights reserved.   58
Moving a Switch


Host is moved:
• from one port or switch to another;
• configurations that can cause unexpected
  behavior should be removed;
• configuration that is required can then be
  added.


       © 2004, Cisco Systems, Inc. All rights reserved.   59

Mais conteúdo relacionado

Mais procurados

Nat гэж юу вэ
Nat  гэж юу вэNat  гэж юу вэ
Nat гэж юу вэOchiroo Dorj
 
компьютерийн сүлжээ
компьютерийн сүлжээкомпьютерийн сүлжээ
компьютерийн сүлжээEnkh Gvnj
 
сүлжээний хичээл
сүлжээний хичээлсүлжээний хичээл
сүлжээний хичээлenhsaran_tsahim
 
өгөгдөл дамжуулах 4
өгөгдөл дамжуулах 4өгөгдөл дамжуулах 4
өгөгдөл дамжуулах 4Oidov Umbelee
 
Cs101 lecture3
Cs101 lecture3Cs101 lecture3
Cs101 lecture3Purev
 
компьютерийн сүлжээний техник хангамж
компьютерийн сүлжээний  техник хангамжкомпьютерийн сүлжээний  техник хангамж
компьютерийн сүлжээний техник хангамжЖавзмаа Ж
 
төрийн байгууллагын вэбсайтад тавих шаардлага стандарт
төрийн байгууллагын вэбсайтад тавих шаардлага   стандарттөрийн байгууллагын вэбсайтад тавих шаардлага   стандарт
төрийн байгууллагын вэбсайтад тавих шаардлага стандартdBayarmagnai
 
Lekts presentation7
Lekts presentation7Lekts presentation7
Lekts presentation7ganzorigb
 
Лекц 3
Лекц 3Лекц 3
Лекц 3Muuluu
 
Computerin tehnikin undes 1hicheeliin lektsiin huraangui
Computerin tehnikin undes 1hicheeliin lektsiin huraanguiComputerin tehnikin undes 1hicheeliin lektsiin huraangui
Computerin tehnikin undes 1hicheeliin lektsiin huraanguiE-Gazarchin Online University
 

Mais procurados (20)

Lecture 1 2
Lecture 1 2Lecture 1 2
Lecture 1 2
 
Suljee
SuljeeSuljee
Suljee
 
Ospf
OspfOspf
Ospf
 
TCP/IP protocol
TCP/IP protocolTCP/IP protocol
TCP/IP protocol
 
Nat гэж юу вэ
Nat  гэж юу вэNat  гэж юу вэ
Nat гэж юу вэ
 
компьютерийн сүлжээ
компьютерийн сүлжээкомпьютерийн сүлжээ
компьютерийн сүлжээ
 
сүлжээний хичээл
сүлжээний хичээлсүлжээний хичээл
сүлжээний хичээл
 
өгөгдөл дамжуулах 4
өгөгдөл дамжуулах 4өгөгдөл дамжуулах 4
өгөгдөл дамжуулах 4
 
Switch and Hub
Switch and HubSwitch and Hub
Switch and Hub
 
Cs101 lec2
Cs101 lec2Cs101 lec2
Cs101 lec2
 
Cs101 lecture3
Cs101 lecture3Cs101 lecture3
Cs101 lecture3
 
Сүлжээ
СүлжээСүлжээ
Сүлжээ
 
192.168.2.1
192.168.2.1192.168.2.1
192.168.2.1
 
Lab7
Lab7Lab7
Lab7
 
компьютерийн сүлжээний техник хангамж
компьютерийн сүлжээний  техник хангамжкомпьютерийн сүлжээний  техник хангамж
компьютерийн сүлжээний техник хангамж
 
төрийн байгууллагын вэбсайтад тавих шаардлага стандарт
төрийн байгууллагын вэбсайтад тавих шаардлага   стандарттөрийн байгууллагын вэбсайтад тавих шаардлага   стандарт
төрийн байгууллагын вэбсайтад тавих шаардлага стандарт
 
Lekts presentation7
Lekts presentation7Lekts presentation7
Lekts presentation7
 
VLAN
VLANVLAN
VLAN
 
Лекц 3
Лекц 3Лекц 3
Лекц 3
 
Computerin tehnikin undes 1hicheeliin lektsiin huraangui
Computerin tehnikin undes 1hicheeliin lektsiin huraanguiComputerin tehnikin undes 1hicheeliin lektsiin huraangui
Computerin tehnikin undes 1hicheeliin lektsiin huraangui
 

Destaque

Лекц 5
Лекц 5Лекц 5
Лекц 5Muuluu
 
2.1 users & groups
2.1 users & groups2.1 users & groups
2.1 users & groupsMuuluu
 
1.1 windows server 2003
1.1 windows server 20031.1 windows server 2003
1.1 windows server 2003Muuluu
 
Лекц 10
Лекц 10Лекц 10
Лекц 10Muuluu
 
Лекц 15
Лекц 15Лекц 15
Лекц 15Muuluu
 
Лекц 11
Лекц 11Лекц 11
Лекц 11Muuluu
 
Лекц 7
Лекц 7Лекц 7
Лекц 7Muuluu
 
Лекц 13
Лекц 13Лекц 13
Лекц 13Muuluu
 
2.1 user practical
2.1 user practical2.1 user practical
2.1 user practicalMuuluu
 
2.2 determining trust relationships
2.2 determining trust relationships2.2 determining trust relationships
2.2 determining trust relationshipsMuuluu
 
1.2 ad installation
1.2 ad installation1.2 ad installation
1.2 ad installationMuuluu
 
Dns server
Dns serverDns server
Dns serverMuuluu
 
1.2 active directory
1.2 active directory1.2 active directory
1.2 active directoryMuuluu
 
Лекц 14
Лекц 14Лекц 14
Лекц 14Muuluu
 
User account policy
User account policyUser account policy
User account policyMuuluu
 
Switch function
Switch functionSwitch function
Switch functionMuuluu
 
Лекц 12
Лекц 12Лекц 12
Лекц 12Muuluu
 
Лекц 1
Лекц 1Лекц 1
Лекц 1Muuluu
 
Лекц 2
Лекц 2Лекц 2
Лекц 2Muuluu
 
Switch configuration
Switch configurationSwitch configuration
Switch configurationMuuluu
 

Destaque (20)

Лекц 5
Лекц 5Лекц 5
Лекц 5
 
2.1 users & groups
2.1 users & groups2.1 users & groups
2.1 users & groups
 
1.1 windows server 2003
1.1 windows server 20031.1 windows server 2003
1.1 windows server 2003
 
Лекц 10
Лекц 10Лекц 10
Лекц 10
 
Лекц 15
Лекц 15Лекц 15
Лекц 15
 
Лекц 11
Лекц 11Лекц 11
Лекц 11
 
Лекц 7
Лекц 7Лекц 7
Лекц 7
 
Лекц 13
Лекц 13Лекц 13
Лекц 13
 
2.1 user practical
2.1 user practical2.1 user practical
2.1 user practical
 
2.2 determining trust relationships
2.2 determining trust relationships2.2 determining trust relationships
2.2 determining trust relationships
 
1.2 ad installation
1.2 ad installation1.2 ad installation
1.2 ad installation
 
Dns server
Dns serverDns server
Dns server
 
1.2 active directory
1.2 active directory1.2 active directory
1.2 active directory
 
Лекц 14
Лекц 14Лекц 14
Лекц 14
 
User account policy
User account policyUser account policy
User account policy
 
Switch function
Switch functionSwitch function
Switch function
 
Лекц 12
Лекц 12Лекц 12
Лекц 12
 
Лекц 1
Лекц 1Лекц 1
Лекц 1
 
Лекц 2
Лекц 2Лекц 2
Лекц 2
 
Switch configuration
Switch configurationSwitch configuration
Switch configuration
 

Semelhante a Лекц 8

Switch configuration
Switch configurationSwitch configuration
Switch configurationMuuluu
 
Itn6 instructor materials_chapter2
Itn6 instructor materials_chapter2Itn6 instructor materials_chapter2
Itn6 instructor materials_chapter2limenih muluneh
 
CCNA (R & S) Module 01 - Introduction to Networks - Chapter 2
CCNA (R & S) Module 01 - Introduction to Networks - Chapter 2CCNA (R & S) Module 01 - Introduction to Networks - Chapter 2
CCNA (R & S) Module 01 - Introduction to Networks - Chapter 2Waqas Ahmed Nawaz
 
Chapter 2 Configure a Network Operating System
Chapter 2 Configure a Network Operating SystemChapter 2 Configure a Network Operating System
Chapter 2 Configure a Network Operating Systemnewbie2019
 
Поиск и устранение неисправностей в вычислительной системе Cisco UCS
Поиск и устранение неисправностей в вычислительной системе Cisco UCSПоиск и устранение неисправностей в вычислительной системе Cisco UCS
Поиск и устранение неисправностей в вычислительной системе Cisco UCSCisco Russia
 
CCNA v6.0 ITN - Chapter 02
CCNA v6.0 ITN - Chapter 02CCNA v6.0 ITN - Chapter 02
CCNA v6.0 ITN - Chapter 02Irsandi Hasan
 
Cis81 ccna1v5-2-configuring networkoperatingsystem
Cis81 ccna1v5-2-configuring networkoperatingsystemCis81 ccna1v5-2-configuring networkoperatingsystem
Cis81 ccna1v5-2-configuring networkoperatingsystemBetselove
 
CCNA2 Verson6 Chapter1
CCNA2 Verson6 Chapter1CCNA2 Verson6 Chapter1
CCNA2 Verson6 Chapter1Chaing Ravuth
 
CCNA 2 Routing and Switching v5.0 Chapter 2
CCNA 2 Routing and Switching v5.0 Chapter 2CCNA 2 Routing and Switching v5.0 Chapter 2
CCNA 2 Routing and Switching v5.0 Chapter 2Nil Menon
 
CCNAv5 - S2: Chapter2 Basic Switching Concepts and Configuration
CCNAv5 - S2: Chapter2 Basic Switching Concepts and ConfigurationCCNAv5 - S2: Chapter2 Basic Switching Concepts and Configuration
CCNAv5 - S2: Chapter2 Basic Switching Concepts and ConfigurationVuz Dở Hơi
 
Chapter 02 - Introduction to Switched Networks
Chapter 02 - Introduction to Switched NetworksChapter 02 - Introduction to Switched Networks
Chapter 02 - Introduction to Switched NetworksYaser Rahmati
 
KPUCC-Rs instructor ppt_chapter2_final
KPUCC-Rs instructor ppt_chapter2_finalKPUCC-Rs instructor ppt_chapter2_final
KPUCC-Rs instructor ppt_chapter2_finalFisal Anwari
 
Ex 1 chapter11-configure-network-tony_chen
Ex 1 chapter11-configure-network-tony_chenEx 1 chapter11-configure-network-tony_chen
Ex 1 chapter11-configure-network-tony_chenĐô GiẢn
 
1627478708347_Chapter 1.pptx
1627478708347_Chapter 1.pptx1627478708347_Chapter 1.pptx
1627478708347_Chapter 1.pptxTesfaMinuyelet
 

Semelhante a Лекц 8 (20)

Switch configuration
Switch configurationSwitch configuration
Switch configuration
 
Itn6 instructor materials_chapter2
Itn6 instructor materials_chapter2Itn6 instructor materials_chapter2
Itn6 instructor materials_chapter2
 
CCNA (R & S) Module 01 - Introduction to Networks - Chapter 2
CCNA (R & S) Module 01 - Introduction to Networks - Chapter 2CCNA (R & S) Module 01 - Introduction to Networks - Chapter 2
CCNA (R & S) Module 01 - Introduction to Networks - Chapter 2
 
PC LEESOON 6.pptx
PC LEESOON 6.pptxPC LEESOON 6.pptx
PC LEESOON 6.pptx
 
Redes
RedesRedes
Redes
 
Basic switch management
Basic switch managementBasic switch management
Basic switch management
 
CCNA_ITN_Chp2_.pptx
CCNA_ITN_Chp2_.pptxCCNA_ITN_Chp2_.pptx
CCNA_ITN_Chp2_.pptx
 
Chapter 2 Configure a Network Operating System
Chapter 2 Configure a Network Operating SystemChapter 2 Configure a Network Operating System
Chapter 2 Configure a Network Operating System
 
Поиск и устранение неисправностей в вычислительной системе Cisco UCS
Поиск и устранение неисправностей в вычислительной системе Cisco UCSПоиск и устранение неисправностей в вычислительной системе Cisco UCS
Поиск и устранение неисправностей в вычислительной системе Cisco UCS
 
Day 13.1 startingaswitch
Day 13.1 startingaswitchDay 13.1 startingaswitch
Day 13.1 startingaswitch
 
CCNA v6.0 ITN - Chapter 02
CCNA v6.0 ITN - Chapter 02CCNA v6.0 ITN - Chapter 02
CCNA v6.0 ITN - Chapter 02
 
Cis81 ccna1v5-2-configuring networkoperatingsystem
Cis81 ccna1v5-2-configuring networkoperatingsystemCis81 ccna1v5-2-configuring networkoperatingsystem
Cis81 ccna1v5-2-configuring networkoperatingsystem
 
CCNA2 Verson6 Chapter1
CCNA2 Verson6 Chapter1CCNA2 Verson6 Chapter1
CCNA2 Verson6 Chapter1
 
CCNA Icnd110 s04l04
CCNA Icnd110 s04l04CCNA Icnd110 s04l04
CCNA Icnd110 s04l04
 
CCNA 2 Routing and Switching v5.0 Chapter 2
CCNA 2 Routing and Switching v5.0 Chapter 2CCNA 2 Routing and Switching v5.0 Chapter 2
CCNA 2 Routing and Switching v5.0 Chapter 2
 
CCNAv5 - S2: Chapter2 Basic Switching Concepts and Configuration
CCNAv5 - S2: Chapter2 Basic Switching Concepts and ConfigurationCCNAv5 - S2: Chapter2 Basic Switching Concepts and Configuration
CCNAv5 - S2: Chapter2 Basic Switching Concepts and Configuration
 
Chapter 02 - Introduction to Switched Networks
Chapter 02 - Introduction to Switched NetworksChapter 02 - Introduction to Switched Networks
Chapter 02 - Introduction to Switched Networks
 
KPUCC-Rs instructor ppt_chapter2_final
KPUCC-Rs instructor ppt_chapter2_finalKPUCC-Rs instructor ppt_chapter2_final
KPUCC-Rs instructor ppt_chapter2_final
 
Ex 1 chapter11-configure-network-tony_chen
Ex 1 chapter11-configure-network-tony_chenEx 1 chapter11-configure-network-tony_chen
Ex 1 chapter11-configure-network-tony_chen
 
1627478708347_Chapter 1.pptx
1627478708347_Chapter 1.pptx1627478708347_Chapter 1.pptx
1627478708347_Chapter 1.pptx
 

Mais de Muuluu

Lecture 2
Lecture 2Lecture 2
Lecture 2Muuluu
 
Lecture 5
Lecture 5Lecture 5
Lecture 5Muuluu
 
Lecture 3
Lecture 3Lecture 3
Lecture 3Muuluu
 
Өгөгдлийн бүтэц
Өгөгдлийн бүтэцӨгөгдлийн бүтэц
Өгөгдлийн бүтэцMuuluu
 
Basic software
Basic software Basic software
Basic software Muuluu
 
Wide area networks
Wide area networksWide area networks
Wide area networksMuuluu
 
NAT and PAT
NAT and PATNAT and PAT
NAT and PATMuuluu
 
Spanning tree protocol
Spanning tree protocolSpanning tree protocol
Spanning tree protocolMuuluu
 
Firewall
FirewallFirewall
FirewallMuuluu
 
User practical
User practicalUser practical
User practicalMuuluu
 
Active directory
Active directoryActive directory
Active directoryMuuluu
 
Hardware
HardwareHardware
HardwareMuuluu
 
windows server 2003
 windows server 2003 windows server 2003
windows server 2003Muuluu
 
Процессорын архитектур
Процессорын архитектурПроцессорын архитектур
Процессорын архитектурMuuluu
 
6 network devices
6 network devices6 network devices
6 network devicesMuuluu
 
Бие даалт
Бие даалтБие даалт
Бие даалтMuuluu
 
Лекц 16
Лекц 16Лекц 16
Лекц 16Muuluu
 
Лекц 15
Лекц 15Лекц 15
Лекц 15Muuluu
 
Лекц 14
Лекц 14Лекц 14
Лекц 14Muuluu
 
Лекц 13
Лекц 13Лекц 13
Лекц 13Muuluu
 

Mais de Muuluu (20)

Lecture 2
Lecture 2Lecture 2
Lecture 2
 
Lecture 5
Lecture 5Lecture 5
Lecture 5
 
Lecture 3
Lecture 3Lecture 3
Lecture 3
 
Өгөгдлийн бүтэц
Өгөгдлийн бүтэцӨгөгдлийн бүтэц
Өгөгдлийн бүтэц
 
Basic software
Basic software Basic software
Basic software
 
Wide area networks
Wide area networksWide area networks
Wide area networks
 
NAT and PAT
NAT and PATNAT and PAT
NAT and PAT
 
Spanning tree protocol
Spanning tree protocolSpanning tree protocol
Spanning tree protocol
 
Firewall
FirewallFirewall
Firewall
 
User practical
User practicalUser practical
User practical
 
Active directory
Active directoryActive directory
Active directory
 
Hardware
HardwareHardware
Hardware
 
windows server 2003
 windows server 2003 windows server 2003
windows server 2003
 
Процессорын архитектур
Процессорын архитектурПроцессорын архитектур
Процессорын архитектур
 
6 network devices
6 network devices6 network devices
6 network devices
 
Бие даалт
Бие даалтБие даалт
Бие даалт
 
Лекц 16
Лекц 16Лекц 16
Лекц 16
 
Лекц 15
Лекц 15Лекц 15
Лекц 15
 
Лекц 14
Лекц 14Лекц 14
Лекц 14
 
Лекц 13
Лекц 13Лекц 13
Лекц 13
 

Лекц 8

  • 1. Switch-ийн тохиргоо © 2004, Cisco Systems, Inc. All rights reserved. 1
  • 2. Starting the Switch Switches: • Хостын холбоход зориулагдсан хэд хэдэн оролттой • Мөн тусгай зориулалтын оролттой • Тохиргоо хийлгэхдээ удирдуулахаас гадна шууд холболтын console port-той • Цахилгаанд залгаагүй тохиолдолд switch нь унтраастай буюу холбогдоогүй байна © 2004, Cisco Systems, Inc. All rights reserved. 3
  • 3. Catalyst 2950 series Switches Features • Бүх оролт нь тэгш хэмийн дагуу бэхлэгдсэн. FastEthernet or 10/100; • Оролт нь тэгш бус. Шилэн кабелийн 2 эсвэл Gigabit Ethernet-ийн зэс оролттой. • Оролт нь тэгш бус. Модулийн Gigabit Interface Converter (GBIC) суурьтай. © 2004, Cisco Systems, Inc. All rights reserved. 4
  • 4. LEDs-гэрэлүүд Light-emitting diodes (LEDs) • Дэлгэцэн дээр системийн үйл ажиллагаа ба гүйцэтгэлийг харуулна. • Switch дээр байрлах гэрлүүд: - System LED - Remote Power Supply (RPS) LED - Port Mode LEDs - Port Status LEDs © 2004, Cisco Systems, Inc. All rights reserved. 5
  • 5. Mode LED © 2004, Cisco Systems, Inc. All rights reserved. 7
  • 6. Verifying Port LEDs During Switch POST Power-On Self Test (POST) •Switch-ийг алдаагүй үүргээ биелүүлж байгааг шалгах зорилгоор автоматаар ажиллаж эхлэнэ. © 2004, Cisco Systems, Inc. All rights reserved. 8
  • 7. Verifying Port LEDs During Switch POST Port Status LEDs during POST: turn amber - ойролцоогоор 30 seconds • Switch нь сүлжээний топологи ба зангилааг хайж олно. turn green • switch нь компьютер ба оролт нь зөв холбогдсон тохиолдолд turn off • switch-ийн оролтод ямарч холболт байхгүй тохиолдолд © 2004, Cisco Systems, Inc. All rights reserved. 9
  • 8. Switch-ээс PC рүү холбох © 2004, Cisco Systems, Inc. All rights reserved. 10
  • 9. Console Connection © 2004, Cisco Systems, Inc. All rights reserved. 11
  • 10. Console Connection © 2004, Cisco Systems, Inc. All rights reserved. 12
  • 11. Console Connection Shows information about the switch: • details about POST status; • data about the switch hardware. © 2004, Cisco Systems, Inc. All rights reserved. 13
  • 12. Switch CLI © 2004, Cisco Systems, Inc. All rights reserved. 14
  • 13. Command-Line Interface (CLI) командын мөрийн интерпайс Command-line interface (CLI) Cisco-ийн switch-үүд хэрэглэнэ. • энэ CLI дээр командууд нь Cisco-ийн router-үүд дээр хийгдэх командтай их адилхан. © 2004, Cisco Systems, Inc. All rights reserved. 15
  • 14. “Help” command © 2004, Cisco Systems, Inc. All rights reserved. 16
  • 15. Command Modes • User EXEC (хэрэглэгчийн) • Privileged EXEC (давуу эрхтэй) © 2004, Cisco Systems, Inc. All rights reserved. 17
  • 16. User EXEC mode User EXEC mode • Өөрчлөх горим; • Зөвшөөрөгдсөн командуудын хязгаар: - Терминалын тохиргоог өөрчлөх; - үндсэн текстийг гүйцэтгэх; - дэлгэцэн дээр системийн мэдээллийг гаргах. © 2004, Cisco Systems, Inc. All rights reserved. 18
  • 17. Privileged EXEC mode Privileged EXEC mode • enable command-ийг өгч хэрэглэчийн EXEC горим ажиллагаанд бэлэн болно • Үүний дараа нэрийн ард (#) тэмдэглэгээтэй болно • Командуудын хэрэглээ нээлттэй болно. • Зөвшөөрөлгүй хэрэглэгчийн хандалтаас сэргийлж нууц үг хийж хамгаалж болно. • нууц үг нь дэлгэц нь дээр харагдахгүй © 2004, Cisco Systems, Inc. All rights reserved. 19
  • 18. Default Running Configuration © 2004, Cisco Systems, Inc. All rights reserved. 20
  • 19. Default Running Configuration Default Running Configuration • Дөнгөж ажиллуулж эхлэхэд switch нь ямар нэгэн өгөгдөлгүй тохиргоо хийхэд бэлэн байна. • Switch-ийн нэрийг өөрчлөх боломжтой. • Ямар ч нууц үггүй байх ба нууц үгийг цогцоор нь хийж болно. Console эсвэл virtual terminal (vty) lines • Switch нь IP address хаяггүй. (IP address for management purposes is configured on the virtual interface VLAN 1) © 2004, Cisco Systems, Inc. All rights reserved. 21
  • 20. Verifying the Catalyst Switch Default Configuration • show running-config • show interface • show vlan • show flash • show version © 2004, Cisco Systems, Inc. All rights reserved. 22
  • 21. Default Running Configuration © 2004, Cisco Systems, Inc. All rights reserved. 23
  • 22. Default Port Settings Default Running Configuration • Switch-ийн оролтууд эсвэл interface нь бүгд автомат горимд байна. • Switch-ийн бүх оролтууд нь VLAN 1 байна. • VLAN 1 нь VLAN менежемент © 2004, Cisco Systems, Inc. All rights reserved. 24
  • 23. Default Port Settings © 2004, Cisco Systems, Inc. All rights reserved. 25
  • 24. Default Port Settings © 2004, Cisco Systems, Inc. All rights reserved. 26
  • 25. Default Flash Directory Content IOS image file env_vars sub-directory html © 2004, Cisco Systems, Inc. All rights reserved. 27
  • 26. Default Flash Directory Content Default Running Configuration • by default flash directory агуулна: - IOS image; - file env_vars; - sub-directory html. • flash directory агуулахгүй: - config.text – switch configuration file; - vlan.dat - VLAN database file. © 2004, Cisco Systems, Inc. All rights reserved. 28
  • 27. IOS Version and Config. Register show version command – хэрэглэгч шалгах команд: • IOS version; • configuration register settings. © 2004, Cisco Systems, Inc. All rights reserved. 29
  • 28. Configuring the Switch © 2004, Cisco Systems, Inc. All rights reserved. 30
  • 29. Hostname and Passwords Configuration © 2004, Cisco Systems, Inc. All rights reserved. 31
  • 30. IP address and Default Gateway Configuration IP address Configuration: • switch нь Telnet ба бусад TCP/IP протоколуудыг ашиглахыг зөвшөөрдөг ба хэрэглэхэд дөхөм байдаг. © 2004, Cisco Systems, Inc. All rights reserved. 32
  • 31. VLAN1 Management VLAN: • by default, VLAN 1 is the management VLAN; • Интернетэд холбогдон ажиллаж байгаа бүх төхөөрөмжүүд нь менежемент VLAN-тай байна. • Менежементтай workstation нь бусад төхөөрөмжүүдрүү хандах, тохиргоо хийх, эзэмших эрхтэй. © 2004, Cisco Systems, Inc. All rights reserved. 33
  • 32. Port Speed and Duplex Settings Configuration © 2004, Cisco Systems, Inc. All rights reserved. 34
  • 33. Port Speed and Duplex Settings Configuration Fast Ethernet switch ports: •by default set to auto-speed and auto- duplex (allows the interfaces to negotiate these settings); •Network administrators can manually configure the interface speed and duplex values © 2004, Cisco Systems, Inc. All rights reserved. 35
  • 34. HTTP Service and Port Configuration • Intelligent network devices can provide a web-based interface for configuration and management purposes; • Once a switch is configured with an IP address and gateway, it can be accessed by a web-based interface; HTTP services: • can be access by a web browser using: - IP address; - port 80 - the default port for http. • can be turned on or off, and the port address for the service can be chosen. © 2004, Cisco Systems, Inc. All rights reserved. 36
  • 35. HTTP Service and Port Configuration © 2004, Cisco Systems, Inc. All rights reserved. 37
  • 36. Configuring the Catalyst Switch Web Management Interface Web Management Interface © 2004, Cisco Systems, Inc. All rights reserved. 38
  • 37. Managing the MAC Address Table © 2004, Cisco Systems, Inc. All rights reserved. 39
  • 38. MAC Address Table Switches • examine the source address of frames that are received on the ports; • learn the MAC addresses of PCs or workstations that are connected to their switch ports; • record learned MAC addresses in a MAC address table. © 2004, Cisco Systems, Inc. All rights reserved. 40
  • 39. Check Learned MAC Addresses show mac-address-table command - Privileged EXEC mode • examines the addresses that a switch has learned © 2004, Cisco Systems, Inc. All rights reserved. 41
  • 40. MAC Address Table Switches: • dynamically learn and maintain thousands of MAC addresses; • learned entries may be discarded from the MAC address table (to preserve memory and for optimal operation) ; • the MAC address entry is automatically discarded or aged out after 300 seconds (if no frames are seen with a previously learned address). © 2004, Cisco Systems, Inc. All rights reserved. 42
  • 41. Check Learned MAC Addresses Clear mac-address-table command - Privileged EXEC mode • used to remove dynamically learned MAC addresses; • used to remove static MAC address entries. © 2004, Cisco Systems, Inc. All rights reserved. 43
  • 42. Managing the MAC Address Table © 2004, Cisco Systems, Inc. All rights reserved. 44
  • 43. Static MAC Addresses Static MAC address: • permanently assigned to an interface; Reasons for use a Static MAC address: • will not be aged out automatically by the switch; • a specific server or user workstation must be attached to the port and the MAC address is known; • Security is enhanced. © 2004, Cisco Systems, Inc. All rights reserved. 45
  • 44. Configuring Static MAC Addresses © 2004, Cisco Systems, Inc. All rights reserved. 46
  • 45. Configuring Static MAC Addresses © 2004, Cisco Systems, Inc. All rights reserved. 47
  • 46. Static MAC Addresses To configure: Switch(config)#mac-address-table static <mac- address of host > interface FastEthernet <Ethernet number > vlan <vlan name > To remove: Switch(config)# no mac-address-table static <mac- address of host > interface FastEthernet <Ethernet number > vlan <vlan name > © 2004, Cisco Systems, Inc. All rights reserved. 48
  • 47. Port Security © 2004, Cisco Systems, Inc. All rights reserved. 49
  • 48. Port Security Port Security • It is possible to limit the number of addresses that can be learned on an interface; • the number of MAC addresses per port can be limited to 1; • the first address dynamically learned by the switch becomes the secure address. © 2004, Cisco Systems, Inc. All rights reserved. 50
  • 49. Port Security Configuration © 2004, Cisco Systems, Inc. All rights reserved. 51
  • 50. Configuring Port Security Catalyst 2950 Series wg_sw_2950(config-if)#switchport port-security [mac-address mac-address] | [maximum value] | [violation {protect |restrict | shutdown}] wg_sw_2950(config)#interface fa0/1 wg_sw_2950(config-if)#switchport mode access wg_sw_2950(config-if)#switchport port-security wg_sw_2950(config-if)#switchport port-security maximum 1 wg_sw_2950(config-if)#switchport port-security mac-address 0008.eeee.eeee wg_sw_2950(config-if)#switchport port-security violation shutdown © 2004, Cisco Systems, Inc. All rights reserved. 52
  • 51. Verifying Port Security on the Catalyst 2950 Series wg_sw_2950#show port-security [interface interface-id] [address] [ | {begin | exclude | include} expression] wg_sw_2950#show port-security interface fastethernet 0/5 Port Security : Enabled Port Status : Secure-up Violation Mode : Shutdown Aging Time : 20 mins Aging Type : Absolute SecureStatic Address Aging : Disabled Maximum MAC Addresses : 1 Total MAC Addresses : 1 Configured MAC Addresses : 0 Sticky MAC Addresses : 0 Last Source Address : 0000.0000.0000 Security Violation Count : 0 © 2004, Cisco Systems, Inc. All rights reserved. 53
  • 52. Verifying Port Security on the Catalyst 2950 Series (Cont.) wg_sw_2950#sh port-security Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action (Count) (Count) (Count) ---------------------------------------------------------------- ---------- Fa0/2 1 1 0 Shutdown ---------------------------------------------------------------- ----------- Total Addresses in System (excluding one mac per port) : 0 Max Addresses limit in System (excluding one mac per port) : 1024 © 2004, Cisco Systems, Inc. All rights reserved. 54
  • 53. Port Security To configure port security : Switch(config-if)#switchport port-security To reverse port security: Switch(config-if)# no switchport port-security To verify port security status: Switch(config)#show port security © 2004, Cisco Systems, Inc. All rights reserved. 55
  • 54. Adding and Moving Switches to the Network © 2004, Cisco Systems, Inc. All rights reserved. 56
  • 55. Adding New Switch Adding New Switch Must be configured: • Switch name; • IP address for the switch in the management VLAN; • a default gateway; • Line passwords. © 2004, Cisco Systems, Inc. All rights reserved. 57
  • 56. Adding New Switch © 2004, Cisco Systems, Inc. All rights reserved. 58
  • 57. Moving a Switch Host is moved: • from one port or switch to another; • configurations that can cause unexpected behavior should be removed; • configuration that is required can then be added. © 2004, Cisco Systems, Inc. All rights reserved. 59