顯示具有 cisco 標籤的文章。 顯示所有文章
顯示具有 cisco 標籤的文章。 顯示所有文章

2015年2月17日 星期二

CISCO NAT 運作查詢指令

CISCO NAT 運作查詢指令

指令 :  show ip nat translation

指令 : show ip nat statistics

官網詳細資料
http://www.cisco.com/c/en/us/support/docs/ip/network-address-translation-nat/8605-13.html

2013年4月25日 星期四

CISCO Monitor PORT 設定 範例


若需要監聽特定的網路設備 , 來做分析的話 , 必須把被監聽跟收集資料
的設備在 SWITCH 上作設定。把所有經過被監聽對象的網路流都複製到
指定的設備上。

此篇文章以 CISCO 的 SWITCH 作為範例。

===================================================
User Access Verification
Password:
4507R-1#en
Password:
4507R-1#
4507R-1#config
Configuring from terminal, memory, or network [terminal]?
Enter configuration commands, one per line.  End with CNTL/Z.

設定 source
指令 :monitor session x source interface gigabitEthernet x/x

範例如下
4507R-1(config)#monitor session 1 source interface gigabitEthernet Gi3/19


設定 destination
指令 :monitor session x destination interface gigabitEthernet x/x

範例如下
4507R-1(config)#monitor session 1 destination interface gigabitEthernet Gi3/18



PS : x/x 請寫上 PORT的位置,如 Gi3/19 (第3張卡片的第 19 port)
        session X 其 X 值 要一致 , 這樣視為一個完整的來源跟目的地 .



查看設定狀況 :

指令 : show monitor (detail)

範例如下圖所示 :




























大功告成

2009年4月16日 星期四

CISCO Route 設定 : Clock 篇

設定 CISCO Clock 步驟 :

首先 telnet 到 route 然後到 privileged mode

指令 : clock set (hh:mm:ss) (day) (month) (Year)

整個設定步驟如下圖 :



查詢目前 route 的 clock


指令 : show clock


執行如下圖 :


2009年1月10日 星期六

CISCO Switch 如何控管 PORT 防私接 HUB 之密技

當網管的有時候好像 007 , 調查局 , 要時時維護網路的暢通和監控網路上各種狀況
免得 USER 一些有意或無意的行為導致整個企業網路損壞 , 其中對於 switch 連接到各 user
最容易被偷偷接未授權的 HUB (switch) 最常發生 .

以前都是用道德勸說 , 或不定時檢查實體網路 . 這樣往往無法得到預期的結果
如何控管 SWITCH PORT 不被 USER 私自接上 HUB (switch) , 能自動偵測 , 一有發現立刻
disable port , 這樣不是很完美 ..

本案例是使用 CISCO SWITCH

telnet 到 switch

cisco > enable
Password: .....
cisco# config
Configuring from terminal, memory, or network [terminal] ?
Enter configuration commands, one per line. End with CNTL/z.

cisco (config)# interface fastEthernet 0/xx
cisco (config-if)#switchport mode access
cisco (config-if)#switchport port-security

按 ctrl /z 離開

<< 最後記得 wr m 存起來 , 免得重開設定又恢復原狀 >>



可以用 show port-security interface fastEthernet 0/xx 查看設定是否有成功

設定前 , 如下圖所示 :




設定後 , 如下圖所示 :




當 switch 偵測到 port 有私接 HUB(switch) 立刻 disable port
如下圖所示 : (紅色圈圈處)