CISCO NAT 運作查詢指令
指令 : show ip nat translation
指令 : show ip nat statistics
官網詳細資料
http://www.cisco.com/c/en/us/support/docs/ip/network-address-translation-nat/8605-13.html
2015年2月17日 星期二
2013年4月25日 星期四
CISCO Monitor PORT 設定 範例
若需要監聽特定的網路設備 , 來做分析的話 , 必須把被監聽跟收集資料
的設備在 SWITCH 上作設定。把所有經過被監聽對象的網路流都複製到
指定的設備上。
此篇文章以 CISCO 的 SWITCH 作為範例。
===================================================
User Access Verification
Password:
4507R-1#en
Password:
4507R-1#
4507R-1#config
Configuring from terminal, memory, or network [terminal]?
Enter configuration commands, one per line. End with CNTL/Z.
設定 source
指令 :monitor session x source interface gigabitEthernet x/x
範例如下
4507R-1(config)#monitor session 1 source interface gigabitEthernet Gi3/19
設定 destination
指令 :monitor session x destination interface gigabitEthernet x/x
範例如下
4507R-1(config)#monitor session 1 destination interface gigabitEthernet Gi3/18
PS : x/x 請寫上 PORT的位置,如 Gi3/19 (第3張卡片的第 19 port)
session X 其 X 值 要一致 , 這樣視為一個完整的來源跟目的地 .
查看設定狀況 :
指令 : show monitor (detail)
範例如下圖所示 :
大功告成
2009年4月16日 星期四
CISCO Route 設定 : Clock 篇
2009年1月10日 星期六
CISCO Switch 如何控管 PORT 防私接 HUB 之密技
當網管的有時候好像 007 , 調查局 , 要時時維護網路的暢通和監控網路上各種狀況
免得 USER 一些有意或無意的行為導致整個企業網路損壞 , 其中對於 switch 連接到各 user
最容易被偷偷接未授權的 HUB (switch) 最常發生 .
以前都是用道德勸說 , 或不定時檢查實體網路 . 這樣往往無法得到預期的結果
如何控管 SWITCH PORT 不被 USER 私自接上 HUB (switch) , 能自動偵測 , 一有發現立刻
disable port , 這樣不是很完美 ..
本案例是使用 CISCO SWITCH
telnet 到 switch
cisco > enable
Password: .....
cisco# config
Configuring from terminal, memory, or network [terminal] ?
Enter configuration commands, one per line. End with CNTL/z.
cisco (config)# interface fastEthernet 0/xx
cisco (config-if)#switchport mode access
cisco (config-if)#switchport port-security
按 ctrl /z 離開
<< 最後記得 wr m 存起來 , 免得重開設定又恢復原狀 >>
可以用 show port-security interface fastEthernet 0/xx 查看設定是否有成功
設定前 , 如下圖所示 :

設定後 , 如下圖所示 :

當 switch 偵測到 port 有私接 HUB(switch) 立刻 disable port
如下圖所示 : (紅色圈圈處)
免得 USER 一些有意或無意的行為導致整個企業網路損壞 , 其中對於 switch 連接到各 user
最容易被偷偷接未授權的 HUB (switch) 最常發生 .
以前都是用道德勸說 , 或不定時檢查實體網路 . 這樣往往無法得到預期的結果
如何控管 SWITCH PORT 不被 USER 私自接上 HUB (switch) , 能自動偵測 , 一有發現立刻
disable port , 這樣不是很完美 ..
本案例是使用 CISCO SWITCH
telnet 到 switch
cisco > enable
Password: .....
cisco# config
Configuring from terminal, memory, or network [terminal] ?
Enter configuration commands, one per line. End with CNTL/z.
cisco (config)# interface fastEthernet 0/xx
cisco (config-if)#switchport mode access
cisco (config-if)#switchport port-security
按 ctrl /z 離開
<< 最後記得 wr m 存起來 , 免得重開設定又恢復原狀 >>
可以用 show port-security interface fastEthernet 0/xx 查看設定是否有成功
設定前 , 如下圖所示 :

設定後 , 如下圖所示 :

當 switch 偵測到 port 有私接 HUB(switch) 立刻 disable port
如下圖所示 : (紅色圈圈處)
訂閱:
文章 (Atom)


