
1.3 配置 MDA端口
1.3.1 POS端口配置
configure port 1/1/1
sonet-sdh framing sdh path
scramble 打开加扰 no shutdown exit exit
no shutdown exit
1.3.2 以太口配置
configure port 2/1/1 ethernet
no autonegotiate 关闭自动协商 exit
no shutdown exit port 2/1/1 ethernet
encap-type dot1q 封装为dot1q no autonegotiate exit
no shutdown exit
1.3.3 查看port信息
SR#show port SR#show port 1/1/1 Confidential
第 6 页 共 27 页
IPD
二、设备管理配置
2.1 配置路由器名称、location、contact
SR#Configure system name WHG7750
SR#configure system contact “Fred Information Technology” SR#configure system location “Bldg.1-floor 2-Room 201”
2.2 配置系统时间
SR#admin set-time 2006/03/16 11:26:00
2.3 配置SNTP
2.3.1 打开SNTP
SR#Configure system time
SR>configure>sntp no shutdown
2.3.2 配置SNTP地址
SR>configure>Sntp server-address 61.154.237.1 preferred
2.4 配置SR为telnet服务器
SR#configure system security
SR>config>system>security# telnet-server SR>config>system>security# ssh
Confidential 第 7 页 共 27 页 IPD
2.5 配置telnet登陆限制
2.5.1 配置默认动作为允许,因为是所有上主控板的流量。
SR>config>system>security# management-access-filter security>mgmt-access-filter# default-action permit 2.5.2 配置允许
IP段的ACL,配置源IP,协议,目的端口
security>mgmt-access-filter# entry 10
security>mgmt-access-filter>entry# action permit
security>mgmt-access-filter>entry# src-ip 61.143.127.192/27 security>mgmt-access-filter>entry# protocol 6
security>mgmt-access-filter>entry# dst-port 23 65535
2.5.3 配置一条拒绝的ACL,拒绝其他IP段。
security>mgmt-access-filter>entry# entry 150 security>mgmt-access-filter>entry# action deny security>mgmt-access-filter>entry# protocol 6
security>mgmt-access-filter>entry# dst-port 23 65535 security>mgmt-access-filter>entry# exit
2.6 配置用户 2.6.1 配置用户名
SR>config>system>security#user \
2.6.2 配置用户密码
SR>config>system>security#password 123456
Confidential
第 8 页 共 27 页
IPD
2.6.3 配置用户登陆方式
SR>config>system>security#access console ftp
2.6.4 配置用户所属的组
SR>config>system>security#console
SR>config>system>security> console #no member \ SR>config>system>security> console #member \
2.7 配置LOG
2.7.1 配置log-id
SR>config# log
SR>config>log# log-id 10
2.7.2 配置log信息类型
SR>config>log>log-id# from main security change
2.7.3 配置记录log的方式
SR>config>log>log-id# to file 10 SR>config>log>log-id# to syslog 5 SR>config>log>log-id# no shutdown SR>config>log>log-id# exit
2.7.4 配置记录log方式的具体配置
SR>config>log>file-id 10
SR>config>log>file-id#location cf3: SR>config>log>syslog 5
SR>config>log>syslog#address 218.14.118.29
Confidential
第 9 页 共 27 页
IPD
2.8 配置SNMP
SR>config>system>security# snmp
SR>config>system>security>snmp# community private rwa version both SR>config>system>security>snmp# community public r version v2c
2.9 配置主备板同步
2.9.1 配置自动同步
SR#config redundancy synchronize config
2.9.2 手工同步命令 SR#admin synchronize config
SR#admin redundancy force-switchover now
2.10 配置空闲时间
SR#config system login-control idle-timeout 600
2.11 配置anti-spoof
SR-7>config>service>ies# info
---------------------------------------------- interface \ address 201.201.1.1/24 sap 1/1/2 create anti-spoof exit exit
no shutdown
Confidential
第 10 页 共 27 页
IPD
百度搜索“70edu”或“70教育网”即可找到本站免费阅读全部范文。收藏本站方便下次阅读,70教育网,提供经典综合文库阿尔卡特7750配置文档(2)在线全文阅读。
相关推荐: