ÎÞ·¨Í¨¹ýCLI¹ÜÀí×°±¸
Ò»¡¢Õ÷ÏóÐÎò
×°±¸ÓÐËÄÖֵǼ·½·¨£ºSSH / TELNET / CONSOLE / WEB
·ºÆðÈçϹÊÕÏ£º
1¡¢CONSOLE¿ÚÎÞ·¨µÇ¼
2¡¢TELNETÎÞ·¨µÇ¼
3¡¢SSHÎÞ·¨µÇ¼
4¡¢WEBÎÞ·¨µÇ¼
¶þ¡¢×éÍøÍØÆË

Èý¡¢¿ÉÄÜÔµ¹ÊÔÓÉ
1¡¢CRTÈí¼þÉèÖòÎÊýÎÊÌ⣬»òÕßconsoleÏßÎÊÌâ
2¡¢control-planeեȡµÇ¼ÉèÖã¬ACL¹ýÂËÏÞÖÆ£¬VTYÏß³ÌÕ¼Âú
ËÄ¡¢´¦Öóͷ£°ì·¨
Õ÷Ïó1£ºCONSOLEÎÞ·¨µÇ¼
°ì·¨1¡¢¼ì²é×°±¸µçÔ´µÆÔËÐÐ״̬
1. ¼ì²éPWRµÆ×´Ì¬
µçÔ´Õý³££ºÂÌÉ«³£ÁÁ
µçÔ´¹Ø±Õ»ò¹ÊÕÏ£º²»ÁÁ
±¸×¢£ºÈôÊǵçÔ´µÆ²»ÁÁ£¬Çë¼ì²éµçÔ´ÊÇ·ñÕý³£¼Óµç£¬ÅжÏ×°±¸ÊÇ·ñ±£´æÓ²¼þÎÊÌâµ¼ÖÂÎÞ·¨¼Óµç
2. ¼ì²éSYSµÆ×´Ì¬
Éϵç³õʼ»¯£ºÂÌÉ«ÉÁׯ
³õʼ»¯Íê³É£ºÂÌÉ«³£ÁÁ
¸æ¾¯£ººìÉ«³£ÁÁ
±¸×¢£º¿ÉÒÔ¹Ø×¢consoleÊä³öÈÕÖ¾¾ÙÐÐÅжÏÈí¼þÊÇ·ñ±£´æÒì³£
°ì·¨2¡¢ConsoleÏß²ÎÊýÉèÖÃ
ÈôÊÇʹÓÃCRTÈí¼þ£¬ConsoleÏߵǼÐèҪѡÔñ׼ȷµÄcom¿Ú£¬ÒÔ¼°²¨ÌØÂÊΪ9600£¬²»¿É¹´Ñ¡Á÷¿ØÎ»
¶Ë¿Ú¿ÉÒÔͨ¹ýµçÄԶ˵Ä×°±¸¹ÜÀíÆ÷Éó²é
ÈçÏÂͼËùʾ
°ì·¨3¡¢Ìæ»»consoleÏß/×°±¸²âÊÔ
1¡¢Ìæ»»consoleÏß¾ÙÐвâÊÔ£¬ÅжÏÏÂconsoleÏßÊÇ·ñ±£´æÎÊÌâ
2¡¢ÈôÊÇûÓжàÓàconsoleÏߣ¬Ìæ»»ÆäËûÖ§³ÖconsoleµÇ¼µÄ·½·¨²âÊÔ
ÈôÊÇconsole¿ÚÈÔÈ»ÎÞ·¨µÇ¼£¬´°¿ÚûÓÐÊäÈëºÍÊä³ö£¬¿ÉÄܱ£´æconsole±£´æÓ²¼þÎÊÌâ¡£¿ÉÒÔʹÓÃÆäËû·½·¨¾ÙÐеǼ²âÊÔ¡£
Õ÷Ïó2£ºTELNETÎÞ·¨µÇ¼
°ì·¨1¡¢ÅŲéµÇ¼²ÎÊýÉèÖ㨵ØÖ·¡¢¶Ë¿Ú£©
1¡¢µÇ¼µØÖ·¹ýʧ
a. consoleÏߵǼ¿ÉÒÔÉó²é½Ó¿ÚµØÖ·£¬ÏêϸÏÂÁîΪshow ip interface brief
ÈçÉÏÏÖÔÚ2¿ÚΪÄÚÍø¿Ú£¬7¿ÚΪÍâÍø¿ÚµØÖ·£¬¿ÉÒÔͨ¹ýÕâÁ½¸ö½Ó¿ÚµÇ¼װ±¸£¬ÍâÍøÓû§Ö»ÄÜͨ¹ýÍâÍø¿ÚµØÖ·µÇ¼װ±¸
b¡¢ÏëҪȷÈÏÍâÍø¿ÚµØÖ·£¬Ò²¿ÉÒÔͨ¹ýÄÚÍø¿ÚÏȵǼװ±¸ºó£¬È»ºóÔÙÉó²é¶ÔÓ¦µÄÍâÍø¿ÚµØÖ·£¬
·¾¶£ºÍøÂç—½Ó¿ÚÉèÖ×¶ÔÓ¦ÍâÍø¿Ú
Ôö²¹£ºtelnetµÄ¶Ë¿ÚĬÒÔΪ23£¬telnet ¶Ë¿ÚÊÇÎÞ·¨Ð޸ĵÄ
°ì·¨2¡¢ÅŲé×°±¸ÉÏÇå¾²ÏÞÖÆ£¬Õ¥È¡µÇ¼£¬ACL¹ýÂË
1. ÍâµØ·À¹¥»÷ÉèÖÃեȡtelnetµÇ¼²Ù×÷£¬Ïêϸ·¾¶ÎªÇå¾²—ÍâµØ·À¹¥»÷—եȡÄÚÍø/ÍâÍøµÇ¼װ±¸
¶ÔÓ¦ÏÂÁîΪ£º
control-plane
security deny lan-telnet-ssh-----եȡÄÚÍøtelnetºÍsshµÇ¼װ±¸
security deny wan-telnet-ssh-----եȡÍâÍøtelnetºÍsshµÇ¼Éè
2. ÔÚ½Ó¿ÚŲÓûòip session filterŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
a. ½Ó¿Ú»á¼ûÁбíϵÄŲÓã¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
b. Ip session filter Á÷¹ýÂ˲Ù×÷£¬È«¾ÖŲÓã¬È«¾ÖÉúЧ£¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
c. Line vtyÏÂŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄÍø¶Î»á¼û×°±¸£¬µ¼ÖÂÎÞ·¨telnet
ËùŲÓõÄACL161ÐèÒª·ÅͨµÇ¼װ±¸µÄ¶Ë¿Ú»òIPµØÖ·
Ïêϸ·¾¶£ºÇå¾²—ACL»á¼ûÁбí
ÉèÖÃÍ꣬ÏÂÁîÐжÔӦϷ¢µÄÏÂÁîÈçÏ£º
°ì·¨3¡¢ÅŲéÓ³É䵼ֵǼ¶Ë¿Ú±»Õ¼ÓÃ
ÏêϸÉèÖÃÈçÏ£ºÄÚÍø·þÎñÆ÷Ó³ÉäʱӳÉäµ½×°±¸µÇ¼¶Ë¿ÚºÃ±È˵23£¬»òÕßÊÇÉèÖÃÁËÕû»úÓ³ÉäÓ³Éäµ½½Ó¿ÚÉÏ£¬µ¼ÖÂ×°±¸µÇ¼¶Ë¿Ú±»Õ¼Ó㬻ᵼÖÂ×°±¸ÎÞ·¨µÇ¼£¬
a. ¶Ë¿ÚÓ³ÉäÉèÖÃ
¶ÔÓ¦ÏÂÁîÈçÏ£º
ip nat inside source static tcp 192.168.1.10 23 172.18.161.111 23
b. Õû»úÓ³ÉäÉèÖÃ
¶ÔÓ¦ÏÂÁîÈçÏ£º
ip nat inside source static 192.168.1.10 172.18.161.111 permit-inside
½â¾öÒªÁ죺½«ÍâÍøÓ³Éä¶Ë¿Ú23Ó³ÉäΪ1023µÈ¶Ë¿Ú£¬×èÖ¹¶Ë¿ÚÕ¼ÓÃÎÊÌâ¡£
°ì·¨4¡¢ÅŲé¶àÌõÍâÍøÏßµÄÇéÐÎÏÂûÓпªÆôÔ´½øÔ´³ö
¶àÌõÍâÍøÏßµÄÇéÐÎÏÂûÓпªÆôÔ´½øÔ´³ö£¬µ¼ÖÂÍâÍø»á¼ûµ½×°±¸µÄÊý¾ÝÁ÷·ºÆð´Ó½Ó¿Ú7½øÀ´¿ÉÊÇ´Ó½Ó¿Ú6³öÈ¥ÁË¡£ÒÔÊÇÔÚÍâÍø¿ÚÐèÒª¿ªÆôÔ´½øÔ´³ö
Ïêϸ·¾¶ÈçÏ£ºÍøÂç—½Ó¿ÚÉèÖ×¶ÔÓ¦½Ó¿ÚϹ´Ñ¡Ô´½øÔ´³ö
¶ÔÓ¦µÄÏÂÁîÈçÏ£º
°ì·¨5¡¢ÅŲé·þÎñÊÇ·ñÆôÓûòÕßÊÇ·ñ±£´æweb°ü
1¡¢µÇ¼·þÎñûÓпªÆô
ÏêϸÏÂÁÉó²ételnetÊÇ·ñ¿ªÆô——show service
2¡¢Éó²é¶Ë¿ÚÊÇ·ñÕý³£¼àÌý
£¨1£©Show tcp connect £¬LISTEN´ú±í¼àÌý״̬ÊôÓÚÕý³£×´Ì¬

°ì·¨6¡¢VTYÏ̱߳»Õ¼Âú
¿ÉÒÔͨ¹ýshow usersÉó²évtyÕ¼ÓõÄÏß³ÌÊÇ·ñÂúÁË£¬Ä¬ÈÏÊÇ5¸öÏ̡߳£¿ÉÒÔͨ¹ýclear line vty ¶ÔÓ¦ÊýÖµ¾ÙÐÐÏß³Ìɨ³ý£¬ÔÙʵÑéµÇ¼¡£
Õ÷Ïó3£ºSSHÎÞ·¨µÇ¼
°ì·¨1¡¢ÅŲéµÇ¼²ÎÊýÉèÖ㨵ØÖ·¡¢¶Ë¿Ú£©
1¡¢µÇ¼µØÖ·¹ýʧ
a. consoleÏߵǼ¿ÉÒÔÉó²é½Ó¿ÚµØÖ·£¬ÏêϸÏÂÁîΪshow ip interface brief
ÈçÉÏÏÖÔÚ2¿ÚΪÄÚÍø¿Ú£¬7¿ÚΪÍâÍø¿ÚµØÖ·£¬¿ÉÒÔͨ¹ýÕâÁ½¸ö½Ó¿ÚµÇ¼װ±¸£¬ÍâÍøÓû§Ö»ÄÜͨ¹ýÍâÍø¿ÚµØÖ·µÇ¼װ±¸
b¡¢ÏëҪȷÈÏÍâÍø¿ÚµØÖ·£¬Ò²¿ÉÒÔͨ¹ýÄÚÍø¿ÚÏȵǼװ±¸ºó£¬È»ºóÔÙÉó²é¶ÔÓ¦µÄÍâÍø¿ÚµØÖ·£¬Â·¾¶£ºÍøÂç—½Ó¿ÚÉèÖ×¶ÔÓ¦ÍâÍø¿Ú
¡¾Ôö²¹¡¿£ºSSHµÇ¼¶Ë¿ÚĬÒÔΪ22£¬SSHµÄ¶Ë¿ÚÊÇÎÞ·¨Ð޸ĵÄ
2¡¢SSH·þÎñÐèÒª¿ªÆô
¸Ã¹¦Ð§Ä¿½ñÖ»Ö§³ÖÏÂÁÆô£¬²»Ö§³Öweb¿ªÆô
Ruijie(config)#enable service ssh-server //¿ªÆôSSH·þÎñ
Ruijie(config)#crypto key generate dsa //¼ÓÃÜ·½·¨ÓÐÁ½ÖÖ£ºDSAºÍRSA,¿ÉÒÔËæÒâÑ¡Ôñ
Choose the size of the key modulus in the range of 360 to 2048 for your
Signature Keys. Choosing a key modulus greater than 512 may take a few minutes.
How many bits in the modulus [512]://Ö±½ÓÇûسµ
% Generating 512 bit DSA keys ...[ok]
°ì·¨2¡¢ÅŲé×°±¸ÉÏÇå¾²ÏÞÖÆ£¬Õ¥È¡µÇ¼£¬ACL¹ýÂË
1¡¢ÍâµØ·À¹¥»÷ÉèÖÃեȡsshµÇ¼µÈ²Ù×÷£¬Ïêϸ·¾¶ÎªÇå¾²—ÍâµØ·À¹¥»÷—եȡÄÚÍø/ÍâÍøµÇ¼װ±¸
¶ÔÓ¦ÏÂÁîΪ£º
control-plane
security deny lan-telnet-ssh-----եȡÄÚÍøtelnetºÍsshµÇ¼װ±¸
security deny wan-telnet-ssh-----եȡÍâÍøtelnetºÍsshµÇ¼װ±¸
2¡¢ÔÚ½Ó¿ÚŲÓûòip session filterŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
a. ½Ó¿Ú»á¼ûÁбíϵÄŲÓã¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
2¡¢ Ip session filter Á÷¹ýÂ˲Ù×÷£¬È«¾ÖŲÓã¬È«¾ÖÉúЧ£¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
3¡¢ Line vtyÏÂŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄÍø¶Î»á¼û×°±¸£¬µ¼ÖÂÎÞ·¨telnet

ËùŲÓõÄACL161ÐèÒª·ÅͨµÇ¼װ±¸µÄ¶Ë¿Ú»òIPµØÖ·
Ïêϸ·¾¶£ºÇå¾²—ACL»á¼ûÁбí
ÉèÖÃÍ꣬ÏÂÁîÐжÔӦϷ¢µÄÏÂÁîÈçÏ£º
°ì·¨3¡¢ÅŲéÓ³É䵼ֵǼ¶Ë¿Ú±»Õ¼ÓÃ
ÏêϸÉèÖãºÄÚÍø·þÎñÆ÷Ó³ÉäʱӳÉäµ½×°±¸µÇ¼¶Ë¿ÚºÃ±È˵22£¬»òÕßÊÇÉèÖÃÁËÕû»úÓ³ÉäÓ³Éäµ½½Ó¿ÚÉÏ£¬µ¼ÖÂ×°±¸µÇ¼¶Ë¿Ú±»Õ¼Ó㬻ᵼÖÂ×°±¸ÎÞ·¨µÇ¼£¬
1¡¢¶Ë¿ÚÓ³ÉäÉèÖÃ
¶ÔÓ¦ÏÂÁîÈçÏ£ºip nat inside source static tcp 192.168.1.10 22 172.18.161.111 22
2. Õû»úÓ³ÉäÉèÖÃ
¶ÔÓ¦ÏÂÁîÈçÏ£ºip nat inside source static 192.168.1.10 172.18.161.111 permit-inside
½â¾öÒªÁ죺½«ÍâÍøÓ³Éä¶Ë¿Ú22Ó³ÉäΪ1022¶Ë¿Ú£¬×èÖ¹¶Ë¿ÚÕ¼ÓÃÎÊÌâ
°ì·¨4¡¢ÅŲé¶àÌõÍâÍøÏßµÄÇéÐÎÏÂûÓпªÆôÔ´½øÔ´³ö
¶àÌõÍâÍøÏßµÄÇéÐÎÏÂûÓпªÆôÔ´½øÔ´³ö£¬µ¼ÖÂÍâÍø»á¼ûµ½×°±¸µÄÊý¾ÝÁ÷·ºÆð´Ó½Ó¿Ú7½øÀ´¿ÉÊÇ´Ó½Ó¿Ú6³öÈ¥ÁË¡£
ÒÔÊÇÔÚÍâÍø¿ÚÐèÒª¿ªÆôÔ´½øÔ´³ö£¬
Ïêϸ·¾¶£ºÍøÂç—½Ó¿ÚÉèÖ×¶ÔÓ¦½Ó¿ÚϹ´Ñ¡Ô´½øÔ´³ö
¶ÔÓ¦µÄÏÂÁîÈçÏ£º
°ì·¨5¡¢ÅŲé·þÎñÊÇ·ñÆôÓûòÕßÊÇ·ñ±£´æweb°ü
1¡¢µÇ¼·þÎñûÓпªÆô£¬
ÏêϸÏÂÁÉó²ételnet»òSSHÊÇ·ñ¿ªÆô——show service
2¡¢Éó²é¶Ë¿ÚÊÇ·ñÕý³£¼àÌý
show tcp connect £¬LISTEN´ú±í¼àÌý״̬ÊôÓÚÕý³£×´Ì¬
°ì·¨6¡¢VTYÏ̱߳»Õ¼Âú
¿ÉÒÔͨ¹ýshow usersÉó²évtyÕ¼ÓõÄÏß³ÌÊÇ·ñÂúÁË£¬Ä¬ÈÏÊÇ5¸öÏ̡߳£¿ÉÒÔͨ¹ýclear line vty ¶ÔÓ¦ÊýÖµ¾ÙÐÐÏß³Ìɨ³ý£¬ÔÙʵÑéµÇ¼¡£
Îå¡¢ÐÅÏ¢ÍøÂç
×¢ÖØ£ºÒÔÏÂÏÂÁîÊÊÓÃÓÚtelnet¡¢sshÎÞ·¨µÇ¼£¬µ«ÉèÖÿڿÉÒԵǼµÄÇéÐΣ¬ÈôÉèÖÿÚÒ²ÎÞ·¨µÇ¼£¬ÇëʵʱÁªÏµ400¹¤³Ìʦ´¦Öóͷ£¡£
sh ver
sh run
sh service
sh users
sh int usage
sh tcp connect
sh memory
sh cpu | ex 0.00
sh log rev
show int usage
sh envir
sh ip fpm sta
debug su
execute diagnose-cmd fdisk
execute diagnose-cmd mount
exit
Áù¡¢×ܽáÓ뽨Òé
µ±µçÄÔÎÞ·¨¹ÜÀí×°±¸£¬½¨ÒéÓÅÏȼì²éSESSION FILTERŲÓõÄACLÊÇ·ñ¾ÙÐÐÁËÏÞÖÆ¡£ÈôÊÇûÓÐÏÞÖÆ£¬¿ÉÒÔͨ¹ýshow usersºÍshow ip fpm flow | in ²âÊÔµçÄÔIP£¬À´ÅжÏÊý¾ÝÊÇ·ñµ½µÖ´ïEG¡£
¡¾Ôö²¹¡¿Èçδ½â¾ö»òÐèÒªÏàʶ¸ü¶àÏêÇ飬¿Éµã»÷ÊÛºóÉÁµçÍþÙÐÐ×Éѯ