L2/L3 ½ºÀ§Ä¡·Î ±×µ¿¾È ½Ã½ºÄÚ 3560G ½ºÀ§Ä¡¸¦ ÁÖ·Î »ç¿ëÇØ ¿Ô´Ù.
ÇÏÁö¸¸ ÃÖ±Ù¿¡ 10G ¿Í 1G¸¦ È¥¿ëÇÑ L2/L3 ½ºÀ§Ä¡¸¦ »ìÆ캸´Ù°¡
¾ËÄ«ÅÚ-·ç½¼Æ® »çÀÇ ¿È´Ï½ºÀ§Ä¡ 6850 ½ºÀ§Ä¡¸¦ »ç¿ëÇÏ°Ô µÇ¾ú½À´Ï´Ù.
1~24 1G UTP Æ÷Æ®°¡ ÀÖ°í, 21~24 ³× Æ÷Æ®´Â GBIC À¸·Î ²Å¾Æ ±¤¿¬°áÀÌ °¡´ÉÇϵµ·Ï µÇ¾î ÀÖ±¸¿ä,
25,26 µÎ °³ÀÇ XFP 10G Æ÷Æ®°¡ ÀÖ½À´Ï´Ù.
ÄÜ¼Ö ¿¬°á½Ã aOS ¿î¿µ½Ã½ºÅÛÀÇ CLI (Command Line Interface)°¡ Á¸ÀçÇϴµ¥,
½Ã½ºÄÚ Ä«Å»¸®½ºÆ®ÀÇ iOS¿Í À¯»çÇÏ°Ô µ¿ÀÛÇÏ¿´½À´Ï´Ù.
¿ì¼± ÄÜ¼Ö ¿¬°áÀ» Çϴµ¥, ±âÁ¸ÀÇ ÄÜ¼Ö ÄÉÀ̺í·Î´Â ¿¬°áÀÌ µÇÁö ¾Ê¾Ò°í,
Àåºñ¿¡¼ Á¦°øÇÏ´Â RJ45 <=> RS232(¾Ï) ¾î´äÅÍ°¡ ¿À´Âµ¥ RJ45¿¡ ÀÏ¹Ý UTP ·£ÄÉÀ̺í·Î
¿È´Ï½ºÀ§Ä¡ÀÇ Äֿܼ¡ ¿¬°áÇÏ°í RS232 ºÎºÐÀ» ÄÜ¼Ö ¿¬°áÇÒ ÄÄÀÇ ½Ã¸®¾ó¿¡ ¿¬°áÇÏ¸é µË´Ï´Ù.
ÀÏ´Ü ÄַܼΠ¿¬°áµÇ¸é
login : admin
password : switch
Welcome to the Alcatel-Lucent OmniSwitch 6000
Software Version 6.4.3.520.R01 GA, April 08, 2010.
Copyright(c), 1994-2010 Alcatel-Lucent. All Rights reserved.
OmniSwitch(TM) is a trademark of Alcatel-Lucent registered
in the United States Patent and Trademark Office.
->
À§¿Í °°Àº ¿¬°áÀ» ÇÏ¸é µË´Ï´Ù.
¾ÏÈ£º¯°æ
-> password
1) Ãʱ⠼³Á¤
1.1) ½Ã°£ ¹× ŸÀÓÁ¸ ¼³Á¤
-> system timezone kst
-> system time HH:MM:SS
-> show system
1.2) Ãʱ⿡´Â ½ºÀ§Ä¡¿¡ IP¸¦ ¼³Á¤ÇÏ°í telnetÀ¸·Î Á¢±ÙÇصµ ¿¬°áÀÌ µÇÁö ¾Ê´Âµ¥,
¾Æ·¡¿Í °°ÀÌ ÀÎÁõÀ» Ç®¾îÁà¾ß ÇÔ.
-> aaa authentication default local
1.3) ¼³Á¤À» Àåºñ¸¦ ²¯´Ù°¡ ´Ù½Ã Äѵµ ¼³Á¤ÀÌ »ì¾ÆÀÖ°Ô ÇÏ·Á¸é,
-> write memory
1.4) Àåºñ reboot
-> reload
2) VLAN ¼³Á¤
¾ÆÁ÷ Àß ¸ô¶ó¼ ±×·² ¼öµµ Àִµ¥ VLAN ¾øÀÌ Æ÷Æ® Çϳª¸¸ IP¸¦ ÁöÁ¤ÇÏ´Â ¹æ¹ýÀº
¾ø°í »óÀ§ÀÇ VLANÀ¸·Î ÁöÁ¤À» ÇØÁÖ°í IP¸¦ ¼³Á¤ÇØ¾ß ÇßÀ½.
2.1) VLAN º¸±â
-> show vlan
2.2) VLAN »ý¼º
-> vlan 99
(¹øÈ£¸¸ ÁöÁ¤ÇÏ¸é µÈ´Ù)
2.3) VLAN »èÁ¦
-> no vlan 99
3) L3 ½ºÀ§Ä¡ ±¸¼º
1~12¸¦ VLAN 100À¸·Î ÁöÁ¤ÇÏ°í 20.20.20.1/24 IP ¼³Á¤
3.1) ¼³Á¤
-> vlan 200
(VLAN 200¹ø »ý¼º)
-> vlan 200 port default 1/1-12
(1~12 ¹ø Æ÷Æ®¸¦ VLAN 100¿¡ ÇÒ´ç)
-> ip interface vlan-200 address 20.20.20.1/24 vlan 200
(ÇØ´ç VLAN¿¡ 20.20.20.1/24 ÁÖ¼Ò ÇÒ´ç)
3.2) È®ÀÎ
(VLAN ¸ñ·Ï È®ÀÎ)
-> show vlan
vlan type admin oper 1x1 flat auth ip ipx tag lrn name
-----+------+------+------+------+------+----+-----+-----+-----+-----+----------
1 std on on on on off on NA off on VLAN 1
99 std on on on on off on NA off on VLAN 99
100 std on off on on off on NA off on VLAN 100
(VLAN ÇÒ´ç Æ÷Æ® ¸ñ·Ï È®ÀÎ)
-> show vlan port
vlan port type status
------+-------+---------+-------------
1 1/13 default inactive
1 1/14 default inactive
1 1/15 default forwarding
1 1/16 default inactive
1 1/17 default inactive
1 1/18 default inactive
1 1/19 default forwarding
1 1/20 default inactive
1 1/21 default inactive
1 1/22 default inactive
1 1/23 default forwarding
1 1/25 default inactive
1 1/26 default inactive
99 1/24 default forwarding
100 1/1 default inactive
100 1/2 default inactive
100 1/3 default inactive
100 1/4 default inactive
100 1/5 default inactive
100 1/6 default inactive
100 1/7 default inactive
100 1/8 default inactive
100 1/9 default inactive
100 1/10 default inactive
100 1/11 default inactive
100 1/12 default inactive
(VLAN ÇÒ´ç IP È®ÀÎ)
-> show ip interface
Total 4 interfaces
Name IP Address Subnet Mask Status Forward Device
--------------------+---------------+---------------+------+-------+--------
Loopback 127.0.0.1 255.0.0.0 UP NO Loopback
dhcp-client 0.0.0.0 0.0.0.0 DOWN NO vlan 1
vlan-100 20.20.20.1 255.255.255.0 DOWN NO vlan 100
vlan_99 10.99.99.1 255.0.0.0 UP YES vlan 99
4) IP ¶ó¿ìÆà ¼³Á¤ (½ºÅÂƽ)
-> ip static-route 40.0.0.0 mask 255.0.0.0 gateway 20.20.20.139
-> show ip route
5) Æ÷Æ® Á¤º¸ º¸±â
-> show interfaces 1/3 counters
1/3 ,
InOctets = 1697512645, OutOctets = 975263938,
InUcastPkts = 15865327, OutUcastPkts = 8779963,
InMcastPkts = 0, OutMcastPkts = 5098,
InBcastPkts = 5456, OutBcastPkts = 13983,
InPauseFrames = 0, OutPauseFrames = 0,
Sampling Interval 5 seconds
InPkts/s = 71318, OutPkts/s = 34765,
InBits/s = 61247760, OutBits/s = 29201904
6) CPU, Memory µîÀÇ Á¤º¸ º¸±â
-> show health
* - current value exceeds threshold
Device 1 Min 1 Hr 1 Hr
Resources Limit Curr Avg Avg Max
-----------------+-------+------+------+-----+----
Receive 80 01 01 01 01
Transmit/Receive 80 01 01 01 01
Memory 80 71 71 71 71
Cpu 80 09 12 12 16
7) Config ÆÄÀÏ °ü·Ã
-> dir
Listing Directory /flash:
drw 1024 Jul 19 10:38 certified/
-rw 317 Jul 19 10:41 boot.params
drw 1024 Jul 19 10:43 working/
-rw 11 Jul 13 03:36 boot.slot.cfg
-rw 64000 Jul 19 10:52 swlog1.log
-rw 64000 Dec 26 2010 swlog2.log
drw 1024 Dec 26 2010 switch/
drw 1024 Jul 13 03:36 network/
12284928 bytes free
À§¿Í °°ÀÌ /flash ¿¡´Â working cerified Æú´õ°¡ Àִµ¥,
working¿¡¼ ÀÛ¾÷À» ÇÏ°Ô µÇ°í, reload ¸í·É¾î·Î rebootÀ» ÇÒ ¼ö Àִµ¥,
-> reload
¶ó Çϸé certified µð·ºÅ͸®¿¡¼ ÀÐ¾î¼ ÀçºÎÆÃÀ» ÇϰԵǰí,
-> reload working no rollback-time
À̶ó Çϸé working µð·ºÅ͸®ÀÇ ¼³Á¤°ªÀ¸·Î ºÎÆÃÀ» ÇÕ´Ï´Ù.
½ÇÁ¦ ¼³Á¤ ÀÛ¾÷À» Çϸé ÀÌ°ÍÀº running-config ¶ó´Â ¸Þ¸ð¸®¿¡ ÀúÀåµÇ´Â °ÍÀÌ°í
-> write memory
¿Í µ¿ÀÏÇÑ ¸í·É¾î·Î
-> copy running-config working
¸Þ¸ð¸®ÀÇ ¼³Á¤ ³»¿ëÀ» working Æú´õ¿¡ º¹»çÇÏ´Â °ÍÀÔ´Ï´Ù.
¶ÇÇÑ,
-> copy working certified
¶ó°í ÇÏ¿© working Æú´õ¿¡ ³»¿ëÀ» certified Æú´õ·Î ÀÏÄ¡¸¦ ½Ãų ¼ö ÀÖ½À´Ï´Ù.
-> cd working
¿¡¼ dir ¸í·ÉÀ¸·Î º¸¸é, ºÎÆà À̹ÌÁö ÆÄÀϵéÀÌ ÀÖ°í ¼³Á¤ÆÄÀÏÀÎ boot.cfg ÆÄÀÏÀÌ ÀÖ½À´Ï´Ù.
-> cp boot.cfg boot_L3.cfg
À§ÀÇ ¸í·ÉÀ¸·Î ÇöÀç ¼³Á¤À» ´Ù¸¥ À̸§À¸·Î º¹»çÇØ ³õÀ» ¼ö ÀÖ½À´Ï´Ù.
-> vi boot.cfg
¶ÇÇÑ vi ¸í·Éµµ ¼öÇàÇÏ¿© ±× ³»¿ëÀ» º¯°æÇÒ ¼ö ÀÖ½À´Ï´Ù.
8) ¼³Á¤ ÃʱâÈ
-> cd working
-> rm boot.cfg
-> reload working no rollback-timeout
9) Æ÷Æ® ¹Ì·¯¸µ
-> policy condition c1 source ip 192.168.20.1
-> policy action a1 mirror ingress 1/10
-> policy rule r1 condition c1 action a1
-> qos apply
½ºÀ§Ä¡¿¡¼ ¼Ò½º IP°¡ 192.168.20.1 ÀÎ ¸ðµç Ç÷ο쿡 ´ëÇÏ¿© 10¹ø Æ÷Æ®·Î ¹Ì·¯¸µ ÇÏ°Ô µË´Ï´Ù.
10) ACL
10.1) Layer2 ACL
-> policy condition toMAC3 destination mac 00:00:00:00:00:03
-> policy action deny disposition drop
-> policy rule r1 condition toMAC3 action deny
-> qos apply
10.2) Layer3 ACL
-> policy condition fromIP1toIP3 source ip 10.0.0.100 destination ip 192.0.0.0 mask 255.0.0.0
-> policy action deny disposition deny
-> policy rule r1 condition fromIP1toIP3 action deny
-> qos apply
10.3) Layer4 ACL
-> policy service t445 destination tcp port 445
-> policy service t135 destination tcp port 135
-> policy service group tcp_group t445 t135
-> policy condition c1 service group tcp_group
-> policy action deny disposition deny
-> policy rule r1 condition c1 action deny
-> qos apply