ÎÞ·¨Í¨¹ýCLIÖÎÀíÉ豸
Ò»¡¢¾°ÏóÃèÊö
É豸ÓÐËÄÖֵǼ·½Ê½£ºSSH / TELNET / CONSOLE / WEB
³öÏÖÈçϹÊÕÏ£º
1¡¢CONSOLE¿ÚÎÞ·¨µÇ¼
2¡¢TELNETÎÞ·¨µÇ¼
3¡¢SSHÎÞ·¨µÇ¼
4¡¢WEBÎÞ·¨µÇ¼
¶þ¡¢×éÍøÍØÆË

Èý¡¢¿ÉÄÜÔÒò
1¡¢CRTÈí¼þÉèÖòÎÊýÎÊÌ⣬»òÕßconsoleÏßÎÊÌâ
2¡¢control-plane²»ÈݵǼÉèÖã¬ACL¹ýÂËÏÞ¶È£¬VTYÏß³ÌÕ¼Âú
ËÄ¡¢´¦Öò½Öè
¾°Ïó1£ºCONSOLEÎÞ·¨µÇ¼
²½Öè1¡¢²é³É豸µçÔ´µÆÔËÐÐ״̬
1. ²é³PWRµÆ×´Ì¬
µçÔ´Õý³££ºÂÌÉ«³£ÁÁ
µçÔ´¹Ø¹Ø»ò¹ÊÕÏ£º²»ÁÁ
±¸×¢£ºÈôÊǵçÔ´µÆ²»ÁÁ£¬Çë²é³µçÔ´ÊÇ·ñÕý³£¼Óµç£¬ÅжÏÉ豸ÊÇ·ñ´æÔÚÓ²¼þÎÊÌâµ¼ÖÂÎÞ·¨¼Óµç
2. ²é³SYSµÆ×´Ì¬
Éϵç³õʼ»¯£ºÂÌÉ«ÉÁ¶¯
³õʼ»¯ÊµÏÖ£ºÂÌÉ«³£ÁÁ
¸æ¾¯£ººìÉ«³£ÁÁ
±¸×¢£ºÄܹ»¹Ø×¢consoleÊä³öÈÕÖ¾½øÐÐÅжÏÈí¼þÊÇ·ñ´æÔÚÒì³£
²½Öè2¡¢ConsoleÏß²ÎÊýÉèÖÃ
ÈôÊÇʹÓÃCRTÈí¼þ£¬ConsoleÏߵǼ±ØÒªÑ¡ÔñÕýÈ·µÄcom¿Ú£¬ÒÔ¼°²¨ÌØÂÊΪ9600£¬²»Äܹ´Ñ¡Á÷¿ØÎ»
¶Ë¿ÚÄܹ»Í¨¹ýµçÄԶ˵ÄÉ豸ÖÎÀíÆ÷²é¿´
ÈçÏÂͼËùʾ
²½Öè3¡¢´úÌæconsoleÏß/É豸²âÊÔ
1¡¢´úÌæconsoleÏß½øÐвâÊÔ£¬ÅжÏÏÂconsoleÏßÊÇ·ñ´æÔÚÎÊÌâ
2¡¢ÈôÊÇûÓÐÓÐÓàconsoleÏߣ¬´úÌæÆäËûÖ§³ÖconsoleµÇ¼µÄ·½Ê½²âÊÔ
ÈôÊÇconsole¿ÚÒÀÈ»ÎÞ·¨µÇ¼£¬´°¿ÚûÓÐÊäÈëºÍÊä³ö£¬¿ÉÄÜ´æÔÚconsole´æÔÚÓ²¼þÎÊÌâ¡£Äܹ»Ê¹ÓÃÆäËû·½Ê½½øÐеǼ²âÊÔ¡£
¾°Ïó2£ºTELNETÎÞ·¨µÇ¼
²½Öè1¡¢ÅŲéµÇ¼²ÎÊýÉèÖ㨵ØÖ·¡¢¶Ë¿Ú£©
1¡¢µÇ¼µØÖ·ÃýÎó
a. consoleÏߵǼÄܹ»²é¿´½Ó¿ÚµØÖ·£¬¾ßÌåºÅÁîΪshow ip interface brief
ÈçÉÏĿǰ2¿ÚΪÄÚÍø¿Ú£¬7¿ÚΪ±íÍø¿ÚµØÖ·£¬Äܹ»Í¨¹ýÕâÁ½¸ö½Ó¿ÚµÇ¼É豸£¬±íÍøÓû§Ö»ÄÜͨ¹ý±íÍø¿ÚµØÖ·µÇ¼É豸
b¡¢ÏëҪȷÈϱíÍø¿ÚµØÖ·£¬Ò²Äܹ»Í¨¹ýÄÚÍø¿ÚÏȵǼÉ豸ºó£¬¶øºóÔٲ鿴¶ÔÓ¦µÄ±íÍø¿ÚµØÖ·£¬
õè¾¶£ºÍøÂç—½Ó¿ÚÅäÖ×¶ÔÓ¦±íÍø¿Ú
²¹³ä£ºtelnetµÄ¶Ë¿ÚĬÒÔΪ23£¬telnet ¶Ë¿ÚÊÇÎÞ·¨Åú¸ÄµÄ
²½Öè2¡¢ÅŲéÉ豸Éϰ²È«ÏÞ¶È£¬²»ÈݵǼ£¬ACL¹ýÂË
1. ±¾µØ·À¹¥»÷ÉèÖò»ÈÝtelnetµÇ¼²Ù×÷£¬¾ßÌåõ辶Ϊ°²È«—±¾µØ·À¹¥»÷—²»ÈÝÄÚÍø/±íÍøµÇ¼É豸
¶Ô±¨ºÅÁîΪ£º
control-plane
security deny lan-telnet-ssh-----²»ÈÝÄÚÍøtelnetºÍsshµÇ¼É豸
security deny wan-telnet-ssh-----²»ÈݱíÍøtelnetºÍsshµÇ¼Éè
2. ÔÚ½Ó¿ÚŲÓûòip session filterŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
a. ½Ó¿Ú½Ó¼ûÁбíϵÄŲÓ㬱ØÒª²é³ACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
b. Ip session filter Á÷¹ýÂ˲Ù×÷£¬È«¾ÖŲÓã¬È«¾ÖÉúЧ£¬±ØÒª²é³ACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
c. Line vtyÏÂŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄÍø¶Î½Ó¼ûÉ豸£¬µ¼ÖÂÎÞ·¨telnet
ËùŲÓõÄACL161±ØÒª·ÅͨµÇ¼É豸µÄ¶Ë¿Ú»òIPµØÖ·
¾ßÌåõè¾¶£º°²È«—ACL½Ó¼ûÁбí
ÅäÖÃÍ꣬ºÅÁîÐжÔӦϷ¢µÄºÅÁîÈçÏ£º
²½Öè3¡¢ÅŲéÓ³É䵼ֵǼ¶Ë¿Ú±»Õ¼ÓÃ
¾ßÌåÅäÖÃÈçÏ£ºÄÚÍø·þÎñÆ÷Ó³ÉäʱӳÉäµ½É豸µÇ¼¶Ë¿ÚºÃ±È˵23£¬»òÕßÊÇÅäÖÃÁËÕû»úÓ³ÉäÓ³Éäµ½½Ó¿ÚÉÏ£¬µ¼ÖÂÉ豸µÇ¼¶Ë¿Ú±»Õ¼Ó㬻ᵼÖÂÉ豸ÎÞ·¨µÇ¼£¬
a. ¶Ë¿ÚÓ³ÉäÅäÖÃ
¶Ô±¨ºÅÁîÈçÏ£º
ip nat inside source static tcp 192.168.1.10 23 172.18.161.111 23
b. Õû»úÓ³ÉäÅäÖÃ
¶Ô±¨ºÅÁîÈçÏ£º
ip nat inside source static 192.168.1.10 172.18.161.111 permit-inside
½â¾ö²½Ö裺½«±íÍøÓ³Éä¶Ë¿Ú23Ó³ÉäΪ1023µÈ¶Ë¿Ú£¬Ô¤·À¶Ë¿ÚÕ¼ÓÃÎÊÌâ¡£
²½Öè4¡¢ÅŲé¶àÌõ±íÍøÏßµÄÇé¿öÏÂûÓпªÆôÔ´½øÔ´³ö
¶àÌõ±íÍøÏßµÄÇé¿öÏÂûÓпªÆôÔ´½øÔ´³ö£¬µ¼Ö±íÍø½Ó¼ûµ½É豸µÄÊý¾ÝÁ÷³öÏÖ´Ó½Ó¿Ú7½øÀ´µ«ÊÇ´Ó½Ó¿Ú6³öÈ¥ÁË¡£ËùÒÔÔÚ±íÍø¿Ú±ØÒª¿ªÆôÔ´½øÔ´³ö
¾ßÌåõè¾¶ÈçÏ£ºÍøÂç—½Ó¿ÚÅäÖ×¶ÔÓ¦½Ó¿ÚϹ´Ñ¡Ô´½øÔ´³ö
¶ÔÓ¦µÄºÅÁîÈçÏ£º
²½Öè5¡¢ÅŲé·þÎñÊÇ·ñÆôÓûòÕßÊÇ·ñ´æÔÚweb°ü
1¡¢µÇ¼·þÎñûÓпªÆô
¾ßÌåºÅÁ²é¿´telnetÊÇ·ñ¿ªÆô——show service
2¡¢²é¿´¶Ë¿ÚÊÇ·ñÕý³£¼àÌý
£¨1£©Show tcp connect £¬LISTEN´ú±í¼àÌý״̬ÊôÓÚÕý³£×´Ì¬

²½Öè6¡¢VTYÏ̱߳»Õ¼Âú
Äܹ»Í¨¹ýshow users²é¿´vtyÕ¼ÓõÄÏß³ÌÊÇ·ñÂúÁË£¬Ä¬ÈÏÊÇ5¸öÏ̡߳£Äܹ»Í¨¹ýclear line vty ¶ÔÓ¦ÊýÖµ½øÐÐÏ̶߳ϸù£¬ÔÙ³¢ÊԵǼ¡£
¾°Ïó3£ºSSHÎÞ·¨µÇ¼
²½Öè1¡¢ÅŲéµÇ¼²ÎÊýÉèÖ㨵ØÖ·¡¢¶Ë¿Ú£©
1¡¢µÇ¼µØÖ·ÃýÎó
a. consoleÏߵǼÄܹ»²é¿´½Ó¿ÚµØÖ·£¬¾ßÌåºÅÁîΪshow ip interface brief
ÈçÉÏĿǰ2¿ÚΪÄÚÍø¿Ú£¬7¿ÚΪ±íÍø¿ÚµØÖ·£¬Äܹ»Í¨¹ýÕâÁ½¸ö½Ó¿ÚµÇ¼É豸£¬±íÍøÓû§Ö»ÄÜͨ¹ý±íÍø¿ÚµØÖ·µÇ¼É豸
b¡¢ÏëҪȷÈϱíÍø¿ÚµØÖ·£¬Ò²Äܹ»Í¨¹ýÄÚÍø¿ÚÏȵǼÉ豸ºó£¬¶øºóÔٲ鿴¶ÔÓ¦µÄ±íÍø¿ÚµØÖ·£¬õè¾¶£ºÍøÂç—½Ó¿ÚÅäÖ×¶ÔÓ¦±íÍø¿Ú
¡¾²¹³ä¡¿£ºSSHµÇ¼¶Ë¿ÚĬÒÔΪ22£¬SSHµÄ¶Ë¿ÚÊÇÎÞ·¨Åú¸ÄµÄ
2¡¢SSH·þÎñ±ØÒª¿ªÆô
¸ÃÖ°Äܵ±Ç°Ö»Ö§³ÖºÅÁÆô£¬²»Ö§³Öweb¿ªÆô
Ruijie(config)#enable service ssh-server //¿ªÆôSSH·þÎñ
Ruijie(config)#crypto key generate dsa //¼ÓÃÜ·½Ê½ÓÐÁ½ÖÖ£ºDSAºÍRSA,Äܹ»ÇáÒ×Ñ¡Ôñ
Choose the size of the key modulus in the range of 360 to 2048 for your
Signature Keys. Choosing a key modulus greater than 512 may take a few minutes.
How many bits in the modulus [512]://Ö±½ÓÇûسµ
% Generating 512 bit DSA keys ...[ok]
²½Öè2¡¢ÅŲéÉ豸Éϰ²È«ÏÞ¶È£¬²»ÈݵǼ£¬ACL¹ýÂË
1¡¢±¾µØ·À¹¥»÷ÉèÖò»ÈÝsshµÇ¼µÈ²Ù×÷£¬¾ßÌåõ辶Ϊ°²È«—±¾µØ·À¹¥»÷—²»ÈÝÄÚÍø/±íÍøµÇ¼É豸
¶Ô±¨ºÅÁîΪ£º
control-plane
security deny lan-telnet-ssh-----²»ÈÝÄÚÍøtelnetºÍsshµÇ¼É豸
security deny wan-telnet-ssh-----²»ÈݱíÍøtelnetºÍsshµÇ¼É豸
2¡¢ÔÚ½Ó¿ÚŲÓûòip session filterŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
a. ½Ó¿Ú½Ó¼ûÁбíϵÄŲÓ㬱ØÒª²é³ACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
2¡¢ Ip session filter Á÷¹ýÂ˲Ù×÷£¬È«¾ÖŲÓã¬È«¾ÖÉúЧ£¬±ØÒª²é³ACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
3¡¢ Line vtyÏÂŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄÍø¶Î½Ó¼ûÉ豸£¬µ¼ÖÂÎÞ·¨telnet

ËùŲÓõÄACL161±ØÒª·ÅͨµÇ¼É豸µÄ¶Ë¿Ú»òIPµØÖ·
¾ßÌåõè¾¶£º°²È«—ACL½Ó¼ûÁбí
ÅäÖÃÍ꣬ºÅÁîÐжÔӦϷ¢µÄºÅÁîÈçÏ£º
²½Öè3¡¢ÅŲéÓ³É䵼ֵǼ¶Ë¿Ú±»Õ¼ÓÃ
¾ßÌåÅäÖãºÄÚÍø·þÎñÆ÷Ó³ÉäʱӳÉäµ½É豸µÇ¼¶Ë¿ÚºÃ±È˵22£¬»òÕßÊÇÅäÖÃÁËÕû»úÓ³ÉäÓ³Éäµ½½Ó¿ÚÉÏ£¬µ¼ÖÂÉ豸µÇ¼¶Ë¿Ú±»Õ¼Ó㬻ᵼÖÂÉ豸ÎÞ·¨µÇ¼£¬
1¡¢¶Ë¿ÚÓ³ÉäÅäÖÃ
¶Ô±¨ºÅÁîÈçÏ£ºip nat inside source static tcp 192.168.1.10 22 172.18.161.111 22
2. Õû»úÓ³ÉäÅäÖÃ
¶Ô±¨ºÅÁîÈçÏ£ºip nat inside source static 192.168.1.10 172.18.161.111 permit-inside
½â¾ö²½Ö裺½«±íÍøÓ³Éä¶Ë¿Ú22Ó³ÉäΪ1022¶Ë¿Ú£¬Ô¤·À¶Ë¿ÚÕ¼ÓÃÎÊÌâ
²½Öè4¡¢ÅŲé¶àÌõ±íÍøÏßµÄÇé¿öÏÂûÓпªÆôÔ´½øÔ´³ö
¶àÌõ±íÍøÏßµÄÇé¿öÏÂûÓпªÆôÔ´½øÔ´³ö£¬µ¼Ö±íÍø½Ó¼ûµ½É豸µÄÊý¾ÝÁ÷³öÏÖ´Ó½Ó¿Ú7½øÀ´µ«ÊÇ´Ó½Ó¿Ú6³öÈ¥ÁË¡£
ËùÒÔÔÚ±íÍø¿Ú±ØÒª¿ªÆôÔ´½øÔ´³ö£¬
¾ßÌåõè¾¶£ºÍøÂç—½Ó¿ÚÅäÖ×¶ÔÓ¦½Ó¿ÚϹ´Ñ¡Ô´½øÔ´³ö
¶ÔÓ¦µÄºÅÁîÈçÏ£º
²½Öè5¡¢ÅŲé·þÎñÊÇ·ñÆôÓûòÕßÊÇ·ñ´æÔÚweb°ü
1¡¢µÇ¼·þÎñûÓпªÆô£¬
¾ßÌåºÅÁ²é¿´telnet»òSSHÊÇ·ñ¿ªÆô——show service
2¡¢²é¿´¶Ë¿ÚÊÇ·ñÕý³£¼àÌý
show tcp connect £¬LISTEN´ú±í¼àÌý״̬ÊôÓÚÕý³£×´Ì¬
²½Öè6¡¢VTYÏ̱߳»Õ¼Âú
Äܹ»Í¨¹ýshow users²é¿´vtyÕ¼ÓõÄÏß³ÌÊÇ·ñÂúÁË£¬Ä¬ÈÏÊÇ5¸öÏ̡߳£Äܹ»Í¨¹ýclear line vty ¶ÔÓ¦ÊýÖµ½øÐÐÏ̶߳ϸù£¬ÔÙ³¢ÊԵǼ¡£
Îå¡¢ÐÅÏ¢ÍøÂç
°ÑÎÈ£ºÒÔϺÅÁîºÏÓÃÓÚtelnet¡¢sshÎÞ·¨µÇ¼£¬µ«ÅäÖÿÚÄܹ»µÇ¼µÄÇé¿ö£¬ÈôÅäÖÿÚÒ²ÎÞ·¨µÇ¼£¬ÇëʵʱÁªÏµ400¹¤³Ìʦ´¦Öá£
sh ver
sh run
sh service
sh users
sh int usage
sh tcp connect
sh memory
sh cpu | ex 0.00
sh log rev
show int usage
sh envir
sh ip fpm sta
debug su
execute diagnose-cmd fdisk
execute diagnose-cmd mount
exit
Áù¡¢×ܽáÓ뽨Òé
µ±µçÄÔÎÞ·¨ÖÎÀíÉ豸£¬½¨ÒéÓÅÏȲé³SESSION FILTERŲÓõÄACLÊÇ·ñ½øÐÐÁËÏÞ¶È¡£ÈôÊÇûÓÐÏÞ¶È£¬Äܹ»Í¨¹ýshow usersºÍshow ip fpm flow | in ²âÊÔµçÄÔIP£¬À´ÅжÏÊý¾ÝÊÇ·ñµ½´ïµ½EG¡£
¡¾²¹³ä¡¿Èçδ½â¾ö»ò±ØÒªÏàʶ¸ü¶àÏêÇ飬¿Éµã»÷ÊÛºóÉÁµçÍýøÐÐÕ÷ѯ