¹«º£²Ê´¬¡¤6600(ÖйúÓÎ)¹Ù·½ÍøÕ¾

µã»÷ÏÂÔØ¡¶ÍòÕ×Ô°ÇøÒÔÌ«²Ê¹âÑо¿±¨¸æ¡·£¬½âËøÍòÕ×Ô°ÇøÍøÂ罨ÉèÖ¸ÄÏ
Á¢¼´ÏÂÔØ
ÎÞ¸Ð×¼Èë ÈËÎïͳ¹Ü Ø­ RG-SAM+5.X ÐÂÒ»´ú¸ßУAIÈÏ֤ƽ̨·¢²¼
Ô¤Ô¼Ö±²¥
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
ºÏ×÷»ï°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/ÓïÑÔ

¡¾¾­µä°¸Àý¡¿Íø¹ØÎÞ·¨Ô¶³Ì¹ÜÀí

·¢²¼Ê±¼ä£º2024-06-07
µã»÷Á¿£º307

ÎÞ·¨Í¨¹ýCLI¹ÜÀíÉ豸

Ò»¡¢ÏÖÏóÃèÊö

É豸ÓÐËÄÖֵǼ·½Ê½£ºSSH / TELNET / CONSOLE / WEB
³öÏÖÈçϹÊÕÏ£º
1¡¢CONSOLE¿ÚÎÞ·¨µÇ¼
2¡¢TELNETÎÞ·¨µÇ¼
3¡¢SSHÎÞ·¨µÇ¼
4¡¢WEBÎÞ·¨µÇ¼

¶þ¡¢×éÍøÍØÆË

Èý¡¢¿ÉÄÜÔ­Òò

1¡¢CRTÈí¼þÉèÖòÎÊýÎÊÌ⣬»òÕßconsoleÏßÎÊÌâ
2¡¢control-plane½ûÖ¹µÇ¼ÉèÖã¬ACL¹ýÂËÏÞÖÆ£¬VTYÏß³ÌÕ¼Âú


ËÄ¡¢´¦Àí²½Öè

ÏÖÏó1£ºCONSOLEÎÞ·¨µÇ¼

²½Öè1¡¢¼ì²éÉ豸µçÔ´µÆÔËÐÐ״̬

1. ¼ì²éPWRµÆ×´Ì¬
µçÔ´Õý³££ºÂÌÉ«³£ÁÁ
µçÔ´¹Ø±Õ»ò¹ÊÕÏ£º²»ÁÁ
±¸×¢£ºÈç¹ûµçÔ´µÆ²»ÁÁ£¬Çë¼ì²éµçÔ´ÊÇ·ñÕý³£¼Óµç£¬ÅжÏÉ豸ÊÇ·ñ´æÔÚÓ²¼þÎÊÌâµ¼ÖÂÎÞ·¨¼Óµç

2. ¼ì²éSYSµÆ×´Ì¬
Éϵç³õʼ»¯£ºÂÌÉ«ÉÁ˸
³õʼ»¯Íê³É£ºÂÌÉ«³£ÁÁ
¸æ¾¯£ººìÉ«³£ÁÁ
±¸×¢£º¿ÉÒÔ¹Ø×¢consoleÊä³öÈÕÖ¾½øÐÐÅжÏÈí¼þÊÇ·ñ´æÔÚÒì³£

²½Öè2¡¢ConsoleÏß²ÎÊýÉèÖÃ

Èç¹ûʹÓÃCRTÈí¼þ£¬ConsoleÏߵǼÐèҪѡÔñÕýÈ·µÄcom¿Ú£¬ÒÔ¼°²¨ÌØÂÊΪ9600£¬²»Äܹ´Ñ¡Á÷¿ØÎ»
¶Ë¿Ú¿ÉÒÔͨ¹ýµçÄԶ˵ÄÉ豸¹ÜÀíÆ÷²é¿´
ÈçÏÂͼËùʾ

²½Öè3¡¢Ìæ»»consoleÏß/É豸²âÊÔ

1¡¢Ìæ»»consoleÏß½øÐвâÊÔ£¬ÅжÏÏÂconsoleÏßÊÇ·ñ´æÔÚÎÊÌâ
2¡¢Èç¹ûûÓжàÓàconsoleÏߣ¬Ìæ»»ÆäËûÖ§³ÖconsoleµÇ¼µÄ·½Ê½²âÊÔ
Èç¹ûconsole¿ÚÈÔÈ»ÎÞ·¨µÇ¼£¬´°¿ÚûÓÐÊäÈëºÍÊä³ö£¬¿ÉÄÜ´æÔÚconsole´æÔÚÓ²¼þÎÊÌâ¡£¿ÉÒÔʹÓÃÆäËû·½Ê½½øÐеǼ²âÊÔ¡£


ÏÖÏó2£ºTELNETÎÞ·¨µÇ¼

²½Öè1¡¢ÅŲéµÇ¼²ÎÊýÉèÖ㨵ØÖ·¡¢¶Ë¿Ú£©

1¡¢µÇ¼µØÖ·´íÎó
  a. consoleÏߵǼ¿ÉÒԲ鿴½Ó¿ÚµØÖ·£¬¾ßÌåÃüÁîΪshow ip interface brief
ÈçÉÏĿǰ2¿ÚΪÄÚÍø¿Ú£¬7¿ÚΪÍâÍø¿ÚµØÖ·£¬¿ÉÒÔͨ¹ýÕâÁ½¸ö½Ó¿ÚµÇ¼É豸£¬ÍâÍøÓû§Ö»ÄÜͨ¹ýÍâÍø¿ÚµØÖ·µÇ¼É豸
  b¡¢ÏëҪȷÈÏÍâÍø¿ÚµØÖ·£¬Ò²¿ÉÒÔͨ¹ýÄÚÍø¿ÚÏȵǼÉ豸ºó£¬È»ºóÔٲ鿴¶ÔÓ¦µÄÍâÍø¿ÚµØÖ·£¬
 Â·¾¶£ºÍøÂç—½Ó¿ÚÅäÖ×¶ÔÓ¦ÍâÍø¿Ú
²¹³ä£ºtelnetµÄ¶Ë¿ÚĬÈÏΪ23£¬telnet ¶Ë¿ÚÊÇÎÞ·¨Ð޸ĵÄ

²½Öè2¡¢ÅŲéÉ豸Éϰ²È«ÏÞÖÆ£¬½ûÖ¹µÇ¼£¬ACL¹ýÂË

1. ±¾µØ·À¹¥»÷ÉèÖýûÖ¹telnetµÇ¼²Ù×÷£¬¾ßÌå·¾¶Îª°²È«—±¾µØ·À¹¥»÷—½ûÖ¹ÄÚÍø/ÍâÍøµÇ¼É豸
¶ÔÓ¦ÃüÁîΪ£º  
control-plane
security deny lan-telnet-ssh-----½ûÖ¹ÄÚÍøtelnetºÍsshµÇ¼É豸
security deny wan-telnet-ssh-----½ûÖ¹ÍâÍøtelnetºÍsshµÇ¼Éè
2. ÔÚ½Ó¿Úµ÷Óûòip session filterµ÷ÓõÄACLûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
  a. ½Ó¿Ú·ÃÎÊÁбíϵĵ÷Óã¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP


  b. Ip session filter Á÷¹ýÂ˲Ù×÷£¬È«¾Öµ÷Óã¬È«¾ÖÉúЧ£¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP


  c. Line vtyϵ÷ÓõÄACLûÓзÅͨ¶ÔÓ¦µÄÍø¶Î·ÃÎÊÉ豸£¬µ¼ÖÂÎÞ·¨telnet
  Ëùµ÷ÓõÄACL161ÐèÒª·ÅͨµÇ¼É豸µÄ¶Ë¿Ú»òIPµØÖ·
  ¾ßÌå·¾¶£º°²È«—ACL·ÃÎÊÁбí
  ÅäÖÃÍ꣬ÃüÁîÐжÔӦϷ¢µÄÃüÁîÈçÏ£º

²½Öè3¡¢ÅŲéÓ³É䵼ֵǼ¶Ë¿Ú±»Õ¼ÓÃ

¾ßÌåÅäÖÃÈçÏ£ºÄÚÍø·þÎñÆ÷Ó³ÉäʱӳÉäµ½É豸µÇ¼¶Ë¿Ú±ÈÈç˵23£¬»òÕßÊÇÅäÖÃÁËÕû»úÓ³ÉäÓ³Éäµ½½Ó¿ÚÉÏ£¬µ¼ÖÂÉ豸µÇ¼¶Ë¿Ú±»Õ¼Ó㬻ᵼÖÂÉ豸ÎÞ·¨µÇ¼£¬

a. ¶Ë¿ÚÓ³ÉäÅäÖÃ
¶ÔÓ¦ÃüÁîÈçÏ£º
ip nat inside source static tcp 192.168.1.10 23 172.18.161.111 23

b. Õû»úÓ³ÉäÅäÖÃ
¶ÔÓ¦ÃüÁîÈçÏ£º
ip nat inside source static 192.168.1.10 172.18.161.111 permit-inside
½â¾ö·½·¨£º½«ÍâÍøÓ³Éä¶Ë¿Ú23Ó³ÉäΪ1023µÈ¶Ë¿Ú£¬±ÜÃâ¶Ë¿ÚÕ¼ÓÃÎÊÌâ¡£

²½Öè4¡¢ÅŲé¶àÌõÍâÍøÏßµÄÇé¿öÏÂûÓпªÆôÔ´½øÔ´³ö

¶àÌõÍâÍøÏßµÄÇé¿öÏÂûÓпªÆôÔ´½øÔ´³ö£¬µ¼ÖÂÍâÍø·ÃÎʵ½É豸µÄÊý¾ÝÁ÷³öÏÖ´Ó½Ó¿Ú7½øÀ´µ«ÊÇ´Ó½Ó¿Ú6³öÈ¥ÁË¡£ËùÒÔÔÚÍâÍø¿ÚÐèÒª¿ªÆôÔ´½øÔ´³ö
¾ßÌå·¾¶ÈçÏ£ºÍøÂç—½Ó¿ÚÅäÖ×¶ÔÓ¦½Ó¿ÚϹ´Ñ¡Ô´½øÔ´³ö
¶ÔÓ¦µÄÃüÁîÈçÏ£º

²½Öè5¡¢ÅŲé·þÎñÊÇ·ñÆôÓûòÕßÊÇ·ñ´æÔÚweb°ü 

1¡¢µÇ¼·þÎñûÓпªÆô
¾ßÌåÃüÁ²é¿´telnetÊÇ·ñ¿ªÆô——show service


2¡¢²é¿´¶Ë¿ÚÊÇ·ñÕý³£¼àÌý
£¨1£©Show tcp connect £¬LISTEN´ú±í¼àÌý״̬ÊôÓÚÕý³£×´Ì¬

²½Öè6¡¢VTYÏ̱߳»Õ¼Âú

¿ÉÒÔͨ¹ýshow users²é¿´vtyÕ¼ÓõÄÏß³ÌÊÇ·ñÂúÁË£¬Ä¬ÈÏÊÇ5¸öÏ̡߳£¿ÉÒÔͨ¹ýclear line vty ¶ÔÓ¦ÊýÖµ½øÐÐÏß³ÌÇå³ý£¬ÔÙ³¢ÊԵǼ¡£


ÏÖÏó3£ºSSHÎÞ·¨µÇ¼

²½Öè1¡¢ÅŲéµÇ¼²ÎÊýÉèÖ㨵ØÖ·¡¢¶Ë¿Ú£©

1¡¢µÇ¼µØÖ·´íÎó
  a. consoleÏߵǼ¿ÉÒԲ鿴½Ó¿ÚµØÖ·£¬¾ßÌåÃüÁîΪshow ip interface brief
ÈçÉÏĿǰ2¿ÚΪÄÚÍø¿Ú£¬7¿ÚΪÍâÍø¿ÚµØÖ·£¬¿ÉÒÔͨ¹ýÕâÁ½¸ö½Ó¿ÚµÇ¼É豸£¬ÍâÍøÓû§Ö»ÄÜͨ¹ýÍâÍø¿ÚµØÖ·µÇ¼É豸

  b¡¢ÏëҪȷÈÏÍâÍø¿ÚµØÖ·£¬Ò²¿ÉÒÔͨ¹ýÄÚÍø¿ÚÏȵǼÉ豸ºó£¬È»ºóÔٲ鿴¶ÔÓ¦µÄÍâÍø¿ÚµØÖ·£¬Â·¾¶£ºÍøÂç—½Ó¿ÚÅäÖ×¶ÔÓ¦ÍâÍø¿Ú
¡¾²¹³ä¡¿£ºSSHµÇ¼¶Ë¿ÚĬÈÏΪ22£¬SSHµÄ¶Ë¿ÚÊÇÎÞ·¨Ð޸ĵÄ

2¡¢SSH·þÎñÐèÒª¿ªÆô
¸Ã¹¦Äܵ±Ç°Ö»Ö§³ÖÃüÁÆô£¬²»Ö§³Öweb¿ªÆô
 Ruijie(config)#enable service ssh-server     //¿ªÆôSSH·þÎñ
 Ruijie(config)#crypto key generate dsa        //¼ÓÃÜ·½Ê½ÓÐÁ½ÖÖ£ºDSAºÍRSA,¿ÉÒÔËæÒâÑ¡Ôñ
            Choose the size of the key modulus in the range of 360 to 2048 for your
            Signature Keys. Choosing a key modulus greater than 512 may take  a few minutes.
            How many bits in the modulus [512]://Ö±½ÓÇûسµ
             % Generating 512 bit DSA keys ...[ok]

²½Öè2¡¢ÅŲéÉ豸Éϰ²È«ÏÞÖÆ£¬½ûÖ¹µÇ¼£¬ACL¹ýÂË

1¡¢±¾µØ·À¹¥»÷ÉèÖýûÖ¹sshµÇ¼µÈ²Ù×÷£¬¾ßÌå·¾¶Îª°²È«—±¾µØ·À¹¥»÷—½ûÖ¹ÄÚÍø/ÍâÍøµÇ¼É豸
¶ÔÓ¦ÃüÁîΪ£º  
control-plane
security deny lan-telnet-ssh-----½ûÖ¹ÄÚÍøtelnetºÍsshµÇ¼É豸
security deny wan-telnet-ssh-----½ûÖ¹ÍâÍøtelnetºÍsshµÇ¼É豸

2¡¢ÔÚ½Ó¿Úµ÷Óûòip session filterµ÷ÓõÄACLûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
  a. ½Ó¿Ú·ÃÎÊÁбíϵĵ÷Óã¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
  2¡¢ Ip session filter Á÷¹ýÂ˲Ù×÷£¬È«¾Öµ÷Óã¬È«¾ÖÉúЧ£¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP


  3¡¢ Line vtyϵ÷ÓõÄACLûÓзÅͨ¶ÔÓ¦µÄÍø¶Î·ÃÎÊÉ豸£¬µ¼ÖÂÎÞ·¨telnet


 Ëùµ÷ÓõÄACL161ÐèÒª·ÅͨµÇ¼É豸µÄ¶Ë¿Ú»òIPµØÖ·
 ¾ßÌå·¾¶£º°²È«—ACL·ÃÎÊÁбí
  ÅäÖÃÍ꣬ÃüÁîÐжÔӦϷ¢µÄÃüÁîÈçÏ£º

²½Öè3¡¢ÅŲéÓ³É䵼ֵǼ¶Ë¿Ú±»Õ¼ÓÃ

¾ßÌåÅäÖãºÄÚÍø·þÎñÆ÷Ó³ÉäʱӳÉäµ½É豸µÇ¼¶Ë¿Ú±ÈÈç˵22£¬»òÕßÊÇÅäÖÃÁËÕû»úÓ³ÉäÓ³Éäµ½½Ó¿ÚÉÏ£¬µ¼ÖÂÉ豸µÇ¼¶Ë¿Ú±»Õ¼Ó㬻ᵼÖÂÉ豸ÎÞ·¨µÇ¼£¬
1¡¢¶Ë¿ÚÓ³ÉäÅäÖÃ
¶ÔÓ¦ÃüÁîÈçÏ£ºip nat inside source static tcp 192.168.1.10 22 172.18.161.111 22

2. Õû»úÓ³ÉäÅäÖÃ
¶ÔÓ¦ÃüÁîÈçÏ£ºip nat inside source static 192.168.1.10 172.18.161.111 permit-inside
½â¾ö·½·¨£º½«ÍâÍøÓ³Éä¶Ë¿Ú22Ó³ÉäΪ1022¶Ë¿Ú£¬±ÜÃâ¶Ë¿ÚÕ¼ÓÃÎÊÌâ

²½Öè4¡¢ÅŲé¶àÌõÍâÍøÏßµÄÇé¿öÏÂûÓпªÆôÔ´½øÔ´³ö

¶àÌõÍâÍøÏßµÄÇé¿öÏÂûÓпªÆôÔ´½øÔ´³ö£¬µ¼ÖÂÍâÍø·ÃÎʵ½É豸µÄÊý¾ÝÁ÷³öÏÖ´Ó½Ó¿Ú7½øÀ´µ«ÊÇ´Ó½Ó¿Ú6³öÈ¥ÁË¡£
ËùÒÔÔÚÍâÍø¿ÚÐèÒª¿ªÆôÔ´½øÔ´³ö£¬
¾ßÌå·¾¶£ºÍøÂç—½Ó¿ÚÅäÖ×¶ÔÓ¦½Ó¿ÚϹ´Ñ¡Ô´½øÔ´³ö
¶ÔÓ¦µÄÃüÁîÈçÏ£º

²½Öè5¡¢ÅŲé·þÎñÊÇ·ñÆôÓûòÕßÊÇ·ñ´æÔÚweb°ü 

1¡¢µÇ¼·þÎñûÓпªÆô£¬
¾ßÌåÃüÁ²é¿´telnet»òSSHÊÇ·ñ¿ªÆô——show service
2¡¢²é¿´¶Ë¿ÚÊÇ·ñÕý³£¼àÌý
show tcp connect £¬LISTEN´ú±í¼àÌý״̬ÊôÓÚÕý³£×´Ì¬

²½Öè6¡¢VTYÏ̱߳»Õ¼Âú

¿ÉÒÔͨ¹ýshow users²é¿´vtyÕ¼ÓõÄÏß³ÌÊÇ·ñÂúÁË£¬Ä¬ÈÏÊÇ5¸öÏ̡߳£¿ÉÒÔͨ¹ýclear line vty ¶ÔÓ¦ÊýÖµ½øÐÐÏß³ÌÇå³ý£¬ÔÙ³¢ÊԵǼ¡£

Îå¡¢ÐÅÏ¢ÊÕ¼¯

×¢Ò⣺ÒÔÏÂÃüÁîÊÊÓÃÓÚtelnet¡¢sshÎÞ·¨µÇ¼£¬µ«ÅäÖÿڿÉÒԵǼµÄÇé¿ö£¬ÈôÅäÖÿÚÒ²ÎÞ·¨µÇ¼£¬Ç뼰ʱÁªÏµ400¹¤³Ìʦ´¦Àí¡£
sh ver
sh run
sh service
sh users
sh int usage
sh tcp connect
sh memory
sh cpu | ex 0.00
sh log rev
show int usage
sh envir
sh ip fpm sta
debug su
execute diagnose-cmd fdisk
execute diagnose-cmd mount
exit

Áù¡¢×ܽáÓ뽨Òé

µ±µçÄÔÎÞ·¨¹ÜÀíÉ豸£¬½¨ÒéÓÅÏȼì²éSESSION FILTERµ÷ÓõÄACLÊÇ·ñ½øÐÐÁËÏÞÖÆ¡£Èç¹ûûÓÐÏÞÖÆ£¬¿ÉÒÔͨ¹ýshow usersºÍshow ip fpm flow | in ²âÊÔµçÄÔIP£¬À´ÅжÏÊý¾ÝÊÇ·ñµ½µ½´ïEG¡£
¡¾²¹³ä¡¿Èçδ½â¾ö»òÐèÒªÁ˽â¸ü¶àÏêÇ飬¿Éµã»÷ÊÛºóÉÁµçÍýøÐÐ×Éѯ

·µ»Ø¶¥²¿

ÊÕÆð
ÎĵµAIÖúÊÖ
ÎĵµÆÀ¼Û
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌ⣿
Äú¶Ôµ±Ç°Ò³ÃæµÄÂúÒâ¶ÈÈçºÎ£¿
²»Õ¦µÎ
·Ç³£ºÃ
ÄúÂúÒâµÄÔ­ÒòÊÇ£¨¶àÑ¡£©£¿
Äú¶ÔÎĵµÊÇ·ñ»¹ÓÐÆäËüµÄÎÊÌâ»ò½¨Ò飿
Ϊ¾¡¿ì½â¾öÎÊÌ⣬ÇëÄúÁôÏÂÁªÏµ·½Ê½Òﱋȯ¸´
ÓÊÏä
ÊÖ»úºÅ
¸ÐлÄúµÄ·´À¡£¡
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø±Õ×Éѯҳ
ÊÛǰ×Éѯ ÊÛǰ×Éѯ
ÊÛǰ×Éѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
Òâ¼û·´À¡ Òâ¼û·´À¡
Òâ¼û·´À¡
¸ü¶àÁªÏµ·½Ê½
¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿