当前位置:网站首页>Huawei ENSP simulator realizes communication security (switch)
Huawei ENSP simulator realizes communication security (switch)
2022-07-04 21:13:00 【Python Pegasus】
Catalog
vlan Implementation in simulator
Two 、 Connect different pc The interface of the machine is put into different vlan.
1、 Enter to divide vlan The interface of
2、 Change the interface type to access
3、 Talk about the division of interfaces into different vlan
Network security
vlan: Virtual machine lan
principle : Put the real LAN , Divided into multiple virtual LANs , This can realize different virtual LANs (vlan) The isolation .
effect : Limit the spread of the virus , For example, a computer is infected with a virus , If not set vlan, It may infect all computers , Set up vlan after , It can only infect the area where the computer is located vlan, other vlan Your computer is safe .
acl: A firewall
vlan Implementation in simulator
vlan Need to be configured in the switch , Create... In the switch vlan, And put different interfaces into different vlan.
No configuration vlan when , Switch interface twice pc Can visit each other , At this time, one pc The machine is infected with a virus , The other one will also be infected , Therefore, you need to configure vlan.
Realization vlan step :
1、 Create in switch vlan
2、 Put two computers into different vlan
One 、 establish vlan
vlan vlan name
example : establish vlan 20
After the command line enters the system view , Input vlan 20
Batch creation vlan:
vlan batch Enter the to be created vlan name Each is separated by a space
establish vlan 10 and vlan 20
Once created , We want to see what vlan, You can enter commands ,display vlan
Check out the existing vlan
display vlan
Two 、 Connect different pc The interface of the machine is put into different vlan.
Be careful : The division is different vlan Not will pc Machine put in vlan, Instead, it will connect pc Put the interface of the machine into vlan Implement interface isolation .
1、 Enter to divide vlan The interface of
int The interface name
2、 Change the interface type to access
Change the interface to access Interface
port link-type access
Change the interface to trunk Interface
port link-type trunk
Why modify the interface type , Because switches have many interface types , Each type is used to connect different machines .
There are mainly two kinds :
access Interface : Used to connect terminal 、 The computer 、 The printer
trunk Interface : Used to connect other Switch , When connecting other switches, change the interface to trunk Interface .
trunk The function of the interface is to mark data packets vlan label , Let another switch know to which vlan Of .
3、 Talk about the division of interfaces into different vlan
port default Which one do you want to divide into vlan
example : take 0/0/1 The interface is divided into vlan10
port default vlan 10
Check it out. vlan What interfaces are there in
We can see 0/0/1 The interface has been divided into vlan 10
Same method , Put another interface into vlan 20
The two interfaces have been put into different vlan. These two pc The machine has been vlan Isolation , It's already impassable .
We can see , The host is not reachable .
Realize data communication between two switches (trunk Interface )
trunk Function of interface :
Set the port connected by the two switches to trunk Interface , because trunk The interface can mark the data vlan label , Let another switch know which one to send data to vlan.
Implementation steps :
In the following steps, the interface between the two switches should be set , That is, set it twice
1、 Set the interface to trunk Interface
port link-type trunk
2、 Set the vlan( That's what vlan Data packets can be sent through this interface )
# Allow all vlan adopt
port trunk allow-pass vlan all
# It can also be put through separately vlan
example : Let go vlan 10 and vlan 20
port trunk allow-pass vlan 10
port trunk allow-pass vlan 20
example :
Another switch operates the same :
1、 Set the interface to trunk Interface
2、 Set the allowed vlan
Set the trunk After the interface , Connect other pc The port of the machine is set to access Interface , And divided into vlan in .( There are operation steps )
边栏推荐
- What if the win11 shared file cannot be opened? The solution of win11 shared file cannot be opened
- 网络命名空间
- 偷窃他人漏洞报告变卖成副业,漏洞赏金平台出“内鬼”
- Jmeter 之压测入门
- acwing 3302. Expression evaluation
- 华为模拟器ensp的路由配置以及连通测试
- Implementation of redis distributed lock
- Record the online bug solving list (unfinished to be continued 7/4)
- 五子棋 上班摸鱼工具 可局域网/人机
- 杰理之AD 系列 MIDI 功能说明【篇】
猜你喜欢
《动手学深度学习》(三) -- 卷积神经网络 CNN
搭建一个仪式感点满的网站,并内网穿透发布到公网 1/2
js 3D爆炸碎片图片切换js特效
Summary of the mistakes in the use of qpainter in QT gobang man-machine game
Jmeter 之压测入门
heatmap.js图片热点热力图插件
Flet tutorial 04 basic introduction to filledtonalbutton (tutorial includes source code)
Detailed explanation of multi-mode input event distribution mechanism
杰理之AD 系列 MIDI 功能说明【篇】
多模输入事件分发机制详解
随机推荐
杰理之AD 系列 MIDI 功能说明【篇】
华为ensp模拟器 DNS服务器的配置
FastDfs的快速入门,三分钟带你上传下载文件到云服务器
Detailed explanation of multi-mode input event distribution mechanism
冰河的海报封面
【微服务|SCG】Predicate的使用
WinCC7.5 SP1如何通过交叉索引来寻找变量及其位置?
【解决方案】PaddlePaddle 2.x调用静态图模式
[solution] paddlepaddle 2 X call static graph mode
接口设计时的一些建议
偷窃他人漏洞报告变卖成副业,漏洞赏金平台出“内鬼”
Quelques suggestions pour la conception de l'interface
字节测试工程师十年经验直击UI 自动化测试痛点
Leetcode+ 81 - 85 monotone stack topic
B站视频 声音很小——解决办法
Google colab踩坑
What are the functional modules of RFID warehouse management system solution
__init__() missing 2 required positional arguments 不易查明的继承错误
HWiNFO硬件检测工具v7.26绿色版
word中插入圖片後,圖片上方有一空行,且删除後布局變亂