当前位置:网站首页>Huawei ENSP simulator realizes communication security (switch)
Huawei ENSP simulator realizes communication security (switch)
2022-07-04 21:13:00 【Python Pegasus】
Catalog
vlan Implementation in simulator
Two 、 Connect different pc The interface of the machine is put into different vlan.
1、 Enter to divide vlan The interface of
2、 Change the interface type to access
3、 Talk about the division of interfaces into different vlan
Network security
vlan: Virtual machine lan
principle : Put the real LAN , Divided into multiple virtual LANs , This can realize different virtual LANs (vlan) The isolation .
effect : Limit the spread of the virus , For example, a computer is infected with a virus , If not set vlan, It may infect all computers , Set up vlan after , It can only infect the area where the computer is located vlan, other vlan Your computer is safe .
acl: A firewall
vlan Implementation in simulator
vlan Need to be configured in the switch , Create... In the switch vlan, And put different interfaces into different vlan.
No configuration vlan when , Switch interface twice pc Can visit each other , At this time, one pc The machine is infected with a virus , The other one will also be infected , Therefore, you need to configure vlan.
Realization vlan step :
1、 Create in switch vlan
2、 Put two computers into different vlan
One 、 establish vlan
vlan vlan name
example : establish vlan 20
After the command line enters the system view , Input vlan 20
Batch creation vlan:
vlan batch Enter the to be created vlan name Each is separated by a space
establish vlan 10 and vlan 20
Once created , We want to see what vlan, You can enter commands ,display vlan
Check out the existing vlan
display vlan
Two 、 Connect different pc The interface of the machine is put into different vlan.
Be careful : The division is different vlan Not will pc Machine put in vlan, Instead, it will connect pc Put the interface of the machine into vlan Implement interface isolation .
1、 Enter to divide vlan The interface of
int The interface name
2、 Change the interface type to access
Change the interface to access Interface
port link-type access
Change the interface to trunk Interface
port link-type trunk
Why modify the interface type , Because switches have many interface types , Each type is used to connect different machines .
There are mainly two kinds :
access Interface : Used to connect terminal 、 The computer 、 The printer
trunk Interface : Used to connect other Switch , When connecting other switches, change the interface to trunk Interface .
trunk The function of the interface is to mark data packets vlan label , Let another switch know to which vlan Of .
3、 Talk about the division of interfaces into different vlan
port default Which one do you want to divide into vlan
example : take 0/0/1 The interface is divided into vlan10
port default vlan 10
Check it out. vlan What interfaces are there in
We can see 0/0/1 The interface has been divided into vlan 10
Same method , Put another interface into vlan 20
The two interfaces have been put into different vlan. These two pc The machine has been vlan Isolation , It's already impassable .
We can see , The host is not reachable .
Realize data communication between two switches (trunk Interface )
trunk Function of interface :
Set the port connected by the two switches to trunk Interface , because trunk The interface can mark the data vlan label , Let another switch know which one to send data to vlan.
Implementation steps :
In the following steps, the interface between the two switches should be set , That is, set it twice
1、 Set the interface to trunk Interface
port link-type trunk
2、 Set the vlan( That's what vlan Data packets can be sent through this interface )
# Allow all vlan adopt
port trunk allow-pass vlan all
# It can also be put through separately vlan
example : Let go vlan 10 and vlan 20
port trunk allow-pass vlan 10
port trunk allow-pass vlan 20
example :
Another switch operates the same :
1、 Set the interface to trunk Interface
2、 Set the allowed vlan
Set the trunk After the interface , Connect other pc The port of the machine is set to access Interface , And divided into vlan in .( There are operation steps )
边栏推荐
猜你喜欢
In the face of the same complex test task, why can the elder sort out the solution quickly? Ali's ten-year test engineers showed their skills
NetWare r7000 Merlin system virtual memory creation failed, prompting that the USB disk reading and writing speed does not meet the requirements. Solution, is it necessary to create virtual memory??
接口設計時的一些建議
看腾讯大老如何做接口自动化测试
【服务器数据恢复】某品牌服务器存储raid5数据恢复案例
华为ensp模拟器 给路由器配置DHCP
Sword finger offer II 80-100 (continuous update)
Hands on deep learning (III) -- convolutional neural network CNN
Day24:文件系统
Automatic generation of interface automatic test cases by actual operation
随机推荐
Leetcode+ 81 - 85 monotone stack topic
render函数与虚拟dom
Roast B station charges, is it because it has no money?
MySQL --- 数据库查询 - 聚合函数的使用、聚合查询、分组查询
Solution of 5g unstable 5g signal often dropped in NetWare r7000 Merlin system
shp数据制作3DTiles白膜
ACM组合计数入门
B站视频 声音很小——解决办法
[solution] paddlepaddle 2 X call static graph mode
字节测试工程师十年经验直击UI 自动化测试痛点
Automatic generation of interface automatic test cases by actual operation
6月“墨力原创作者计划”获奖名单公布!邀您共话国产数据库
Gobang go to work fishing tools can be LAN / man-machine
Day24:文件系统
《动手学深度学习》(三) -- 卷积神经网络 CNN
测试员的算法面试题-找众数
测试用例 (TC)
Actual combat simulation │ JWT login authentication
HMS Core 统一扫码服务
Foxit pdf editor v10.1.8 green version