《Juniper-華為-H3C設(shè)備維護(hù)常用命令.doc》由會員分享,可在線閱讀,更多相關(guān)《Juniper-華為-H3C設(shè)備維護(hù)常用命令.doc(19頁珍藏版)》請?jiān)谘b配圖網(wǎng)上搜索。
Juniper_華為_H3C設(shè)備維護(hù)常用命令
1、[Router&Swithc]華為/H3C設(shè)備常規(guī)巡檢命令
#系統(tǒng)時間
display clock
#系統(tǒng)以及各單板軟件版本
display version
#設(shè)備溫度
display environment
#日志信息
display logbuffer
#單板運(yùn)行狀態(tài)
display device
#電源狀態(tài)
display device
#風(fēng)扇狀態(tài)
display device
#CPU占用狀態(tài)
display cpu-usage
#內(nèi)存占用率
display memory limit
#接口流量
display interface
#接口、鏈路狀態(tài)
display interface
#地址分配
display current-configuration interface#
#路由擴(kuò)散
display current-configuration | include ospf
#OSPF(Open Shortest Path First)配置
display router id
#路由信息
display ip routing-table
#端口統(tǒng)計(jì)數(shù)據(jù)
display ip interface
#當(dāng)前配置文件
display current-configuration
#保存配置文件
display saved-configuration
端口使用狀態(tài)
display interface GigabitEthernet/Ten-GigabitEthernet brief
VLAN使用狀態(tài)
display ip interface brief
2、腳本—華為
display version
dis patch-information
display clock
dis dustproof
dis frame-type
dis health
display cpu-usage
display memory
display memory limit
display device
display device manuinfo
display power
display fan
display voltage
dir cfcard2:/
dir cfcard:
display device pic-status
dis switchover state
display environment
display interface
display logbuffer
dis alarm
dis bootrom ethernet
display current-configuration
display current-configuration interface#
display router id
display ip routing-table
display ip interface
display ip interface brief
display current-configuration
display saved-configuration
display diagnostic-information
3、腳本—華為NE40e
display version 查看VRP版本等信息
dis patch-information 查看版本補(bǔ)丁
display clock 查看時鐘
dis dustproof 防塵網(wǎng)信息
Dis frame-type 顯示NE40E機(jī)框類型
dis health 顯示系統(tǒng)資源的使用情況
display cpu-usage 查看1分鐘CPU利用率
display memory 查看內(nèi)存使用情況
display memory limit
display device 查看母板信息
display device manuinfo
display power 查看電源狀態(tài)
display fan 查看風(fēng)扇狀態(tài)
display voltage 查看板卡電壓
dir cfcard2:/ 查看設(shè)備crash信息
dir cfcard: 查看設(shè)備cf卡信息
display device pic-status 查看子卡型號,序列號 (NE40E NE80E)
dis switchover state 查看引擎HA情況
display environment
display interface 查看接口狀態(tài)
display logbuffer 查看日志
dis alarm 查看設(shè)備告警
dis bootrom ethernet 查看設(shè)備bootrom信息
display current-configuration查看當(dāng)前配置
display current-configuration interface# 查看設(shè)備當(dāng)前接口配置
display router id 查看設(shè)備路由ID
display ip routing-table 查看設(shè)備路由
display ip interface 查看設(shè)備接口情況
display ip interface brief 查看設(shè)備接口狀態(tài)
display current-configuration 查看設(shè)備當(dāng)前配置
display saved-configuration 查看設(shè)備內(nèi)存配置(相當(dāng)show start)
display diagnostic-information 抓取設(shè)備完整信息相對于show tech
二、JUNIPER設(shè)備常用維護(hù)巡檢命令
1、腳本—JUNIPER
show system uptime
show version detail
show chassis hardware detail
show chassis environment //顯示設(shè)備的環(huán)境信息,包括溫度、風(fēng)扇狀況、電源狀況、路由引擎狀況。
show chassis routing-engine
show chassis firmware
show configuration
show chassis fpc detail
show interface
show interfaces terse
show chassis alarms
show system alarms
show log messages|no-more
show log chassisd|no-more
show log logfile Displays
show chassis sfm Reports
show system boot-messages
show system core-dumps
show system processes extensive
show pfe statistics error
show chassis routing-engine
show system storage
show system virtual-memory
show system buffer
show system queues
show system statistics
show configuration | except SECRET-DATA
show interfaces extensive
show chassis hardware extensive
2、腳本—Juniper Firewall
get system
get config
get log event
get filiter
get per cpu detail
get session info
get per session detail
get mac-learn
get alarm event
get tech
get log system
get chassis
基本命令
1. get int 查看接口配置信息
2. get int eth x/x 查看指定接口配置信息
3. get mip 查看映射ip關(guān)系
4. get route 查看路由表
5. get policy id x 查看指定策略
6. get nsrp 查看nsrp信息,后可接參數(shù)查看具體vsd組、端口監(jiān)控設(shè)置等
7. get per cpu de 查看cpu利用率信息
8. get per session de 查看每秒新建會話信息
9. get session 查看當(dāng)前會話信息,后可匹配源地址、源端口、目的地址、目的端口、協(xié)議等選項(xiàng)
10. get session info 查看當(dāng)前會話數(shù)量
11. get system 查看系統(tǒng)信息、包括當(dāng)前OS版本,接口信息,設(shè)備運(yùn)行時間等
12. get chaiss 查看設(shè)備及板卡序列號,查看設(shè)備運(yùn)行溫度
13. get counter stat 查看所有 接口計(jì)數(shù)信息
14. get counter stat eth x/x 查看指定接口計(jì)數(shù)信息
15. get counter flow zone untrust/untrust 查看指定區(qū)域數(shù)據(jù)流信息
16. get counter screen zone untrust/trust 查看指定區(qū)域攻擊防護(hù)統(tǒng)計(jì)信息
17. get tech-support 查看設(shè)備狀態(tài)命令集,一般在出現(xiàn)故障時,收集該信息尋求JTAC支持
常用設(shè)置命令
Set int ethx/x zone trust/untrust/dmz/ha
配置指定接口進(jìn)入指定區(qū)域(trust/untrust/dmz/ha等)
Set int ethx/x ip x.x.x.x/xx 配置指定接口ip地址
Set int ethx/x manage
配置指定接口管理選項(xiàng),打開所有管理選項(xiàng)
Set int ethx/x manage web/telnet/ssl/ssh 配置指定接口指定管理選項(xiàng)
Set int ethx/x phy full 100mb 配置指定接口速率及雙工方式
Set int ethx/x phy link-down 配置指定接口
shutdown
Set nsrp vsd id 0 monitor interface ethx/x
配置ha監(jiān)控端口,如此端口斷開,則設(shè)備發(fā)生主/備切換
Exec nsrp vsd 0 mode backup
手工進(jìn)行設(shè)備主/備切換,在當(dāng)前的主設(shè)備上執(zhí)行
set route 0.0.0.0/0 interface ethernet1/3 gateway 222.92.116.33 配置路由,需同時指定下一跳接口及ip地址
所有set命令,都可以通過unset命令來取消,相當(dāng)于cisco中的no
所有命令都可以通過“TAB”鍵進(jìn)行命令補(bǔ)全,通過“?”來查看后續(xù)支持的命令
防火墻基本配置
1.登錄
create account [admin | user]
回車
輸入密碼:
再次輸入密碼:
configure account admin 回車
輸入密碼:
再次輸入密碼:
2.port配置
config ports auto off {speed [10 | 100 | 1000]} duplex [half | full] auto off
3.Vlan配置
無論是核心還是接入層,都要先創(chuàng)建三個Vlan,并且將所有歸于Default Vlan的端口刪除:
config vlan default del port all
create vlan Server
create vlan User
create vlan Manger
定義802.1q標(biāo)記
config vlan Server tag 10
config vlan User tag 20
config vlan Manger tag 30
設(shè)定Vlan網(wǎng)關(guān)地址:
config vlan Server ipa 192.168.41.1/24
config vlan User ipa 192.168.40.1/24
config vlan Manger ipa 192.168.*.*/24
Enable ipforwarding 啟用ip路由轉(zhuǎn)發(fā),即vlan間路由
Trunk 配置
config vlan Server add port 1-3 t
config vlan User add port 1-3 t
config vlan manger add port 1-3 t
4.VRRP配置
enable vrrp
configure vrrp add vlan UserVlan
configure vrrp vlan UserVlan add master vrid 10 192.168.6.254
configure vrrp vlan UserVlan authentication simple-password extreme
configure vrrp vlan UserVlan vrid 10 priority 200
configure vrrp vlan UserVlan vrid 10 advertisement-interval 15
configure vrrp vlan UserVlan vrid 10 preempt
5.端口鏡像配置
首先將端口從VLAN中刪除
enable mirroring to port 3 #選擇3作為鏡像口
config mirroring add port 1 #把端口1的流量發(fā)送到3
config mirroring add port 1 vlan default #把1和vlan default的流量都發(fā)送到3
6.port-channel配置
enable sharing grouping {port-based | address-based | round-robin}
show port sharing //查看配置
7.stp配置
enable stpd //啟動生成樹
create stpd stp-name //創(chuàng)建一個生成樹
configure stpd add vlan {ports [dot1d | emistp | pvst-plus]}
configure stpd stpd1 priority 16384
configure vlan marketing add ports 2-3 stpd stpd1 emistp
8.DHCP 中繼配置
enable bootprelay
config bootprelay add
9.NAT配置
Enable nat #啟用nat
Static NAT Rule Example
config nat add out_vlan_1 map source 192.168.1.12/32 to 216.52.8.32/32
Dynamic NAT Rule Example
config nat add out_vlan_1 map source 192.168.1.0/24 to 216.52.8.1 - 216.52.8.31
Portmap NAT Rule Example
config nat add out_vlan_2 map source 192.168.2.0/25 to 216.52.8.32 /28 both portmap
Portmap Min-Max Example
config nat add out_vlan_2 map source 192.168.2.128/25 to 216.52.8.64/28 tcp portmap 1024 – 8192
10.OSPF配置
enable ospf 啟用OSPF進(jìn)程
create ospf area 創(chuàng)建OSPF區(qū)域
configure ospf routerid [automatic | ] 配置Routerid
configure ospf add vlan [ | all] area {passive} 把某個vlan加到某個Area中去,相當(dāng)于Cisco中的
network的作用
configure ospf area add range [advertise | noadvertise] {type-3 | type-7} 把某個網(wǎng)段加到
某個Area中去,相當(dāng)于Cisco中的network的作用
configure ospf vlan neighbor add
OSPF中路由重發(fā)布配置
enable ospf export direct [cost [ase-type-1 | ase-type-2] {tag } | ]
enable ospf export static [cost [ase-type-1 | ase-type-2] {tag } | ]
enable ospf originate-default {always} cost [ase-type-1 | ase-type-2] {tag }
enable ospf originate-router-id
11.SNMP配置
enable snmp access
enable snmp traps
create access-profile type [ipaddress | vlan]
config snmp access-profile readonly [ | none]配置snmp的只讀訪問列表,none是去除
config snmp access-profile readwrite [ | none] 這是控制讀寫控制
config snmp add trapreceiver {port } community {from
鏈接地址:http://m.zhongcaozhi.com.cn/p-6668329.html