-

   rss_rss_hh_new

 - e-mail

 

 -

 LiveInternet.ru:
: 17.03.2011
:
:
: 51

:


: Huawei S5720-52X-PWR-SI V2R9SPC500

, 04 2017 . 18:35 +


, ! Huawei !

.
, Cisco 2960S-24-PWR, Huawei / Huawei S5720-52X-PWR-SI V2R9SPC500.


:
48GE PoE+, 4*10GE .
SI L3 , RIP OSPF.
V200R009C00SPC500.
500, PoE 370.
1/10GE Uplinks.
10GE , SNR.
web CLI (telnet, ssh v2), SNMP v2c/v3, eSight.

S5720 IP-.

, .. S5700-LI, , , .

, S5720 ?

. VLAN


VLAN . . LLDP.

Voice VLAN hybrid. IP- Yealink LLDP, .

, Voice VLAN. , .

LLDP PoE .

. :

router id 192.168.30.4
#
ospf 1
area 0.0.0.0
network 10.0.50.0 0.0.0.255
#
interface Vlanif50
mtu 9198
ospf timer hello 1
ospf timer dead 3


peer . ( LAN-based design). neighbor ASA5512 .

: , SI , Vlan (Vlanif). .. L3 IP-. EI, HI.



.


DHCP snooping, IP Source Guard, ARP security , , .

, DHCP-. DHCP snooping , .. , .

DHCP snooping IP Source Guard ARP security, IP MAC . , DHCP, IPMAC .

, - IP-MAC, MITM- (Man-in-the-Middle).

STP. BPDU ( STP- ).

, BPDU stp bpdu-protection, stp root.

stp edge-port enable STP, .

stp bpdu-protection stp edge-port enable, Cisco spanning-tree portfast.

, :

dhcp enable
#
dhcp snooping enable
dhcp snooping alarm dhcp-rate enable
dhcp snooping user-bind autosave flash:/dhcp-bind.tbl write-delay 6000
arp dhcp-snooping-detect enable
dhcp server detect

vlan 2
name office
dhcp snooping enable
dhcp snooping check dhcp-request enable
dhcp snooping check dhcp-rate enable
arp anti-attack check user-bind enable
ip source check user-bind enable

vlan 3
name guest
dhcp snooping enable
dhcp snooping check dhcp-request enable
dhcp snooping check dhcp-rate enable
arp anti-attack check user-bind enable
ip source check user-bind enable

vlan 4
name voice
dhcp snooping enable
dhcp snooping check dhcp-request enable
dhcp snooping check dhcp-rate enable
arp anti-attack check user-bind enable
ip source check user-bind enable

interface GigabitEthernet0/0/1
port link-type hybrid
voice-vlan 4 enable
port hybrid pvid vlan 2
port hybrid tagged vlan 4
port hybrid untagged vlan 2
stp root-protection
stp bpdu-filter enable
stp edged-port enable
trust dscp

stp instance 0 root primary
stp bpdu-protection


.


, NTP, SNMP, AAA, Radius.

, 16 VTY, 5.

, , .

user-interface maximum-vty 15
user-interface con 0
authentication-mode aaa
history-command max-size 20
screen-length 40
user-interface vty 0 14
authentication-mode aaa
history-command max-size 20
idle-timeout 30 0
screen-length 40


?

SSH SSH, .

RSA , , .

ssh v1 , ( ).

stelnet server enable
[HUAWEI] aaa
[HUAWEI-aaa] local-user admin123 password irreversible-cipher Huawei@123
[HUAWEI-aaa] local-user admin123 service-type ssh
[HUAWEI-aaa] local-user admin123 privilege level 15
[HUAWEI-aaa] quit
[HUAWEI] ssh user admin123 authentication-type password


Radius.

, domain default_admin!

domain default_admin
authentication-scheme default
accounting-scheme Radius
service-scheme Admin
radius-server Radius


.


, ( ).

CLI.

, , , pfx .

, , , (, CA).

pem, CA .

, security flash. .

:

1. CA.
2. .
3. ( ) , .
4. mkdir flash:/security
5. tftp 192.168.0.1 chain-servercert.pem /security/chain-servercert.pem
, , .

system-view
[HUAWEI] ssl policy http_server
[HUAWEI-ssl-policy-http_server] certificate load pfx-cert servercert.pfx key-pair rsa key-file serverkey.pfx auth-code cipher 123456
# Load a PEM certificate chain for the SSL policy.

system-view
[HUAWEI] ssl policy http_server
[HUAWEI-ssl-policy-http_server] certificate load pem-chain chain-servercert.pem key-pair rsa key-file chain-servercertkey.pem auth-code cipher 123456

https , . web .

http server disable
http server enable

, web- .


:

  • CPU 20%, 30%. .
    CPU utilization for five seconds: 25%: one minute: 25%: five minutes: 24%
    TaskName CPU Runtime(CPU Tick High/Tick Low) Task Explanation
    VIDL 75% 2/187119ff DOPRA IDLE
    OS 12% 0/55d4a7fe Operation System
    POE 4% 0/204e4380 POE Power Over Ethernet

  • ESX, 804/ 999/, .

    Input peak rate 804556024 bits/sec, Record time: 2016-08-15 15:09:17
    Output peak rate 999957528 bits/sec, Record time: 2016-08-12 12:20:09

  • 1000/, 100/. AUTO, . 1 -, . Cisco 2960 1G . 20 . .

  • web , .

P.S. , !
Original source: habrahabr.ru (comments, light).

https://habrahabr.ru/post/334910/

:  

: [1] []
 

:
: 

: ( )

:

  URL