system-view 进入系统视图
display version 查看系统属性
显示诊断信息:display diagnostic-information
显示系统当前配置:display current-configuration
显示系统保存配置: display saved-configuration
显示接口信息:display interface
显示路由信息:display ip routing-table
显示VLAN信息:display vlan
显示生成树信息:display stp
显示MAC地址表:display mac-address
显示ARP表信息:display arp
显示系统CPU使用率:display cpu-usage
显示系统内存使用率:display memory
显示系统日志:display log
显示系统时钟:display clock
验证配置正确后,使用保存配置命令:save
删除某条命令,一般使用命令: undo
进入端口:interface GigabitEthernet0/0/11 (注意:先应该进入系统视图,即先输入:system-view 进入系统视图)
知道某个接口对应哪个MAC地址 : display mac-address interface ethernet0/0/1
知道本设备所有学到的MAC地址: display mac-address
实例:
<S5700-19F-02>system-view
Enter system view, return user view with Ctrl+Z.
[S5700-19F-02]display version
Huawei Versatile Routing Platform Software
VRP (R) software, Version 5.110 (S5700 V200R001C00SPC300)
Copyright (C) 2000-2012 HUAWEI TECH CO., LTD
Quidway S5700-52P-LI-AC Routing Switch uptime is 4 weeks, 3 days, 9 hours, 58 minutes
LS52T52S 0(Master) : uptime is 4 weeks, 3 days, 9 hours, 57 minutes
256M bytes DDR Memory
64M bytes FLASH
Pcb Version : VER B
Basic BOOTROM Version : 121 Compiled at Jun 14 2012, 10:49:20
CPLD Version : 262
Software Version : VRP (R) Software, Version 5.110 (V200R001C00SPC300)
[s5700-1902]interface GigabitEthernet0/0/22
[s5700-1902-GigabitEthernet0/0/22]
<s5700-1902>display mac-address GigabitEthernet0/0/11
-------------------------------------------------------------------------------
MAC Address VLAN/VSI Learned-From Type
-------------------------------------------------------------------------------
e005-c540-8b03 23/- GE0/0/11 dynamic
-------------------------------------------------------------------------------
Total items displayed = 1
#添加VLAN
<Quidway> system-view
[Quidway] vlan 128
[Quidway-vlan128] quit
#设定端口模式
<Quidway> system-view
[Quidway] int gigabitethernet 0/0/1
[Quidway-GigabitEthernet0/0/1] port link-type access
#将端口加入Vlan
<Quidway> system-view
[Quidway] vlan 131
[Quidway-vlan131] port gigabitethernet 0/0/21 to 0/0/22
[Quidway-Vlan131] quit
#设置Trunk
<Quidway> system-view
[Quidway] interface GigabitEthernet 0/0/23
[Quidway-GigabitEthernet0/0/23] port link-type trunk
[Quidway-GigabitEthernet0/0/23] port trunk allow-pass vlan 128 131
#设置VLAN IP(管理IP)
<Quidway> system-view
[Quidway] interface vlanif 131
[Quidway-Vlanif131] ip address 192.168.0.253 255.255.255.0
[Quidway-Vlanif131] shutdown
[Quidway-Vlanif131] undo shutdown
#设置默认路由
<Quidway> system-view
[Quidway] ip route-static 0.0.0.0 0.0.0.0 192.168.0.254
#设定NTP
<Quidway> system-view
[Quidway] ntp-service unicast-peer 192.168.0.254
# 关闭WEB Server,dhcp
<Quidway> system-view
[Quidway] undo http server enable
[Quidway] undo dhcp enable
#保存配置
<Quidway> save
这里先要分清镜像口和观察口
然后设置观察口
[SW1]observe-port 1 interface GigabitEthernet 0/0/1 这里设置交换机1口为观察口,并且把标记为1
然后就是设置镜像口,先要进入你要设置镜像口的接口模式
[SW1]interface GigabitEthernet 0/0/10
[SW1-GigabitEthernet0/0/10]port-mirroring to observe-port 1 ?
both Both(inbound and outbound)
inbound Inbound
outbound Outbound 这边在设置观察口的时候你可以选择观察进或者出的情况、、可以由自己来
[SW1-GigabitEthernet0/0/11]port-mirroring to observe-port 1 both
[SW1-GigabitEthernet0/0/11]display th
#
interface GigabitEthernet0/0/11
port-mirroring to observe-port 1 both 查看下当前端口的配置情况。
PS: 一个观察口可以对多个镜像口
文章二 http://bbs.51cto.com/thread-928235-1.html
# 配置GigabitEthernet0/0/1为镜像接口,GigabitEthernet0/0/2为观察接口,观察接口索引号为1。镜像GigabitEthernet0/0/1上的入方向业务流量到GigabitEthernet0/0/2上。
<Quidway> system-view
[Quidway] observe-port 1 interface gigabitethernet 0/0/2
[Quidway] interface gigabitethernet 0/0/1
[Quidway-GigabitEthernet0/0/1] port-mirroring to observe-port 1 inbound
引用:
原帖由 lisudan 于 2012-5-5 22:34 发表
我有3个端口要镜像怎么弄?
步骤1 执行命令system-view,进入系统视图。
步骤2 执行命令observe-port index interface interface-type interface-number ,配置观察接口。
步骤3 执行命令interface interface-type interface-number,进入镜像接口的接口视图。
步骤4 执行命令port-mirroring to observe-port index { both | inbound | outbound } ,配置接口
镜像。
当需要同时监控多个接口的入方向或出方向的报文时,可以重复执行步骤3 和步骤4。
disp cu 查看配置。看一下接的是什么接口!!
1、通过串口配置管理用接口(一般为interface 0/0/1)和ip
<Quidway> system-view
[Quidway] vlan 100
[Quidway-Vlan100] quit
[Quidway]interface GigabitEthernet 0/0/1
[Quidway-GigabitEthernet0/0/1]port hybrid pvid vlan 100
[Quidway-GigabitEthernet0/0/1] port hybrid untagged vlan 100
[Quidway-GigabitEthernet0/0/1] quit
[Quidway] interface vlanif 100
[Quidway-Vlanif100] ip address 192.168.1.1 24
[Quidway-Vlanif100] quit
[Quidway]save
将PC配置ip 192.168.1.5,然后访问http://192.1681.1
2.端口镜像功能配置
a. 在Switch上创建VLAN,把相应接口以Trunk方式加入VLAN
# 将接口GigabitEthernet0/0/4和GigabitEthernet0/0/24以Trunk方式加入同一VLAN。
(以下配置以接口GigabitEthernet0/0/4为例,同理配置接口GigabitEthernet0/0/24)
<Switch> system-view
[Switch] vlan 10
[Switch-vlan10] quit
[Switch] interface GigabitEthernet 0/0/4
[Switch-GigabitEthernet0/0/4] port link-type trunk
[Switch-GigabitEthernet0/0/4] port trunk allow-pass vlan 10
[Switch-GigabitEthernet0/0/4] quit
b. 配置观察接口
# 将GigabitEthernet0/0/24接口配置为观察接口。
<Switch> system-view
[Switch] observe-port 1 interface GigabitEthernet 0/0/24
c. 配置镜像接口
# 将GigabitEthernet0/0/4接口配置为镜像接口。
[Switch] interface gigabitethernet 0/0/4
[Switch-GigabitEthernet0/0/4] port-mirroring to observe-port 1 inbound
[Switch-GigabitEthernet0/0/4] quit
d. 检查配置结果
# 执行display port-mirroring命令查看观察接口和镜像接口的配置情况。
[Switch] display port-mirroring
Port-mirror:
----------------------------------------------------------
Mirror-port Direction Observe-port
----------------------------------------------------------
GigabitEthernet0/0/1 Inbound GigabitEthernet0/0/24
3.DHCP srv 配置
<Quidway> system-view
[Quidway] dhcp enable
[Quidway] ip pool 1
[Quidway-ip-pool-1] network 10.1.1.0 mask 255.255.255.128
[Quidway-ip-pool-1] dns-list 10.1.1.2
[Quidway-ip-pool-1] gateway-list 10.1.1.126
[Quidway-ip-pool-1] excluded-ip-address 10.1.1.2 10.1.1.3
[Quidway-ip-pool-1] excluded-ip-address 10.1.1.5
[Quidway-ip-pool-1] lease day 10
[Quidway-ip-pool-1] quit
[Quidway] interface vlanif 10
[Quidway-Vlanif10] dhcp select global
[Quidway-Vlanif10] quit
注意,vlan if ip必须要是ip pool同网段ip。否则dhcp失败。
4.执行如下配置后,网关ping不通,外网不通(注:172.31.1.x为外网ip)
<Quidway>disp current-configuration
#
!Software Version V200R001C00SPC300
sysname Quidway
#
vlan batch 10 100
#
undo http server enable
#
observe-port 1 interface GigabitEthernet0/0/24
#
dhcp enable
#
ip pool 1
gateway-list 172.31.1.251
network 172.31.1.0 mask 255.255.255.0
excluded-ip-address 172.31.1.1 172.31.1.145
excluded-ip-address 172.31.1.147 172.31.1.250
excluded-ip-address 172.31.1.252 172.31.1.254
lease day 10 hour 0 minute 0
dns-list 221.11.1.67
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %$%$O9hP7mbf4Q#E\vU4j#wX3ypg%$%$
local-user admin service-type http
#
interface Vlanif10
ip address 172.31.1.148 255.255.255.0
dhcp select global
#
interface Vlanif100
ip address 192.168.1.1 255.255.255.0
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port hybrid pvid vlan 100
port hybrid untagged vlan 100
#
interface GigabitEthernet0/0/2
port hybrid pvid vlan 10
#
interface GigabitEthernet0/0/3
port hybrid pvid vlan 10
port hybrid untagged vlan 10
#
interface GigabitEthernet0/0/4
port hybrid pvid vlan 10
port hybrid untagged vlan 10
port-mirroring to observe-port 1 inbound
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
port hybrid pvid vlan 10
port hybrid untagged vlan 10
#
interface NULL0
#
snmp-agent
snmp-agent local-engineid 800007DB03200BC79F2180
snmp-agent sys-info version v3
#
user-interface con 0
authentication-mode password
set authentication password cipher %$%$FY0$Z5Jw&>&N‘"V0[_ZD,sjaQ7|^9Tj#(FRA:x0mA<26.ypk%$%$
user-interface vty 0 4
user-interface vty 16 20
#
return
经查,为interface 2上vlan 没有设置untag属性,导致。增加设置port hybrid untagged vlan 10 后正常。