You are on page 1of 5

************************************

**************SWITCH***************
************************************
Config basic
hostname SWA
ip domain-name www.duoc.cl
username SWA password cisco
crypto key generate rsa
1024
line vty 0 4
transport input ssh
login local
exit
enable
configure terminal
hostname (NAME)
enable secret (PASSWORD)
line console 0
password (PASSWORD)
login
exit
banner motd "#SOLO ACCE#"
service password-encryption
ip domain-name (DOMINIO)
username (NAME) password (PASSWORD)
crypto key generate rsa
1024
line vty 0 4
transport input ssh
login local
exit
interface vlan 1
ip address (DIRECCION IPV4) (MASK)
description SWITCH LAN (NAMEROUTER)
no shutdown
end
wr
Crear vlan
vlan XX
name XXXX
exit
Asociar vlan a interface
interface INTERFACE PUERTO
interface range INTERFACE PUERTO-XX
switchport mode access
switchport access vlan XX
exit
interface range INTERFACE PUERTO-XX, INTERFACE PUERTO-XX
GW VLAN
ip default-gategay IP
interface vlan XX
ip address IP MASK
exit
VLAN TRUNK
interface INTERFACE PUERTO
interface range INTERFACE PUERTO-XX
switchport mode trunk
switchport trunk allowed vlan XX,XX,XX
switchport trunk native vlan XX
SEGURIDAD DE PUERTOS
Seguridad de puerto dinamica
interface range INTERFACE PUERTO
interface range INTERFACE PUERTO-XX
switchport port-security
Seguridad de puerto por aprendizaje
interface range INTERFACE PUERTO
interface range INTERFACE PUERTO-XX
switchport port-security maximum XX
switchport port-security mac-address sticky
POLITICA VIOLACION DE PUERTO
switchport port-security violation shutdown

************************************
**************ROUTER****************
************************************
enable
configure terminal
hostname (NAME)
security passwords min-length (TAMAO)
enable secret (PASSWORD)
line console 0
password (PASSWORD)
login
exit
banner motd "(TEXTO)"
service password-encryption
ip domain-name (DOMINIO)
username (NAME) password (PASSWORD)
crypto key generate rsa
(LONGITUD)
line vty 0 4
transport input ssh
login local
exit
ENRUTAMIENTO INTERVLAN
interface INTERFACE PUERTO.subint
encapsulation dot1Q VLAN
ip address IP MASK
ipv6 address IPV6/MASK
exit
LEVANTAR PUERTO CON subinterfaces
interface INTERFACE PUERTO
no shutdown
interface INTERFACE PUERTO (SERIAL 0/0/0)
ip address IP MASK
ipv6 address IPV6/MASK
clock rate XXXXX
no shutdown
================================================================================
================================
ENRUTAMIENTO DINAMICO POR DEFECTO
ip route 0.0.0.0 0.0.0.0 INTERFACE PUERTO
ipv6 route ::/0 INTERFACE PUERTO
RUTAS FLOTANTES POR DEFEECTO
ip route 0.0.0.0 0.0.0.0 INTERFACE PUERTO
ip route 0.0.0.0 0.0.0.0 INTERFACE PUERTO A.D
ipv6 route ::/0 INTERFACE PUERTO
ipv6 route ::/0 INTERFACE PUERTO A.D
ENRUTAMIENTO ESTATICO CON RUTAS POR DEFECTO
RUTA ESTATICA FLOTANTE
ip route "RED A LLEGAR MASK" "INTERFACE" "PUERTO"
ip route "RED A LLEGAR" "MASK" "INTERFACE" "PUERTO" "A.D"
ipv6 route "RED A LLEGAR MASK" "INTERFACE" "PUERTO"
ipv6 route "RED A LLEGAR" "MASK" "INTERFACE" "PUERTO" "A.D"
================================================================================
===============================
RIP V2 (ipv4)
router rip
version 2
no auto-summary
network IP RED
passive-interface INTERFACE PUERTO
passive-interface INTERFACE PUERTO.subint
default-information originate
exit
network IP RED (se debe declarar redes tipo C)
desactivar protocolo hacia equipos finales y router de borde ISP
default-information originate (se debe aplicar en router de borde)
================================================================================
===============================
RIPng (ipv6) nent generation
ipv6 unicast-routing
ipv6 router rip PROCESO
redistribute static
redistribute connected
interface INTERFACE PUERTO
interface INTERFACE PUERTO.subint
ipv6 rip PROCESO enable
exit
Solo en router de borde aplicar:
redistribute static
redistribute connected
*PROCESO: se le designa de forma manual
================================================================================
===============================
OSPF v2
router ospf ID
router-id ip
passive-interface INTERFACE PUERTO
network IP RED MASK area X
default-information originate
redistribute subnets tag ID
exit
passive interface (Solo se aplica en casos de; loopback, otro protocolo, redes l
an)
network solo redes tipo C directamente conectada
Area = 0
default-information originate (solo en router de borde)
tag N del ID
OSPF v3
ipv6 unicast-routing
ipv6 router ospf ID
router-id IP
passive-interface INTERFACE PUERTO
interface INTERFACE PUERTO
ipv6 ospf ID PROCESO area XX
ipv6 router ospf ID
redistribute static subnets tag ID
publicar redes tipo C, se asigna dentro de la interfaz
Area= 0
**************************
*****COMANDOS UTILES******
**************************
show vlan brief
show running-config
end
wr
copy running-config startup-config
show ip route
show ipv6 route
show ip ospf neighbor
show ipv6 ospf neighbor
Para conectar por ssh desde un equipo a otro en red desde consola aplica:
ssh -l USER IP
PASSWORD

You might also like