You are on page 1of 3

Configurar Seguran�a de Switch ou Router

enable
!
configure terminal
enable secret password
service password-encryption
!
line vty 0 15
transport input telnet|ssh|all
login
logging synchronous
password password
!
line console 0
transport ouput telnet|all
login
logging synchronous
password password
!

######################################################################
Seguran�a para telnet e SSH

username ERNESTO privilege <0-15> secret password


!
hostname SW
ip domain-name ernesto.com
crypto key generate rsa
line vty 0 15
transport input telnet|ssh|all
login local
!
line console 0
transport output ssh
login local
######################################################################
!
line vty 0 15
login
password password
access-class 3 in
!
access-list 3 permit 192.168.0.0 0.0.0.255
######################################################################
Configure terminal
!
banner motd @
######################################################################
######################SOMENTE PESSOAL AUTORIZADO######################
######################################################################
@

=====================================================================
APAGAR AS CONFIGURA��ES

write erase
erase startup-config
erase nvram
=====================================================================
LIMPAR A MAC TABLE

clear mac-address-table dynamic vlan 10


clear mac-address-table dynamic ineterface fast0/0
clear mac-address-table dynamic address 0200.AAAA.AAAA
=====================================================================
GERIR O SWITCH
OBS:Usa sempre a vlan que possui portas atribuidas a ela

interface vlan 1
ip address 192.168.1.10 255.255.255.0
ip address dhcp (aprender ip via DHCP)
no shut
exit
!
ip default-gateway 192.168.1.1
======================================================================
CONFIGURAR VTP

vtp mode off


vtp mode server
vtp mode client
vtp mode transparente
show vtp status
======================================================================
CONFIGURAR VLAN�s E ATRIBUIR PORTAS

vlan 10
name DATA
vlan 11
name VOICE
interface-range fastethernet 0/1-10
switchport mode access
switchport access vlan 10
switchport voice vlan 11
======================================================================
TROUBLESHOOT

show interface trunk


show spanning-tree vlan 10
show interface fastethernet 0/0 trunk
show spanning-tree vlan 10
=======================================================================
CONFIGURAR STP MODE

spanning-tree mode ? (mst, pvst, rapid-pvst)


spanning-tree vlan 1 priority ?
spanning-tree vlan 1 root primary (root switch para vlan1)
spanning-tree vlan 1 root secondary (segundo root switch para vlan1)
spanning-tree vlan 1 cost 2
=======================================================================
CONFIGURAR EtherChannel

interface-range fast 0/14-15


channel-group 1 mode on
channel-group 1 mode desirable | auto (PAgP Cisco)
channel-group 1 mode active | passive (LACP IEEE)
!
port-channel load-balance ?
test etherchannel load-balance interface pol mac ?
!
show etherchannel 1 summary
show etherchannel 1 ?
show etherchannel load-balance
========================================================================
CONFIGURAR ROTA ESTATICA

OBS: A interface de saida � local e ip de saida � do router vizinho


as redes s�o as que queremos alcan�ar

ip route 172.16.2.0 255.255.255.0 fast0/0 ?


ip route 172.16.3.0 255.255.255.0 172.15.5.3 ?

Rota Default

ip route 0.0.0.0 0.0.0.0 fast0/0


ip route 0.0.0.0 0.0.0.0 172.16.5.3
=========================================================================
CONFIGURA ROUTING NO SWITCH L3 (SVI)

sdm prefer lanbase-routing (switches 2960 e 2960-XR)


exit
reload
!
configure terminal

ip route

You might also like