2 Router> enable
3 [Router# djsable
User mode, chuyén tir User mode sang Privilege mode
4 Router# configure terminal
5. (Router(config}# hostname (abc...
Privilege mode, chuyén tir Privilege mode sang User mode
Privilege mode, chuyén tir Pri
6 ‘Router(config}# banner motd Biabe....&
dat tén cho thiét bi
7 Router(config)# service password-encryption
8 Router(config)# enable password [password]
[dat canh bao khi ket néi vao thiét bi
ma héa t&t ca céc password
9 Router(config}t enable secret [password]
10 Router(config}# no ip domain-lookup
|dat password khi diing lénh enable (khéng ma héa)
[dat password khi ding lénh enable (cd ma héa)
tat tinh nang lookup
11.1 Console (router + switch)
12 |Router(config)# line console 0
13 Router(config-line}# password [password] ==SSSSs~C*~“~“~*~*~“‘“‘“~*~*~*S*S*S
14 Router(config-line)# login
_ Jeau hinh két néi console
[dat password console
15 Router(config-line}# logging synchronous
bat tinh nang kiém tra password khi login |
|déng bd dong lénh trong két néi console
16 Router(config-line}# exc-timeout [minutes] [seconds] [d8t thoi gian timeout cho két néi
W7 1.2 Telnet (router + switch)
18 Router(config)# line vty 04 (cu hinh két néi telnet (0-15)
19 /Router(configline)# password (password) [dat password telnet
20 Router(config-line)# login bat tinh nang kiém tra password khi login
21 Router(config-line)# logging synchronous
22
Router(configrline}# exc-timeout [minutes] [seconds]
dong b6 ding lénh trong két nditeinet _|
[d&t thoi gian timeout cho két néi
lege mode sang Global confiKouter(contig-line)# exc-timeout [minutes] [seconds]
1.2 Telnet (router + switch)
Router(config)# line vty 04
Router(config-line)# password [password]
Router(config-line)# login
Router(config-line)# logging synchronous
Router(config-line)# exc-timeout [minutes] [seconds]
Router(config-line)# transport input [telnet/ssh/rlogin/...
1.3 Delete config (router + switch)
Router# erase startup-config
dat thai gian timeout cho két ndi
cau hinh két ndi telnet (0-15)
dat password telnet
bat tinh nang kiém tra password khi lo;
idéng bé dong lénh trong két ndi telnet
dat thdi gian timeout cho két néi
chi ra giao thirc két néi
xéa cdu hinh startup config
Switch# delete vian.dat
xa file chira dit liu vlan
1.4 Default gateway (switch)
Router(config)# ip default-gateway [ip address}
[a3t ip default gateway cho switchch commit
30 2.1 VLAN
31 Switch(config)# vian [id]
tao vlan
32. Switch(config-vian)# name [abc..] Jat tén cho vlan
33 Switch(config)# no vian [id] ixéa vian
34. Switch(config)# vlan [id]
35 (2.2 Port access
36 Switch(config)# interface [id] vio céng can cdu hinh
37. Switch(config-if)# switchport mode access
38 |Switch(config-if}# switchport access vlan [id]
gan mode access cho port
gan port cho vian
mé ta port
40 [2.2 Port trunk
41 Switch(config)# interface [id]
[vo céng can cau hinh
42 Switch(config-if)# switchport trunk encapsulation dotiq [chi ra co’ ché tagging va untagging
43 Switch(config-if}# switchport mode trunk gan mode trunk cho port
44 Switch(config-if)# switchport trunk allow vlan [id/all/....] VLAN access control list
45 Switch(config-if}# switchport trunk native vian [id] [gan vian native va port trunk cho vian
46 Switch(config-if}# description [abc...] mé ta port| 40 [2.3 Port trunk.
a1 BueNconignterace
| 42 |Switch(config-if}# switchport trunkencapsulationdotig
43 |Switch(config-if) switchport mode trunk
| 44 |Switch(config-fit switchport trunk allow vlan [i/all/.<]
| 45 |Switch(config-if)# switchport trunk native vian [id]
| 46 Switch(config-if)}# description [abc...]
re nana -22---- >
vao céng can cau hinh
Ichi ra co’ ché tagging va untagging
gan mode trunk cho port
|VLAN access control list
lgdn vian native va port trunk cho vian
mé ta port[2.4 VTP
Switch(config)# vtp mode [server/client/transparent]
[gan mode cho switch
tao vtp domain
Switch(config)# vtp domain [ab
[tao vtp password
Switch(config)# vtp password [abc...]
2.5SVI
Switch(config)# interface vian [id] tao ra céng vlan =
Switch(config-if}# no shutdown factive céng
[dat ip cho céng
mé ta port
Switch config-if)# ip address [ip] [subnet mask]
Switch(config-if}# description [abc...]56 2.6 Switchport (switch layer 3)
57 Switch(config}# interface [id]
58. Switch(config-if}# no switchport
59. Switch(config-if}# switchport
vao céng can cau hinh
{tat tinh nang port switch
bat tinh nang port switch2.7 Spanning-tree Root bridge
Switch(config}# spanning-tree vian [id] root [primary/secondary]
chi ra root switch cho vlan nao
Switch(config}# spanning-tree vian [id] priority food
\gan priority cho switch trén vian
2.8 Spanning-tree port fast & bpdu guard
Switch(config}# spanning-tree portfast bpduguard default
bat tinh nang portfast & bpduguard trén tat ca cac port:
Switch(config}# interface [id]
vao céng can cau hinh
Switch(config-if}# spanning-tree vian [id] portfast [bat tinh nang portfast
Switch(config-if}# spanning-tree vian [id] bpduguard enable [bat tinh nang bpduguard
2.9 Spanning-tree higu chinh port
Switch(config}# interface [id] \vao céng cBn cau hinh
Switch(config-if}# spanning-tree vian [id] cost hood
higu chinh cost cua port trén vlan
Switch config-if}# spanning-tree vian [id] port-priority [ox
higu chinh gia tri dé wu tién cla port trén vian
Switch(config}# interface [id] (interface range [id]
ivao céng can cau hinh
Switch(config-if}# channel-protocol [lacp/pagp]
Switch(config-if}# channel-group [id] mode [auto/desirable/active/passive)
chi ra giao thc etherchannel
chi ra mode cila port3.1 Interface configuration
[vao cng can cau hinh
Router(config}# interface [id]
Router(config-if}# no shutdown jactive cng
Router(config-if)# ip address [ip] [subnet mask] dat ip cho céng
Router(config-if)# description [abc...} mé ta port
Router(config-if)# clock rate [clock]
ce Sate I NE Om CN
Router(config)# interface [id]
Router(config-if)# no shutdown,
dat tan suat hoat déng ctia céng, chi trén céng serial
\vao céng can cau hinh
lactive cng
Router(config}# interface [id).[vlan-id)
tao ra céng sub-interface
Router(config-if}# encapsulation dotiq [vlan-id] (native)
Router(config-if}# ip address [ip] [subnet mask]
Router(config-if|# description [abc...]
ira co ché tagging va untageing
dat ip cho céng
imé ta port| 3.3 Static route
) Router(config)# ip route [dest-network] [netmask] [exit-int] [ip-next-hop]
| Router(config)# ip route 0.0.0.0 0.0.0.0 [exit-int] [ip-next-hop]
, 3.4 IP SLA
) Router(config)# ip sla [id]
Router(config-ip-sla)# icmp-echo [dest-ip] source-ip [source-ip]
- Router(config-ip-sla-echo}# frequency [second]
“Router(config)# ip sla schedule [id] start-time now life forever
{tao ra hanh déng ping
thiét lp dia chi source va dest
thiét lap théi gian ping
ich hoat hanh d6ng ping
thiét lp diéu kién ding
Router(config)# track [id] ip sla [sla-id] reachability3.5 HSRP
Router(config)# interface [id) lvao céng can cau hinh
Router(config-if}# no shutdown active cong
Router(config-if}# ip address [ip} [subnet mask] dt ip cho céng
Router(config-if}# description [abc...) Imé ta port
dat ip 40 cho céng
Router(config-if}# standby [id] ip [virtual-ip}
Router(config-if}# standby [id] priority [number]
dat gid tri uu tién cla cong
Router(config-if)# standby [id] preempt
3.6 OSPF
Router(config}# router ospf [process-id]
Router(config-router)# network [direct-connected-network] [wildcard] area [area-Id]
bat tinh nang chiém quyén
Jactive giao thc ospf
hai bao cac network két ndi try’c tiép
Router (config-router)# passive- interface [interface-id]
chn quang ba céng local/public
Router(config-router)# default-information originate
Router(config-router}# router-id lipv4]
|quang ba dong default-route (néu cd)
dat router-id3.7 DHCP
Router(config)# ip dhcp excluded-address [ip] ogi dia chi !P
Router(config)# ip dhcp excluded-address (start-ip] [end-ip] logi day dia chi IP
Router(config)# ip dhcp pool [name] [tao pool ip
Router(config-router)# network [network] [netmask]
‘a network cap ip
Router(config-router)# default-router [ip]
dat ip default gateway
Router(config-router)# dns-server [ip]
[dat ip dns server
3.7 DHCP relay agent
Router(config}# interface [id]
vao céng can cau hinh
Router(config-if}# no shutdown active céng
Router(config-if}# ip address [ip] [subnet mask] dat ip cho céng
Router(config-if}# description [abc...] imé ta port
Router(config-if}# ip hepler-address [ip]
chi ra ip DHCP server3.7 Syslog
Router(config)# logging on
bat tinh nang syslog
Router(config)# logging [ip]
chi ra syslog server
Router(config)# logging trap [level]
chi ra cp dé bao log3.8 NTP
Router(config)# ntp server [ip]
3.9 NAT stati
Router(config)# interface [id]
Router(config-if)# ip nat inside/outside
Router(config)# ip nat inside source static [private-ip] [pulic-ip]
3.10 NAT dynamic
rantp server
\vao céng can cau
active cong
tao map ip private va ip public
Router(config)# interface [id]
Router(config-if}# ip nat inside/outside
vao céng can cau hinh
active cong
Router(config)# access-list [acl-id] permit any
tao ra day ip private
Router(config}# ip nat pool [name] [start-ip] [end-ip] netmask [netmask]
tao pool ip publ
Router (config)# ip nat inside source list [acl-id] pool [name]
tao map ip private va ip public3.11 NAT PAT
Router(config}# interface [id]
vao céng can cau hinh
Router(config-if}# ip nat inside/outside
active cong
‘Router(config)# access-list [acl-id] permit any
[tao ra day ip private
Router(config)# ip nat inside source list [acl-id] interface [public-int-
|] overload
tao map ip private va céng public
3.12 ACL telnet
Router(config)# access-list [acl-id] [permit/deny] [network] [wildcard]
tao ra day ip cho phép/chn
Router(config)# line vty 04
cau hinh két néi telnet (0-15)
Router(config-line}# password [password]
dat password telnet
Router(config-line)# login
bat tinh nding kiém tra password khi login
Router(config-line)# logging synchronous
déng bé dong lénh trong két ndi telnet
Router(config-line}# exc-timeout [minutes] [seconds]
dat thoi gian timeout cho két ndi
Router(config-line)# transport input [telnet/ssh/rlogin/....]
chi ra giao thttc két néi
Router(config-line)# access-class [acl-id] in
map access-list vao cong vty3.13 ACLiemp epee oo .
Router|config)# access-list [ac-id] [permit/deny] icmp [source] [wildcard] [dest] [wildcard] [echo/echo-rely] {to didu kign ACL
Router(config)# interface [id] “ie ‘cong apply ACL
ut -f}# ip access-group [acl] [in/out] [@8tACL theo chiSuinfout
3.14 ACL standard
Router(config}# access-list [acl-id] [permit/deny] [network] [wildcard] e
Router(config}# interface [id]
Router(config-if}# ip access-group [acl-id] [in/out]
3.15 ACL extend
Router(config}# access-list [acl-id] [permit/deny] [tcp/udp/ip] [source] [wildcard] [dest] [wildcard] eq [protocol-name/port]3.16 VPN
Router (config)# interface tunnel [i
|tao céng tunnel
Router(config-if}# no shutdown
lactive cong
Router(config-if}# ip address [ip] [subnet mask] d&t ip cho céng
Router(config-if)# tunnel source [source-int] Ichi ra céng source cla VPN
Router(config-if)# tunnel destination [destination-ip]
ra dich clia VPN
Router(config-if)# tunnel mode gre ip
ramode cla VPN