顯示具有 Cisco 標籤的文章。 顯示所有文章
顯示具有 Cisco 標籤的文章。 顯示所有文章

2015年3月24日 星期二

Cisco ASA5505 Transparent Firewall Configuration


台中某電廠的ASA 5505使用的透通式L2 Firewall的設定。

詳情請參考影片檔。

2014年9月19日 星期五

去友聲電子進行網路基礎教學


有幸應張弘毅老師的邀約去友聲電子進行網路基礎概念的教學,由於他們公司尚無完善的網路基礎建設和伺服器相關的概念,所以就決定從OSI模型和TCP/IP架構先開始講起,過程當中輔助一些必要的操作Demo讓大家理解網路指令和參數的作用,仍然是一次相當寶貴的經驗。

我認為上台需要練習自己的口條和台風,還有回答問題的技術,這些都是比台上講述專業技術更需要學問的地方,每次報告完畢都必須從頭省視這是報告的缺陷,時間的掌控、大家的理解程度,是不是符合與會者們的期待,這點很重要。

有些部分的說明還踏出了原本預期的範圍,我額外解釋了RAID和伺服器部分的容錯機制,希望他們將來能夠朝著這一部分來做努力。RAID 0、RAID 1、RAID 0+1、RAID 5這些比較重要並且常用到的機制。我儘量將技術面講得淺白易懂,讓大家都能夠理解這些技術的用途和作法,並且在短時間內講述了絕大數的網路技術、硬體、軟體和應用面。

互動式的講課,我覺得是比較不會無趣的演講方式,才不會只有單向的交流、雙向的交叉提問,可以有助於自己釐清所講述的議題。期許自己有朝一日也能當個合格的講師。

當日簡報檔案

2014年4月3日 星期四

Cisco 4710 簡易設定步驟


本文提供Cisco ACE 4710的簡易設定流程 ,請參考。

本人親著,版權所有,與分享使用者請來信聯繫。

2014年2月13日 星期四

關於AP IOS升降版初始化找不到tftp server的問題


昨天在Nike與公司環境都有發生過初始化AP的問題,以下針對AP開機按住Reset Button將預設IP設定回10.0.0.1,卻無法連上同網段Tftp Server時提供解決方式。

以下幾行為在AP上進行設定的關鍵指令,請參考:
debug capwap console client
debug capwap client no-reload

archive download-sw /overwrite tftp://10.66.74.250/ap3g2-k9w7-tar.default
最後一行請改成相對應的邏輯路徑,AP即可利用IP位址從Tftp Server端下載指定的IOS。


2014年1月20日 星期一

學校(TAS)無線網路規模


學校(TAS)無線網路規模


總控制端有一顆Wireless Control System(WCS),下轄8個Wireless LAN Controller(WLC),WLC下面在控制550顆左右數量的AP(Access Point)這樣形成了學校的主幹網路。學校的無線網路總共有四個SSID,這裡指的是Produation,測試用的不算。

第一種是TAS-MAC,這個ID可以連接學校伺服器與網路設備但是不能使用系統,通常給與廠商或者是硬體裝置使用(例如:無線印表機),我們也是用這個網段來進行學校網路連接與控管,驗證方式WEP加密而且綁硬體MAC。

第二種是TAS-IOS,因為學校多數學生的配備使用Apple(通常是蘋果的NB或是ipad的IOS來使用),驗證方式是WPA2,用學生或是教職員的帳號密碼來登入。

第三種是TAS-IT顧名思義,這個無線網路專門用來給IT部門使用(MIS、APP開發、PC維修部使用),驗證使用WPA2-PSK。

第四種是TAS-Intranet,給校內內部非IOS的裝置使用(通常是Windows系統),驗證方式是WPA2,用裝置網域的帳號密碼登入。

第五種是TAS-Guest,臨時申請可以到MIS部門臨櫃取得一組當日有效的密碼,登入連SSID沒有驗證,但有重導網頁登入的密碼系統控制,長期申請就是綁MAC跟私人密碼,通常給家長或是外賓到學校參訪時使用。

2014年1月15日 星期三

Cisco ACE 4710 Startup Configuration


設定清除步驟與重新開機
Starting sysmgr processes.. Please wait...Done!!!

switch login: admin
Password:
Cisco Application Control Software (ACSW)
TAC support: http://www.cisco.com/tac
Copyright (c) 1985-2012 by Cisco Systems, Inc. All rights reserved.
The copyrights to certain works contained herein are owned by
other third parties and are used and distributed under license.
Some parts of this software are covered under the GNU Public
License. A copy of the license is available at
http://www.gnu.org/licenses/gpl.html.
switch/Admin#
switch/Admin# ?
Exec commands:
  backup      Backup commands
  capture     Capture packets on one or more interfaces
  changeto    Changeto another context
  checkpoint  Checkpoint/Rollback commands
  clear       Reset functions
  clock       Manage the system clock
  compare     Compare checkpoint config with running config
  configure   Enter configuration mode
  copy        Copy from one file to another
  crypto      Execute PKI related commands
  debug       Debugging functions
  delete      Remove files -1
  dir         Directory listing for files
  dm          Device mgr commands for internal use
  exit        Exit from the EXEC
  format      Format a device with FAT16 file system
  ft          Fault-tolerant switchover
  gunzip      Uncompresses LZ77 coded files
  invoke      Invoke commands in other contexts from admin context
  license     Licensing specific commands
  load        Load plug-in image
  mkdir       Create new directory
  move        Move files
  ping        Send echo messages
  reload      Halt and perform a cold restart
  restore     Restore commands
  rmdir       Remove existing directory
  set         Set various asic registers
  setup       Run the basic SETUP command facility
  show        Show running system information
  sleep       Sleep some time for vsh script
  ssh         SSH to another system
  system      System management commands
  tac-pac     Save tac information to a specific location
  telnet      Telnet to another system
  terminal    Set terminal line parameters
  traceroute  Trace route to destination
  undebug     Disable Debugging functions (See also debug)
  untar       Untar the given file
  write       Write current configuration
  xml-show    Display xmlized show command result in xml

switch/Admin# clear st
startup-config  stats           sticky         
switch/Admin# clear startup-config
Warning: This command will erase the startup-configuration.
Do you wish to proceed anyway? (y/n)  [n] y
switch/Admin# reload
This command will reboot the system
Save configurations for all the contexts. Save? [yes/no]: [yes] no
Validating system image...
Perform system reload. [yes/no]: [yes]
switch/Admin#
以上步驟結束後,等待重新開機。



kernel=(hd0,1)/c4710ace-t1k9-mz.A5_1_2.bin ro root=LABEL=/ auto console=ttyS0,9
600n8 quiet bigphysarea=32768                                                  
   [Linux-bzImage, setup=0x1400, size=0xe75a16c]                               
                                                                               
INIT: version 2.85 booting                                                     
                                                                                
b4 lspci                                                                       
1 Cavium device(s) found.                                                      
Bringing up NP 0                                                                
Downloading U-Boot to NP card 0                                                
Downloading DP image to NP card 0                                              
Starting DP image on NP card on all cores                                       
DP image started on NP card                                                    
                                                                               
                                                                                
Setting up dynamic memory size                                                 
Initializing Shared Memory                                                     
INIT: Entering runlevel: 3                                                     
Testing PCI path for Octeon(0)....                                             
This may take some time, Please wait ....                                      
PCI test loop , count 0                                                        
PCI path is ready                                                              
Starting services...                                                          
Waiting for 3 seconds to enter setup mode...
Certificate & key are up to date [yes]
. itch/Admin# Unmounting ext3 filesystems...
Unmounting Other filesystems...
Installing MySQLRestarting system.
groupadd: group nobody exists
useradd: user nobody exists
MySQL Installed
Installing JRE
JRE Installed


Starting sysmgr processes.. Please wait...Done!!!

switch login: admin
Password:

 Admin user is allowed to login only from console until the default password is changed.
 www user is allowed to login only after the default password is changed.

 Enter the new password for user "admin":
 Confirm the new password for user "admin":
 admin user password successfully changed.

 Enter the new password for user "www":
 Confirm the new password for user "www":
 www user password successfully changed.

Cisco Application Control Software (ACSW)
TAC support: http://www.cisco.com/tac
Copyright (c) 1985-2012 by Cisco Systems, Inc. All rights reserved.
The copyrights to certain works contained herein are owned by
other third parties and are used and distributed under license.
Some parts of this software are covered under the GNU Public
License. A copy of the license is available at
http://www.gnu.org/licenses/gpl.html.


  ACE>                         

        This script will perform the configuration necessary for a user to
        manage the ACE Appliance using the ACE Device Manager.The management
        port is a designated Ethernet port which has access to the same
        network as your management tools including the ACE Device Manager.
        You will be prompted for the Port Number, IP Address, Netmask and
        Default Route (optional).
        Enter 'ctrl-c' at any time to quit the script

ACE>Would you like to enter the basic configuration dialog (yes/no) [y]: no
switch/Admin#

ACE清除設定後的預設帳密為
Account: admin
Password: admin
輸入後會要求修改admin與www兩帳號的密碼,請符合密碼原則輸入。
之後ACE會詢問是否要進行互動式設定
ACE>Would you like to enter the basic configuration dialog (yes/no) [y]: no
預設回答為Yes;如果不需要請輸入No。

附帶一提,如果事後仍覺得需要進行互動式設定,可以輸入Setup指令執行之。
switch/Admin# setup


  ACE>                         

        This script will perform the configuration necessary for a user to
        manage the ACE Appliance using the ACE Device Manager.The management
        port is a designated Ethernet port which has access to the same
        network as your management tools including the ACE Device Manager.
        You will be prompted for the Port Number, IP Address, Netmask and
        Default Route (optional).
        Enter 'ctrl-c' at any time to quit the script

ACE>Would you like to enter the basic configuration dialog (yes/no) [y]:

以下是互動式選項的設定方式的範例,供參考。
ACE>Would you like to enter the basic configuration dialog (yes/no) [y]:


  ACE> Enter the Ethernet port number to be used as the management port (1-4):? [1]:

  ACE> Enter the management port IP Address (n.n.n.n): [192.168.1.10]: 192.168.1.144

  ACE> Enter the management port Netmask(n.n.n.n): [255.255.255.0]:

  ACE> Enter the default route next hop IP Address (n.n.n.n) or to skip this step: 192.168.1.254

  ACE> Summary of entered values:

  Management Port: 1
  Ip address 192.168.1.144
  Netmask: 255.255.255.0
  Default Route: 192.168.1.254

  ACE>Submit the configuration including security settings to the ACE Appliance? (yes/no/details) [y]:


ACE> Configuration successfully applied. You can now manage this
ACE Appliance by entering the url 'http://192.168.1.144' into a
web browser to access the Device Manager GUI.

利用指令建立context
switch/Admin# conf t
Enter configuration commands, one per line.  End with CNTL/Z.
switch/Admin(config)# context ?
    Enter the context name (Max Size - 64)
  Admin  
switch/Admin(config)# context Bridge
switch/Admin(config-context)#
switch/Admin# sh context

Number of Contexts = 2

Name: Admin , Id: 0
Config count: 25
Description: 
Resource-class: default


Name: Bridge , Id: 1
Config count: 0
Description: 
Resource-class: default
Vlans:
switch/Admin#

進入選定的context進行設定
switch/Admin# changeto bridge
Error: context not found
switch/Admin# changeto Bridge
switch/Bridge#
請注意!所建立的Context名稱有區分大小寫。
還有是否成功切換所在位置的context請看/後面的context是否以切換。
不同context間的設定完全獨立,不會互通,需要個別儲存之。

檢查interface狀態
switch/Admin# sh interface

vlan1000 is up, VLAN up on the physical port

  Hardware type is VLAN
  MAC address is 00:1b:24:78:7f:4c
  Mode : routed
  IP address is 192.168.0.10 netmask is 255.255.255.0
  FT status is non-redundant
  Description:not set
  MTU: 1500 bytes
  Last cleared: never
  Last Changed: Sun Jan  5 22:40:45 2014
  No of transitions: 1
  Alias IP address not set
  Peer IP address not set
  Assigned on the physical port, up on the physical port

     633 unicast packets input, 189322 bytes
     400 multicast, 25 broadcast
     0 input errors, 0 unknown, 0 ignored, 0 unicast RPF drops
     1396 unicast packets output, 1671574 bytes
     0 multicast, 1 broadcast
     0 output errors, 0 ignored

GigabitEthernet Port 1/1 is UP, line protocol is UP
 Hardware is ACE Appliance 1000Mb 802.3, address is 00:1b:24:78:7f:4c
 Description:
 MTU 9216 bytes
 Full-duplex, 1000Mb/s
 COS bits based QoS is disabled
 input flow-control is off, output flow-control is off
    1063 packets input, 195505 bytes, 0 dropped
    Received 132 broadcasts (405 multicasts)
    0 runts , 0 giants
    0 FCS/Align errors , 0 runt FCS, 0 giant FCS
    1397 packets output, 1671574 bytes
    1 broadcast, 0 multicast, 0 control output packets 
    0 underflow, 0 single collision, 0 multiple collision output packets
    0 excessive collision and dropped, 0 Excessive Deferral and dropped 
GigabitEthernet Port 1/2 is ADMIN DOWN, line protocol is DOWN
 Hardware is ACE Appliance 1000Mb 802.3, address is 00:1b:24:78:7f:4c
 Description:
 MTU 0 bytes
 Auto-duplex, Auto-speed
 COS bits based QoS is disabled
 input flow-control is off, output flow-control is off
    0 packets input, 0 bytes, 0 dropped
    Received 0 broadcasts (0 multicasts)
    0 runts , 0 giants
    0 FCS/Align errors , 0 runt FCS, 0 giant FCS
    0 packets output, 0 bytes
    0 broadcast, 0 multicast, 0 control output packets 
    0 underflow, 0 single collision, 0 multiple collision output packets
    0 excessive collision and dropped, 0 Excessive Deferral and dropped 
GigabitEthernet Port 1/3 is ADMIN DOWN, line protocol is DOWN
 Hardware is ACE Appliance 1000Mb 802.3, address is 00:1b:24:78:7f:4c
 Description:
 MTU 0 bytes
 Auto-duplex, Auto-speed
 COS bits based QoS is disabled
 input flow-control is off, output flow-control is off
    0 packets input, 0 bytes, 0 dropped
    Received 0 broadcasts (0 multicasts)
    0 runts , 0 giants
    0 FCS/Align errors , 0 runt FCS, 0 giant FCS
    0 packets output, 0 bytes
    0 broadcast, 0 multicast, 0 control output packets 
    0 underflow, 0 single collision, 0 multiple collision output packets
    0 excessive collision and dropped, 0 Excessive Deferral and dropped 
GigabitEthernet Port 1/4 is ADMIN DOWN, line protocol is DOWN
 Hardware is ACE Appliance 1000Mb 802.3, address is 00:1b:24:78:7f:4c
 Description:
 MTU 0 bytes
 Auto-duplex, Auto-speed
 COS bits based QoS is disabled
 input flow-control is off, output flow-control is off
    0 packets input, 0 bytes, 0 dropped
    Received 0 broadcasts (0 multicasts)
    0 runts , 0 giants
    0 FCS/Align errors , 0 runt FCS, 0 giant FCS
    0 packets output, 0 bytes
    0 broadcast, 0 multicast, 0 control output packets 
    0 underflow, 0 single collision, 0 multiple collision output packets
    0 excessive collision and dropped, 0 Excessive Deferral and dropped

switch/Admin# sh ip int bri
Interface             IP-Address      Status                  Protocol
vlan1000              192.168.0.10    up                      up 
gigabitEthernet1/1    unassigned      up                      up 
gigabitEthernet1/2    unassigned      administratively down   down
gigabitEthernet1/3    unassigned      administratively down   down
gigabitEthernet1/4    unassigned      administratively down   down
檢查Port up/down狀態

檢查configuration設定
switch/Admin# sh running-config
Generating configuration....



boot system image:c4710ace-t1k9-mz.A5_1_2.bin

interface gigabitEthernet 1/1
  switchport access vlan 1000
  no shutdown
interface gigabitEthernet 1/2
  shutdown
interface gigabitEthernet 1/3
  shutdown
interface gigabitEthernet 1/4
  shutdown


access-list ALL line 8 extended permit ip any any






class-map type management match-any remote_access
  2 match protocol xml-https any
  3 match protocol icmp any
  4 match protocol telnet any
  5 match protocol ssh any
  6 match protocol http any
  7 match protocol https any
  8 match protocol snmp any

policy-map type management first-match remote_mgmt_allow_policy
  class remote_access
    permit

interface vlan 1000
  ip address 192.168.0.10 255.255.255.0
  access-group input ALL
  service-policy input remote_mgmt_allow_policy
  no shutdown

ip route 0.0.0.0 0.0.0.0 192.168.1.254

context Bridge


 
username admin password 5 $1$.HBIfcex$OzUi5Uv7eTEylxAf3NEPs/  role Admin domain
default-domain
username www password 5 $1$.wH9fZJd$X1MvFbstxWIWTCcHh9PjR0  role Admin domain de
fault-domain

ssh key rsa 1024 force


switch/Admin#

進到這邊,通常你就可以用Web介面去連接和管理ACE 4710了。重點是你連接ACE 4710的第一個Port網卡要設成跟它同網段。
  

2013年11月26日 星期二

How to add and remove a Cisco Catalyst 3750 switch from the existing switch stack


Resolution
It is very important that the switches added to or removed from the switch stack are powered OFF.
Issue the switch provision global configuration command on the stack master in order to provision or supply a configuration to the new switch before it joins the switch stack. Issue the no form of this command in order to delete all configuration information associated with the removed switch.
Complete these steps in order to add a switch:

Issue the switch stack-member-number provision type command.  

Power off the new stack member.   

Reconnect to the existing switch stack through the StackWise ports.  

Power on the new stack member.    
Complete these steps in order to remove a switch:

Power off the new stack member to be removed.       
Remove the StackWise cable from the switch.   
Note: The switch stack operation continues uninterrupted during membership changes unless the stack master is removed or powered-on standalone switches or switch stacks are added.

Issue the command no switch stack-member-number provision command.       
Note: You must remove the specified switch from the switch stack before you use this command in order to delete a provisioned configuration.

*本文為分享並非親著。
Ref. https://supportforums.cisco.com/docs/DOC-3794

2013年11月18日 星期一

CatOS Password Recovery


Cisco 的設備當中,CatOS已經是相當少機灰能碰得上的了,不過既然遇到就必須知道怎樣把記錄給記下來的關鍵。
CatOS Command 參考

可以使用clear config all指令去執行清除設定動作也可以按照思科的密碼回復步驟進行作業,詳請請鍵連結操作方式。

Cisco Ref.
Password Recovery Procedure for the Catalyst 1200, 1400, 2901, 2902, 2926T/F, 2926GS/L, 2948G, 2980G, 4000, 5000, 5500, 6000, 6500 Running CatOS

2013年11月14日 星期四

IP Default Route & IP Default-gateway


Not a dumb question at all.  Here is a doc that actually compares the commands and explains when and why you would use them.

事實上很少人能夠弄懂這兩者間的差異。

Ip default gateway is only used when the switch is in L2. You can use ip route or default-network at L3.

我想以上說明已經夠清楚了。

Use the ip default-gateway command when ip routing is disabled on a Cisco router. 

Use the ip default-network and ip route 0.0.0.0 0.0.0.0 commands to set the gateway of last resort on Cisco routers that have ip routing enabled. 

info from cisco.com 思科闡述的更加明白。

事實上思科設備把以下兩行指令視為相同:

(ip default route)
ip route 0.0.0.0 0.0.0.0 [next_hop]
(ip default-network)
ip default-network [next_hop]
(L2 Switch)
ip default-gateway [next_hop]

而IPv6的下法則是:

(ip default route)
ip route ::/0 [next_hop]
(ip default-network)
ip default-network [next_hop]
(L2 Switch)
ip default-gateway [next_hop]

記得下一站的目的地位址或網卡出口要下正確。

Ref. Configuring a Gateway of Last Resort Using IP Commands

2013年11月5日 星期二

Cisco ISE Install & Setup


關於利用VMWare進行ISE安裝步驟的模擬,可以詳見思科網站的連結。
請務必注意,硬碟大小建議200GB與RAM不得低於4GB,使用RedHat 5 64位元進行模擬安裝作業。


主要設定項目步驟

Enter hostname[]: ise-server-1 輸入主機名稱
Enter IP address[]: 10.1.1.10 輸入IP位址
Enter Netmask[]: 255.255.255.0 輸入子網路遮罩
Enter IP default gateway[]: 172.10.10.10 輸入預設閘道
Enter default DNS domain[]: cisco.com 輸入網域名稱
Enter Primary nameserver[]: 200.150.200.150 輸入DNS伺服器
Add/Edit another nameserver? Y/N: n 是否設定額外的DNS伺服器
Enter primary NTP domain[]: clock.cisco.com 輸入NTP伺服器位址
Add/Edit another NTP domain? Y/N: n 是否輸入額外的NTP伺服器
Enter system time zone[]: UTC 輸入時區,台灣請輸入Asia/Taipei
Enter username [admin]: admin 輸入登入帳號
Enter password: 輸入登入密碼[隱碼]
Enter password again: 再次輸入登入密碼[隱碼]

---以下開始進行安裝作業(時間非常漫長)---

Bringing up the network interface...
Pinging the gateway...
Pinging the primary nameserver...
Do not use `Ctrl-C' from this point on...
Virtual machine detected, configuring VMware tools...
Appliance is configured
Installing applications...
Installing ISE...
Application bundle (ise) installed successfully
===Initial Setup for Application: ise===
Welcome to the ISE initial setup. The purpose of this setup is to provision the 
internal ISE database. This setup requires you to create database administrator 
password and also create a database user password.
Please follow the prompts below to create the database administrator password.
Enter new database admin password:
Confirm new database admin password:
Successfully created database administrator password.
Please follow the prompts below to create the database user password.
Enter new database user password:
Confirm new database user password:
Successfully created database user password.
Running database cloning script...
Generating configuration...
Rebooting...
Welcome to the ISE initial setup. The purpose of this setup is to provision the 
internal database. This setup is non-interactive and will take roughly 15 
minutes to complete. Please be patient.
Running database cloning script...
Running database network config assistant tool...
Extracting ISE database contents...
Starting ISE database processes...
...

2013年10月28日 星期一

Cisco ACL 指令差異整理

Cisco ASA(Adaptive Security Appliance, ASA)
 不使用反向遮罩,使用一般的子網路遮罩。

access-list GAD extended permit tcp any 10.0.0.0 255.255.255.0 www

相當於C3750交換器所設定的存取清單:

ip access-list extended GAD
 permit tcp any 10.10.10.0 0.0.0.255 eq www

而NX-OS則是使用prefix來取代子網路遮罩或萬用遮罩

ip access-list GAD
  10 permit tcp 10.10.10.0/24 any eq www

*注意一下各種指令下達時候的差別。

2013年10月22日 星期二

Cisco 6500 多層交換器 簡介


特性:擴充性、電力備援、高容量、高密度連接埠。
插槽規格槽位數量從3-13個不等。
每一個模組都是可以熱插拔(hot-swappable)。
電源供應器可設為故障切換(failover)或聯合(combined)模式支援更多耗電模組。
符合電信等級認證的網路設備建置系統(Network Equipment Building System,NEBS)。

最初僅支援 32Gbps 背板速度,如今可以支持 720Gbps 背板速度,未來可以支持 1440Gbps 背板速度。
在大規模企業中扮演Core網路核心設備。

即使在小規模公司,也可以使用6509。包含防火牆模組(FWSM)、內容交換模組(CSM)、網路分析模組(NAM),單一機箱就能包含完整的 網路基礎架構、安全、負載平衡、裝置監控 等功能。

配備多層交換卡(包含在最新的supervisor之內),就成為了多層交換器,若執行原生的IOS還可以在保持交換器功能與速度的前提下,化為擁有300多個Ethernet連接埠介面的路由器。

C6500系列的槽位不能隨意亂插,例如:C6509,Supervisor可以主要插在槽位1,備援Supervisor插在槽位2;SFM(Switch Fabric Module)主要插在槽位5,備援SFM插在槽位6。如有內建SFM的Supervisor(例如sup-720)主要必須插在槽位5,備援插在槽位6,不要錯置了。

C6506沒有槽位7,8,9;C6513須將sup-720插在槽位7(主要)、槽位8(備援)。如有疑問請查閱思科相關文件。

增強型機箱(例如C6509E)
多一碼E代表增強型機箱,目的為了供應更多電力給線卡(Line card)。例如:VOIP的乙太網路供電(POE)線卡使用。

E經重新設計過後,每個槽位能支援 80Gbps 的總傳輸量;此理論值是一般C6500機箱的兩倍。C6509-V-E則為每個槽位均支持 80Gbps ,且包含NEBS機箱前版功能,包含了前後散熱與垂直模組。

2013年10月21日 星期一

如何在Switch上啟用snmp設定


以snmp-server為主要指令

C3750(Config)#snmp-server community RO

指的是SNMP協定時互相溝通的密碼
RO指的是Read Only (SNMP工具不允許修改設定)
RW指的是Read and Write (SNMP工具可以修改設定)

C3750(config)#snmp-server group SNMP_ROA v3 priv match exact

1.設定SNMP Group 名: SNMP_ROA  
2.Version : V3   
3.最高的priv

C3750(config)#snmp-server user cater SNMP_ROA v3 auth MD5 cisco12345 priv des56 test12345

這行設定跟PRTG設定有關聯,一定要記清楚

1.使用者          :cater
2.隸屬Group為:SNMP_ROA
3.驗證模式       :MD5
4.密碼(MD5)    :cisco12345   (PRTG要求要8碼以上)
5.Priv驗證密碼 :test12345     (PRTG要求要8碼以上)

C3750(config)#snmp-server host 192.168.3.100 version 3 priv cater

1.指定SNMP SERVER:192.168.3.100
2.使用Version 3
3.使用Priv 模式,使用者為cater

2013年10月18日 星期五

ICMP/PING drops when pinging from Nexus 7000


Ref. https://supportforums.cisco.com/docs/DOC-15510

重要勘查指令
clear copp statistics 清除計數器
show policy-map interface cpntrol-plane 查看現行的內建Policy Tramit or Drop的累計量,如果沒有執行上述清除,這個指令下呈現的值會是累計量。


2013年10月16日 星期三

Cisco學習資訊分享: 端點身分識別和授權定義與實施,Cisco ISE 產品介紹影片

Cisco學習資訊分享: 端點身分識別和授權定義與實施,Cisco ISE 產品介紹影片: From June 16~17, 2001. Green Island, 綠島 Cisco Identity Services Engine (ISE) 提供端點(Endpoints)在接入企業網路時,使用者的身分識別,和網路授權政策的定義和實施。這些功能,是以統一的管理介面,和分散式的佈署來完成。我們可以從以下的影片,瞭解這項產品所要解決的主要問題。




影片重點解析

1:17, ISE是授權政策定義、控制、和報表產生的統一來源。
1:25, ISE所提供的服務,包括身份識別(Authentication), 授權 (Authorization),和使用歷程紀錄(Accounting)
1:35, 包括端點使用網路的姿態檢查 (Posture),例如,檢查端點是否具有最新的病毒碼。
1:41, 包括端點的特性側寫(Profiler),例如,辨認端點是PC還是iPhone。
1:48, 包括來賓用戶管理(Guest Management)。
2:04, ISE = ACS + NAC. ISE 包含兩者所有的功能,但是管理統一化,而且佈署模式更簡單。
2:28, 包含兩種包裝,包括(1)Base Package 這種包裝基本上就是 ACS + NAC Guest Server.
2:36, 和(2) Advanced package. 這種包裝基本上就是 Base Package + NAC Appliance 和NAC Profiler.
2:48, Cisco 原有的NAC佈署,不是所有的情境都需要立刻轉換成 ISE。例如,原有的 NAC 僅僅是小規模的局部佈署,只提供簡單的單一進出管制點(Choke Point).
3:07, Cisco NAC 新版的產品硬體,跟ISE完全一樣。只需要更換軟體,就能變成ISE產品。

後記

很多企業都開始準備推動,員工攜帶自己的IT產品到公司內使用 (Bring Your Own Device, BYOD)。或者是為了法規遵循,企業必須追蹤所有網路活動的「使用者身份」。這時候身份識別和授權定義與實施的系統,將是不可缺少的基本元件。
如果管制的技術必須包括有線、無線、和VPN,再加上分散式佈署模式,我目前的理解只有 Cisco ISE符合以上需求。
尚未採購的NAC佈署,建議直接從ISE開始。

*此文為引用,作者為連結上部落格主,非本人所著,特此聲明。

2013年10月15日 星期二

思科AP三角定位實際應用成果

這是Cisco Wireless Control System下轄七部Cisco Wireless LAN Controller,控制500顆左右的Wireless AP(Thin AP架構,有效Roaming),利用Location Server計算三角定位後所有區域內上網行動裝置的動態示意圖,所有點位都是會移動。可以查看細節更是驚人,包含 登入PC名稱、網域的驗證、拿到的IP、用何種無線網路規格連上(a,b,g,n)、目前存取的AP與SSID資訊、連線時間、最近十筆連上記錄 都可以顯示。定位會有些許的上下樓層落差是目前技術上待改善的問題,不過已經算是相當精確了,因為在建置過程中是有輸入平面圖比例尺的。

PS:大顆綠點就是AP,藍點就是行動裝置,圖中顏色就是AP訊號強弱囉!

對華人區開思科案件(Cisco Case/TAC)


以下是思科的標準資訊回覆信件內容

對於泛亞華人區可以寄信到chinese-tac@cisco.com

信件內容需要完整提供以下資訊

如果您需要申请一个故障诊断/备件更换的CASE,请您提供以下相关信息:
用户名 (CCO):
产品序列号(SN):
售后服务合同号:
故障描述:
最终用户信息: (指使用該設備的客戶名稱)
(以下資訊為 工程師的連繫窗口)
联系人:
电话:
邮件地址:

思科會在短時間內以Mail回覆TAC Number,即完成開Case的手續。

或者有以上資訊直接使用思科電話報修:0080-1611206
思科客服部門會依序詢問以上相關信息,已完成開Case手續。

Case開立後,Cisco會派工尋找原廠工程師解決問題,20-40分鐘左右會致電給連繫人,詢問問題的詳細故障內容,屆時請直接與該思科原廠工程師溝通並偕同解決。

2013年10月14日 星期一

Cisco WLC (Wireless LAN Controller) Configuration Guide

Cisco WLC (Wireless LAN Controller)
無線區域網路控制器

如果我們要Reset這台裝置
在開機過程中,請按下Esc進行開機設定選項

Boot Options 
Please choose an option from below: 
 1. Run primary image 
 2. Run backup image 
 3. Manually update images 
 4. Change active boot image 
 5. Clear Configuration 
Please enter your choice: 5

選擇5,清除設定後重新開機
選擇問答方式配置,參考以下文件。

WLC 4404快速配置指南

2013年5月30日 星期四

常見的網路架構

*紅線代表光纖、黑線代表一般網路線、藍\紫線代表堆疊線或特殊線(也有可能是一般光纖或網路線),當然圖中省略了防火牆、負載平衡等設備,僅列出網路基礎建設的設備。

通常在竹科的公司為了產線網路都要求能做到7*24的高可用性(High Availability, HA),都會要求在更新案或是建置案上,要求一個完善的Solution去解決任何硬體故障時候的切換,所以網路架構都會是一個相當固定的模式,例如上圖,網路架構通常大同小異,當然實際公司或組織的拓樸都會比這還來得複雜,有很多時候被受限在拉線長度(Cat 5e僅能拉100M內)、傳輸距離(光纖物理特性)、設備功能上被迫調整網路架構而損失部分的線路容錯。
在Core(核心層)網路,技術上除了Routing(路由)跟其他Layer 4服務外,HSRP與VRRP所提供技術非常重要。

在Distribution與Access Layer(或稱為Edge)這兩層上,關鍵技術是STP(Spanning Tree Protocol)相關協定(RSTP、PVST…)與Vlan、VTP、Trunk、帶Tag、Etherchannel等。
安全性部分則是以ACL(Access Control List)與Port Security為主。

網路高可用性(HA)通常包含幾個部分:任一裝置或結點(Device/Node)、任一連接埠或模組(Port/Module)、任一線路(Line)的損壞或故障,都必須在有限時間內以硬體內部機制自動回復原有網路服務。



因此每當任何符合HA的網路架構建置案完工後,通常會進行HA測試,包含任一層網路裝置的斷電與復電測試、層與層之間的拔線測試,以底層Client連外Internet的Ping來檢視連外服務是否會受到影響,Ping掉包數量多寡,耗時多久能回復正常網路運作作為驗收參考的重要資料,做不到的時候將無法驗收。


這張圖描繪了底層Switch使用雙線路連接Distribution的情況,這種情況較著重在效能運作上(每台底層Switch皆提供Redundant Uplink),但是所耗費成本較高(很多時候不切實際),而頂層設備仍是接近Mesh情況較為常見。
當然,任何的網路架構都會將Performance(效能)、Cost(成本)、Security(安全性)、Convenience(方便性)幾個大方向列入重要考量,這些點無法同時兼顧只能視著User的需求進行調整,基於工程師立場只能給與User建議與可行的解決方案而不會涉入報價與成本,通常工程師追尋的是最適解答,而非最佳解答,因為這幾項因素都有互斥的因子存在,而在設計網路架構上,工程師通常還需要考慮到網路架構的彈性與擴張,如果一個客戶要做長久,彈性與擴張是必定要列入考量的點。如果有機會與User談網路架構的時候,務必釐清需求,很多時候會存在著資訊落差,一個專有名詞所代表的意義在各專業領域上會有所不同,很容易出現誤解(例如:Trunk這名詞在網路跟伺服器上就有明顯的不同)。


上圖就是幾種下層常見網路拓樸方式,分別代表泛用單環、效能傾向的雙層架構與高成本雙環三種,可以思考一下效能與成本間的差異,以及如何被實作。

上圖代表伺服器連接網路設備的架構圖,通常會配合Teaming建置,可以進行Lab實測,之前有實測過幾種,還有幾種需要待測,例如:Switch Stacking後的Server設Teaming情況。有興趣的,仍可以實測一下幾種架構在運作上的差異性、容錯的差別,附帶一提,Cisco Nexus系列會有VPCs的連接方式。