本文共 8409 字,大约阅读时间需要 28 分钟。
qnqy-dpf-jrex2200-01# show | display set
set version 12.3R11.2set system host-name qnqy-dpf-jrex2200-01set system time-zone Asia/Shanghaiset system root-authentication encrypted-password "$1$7RMyTyeG$tLGAToBggMFhcOw85Ts.EP/"set system login user admin uid 2000set system login user admin class super-userset system login user admin authentication encrypted-password "$1$m5Fp3PtY$cenAvv5Yq6VKsAlA317C2E/"set system services ftpset system services sshset system services telnetset system services web-management https system-generated-certificateset system services web-management https interface allset system syslog user * any emergencyset system syslog file messages any noticeset system syslog file messages authorization infoset system syslog file interactive-commands interactive-commands anyset system ntp boot-server 192.168.16.45set system ntp server 192.168.16.45set chassis alarm management-ethernet link-down ignoreset chassis auto-image-upgradeset interfaces interface-range allport member-range ge-0/0/0 to ge-0/0/20set interfaces interface-range allport unit 0 family ethernet-switching port-mode accessset interfaces interface-range allport unit 0 family ethernet-switching vlan members vlan_54set interfaces interface-range allport unit 0 family ethernet-switching filter input 54deactivate interfaces interface-range allport unit 0 family ethernet-switching filterset interfaces ge-0/0/0 unit 0 family ethernet-switchingset interfaces ge-0/0/1 unit 0 family ethernet-switchingset interfaces ge-0/0/2 unit 0 family ethernet-switchingset interfaces ge-0/0/3 unit 0 family ethernet-switchingset interfaces ge-0/0/4 unit 0 family ethernet-switchingset interfaces ge-0/0/5 unit 0 family ethernet-switchingset interfaces ge-0/0/6 unit 0 family ethernet-switchingset interfaces ge-0/0/7 unit 0 family ethernet-switchingset interfaces ge-0/0/8 unit 0 family ethernet-switchingset interfaces ge-0/0/9 unit 0 family ethernet-switchingset interfaces ge-0/0/10 unit 0 family ethernet-switchingset interfaces ge-0/0/11 unit 0 family ethernet-switchingset interfaces ge-0/0/12 unit 0 family ethernet-switchingset interfaces ge-0/0/13 unit 0 family ethernet-switchingset interfaces ge-0/0/14 unit 0 family ethernet-switchingset interfaces ge-0/0/15 unit 0 family ethernet-switchingset interfaces ge-0/0/16 unit 0 family ethernet-switchingset interfaces ge-0/0/17 unit 0 family ethernet-switchingset interfaces ge-0/0/18 unit 0 family ethernet-switchingset interfaces ge-0/0/19 unit 0 family ethernet-switchingset interfaces ge-0/0/20 unit 0 family ethernet-switchingset interfaces ge-0/0/21 unit 0 family ethernet-switching port-mode accessset interfaces ge-0/0/21 unit 0 family ethernet-switching vlan members 917set interfaces ge-0/0/22 unit 0 family ethernet-switching port-mode accessset interfaces ge-0/0/22 unit 0 family ethernet-switching vlan members vlan_54set interfaces ge-0/0/23 unit 0 family ethernet-switching port-mode trunkset interfaces ge-0/0/23 unit 0 family ethernet-switching vlan members allset interfaces ge-0/1/0 unit 0 family ethernet-switching port-mode trunkset interfaces ge-0/1/0 unit 0 family ethernet-switching vlan members allset interfaces ge-0/1/2 unit 0 family ethernet-switchingset interfaces ge-0/1/3 unit 0 family ethernet-switchingset interfaces vlan unit 0set interfaces vlan unit 502 family inet address 192.168.13.171/24set snmp community public authorization read-onlyset routing-options static route 0.0.0.0/0 next-hop 192.168.13.254set protocols igmp-snooping vlan allset protocols rstp bridge-priority 60kset protocols rstp interface allport edgeset protocols vstp vlan vlan_502set protocols vstp vlan vlan_54set protocols lldp interface allset protocols lldp-med interface allset firewall family inet filter RE_Filter term 1 from source-address 192.168.16.0/24set firewall family inet filter RE_Filter term 1 from protocol tcpset firewall family inet filter RE_Filter term 1 from destination-port telnetset firewall family inet filter RE_Filter term 1 from destination-port sshset firewall family inet filter RE_Filter term 1 from destination-port httpset firewall family inet filter RE_Filter term 1 from destination-port ftpset firewall family inet filter RE_Filter term 1 from destination-port httpsset firewall family inet filter RE_Filter term 1 then acceptset firewall family inet filter RE_Filter term 2 from protocol tcpset firewall family inet filter RE_Filter term 2 from destination-port telnetset firewall family inet filter RE_Filter term 2 from destination-port sshset firewall family inet filter RE_Filter term 2 from destination-port httpset firewall family inet filter RE_Filter term 2 from destination-port ftpset firewall family inet filter RE_Filter term 2 from destination-port httpsset firewall family inet filter RE_Filter term 2 then discardset firewall family inet filter RE_Filter term icmp from source-address 192.168.16.0/24set firewall family inet filter RE_Filter term icmp from protocol icmpset firewall family inet filter RE_Filter term icmp then acceptset firewall family inet filter RE_Filter term icmp-other from protocol icmpset firewall family inet filter RE_Filter term icmp-other then discardset firewall family inet filter RE_Filter term NTP from source-address 192.168.16.45/32set firewall family inet filter RE_Filter term NTP from protocol tcpset firewall family inet filter RE_Filter term NTP from protocol udpset firewall family inet filter RE_Filter term NTP from source-port ntpset firewall family inet filter RE_Filter term NTP-Other from protocol tcpset firewall family inet filter RE_Filter term NTP-Other from protocol udpset firewall family inet filter RE_Filter term NTP-Other from source-port ntpset firewall family inet filter RE_Filter term NTP-Other then discardset firewall family inet filter RE_Filter term Other then acceptset firewall family ethernet-switching filter 54 term 1 from protocol udpset firewall family ethernet-switching filter 54 term 1 from destination-port 1434set firewall family ethernet-switching filter 54 term 1 from destination-port 1433set firewall family ethernet-switching filter 54 term 1 from destination-port netbios-nsset firewall family ethernet-switching filter 54 term 1 from destination-port netbios-dgmset firewall family ethernet-switching filter 54 term 1 from destination-port 139set firewall family ethernet-switching filter 54 term 1 from destination-port netbios-ssnset firewall family ethernet-switching filter 54 term 1 then discardset firewall family ethernet-switching filter 54 term 2 from protocol tcpset firewall family ethernet-switching filter 54 term 2 from destination-port 135set firewall family ethernet-switching filter 54 term 2 from destination-port 139set firewall family ethernet-switching filter 54 term 2 from destination-port 445set firewall family ethernet-switching filter 54 term 2 then discardset firewall family ethernet-switching filter 54 term Other-Permit then acceptset ethernet-switching-options secure-access-port interface ge-0/0/23.0 dhcp-trustedset ethernet-switching-options secure-access-port interface ge-0/1/0.0 dhcp-trustedset ethernet-switching-options secure-access-port interface allport mac-limit 10set ethernet-switching-options secure-access-port interface allport mac-limit action shutdownset ethernet-switching-options secure-access-port interface allport vlan 54 mac-limit 10set ethernet-switching-options secure-access-port interface allport vlan 54 mac-limit action dropset ethernet-switching-options secure-access-port interface allport no-dhcp-trustedset ethernet-switching-options secure-access-port vlan vlan_54 arp-inspectionset ethernet-switching-options secure-access-port vlan vlan_54 examine-dhcpset ethernet-switching-options secure-access-port vlan vlan_54 ip-source-guardset ethernet-switching-options port-error-disable disable-timeout 600set ethernet-switching-options storm-control interface allset ethernet-switching-options bpdu-block interface allportset vlans default l3-interface vlan.0set vlans vlan917 vlan-id 917set vlans vlan_502 vlan-id 502set vlans vlan_502 l3-interface vlan.502set vlans vlan_506 vlan-id 506set vlans vlan_54 vlan-id 54set vlans vlan_924 description guanli-vlanset vlans vlan_924 vlan-id 924转载于:https://blog.51cto.com/yzmlinux/2407148