﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>IT博客-Think and Grow rich－－－－－－－－－－－－－－－－－－－－－－－-文章分类-网络知识</title><link>http://www.cnitblog.com/watermelonbig/category/3849.html</link><description /><language>zh-cn</language><lastBuildDate>Thu, 29 Sep 2011 21:53:06 GMT</lastBuildDate><pubDate>Thu, 29 Sep 2011 21:53:06 GMT</pubDate><ttl>60</ttl><item><title>前天已经得知自己通过了网工中级考试，还好，57/53</title><link>http://www.cnitblog.com/watermelonbig/articles/21500.html</link><dc:creator>大西瓜</dc:creator><author>大西瓜</author><pubDate>Thu, 04 Jan 2007 06:03:00 GMT</pubDate><guid>http://www.cnitblog.com/watermelonbig/articles/21500.html</guid><wfw:comment>http://www.cnitblog.com/watermelonbig/comments/21500.html</wfw:comment><comments>http://www.cnitblog.com/watermelonbig/articles/21500.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/watermelonbig/comments/commentRss/21500.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/watermelonbig/services/trackbacks/21500.html</trackback:ping><description><![CDATA[下一步就是从网工的学习中转移视线了，在java和数据库上花些精力。<img src ="http://www.cnitblog.com/watermelonbig/aggbug/21500.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/watermelonbig/" target="_blank">大西瓜</a> 2007-01-04 14:03 <a href="http://www.cnitblog.com/watermelonbig/articles/21500.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>路由器配置一例</title><link>http://www.cnitblog.com/watermelonbig/articles/16958.html</link><dc:creator>大西瓜</dc:creator><author>大西瓜</author><pubDate>Sun, 17 Sep 2006 04:42:00 GMT</pubDate><guid>http://www.cnitblog.com/watermelonbig/articles/16958.html</guid><wfw:comment>http://www.cnitblog.com/watermelonbig/comments/16958.html</wfw:comment><comments>http://www.cnitblog.com/watermelonbig/articles/16958.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/watermelonbig/comments/commentRss/16958.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/watermelonbig/services/trackbacks/16958.html</trackback:ping><description><![CDATA[Current configuration:<br />!<br />Version 11.3<br />no service password-encryption<br />!<br />hostname Router1         －－将路由器命名为Router1<br />!<br />enable password pwd12345　　　－－使能密码为pwd12345<br />!<br />interface Ethernet0<br />ip address 192.4.1.1 255.255.255.0<br />!<br />interface Serial0<br />ip address 192.3.1.1 255.255.255.0<br />encapsulation frame-relay IETF　　－－在串口配置中封装帧中继，并且使用IETF包装格式<br />no ip mroute-cache<br />bandwidth 2000 　　－－带宽为2M<br />frame-relay map ip 192.3.1.2 100 broadcase　　－－将IP地址与帧中继地址进行映射。对端路由器接口的IP地址为192.3.1.2，本端口的帧中继号码为100，使用广播方式在帧中继线路上传送路由信息。<br />frame-relay lmi-type cisco<br />!<br />router ospf 1　　－－启动OSPF路由协议，且该OSPF路由进程ID为1。<br />network 192.1.1.0   0.0.0.255  area  0　　－－指定与该路器相连的网络IP为192.1.1.0，子网通配符为0.0.0.255，网络区域ID为0。<br />network 192.3.1.0   0.0.0.255  area  0<br />network 192.4.1.0   0.0.0.255  area  0<br />neighbor 192.1.1.2    　　－－指定相邻的路由器为192.1.1.2<br />!<br />End<br /><img src ="http://www.cnitblog.com/watermelonbig/aggbug/16958.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/watermelonbig/" target="_blank">大西瓜</a> 2006-09-17 12:42 <a href="http://www.cnitblog.com/watermelonbig/articles/16958.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>IPsec VPN (cisco)配置一例</title><link>http://www.cnitblog.com/watermelonbig/articles/16957.html</link><dc:creator>大西瓜</dc:creator><author>大西瓜</author><pubDate>Sun, 17 Sep 2006 04:30:00 GMT</pubDate><guid>http://www.cnitblog.com/watermelonbig/articles/16957.html</guid><wfw:comment>http://www.cnitblog.com/watermelonbig/comments/16957.html</wfw:comment><comments>http://www.cnitblog.com/watermelonbig/articles/16957.html#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://www.cnitblog.com/watermelonbig/comments/commentRss/16957.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/watermelonbig/services/trackbacks/16957.html</trackback:ping><description><![CDATA[
		<p class="MsoPlainText">
				<span lang="EN-US">Cisco配置举例</span>
		</p>
		<p class="MsoPlainText">本例假设两端分别为广州和中山，两路由器之间简单用直接电缆连接，其地址分别假设如下表</p>
		<p class="MsoPlainText">
				<span lang="EN-US"> <?xml:namespace prefix = o /?><o:p></o:p></span>
		</p>
		<p class="MsoPlainText">广<span lang="EN-US"><span>     </span>州</span></p>
		<p class="MsoPlainText">中<span lang="EN-US"><span>     </span>山</span></p>
		<p class="MsoPlainText">内部网段网号</p>
		<p class="MsoPlainText">
				<span lang="EN-US">172．22．1．0</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">172．22．2．0</span>
		</p>
		<p class="MsoPlainText">互连网段网号</p>
		<p class="MsoPlainText">
				<span lang="EN-US">168．1．1．0</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">167．1．1．0</span>
		</p>
		<p class="MsoPlainText">路由器内部端口<span lang="EN-US">IP地址</span></p>
		<p class="MsoPlainText">
				<span lang="EN-US">172．22．1．100</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">172．22．2．100</span>
		</p>
		<p class="MsoPlainText">路由器<span lang="EN-US">Internet端口IP地址</span></p>
		<p class="MsoPlainText">
				<span lang="EN-US">168．1．1．1</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">167．1．1．1</span>
		</p>
		<p class="MsoPlainText">路由器串口<span lang="EN-US">IP地址</span></p>
		<p class="MsoPlainText">
				<span lang="EN-US">202．96．1．1</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">202．96．1．2</span>
		</p>
		<p class="MsoPlainText">隧道端口<span lang="EN-US">IP地址</span></p>
		<p class="MsoPlainText">
				<span lang="EN-US">192．168．1．1</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">192．168．1．2</span>
		</p>
		<p class="MsoPlainText">则两端路由器配置分别如下：</p>
		<p class="MsoPlainText">广州端路由器部分配置：</p>
		<p class="MsoPlainText">
				<span lang="EN-US">crypto isakmp policy 1<span>        </span>;配置IKE 策略1</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>authentication pre-share<span>     </span>；IKE 策略1验证方法设为pre-share</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>group 2<span>                      </span>；1024-bit Diffie-Hellman，加密算法未设置则取缺省值：DES</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">crypto isakmp key test123 address 202.96.1.2<span>  </span>；设置Pre-share密钥为test123,此值两端需一致</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">crypto ipsec transform-set VPNtag ah-md5-hmac esp-des ；设置AH散列算法为md5 ，</span>
		</p>
		<p class="MsoPlainText">！<span lang="EN-US"><span>                                                      </span>ESP加密算法为DES。</span></p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>crypto map VPNdemo 10 ipsec-isakmp<span>     </span>；定义crypto map</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>set peer 202.96.1.2<span>                  </span>；设置隧道对端IP地址</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>set transform-set VPNtag<span>    </span>；设置隧道AH及ESP，</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>match address 101<span>           </span>；</span>
		</p>
		<p class="MsoPlainText">！</p>
		<p class="MsoPlainText">
				<span lang="EN-US">interface Tunnel0<span>          </span>；定义隧道接口</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>ip address 192.168.1.1 255.255.255.0 ；隧道端口IP地址</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>no ip directed-broadcast</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>tunnel source 202.96.1.1<span>         </span>;隧道源端地址</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>tunnel destination 202.96.1.2<span>    </span>；隧道目的端地址</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>crypto map VPNdemo<span>              </span>；应用VPNdemo 于此接口</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US"> <o:p></o:p></span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">interface Serial0/0</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>ip address 202.96.1.1 255.255.255.252<span>  </span>；串口的Internet IP地址</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>no ip directed-broadcast</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>crypto map VPNdemo<span>             </span>；应用VPNdemo 于串口</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US"> <o:p></o:p></span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">!</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">interface Ethernet0/1</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>ip address 168.1.1.1 255.255.255.0<span>   </span>；外部端口IP地址</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>no ip directed-broadcast</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">interface Ethernet0/0<span>  </span></span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>ip address 172.22.1.100 255.255.255.0<span>   </span>； 内部端口IP地址</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>no ip directed-broadcast</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">!</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">ip classless</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">ip route 0.0.0.0 0.0.0.0 202.96.1.2<span>    </span>；缺省路由</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">ip route 172.22.2.0 255.255.0.0 192.168.1.2<span>  </span>；到中山端内网静态路由（经过隧道）</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">access-list 101 permit gre host 202.96.1.1 host 202.96.1.2<span>  </span>；定义存取列表</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US"> <o:p></o:p></span>
		</p>
		<p class="MsoPlainText">中山端路由器部分配置：</p>
		<p class="MsoPlainText">
				<span lang="EN-US">crypto isakmp policy 1</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>authentication pre-share</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>group 2</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">crypto isakmp key test123 address 202.96.1.1</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">crypto ipsec transform-set VPNtag ah-md5-hmac esp-des</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">!</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">crypto map VPNdemo 10 ipsec-isakmp</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>set peer 202.96.1.1</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>set transform-set VPNtag</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>match address 101</span>
		</p>
		<p class="MsoPlainText">！</p>
		<p class="MsoPlainText">
				<span lang="EN-US">interface Tunnel0</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>ip address 192.168.1.2 255.255.255.0</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>no ip directed-broadcast</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>tunnel source Serial0/0</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>tunnel destination 202.96.1.1</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>crypto map VPNdemo</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US"> <o:p></o:p></span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">interface Serial0/0</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>ip address 202.96.1.2 255.255.255.252</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>no ip directed-broadcast</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>crypto map VPNdemo</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">!</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">interface Ethernet0/1</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>ip address 167.1.1.1 255.255.255.0</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>no ip directed-broadcast</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">interface Ethernet0/0</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>ip address 172.22.2.100 255.255.255.0</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">
						<span> </span>no ip directed-broadcast</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">!</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">ip classless</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">ip route 0.0.0.0 0.0.0.0 202.96.1.1</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">ip route 172.22.1.0 255.255.0.0 192.168.1.1</span>
		</p>
		<p class="MsoPlainText">
				<span lang="EN-US">access-list 101 permit gre host 202.96.1.2 host 202.96.1.1</span>
		</p>
<img src ="http://www.cnitblog.com/watermelonbig/aggbug/16957.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/watermelonbig/" target="_blank">大西瓜</a> 2006-09-17 12:30 <a href="http://www.cnitblog.com/watermelonbig/articles/16957.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>