Escolar Documentos
Profissional Documentos
Cultura Documentos
com
Switch de Capa 2
-------------------------------------------
Crear una vlan
Forma 1:
switch#configure terminal
switch(config)#vlan 2
switch(config-vlan)#name ssur
switch(config-vlan)#exit
switch(config)#exit
switch#
Forma 2:
swirch#vlan database
Warning: It is recommended to configure VLAN from config mode, as VLAN database mode is
being deprecated. Please consult user documentation for configuring VTP/VLAN in config
mode.
switch(vlan)#vlan 2 name ssur
VLAN 2 added:
Name: ssur
swirch(vlan)#exit
Swirch#
ssur es un ejemplo
Switch#show vlan
-------------------------------------------
Contraseñas (enable – consola – vty y encriptado)
switch#configure terminal
Switch(config)#enable secret ssur_1
Switch(config)#
Switch(config)#line console 0
Switch(config-line)#password ssur_2
Switch(config-line)#login
Switch(config-line)#exit
Switch(config)#
Switch(config)#line vty 0 15
Switch(config-line)#password ssur_3
Switch(config-line)#login
Switch(config-line)#exit
Switch(config)#service password-encryption
Switch#show running-config
-------------------------------------------
Interface (trunk o access) y asociarlos a vlan
Agregar a vlan 2 y dejarla como acceso
Switch#configure terminal
Switch(config)#interface fastEthernet 0/1
piriwenho@hotmail.com 1
Resumen CCNA 3 | Comandos http.telecossur.blogspot.com
Dejarla Trunk
Switch#configure terminal
Switch(config)#interface fastEthernet 0/1
Switch(config-if)#switchport mode trunk
Switch(config-if)#exit
Switch(config)#exit
Switch#show running-config
Switch#show interface trunk
Switch#show vlan
-------------------------------------------
Puerta de enlace por defecto
switch#configure terminal
Switch(config)#ip default-gateway A.B.C.D
Switch(config)#exit
Switch#
Switch#show running-config
-------------------------------------------
Vlan de administración
switch#configure terminal
Switch(config)#interface vlan 2
Switch(config-if)#ip address 10.0.0.1 255.0.0.0
Switch(config-if)#no shutdown
Switch#show running-config
-------------------------------------------
Vlan nativa
switch#configure terminal
Switch(config)#interface fastEthernet 0/5
Switch(config-if)#switchport mode trunk
Switch(config-if)#switchport trunk native vlan 2
-------------------------------------------
VTY (virtual trunking protocol)
Dominio (ej. inacap)
Switch#configure terminal
piriwenho@hotmail.com 2
Resumen CCNA 3 | Comandos http.telecossur.blogspot.com
-------------------------------------------
Spanning-tree
Bridge ID
Switch#configure terminal
Switch(config)#spanning-tree vlan 2 priority 4096
Ejemplo: vlan 2
<0-61440> bridge priority in increments of 4096
Port ID
Switch#configure terminal
Switch(config)#spanning-tree vlan 2 root primary
Switch#show spanning-tree
-------------------------------------------
Direcciones MAC
Configuracion MAC Statica
Switch#configure terminal
Switch(config)#mac-address-table static 0000.0a00.1232 vlan 2
interface fastEthernet 0/1
-------------------------------------------
IP Snooping
Switch#configure terminal
Switch(config)#ip dhcp snooping
Switch(config)#interface fastEthernet 0/2
Switch(config-if)#ip dhcp snooping trust
piriwenho@hotmail.com 3
Resumen CCNA 3 | Comandos http.telecossur.blogspot.com
-------------------------------------------
SSH
Switch#configure terminal
Switch(config)#hostname SSUR-1
SSUR-1(config)#ip domanin-name ssur
SSUR-1(config)#crypto key generate rsa
SSUR-1(config)#ip ssh version 2
SSUR-1(config)#line vty 0 15
SSUR-1(config-line)#tansport input ssh
Switch#show ip ssh
Switch#show ssh
-------------------------------------------
Recuperar contraseña en un switch (2950)
###########
flash_init
load_helper
boot
switch:flash_init
switch:load_helper
switch:dir flash:/
switch:delete flash:config.text
switch:boot
####################
-------------------------------------------
Por defecto estos switch vienen en función capa 2, se les debe activar el enrutamiento
Switch#configure terminal
Switch(config)#ip routing
Switch#configure terminal
Switch(config)#interface fastEthernet 0/1
piriwenho@hotmail.com 4
Resumen CCNA 3 | Comandos http.telecossur.blogspot.com
Switch(config-if)#no switchport
Switch(config-if)#ip address 10.0.0.1 255.0.0.0
Switch(config-if)#no shutdown
Switch(config-if)#end
-------------------------------------------
Rip y Rip version 2
RIP
Router#configure terminal
Router(config)#router rip
Router(config-router)#network A.B.C.D
RIP version 2
Router#configure terminal
Router(config)#router rip
Router(config-router)#version 2
Router(config-router)#network A.B.C.D
router#show ip route
-------------------------------------------
Eigrp
Router#configure terminal
Router(config)#router eigrp <1-65535>
Router(config-router)#network A.B.C.D
router#show ip route
-------------------------------------------
OSPF
Router#configure terminal
Router(config)#router ospf <1-65535>
Router(config-router)#network A.B.C.D “wildcard” area <0-4294967295>
Ejemplo:
Router(config)#router ospf 1
Router(config-router)#network 10.0.0.0 0.255.255.255 area 0
router#show ip route
-------------------------------------------
Ruta Estatica
Forma 1:
Router#configure terminal
Router(config)#ip route “red destino” “mascara red” “siguiente salto”
Ejemplo:
Router(config)#ip route 10.0.0.0 255.255.255.0 11.0.0.1
Forma 2:
Router#configure terminal
Router(config)#ip route “red destino” “mascara red” “interfaz salida”
Ejemplo:
Router(config)#ip route 10.0.0.0 255.255.255.0 serial 0/1
piriwenho@hotmail.com 5
Resumen CCNA 3 | Comandos http.telecossur.blogspot.com
-------------------------------------------
Ruta Por Defecto
Forma 1:
Router#configure terminal
Router(config)#ip route 0.0.0.0 0.0.0.0 “siguiente salto”
Forma 2:
Router#configure terminal
Router(config)#ip route 0.0.0.0 0.0.0.0 “interfaz salida”
Ejemplo
Router(config)#ip route 0.0.0.0 0.0.0.0 serial 0/1
-------------------------------------------
ACL
Eliminar ACL
ACL:
router(config)#no access-list[Nº de lista de acceso]
Interface:
Router(config-if)#no ip access-group[Nº de lista de acceso]
Vty:
router(config-line)#no access-class[Nº de lista de acceso]
Ejemplo:
Router(config)#access-list 11 deny tcp host 192.168.1.1 any eq 80
Router(config)#access-list 11 permit ip any any
Router(config)#interface fastEthernet 0/1
Router(config-if)#ip access-group 11 in
Router(config-if)#end
Router#configure terminal
Router(config)#access-list 10 deny 192.168.1.0 0.0.0.0
Router(config)#access-list 10 permit any
Router(config)#line vty 0 4
Router(config-line)#access-class 10 in
Router(config-line)#end
Router#sh access-lists
-------------------------------------------
piriwenho@hotmail.com 6