ÎÞ·¨Í¨¹ýCLI¹ÜÀí×°±¸
Ò»¡¢Õ÷ÏóÐÎò
×°±¸ÓÐËÄÖֵǼ·½·¨£ºSSH / TELNET / CONSOLE / WEB
·ºÆðÈçϹÊÕÏ£º
1¡¢CONSOLE¿ÚÎÞ·¨µÇ¼
2¡¢TELNETÎÞ·¨µÇ¼
3¡¢SSHÎÞ·¨µÇ¼
4¡¢WEBÎÞ·¨µÇ¼
¶þ¡¢×éÍøÍØÆË

Èý¡¢¿ÉÄÜÔµ¹ÊÔÓÉ
1¡¢CRTÈí¼þÉèÖòÎÊýÎÊÌ⣬£¬£¬£¬£¬»òÕßconsoleÏßÎÊÌâ
2¡¢control-planeեȡµÇ¼ÉèÖ㬣¬£¬£¬£¬ACL¹ýÂËÏÞÖÆ£¬£¬£¬£¬£¬VTYÏß³ÌÕ¼Âú
ËÄ¡¢´¦Öóͷ£°ì·¨
Õ÷Ïó1£ºCONSOLEÎÞ·¨µÇ¼
°ì·¨1¡¢¼ì²é×°±¸µçÔ´µÆÔËÐÐ״̬
1. ¼ì²éPWRµÆ×´Ì¬
µçÔ´Õý³££ºÂÌÉ«³£ÁÁ
µçÔ´¹Ø±Õ»ò¹ÊÕÏ£º²»ÁÁ
±¸×¢£ºÈôÊǵçÔ´µÆ²»ÁÁ£¬£¬£¬£¬£¬Çë¼ì²éµçÔ´ÊÇ·ñÕý³£¼Óµç£¬£¬£¬£¬£¬ÅжÏ×°±¸ÊÇ·ñ±£´æÓ²¼þÎÊÌâµ¼ÖÂÎÞ·¨¼Óµç
2. ¼ì²éSYSµÆ×´Ì¬
Éϵç³õʼ»¯£ºÂÌÉ«ÉÁׯ
³õʼ»¯Íê³É£ºÂÌÉ«³£ÁÁ
¸æ¾¯£ººìÉ«³£ÁÁ
±¸×¢£º¿ÉÒÔ¹Ø×¢consoleÊä³öÈÕÖ¾¾ÙÐÐÅжÏÈí¼þÊÇ·ñ±£´æÒì³£
°ì·¨2¡¢ConsoleÏß²ÎÊýÉèÖÃ
ÈôÊÇʹÓÃCRTÈí¼þ£¬£¬£¬£¬£¬ConsoleÏߵǼÐèҪѡÔñ׼ȷµÄcom¿Ú£¬£¬£¬£¬£¬ÒÔ¼°²¨ÌØÂÊΪ9600£¬£¬£¬£¬£¬²»¿É¹´Ñ¡Á÷¿ØÎ»
¶Ë¿Ú¿ÉÒÔͨ¹ýµçÄԶ˵Ä×°±¸¹ÜÀíÆ÷Éó²é
ÈçÏÂͼËùʾ
°ì·¨3¡¢Ìæ»»consoleÏß/×°±¸²âÊÔ
1¡¢Ìæ»»consoleÏß¾ÙÐвâÊÔ£¬£¬£¬£¬£¬ÅжÏÏÂconsoleÏßÊÇ·ñ±£´æÎÊÌâ
2¡¢ÈôÊÇûÓжàÓàconsoleÏߣ¬£¬£¬£¬£¬Ìæ»»ÆäËûÖ§³ÖconsoleµÇ¼µÄ·½·¨²âÊÔ
ÈôÊÇconsole¿ÚÈÔÈ»ÎÞ·¨µÇ¼£¬£¬£¬£¬£¬´°¿ÚûÓÐÊäÈëºÍÊä³ö£¬£¬£¬£¬£¬¿ÉÄܱ£´æconsole±£´æÓ²¼þÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔʹÓÃÆäËû·½·¨¾ÙÐеǼ²âÊÔ¡£¡£¡£¡£¡£¡£¡£¡£
Õ÷Ïó2£ºTELNETÎÞ·¨µÇ¼
°ì·¨1¡¢ÅŲéµÇ¼²ÎÊýÉèÖ㨵ØÖ·¡¢¶Ë¿Ú£©
1¡¢µÇ¼µØÖ·¹ýʧ
a. consoleÏߵǼ¿ÉÒÔÉó²é½Ó¿ÚµØÖ·£¬£¬£¬£¬£¬ÏêϸÏÂÁîΪshow ip interface brief
ÈçÉÏÏÖÔÚ2¿ÚΪÄÚÍø¿Ú£¬£¬£¬£¬£¬7¿ÚΪÍâÍø¿ÚµØÖ·£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÕâÁ½¸ö½Ó¿ÚµÇ¼װ±¸£¬£¬£¬£¬£¬ÍâÍøÓû§Ö»ÄÜͨ¹ýÍâÍø¿ÚµØÖ·µÇ¼װ±¸
b¡¢ÏëҪȷÈÏÍâÍø¿ÚµØÖ·£¬£¬£¬£¬£¬Ò²¿ÉÒÔͨ¹ýÄÚÍø¿ÚÏȵǼװ±¸ºó£¬£¬£¬£¬£¬È»ºóÔÙÉó²é¶ÔÓ¦µÄÍâÍø¿ÚµØÖ·£¬£¬£¬£¬£¬
·¾¶£ºÍøÂç—½Ó¿ÚÉèÖ×¶ÔÓ¦ÍâÍø¿Ú
Ôö²¹£ºtelnetµÄ¶Ë¿ÚĬÒÔΪ23£¬£¬£¬£¬£¬telnet ¶Ë¿ÚÊÇÎÞ·¨Ð޸ĵÄ
°ì·¨2¡¢ÅŲé×°±¸ÉÏÇå¾²ÏÞÖÆ£¬£¬£¬£¬£¬Õ¥È¡µÇ¼£¬£¬£¬£¬£¬ACL¹ýÂË
1. ÍâµØ·À¹¥»÷ÉèÖÃեȡtelnetµÇ¼²Ù×÷£¬£¬£¬£¬£¬Ïêϸ·¾¶ÎªÇå¾²—ÍâµØ·À¹¥»÷—եȡÄÚÍø/ÍâÍøµÇ¼װ±¸
¶ÔÓ¦ÏÂÁîΪ£º
control-plane
security deny lan-telnet-ssh-----եȡÄÚÍøtelnetºÍsshµÇ¼װ±¸
security deny wan-telnet-ssh-----եȡÍâÍøtelnetºÍsshµÇ¼Éè
2. ÔÚ½Ó¿ÚŲÓûòip session filterŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
a. ½Ó¿Ú»á¼ûÁбíϵÄŲÓ㬣¬£¬£¬£¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
b. Ip session filter Á÷¹ýÂ˲Ù×÷£¬£¬£¬£¬£¬È«¾ÖŲÓ㬣¬£¬£¬£¬È«¾ÖÉúЧ£¬£¬£¬£¬£¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
c. Line vtyÏÂŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄÍø¶Î»á¼û×°±¸£¬£¬£¬£¬£¬µ¼ÖÂÎÞ·¨telnet
ËùŲÓõÄACL161ÐèÒª·ÅͨµÇ¼װ±¸µÄ¶Ë¿Ú»òIPµØÖ·
Ïêϸ·¾¶£ºÇå¾²—ACL»á¼ûÁбí
ÉèÖÃÍ꣬£¬£¬£¬£¬ÏÂÁîÐжÔӦϷ¢µÄÏÂÁîÈçÏ£º
°ì·¨3¡¢ÅŲéÓ³É䵼ֵǼ¶Ë¿Ú±»Õ¼ÓÃ
ÏêϸÉèÖÃÈçÏ£ºÄÚÍø·þÎñÆ÷Ó³ÉäʱӳÉäµ½×°±¸µÇ¼¶Ë¿ÚºÃ±È˵23£¬£¬£¬£¬£¬»òÕßÊÇÉèÖÃÁËÕû»úÓ³ÉäÓ³Éäµ½½Ó¿ÚÉÏ£¬£¬£¬£¬£¬µ¼ÖÂ×°±¸µÇ¼¶Ë¿Ú±»Õ¼Ó㬣¬£¬£¬£¬»áµ¼ÖÂ×°±¸ÎÞ·¨µÇ¼£¬£¬£¬£¬£¬
a. ¶Ë¿ÚÓ³ÉäÉèÖÃ
¶ÔÓ¦ÏÂÁîÈçÏ£º
ip nat inside source static tcp 192.168.1.10 23 172.18.161.111 23
b. Õû»úÓ³ÉäÉèÖÃ
¶ÔÓ¦ÏÂÁîÈçÏ£º
ip nat inside source static 192.168.1.10 172.18.161.111 permit-inside
½â¾öÒªÁ죺½«ÍâÍøÓ³Éä¶Ë¿Ú23Ó³ÉäΪ1023µÈ¶Ë¿Ú£¬£¬£¬£¬£¬×èÖ¹¶Ë¿ÚÕ¼ÓÃÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£
°ì·¨4¡¢ÅŲé¶àÌõÍâÍøÏßµÄÇéÐÎÏÂûÓпªÆôÔ´½øÔ´³ö
¶àÌõÍâÍøÏßµÄÇéÐÎÏÂûÓпªÆôÔ´½øÔ´³ö£¬£¬£¬£¬£¬µ¼ÖÂÍâÍø»á¼ûµ½×°±¸µÄÊý¾ÝÁ÷·ºÆð´Ó½Ó¿Ú7½øÀ´¿ÉÊÇ´Ó½Ó¿Ú6³öÈ¥ÁË¡£¡£¡£¡£¡£¡£¡£¡£ÒÔÊÇÔÚÍâÍø¿ÚÐèÒª¿ªÆôÔ´½øÔ´³ö
Ïêϸ·¾¶ÈçÏ£ºÍøÂç—½Ó¿ÚÉèÖ×¶ÔÓ¦½Ó¿ÚϹ´Ñ¡Ô´½øÔ´³ö
¶ÔÓ¦µÄÏÂÁîÈçÏ£º
°ì·¨5¡¢ÅŲé·þÎñÊÇ·ñÆôÓûòÕßÊÇ·ñ±£´æweb°ü
1¡¢µÇ¼·þÎñûÓпªÆô
ÏêϸÏÂÁÉó²ételnetÊÇ·ñ¿ªÆô——show service
2¡¢Éó²é¶Ë¿ÚÊÇ·ñÕý³£¼àÌý
£¨1£©Show tcp connect £¬£¬£¬£¬£¬LISTEN´ú±í¼àÌý״̬ÊôÓÚÕý³£×´Ì¬

°ì·¨6¡¢VTYÏ̱߳»Õ¼Âú
¿ÉÒÔͨ¹ýshow usersÉó²évtyÕ¼ÓõÄÏß³ÌÊÇ·ñÂúÁË£¬£¬£¬£¬£¬Ä¬ÈÏÊÇ5¸öÏ̡߳£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔͨ¹ýclear line vty ¶ÔÓ¦ÊýÖµ¾ÙÐÐÏß³Ìɨ³ý£¬£¬£¬£¬£¬ÔÙʵÑéµÇ¼¡£¡£¡£¡£¡£¡£¡£¡£
Õ÷Ïó3£ºSSHÎÞ·¨µÇ¼
°ì·¨1¡¢ÅŲéµÇ¼²ÎÊýÉèÖ㨵ØÖ·¡¢¶Ë¿Ú£©
1¡¢µÇ¼µØÖ·¹ýʧ
a. consoleÏߵǼ¿ÉÒÔÉó²é½Ó¿ÚµØÖ·£¬£¬£¬£¬£¬ÏêϸÏÂÁîΪshow ip interface brief
ÈçÉÏÏÖÔÚ2¿ÚΪÄÚÍø¿Ú£¬£¬£¬£¬£¬7¿ÚΪÍâÍø¿ÚµØÖ·£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÕâÁ½¸ö½Ó¿ÚµÇ¼װ±¸£¬£¬£¬£¬£¬ÍâÍøÓû§Ö»ÄÜͨ¹ýÍâÍø¿ÚµØÖ·µÇ¼װ±¸
b¡¢ÏëҪȷÈÏÍâÍø¿ÚµØÖ·£¬£¬£¬£¬£¬Ò²¿ÉÒÔͨ¹ýÄÚÍø¿ÚÏȵǼװ±¸ºó£¬£¬£¬£¬£¬È»ºóÔÙÉó²é¶ÔÓ¦µÄÍâÍø¿ÚµØÖ·£¬£¬£¬£¬£¬Â·¾¶£ºÍøÂç—½Ó¿ÚÉèÖ×¶ÔÓ¦ÍâÍø¿Ú
¡¾Ôö²¹¡¿£ºSSHµÇ¼¶Ë¿ÚĬÒÔΪ22£¬£¬£¬£¬£¬SSHµÄ¶Ë¿ÚÊÇÎÞ·¨Ð޸ĵÄ
2¡¢SSH·þÎñÐèÒª¿ªÆô
¸Ã¹¦Ð§Ä¿½ñÖ»Ö§³ÖÏÂÁÆô£¬£¬£¬£¬£¬²»Ö§³Öweb¿ªÆô
Ruijie(config)#enable service ssh-server //¿ªÆôSSH·þÎñ
Ruijie(config)#crypto key generate dsa //¼ÓÃÜ·½·¨ÓÐÁ½ÖÖ£ºDSAºÍRSA,¿ÉÒÔËæÒâÑ¡Ôñ
Choose the size of the key modulus in the range of 360 to 2048 for your
Signature Keys. Choosing a key modulus greater than 512 may take a few minutes.
How many bits in the modulus [512]://Ö±½ÓÇûسµ
% Generating 512 bit DSA keys ...[ok]
°ì·¨2¡¢ÅŲé×°±¸ÉÏÇå¾²ÏÞÖÆ£¬£¬£¬£¬£¬Õ¥È¡µÇ¼£¬£¬£¬£¬£¬ACL¹ýÂË
1¡¢ÍâµØ·À¹¥»÷ÉèÖÃեȡsshµÇ¼µÈ²Ù×÷£¬£¬£¬£¬£¬Ïêϸ·¾¶ÎªÇå¾²—ÍâµØ·À¹¥»÷—եȡÄÚÍø/ÍâÍøµÇ¼װ±¸
¶ÔÓ¦ÏÂÁîΪ£º
control-plane
security deny lan-telnet-ssh-----եȡÄÚÍøtelnetºÍsshµÇ¼װ±¸
security deny wan-telnet-ssh-----եȡÍâÍøtelnetºÍsshµÇ¼װ±¸
2¡¢ÔÚ½Ó¿ÚŲÓûòip session filterŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
a. ½Ó¿Ú»á¼ûÁбíϵÄŲÓ㬣¬£¬£¬£¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
2¡¢ Ip session filter Á÷¹ýÂ˲Ù×÷£¬£¬£¬£¬£¬È«¾ÖŲÓ㬣¬£¬£¬£¬È«¾ÖÉúЧ£¬£¬£¬£¬£¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
3¡¢ Line vtyÏÂŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄÍø¶Î»á¼û×°±¸£¬£¬£¬£¬£¬µ¼ÖÂÎÞ·¨telnet

ËùŲÓõÄACL161ÐèÒª·ÅͨµÇ¼װ±¸µÄ¶Ë¿Ú»òIPµØÖ·
Ïêϸ·¾¶£ºÇå¾²—ACL»á¼ûÁбí
ÉèÖÃÍ꣬£¬£¬£¬£¬ÏÂÁîÐжÔӦϷ¢µÄÏÂÁîÈçÏ£º
°ì·¨3¡¢ÅŲéÓ³É䵼ֵǼ¶Ë¿Ú±»Õ¼ÓÃ
ÏêϸÉèÖãºÄÚÍø·þÎñÆ÷Ó³ÉäʱӳÉäµ½×°±¸µÇ¼¶Ë¿ÚºÃ±È˵22£¬£¬£¬£¬£¬»òÕßÊÇÉèÖÃÁËÕû»úÓ³ÉäÓ³Éäµ½½Ó¿ÚÉÏ£¬£¬£¬£¬£¬µ¼ÖÂ×°±¸µÇ¼¶Ë¿Ú±»Õ¼Ó㬣¬£¬£¬£¬»áµ¼ÖÂ×°±¸ÎÞ·¨µÇ¼£¬£¬£¬£¬£¬
1¡¢¶Ë¿ÚÓ³ÉäÉèÖÃ
¶ÔÓ¦ÏÂÁîÈçÏ£ºip nat inside source static tcp 192.168.1.10 22 172.18.161.111 22
2. Õû»úÓ³ÉäÉèÖÃ
¶ÔÓ¦ÏÂÁîÈçÏ£ºip nat inside source static 192.168.1.10 172.18.161.111 permit-inside
½â¾öÒªÁ죺½«ÍâÍøÓ³Éä¶Ë¿Ú22Ó³ÉäΪ1022¶Ë¿Ú£¬£¬£¬£¬£¬×èÖ¹¶Ë¿ÚÕ¼ÓÃÎÊÌâ
°ì·¨4¡¢ÅŲé¶àÌõÍâÍøÏßµÄÇéÐÎÏÂûÓпªÆôÔ´½øÔ´³ö
¶àÌõÍâÍøÏßµÄÇéÐÎÏÂûÓпªÆôÔ´½øÔ´³ö£¬£¬£¬£¬£¬µ¼ÖÂÍâÍø»á¼ûµ½×°±¸µÄÊý¾ÝÁ÷·ºÆð´Ó½Ó¿Ú7½øÀ´¿ÉÊÇ´Ó½Ó¿Ú6³öÈ¥ÁË¡£¡£¡£¡£¡£¡£¡£¡£
ÒÔÊÇÔÚÍâÍø¿ÚÐèÒª¿ªÆôÔ´½øÔ´³ö£¬£¬£¬£¬£¬
Ïêϸ·¾¶£ºÍøÂç—½Ó¿ÚÉèÖ×¶ÔÓ¦½Ó¿ÚϹ´Ñ¡Ô´½øÔ´³ö
¶ÔÓ¦µÄÏÂÁîÈçÏ£º
°ì·¨5¡¢ÅŲé·þÎñÊÇ·ñÆôÓûòÕßÊÇ·ñ±£´æweb°ü
1¡¢µÇ¼·þÎñûÓпªÆô£¬£¬£¬£¬£¬
ÏêϸÏÂÁÉó²ételnet»òSSHÊÇ·ñ¿ªÆô——show service
2¡¢Éó²é¶Ë¿ÚÊÇ·ñÕý³£¼àÌý
show tcp connect £¬£¬£¬£¬£¬LISTEN´ú±í¼àÌý״̬ÊôÓÚÕý³£×´Ì¬
°ì·¨6¡¢VTYÏ̱߳»Õ¼Âú
¿ÉÒÔͨ¹ýshow usersÉó²évtyÕ¼ÓõÄÏß³ÌÊÇ·ñÂúÁË£¬£¬£¬£¬£¬Ä¬ÈÏÊÇ5¸öÏ̡߳£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔͨ¹ýclear line vty ¶ÔÓ¦ÊýÖµ¾ÙÐÐÏß³Ìɨ³ý£¬£¬£¬£¬£¬ÔÙʵÑéµÇ¼¡£¡£¡£¡£¡£¡£¡£¡£
Îå¡¢ÐÅÏ¢ÍøÂç
×¢ÖØ£ºÒÔÏÂÏÂÁîÊÊÓÃÓÚtelnet¡¢sshÎÞ·¨µÇ¼£¬£¬£¬£¬£¬µ«ÉèÖÿڿÉÒԵǼµÄÇéÐΣ¬£¬£¬£¬£¬ÈôÉèÖÿÚÒ²ÎÞ·¨µÇ¼£¬£¬£¬£¬£¬ÇëʵʱÁªÏµ400¹¤³Ìʦ´¦Öóͷ£¡£¡£¡£¡£¡£¡£¡£¡£
sh ver
sh run
sh service
sh users
sh int usage
sh tcp connect
sh memory
sh cpu | ex 0.00
sh log rev
show int usage
sh envir
sh ip fpm sta
debug su
execute diagnose-cmd fdisk
execute diagnose-cmd mount
exit
Áù¡¢×ܽáÓ뽨Òé
µ±µçÄÔÎÞ·¨¹ÜÀí×°±¸£¬£¬£¬£¬£¬½¨ÒéÓÅÏȼì²éSESSION FILTERŲÓõÄACLÊÇ·ñ¾ÙÐÐÁËÏÞÖÆ¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊÇûÓÐÏÞÖÆ£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýshow usersºÍshow ip fpm flow | in ²âÊÔµçÄÔIP£¬£¬£¬£¬£¬À´ÅжÏÊý¾ÝÊÇ·ñµ½µÖ´ïEG¡£¡£¡£¡£¡£¡£¡£¡£
¡¾Ôö²¹¡¿Èçδ½â¾ö»òÐèÒªÏàʶ¸ü¶àÏêÇ飬£¬£¬£¬£¬¿Éµã»÷ÊÛºóÉÁµçÍþÙÐÐ×Éѯ