<?xml version="1.0" encoding="GBK"?>
<rss version="2.0" >
<channel> <title><![CDATA[51CTO技术博客-领先的IT技术博客]]></title>
 <link><![CDATA[http://blog.51cto.com]]></link>
 <description><![CDATA[Latest 20 blogs of edwardlee]]></description>
 <copyright><![CDATA[Copyright(C) 51CTO技术博客-领先的IT技术博客]]></copyright>
 <generator><![CDATA[51CTO BLOG by 51CTO Studio]]></generator>
 <lastBuildDate><![CDATA[Wed, 10 Feb 2010 01:22:14 +0000]]></lastBuildDate>
  <image>
 <url><![CDATA[http://img1.51cto.com/image/skin/1/rss.gif]]></url>
 <title><![CDATA[51CTO BLOG]]></title>
 <link><![CDATA[http://blog.51cto.com]]></link>
 <description><![CDATA[51CTO技术博客-领先的IT技术博客]]></description>
  </image>
<item>
 <title><![CDATA[Cisco ASA 5510 and Squid with WCCPv2]]></title>
 <description><![CDATA[<div>Environment:</div>
<div>Squid server: Ubuntu 8.10 Server Edition&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; IP Address:192.168.50.100/24<br />ASA5510:&nbsp; &nbsp;E0/1 inside&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; IP Address:192.168.50.1/24<br />Local Network:&nbsp;&nbsp;&nbsp;&nbsp; 10.1.0.0/16</div>
<div>&nbsp;</div>
<div>1. ASA WCCP Configuration<br />ASAconfig)#access-list PROXY extended permit 10.1.0.0 255.255.0.0 any eq www<br />ASAconfig)# wccp web-cache redirect-list PROXY<br />ASA(config)# wccp interface inside web-cache redirect in</div>
<div>&nbsp;</div>
<div>2. Squid Installation<br /><a href="mailto:root@ubuntu-squid">root@ubuntu-squid</a>:~# apt-get install squid<br /><a href="mailto:root@ubuntu-squid">root@ubuntu-squid</a>:~# vi /etc/squid/squid.conf<br />http_port 3128 transparent<br />wccp2_router 192.168.50.1</div>
<div>wccp2_forwarding_method 1<br />wccp2_return_method 1<br />wccp2_assignment_method 1<br />acl all src 0.0.0.0/0.0.0.0<br />http_access allow all<br />cache_mem 256MB<br />cache_dir ufs /var/spool/squid 10240 16 256</div>
<div>&nbsp;</div>
<div>3. Linux Server Configuration<br /><a href="mailto:root@ubuntu-squid">root@ubuntu-squid</a>:~# vi /etc/rc.local<br />#setup gre tunnel to ASA. Remote is the WCCP route identifier and local is the ip address of Squid<br />ip tunnel add&nbsp;wccp0 mode gre remote 192.168.50.1 local 192.168.50.100 dev eth0<br />ifconfig&nbsp;wccp0 inet 127.0.0.3 netmask 255.255.255.255 up</div>
<div>echo 1 &gt; /proc/sys/net/ipv4/ip_forward<br />echo 0 &gt; /proc/sys/net/ipv4/conf/wccp0/rp_filter<br />iptables -F -t nat<br />iptables -t nat -A PREROUTING -i&nbsp;wccp0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.50.100:3128</div>
<div>&nbsp;</div>
<div>4. Verify Configuration<br />ASA# sh wccp</div>
<div>Global WCCP information:<br />&nbsp;&nbsp;&nbsp; Router information:<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Router Identifier:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 192.168.50.1<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Protocol Version:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2.0</div>
<div>&nbsp;&nbsp;&nbsp; Service Identifier: web-cache<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Number of Cache Engines:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Number of routers:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Total Packets Redirected:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 7611<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Redirect access-list:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; PROXY</div>
<div><a href="mailto:root@ubuntu-squid">root@ubuntu-squid</a>:~# tail /var/log/squid/access.log<br />1246847635.924&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2 10.1.254.115 TCP_IMS_HIT/304 445 GET <a href="http://wiki.squid-cache.org/wiki/squidtheme/css/screen.css">http://wiki.squid-cache.org/wiki/squidtheme/css/screen.css</a> - NONE/- text/css<br />1246847635.927&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2 10.1.254.115 TCP_IMS_HIT/304 444 GET <a href="http://wiki.squid-cache.org/wiki/squidtheme/css/print.css">http://wiki.squid-cache.org/wiki/squidtheme/css/print.css</a> - NONE/- text/css</div>
<div>&nbsp;</div>
<div>5. Related Information<br /><a href="http://wiki.squid-cache.org/ConfigExamples/NatAndWccp2">http://wiki.squid-cache.org/ConfigExamples/NatAndWccp2</a></div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/174541]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[路由交换]]></category>
 <pubdate><![CDATA[Mon, 06 Jul 2009 13:10:47 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[Cisco Nexus 1000V安装指南]]></title>
 <description><![CDATA[<div class=MsoNormal style="margin: 0cm 0cm 0pt"><font size="3"><span lang=EN-US>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Nexus 1000V是Cisco推出的第一款纯软件的虚拟交换机产品，可以在VMware虚拟化环境中提供Cisco Catalyst交换机的功能，如QoS、ACL、SPAN等。</span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><font size="3"><span lang=EN-US>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Cisco Nexus 1000V</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>包含</span><span lang=EN-US>VEM</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>和</span><span lang=EN-US>VSM</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>两部分，其中</span><span lang=EN-US>VEM</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>运行在</span><span lang=EN-US>ESXi</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>服务器上取代VMware原有的虚拟交换机，</span><span lang=EN-US>VSM是一个单独运行的虚拟机，提供CLI接口，</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>用于管理和配置整个虚拟交换机。</span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><font size="3"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times></span></font>&nbsp;</div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=EN-US></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=EN-US><?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p><font size="3"><img onclick='window.open(this.src)' style="width: 370px; height: 189px" onclick=window.open(this.src) height="241" alt="" src="http://blog.51cto.com/attachment/200906/200906111244706048871.jpg" width="423" border="0" />&nbsp;</font></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><font size="3"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=EN-US><o:p><font size="3">&nbsp;</font></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=EN-US><o:p></o:p></span><font size="3"><span lang=EN-US>Cisco Nexus 1000V</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>的具体安装步骤如下：</span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><font size="3"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times></span></font>&nbsp;</div><font size="3"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times><font size="3">安装环境：</font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=EN-US><font size="3">ESXi 4.0 x 1<span style="mso-tab-count: 5">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span>ip address:<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>192.168.0.10</font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=EN-US><font size="3">vCenter Server x 1<span style="mso-tab-count: 4">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span>ip address:<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>192.168.0.20</font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=EN-US><font size="3">vSphere Client and RCLI x 1<span style="mso-tab-count: 2">&nbsp;&nbsp;&nbsp;</span>ip address:<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>192.168.0.30</font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><font size="3"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>（</span><span lang=EN-US>Cisco Nexus 1000V<span style="mso-tab-count: 3">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span>management ip</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>：</span><span lang=EN-US> 192.168.0.50</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>）</span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><font size="3"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times></span></font>&nbsp;</div></span></font>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span lang=EN-US style="mso-fareast-font-family: " Roman? New Times><span style="mso-list: ignore"><font size="3">1、</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman? New Times>&nbsp; </span></span></span><font size="3"><span dir="ltr"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>从</span><span lang=EN-US>www.cisco.com</span></span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>下载</span><span lang=EN-US>Nexus 1000V</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>安装包，将安装包解压得到</span><span lang=EN-US>VSM</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>和</span><span lang=EN-US>VEM</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>安装程序。</span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=EN-US><a href="http://tools.cisco.com/support/downloads/pub/Redirect.x?mdfid=282362725"><font color="#800080" size="3">http://tools.cisco.com/support/downloads/pub/Redirect.x?mdfid=282362725</font></a></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=EN-US><o:p><font size="3">&nbsp;</font></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span lang=EN-US style="mso-fareast-font-family: " Roman? New Times><span style="mso-list: ignore"><font size="3">2、</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman? New Times>&nbsp; </span></span></span><font size="3"><span dir="ltr"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>在</span><span lang=EN-US>ESXi</span></span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>服务器上安装并验证</span><span lang=EN-US>VEM</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>。</span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><font size="3"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>将</span><span lang=EN-US>VEM</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>目录中的</span><span lang=EN-US>cisco-vem-v100-4.0.4.1.1.27-0.4.2.zip</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>复制到</span><span lang=EN-US>C:\Program Files\VMware\VMware vSphere CLI\bin\ </span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>目录中，选择开始菜单中的</span><span lang=EN-US>All programs &gt; VMware &gt;VMware vSphere CLI &gt; Command Prompt</span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=DE style="mso-ansi-language: de"><font size="3">C:\Program Files\VMware\VMware vSphere CLI&gt;cd bin<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=DE style="mso-ansi-language: de"><font size="3">C:\Program Files\VMware\VMware vSphere CLI\bin&gt;vihostupdate.pl -i -b cisco-vem-v100-4.0.4.1.1.27-0.4.2.zip --server 192.168.0.20<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=DE style="mso-ansi-language: de"><font size="3">C:\Program Files\VMware\VMware vSphere CLI\bin&gt;vihostupdate.pl -q --server 192.168.0.20<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=DE style="mso-ansi-language: de"><o:p><font size="3">&nbsp;</font></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span lang=DE style="mso-fareast-font-family: " New Roman?; Times DE mso-ansi-language:><span style="mso-list: ignore"><font size="3">3、</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman? New Times>&nbsp; </span></span></span><font size="3"><span dir="ltr"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>在</span></span><span lang=DE style="mso-ansi-language: de">vSphere Client</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>中</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times DE mso-ansi-language:>，</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>选择</span><span lang=DE style="mso-ansi-language: de">File &gt; Deploy OVF Template</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times DE mso-ansi-language:>，</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>选中</span><span lang=DE style="mso-ansi-language: de">VSM</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>目录中的</span><span lang=DE style="mso-ansi-language: de">Nexus1000v-4.0.4.SV1.1.ova</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times DE mso-ansi-language:>，</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>导入</span><span lang=DE style="mso-ansi-language: de">VSM</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>虚拟机。</span><span lang=DE style="mso-ansi-language: de"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span lang=EN-US style="mso-fareast-font-family: " Roman? New Times><span style="mso-list: ignore"><font size="3">4、</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman? New Times>&nbsp; </span></span></span><font size="3"><span dir="ltr"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>启动虚拟机，选择安装</span><span lang=EN-US>Nexus 1000V</span></span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>，</span><span lang=EN-US>HA</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>模式设定为</span><span lang=EN-US>standalone</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>，定义管理地址及网关。</span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span lang=EN-US style="mso-fareast-font-family: " Roman? New Times><span style="mso-list: ignore"><font size="3">5、</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman? New Times>&nbsp; </span></span></span><font size="3"><span dir="ltr"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>查看虚拟机的</span><span lang=EN-US>host-id</span></span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>，并根据此id</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>在</span><span lang=EN-US><a href="http://www.cisco.com">www.cisco.com</a></span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>上申请</span><span lang=EN-US>60</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>天试用</span><span lang=EN-US>License</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>。</span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt"><span lang=EN-US><font size="3">#show license host-id</font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span lang=EN-US style="mso-fareast-font-family: " Roman? New Times><span style="mso-list: ignore"><font size="3">6、</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman? New Times>&nbsp; </span></span></span><font size="3"><span dir="ltr"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>将下载的</span><span lang=EN-US>License</span></span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>文件放在</span><span lang=EN-US>TFTP</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>服务器，并上传到虚拟机的</span><span lang=EN-US>bootflash</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>中。</span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: 3pt"><span lang=EN-US><font size="3">#copy tftp://192.168.0.30/cisco.lic bootflash:</font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=EN-US><font size="3"><span style="mso-spacerun: yes">&nbsp;&nbsp; </span><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp; </span>#install license bootflash:cisco.lic</font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=EN-US><font size="3"><span style="mso-spacerun: yes">&nbsp;&nbsp; </span><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp; </span>#show license usage</font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=EN-US><font size="3"><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>#copy run start</font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span lang=EN-US style="mso-fareast-font-family: " Roman? New Times><span style="mso-list: ignore"><font size="3">7、</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman? New Times>&nbsp; </span></span></span><font size="3"><span dir="ltr"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>在</span><span lang=EN-US>vCenter Server</span></span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>上安装</span><span lang=EN-US>Cisco Nexus 1000V Plug-in</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>。</span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt"><font size="3"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>用浏览器打开虚拟机管理地址</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>，</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>如</span><span lang=EN-US><a href="http://192.168.0.50/"><span lang=FR style="mso-ansi-language: fr">http://192.168.0.50</span></a></span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>，</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>下载</span></font><span lang=FR style="font-size: 10pt; font-family: times-bold; mso-ansi-language: fr; mso-font-kerning: 0pt; mso-bidi-font-family: times-bold">cisco_nexus1000v_extension.xml</span><span style="font-size: 10pt; font-family: 宋体; mso-ascii-font-family: times-bold; mso-ansi-language: fr; mso-font-kerning: 0pt; mso-bidi-font-family: times-bold; mso-hansi-font-family: times-bold">，</span><span style="font-size: 10pt; font-family: 宋体; mso-ascii-font-family: times-bold; mso-font-kerning: 0pt; mso-bidi-font-family: times-bold; mso-hansi-font-family: times-bold">在</span><font size="3"><span lang=FR style="mso-ansi-language: fr">vSphere Client</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>中选择</span><span lang=FR style="mso-ansi-language: fr">Manage Plug-in</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>，右键点击空白处选择新建</span><span lang=FR style="mso-ansi-language: fr">Plug-in</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>，选择下载的</span><span lang=FR style="mso-ansi-language: fr">xml</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>文件并点击注册。如果注册失败，可以删除此plug-in然后重新尝试注册，具体方法见如下的Nexus 1000V安装故障解决指南</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>。</span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt"><font size="3"><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR></span><span lang=FR style="mso-ansi-language: fr"><o:p><font face=宋体><a href="http://www.cisco.com/en/US/docs/switches/datacenter/nexus1000/sw/4_0/troubleshooting/configuration/guide/trouble_3install.html#wp1197079">http://www.cisco.com/en/US/docs/switches/datacenter/nexus1000/sw/4_0/troubleshooting/configuration/guide/trouble_3install.html#wp1197079</a></font></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span lang=FR style="mso-fareast-font-family: " New Roman?; Times mso-ansi-language: FR><span style="mso-list: ignore"><font size="3">8、</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman? New Times>&nbsp; </span></span></span><font size="3"><span dir="ltr"><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>从</span></span><span lang=FR style="mso-ansi-language: fr">VSM</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>虚拟机连接</span><span lang=FR style="mso-ansi-language: fr">vCenter Server</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>，如果连接失败通常是第</span><span lang=FR style="mso-ansi-language: fr">6</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>步没有成功注册</span><span lang=FR style="mso-ansi-language: fr">Plug-in</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>。</span><span lang=FR style="mso-ansi-language: fr"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-indent: 18pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">config t<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-indent: 18pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">svs connection VC<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-indent: 18pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v((config-svs-conn)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">vmware dvs datacenter-name DC-1<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-indent: 18pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v((config-svs-conn)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">protocol vmware-vim<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v((config-svs-conn)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">remote ip address 192.168.0.20<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-svs-conn)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">connect<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">show svs connections<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span lang=FR style="mso-fareast-font-family: " New Roman?; Times mso-ansi-language: FR><span style="mso-list: ignore"><font size="3">9、</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman? New Times>&nbsp; </span></span></span><font size="3"><span dir="ltr"><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>定义</span></span><span lang=FR style="mso-ansi-language: fr">VSM</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>和</span><span lang=FR style="mso-ansi-language: fr">VEM</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>通讯使用的</span><span lang=FR style="mso-ansi-language: fr">Port Profile</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>。</span><span lang=FR style="mso-ansi-language: fr"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">port-profile system-uplink<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=FR style="font-size: 8pt; font-family: courier; mso-ansi-language: fr; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=FR style="font-size: 8pt; font-family: courier-bold; mso-ansi-language: fr; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">switchport mode trunk<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">switchport trunk allowed vlan 1<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">no shut<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">system vlan 1<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=FR style="font-size: 8pt; font-family: courier; mso-ansi-language: fr; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=FR style="font-size: 8pt; font-family: courier-bold; mso-ansi-language: fr; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">vmware port-group<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">capability uplink<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">state enabled<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span lang=FR style="mso-fareast-font-family: " New Roman?; Times mso-ansi-language: FR><span style="mso-list: ignore"><font size="3">10、</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman? New Times>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><font size="3"><span dir="ltr"><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>定义其他虚拟机数据和上联通讯的</span></span><span lang=FR style="mso-ansi-language: fr">Port Profile</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>。</span><span lang=FR style="mso-ansi-language: fr"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v$ </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">config t<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">port-profile vm-uplink<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=FR style="font-size: 8pt; font-family: courier; mso-ansi-language: fr; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=FR style="font-size: 8pt; font-family: courier-bold; mso-ansi-language: fr; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">switchport mode access<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">capability uplink<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">switchport access vlan 262<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">vmware port-group<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">no shut<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">state enabled<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold"><o:p>&nbsp;</o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=FR style="font-size: 8pt; font-family: courier; mso-ansi-language: fr; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config)# </span><b><span lang=FR style="font-size: 8pt; font-family: courier-bold; mso-ansi-language: fr; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">port-profile data262<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=FR style="font-size: 8pt; font-family: courier; mso-ansi-language: fr; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=FR style="font-size: 8pt; font-family: courier-bold; mso-ansi-language: fr; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">switchport mode access<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">switchport access vlan 262<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">vmware port-group data262<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">no shut<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">state enabled<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">n1000v(config-port-prof)# </span><b><span lang=EN-US style="font-size: 8pt; font-family: courier-bold; mso-font-kerning: 0pt; mso-bidi-font-family: courier-bold">copy run start<o:p></o:p></span></b></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier">[########################################]<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier"><o:p>&nbsp;</o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span lang=EN-US style="mso-fareast-font-family: " Roman? New Times><span style="mso-list: ignore"><font size="3">11、</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman? New Times>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><font size="3"><span dir="ltr"><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>完成上述步骤后就可以在</span><span lang=EN-US>vSphere Client</span></span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>中的</span><span lang=EN-US>Inventory &gt; Networking</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>中看到</span><span lang=EN-US>Nexus 1000V</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>，</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>在</span><span lang=EN-US>Nexus 1000V</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>上点右键</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>，</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>选择</span><span lang=EN-US>add host</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>，</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>把</span><span lang=EN-US>ESXi</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>主机添加到分布式虚拟交换机</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>（</span><span lang=EN-US>DVS</span><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times>）</span><span style="font-family: 宋体; mso-ascii-font-family: " New ?Times mso-hansi-font-family: Roman?; Times mso-ansi-language: FR>。</span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span lang=EN-US style="mso-fareast-font-family: " Roman? New Times><span style="mso-list: ignore"><font size="3">12、</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman? New Times>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span dir="ltr"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times><font size="3">验证安装是否成功</font></span></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span dir="ltr"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times><font size="3">n1000v# <strong>show module</strong></font></span></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier"><font size="3">Mod Ports Module-Type Model Status<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier"><font size="3">--- ----- -------------------------------- ------------------ ------------<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-align: left; mso-layout-grid-align: none" align="left"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier"><font size="3">1 0 Virtual Supervisor Module Nexus1000V active *<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier"><font size="3">3 248 Virtual Ethernet Module NA ok<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=EN-US style="font-size: 8pt; font-family: courier; mso-font-kerning: 0pt; mso-bidi-font-family: courier"><o:p>&nbsp;</o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span style="font-family: 宋体; mso-ascii-font-family: " Roman? New ?Times mso-hansi-font-family: Roman?; Times><font size="3">参考资料：</font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt"><span lang=EN-US><font size="3">http://www.cisco.com/en/US/products/ps9902/prod_installation_guides_list.html</font></span></div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/165941]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[路由交换]]></category>
 <pubdate><![CDATA[Thu, 11 Jun 2009 15:44:27 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[ISO27001 Study Note I]]></title>
 <description><![CDATA[<div>1. Three aspects of information security:<br />Confidentiality<br />Integrity<br />Availability</div>
<div>&nbsp;</div>
<div>2. ISO PDCA Model:<br />Plan - Establish the ISMS<br />Do - Implement and Operate the ISMS<br />Check - Monitor and Review ISMS<br />Act - Maintain and Improve ISMS</div>
<div>&nbsp;</div>
<div>3. Risk<br />Assessing security risks<br />Treating security risks<br />Risk Priority Number (RPN) = Severity x Occurrence x weakness</div>
<div>&nbsp;</div>
<div>4. The ISMS documentation:<br />Statement of ISMS Policy<br />Control of documents<br />Control of records<br />Risk assessment and treatment plan<br />Internal ISMS audits<br />Management Review of the ISMS<br />Corrective and Preventive actions</div>
<div>&nbsp;</div>
<div>5. Audit findings:<br />Noteworthy efforts<br />Observations<br />Non-conformities</div>
<div>&nbsp;</div>
<div>Annex A: Control Objectives and controls:<br />5. Information security policy<br />6. Organization of information security<br />7. asset management<br />8. human resources security<br />9. Physical and environment security<br />10. communications and operations management<br />11. access control<br />12. information systems acquisition, development and maintenance<br />13. management of information security incidents and improvement<br />14. Business continuity management<br />15. Compliance</div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/165473]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[安 全]]></category>
 <pubdate><![CDATA[Wed, 10 Jun 2009 13:23:49 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[VMware ESXi 4.0升级指南]]></title>
 <description><![CDATA[<div>&nbsp;&nbsp;&nbsp; VMware上个月发布了免费版的ESXi 4.0版，真是广大中小企业用户的福音，呵呵。VMware此次发布了全新安装的ISO镜像及从ESXi 3.5到4.0的升级包。在官方的说明中，升级包需要配合vCenter Update Manager使用，下面我们给大家介绍一种无需vCenter Update Manager的简便升级方法。</div>
<div>&nbsp;</div>
<div>1. 首先把ESXi 3.5中的虚拟机关闭，将整个服务器切换为“maintenance mode”。</div>
<div>&nbsp;</div>
<div>2. 下载安装7-zip，用于后面从ESXi 4.0升级包中解压vSphere Client。</div>
<div><a href="http://www.7-zip.org">http://www.7-zip.org</a></div>
<div>&nbsp;</div>
<div>3. 下载安装Microsoft .net framework 3.5 sp1，安装vSphere Client时会自动从网上下载.net 3.0sp1，比较费时间，我是先从微软的网站下载安装了最新的.net 3.5sp1。</div>
<div><a href="http://download.microsoft.com/download/2/0/e/20e90413-712f-438c-988e-fdaa79a8ac3d/dotnetfx35.exe">http://download.microsoft.com/download/2/0/e/20e90413-712f-438c-988e-fdaa79a8ac3d/dotnetfx35.exe</a></div>
<div>&nbsp;</div>
<div>4. 从VMware网站下载ESXi 4.0升级包，需要注册一个帐号才能下载，升级包是一个274M的ZIP文件。</div>
<div><a href="https://www.vmware.com/tryvmware/index.php?p=free-esxi&amp;lp=1">https://www.vmware.com/tryvmware/index.php?p=free-esxi&amp;lp=1</a></div>
<div>&nbsp;</div>
<div>5. 用7-zip打开下载的升级包，解压出viclient安装文件，该文件在压缩包中的路径如下：</div>
<div>(VMware-viclient.vib\data.tar.gz\data.tar\.\4.0.0\client\VMware-viclient.exe) </div>
<div>&nbsp;</div>
<div><img onclick='window.open(this.src)' onclick=window.open(this.src) alt="" src="http://blog.51cto.com/attachment/200906/200906041244121973109.jpg" border="0" /></div>
<div>&nbsp;</div>
<div>6. 安装vSphere Client, 并在安装中选中“install vSphere Host Update Utility 4.0”。</div>
<div>&nbsp;</div>
<div>7. 从开始菜单中运行“vSphere Host Update Utility 4.0”，选中你要升级的ESXi服务器，使用下载的升级包进行升级。</div>
<div><img onclick='window.open(this.src)' onclick=window.open(this.src) alt="" src="http://blog.51cto.com/attachment/200906/200906041244122737484.jpg" border="0" /></div>
<div>&nbsp;</div>
<div>8. 升级过程中ESXi服务器会自动重启，完成后退出维护模式，启动VM测试是否成功。</div>
<div><img onclick='window.open(this.src)' onclick=window.open(this.src) alt="" src="http://blog.51cto.com/attachment/200906/200906041244122904781.jpg" border="0" /></div>
<div>&nbsp;</div>
<div>9.升级完成后有可能需要输入新的License，升级VM中的VMware Tool和虚拟硬件，但由于没有测试我没有执行这些步骤。</div>
<div>&nbsp;</div>
<div>10. ESXi 4.0中增加了许多特性，如采用了64bit架构，单个虚拟机的硬件提高到了8个SMP和256GB内存，支持ipv6等等，与上一版本相比有了较大的飞跃，成为VMware2009年虚拟化架构的重要组成部分。</div>
<div>&nbsp;</div>
<div>参考资料：</div>
<div><a href="http://www.vm-help.com/esx40i/ESXi40_upgrade_without_virtualcenter.php">http://www.vm-help.com/esx40i/ESXi40_upgrade_without_virtualcenter.php</a></div>
<div>&nbsp;</div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/163054]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[服务器&存储]]></category>
 <pubdate><![CDATA[Thu, 04 Jun 2009 22:03:06 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[ESXi中Linux虚拟机LVM扩展实例]]></title>
 <description><![CDATA[<div>LVM是Linux下常用的磁盘管理技术，可以在线的动态扩展逻辑卷的大小，我们以ESXi中的Linux虚拟机为例说明如何使用LVM动态扩展磁盘空间。</div>
<div>1. ESXi中为Linux虚拟机添加第二块硬盘，查看磁盘状态</div>
<div>#fdisk -l</div>
<div>&nbsp;</div>
<div>2. 在新加的硬盘上创建分区，分区类型为8e</div>
<div>#fdisk /dev/sdb</div>
<div>Command (m for help): <strong>new</strong><br />Command action<br />e&nbsp; &nbsp;extended<br />p&nbsp; &nbsp;primary partition (1-4) <strong>p</strong></div>
<div>Partition number (1-4): <strong>1</strong><br />First cylinder (1-512, default <strong>1</strong>):<br />Last cylinder or +size or +sizeM or +sizeK (1-512, default <strong>512</strong>):<br />Command (m for help): <strong>t</strong></div>
<div>Partition's system id: <strong>8e</strong></div>
<div>Command(m for help): <strong>w</strong></div>
<div><strong></strong>&nbsp;</div>
<div>3. 创建物理卷</div>
<div>#pvcreate /dev/sdb</div>
<div>&nbsp;</div>
<div>4 将新建物理卷添加到卷组中</div>
<div>#vgextend&nbsp;vg-1 /dev/sdb</div>
<div>&nbsp;</div>
<div>5. 扩展逻辑卷大小</div>
<div>#lvextend -L+1G /dev/vg-1/home</div>
<div>&nbsp;</div>
<div>6. 扩展文件系统大小</div>
<div>#resize2fs -p /dev/vg-1/home</div>
<div>&nbsp;</div>
<div>7. 查看配置完成后的磁盘空间大小</div>
<div>#df -h</div>
<div>&nbsp;</div>
<div>8. 查看卷组和逻辑卷状态</div>
<div>#vgdisplay</div>
<div>#lvdisplay</div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/162175]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[服务器&存储]]></category>
 <pubdate><![CDATA[Mon, 01 Jun 2009 21:12:21 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[Cisco 安全技术系列之三：ASA5500 ACL配置详解]]></title>
 <description><![CDATA[<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 访问控制列表（ACL）是防火墙配置中最常用的技术之一，下面以Cisco ASA5500为例介绍一下在不同的应用环境中访问控制列表的具体配置。</div>
<div>&nbsp;</div>
<div>1）发布服务器</div>
<div>要将内部服务器发布要公网上，只要配置一个静态NAT和与之对应的ACL就可以，下面是将内部地址192.168.0.100服务器的WWW发布的具体配置，公网地址200.200.200.200。</div>
<div>static (inside,outside) 200.200.200.200 192.168.0.100</div>
<div>access-list OUTSIDE_IN extended permit tcp any host 200.200.200.200 eq www</div>
<div>access-group OUTSIDE_IN in interface outside</div>
<div>&nbsp;</div>
<div>2）基于时间的ACL</div>
<div>ASA5500支持基于时间的ACL，下面的例子将周一到周五工作时间的www流量限制为1Mb/s。</div>
<div>time-range working_time</div>
<div>periodic weekdays 9:00 to 17:00</div>
<div>access-list&nbsp;HTTP extended permit&nbsp;tcp any eq 80 any&nbsp;time-rang working_time</div>
<div>class-map HTTP<br />&nbsp;match port tcp eq www</div>
<div>policy-map&nbsp;HTTP<br />&nbsp;class&nbsp;HTTP<br />&nbsp; police output 1000000 1000</div>
<div>service-policy&nbsp;HTTP interface inside</div>
<div>&nbsp;</div>
<div>3）Lan-to-Lan VPN ACL</div>
<div>基于端口的ACL对于VPN流量是不起作用的，因此需要使用vpn-filter命令来对Lan-to-Lan和Remote AccessVPN流量进行过滤和控制。下面的例子只允许本地10.10.10.0/24网段的PC访问VPN对段192.168.0.100服务器的FTP服务，在这里需要注意ACL中的源地址是指VPN对段的地址。</div>
<div>access-list Filter extended permit tcp host 192.168.0.100 eq&nbsp;ftp&nbsp;10.10.10.0 255.255.255.0</div>
<div>group-policy&nbsp;VPN_1 internal<br />group-policy&nbsp;VPN_1 attributes<br />vpn-filter value Filter</div>
<div>tunnel-group&nbsp;x.x.x.x type ipsec-l2l<br />tunnel-group&nbsp;x.x.x.x general-attributes<br />default-group-policy VPN_1</div>
<div>&nbsp;</div>
<div>4）Remote Access VPN ACL</div>
<div>下面的例子只允许远程接入VPN的客户端访问内部地址为10.10.10.100的服务器。</div>
<div>access-list RAVPN extended permit ip&nbsp;any host 10.10.10.100</div>
<div>group-policy&nbsp;VPN_2 internal</div>
<div>group-policy&nbsp;VPN_2 attributes<br />&nbsp;vpn-filter value RAVPN<br />vpn-tunnel-protocol IPSec </div>
<div>tunnel-group&nbsp;VPN_2 general-attributes<br />&nbsp;default-group-policy VPN_2<br /></div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/160138]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[安 全]]></category>
 <pubdate><![CDATA[Fri, 22 May 2009 21:50:24 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[思科站点间VPN技术比较]]></title>
 <description><![CDATA[<h3><font face=FangSong_GB2312 size="2">思科系统公司&reg;提供了业界特性最为丰富、最灵活的站点间VPN解决方案。思科&reg;站点间VPN解决方案集成了先进的网络智能特性和路由功能，为语音和客户端-服务器应用等复杂的关键任务流量提供了可靠的传输，且对通信质量无影响。这些解决方案以五种底层VPN技术为基础：动态多点VPN (DMVPN)、Easy VPN、GRE隧道、标准IP安全(IPsec)和全新的群组加密传输VPN (GET-VPN)。每种技术都各具优点，专为满足特定部署需求而定制。下面对各项技术进行了比较，并提供了使用它们的准则。</font></h3>
<div><a href="http://www.cisco.com/web/CN/products/products_netsol/routers/solution/isr/solutions/network_routers_white_book_aag.html">http://www.cisco.com/web/CN/products/products_netsol/routers/solution/isr/solutions/network_routers_white_book_aag.html</a></div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/159447]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[安 全]]></category>
 <pubdate><![CDATA[Wed, 20 May 2009 12:03:25 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[Networkers 2009系列之二：Cisco IOS设备管理艺术]]></title>
 <description><![CDATA[<div>Cisco 在IOS设备中提供了DMI特性，可以实现更加灵活和智能的配置管理，下面我们给大家介绍几个既可以提供工作效率，又非常有趣的技术。</div>
<div>1、CLI基础</div>
<div>配置模式下执行EXEC命令: (在命令前加do)</div>
<div>router(config)# <strong><font color="#0000ff">do</font></strong> show run</div>
<div>命令别名:</div>
<div>router(config)# alias exec shib show ip interface brief</div>
<div>router# show aliases</div>
<div>&nbsp;</div>
<div>2、CLI高级技巧</div>
<div>配置回滚：</div>
<div>router# config replace disk0:/config-archive-3 time 10</div>
<div>当远程调试设备时，有可能错误的配置中断连接，上面的命令可以让路由器10分钟后自动恢复flash中保存的正确配置。</div>
<div>&nbsp;</div>
<div>3、TCL脚本</div>
<div>使用noetpad编辑一个文件hello.tcl，然后将文件上传到路由器的flash中。</div>
<div>puts "Hello World"</div>
<div>运行tcl脚本：</div>
<div>Router#tclsh flash:/hello.tcl</div>
<div>&nbsp;</div>
<div>4、EEM事件触发变更 </div>
<div>当收到NTP更新的log，自动执行自定义的一组命令。</div>
<div>event manager applet config_upon_ntp<br />event syslog pattern ".*%NTP-5-PEERSYNC.*"<br />action 1.0 syslog msg "Starting ..."<br />:<br />... Your Config Changes Here ...<br />:<br />action 3.0 syslog msg "... done"</div>
<div>&nbsp;</div>
<div>5、EEM配置变更报警</div>
<div>禁止修改hostname，并记录日志</div>
<div>event manager applet cli-async-skip<br />event cli pattern "hostname *" sync no skip yes<br />action 1.0 syslog msg "Deny to change hostname"</div>
<div>&nbsp;</div>
<div>6、命令行下编辑文件</div>
<div>从<a href="http://www.cisco.com/go/ciscobeyond">www.cisco.com/go/ciscobeyond</a> 下载ed.tcl并上传到路由器flash中，就可以命令行下使用ed编辑简单的文本文件。</div>
<div>router(config)# alias exec ed tclsh flash:/ed.tcl</div>
<div>router# ed flash:/testfile.txt</div>
<div>&nbsp;</div>
<div>7、配置文件归档</div>
<div>每24小时或执行wirte命令时自动将原有配置保存到flash。</div>
<div>archive<br />path disk0:/config-archive<br />maximum 7<br />time-period 1440</div>
<div>write memory</div>
<div>&nbsp;</div>
<div>8、图形化管理-SDM</div>
<div>使用web图形化管理工具SDM配置和监控路由器，思科图形化管理工具一直不太好用，SDM算是比较大的一个进步，还有ASA的ASDM，用来监控确实不错，但配置我还是习惯用命令行。</div>
<div>&nbsp;</div>
<div>9、自定义菜单管理-EMM<br />IOS 12.4(20)T 后增加了Embedded Menu Manager，可以自定义配置菜单，可以简化配置和便于多人管理，还没有机会尝试。</div>
<div>&nbsp;</div>
<div>10、多设备和脚本- E-DI</div>
<div>E-DI提供了加强的命令行、Perl和XML的管理方式，可以同时管理多个设备，下载地址：<a href="http://www.cisco.com/go/ciscobeyond">www.cisco.com/go/ciscobeyond</a></div>
<div>&nbsp;</div>
<div>参考资料：Networkers 2009 - 13 smarts ways to configure your cisco ios network elements</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div>&nbsp;</div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/159150]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[路由交换]]></category>
 <pubdate><![CDATA[Mon, 18 May 2009 22:57:08 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[Networkers 2009系列之一：通过PfR实现负载均衡]]></title>
 <description><![CDATA[<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 传统的负载均衡厂家都是通过专用的硬件产品来实现负载均衡，不同的产品可以支持出站、入站或双向的负载均衡，如F5的Big-IP系列，Radware LinkProof系列产品。此类产品的价格比较高，通常适用于小型的数据中心或大、中型企业。</div>
<div>&nbsp;</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 现在有更多的中、小企业也部署了多条internet线路，希望能在这些线路上实现负载均衡。其实Cisco在IOS 12.3(8)T以后就推出了Performance Routing&nbsp;(PfR)技术，可以在Cisco路由器上根据延时、丢包率、抖动、负载等条件实现非常灵活的负载均衡，在很多方面甚至超过了专用的负载均衡产品。下面我们给大家具体介绍一下Performance Routing的架构与实现。</div>
<div>&nbsp;</div>
<div>1、Performance Routing 架构</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Performance Routing由MC和BR构成，其中MC记录线路状况并做出决定，BR是实际的边界路由器，执行MC的命令，实现线路的智能切换。</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; 根据企业网络规模大小不同，MC/BR的部署可有一下三种常见的方式：</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; 1）MC和BR在同一台路由器上</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; 2）MC和一个BR在一台路由器上，另一个BR在一台单独的路由器</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; 3）MC和两个BR都在单独的路由器上</div>
<div>&nbsp;</div>
<div align="center"><img onclick='window.open(this.src)' style="width: 354px; height: 183px" onclick=window.open(this.src) height="164" alt="" src="http://blog.51cto.com/attachment/200905/200905191242723077590.jpg" width="272" border="0" /></div>
<div>&nbsp;</div>
<div>2、Performance Routing 操作流程</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Performance Routing的执行过程可以分为以下5步：</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1）学习:&nbsp; 自定义需要监控的数据流，可以根据地址、端口、协议或者应用类型区分数据流。</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2）测量：测量分被动和主动和综合3种方式，被动方式采用Netflow检测数据，主动方式采用IP SLA方式，通常适用于VoIP等实时应用。</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; 3）应用策略：根据定义的策略，综合延时、丢包率、流量等因素，选出最佳路径</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; 4）执行策略：由MC通知BR添加静态或BGP路由，实现动态的负载均衡</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;5）验证：可以通过查看MC/BR状态、路由表和日志监控Performance Routing的具体执行情况。</div>
<div>&nbsp;</div>
<div>3、Performance Routing配置范例</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 下面我们以一个简单的单路由器来说明Performance Routing的具体配置。</div>
<div>&nbsp;</div>
<div align="center"><img onclick='window.open(this.src)' onclick=window.open(this.src) height="121" alt="" src="http://blog.51cto.com/attachment/200905/200905191242738550218.jpg" width="271" border="0" /></div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1）MC/BR基本配置</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; key chain key-1</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; key 1</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; key-string cisco</div>
<div>&nbsp;</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; oer master&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; #定义MC与BR通讯的地址、端口和密钥</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; port 9999</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; logging</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; border 10.10.10.10. key key-1</div>
<div>&nbsp;&nbsp;&nbsp; &nbsp;interface e9/0 external</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; interface e12/0 external</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; interface e8/0 internal</div>
<div>&nbsp;</div>
<div>&nbsp;&nbsp;&nbsp; oer border&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; #定义BR</div>
<div>&nbsp;&nbsp;&nbsp; logging</div>
<div>&nbsp;&nbsp;&nbsp; local loopback0</div>
<div>&nbsp;&nbsp;&nbsp; port 9999</div>
<div>&nbsp;&nbsp;&nbsp; master 10.10.10.10 key-chain key-1</div>
<div>&nbsp;</div>
<div>&nbsp;&nbsp;&nbsp; interface loopback0</div>
<div>&nbsp; &nbsp; ip address 10.10.10.10 255.255.255.255</div>
<div>&nbsp;</div>
<div>&nbsp;&nbsp;&nbsp; ip route 0.0.0.0 0.0.0.0 e9/0</div>
<div>&nbsp;&nbsp;&nbsp; ip route 0.0.0.0 0.0.0.0 e12/0</div>
<div>&nbsp;</div>
<div>&nbsp;&nbsp;&nbsp; 2）定义学习内容和测量标准</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; oer master</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; learn</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; delay&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; #学习延时</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; throughput&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;#学习线路负载</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; periodic-interval&nbsp;3&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; #学习周期，每隔3分钟学习一次</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; monitor-period 1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; #每次学习1分钟</div>
<div>&nbsp;&nbsp;&nbsp; </div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; 3）定义执行策略</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; oer master</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; delay threshold 200&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ＃延时超过200ms会自动选择最优路径</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; mode route control&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ＃定义执行路由控制</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; mode monitor passive&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ＃定义采用被动方式监控</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; mode select-exit best&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ＃定义选择最优路径</div>
<div>&nbsp;</div>
<div>&nbsp;&nbsp;&nbsp; 4）验证配置</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; # show oer master</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; # show oer master border detail</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; # show ip route static</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp; # show logging</div>
<div>&nbsp;</div>
<div>参考资料：Networkers 2009 - Deploy Performance Routing</div>
<div>&nbsp;&nbsp;&nbsp; </div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/159135]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[路由交换]]></category>
 <pubdate><![CDATA[Mon, 18 May 2009 21:49:59 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[开源网络管理系统简介]]></title>
 <description><![CDATA[<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 当企业完成了基础架构的建设及应用系统的部署后，就会产生加强网络管理和监控的需求，同时虚拟化的普及会进一步推动这种需求，但传统的网络管理产品价格较高，部署时间长，很难适用于中小企业。</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 其实有很多优秀的开源产品，就可以满足我们不同的管理需要，甚至在某些方面要强于商业软件，但由于宣传不足，不为大家所熟知，下面我们就为大家介绍几款开源的网络管理系统产品。</div>
<div>&nbsp;</div>
<div>1、网络设备及流量监控---Cacti&nbsp; (<a href="http://www.cacti.net">http://www.cacti.net</a>)</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Cacti是一套基于PHP、MYSQL、SNMP和RRDTOOL开发的网络流量监控工具，你只需要在网络设备中开启SNMP协议，就可以在Cacti中轻松的生成设备CPU、内存、端口流量图。如果你对SNMP协议比较了解，还可以通过自定义生成丰富的图表，如防火墙的连接数、VPN连接数、设备环境温度、UPS电压变化等等。Cacti有丰富的插件库，可以支持路由器、交换机、防火墙、服务器、存储、UPS等等。</div>
<div>&nbsp;</div>
<div>2、服务器监控---Nagios (<a href="http://www.nagios.org">http://www.nagios.org</a>)</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 如果你想监控服务器的状态，Nagios是最好的平台之一。Nagios可以通过代理及无代理的方式监控windows和linux服务器，包括CPU、内存、磁盘、进程及服务，可以通过声音、邮件及短信报警，支持分布式部署，可以将记录保存在MYSQL中存档。我们现在采用的就是将Cacti和Nagios集成在一起的监控模式。Nagios的安装配置比较复杂，如何你对linux不太熟悉，可以选用Groundwork，它把nagios及图形化管理工具打包在一下，安装使用都非常简单。</div>
<div>&nbsp;</div>
<div>3、应用流量监控---Ntop (<a href="http://www.ntop.org">http://www.ntop.org</a>)</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 通过Cacti我们可以看到路由器和交换机每个端口的流量，但如何我们想了解每个人的流量情况及不同应用的带宽占用情况，就需要使用Ntop。Ntop通过分析数据镜像端口的流量，生成详细的源地址、目的地址、应用带宽利用率，便于找出视频、P2P等高带宽应用，保证网络的正常通讯。</div>
<div>&nbsp;</div>
<div>4、安全管理平台---OSSIM (<a href="http://www.ossim.net">http://www.ossim.net</a>)</div>
<div>SOC是这几年比较热的一个概念，商业化的安全管理平台的产品都比较贵，OSSIM是一个开源的安全管理产品，它集成了Snort、Nagios、Ntop、OCSNG等15个开源安全工具，同时将不同的事件进行关联，构建一个统一的管理平台。应该说它的想法非常好，但还有很多需要完善的地方。</div>
<div>&nbsp;</div>
<div>除了上面介绍的产品，其实还有很多开源的网络管理工具，如OpenNMS，Hyperic HQ，OpenQRM等等。但由于开源产品宣传不足及安装使用复杂，很难被大家认可，我认为开源产品一方面要加强合作，注重宣传，另一方面要简化安装配置，如提供自启动安装光盘、vmware 虚拟机等简便的安装方式。开源之路仍任重而道远。。。</div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/158626]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[系统软件]]></category>
 <pubdate><![CDATA[Sat, 16 May 2009 23:57:24 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[Cisco 安全技术系列之二：IOS设备安全管理]]></title>
 <description><![CDATA[<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-indent: 36pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">Cisco IOS </span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>设备的安全加固包括了管理层面、控制层面和数据层面的三方面的内容，管理层面指通过</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">SSH</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>或</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">SNMP</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>对设备的管理，控制层面指路由协议</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">IGP</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>以及</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">BGP</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>的管理，数据层面指用户的正常数据通讯，下面主要介绍一下管理层面的安全技术。</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p>&nbsp;</o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; line-height: 150%; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn; mso-fareast-font-family: " Times New Roman?><span style="mso-list: ignore">1、<span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Times New Roman?>&nbsp; </span></span></span><span dir="ltr"><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>管理层面</span></span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>密码管理：</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">service password-encryption<span style="mso-tab-count: 2">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>//</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>启用密码加密服务</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">username cisco secret cisco<span style="mso-tab-count: 2">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>//MD5</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>加密用户密码</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">aaa authentication attempts loging<span style="mso-tab-count: 2">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>//</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>限制用户登陆的尝试次数</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p>&nbsp;</o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>禁用以下服务：</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">no ip domain-lookup<span style="mso-tab-count: 3">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>//</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>禁用</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">DNS</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>解析服务</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">no ip http server<span style="mso-tab-count: 4">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>//</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>禁用</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">HTTP</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>服务</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">no service config<span style="mso-tab-count: 3">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>//</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>禁用网络下载配置服务</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">no cdp run<span style="mso-tab-count: 4">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>//</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>禁用</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">CDP</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>服务</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p>&nbsp;</o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>使用</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">AAA</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>服务：</span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?></span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">aaa new-model<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">aaa authentication login default group tacacs+ enable<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">tacacs-server host &lt;ip-address-of-tacacs-server&gt;<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">tacacs-server key &lt;key&gt;<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p>&nbsp;</o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">aaa authorization exec default group tacacs none<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">aaa authorization commands 0 default group tacacs none<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">aaa authorization commands 1 default group tacacs none <o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">aaa authorization commands 15 default group tacacs none<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p>&nbsp;</o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">aaa accounting exec default start-stop group tacacs <o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">aaa accounting commands 0 default start-stop group tacacs<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">aaa accounting commands 1 default start-stop group tacacs<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">aaa accounting commands 15 default start-stop group tacacs<o:p></o:p></span></div></o:p></span></div><pre class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span>&nbsp;</pre><pre><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">SNMP</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>管理：</span></pre><pre><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?></span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">Access-list 99 permit 192.168.100.1<span style="mso-tab-count: 2">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>//</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>定义允许访问</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">SNMP</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>服务的地址</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></pre>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">Snmp-server community READONLY RO 99<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp; </span>//</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>定义</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">SNMP</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>只读字符串</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p>&nbsp;</o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>日志管理：</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">Logging host 192.168.100.1<span style="mso-tab-count: 2">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>//</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New mso-ansi-language: NO-BOK>定义</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">syslog</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New mso-ansi-language: NO-BOK>主机地址</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">Logging trap 6<span style="mso-tab-count: 4">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>//</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New mso-ansi-language: NO-BOK>定义网络日志等级</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">Logging buffered 6<span style="mso-tab-count: 3">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>//</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New mso-ansi-language: NO-BOK>定义缓存日志等级</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">No logging console<span style="mso-tab-count: 3">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>//</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>禁用控制台日志功能</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">No logging monitor<span style="mso-tab-count: 3">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>//</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>禁用远程登陆日志功能</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">Logging source-interface loopback 0<span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp; </span>//</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>定义日志源地址</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">Service timestamps log datetime mesc show-timezone<span style="mso-tab-count: 1"> </span>//</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>定义日志时间格式</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p>&nbsp;</o:p></span></div><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>配置管理：</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">Archive<span style="mso-tab-count: 4">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>//</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>定义每天自动保存配置到</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">flash<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><span style="mso-spacerun: yes">&nbsp;</span>path disk0:archived-config<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><span style="mso-spacerun: yes">&nbsp;</span>maximum 14<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><span style="mso-spacerun: yes">&nbsp;</span>time-period 1440<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><span style="mso-spacerun: yes">&nbsp;</span>write-memory<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p>&nbsp;</o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">archive<span style="mso-tab-count: 4">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>//</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>定义记录配置更改并发送</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn">syslog</span><span style="font-size: 10.5pt; line-height: 150%; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Times Roman?; mso-hansi-font-family: ?Times New Roman?>日志</span><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><span style="mso-spacerun: yes">&nbsp;</span>log config<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><span style="mso-spacerun: yes">&nbsp; </span>logging enable<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><span style="mso-spacerun: yes">&nbsp; </span>logging size 200<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><span style="mso-spacerun: yes">&nbsp; </span>hidekeys<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><span style="mso-spacerun: yes">&nbsp; </span>notify syslog<o:p></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p>&nbsp;</o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p>参考资料：</o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="font-size: 10.5pt; line-height: 150%; mso-fareast-language: zh-cn"><o:p><a href="http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080120f48.shtml#gc">http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080120f48.shtml#gc</a></o:p></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"></o:p></span>&nbsp;</div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/158336]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[安 全]]></category>
 <pubdate><![CDATA[Fri, 15 May 2009 16:53:38 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[Cisco 安全技术系列之一：2层攻击防范技术]]></title>
 <description><![CDATA[<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; line-height: 150%; mso-list: l0 level1 lfo1; tab-stops: list 0cm"><span lang=EN-US style="mso-fareast-font-family: " Roman?? New Times><span style="mso-list: ignore"><font size="3">1.</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman?? New Times>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><font size="3"><span dir="ltr"><span lang=EN-US style="mso-fareast-language: zh-cn">VLAN</span></span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>跳跃攻击（</span><span lang=EN-US style="mso-fareast-language: zh-cn">VLAN Hopping</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>）</span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>分析：用户可以将自己的端口配置为</span><span lang=EN-US style="mso-fareast-language: zh-cn">trunk</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>，将自己加入到所有的</span><span lang=EN-US style="mso-fareast-language: zh-cn">Vlan</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>中。另一方法是伪造数据包，在包头中添加双重</span><span lang=EN-US style="mso-fareast-language: zh-cn">tag</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>标记，这样即使管理员关闭了该接口的</span><span lang=EN-US style="mso-fareast-language: zh-cn">trunk</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>功能，仍可以将数据包发送到其他</span><span lang=EN-US style="mso-fareast-language: zh-cn">Vlan</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>。</span><span lang=EN-US style="mso-fareast-language: zh-cn"><?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>防范：关闭不用的端口或者将他们放在一个隔离的</span><span lang=EN-US style="mso-fareast-language: zh-cn">VLAN</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>中。</span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;></span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font>&nbsp;</div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; line-height: 150%; mso-list: l0 level1 lfo1; tab-stops: list 0cm"><span lang=EN-US style="mso-fareast-font-family: " Roman?? New Times><span style="mso-list: ignore"><font size="3">2.</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman?? New Times>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><font size="3"><span dir="ltr"><span lang=EN-US style="mso-fareast-language: zh-cn">MAC</span></span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>攻击</span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>分析：交换机的</span><span lang=EN-US style="mso-fareast-language: zh-cn">MAC</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>的地址表的空间大小是固定的，攻击者可以通过发送随机地址的数据包将地址表空间填满，该交换机就会成为一个</span><span lang=EN-US style="mso-fareast-language: zh-cn">HUB</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>，攻击者可以通过监听工具收集和分析网络中的所有数据。</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>防范：启用端口安全功能，限制每个端口允许的</span><span lang=EN-US style="mso-fareast-language: zh-cn">MAC</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>地址数量并发送</span><span lang=EN-US style="mso-fareast-language: zh-cn">syslog</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>日志。</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3">Switchport port-security<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3">Switchport port-security maximum 1 vlan access<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3">Switchport port-security violation restrict<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3">Switchport port-security aging time 2<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3">Switchport port-security aging type inactivity<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3">Snmp-server enable traps port-security trap-rate 5</font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3"><o:p></o:p></font></span>&nbsp;</div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; line-height: 150%; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span lang=EN-US style="mso-fareast-font-family: " New Times Roman?; ZH-CN? mso-fareast-language:><span style="mso-list: ignore"><font size="3">3.</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman?? New Times>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><font size="3"><span dir="ltr"><span lang=EN-US style="mso-fareast-language: zh-cn">DHCP</span></span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>攻击</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>分析：攻击者可以将自己伪装为</span><span lang=EN-US style="mso-fareast-language: zh-cn">DHCP</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>服务器向用户提供</span><span lang=EN-US style="mso-fareast-language: zh-cn">DHCP</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>服务，从而将数据引向自身，获得用户数据的内容和流向控制。</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>防范：启用</span><span lang=EN-US style="mso-fareast-language: zh-cn">DHCP Snooping</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>功能</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>用户端口：</span><span lang=EN-US style="mso-fareast-language: zh-cn">&nbsp;no ip dhcp snooping trust<o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span lang=EN-US style="mso-fareast-language: zh-cn">DHCP</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>服务器端口：</span><span lang=EN-US style="mso-fareast-language: zh-cn">ip dhcp snooping trust </span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font>&nbsp;</div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; line-height: 150%; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span lang=EN-US style="mso-fareast-font-family: " New Times Roman?; ZH-CN? mso-fareast-language:><span style="mso-list: ignore"><font size="3">4.</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman?? New Times>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><font size="3"><span dir="ltr"><span lang=EN-US style="mso-fareast-language: zh-cn">ARP</span></span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>攻击</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>分析：攻击者可以将自己</span><span lang=EN-US style="mso-fareast-language: zh-cn">MAC</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>伪装成网关的</span><span lang=EN-US style="mso-fareast-language: zh-cn">MAC</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>地址，从而将同网段的所有流量引向自己。获得用户数据的内容和控制。流行的</span><span lang=EN-US style="mso-fareast-language: zh-cn">ARP</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>病毒就是通过这种方式实现的。</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>防范：</span><span lang=EN-US style="mso-fareast-language: zh-cn">DHCP</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>环境（启用动态</span><span lang=EN-US style="mso-fareast-language: zh-cn">ARP</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>检测－</span><span lang=EN-US style="mso-fareast-language: zh-cn">DAI</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>，可以监控网络中</span><span lang=EN-US style="mso-fareast-language: zh-cn">ARP</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>数据）</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span lang=EN-US style="mso-fareast-language: zh-cn"><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>全局配置：</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3"><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Ip arp inspection vlan 4,104<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3"><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Ip arp inspection log buffer entries 1024<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3"><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Ip arp inspesction log-buffer logs 1024 interval 10<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span lang=EN-US style="mso-fareast-language: zh-cn"><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>端口配置：</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3"><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Ip arp inspection trust</font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3"><o:p></o:p></font></span>&nbsp;</div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span lang=EN-US style="mso-fareast-language: zh-cn"><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>非</span><span lang=EN-US style="mso-fareast-language: zh-cn">DHCP</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>环境（为网关和服务器设置静态</span><span lang=EN-US style="mso-fareast-language: zh-cn">IP</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>和</span><span lang=EN-US style="mso-fareast-language: zh-cn">MAC</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>绑定）</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3"><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Ip source binding 0000.0000.0001 vlan 4 10.1.1.1 interface fastethernet 3/1</font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3"><o:p></o:p></font></span>&nbsp;</div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; line-height: 150%; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span lang=EN-US style="mso-fareast-font-family: " New Times Roman?; ZH-CN? mso-fareast-language:><span style="mso-list: ignore"><font size="3">5.</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman?? New Times>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><font size="3"><span dir="ltr"><span lang=EN-US style="mso-fareast-language: zh-cn">IP/MAC</span></span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>欺骗攻击</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>分析：攻击者可以伪装成合法的</span><span lang=EN-US style="mso-fareast-language: zh-cn">IP</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>和</span><span lang=EN-US style="mso-fareast-language: zh-cn">MAC</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>地址，从而影响用户的正常通讯和获得非法的权限。</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>防范：启用</span><span lang=EN-US style="mso-fareast-language: zh-cn">ip source guard</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>，可以检测数据包的源</span><span lang=EN-US style="mso-fareast-language: zh-cn">IP</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>地址或者源</span><span lang=EN-US style="mso-fareast-language: zh-cn">MAC</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>地址，过滤掉非法的数据，</span><span lang=EN-US style="mso-fareast-language: zh-cn">ip source guard</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>需要先启用</span><span lang=EN-US style="mso-fareast-language: zh-cn">DHCP snooping</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>功能。</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; text-indent: 36pt; line-height: 150%"><font size="3"><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>全局配置：</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3"><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Ip dhcp snooping vlan 4,104<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3"><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>No ip dhcp snooping information option<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3"><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Ip dhcp snooping<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span lang=EN-US style="mso-fareast-language: zh-cn"><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>端口配置</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3"><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Ip verify source vlan dhcp-snooping</font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3"><o:p></o:p></font></span>&nbsp;</div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; line-height: 150%; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><span lang=EN-US style="mso-fareast-font-family: " New Times Roman?; ZH-CN? mso-fareast-language:><span style="mso-list: ignore"><font size="3">6.</font><span style="font-weight: normal; font-size: 7pt; line-height: normal; font-style: normal; font-variant: normal" Roman?? New Times>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><font size="3"><span dir="ltr"><span lang=EN-US style="mso-fareast-language: zh-cn">STP</span></span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>攻击</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>分析：攻击者可以发送</span><span lang=EN-US style="mso-fareast-language: zh-cn">BPDU</span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>引起根桥的变化，从而获得非法的数据并造成网络的震荡。</span><span lang=EN-US style="mso-fareast-language: zh-cn"><o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>防范：接入层交换机端口启用</span><span lang=EN-US style="mso-fareast-language: zh-cn">BPDU Guard<o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3"><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Spanning-tree portfast bpdugurad<o:p></o:p></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><font size="3"><span lang=EN-US style="mso-fareast-language: zh-cn"><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>核心层交换机端口启用</span><span lang=EN-US style="mso-fareast-language: zh-cn">Root Guard<o:p></o:p></span></font></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3"><span style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Spanning-tree guard root</font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font size="3"><o:p></o:p></font></span>&nbsp;</div>
<div><span style="font-size: 12pt; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " New Times ?Times mso-hansi-font-family: Roman?; AR-SA? mso-bidi-language: EN-US; mso-ansi-language: mso-bidi-font-family:>总结：</span><span lang=EN-US style="font-size: 12pt; font-family: " New Times Roman?; mso-fareast-language: AR-SA? mso-bidi-language: EN-US; mso-ansi-language: ZH-CN; 宋体; mso-fareast-font-family:><span style="mso-tab-count: 1">&nbsp; </span>Cisco 2</span><span style="font-size: 12pt; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " New Times ?Times mso-hansi-font-family: Roman?; AR-SA? mso-bidi-language: EN-US; mso-ansi-language: mso-bidi-font-family:>层攻击防范架构</span></div>
<div><span style="font-size: 12pt; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " New Times ?Times mso-hansi-font-family: Roman?; AR-SA? mso-bidi-language: EN-US; mso-ansi-language: mso-bidi-font-family:><img onclick='window.open(this.src)' onclick=window.open(this.src) alt="" src="http://blog.51cto.com/attachment/200905/200905141242278882200.jpg" border="0" /></span></div><span style="font-size: 12pt; font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " New Times ?Times mso-hansi-font-family: Roman?; AR-SA? mso-bidi-language: EN-US; mso-ansi-language: mso-bidi-font-family:>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>参考资料：</span><span style="mso-fareast-language: zh-cn"><font face="Times New Roman"> <span lang=EN-US><o:p></o:p></span></font></span></div>
<div class=MsoNormal style="margin: 0cm 0cm 0pt; line-height: 150%"><span lang=EN-US style="mso-fareast-language: zh-cn"><font face="Times New Roman">Networkers 2009 BRKSEC</font></span><span style="font-family: 宋体; mso-fareast-language: zh-cn; mso-ascii-font-family: " Roman?? New Times ?Times mso-hansi-font-family: Roman?;>－</span><span lang=EN-US style="mso-fareast-language: zh-cn"><font face="Times New Roman">2002 Understanding and Preventing Layer 2 Attacks<o:p></o:p></font></span></div>
<div></span>&nbsp;</div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/157807]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[安 全]]></category>
 <pubdate><![CDATA[Thu, 14 May 2009 13:30:08 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[Cisco ACS替代方案系列之一---Windows IAS]]></title>
 <description><![CDATA[<div>Cisco的ACS服务器可以提供完善AAA服务，包括认证、授权和记账的功能。但价格较高，不适合中小企业使用。我们可以使用windows IAS和域控制器来提供AAA中的认证功能，通过域用户和密码来管理网络设备，避免了更新设备密码的麻烦。</div>
<div>&nbsp;</div>
<div>1）cisco设备配置</div>
<div>aaa new-model<br />aaa authentication login&nbsp;test group radius local</div>
<div>&nbsp;</div>
<div>radius-server host&nbsp;x.x.x.x key cisco&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; #x.x.x.x是windows IAS服务器地址<br />radius-server source-ports 1645-1646<br />radius-server directed-request</div>
<div>&nbsp;</div>
<div>user cisco privilege 15 password cisco</div>
<div>&nbsp;</div>
<div>line vty 0 4</div>
<div>privilege level 15</div>
<div>login authentication test</div>
<div>&nbsp;</div>
<div>2）windows IAS服务器配置</div>
<div>在windows administrative tools中选择internet authentication service，右键单击radius clients添加网络设备的ip和key。</div>
<div>在Remote Access Policies,&nbsp;右键单击 Connections to Other Access Servers, 选择<br />Properties，将允许登陆网络设备的用户添加到policy condition框中，确保选中下面的Grant Remote Access Permissions。</div>
<div>点击Edit Profile，在Authentication页面中选中Unencrypted authentication (PAP, SPAP), MS&#8722;CHAP,和 MS&#8722;CHAP&#8722;v2，在Encryption页面中选中No Encryption。</div>
<div><br />&nbsp;</div>
<div>3）验证认证服务功能</div>
<div>使用域用户和密码登陆网络设备，确认上述配置是否生效。</div>
<div>&nbsp;</div>
<div>参考资料：<a href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806de37e.shtml">http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806de37e.shtml</a></div>
<div>&nbsp;</div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/157376]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[路由交换]]></category>
 <pubdate><![CDATA[Tue, 12 May 2009 22:33:32 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[Cisco ACS替代方案系列之二---Splunk]]></title>
 <description><![CDATA[<div>Cisco的ACS服务器可以提供完善AAA服务，包括认证、授权和记账的功能。但价格较高，不适合中小企业使用。其实我们可以让Cisco网络设备本身记录配置的变更，并将变更的内容发送到syslog服务器上，然后由syslog定时将相关的记录过滤出来，通过邮件发送到指定的邮箱来实现记账的功能。</div>
<div>&nbsp;</div>
<div>在这里我使用Splunk作为syslog服务器，splunk是linux下一款优秀的日志收集和分析软件，免费版可以提供每天500M的日志索引量，对于中小企业已经足够了。下面我们以cisco的交换机和防火墙为例：</div>
<div>&nbsp;</div>
<div>1）cisco交换机配置</div>
<div>archive<br />log config<br />logging enable<br />logging size 200<br />hidekeys<br />notify syslog</div>
<div>&nbsp;</div>
<div>logging trap notifications<br />logging x.x.x.x<br /></div>
<div>2） cisco ASA5500配置</div>
<div>logging enable<br />logging host inside x.x.x.x<br />logging class config trap notifications</div>
<div>&nbsp;</div>
<div>3）splunk基本配置</div>
<div>linux下splunk的安装具体见<a href="http://www.splunk.com">www.splunk.com</a>，同时需要安装smtp邮件系统，我使用的是postfix。安装完成后通过IE访问splunk管理页面。在admin页面中定义使用udp 514端口接受syslog日志。</div>
<div>&nbsp;</div>
<div>4）splunk报警配置</div>
<div>在搜索框中输入以下条件，并点击搜索框左边的小箭头，选择‘save search’。</div>
<div>&nbsp;</div>
<div><font color="#ff0000">%ASA-5-111008 OR %PARSER-5-CFGLOG_LOGGEDCMD startminutesago=60</font></div>
<div>&nbsp;</div>
<div>在‘save search’的定义页面中选择以下选项，</div>
<div>选中 Run this search on a schedule</div>
<div>schedule：run every hour</div>
<div>alert：alert when number of event greater than 1</div>
<div>send email : <a href="mailto:xxx@xxx.com">xxx@xxx.com</a></div>
<div>选中 include results</div>
<div>&nbsp;</div>
<div>5）验证邮件报警功能</div>
<div>在交换机或者防火墙上修改配置，splunk将每隔60分钟搜寻一下前60分钟收到的日志，将与配置变更有关的内容自动发送到你指定的邮箱中，邮件范例如下：</div>
<div>From: <a href="mailto:splunk@localhost">splunk@localhost</a></div>
<div>To: <a href="mailto:xxx@xxx.com">xxx@xxx.com</a></div>
<div>Content：Saved search results.&nbsp;&nbsp; Name: 'Config Change'<br />Query Terms: 'now=1242100800 %ASA-5-111008 OR %PARSER-5-CFGLOG_LOGGEDCMD startminutesago=60'<br />Alert was triggered because of: 'Saved Search [Config Change]: number of events(16) greater than 1' Search results attached:</div>
<div>attachment: %PARSER-5-CFGLOG_LOGGEDCMD: User:xxx&nbsp; logged command:service timestamps log datetime</div>
<div>&nbsp;</div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/157367]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[路由交换]]></category>
 <pubdate><![CDATA[Tue, 12 May 2009 21:58:31 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[VMware ThinApp使用教程]]></title>
 <description><![CDATA[<div>VMware ThinApp是一个应用程序虚拟化的工具，可以将应用程序打包为一个EXE文件，用户可以在任何地方运行而无需安装和管理员权限。我们可以将它看作是绿色软件和单文件的打包工具，VMware推荐和VDI一起使用可以简化桌面应用程序的发布。VMware ThinApp安装和测试过程如下：</div>
<div>&nbsp;</div>
<div>1、从<a href="http://www.vmware.com/download/">[url]http://www.vmware.com/download/[/url]</a> 下载ThinApp，并注册申请60天的试用License。</div>
<div>2、在VMware Workstation中新建一个win xp的虚拟机，安装下载的ThinApp。</div>
<div>3、运行ThinApp Setup Capture，点Next建立系统快照。</div>
<div>4、安装需要打包的软件，再点击Next，建立第二次快照，系统自动记录2次快照的区别。</div>
<div>5、勾选运行软件的主文件，点击Next。</div>
<div>6、选择运行时缓存文件的存储位置（sandbox location），保持缺省设置，点击Next。</div>
<div>7、选择文件隔离模式（isolation mode），保持缺省设置，点击Next。</div>
<div>8、选择文件输出目录，是否生成msi文件以及是否压缩。</div>
<div>9、点击‘build now’生成exe文件，在输出目录中的bin文件夹中找到生成的exe文件，用户将该文件复制到本地就可以运行打包的程序，无需安装和管理员权限，十分方便部署和升级。</div>
<div>&nbsp;</div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/155807]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[系统软件]]></category>
 <pubdate><![CDATA[Thu, 07 May 2009 09:10:01 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[VMware vSphere 4的特性分析]]></title>
 <description><![CDATA[<div><span class=Title_blue>【TechTarget中国原创】</span>随着vSphere的发布，VMware持续强调这个企业级hypervisor是成熟的。这强调了VMware决定注重的方面：补充其产品。VSphere对VMware ESX 3.5作出的主要更改包括稳定性、可用性和安全性，这些都是服务而不是hypervisor功能。</div><span class=displayclass></span>
<div>　　VMware已经发布官方申明，最新的产品套件围绕着其龙头产品VMware ESX建立，叫做VMware vSphere。有了vSphere，VMware将其hypervisor定位为虚拟数据中心操作系统或者VDC-OS。与先前的版本相反，许多新功能几乎是与单个系统相关的，新的vSphere几乎以服务为导向，通过VMware的名字选择就能看出来：Application vServices和Infrastructure vServices。Application vServices是提供增强性可用性、稳定性和安全性的产品。作为一个整体，Application vServices位于Infrastructure vServices之上，如vCompute、vStorage和vNetwork。</div><span class=displayclass></span>
<div>　　在本文中，TechTarget中国的特约虚拟化专家Gabrie van Zanten将介绍这些服务，并介绍VMware vSphere 4的新功能。</div><span class=displayclass></span>
<div><strong>　　Application vServices</strong></div><span class=displayclass></span>
<div>　　当涉及到业务应用，终端用户不关心运行应用的硬件或者运行应用的操作系统。用户希望应用作为服务运行，因此，主要的关心问题是在需要时服务是否可用，有多安全，什么时候需要更多的能耗和资源，扩展性能如何等。有了Application vServices，VMware在这些领域的每一个中都添加了新功能。</div><span class=displayclass></span>
<div><strong>　　可用性</strong></div><span class=displayclass></span>
<ul>
<li><strong>VMware Fault Tolerance</strong>（VMware FT）。当需要增加可用性时，许多公司考虑集群技术，但这种技术很复杂。应用也必须运行在集群里，并能感知集群，但应用很少能做到。使用VMware FT，虚拟机能在单独主机上使用“ghost”副本运行在lockstep里。如果出现问题需要虚拟机故障转移，故障转移马上就会发生。</li></ul>
<div>&nbsp;&nbsp;&nbsp; 每台虚拟机都可启动VMware FT，目前的版本只需要花费10%的性能。VMware FT只运行在单个虚拟CPU的虚拟机里。这个技术最有用的部分在于虚拟机不需要感知VMware FT，你也不需要对操作系统和应用作出任何修改。</div><span class=displayclass></span>
<ul>
<li><strong>VMware Data Recovery</strong>（VMware DR）。VMware DR使在文件级别和虚拟机级别备份和存储虚拟机数据更容易。VMware Disaster Recovery比VMware Consolidated Backup（VCB）提供了更高颗粒度。除了有图形用户界面（GUL），现在更容易指定备份、定义保留策略和执行恢复，只需要鼠标点击几下就能做到。VMware DR是无代理的，能使用重复数据删除技术存储增量备份。使用VMware DR有助于成本效益的存储管理。</li></ul>
<div><strong>　　安全性</strong></div><span class=displayclass></span>
<ul>
<li><strong>VMware VMsafe</strong>。如果环境中的每台虚拟机不需要本身的杀毒软件和恶意软件扫描该有多好！VMware VMsafe是一个应用程序接口，能让安全厂商在影响到虚拟机之前扫描所有内存和网络流量。使用这种技术，病毒在影响到虚拟机之前就被截获，预防衍生物。对整个主机只进行一次扫描比对主机上的每个字操作系统进行扫描更好。 
<li><strong>VMware vShield Zones</strong>。作为管理员，你可以创建VMotion、网络和配置感知的vShield信任区。换句话说，从一台主机迁移到另一台的虚拟机能受到来自网络外面的区域保护。分配给区域的虚拟机可能只能移动到另一台拥有相同渔区配置和相同防火墙的主机。</li></ul>
<div><strong>　　可扩展性</strong></div><span class=displayclass></span>
<ul>
<li><strong>热添加设备</strong>。在先前的版本中，只有虚拟磁盘能添加到运行中的虚拟机。使用VMware vSphere，可以在虚拟机运行时添加更多CPU（内存）。网络和存储设备也能进行“热添加”和“热移除”。通过这样的方式扩展虚拟机，由于给虚拟机添加内存时没有宕机，这就增加了应用的可扩展性。 
<li><strong>新虚拟机限制</strong>。能给与虚拟机的能耗最大值也增加了。在VMware vSphere里，虚拟机能最多拥有8个虚拟CPU和255GB RAM。更多应用现在是运行在虚拟环境中的合适选后者。例如，用户可能不能在VMware ESX 3.5里运行大型Microsoft SQL数据库或者SAP，因为ESX 3.5最多支持四个CPU。现在虚拟机拥有八个CPU，虚拟化这样的数据库或者SAP就可行了。</li></ul>
<div><strong>　　Infrastructure vServices</strong></div><span class=displayclass></span>
<div>　　在基础设施层有几大改变，这就是VMware所指的Infrastructure vServices。VMware创造了三个焦点领域：vComputer、vStorage和vNetwork，这些新功简化了管理员的工作量，包括Application vServices的植入。</div><span class=displayclass></span>
<div><strong>　　VMware vComputer </strong></div><span class=displayclass></span>
<ul>
<li><strong>主机限制</strong>。要使用vSphere，主机最大需要有512GB的可访问RAM和64CPU核心，也就是说每台主机可以运行大量虚拟机。每核心运行三到四台虚拟机很正常，因此现在每台主机可能运行192台虚拟机。 
<li><strong>网络和存储堆栈改良</strong>。结合使用Intel的“Nehalem”处理器和VMDirectPath技术，允许vSphere跳过网络接口卡（NIC）的模拟，直接映射物理NIC到虚拟机，达到最大网络访问速度。使用改良的存储堆栈，vSphere应该能达到每秒40万输入/输出操作，提供低于2毫秒延迟。 
<li><strong>分布式电源管理（DPM）</strong>。使用DPM，当集群的负荷非常小的时候，可以将vSphere主机置于待定模式。DPM将整合虚拟机腾出一台或更多主机，关闭这些主机以降低能源消耗。如果集群上的负荷增加，DPM自动启动待定的主机。</li></ul>
<div><strong>　　VMware vStorage </strong></div><span class=displayclass></span>
<ul>
<li><strong>连接的克隆和精简配置</strong>。以前VMware ESX使用存储的方式导致经常要求存储空间，其实根本用不了那么多，这就浪费了存储空间。精简配置则杜绝了管理员的猜测，而不会导致存储过量使用。结合使用Linked Clones技术——相同磁盘上可以存储大量虚拟机。VMware宣称使用其更新的虚拟机存储方法可以节省的存储空间能达到50%。 
<li><strong>存储提醒和监控</strong>。在VMware Infrastructure 3里，vCenter对精确的存储使用率小有远见。现在也提高了，在vCenter里的存储分配与消耗有更好的报告和告警。</li></ul>
<div><strong>　　vNetwork</strong></div><span class=displayclass></span>
<ul>
<li><strong>分布式vSwitch</strong>。从VMware ESX 2起，分布式vSwitch就是管理员所需求的。在一台主机上创建一个虚拟交换机，并让其与其他所有主机上的vSwitch同步是复杂的。Distributed vSwitches解决了这个问题，因为在分布式交换机上作出的更改将自动在所有主机上更新。这大大减轻了管理虚拟基础设施的负担。较少的管理任务意味着更少的错误和更多的运行时间。 
<li><strong>第三方虚拟交换机</strong>。除了VMware新植入的分布式vSwitch，vSphere也支持第三方虚拟交换机。思科是第一个对vSphere提供支持的厂商，发布了Nexus 1000V。从思科购买一个独立许可证之后，就可以使用网络密匙激活Nexus 1000V，网络管理员就能完全管理虚拟环境里网络的各个方面，而不需要让VMware管理员进行以前必要的配置。这也减轻了管理和减少了配置错误的风险。</li></ul>
<div><strong>　　附加的产品更新</strong></div><span class=displayclass></span>
<div>　　这只是主机方面新功能的一部分，不过也有对业务操作有重大影响的更新。vCenter的新版本有大量的改进，在VMworld Europe 2009大会上，VMware宣布了其他的新服务，如AppSeed何Chargeback，这些将在今年发布。这些服务主要从虚拟架构管理工具升级vCenter，让其成为一个有额外价值的工具。</div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/155604]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[服务器&存储]]></category>
 <pubdate><![CDATA[Wed, 06 May 2009 15:43:36 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[VMware ESXi中安装Vyatta实现虚拟路由器]]></title>
 <description><![CDATA[<div>Vyatta是linux下知名的开源路由器项目，在其官方的测试中性能甚至超过了cisco 7200系列路由器，可以支持RIP、OSPF、BGP等路由协议以及VPN、NAT、HA等特性。</div>
<div>&nbsp;</div>
<div>我们的测试是希望在ESXi中安装Vyatta的虚拟机来替代cisco 1800和2800系列的路由器，或者作为cisco路由器的一个备份，测试的内容只有nat和trunk的支持。</div>
<div>&nbsp;</div>
<div>1、首先从<a href="http://www.vyatta.com">[url]http://www.vyatta.com[/url]</a>下载vyatta的安装ISO文件，在ESXi中新建一个虚拟机，分配2块网卡，将下载的ISO文件挂载为光驱。</div>
<div>2、在ESXi的配置中，将第2块网卡port group的vlan id改为4095</div>
<div>3、启动虚拟机,用缺省的用户名/密码 root/vyatta登陆系统</div>
<div>4、安装vyatta到硬盘上</div>
<div><font color="#0000ff">install-system</font></div>
<div>5、进入配置模式</div>
<div><font color="#0000ff">configure</font></div>
<div>6、配置系统名称</div>
<div><strong><font color="#0000ff">set system host-name v<span class=highlightedSearchTerm><font style="background-color: #ffffaa">yatta</font></span>-1</font></strong></div>
<div>7、设置DNS</div>
<div><strong><font color="#0000ff">set system name-server x.x.x.x</font></strong></div>
<div>8、设置缺省网关</div>
<div><strong><font color="#0000ff">set system gateway-address 10.0.0.1</font></strong></div>
<div>9、定义外网接口IP地址</div>
<div><strong><font color="#0000ff">set interfaces ethernet eth0 address 10.0.0.2/24</font></strong></div>
<div>10、定义内网口IP地址</div>
<div><strong><font color="#0000ff">&nbsp;&nbsp;&nbsp; set interfaces ethernet eth1 vif 6 address 192.168.6.1/24</font></strong> 
<div jQuery1241586198925="58"><strong><font color="#0000ff">&nbsp;&nbsp;&nbsp; set interfaces ethernet eth1 vif&nbsp;7 address 192.168.7.1/24</font></strong></div>
<div jQuery1241586198925="60"><strong jQuery1241586198925="61"><font color="#0000ff">&nbsp;&nbsp;&nbsp; set interfaces ethernet eth1 vif&nbsp;8 address 192.168.8.1/24</font></strong></div></div>
<div>11、设置NAT策略</div>
<div>
<div jQuery1241586198925="65"><font color="#0000ff">&nbsp;&nbsp;&nbsp; <strong jQuery1241586198925="66">set service nat rule 1 source address 192.168.0.0/16</strong></font></div>
<div jQuery1241586198925="67"><strong jQuery1241586198925="68"><font color="#0000ff">&nbsp;&nbsp;&nbsp; set service nat rule 1 outbound-interface eth0</font></strong></div>
<div jQuery1241586198925="69"><strong jQuery1241586198925="70"><font color="#0000ff">&nbsp;&nbsp;&nbsp; set service nat rule 1 type masquerade</font></strong></div></div>
<div>12、保存和启用配置</div>
<div><strong><font color="#0000ff">&nbsp;&nbsp;&nbsp;&nbsp; commit</font></strong> 
<div jQuery1241586198925="74"><strong><font color="#0000ff">&nbsp;&nbsp;&nbsp;&nbsp; save</font></strong></div></div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/155437]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[路由交换]]></category>
 <pubdate><![CDATA[Tue, 05 May 2009 23:11:59 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[虚拟化天下，谁主沉浮]]></title>
 <description><![CDATA[<div>虚拟化技术现在是炙手可热，各大厂商是你方唱罢我登场，好不热闹，谁将笑傲群雄，且让我们一一道来。</div>
<div>&nbsp;</div>
<div>1.、VMware 凭借自己在x86平台10多年的辛勤耕耘，已成为PC服务器虚拟化市场占有率最高的厂商，VI平台也在企业中得到了广泛的应用。VMware的产品线完善，从服务器到桌面、应用程序和灾难备份虚拟化都有相应的产品，应用实例广泛，可以说是产品最为成熟的。今年VMware发布了vSphere，向云计算平台转移，同时加强了与合作伙伴的协作，可以预见在一段时间内VMware仍将保持业界老大的位置，但市场份额在激烈的竞争下将有所下降，同时产品的定价较高也影响了其在中小企业的应用。</div>
<div>&nbsp;</div>
<div>2、Microsoft是虚拟化的后来者，08年与windows 2008一同发布了Hyper-V。Hyper-v还是一个新产品，还有待与市场的检验和产品的不断完善。但与windows 2008的集成、免费的虚拟机OS授权，让我们想起了曾经的Netscape，microsoft将成为VMware最大的挑战者，首先抢占中小企业市场。但随着linux在企业和数据中心的广泛应用，Hyper-V对linux的有限支持将成为制约其发展的重要因素。</div>
<div>&nbsp;</div>
<div>3、Citrix 收购了XenSource后将linux平台开源的Xen包装发布了XenServer，提供了与VMware ESX相类似的解决方案。Citrix通过此次收购，完善了自己的产品线，可以提供从服务器、桌面到应用虚拟化的一体化解决方案。但Citrix既没有VMware广泛的用户群，也没有Microsoft在操作系统市场占有率的优势，XenServer只能在两大厂商的夹缝中寻找生存。Citrix09年3月宣布将XenServer企业版完全免费，或将推动Citrix桌面和应用虚拟化产品销售，在虚拟化市场中占有自己的一席之地。</div>
<div>&nbsp;</div>
<div>虚拟化已成为09年最为热门的技术，从服务器、桌面、应用程序到网络、存储，虚拟化似乎无处不在，一切皆可虚拟化。谁将笑傲江湖，切让我们拭目以待吧。</div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/155138]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[服务器&存储]]></category>
 <pubdate><![CDATA[Mon, 04 May 2009 21:31:19 +0000]]></pubdate>
</item>
<item>
 <title><![CDATA[VMware ESXi Vlan的三种实现方式]]></title>
 <description><![CDATA[<div>在VMware ESX/ESXi网络中vlan实现方式可以分成3种,分别是通过物理交换机, 虚拟交换机(vSwitch) 和ESXi中的虚拟机(vm)来添加vlan标记,具体方式如下:</div>
<div>&nbsp;</div>
<div><font color="#0000ff"><strong>1) EST - External Switch Tagging</strong></font></div>
<div>通过将交换机的端口划分到不同的vlan实现虚拟机的vlan分配.</div>
<div>优点: 与管理物理环境相似,无需在ESXi服务器上配置vlan</div>
<div>缺点: 绑定在同一物理端口的虚拟机只能属于同一vlan</div>
<div>物理交换机配置:&nbsp;&nbsp; switchport mode access</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;switchport access vlan xx</div>
<div>虚拟交换机(vSwitch)配置: 无</div>
<div>虚拟机(vm)配置: 无</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div><font color="#0000ff"><strong>2) VST - Virtual Switch Tagging</strong></font></div>
<div>通过在虚拟交换机中配置多个port group对应多个vlan, 物理交换机启动trunk</div>
<div>优点:VMware推荐的方式,可以在ESXi的一个物理端口支持多个vlan</div>
<div>缺点: 配置比较复杂</div>
<div>物理交换机配置: switchport trunk encap dot1q</div>
<div>虚拟交换机(vSwitch)配置: 在ESXi 'Configuration' - 'Networking' 中选择相应的vSwitch, 在属性中添加多个port group, 每个port group的vlan id对应一个vlan</div>
<div>虚拟机(vm)配置: 无</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div><font style="background-color: #fffafa" color="#0000ff"><strong>3) VGT - Vitual Guest Tagging</strong></font></div>
<div>通过虚拟机来实现标识不同vlan的数据,物理交换机启用trunk</div>
<div>优点:适用于特殊情况,如linux路由器的虚拟机</div>
<div>缺点:需要虚拟机支持802.1q</div>
<div>物理交换机配置: switchport trunk encap dot1q</div>
<div>虚拟交换机(vSwitch)配置:将vSwitch中port group的vlan id改为4095</div>
<div>虚拟机(vm)配置:安装802.1q trunk驱动程序</div>
<div>&nbsp;</div>
<div>参考资料: <font color="#0000ff">[url]www.vmware.com/pdf/esx3_[/url]<b>vlan</b>_wp.pdf </font></div>]]></description>
 <link><![CDATA[http://edwardlee.blog.51cto.com/153979/154966]]></link>
 <author><![CDATA[edwardlee]]></author>
 <category><![CDATA[服务器&存储]]></category>
 <pubdate><![CDATA[Mon, 04 May 2009 10:31:55 +0000]]></pubdate>
</item>
</channel></rss>