Vlan sozdat qilish
1. Switch#vlan database (Ma’lumotlar bazasida vlan yarat degani)
2. Switch(vlan)#vlan 10 name tatu1 (vlanga name berish)
2-yo’li
1. Switch(config)#vlan 10
2.Switch(config-vlan)#name tatu1
Vlanni access portga ilish
1. Switch(config)#interface fastEthernet 0/1 (1-portga murojaat)
2.Switch(config-if)#switchport mode access (1 ta vlan kanal bo’lsa access bo’ladi)
3.Switch(config-if)#switchport access vlan 10 (vlan 10 ni shu portga ilish)
Vlanni trunk portga ilish
1. Switch(config)#interface fastEthernet 0/24 (24-portga murojaat)
2.Switch(config-if)#switchport mode trunk (1 ta linkni logicheskiy vlanlarga bo’lish,trunk kanalida bir nechta vlanlar harakatlanadi)
3.Switch(config-if)#switchport trunk allowed vlan 1,10,20,30 (trunk kanaliga vlanlarni ilish)
4.Switch(config-if)#switchport trunk allowed vlan add 40 (misol yangi vlan 40 ni qo’shish)
5. Switch(config-if)#switchport trunk allowed vlan remove 40 (VLAN 40 ni olib tashash)
Vlanlarning asosiy ustunligi xavfsizlik tomondan ishonchli
Native vlanni portga ilish
1. Switch(config)#interface fastEthernet 0/24
Switch(config-if)#switchport mode trunk
Switch(config-if)#switchport trunk native vlan 99 (native vlanni vlan 1 dan vlan 99 ga ko’chiramiz.Native vlan hech qaysi servisda bo’lmasin shunda hech biriga kirolmaydi)
Praktika
Routerdan DHCP tarqatish
1.Router(config)#service dhcp (DHCP servicega murojaat)
2. Router(config)#ip dhcp pool Tatu220 (DHCP tarqatuvchi pool to’plam nomi)
3. Router(dhcp-config)#network 192.168.1.0 255.255.255.0 (Qanaqa tarmoqqa tarqatayotgani)
4. Router(dhcp-config)#default-router 192.168.1.1 (Gateway)
5. Router(dhcp-config)#dns-server 10.0.2.2 (DNS ni ip sini ko’rsatish)
6. Router(config)#ip dhcp excluded-address 192.168.1.1 192.168.1.7 (shu oraliqdagi ip larni dynamic tarqatmaydi)
Dynamic NAT configuration
Router(config)#ip nat pool LAN1 195.158.1.10 195.158.1.17 netmask 255.255.255.0
(Ya’ni 1 ta pool olamiz uni LAN1 shkaf deb qa’bul qilamiz va uni birinchi kelgan 8 ta odam kiyib ketadi)
2. Router(config)#access-list 10 permit 192.168.1.8 0.0.0.7 (ACCESS LIST routerni ishini yengillashtiradi.Doim ACL ga tushirishga harakat qilish kerak///kimlar kurtkani kiyishini listga yozamiz)
3. Router(config)#ip nat inside source list 10 pool LAN1 (va Aynan o’sha listni LAN1 shkafga ilib qo’yamiz,yani dustup borlar kelib kiyib chiqaveradi)
4. Router#show ip nat translations (NAT tablitsani ko’rish)
5. Router#clear ip nat translation * (NAT tablitsani o’chirish va aynan bizga kerakliligini topish uchun xizmat qiladi)
6. Router#show ip nat statistics
PAT(PORT ADDRESS TRANSLATION) configuration
1. Router(config)#access-list 10 permit 192.168.1.0 0.0.0.255 (ACL yaratamiz)
2. Router(config)#ip nat inside source list 10 interface gigabitEthernet 0/0 overload
(PAT ni oldiga ACL ni qo’yamiz va chiqish interface ni yozamiz overload qilamiz)
PAT ni dynamic qilib olish
Router(config)#ip nat pool GLOBALIP 195.158.1.10 195.158.1.15 netmask 255.255.255.0
(pool qilib olamiz va portlar tugagandan so’ng,ikkinchi diapozonga o’tadi)
Router(config)#ip nat inside source list 10 pool GLOBALIP overload
(10-ACL dan o’tgani GLOBALIP dan olib tashqariga chiqib ketaveradi)
Propros portov(portni yo’naltirish
Router(config)#ip nat inside source static tcp 192.168.1.201 23 195.158.1.201 2001
(telnetga netdan portni o’zgartirib kirish),http 80,https 443 shunaqa
Sw dan FTP serverga qilingan konfiguratsiyalarni ko’chirish
1. Switch(config)#ip ftp username Utkir (Serverdagi faylni nomi)
2. Switch(config)#ip ftp password 123 (Serverdagi faylni kodi)
3. Switch#show flash: (faylni ko’rib copy qilib olish)
4. Switch#copy flash: ftp: (Sw ni flash xotirasidan ftp ga faylni yuklash)
Source filename []? config.text (copy qilingan faylni nomi)
Address or name of remote host []? 195.158.114.2 (ftp serverni nomi yoki ip si)
Destination filename [config.text]? Utkir (ftp faylida qanday nom bilan saqlanishi)
Do'stlaringiz bilan baham: |