1-laboratoriya ishi
Mavzu: Tarmoq qurilmalarida dastlabki xavfsizlik sozlamalarini
o’rnatish - telnet, ssh
Ishdan maqsad: Tarmoq qurilmalarida dastlabki xavfsizlik sozlamalarini telnet va ssh protokollarini sozlashni o’rganish
SSH protokoli
Ishni bajarish tartibi:
1. Ciso packet tracer dasturini ishga tushuramiz.
2. Laboratoriya ishi uchun bitta switch, bitta router, va ikkita kompyuterdan
iborat topologiyani quramiz.
3. Uni qurib ishga tushirib, testlaymiz.
4. Quyidagi oynada keltirilgan kodlarni kiritamiz.
1.Router-1 ga quyidagi buyruqlar ketma-ketligi kiritiladi.
2.Har bir kompyuterda ip manzil berib chiqiladi
3.Topologiya testlab ko’riladi.
Telnet protokoli
Ishni bajarish tartibi:
1.Cisco paket dasturi ishga tushiriladi
2.Labaratoriya ishi uchun bizga 2911 versiyadagi router, 2960 switch, va kompyuterlar kerak bo’ladi
3.Quyidagi keltirilgan topologiya quriladi
4.Qurilgan topologiya testlab ko’riladi
1.Router-1 ga quyidagi buyruqlar ketma-ketligi kiritiladi.
2.Har bir kompyuterda ip manzil berib chiqiladi
3.Topologiya testlab ko’riladi
2-topshiriq
Mavzu:Komutatorlarda Port xavfsizligi (Port Security)ni sozlash
Ishni bajarish tartibi
1.Cisco packet tracer dasturi ishga tushiriladi
2.Labaratoriya ishi uchun bizga 2960 switch va kompyuterlar kerak bo’ladi.
3.Quyida keltirilgan topologiya quriladi
4.Qurilgan topologiya testlab ko’riladi.
1.Switch ga quyida buyruqlar ketma-ketligi kiritiladi.
Switch>en
Switch#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)#inter
Switch(config)#interface fast
Switch(config)#interface fastEthernet 0/1
Switch(config-if)#sw
Switch(config-if)#switchport mode ac
Switch(config-if)#switchport mode access
Switch(config-if)#sw
Switch(config-if)#switchport port
Switch(config-if)#switchport port-security
Switch(config-if)#switchport port
Switch(config-if)#switchport port-security maximum 1
Switch(config-if)#switchport port-security mac-address sticky
Switch(config-if)#switchport port-security violation shutdown
Switch(config-if)#
%LINK-3-UPDOWN: Interface FastEthernet0/1, changed state to down
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to down
%LINK-5-CHANGED: Interface FastEthernet0/1, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to up
2. Har bir kompyuterda ip manzil berib chiqiladi
3. Topologiya testlab ko’riladi
3-topshiriq
Tarmoq qurilmalarini xavfsizligini tahlil qilish
Router>enable
Router#
Router#configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#interface GigabitEthernet0/0
Router(config-if)#ip address 192.168.1.1 255.255.255.0
Router(config-if)#ip address 192.168.1.1 255.255.255.0
Router(config-if)#no shutdown
Router(config-if)#
%LINK-5-CHANGED: Interface GigabitEthernet0/0, changed state to up
Router(config-if)#exit
Router(config)#hostname Sanjar
Sanjar(config)#enable password 111
Sanjar(config)#do wr
Building configuration...
[OK]
Sanjar(config)#line console 0
Sanjar(config-line)#password 111
Sanjar(config-line)#login
Sanjar(config-line)#do wr
Building configuration...
[OK]
Sanjar(config-line)#exit
Sanjar(config)#exit
Sanjar#
%SYS-5-CONFIG_I: Configured from console by console
Sanjar#reload
System configuration has been modified. Save? [yes/no]:yes
Building configuration...
[OK]
Proceed with reload? [confirm]
System Bootstrap, Version 15.1(4)M4, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 2010 by cisco Systems, Inc.
Total memory size = 512 MB - On-board = 512 MB, DIMM0 = 0 MB
CISCO2911/K9 platform with 524288 Kbytes of main memory
Main memory is configured to 72/-1(On-board/DIMM0) bit mode with ECC disabled
Readonly ROMMON initialized
program load complete, entry point: 0x80803000, size: 0x1b340
program load complete, entry point: 0x80803000, size: 0x1b340
IOS Image Load Test
___________________
Digitally Signed Release Software
program load complete, entry point: 0x81000000, size: 0x3bcd3d8
Self decompressing the image :
#################
monitor: command "boot" aborted due to user interrupt
rommon 1 > confreg 0x2142
Router>en
Router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#con
Router(config)#config-register 0x2102
Router(config)#do wr
Building configuration...
[OK]
Do'stlaringiz bilan baham: |