ÎÞ·¨Í¨¹ýCLIÖÎÀí×°±¸
Ò»¡¢Õ÷ÏóÐÎò
×°±¸ÓÐËÄÖֵǼ·½·¨£ºSSH / TELNET / CONSOLE / WEB
·ºÆðÈçϹÊÕÏ£º
1¡¢CONSOLE¿ÚÎÞ·¨µÇ¼
2¡¢TELNETÎÞ·¨µÇ¼
3¡¢SSHÎÞ·¨µÇ¼
4¡¢WEBÎÞ·¨µÇ¼
¶þ¡¢×éÍøÍØÆË

Èý¡¢¿ÉÄÜÔµ¹ÊÔÓÉ
1¡¢CRTÈí¼þÉèÖòÎÊýÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬»òÕßconsoleÏßÎÊÌâ
2¡¢control-planeեȡµÇ¼ÉèÖ㬣¬£¬£¬£¬£¬£¬£¬ACL¹ýÂËÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬£¬VTYÏß³ÌÕ¼Âú
ËÄ¡¢´¦Öóͷ£°ì·¨
Õ÷Ïó1£ºCONSOLEÎÞ·¨µÇ¼
°ì·¨1¡¢¼ì²é×°±¸µçÔ´µÆÔËÐÐ״̬
1. ¼ì²éPWRµÆ×´Ì¬
µçÔ´Õý³££ºÂÌÉ«³£ÁÁ
µçÔ´¹Ø±Õ»ò¹ÊÕÏ£º²»ÁÁ
±¸×¢£ºÈôÊǵçÔ´µÆ²»ÁÁ£¬£¬£¬£¬£¬£¬£¬£¬Çë¼ì²éµçÔ´ÊÇ·ñÕý³£¼Óµç£¬£¬£¬£¬£¬£¬£¬£¬ÅжÏ×°±¸ÊÇ·ñ±£´æÓ²¼þÎÊÌâµ¼ÖÂÎÞ·¨¼Óµç
2. ¼ì²éSYSµÆ×´Ì¬
Éϵç³õʼ»¯£ºÂÌÉ«ÉÁׯ
³õʼ»¯Íê³É£ºÂÌÉ«³£ÁÁ
¸æ¾¯£ººìÉ«³£ÁÁ
±¸×¢£º¿ÉÒÔ¹Ø×¢consoleÊä³öÈÕÖ¾¾ÙÐÐÅжÏÈí¼þÊÇ·ñ±£´æÒì³£
°ì·¨2¡¢ConsoleÏß²ÎÊýÉèÖÃ
ÈôÊÇʹÓÃCRTÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬ConsoleÏߵǼÐèҪѡÔñ׼ȷµÄcom¿Ú£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°²¨ÌØÂÊΪ9600£¬£¬£¬£¬£¬£¬£¬£¬²»¿É¹´Ñ¡Á÷¿ØÎ»
¶Ë¿Ú¿ÉÒÔͨ¹ýµçÄԶ˵Ä×°±¸ÖÎÀíÆ÷Éó²é
ÈçÏÂͼËùʾ
°ì·¨3¡¢Ìæ»»consoleÏß/×°±¸²âÊÔ
1¡¢Ìæ»»consoleÏß¾ÙÐвâÊÔ£¬£¬£¬£¬£¬£¬£¬£¬ÅжÏÏÂconsoleÏßÊÇ·ñ±£´æÎÊÌâ
2¡¢ÈôÊÇûÓжàÓàconsoleÏߣ¬£¬£¬£¬£¬£¬£¬£¬Ìæ»»ÆäËûÖ§³ÖconsoleµÇ¼µÄ·½·¨²âÊÔ
ÈôÊÇconsole¿ÚÈÔÈ»ÎÞ·¨µÇ¼£¬£¬£¬£¬£¬£¬£¬£¬´°¿ÚûÓÐÊäÈëºÍÊä³ö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܱ£´æconsole±£´æÓ²¼þÎÊÌâ¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔʹÓÃÆäËû·½·¨¾ÙÐеǼ²âÊÔ¡£¡£¡£¡£¡£
Õ÷Ïó2£ºTELNETÎÞ·¨µÇ¼
°ì·¨1¡¢ÅŲéµÇ¼²ÎÊýÉèÖ㨵ص㡢¶Ë¿Ú£©
1¡¢µÇ¼µØµã¹ýʧ
a. consoleÏߵǼ¿ÉÒÔÉó²é½Ó¿ÚµØµã£¬£¬£¬£¬£¬£¬£¬£¬ÏêϸÏÂÁîΪshow ip interface brief
ÈçÉÏÏÖÔÚ2¿ÚΪÄÚÍø¿Ú£¬£¬£¬£¬£¬£¬£¬£¬7¿ÚΪÍâÍø¿ÚµØµã£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÕâÁ½¸ö½Ó¿ÚµÇ¼װ±¸£¬£¬£¬£¬£¬£¬£¬£¬ÍâÍøÓû§Ö»ÄÜͨ¹ýÍâÍø¿ÚµØµãµÇ¼װ±¸
b¡¢ÏëҪȷÈÏÍâÍø¿ÚµØµã£¬£¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔͨ¹ýÄÚÍø¿ÚÏȵǼװ±¸ºó£¬£¬£¬£¬£¬£¬£¬£¬È»ºóÔÙÉó²é¶ÔÓ¦µÄÍâÍø¿ÚµØµã£¬£¬£¬£¬£¬£¬£¬£¬
·¾¶£ºÍøÂç—½Ó¿ÚÉèÖ×¶ÔÓ¦ÍâÍø¿Ú
Ôö²¹£ºtelnetµÄ¶Ë¿ÚĬÒÔΪ23£¬£¬£¬£¬£¬£¬£¬£¬telnet ¶Ë¿ÚÊÇÎÞ·¨Ð޸ĵÄ
°ì·¨2¡¢ÅŲé×°±¸ÉÏÇå¾²ÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬£¬Õ¥È¡µÇ¼£¬£¬£¬£¬£¬£¬£¬£¬ACL¹ýÂË
1. ÍâµØ·À¹¥»÷ÉèÖÃեȡtelnetµÇ¼²Ù×÷£¬£¬£¬£¬£¬£¬£¬£¬Ïêϸ·¾¶ÎªÇå¾²—ÍâµØ·À¹¥»÷—եȡÄÚÍø/ÍâÍøµÇ¼װ±¸
¶ÔÓ¦ÏÂÁîΪ£º
control-plane
security deny lan-telnet-ssh-----եȡÄÚÍøtelnetºÍsshµÇ¼װ±¸
security deny wan-telnet-ssh-----եȡÍâÍøtelnetºÍsshµÇ¼Éè
2. ÔÚ½Ó¿ÚŲÓûòip session filterŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
a. ½Ó¿Ú»á¼ûÁбíϵÄŲÓ㬣¬£¬£¬£¬£¬£¬£¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
b. Ip session filter Á÷¹ýÂ˲Ù×÷£¬£¬£¬£¬£¬£¬£¬£¬È«¾ÖŲÓ㬣¬£¬£¬£¬£¬£¬£¬È«¾ÖÉúЧ£¬£¬£¬£¬£¬£¬£¬£¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
c. Line vtyÏÂŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄÍø¶Î»á¼û×°±¸£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÎÞ·¨telnet
ËùŲÓõÄACL161ÐèÒª·ÅͨµÇ¼װ±¸µÄ¶Ë¿Ú»òIPµØµã
Ïêϸ·¾¶£ºÇå¾²—ACL»á¼ûÁбí
ÉèÖÃÍ꣬£¬£¬£¬£¬£¬£¬£¬ÏÂÁîÐжÔӦϷ¢µÄÏÂÁîÈçÏ£º
°ì·¨3¡¢ÅŲéÓ³É䵼ֵǼ¶Ë¿Ú±»Õ¼ÓÃ
ÏêϸÉèÖÃÈçÏ£ºÄÚÍø·þÎñÆ÷Ó³ÉäʱӳÉäµ½×°±¸µÇ¼¶Ë¿ÚºÃ±È˵23£¬£¬£¬£¬£¬£¬£¬£¬»òÕßÊÇÉèÖÃÁËÕû»úÓ³ÉäÓ³Éäµ½½Ó¿ÚÉÏ£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂ×°±¸µÇ¼¶Ë¿Ú±»Õ¼Ó㬣¬£¬£¬£¬£¬£¬£¬»áµ¼ÖÂ×°±¸ÎÞ·¨µÇ¼£¬£¬£¬£¬£¬£¬£¬£¬
a. ¶Ë¿ÚÓ³ÉäÉèÖÃ
¶ÔÓ¦ÏÂÁîÈçÏ£º
ip nat inside source static tcp 192.168.1.10 23 172.18.161.111 23
b. Õû»úÓ³ÉäÉèÖÃ
¶ÔÓ¦ÏÂÁîÈçÏ£º
ip nat inside source static 192.168.1.10 172.18.161.111 permit-inside
½â¾öÒªÁ죺½«ÍâÍøÓ³Éä¶Ë¿Ú23Ó³ÉäΪ1023µÈ¶Ë¿Ú£¬£¬£¬£¬£¬£¬£¬£¬×èÖ¹¶Ë¿ÚÕ¼ÓÃÎÊÌâ¡£¡£¡£¡£¡£
°ì·¨4¡¢ÅŲé¶àÌõÍâÍøÏßµÄÇéÐÎÏÂûÓпªÆôÔ´½øÔ´³ö
¶àÌõÍâÍøÏßµÄÇéÐÎÏÂûÓпªÆôÔ´½øÔ´³ö£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÍâÍø»á¼ûµ½×°±¸µÄÊý¾ÝÁ÷·ºÆð´Ó½Ó¿Ú7½øÀ´¿ÉÊÇ´Ó½Ó¿Ú6³öÈ¥ÁË¡£¡£¡£¡£¡£ÒÔÊÇÔÚÍâÍø¿ÚÐèÒª¿ªÆôÔ´½øÔ´³ö
Ïêϸ·¾¶ÈçÏ£ºÍøÂç—½Ó¿ÚÉèÖ×¶ÔÓ¦½Ó¿ÚϹ´Ñ¡Ô´½øÔ´³ö
¶ÔÓ¦µÄÏÂÁîÈçÏ£º
°ì·¨5¡¢ÅŲé·þÎñÊÇ·ñÆôÓûòÕßÊÇ·ñ±£´æweb°ü
1¡¢µÇ¼·þÎñûÓпªÆô
ÏêϸÏÂÁÉó²ételnetÊÇ·ñ¿ªÆô——show service
2¡¢Éó²é¶Ë¿ÚÊÇ·ñÕý³£¼àÌý
£¨1£©Show tcp connect £¬£¬£¬£¬£¬£¬£¬£¬LISTEN´ú±í¼àÌý״̬ÊôÓÚÕý³£×´Ì¬

°ì·¨6¡¢VTYÏ̱߳»Õ¼Âú
¿ÉÒÔͨ¹ýshow usersÉó²évtyÕ¼ÓõÄÏß³ÌÊÇ·ñÂúÁË£¬£¬£¬£¬£¬£¬£¬£¬Ä¬ÈÏÊÇ5¸öÏ̡߳£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔͨ¹ýclear line vty ¶ÔÓ¦ÊýÖµ¾ÙÐÐÏß³Ìɨ³ý£¬£¬£¬£¬£¬£¬£¬£¬ÔÙʵÑéµÇ¼¡£¡£¡£¡£¡£
Õ÷Ïó3£ºSSHÎÞ·¨µÇ¼
°ì·¨1¡¢ÅŲéµÇ¼²ÎÊýÉèÖ㨵ص㡢¶Ë¿Ú£©
1¡¢µÇ¼µØµã¹ýʧ
a. consoleÏߵǼ¿ÉÒÔÉó²é½Ó¿ÚµØµã£¬£¬£¬£¬£¬£¬£¬£¬ÏêϸÏÂÁîΪshow ip interface brief
ÈçÉÏÏÖÔÚ2¿ÚΪÄÚÍø¿Ú£¬£¬£¬£¬£¬£¬£¬£¬7¿ÚΪÍâÍø¿ÚµØµã£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÕâÁ½¸ö½Ó¿ÚµÇ¼װ±¸£¬£¬£¬£¬£¬£¬£¬£¬ÍâÍøÓû§Ö»ÄÜͨ¹ýÍâÍø¿ÚµØµãµÇ¼װ±¸
b¡¢ÏëҪȷÈÏÍâÍø¿ÚµØµã£¬£¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔͨ¹ýÄÚÍø¿ÚÏȵǼװ±¸ºó£¬£¬£¬£¬£¬£¬£¬£¬È»ºóÔÙÉó²é¶ÔÓ¦µÄÍâÍø¿ÚµØµã£¬£¬£¬£¬£¬£¬£¬£¬Â·¾¶£ºÍøÂç—½Ó¿ÚÉèÖ×¶ÔÓ¦ÍâÍø¿Ú
¡¾Ôö²¹¡¿£ºSSHµÇ¼¶Ë¿ÚĬÒÔΪ22£¬£¬£¬£¬£¬£¬£¬£¬SSHµÄ¶Ë¿ÚÊÇÎÞ·¨Ð޸ĵÄ
2¡¢SSH·þÎñÐèÒª¿ªÆô
¸Ã¹¦Ð§Ä¿½ñÖ»Ö§³ÖÏÂÁÆô£¬£¬£¬£¬£¬£¬£¬£¬²»Ö§³Öweb¿ªÆô
Ruijie(config)#enable service ssh-server //¿ªÆôSSH·þÎñ
Ruijie(config)#crypto key generate dsa //¼ÓÃÜ·½·¨ÓÐÁ½ÖÖ£ºDSAºÍRSA,¿ÉÒÔËæÒâÑ¡Ôñ
Choose the size of the key modulus in the range of 360 to 2048 for your
Signature Keys. Choosing a key modulus greater than 512 may take a few minutes.
How many bits in the modulus [512]://Ö±½ÓÇûسµ
% Generating 512 bit DSA keys ...[ok]
°ì·¨2¡¢ÅŲé×°±¸ÉÏÇå¾²ÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬£¬Õ¥È¡µÇ¼£¬£¬£¬£¬£¬£¬£¬£¬ACL¹ýÂË
1¡¢ÍâµØ·À¹¥»÷ÉèÖÃեȡsshµÇ¼µÈ²Ù×÷£¬£¬£¬£¬£¬£¬£¬£¬Ïêϸ·¾¶ÎªÇå¾²—ÍâµØ·À¹¥»÷—եȡÄÚÍø/ÍâÍøµÇ¼װ±¸
¶ÔÓ¦ÏÂÁîΪ£º
control-plane
security deny lan-telnet-ssh-----եȡÄÚÍøtelnetºÍsshµÇ¼װ±¸
security deny wan-telnet-ssh-----եȡÍâÍøtelnetºÍsshµÇ¼װ±¸
2¡¢ÔÚ½Ó¿ÚŲÓûòip session filterŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
a. ½Ó¿Ú»á¼ûÁбíϵÄŲÓ㬣¬£¬£¬£¬£¬£¬£¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
2¡¢ Ip session filter Á÷¹ýÂ˲Ù×÷£¬£¬£¬£¬£¬£¬£¬£¬È«¾ÖŲÓ㬣¬£¬£¬£¬£¬£¬£¬È«¾ÖÉúЧ£¬£¬£¬£¬£¬£¬£¬£¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
3¡¢ Line vtyÏÂŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄÍø¶Î»á¼û×°±¸£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÎÞ·¨telnet

ËùŲÓõÄACL161ÐèÒª·ÅͨµÇ¼װ±¸µÄ¶Ë¿Ú»òIPµØµã
Ïêϸ·¾¶£ºÇå¾²—ACL»á¼ûÁбí
ÉèÖÃÍ꣬£¬£¬£¬£¬£¬£¬£¬ÏÂÁîÐжÔӦϷ¢µÄÏÂÁîÈçÏ£º
°ì·¨3¡¢ÅŲéÓ³É䵼ֵǼ¶Ë¿Ú±»Õ¼ÓÃ
ÏêϸÉèÖãºÄÚÍø·þÎñÆ÷Ó³ÉäʱӳÉäµ½×°±¸µÇ¼¶Ë¿ÚºÃ±È˵22£¬£¬£¬£¬£¬£¬£¬£¬»òÕßÊÇÉèÖÃÁËÕû»úÓ³ÉäÓ³Éäµ½½Ó¿ÚÉÏ£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂ×°±¸µÇ¼¶Ë¿Ú±»Õ¼Ó㬣¬£¬£¬£¬£¬£¬£¬»áµ¼ÖÂ×°±¸ÎÞ·¨µÇ¼£¬£¬£¬£¬£¬£¬£¬£¬
1¡¢¶Ë¿ÚÓ³ÉäÉèÖÃ
¶ÔÓ¦ÏÂÁîÈçÏ£ºip nat inside source static tcp 192.168.1.10 22 172.18.161.111 22
2. Õû»úÓ³ÉäÉèÖÃ
¶ÔÓ¦ÏÂÁîÈçÏ£ºip nat inside source static 192.168.1.10 172.18.161.111 permit-inside
½â¾öÒªÁ죺½«ÍâÍøÓ³Éä¶Ë¿Ú22Ó³ÉäΪ1022¶Ë¿Ú£¬£¬£¬£¬£¬£¬£¬£¬×èÖ¹¶Ë¿ÚÕ¼ÓÃÎÊÌâ
°ì·¨4¡¢ÅŲé¶àÌõÍâÍøÏßµÄÇéÐÎÏÂûÓпªÆôÔ´½øÔ´³ö
¶àÌõÍâÍøÏßµÄÇéÐÎÏÂûÓпªÆôÔ´½øÔ´³ö£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÍâÍø»á¼ûµ½×°±¸µÄÊý¾ÝÁ÷·ºÆð´Ó½Ó¿Ú7½øÀ´¿ÉÊÇ´Ó½Ó¿Ú6³öÈ¥ÁË¡£¡£¡£¡£¡£
ÒÔÊÇÔÚÍâÍø¿ÚÐèÒª¿ªÆôÔ´½øÔ´³ö£¬£¬£¬£¬£¬£¬£¬£¬
Ïêϸ·¾¶£ºÍøÂç—½Ó¿ÚÉèÖ×¶ÔÓ¦½Ó¿ÚϹ´Ñ¡Ô´½øÔ´³ö
¶ÔÓ¦µÄÏÂÁîÈçÏ£º
°ì·¨5¡¢ÅŲé·þÎñÊÇ·ñÆôÓûòÕßÊÇ·ñ±£´æweb°ü
1¡¢µÇ¼·þÎñûÓпªÆô£¬£¬£¬£¬£¬£¬£¬£¬
ÏêϸÏÂÁÉó²ételnet»òSSHÊÇ·ñ¿ªÆô——show service
2¡¢Éó²é¶Ë¿ÚÊÇ·ñÕý³£¼àÌý
show tcp connect £¬£¬£¬£¬£¬£¬£¬£¬LISTEN´ú±í¼àÌý״̬ÊôÓÚÕý³£×´Ì¬
°ì·¨6¡¢VTYÏ̱߳»Õ¼Âú
¿ÉÒÔͨ¹ýshow usersÉó²évtyÕ¼ÓõÄÏß³ÌÊÇ·ñÂúÁË£¬£¬£¬£¬£¬£¬£¬£¬Ä¬ÈÏÊÇ5¸öÏ̡߳£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔͨ¹ýclear line vty ¶ÔÓ¦ÊýÖµ¾ÙÐÐÏß³Ìɨ³ý£¬£¬£¬£¬£¬£¬£¬£¬ÔÙʵÑéµÇ¼¡£¡£¡£¡£¡£
Îå¡¢ÐÅÏ¢ÍøÂç
×¢ÖØ£ºÒÔÏÂÏÂÁîÊÊÓÃÓÚtelnet¡¢sshÎÞ·¨µÇ¼£¬£¬£¬£¬£¬£¬£¬£¬µ«ÉèÖÿڿÉÒԵǼµÄÇéÐΣ¬£¬£¬£¬£¬£¬£¬£¬ÈôÉèÖÿÚÒ²ÎÞ·¨µÇ¼£¬£¬£¬£¬£¬£¬£¬£¬ÇëʵʱÁªÏµ400¹¤³Ìʦ´¦Öóͷ£¡£¡£¡£¡£¡£
sh ver
sh run
sh service
sh users
sh int usage
sh tcp connect
sh memory
sh cpu | ex 0.00
sh log rev
show int usage
sh envir
sh ip fpm sta
debug su
execute diagnose-cmd fdisk
execute diagnose-cmd mount
exit
Áù¡¢×ܽáÓ뽨Òé
µ±µçÄÔÎÞ·¨ÖÎÀí×°±¸£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓÅÏȼì²éSESSION FILTERŲÓõÄACLÊÇ·ñ¾ÙÐÐÁËÏÞÖÆ¡£¡£¡£¡£¡£ÈôÊÇûÓÐÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýshow usersºÍshow ip fpm flow | in ²âÊÔµçÄÔIP£¬£¬£¬£¬£¬£¬£¬£¬À´ÅжÏÊý¾ÝÊÇ·ñµ½µÖ´ïEG¡£¡£¡£¡£¡£
¡¾Ôö²¹¡¿Èçδ½â¾ö»òÐèÒªÏàʶ¸ü¶àÏêÇ飬£¬£¬£¬£¬£¬£¬£¬¿Éµã»÷ÊÛºóÉÁµçÍþÙÐÐ×Éѯ