Juniper_华为_H3C设备维护常用命令

合集下载

Juniper DX常用维护命令

Juniper DX常用维护命令

Juniper DX常用维护命令1.使用CONFIGURE命令完成对ETH0的配置2.使用HTTP://IP地址:8090登陆设备;admin / admin3.通过WEB界面来对EHT2进行配置:admin---network---4.在SHARE SETTING里可设置DEFAULT GA TEW AY,DNSNAME,DNSIP 5.在services里可配置负载均衡和加速:Cluster:对HTTP和HTTPS来实现负载均衡和加速Forward:对非HTTP协议实现SSL终结和负载均衡SLB:对TCP/UDP协议实现负载均衡Redirector:实现重定向服务6.点击NEW CLUSTER7.ADMIN-----FAILOVER,配置FAILOVER服务在配置failover服务时,要注意以下三个关键参数:1.Failover: Enabled 启用failover服务2.Discovery Interface: ether2 选择侦听对端DX状态的物理端口3.Static Peers: 配置对端DX地址以及监听对端DX的端口IP Address 10.126.1.27Listen Port 9500List file 显示证书文件名SHOW FILE 《文件名》显示证书文件的内容CAPTURE FILE 《文件名》创建证书文件Show boot显示OSSet boot <1或2>选择使用哪个OS启动Install (机器上有UPGRADE FILE 的相应文件,并开启FTTP服务)常用命令:Show capacity 1 每几秒一次,显示CPU,MEM的利用率Show netstat 1看流量ERR不能出现数字,有的话就是接口的匹配问题Show ether 2看断口的MEDIA是什么?Set ether 0 + tab或问号media (数字)Show server status看状态没有FAILOVER的情况,可能FAILOVER与异常1.Show server status2.Tsdump 向TFTP送数据3.Show system debug4.Show failover stats; show activen stats5.Set failover disable6.Set activen disable7.Set server down8.Write9.Set failover enable10.Set activen enable11.Set server upCluster 如果起用STICKY,那么在做ACTIVEN的时候要ENABLE STICKYSYNC同步的时候:1.手工修改DX2上的FAILOVER参数2.先DISABLE FORCE MASTER(防止切换)3.增加FAILOVER PEER:IP OF ANOTHER DX4.SHOW SYNC GROUP (名字)5.SHOW ACTIVEN BLADETSDUMPtcpdumpApplication layer:Show cluster cisapp-http (stats –(http io)Show server stats (io http ssl )dx2% show cluster cisapp-http sticky clientip entriesThere are 3253 sticky entries, it may take a long time to display all the entries Are you sure you want to continue (y/n)? [n] yTotal entries: 3251Timeout IdleClient Sticky Target (sec) (sec)--------------------------------------------------------10.148.0.10 10.137.249.3 3660 90210.148.0.13 10.137.249.3 3660 244010.136.128.16 10.137.249.67 3660 310.148.0.18 10.137.249.62 3660 298010.148.0.19 10.137.249.63 3660 510.148.0.21 10.137.249.66 3660 242910.148.0.23 10.137.249.64 3660 710.148.0.29 10.137.249.5 3660 179810.148.0.31 10.137.249.66 3660 24010.148.0.32 10.137.249.67 3660 23910.148.0.34 10.137.249.6 3660 124610.148.0.38 10.137.249.5 3660 27510.148.0.39 10.137.249.63 3660 109610.148.0.40 10.137.249.64 3660 23810.148.0.41 10.137.249.65 3660 010.148.0.45 10.137.249.67 3660 57010.148.0.51 10.137.249.4 3660 710.148.0.53 10.137.249.5 3660 2310.148.0.59 10.137.249.63 3660 39710.148.0.63 10.137.249.68 3660 257310.148.0.74 10.137.249.6 3660 2610.148.0.82 10.137.249.5 3660 31010.148.0.92 10.137.249.4 3660 15610.148.0.99 10.137.249.64 3660 1010.147.128.104 10.137.249.6 3660 2810.147.128.108 10.137.249.3 3660 7510.137.128.134 10.137.249.63 3660 155110.147.129.147 10.137.249.65 3660 18110.147.129.155 10.137.249.5 3660 1210.147.129.159 10.137.249.68 3660 200810.147.129.177 10.137.249.4 3660 010.137.129.203 10.137.249.64 3660 58910.137.129.205 10.137.249.4 3660 229710.147.129.209 10.137.249.68 3660 172710.147.129.216 10.137.249.67 3660 237510.147.129.217 10.137.249.5 3660 192310.147.129.220 10.137.249.3 3660 241110.147.129.223 10.137.249.3 3660 16810.147.129.225 10.137.249.68 3660 108 10.147.129.227 10.137.249.6 3660 1923 10.147.129.228 10.137.249.62 3660 2219 10.147.129.232 10.137.249.63 3660 1756 10.147.129.233 10.137.249.66 3660 105 10.147.129.234 10.137.249.3 3660 6 10.147.129.235 10.137.249.66 3660 4 10.147.129.239 10.137.249.65 3660 931 10.147.129.241 10.137.249.62 3660 193 10.147.129.243 10.137.249.67 3660 125dx2% show server stats ioIO Statistics - server listenBytes In (Req from Clients) 23.84GBBytes Out (Resp to Clients) 149.97GBCurrent Client Connections 1.50KTotal Client Connections 6.08MRefused Client Connections 34Client IP Sticky To Dead Target 447Client IP Sticky To Deleted Target 54IO Statistics - server service allBytes In (Resp from Servers) 276.47GBBytes Out (Req to Servers) 26.41GBClient IP Sticky To Down Target Service 1.38KIO Statistics - server physical target allCurrent Active Server Conns 58Current Idle Server Conns 233Total Server Connections 33.55MTotal Server Connections Failures 380.65KConsecutive Connection Successes 19.58MConsecutive Connection Failures 334.57KTotal SSL Successes 0 Total SSL Failures 0Maximum Connection Limit Reached 0 Passed Connect Health Chks (Server OK) 2.67MFailed Connect Health Chks (Server Down) 64.68K Passed Request Health Chks (Server OK) 286.57KFailed Request Health Chks (Server Down) 40dx2% show cluster cisapp-http stats ioIO Statistics - cluster cisapp-http listenCurrent State UpBytes In (Req from Clients) 5.70GBBytes Out (Resp to Clients) 33.77GBCurrent Client Connections 1.21KTotal Client Connections 1.39MRefused Client Connections 0Client IP Sticky To Deleted Target 0Client IP Sticky To Dead Target 1IO Statistics - cluster cisapp-http service allBytes In (Resp from Servers) 64.56GBBytes Out (Req to Servers) 6.31GBClient IP Sticky To Down Target Service 0IO Statistics - cluster cisapp-http physical target allCurrent Active Server Conns 24Current Idle Server Conns 53Total Server Connections 24.27MTotal Server Connections Failures 185.45KConsecutive Connection Successes 17.80MConsecutive Connection Failures 167.49KTotal SSL Successes 0 Total SSL Failures 0Maximum Connection Limit Reached 0Passed Connect Health Chks (Server OK) 0Failed Connect Health Chks (Server Down) 29.28KPassed Request Health Chks (Server OK) 87.23KFailed Request Health Chks (Server Down) 0dx1% tcpdump -i ether2Byte counter will be refeshed after 16KB chunks are read.^Ctes processed: 884736Closing tcpdump...Done.Successfully wrote 'tcpdump.0802190435-67' (866KB)dx1% copy tcpdump tcpdump.0802190435-67 tftp://10.137.249.52/tcpdumptestnegotiated TFTP blocksize is 8192 bytes...Done. 887148 bytes transferred.dx1% show tcpdumpdx1% copy tcpdump tcpdump.0802190435-67 tftp://X.X.X.X/filenameAvailable files:tcpdump.0802190435-67 (866KB)Usage: show tcpdump [<tcpdump file>] [-s <keyfile>]dx1% show tcpdump tcpdump.0802190435-6719:04:25.875748 10.137.249.60.22 > 10.136.33.72.3758: P 4022673374:4022673394(20) ack 355801474 win 58400 (DF) [tos 0x10]19:04:25.993984 10.137.249.64.7028 > 10.137.249.60.45048: F 408258459:408258459(0) ack 2621470207 win 2044 <nop,nop,timestamp 1819819:04:25.994012 10.137.249.60.45048 > 10.137.249.64.7028: . ack 1 win 56967 <nop,nop,timestamp 903590 1819827395> (DF)19:04:25.994058 10.137.249.60.45048 > 10.137.249.64.7028: F 1:1(0) ack 1 win 56967 <nop,nop,timestamp 903590 1819827395> (DF)19:04:25.994106 10.137.249.60.45317 > 10.137.249.64.7028: S 1519898316:1519898316(0) win 57344 <mss 1460,nop,nop,sackOK,nop,wscale19:04:25.994233 10.137.249.64.7028 > 10.137.249.60.45048: . ack 2 win 2044 <nop,nop,timestamp 1819827395 903590> (DF)19:04:25.994238 10.137.249.64.7028 > 10.137.249.60.45317: S 463799572:463799572(0) ack 1519898317 win 5792 <mss 1460,sackOK,timesta19:04:25.994258 10.137.249.60.45317 > 10.137.249.64.7028: . ack 1 win 57344 <nop,nop,timestamp 903590 1819827395> (DF)19:04:25.994606 10.137.249.64.7028 > 10.137.249.60.45263: F 453024392:453024392(0) ack 516116623 win 1448 <nop,nop,timestamp 18198219:04:25.994616 10.137.249.60.45263 > 10.137.249.64.7028: . ack 1 win 57343 <nop,nop,timestamp 903590 1819827396> (DF)19:04:25.994650 10.137.249.60.45263 > 10.137.249.64.7028: F 1:1(0) ack 1 win 57343 <nop,nop,timestamp 903590 1819827396> (DF)19:04:25.994683 10.137.249.60.45318 > 10.137.249.64.7028: S 877407194:877407194(0) win 57344 <mss 1460,nop,nop,sackOK,nop,wscale 0,19:04:25.994732 10.137.249.64.7028 > 10.137.249.60.45262: F 447649295:447649295(0) ack 4009036855 win 1448 <nop,nop,timestamp 1819819:04:25.994736 10.137.249.64.7028 > 10.137.249.60.45263: . ack 2 win 1448 <nop,nop,timestamp 1819827396 903590> (DF)19:04:25.994746 10.137.249.60.45262 > 10.137.249.64.7028: . ack 1 win 57343 <nop,nop,timestamp 903590 1819827396> (DF)19:04:25.994766 10.137.249.60.45262 > 10.137.249.64.7028: F 1:1(0) ack 1 win 57343 <nop,nop,timestamp 903590 1819827396> (DF)19:04:25.994786 10.137.249.60.45319 > 10.137.249.64.7028: S 3792145687:3792145687(0) win 57344 <mss 1460,nop,nop,sackOK,nop,wscale19:04:25.994856 10.137.249.64.7028 > 10.137.249.60.45318: S 452566851:452566851(0) ack 877407195 win 5792 <mss 1460,sackOK,timestam19:04:25.994861 10.137.249.64.7028 > 10.137.249.60.45262: . ack 2 win 1448 <nop,nop,timestamp 1819827396 903590> (DF)19:04:25.994872 10.137.249.60.45318 > 10.137.249.64.7028: . ack 1 win 57344 <nop,nop,timestamp 903590 1819827396> (DF)19:04:25.994981 10.137.249.64.7028 > 10.137.249.60.45319: S 452116455:452116455(0) ack 3792145688 win 5792 <mss 1460,sackOK,timesta19:04:25.994991 10.137.249.60.45319 > 10.137.249.64.7028: . ack 1 win 57344 <nop,nop,timestamp 903590 1819827396> (DF)19:04:26.090673 10.136.33.72.3758 > 10.137.249.60.22: . ack 20 win 15600 (DF)。

H3C设备常规巡检命令

H3C设备常规巡检命令

H3C设备常规巡检命令一.巡检基础命令:#系统时间display clock#系统以及各单板软件版本display version#设备温度display environment#日志信息display logbuffer#单板运行状态display device#电源状态display device#风扇状态display device#CPU占用状态display cpu-usage#内存占用率display memory limit#接口流量display interface#接口、链路状态display interface#地址分配display current-configuration interface##路由扩散display current-configuration | include ospf #OSPF(Open Shortest Path First)配置display router id#路由信息display ip routing-table#端口统计数据display ip interface#当前配置文件display current-configuration#保存配置文件display saved-configuration2、脚本—华为display versiondis patch-informationdisplay clockdis dustproofdis frame-typedis healthdisplay cpu-usage display memory display memory limit display devicedisplay device manuinfo display powerdisplay fandisplay voltagedir cfcard2:/dir cfcard:display device pic-status dis switchover state display environment display interface display logbufferdis alarmdis bootrom ethernetdisplay current-configurationdisplay current-configuration interface#display router iddisplay ip routing-tabledisplay ip interfacedisplay ip interface briefdisplay current-configurationdisplay saved-configurationdisplay diagnostic-information3、华为NE40edisplay version 查看VRP版本等信息dis patch-information 查看版本补丁display clock查看时钟dis dustproof防尘网信息Dis frame-type显示NE40E机框类型dis health显示系统资源的使用情况display cpu-usage 查看1分钟CPU利用率display memory查看内存使用情况display memory limitdisplay device查看母板信息。

华三常用命令总结

华三常用命令总结
9.虚链路
进入凌驾区域vlink-peer对端的router-id
认证ospf只支持区域认证
进入区域下开启认证
area 0
authentication simple/md5
进入接口下
ospf authentication-mode simple /md5 1密码
ospf 1 router-id
进去相应的区域模式
area区域id
区域模式下
network直连反掩码宣告直连网段
4.路由引入/重发布
在路由协议模式下
import-route协议名称协议号码cosip下default-route originate
ospf协议default-route-advertise always
rip启动协议
version 1/2开启版本
undo summary关闭汇总
network直连通告网段---主类
认证和汇总接口模式下rip authentication simple密码---明文+两端都配
rip summary-address汇总地址掩码/cidr
3.ospf配置ospf
启动ospf协议
华三、华为常用命令总结
1.基础配置
路由器的视图模式更改
用户模式sys
更改主机名sys +主机名
进入接口interface接口名称
配置ip地址接口模式下ip address ip地址掩码/cidr
指定静态路由ip route目标地址掩码/cidr下一跳ip地址priority值(1-255)
2.rip的配置
6.ospf的网络类型更改--更改优先级
接口模式下ospf dr-priority优先级

华三华为交换机路由器配置常用命令

华三华为交换机路由器配置常用命令

华三华为交换机路由器配置常⽤命令H3C交换机配置命令⼤全1、system-view 进⼊系统视图模式2、sysname 为设备命名3、display current-configuration 当前配置情况4、 language-mode Chinese|English 中英⽂切换5、interface Ethernet 1/0/1 进⼊以太⽹端⼝视图6、 port link-type Access|Trunk|Hybrid 设置端⼝访问模式7、 undo shutdown 打开以太⽹端⼝8、 shutdown 关闭以太⽹端⼝9、 quit 退出当前视图模式10、 vlan 10 创建VLAN 10并进⼊VLAN 10的视图模式11、 port access vlan 10 在端⼝模式下将当前端⼝加⼊到vlan 10中12、port E1/0/2 to E1/0/5 在VLAN模式下将指定端⼝加⼊到当前vlan中13、port trunk permit vlan all 允许所有的vlan通过H3C路由器配置命令⼤全1、system-view 进⼊系统视图模式2、sysname R1 为设备命名为R13、display ip routing-table 显⽰当前路由表4、 language-mode Chinese|English 中英⽂切换5、interface Ethernet 0/0 进⼊以太⽹端⼝视图6、 ip address 192.168.1.1 255.255.255.0 配置IP地址和⼦⽹掩码7、 undo shutdown 打开以太⽹端⼝8、 shutdown 关闭以太⽹端⼝9、 quit 退出当前视图模式10、 ip route-static 192.168.2.0 255.255.255.0 192.168.12.2 description To.R2 配置静态路由11、 ip route-static 0.0.0.0 0.0.0.0 192.168.12.2 description To.R2 配置默认的路由H3C S3100 SwitchH3C S3600 SwitchH3C MSR 20-20 Router1、调整超级终端的显⽰字号;2、捕获超级终端操作命令⾏,以备⽇后查对;3、 language-mode Chinese|English 中英⽂切换;4、复制命令到超级终端命令⾏,粘贴到主机;5、交换机清除配置 :reset save ;reboot ;6、路由器、交换机配置时不能掉电,连通测试前⼀定要检查⽹络的连通性,不要犯最低级的错误。

Juniper华为H3C设备维护通用命令

Juniper华为H3C设备维护通用命令

Juniper华为H3C设备维护通用命令Juniper_华为_H3C设备维护常用命令1、[Router&Swithc]华为/H3C设备常规巡检命令#系统时间display clock#系统以及各单板软件版本display version#设备温度display environment#日志信息display logbuffer#单板运行状态display device#电源状态display device#风扇状态display device#CPU占用状态display cpu-usage#内存占用率display memory limit#接口流量display interface#接口、链路状态display interface#地址分配display current-configuration interface##路由扩散display current-configuration | include ospf#OSPF(Open Shortest Path First)配置display router id#路由信息display ip routing-table#端口统计数据display ip interface#当前配置文件display current-configuration#保存配置文件display saved-configuration端口使用状态display interface GigabitEthernet/T en-GigabitEthernet brief VLAN使用状态display ip interface brief2、脚本—华为display versiondis patch-informationdisplay clockdis dustproofdis frame-typedis healthdisplay cpu-usagedisplay memorydisplay memory limitdisplay devicedisplay device manuinfodisplay powerdisplay fandisplay voltagedir cfcard2:/dir cfcard:display device pic-statusdis switchover statedisplay environmentdisplay interfacedisplay logbufferdis alarmdis bootrom ethernetdisplay current-configurationdisplay current-configuration interface#display router iddisplay ip routing-tabledisplay ip interfacedisplay ip interface briefdisplay current-configurationdisplay saved-configurationdisplay diagnostic-information3、脚本—华为NE40edisplay version 查看VRP版本等信息dis patch-information 查看版本补丁display clock 查看时钟dis dustproof 防尘网信息Dis frame-type 显示NE40E机框类型dis health 显示系统资源的使用情况display cpu-usage 查看1分钟CPU利用率display memory 查看内存使用情况display memory limitdisplay device 查看母板信息display device manuinfodisplay power 查看电源状态display fan 查看风扇状态display voltage 查看板卡电压dir cfcard2:/ 查看设备crash信息dir cfcard: 查看设备cf卡信息display device pic-status 查看子卡型号,序列号(NE40E NE80E) dis switchover state 查看引擎HA情况display environmentdisplay interface 查看接口状态display logbuffer 查看日志dis alarm 查看设备告警dis bootrom ethernet 查看设备bootrom信息display current-configuration查看当前配置display current-configuration interface# 查看设备当前接口配置display router id 查看设备路由IDdisplay ip routing-table 查看设备路由display ip interface 查看设备接口情况display ip interface brief 查看设备接口状态display current-configuration 查看设备当前配置display saved-configuration 查看设备内存配置(相当show start)display diagnostic-information 抓取设备完整信息相对于show tech二、JUNIPER设备常用维护巡检命令1、脚本—JUNIPERshow system uptimeshow version detailshow chassis hardware detailshow chassis environment //显示设备的环境信息,包括温度、风扇状况、电源状况、路由引擎状况。

华三华为交换机路由器配置常用命令汇总

华三华为交换机路由器配置常用命令汇总

H3C交换机配置命令大全1、system-view 进入系统视图模式2、sysname 为设备命名3、display current-configuration 当前配置情况4、 language-mode Chinese|English 中英文切换5、interface Ethernet 1/0/1 进入以太网端口视图6、 port link-type Access|Trunk|Hybrid 设置端口访问模式7、 undo shutdown 打开以太网端口8、 shutdown 关闭以太网端口9、 quit 退出当前视图模式10、 vlan 10 创建VLAN 10并进入VLAN 10的视图模式11、 port access vlan 10 在端口模式下将当前端口加入到vlan 10中12、port E1/0/2 to E1/0/5 在VLAN模式下将指定端口加入到当前vlan中13、port trunk permit vlan all 允许所有的vlan通过H3C路由器配置命令大全华为交换机常用配置实例H3C交换机路由器telnet和console口登录配置2009年11月09日星期一 10:00级别说明Level 名称命令0参观ping、tracert、telnet1监控display、debugging2配置所有配置命令管理级的命令除外3管理文件系统命令、FTP命令、TFTP命令、XMODEM命令telnet仅用密码登录,管理员权限Routeruser-interface vty 0 4Router-ui-vty0-4user privilege level3Router-ui-vty0-4set authentication password simple abctelnet仅用密码登录,非管理员权限Routersuper password level 3 simplesuperRouteruser-interface vty 0 4Router-ui-vty0-4user privilege level1Router-ui-vty0-4set authentication password simple abctelnet使用路由器上配置的用户名密码登录,管理员权限Routerlocal-user admin passwordsimple adminRouterlocal-user admin service-type telnetRouterlocal-useradmin level 3Routeruser-interface vty 04Router-ui-vty0-4authentication-mode localtelnet使用路由器上配置的用户名密码登录,非管理员权限Routersuper password level 3 simple superRouterlocal-user manage password simple manageRouterlocal-usermanage service-type telnetRouterlocal-user manage level2Routeruser-interface vty 0 4Router-ui-vty0-4authentication-mode local对console口设置密码,登录后使用管理员权限Routeruser-interface con0Router-ui-console0user privilege level 3Router-ui-console0set authentication password simple abc对console口设置密码,登录后使用非管理员权限Routersuper password level 3 simple superRouteruser-interfacecon 0Router-ui-console0user privilege level 1Router-ui-console0set authentication password simple abc对console口设置用户名和密码,登录后使用管理员权限Routerlocal-user admin password simpleadminRouterlocal-user admin service-type terminalRouterlocal-user adminlevel 3Routeruser-interface con 0Router-ui-console0authentication-modelocal对console口设置用户名和密码,登录后使用非管理员权限Routersuper password level 3 simple superRouterlocal-user manage password simple manageRouterlocal-user manage service-type terminalRouterlocal-usermanage level 2Routeruser-interface con0Router-ui-console0authentication-mode localsimple 是明文显示,cipher 是加密显示路由器不设置telnet登录配置时,用户无法通过telnet登录到路由器上Router-ui-vty0-4acl 2000 inbound可以通过acl的规则只允许符合条件的用户远程登录路由器华为路由器ospfnat。

华为交换机维护检查用到哪些命令精选全文

华为交换机维护检查用到哪些命令精选全文

可编辑修改精选全文完整版华为交换机维护检查用到哪些命令【--分析报告】2、查看设备复位情况,可以用命令display reboot-info。

3、查看设备温度,可以用命令display temperature all。

各模块当前的温度应该在上下限之间,即Current的值在Lower和Upper 之间。

4、查看设备的告警信息,可以用命令display alarm urgent。

如果没有告警就会显示无。

5、查看cpu状态,可以用命令display cpu-usage。

各模块的CPU占用率正常。

如果出现CPU占用率长时间超过80%或者频繁出现超过80%的情况,建议重点关注。

6、查看内存占用情况,可以使用display memory-usage。

7、查看日志信息,可以用display logbuffer或者display trapbuffer。

这两个命令为会经常用到。

相关阅读:交换机工作原理过程交换机工作于OSI参考模型的第二层,即数据链路层。

交换机内部的CPU会在每个端口成功连接时,通过将MAC地址和端口对应,形成一张MAC表。

在今后的通讯中,发往该MAC地址的数据包将仅送往其对应的端口,而不是所有的端口。

因此,交换机可用于划分数据链路层广播,即冲突域;但它不能划分层广播,即广播域。

交换机拥有一条很高带宽的背部总线和内部交换矩阵。

交换机的所有的端口都挂接在这条背部总线上,控制电路收到数据包以后,处理端口会查找内存中的地址对照表以确定目的MAC(网卡的硬件地址)的NIC(网卡)挂接在哪个端口上,通过内部交换矩阵迅速将数据包传送到目的端口,目的MAC若不存在,广播到所有的端口,接收端口回应后交换机会学习新的MAC地址,并把它添加入内部MAC地址表中。

使用交换机也可以把分段,通过对照IP地址表,交换机只允许必要的流量通过交换机。

通过交换机的过滤和转发,可以有效的减少冲突域,但它不能划分层广播,即广播域。

juniper基本维护命令

juniper基本维护命令

show interfaces extensive 查看接口详细信息
show interfaces queue 查看接口的列队统计信息
show interfaces terse 显示接口概要信息
show route <destination> exact detail warding-table destination <destination> 查看某条路由的转发表信息
show ethernet-switching table 显示以太网媒体访问控制列表
run show route forwarding-table 查看转发表
rollback number 配置回滚
show vlans 查看vlan信息
clear interfaces statistics 清除接口的统计计数器
show route 查看路由表
show route summary 显示路由表的汇总信息
show forwarding-options 查看dhcp中继信息
show | display set 查看所有配置(转化为set命令)
show system 查看系统信息
Display brief outputshow interfaces diagnostics optics 查看光口模块信息
show interfaces descriptions 显示接口描述信息
show interfaces brief 查看接口简要信息
show chassis environmen 显示设备的环境信息,包括温度,风扇状态,电源状态,路由因引擎状态等
show chassis alarms 查看系统当前警告
  1. 1、下载文档前请自行甄别文档内容的完整性,平台不提供额外的编辑、内容补充、找答案等附加服务。
  2. 2、"仅部分预览"的文档,不可在线预览部分如存在完整性等问题,可反馈申请退款(可完整预览的文档不适用该条件!)。
  3. 3、如文档侵犯您的权益,请联系客服反馈,我们会尽快为您处理(人工客服工作时间:9:00-18:30)。

Juniper_华为_H3C设备维护常用命令1、[Router&Swithc]华为/H3C设备常规巡检命令#系统时间display clock#系统以及各单板软件版本display version#设备温度display environment#日志信息display logbuffer#单板运行状态display device#电源状态display device#风扇状态display device#CPU占用状态display cpu-usage#存占用率display memory limit#接口流量display interface#接口、链路状态display interface#地址分配display current-configuration interface##路由扩散display current-configuration | include ospf#OSPF(Open Shortest Path First)配置display router id#路由信息display ip routing-table#端口统计数据display ip interface#当前配置文件display current-configuration#保存配置文件display saved-configuration端口使用状态display interface GigabitEthernet/Ten-GigabitEthernet briefVLAN使用状态display ip interface brief2、脚本—华为display versiondis patch-informationdisplay clockdis dustproofdis frame-typedis healthdisplay cpu-usagedisplay memorydisplay memory limitdisplay devicedisplay device manuinfodisplay powerdisplay fandisplay voltagedir cfcard2:/dir cfcard:display device pic-statusdis switchover statedisplay environmentdisplay interfacedisplay logbufferdis alarmdis bootrom ethernetdisplay current-configurationdisplay current-configuration interface#display router iddisplay ip routing-tabledisplay ip interfacedisplay ip interface briefdisplay current-configurationdisplay saved-configurationdisplay diagnostic-information3、脚本—华为NE40edisplay version 查看VRP版本等信息dis patch-information 查看版本补丁display clock 查看时钟dis dustproof 防尘网信息Dis frame-type 显示NE40E机框类型dis health 显示系统资源的使用情况display cpu-usage 查看1分钟CPU利用率display memory 查看存使用情况display memory limitdisplay device 查看母板信息display device manuinfodisplay power 查看电源状态display fan 查看风扇状态display voltage 查看板卡电压dir cfcard2:/ 查看设备crash信息dir cfcard: 查看设备cf卡信息display device pic-status 查看子卡型号,序列号(NE40E NE80E)dis switchover state 查看引擎HA情况display environmentdisplay interface 查看接口状态display logbuffer 查看日志dis alarm 查看设备告警dis bootrom ethernet 查看设备bootrom信息display current-configuration查看当前配置display current-configuration interface# 查看设备当前接口配置display router id 查看设备路由IDdisplay ip routing-table 查看设备路由display ip interface 查看设备接口情况display ip interface brief 查看设备接口状态display current-configuration 查看设备当前配置display saved-configuration 查看设备存配置(相当show start)display diagnostic-information 抓取设备完整信息相对于show tech二、JUNIPER设备常用维护巡检命令1、脚本—JUNIPERshow system uptimeshow version detailshow chassis hardware detailshow chassis environment //显示设备的环境信息,包括温度、风扇状况、电源状况、路由引擎状况。

show chassis routing-engineshow chassis firmwareshow configurationshow chassis fpc detailshow interfaceshow interfaces terseshow chassis alarmsshow system alarmsshow log messages|no-moreshow log chassisd|no-moreshow log logfile Displaysshow chassis sfm Reportsshow system boot-messagesshow system core-dumpsshow system processes extensiveshow pfe statistics errorshow chassis routing-engineshow system storageshow system virtual-memoryshow system buffershow system queuesshow system statisticsshow configuration | except SECRET-DATAshow interfaces extensiveshow chassis hardware extensive2、脚本—Juniper Firewallget systemget configget log eventget filiterget per cpu detailget session infoget per session detailget mac-learnget alarm eventget techget log systemget chassis基本命令1.get int 查看接口配置信息2.get int eth x/x 查看指定接口配置信息3.get mip 查看映射ip关系4.get route 查看路由表5.get policy id x 查看指定策略6.get nsrp 查看nsrp信息,后可接参数查看具体vsd组、端口监控设置等7.get per cpu de 查看cpu利用率信息8.get per session de 查看每秒新建会话信息9.get session 查看当前会话信息,后可匹配源地址、源端口、目的地址、目的端口、协议等选项10.g et session info 查看当前会话数量11.get system 查看系统信息、包括当前OS版本,接口信息,设备运行时间等12.g et chaiss 查看设备及板卡序列号,查看设备运行温度13.g et counter stat 查看所有接口计数信息14.g et counter stat eth x/x 查看指定接口计数信息15.g et counter flow zone untrust/untrust 查看指定区域数据流信息16.g et counter screen zone untrust/trust 查看指定区域攻击防护统计信息17.g et tech-support 查看设备状态命令集,一般在出现故障时,收集该信息寻求JTAC支持常用设置命令Set int ethx/x zone trust/untrust/dmz/ha配置指定接口进入指定区域(trust/untrust/dmz/ha等)Set int ethx/x ip x.x.x.x/xx 配置指定接口ip地址Set int ethx/x manage配置指定接口管理选项,打开所有管理选项Set int ethx/x manage web/telnet/ssl/ssh 配置指定接口指定管理选项Set int ethx/x phy full 100mb 配置指定接口速率及双工方式Set int ethx/x phy link-down 配置指定接口shutdownSet nsrp vsd id 0 monitor interface ethx/x配置ha监控端口,如此端口断开,则设备发生主/备切换Exec nsrp vsd 0 mode backup手工进行设备主/备切换,在当前的主设备上执行set route 0.0.0.0/0 interface ethernet1/3 gateway 222.92.116.33 配置路由,需同时指定下一跳接口及ip地址所有set命令,都可以通过unset命令来取消,相当于cisco中的no 所有命令都可以通过“TAB”键进行命令补全,通过“?”来查看后续支持的命令防火墙基本配置1.登录create account [admin | user] <username> 回车输入密码:再次输入密码:configure account admin 回车输入密码:再次输入密码:2.port配置config ports <portlist> auto off {speed [10 | 100 | 1000]} duplex [half | full] auto off3.Vlan配置无论是核心还是接入层,都要先创建三个Vlan,并且将所有归于Default Vlan的端口删除:config vlan default del port allcreate vlan Servercreate vlan Usercreate vlan Manger定义802.1q标记config vlan Server tag 10config vlan User tag 20config vlan Manger tag 30设定Vlan网关地址:config vlan Server ipa 192.168.41.1/24config vlan User ipa 192.168.40.1/24config vlan Manger ipa 192.168.*.*/24Enable ipforwarding 启用ip路由转发,即vlan间路由Trunk 配置config vlan Server add port 1-3 tconfig vlan User add port 1-3 tconfig vlan manger add port 1-3 t4.VRRP配置enable vrrpconfigure vrrp add vlan UserVlanconfigure vrrp vlan UserVlan add master vrid 10 192.168.6.254 configure vrrp vlan UserVlan authentication simple-password extremeconfigure vrrp vlan UserVlan vrid 10 priority 200configure vrrp vlan UserVlan vrid 10 advertisement-interval 15 configure vrrp vlan UserVlan vrid 10 preempt5.端口镜像配置首先将端口从VLAN中删除enable mirroring to port 3 #选择3作为镜像口config mirroring add port 1 #把端口1的流量发送到3config mirroring add port 1 vlan default #把1和vlan default的流量都发送到36.port-channel配置enable sharing <port> grouping <portlist> {port-based | address-based | round-robin}show port sharing //查看配置7.stp配置enable stpd //启动生成树create stpd stp-name //创建一个生成树configure stpd <spanning tree name> add vlan <vlan name> {ports <portlist> [dot1d | emistp | pvst-plus]}configure stpd stpd1 priority 16384configure vlan marketing add ports 2-3 stpd stpd1 emistp8.DHCP 中继配置enable bootprelayconfig bootprelay add <dhcp server ip>9.NAT配置Enable nat #启用natStatic NAT Rule Exampleconfig nat add out_vlan_1 map source 192.168.1.12/32 to 216.52.8.32/32Dynamic NAT Rule Exampleconfig nat add out_vlan_1 map source 192.168.1.0/24 to 216.52.8.1 - 216.52.8.31Portmap NAT Rule Exampleconfig nat add out_vlan_2 map source 192.168.2.0/25 to 216.52.8.32 /28 both portmapPortmap Min-Max Exampleconfig nat add out_vlan_2 map source 192.168.2.128/25 to 216.52.8.64/28 tcp portmap 1024 – 819210.OSPF配置enable ospf 启用OSPF进程create ospf area <area identifier> 创建OSPF区域configure ospf routerid [automatic | <routerid>] 配置Routeridconfigure ospf add vlan [<vlan name> | all] area <area identifier> {passive} 把某个vlan加到某个Area中去,相当于Cisco中的network的作用configure ospf area <area identifier> add range <ipaddress> <mask> [advertise | noadvertise] {type-3 | type-7} 把某个网段加到某个Area中去,相当于Cisco中的network的作用configure ospf vlan <vlan name> neighbor add <ipaddress> OSPF中路由重发布配置enable ospf export direct [cost <metric> [ase-type-1 | ase-type-2] {tag <number>} | <route map>]enable ospf export static [cost <metric> [ase-type-1 | ase-type-2] {tag <number>} | <route map>]enable ospf originate-default {always} cost <metric> [ase-type-1 | ase-type-2] {tag <number>}enable ospf originate-router-id11.SNMP配置enable snmp accessenable snmp trapscreate access-profile <access profile> type [ipaddress | vlan]config snmp access-profile readonly [<access_profile> | none]配置snmp的只读访问列表,none是去除config snmp access-profile readwrite [<access_profile> | none] 这是控制读写控制config snmp add trapreceiver <ip address> {port <udp_port>} community <communitystring> {from <source ip address>} 配置snmp接收host和团体字符串12.安全配置disable ip-option loose-source-routedisable ip-option strict-source-routedisable ip-option record-routedisable ip-option record-timestampdisable ipforwarding broadcastdisable udp-echo-serverdisable irdp vlan <vlan name>disable icmp redirectdisable web 关闭web方式访问交换机enable cpu-dos-protect13.Access-Lists配置create access-list icmp destination sourcecreate access-list ip destination source portscreate access-list tcp destination source portscreate access-list udp destination source ports14.默认路由配置config iproute add default <gateway>15.恢复出厂值但不包括用户改的时间和用户信息unconfig switch {all}16.检查配置show versionshow configshow sessionshow management 查看管理信息,以及snmp信息show bannershow ports configurationshow ports utilization ?show memory/show cpu-monitoringshow ospfshow access-list {<name> | port <portlist>}show access-list-monitorshow ospf area <area identifier>show ospf area detailshow ospf ase-summaryshow ospf interfaces {vlan <vlan name> | area <area identifier>} unconfigure ospf {vlan <vlan name> | area <area identifier>} switchshow switchshow configshow diagshow iparpshow iprouteshow ipstatshow logshow tech allshow version detail17.备份和升级软件download image [<hostname> | <ipaddress>] <filename> {primary | secondary}upload image [<hostname> | <ipaddress>] <filename> {primary | secondary}use image [primary | secondary]18.密码恢复。

相关文档
最新文档