• 如果您有任何疑问或者需要投稿请联系站长,感谢您的访问

  • 如果您有任何问题或者建议可以联系站长,QQ403593407

华为交换机配置端口镜像

教程资源 admin 1年前 (2018-10-01) 365次浏览 0个评论

背景:某单位上架一台内网准入设备,在核心交换上配置端口镜像,将内网进出流量镜像到准入设备监控口进行行为监控,当流量来自不可信终端时候阻口发送 reset 报文进行阻断,并把不可信终端的 http 请求重定向到准入设备上,要求终端安装准入客户端进行认证后才允许入网。

配置思路:配置一个本地观察口,该接口和准入设备的监控口对接,将需要监控的端口流量复制一份到该接口。

操作步骤

1. 使用 Telnet 或者 Console 口登陆到交换机。

2. 配置本地观察口(此处配置 23 口为本地观察口)

<span class="tag"><Huawei></span><span class="pln"> system-view
</span><strong><span class="pln">[Huawei] observe-port 1 interface Gigabitethernet 0/0/23</span></strong>

3. 配置端口镜像,将需要监控和的端口流量复制到观察口(此处配置 GE0/0/1-6 口为镜像端口)

<span class="pun">[</span><span class="typ">Huawei</span><span class="pun">]</span> <span class="kwd">interface</span> <span class="typ">Gigabitethernet</span> <span class="lit">0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">1</span>
<span class="pun">[</span><span class="typ">Huawei</span><span class="pun">-</span><span class="typ">GigabitEthernet0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">1</span><span class="pun">]</span><span class="pln"> port</span><span class="pun">-</span><span class="pln">mirroring to observe</span><span class="pun">-</span><span class="pln">port </span><span class="lit">1</span><span class="pln"> both
</span><span class="pun">[</span><span class="typ">Huawei</span><span class="pun">-</span><span class="typ">GigabitEthernet0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">1</span><span class="pun">]</span><span class="pln"> quit

</span><span class="pun">[</span><span class="typ">Huawei</span><span class="pun">]</span> <span class="kwd">interface</span> <span class="typ">Gigabitethernet</span> <span class="lit">0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">2</span>
<span class="pun">[</span><span class="typ">Huawei</span><span class="pun">-</span><span class="typ">GigabitEthernet0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">2</span><span class="pun">]</span><span class="pln"> port</span><span class="pun">-</span><span class="pln">mirroring to observe</span><span class="pun">-</span><span class="pln">port </span><span class="lit">1</span><span class="pln"> both
</span><span class="pun">[</span><span class="typ">Huawei</span><span class="pun">-</span><span class="typ">GigabitEthernet0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">2</span><span class="pun">]</span><span class="pln"> quit

</span><span class="pun">[</span><span class="typ">Huawei</span><span class="pun">]</span> <span class="kwd">interface</span> <span class="typ">Gigabitethernet</span> <span class="lit">0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">3</span>
<span class="pun">[</span><span class="typ">Huawei</span><span class="pun">-</span><span class="typ">GigabitEthernet0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">3</span><span class="pun">]</span><span class="pln"> port</span><span class="pun">-</span><span class="pln">mirroring to observe</span><span class="pun">-</span><span class="pln">port </span><span class="lit">1</span><span class="pln"> both
</span><span class="pun">[</span><span class="typ">Huawei</span><span class="pun">-</span><span class="typ">GigabitEthernet0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">3</span><span class="pun">]</span><span class="pln"> quit

</span><span class="pun">[</span><span class="typ">Huawei</span><span class="pun">]</span> <span class="kwd">interface</span> <span class="typ">Gigabitethernet</span> <span class="lit">0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">4</span>
<span class="pun">[</span><span class="typ">Huawei</span><span class="pun">-</span><span class="typ">GigabitEthernet0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">3</span><span class="pun">]</span><span class="pln"> port</span><span class="pun">-</span><span class="pln">mirroring to observe</span><span class="pun">-</span><span class="pln">port </span><span class="lit">1</span><span class="pln"> both
</span><span class="pun">[</span><span class="typ">Huawei</span><span class="pun">-</span><span class="typ">GigabitEthernet0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">3</span><span class="pun">]</span><span class="pln"> quit</span>

4. 验证配置

查看观测口配置情况

<span class="pun">[</span><span class="typ">Huawei</span><span class="pun">]</span><span class="pln"> display observe</span><span class="pun">-</span><span class="pln">port
</span><span class="pun">----------------------------------------------------------------------</span>
<span class="typ">Index</span> <span class="pun">:</span> <span class="lit">1</span>
<span class="typ">Untag</span><span class="pun">-</span><span class="pln">packet </span><span class="pun">:</span> <span class="typ">No</span>
<span class="typ">Interface</span> <span class="pun">:</span> <span class="typ">GigabitEthernet0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">23</span>
<span class="pun">----------------------------------------------------------------------</span>

查看端口镜像配置情况:

<span class="pun">[</span><span class="typ">Huawei</span><span class="pun">]</span><span class="pln"> display port</span><span class="pun">-</span><span class="pln">mirroring
</span><span class="pun">----------------------------------------------------------------------</span>
<span class="typ">Observe</span><span class="pun">-</span><span class="pln">port </span><span class="lit">1</span> <span class="pun">:</span> <span class="typ">GigabitEthernet23</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">4</span>
<span class="pun">----------------------------------------------------------------------</span>
<span class="typ">Port</span><span class="pun">-</span><span class="pln">mirror</span><span class="pun">:</span>
<span class="pun">----------------------------------------------------------------------</span>
<span class="typ">Mirror</span><span class="pun">-</span><span class="pln">port </span><span class="typ">Direction</span> <span class="typ">Observe</span><span class="pun">-</span><span class="pln">port
</span><span class="pun">----------------------------------------------------------------------</span>
<span class="lit">1</span> <span class="typ">GigabitEthernet0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">1</span> <span class="typ">Inbound</span>  <span class="typ">Observe</span><span class="pun">-</span><span class="pln">port </span><span class="lit">1</span>
<span class="lit">2</span> <span class="typ">GigabitEthernet0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">1</span><span class="pln"> outbound </span><span class="typ">Observe</span><span class="pun">-</span><span class="pln">port </span><span class="lit">1</span>
<span class="lit">3</span> <span class="typ">GigabitEthernet0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">2</span> <span class="typ">Inbound</span>  <span class="typ">Observe</span><span class="pun">-</span><span class="pln">port </span><span class="lit">1</span>
<span class="lit">4</span> <span class="typ">GigabitEthernet0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">2</span><span class="pln"> outbound </span><span class="typ">Observe</span><span class="pun">-</span><span class="pln">port </span><span class="lit">1</span>
<span class="lit">5</span> <span class="typ">GigabitEthernet0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">3</span> <span class="typ">Inbound</span>  <span class="typ">Observe</span><span class="pun">-</span><span class="pln">port </span><span class="lit">1</span>
<span class="lit">6</span> <span class="typ">GigabitEthernet0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">3</span><span class="pln"> outbound </span><span class="typ">Observe</span><span class="pun">-</span><span class="pln">port </span><span class="lit">1</span>
<span class="lit">7</span> <span class="typ">GigabitEthernet0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">4</span> <span class="typ">Inbound</span>  <span class="typ">Observe</span><span class="pun">-</span><span class="pln">port </span><span class="lit">1</span>
<span class="lit">8</span> <span class="typ">GigabitEthernet0</span><span class="pun">/</span><span class="lit">0</span><span class="pun">/</span><span class="lit">4</span><span class="pln"> outbound </span><span class="typ">Observe</span><span class="pun">-</span><span class="pln">port </span><span class="lit">1</span>
<span class="pun">----------------------------------------------------------------------</span>

配置结束,配置成功后要记得 save 一下。

喜欢 (0)
发表我的评论
取消评论

表情 贴图 加粗 删除线 居中 斜体 签到

Hi,您需要填写昵称和邮箱!

  • 昵称 (必填)
  • 邮箱 (必填)
  • 网址