informatique:extreme_networks
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| informatique:extreme_networks [2025/02/05 16:09] – [Hardware] x695 pteu | informatique:extreme_networks [2026/03/04 14:51] (current) – [DHCP snooping] pteu | ||
|---|---|---|---|
| Line 607: | Line 607: | ||
| * via clé USB | * via clé USB | ||
| + | |||
| + | ref: [[https:// | ||
| + | |||
| + | Avant EXOS 31.1: | ||
| <code bash> | <code bash> | ||
| - | # puis vérifier qu' | + | # vérifier qu' |
| show memorycard | show memorycard | ||
| Line 617: | Line 621: | ||
| This image will be used only after rebooting the switch! | This image will be used only after rebooting the switch! | ||
| </ | </ | ||
| + | |||
| + | Depuis la version EXOS 31.1 | ||
| + | <code bash> | ||
| + | # vérifier que la clé USB est reconnue et montée (elle doit être en FAT32) | ||
| + | show switch mounts | ||
| + | Memory storage is present. | ||
| + | ! | ||
| + | show switch usb | ||
| + | USB port: Disabled | ||
| + | # Si KO, activer la prise en chagre de l'USB | ||
| + | enable switch usb | ||
| + | This setting will take effect at the next system reboot | ||
| + | |||
| + | # la clé USB est montée ici: | ||
| + | ls / | ||
| + | -rwxrwxr-- | ||
| + | [..] | ||
| + | |||
| + | # copier l' | ||
| + | download url file:/// | ||
| + | </ | ||
| + | |||
| + | Puis '' | ||
| * via scp | * via scp | ||
| Line 650: | Line 677: | ||
| * '' | * '' | ||
| L' | L' | ||
| + | |||
| + | * autre erreur TFTP quand on passe de la 30.1 à la 30.3 : '' | ||
| + | | ||
| + | |||
| ====Commandes UNIX-like==== | ====Commandes UNIX-like==== | ||
| Line 1208: | Line 1239: | ||
| enable radius netlogin | enable radius netlogin | ||
| </ | </ | ||
| + | |||
| + | NB: le VLAN d' | ||
| ===Configuration côté serveur Radius=== | ===Configuration côté serveur Radius=== | ||
| Line 1237: | Line 1270: | ||
| [...] | [...] | ||
| </ | </ | ||
| + | |||
| + | =====DHCP snooping===== | ||
| + | |||
| + | Le DHCP snooping est un service de sécurité qui permet de spécifier à un switch où (sur quel port) est situé le serveur DHCP légitime, afin qu'il bloque les flux DHCP illicites émanant des ports utilisateur. On ne l' | ||
| + | |||
| + | Le DHCP snooping s' | ||
| + | |||
| + | On peut choisir l' | ||
| + | |||
| + | <code bash> | ||
| + | # définir un serveur DHCP par VLAN (limité à 8) | ||
| + | configure trusted-servers vlan v2 add server 192.168.1.253 trust-for dhcp-server | ||
| + | # alternative: | ||
| + | configure trusted-port 1 trust-for dhcp-server | ||
| + | |||
| + | # activer la protection sur les ports utilisateur et bloquer pour 1h l' | ||
| + | enable ip-security dhcp-snooping vlan v2 port 2-48 violation-action drop-packet block-mac duration 3600 snmp-trap | ||
| + | </ | ||
| + | |||
| + | Vérifications | ||
| + | <code bash> | ||
| + | show ip-security dhcp-snooping vlan v2-Commerciaux | ||
| + | show configuration ipSecurity | ||
| + | </ | ||
| + | |||
| + | Logs typiques : | ||
| + | <code bash> | ||
| + | 03/03/2026 15:56:41.76 < | ||
| + | 03/03/2026 15:56:41.76 < | ||
| + | </ | ||
| =====Spanning-tree===== | =====Spanning-tree===== | ||
| Line 1670: | Line 1733: | ||
| * [[https:// | * [[https:// | ||
| * et particulièrement : [[https:// | * et particulièrement : [[https:// | ||
| + | * [[https:// | ||
| ====Divers==== | ====Divers==== | ||
| Line 1851: | Line 1915: | ||
| show bgp neighbor 10.55.200.92 accepted-routes all | show bgp neighbor 10.55.200.92 accepted-routes all | ||
| show bgp neighbor 10.55.200.92 rejected-routes all | show bgp neighbor 10.55.200.92 rejected-routes all | ||
| + | [...] | ||
| + | BGP Route Statistics | ||
| + | Total Rxed Routes : 8 | ||
| + | Rejected Routes | ||
| + | Unfeasible Routes : 0 | ||
| ! | ! | ||
| show bgp neighbor 10.55.200.92 transmitted-routes all | show bgp neighbor 10.55.200.92 transmitted-routes all | ||
| Line 1862: | Line 1931: | ||
| show bgp neighbor 10.55.200.92 suppressed-routes all | show bgp neighbor 10.55.200.92 suppressed-routes all | ||
| </ | </ | ||
| + | |||
| + | <WRAP center round important 80%> | ||
| + | Les commandes précédentes n' | ||
| + | </ | ||
| ===Suppression de la conf BGP=== | ===Suppression de la conf BGP=== | ||
informatique/extreme_networks.1738771776.txt.gz · Last modified: 2025/02/05 16:09 by pteu