Step3£ºÅäÖÃOSPF
#ÉèÖÃrooter id£¬Í¨³£ÉèÖÃΪloopbackµØÖ· lab@SRX-1# top [edit]
lab@SRX-1#set routing-options router-id 192.168.1.254 # ¡°ÉèÖÃrouter-id \lab@SRX-1#edit protocols ospf
lab@SRX-1#set preference 200 # ¡°µ÷ÕûOSPFµÄ¹ÜÀí¾àÀ룬ȱʡΪ10 \
# \½«²ßÂÔÖеÄÖ¸¶¨Â·ÓÉ·¢²¼¸øOSPFÁÚ¾Ó£¬SRXp_ospfÊDzßÂÔÃû×Ö£¬ÔÚºóÃæ¶¨Òå\lab@SRX-1#se SRXport SRXp_ospf
# \ÉèÖÃËͳöpurged LSAµÄÃëÊý£¬È±Ê¡ÊÇ30Ãë\
lab@SRX-1# set graceful-restart notify-duration 100
# \ÉèÖÃÖØÐ½¨Á¢fullÁÚ¾ÓµÄÃëÊý£¬È±Ê¡ÊÇ180Ãë\
lab@SRX-1#set graceful-restart restart-duration 200
# \ÉèÖÃarea0²ÎÊý\
lab@SRX-1#edit area 0
{master}[edit protocols ospf area 0.0.0.0]
# \ÉèÖÃOSPF¶Ë¿ÚÓÅÏÈֵΪ100£¬È±Ê¡ÊÇ128 \lab@SRX-1#edit interface vlan.10
# \ÉèÖÃOSPFµ±Ã»ÓÐÊÕµ½LS ACKʱ£¬ÖØÐÂËͳöLSAµÄÃëÊý£¬È±Ê¡ÊÇ5Ãë\lab@SRX-1#set retransmit-interval 10
# \ÉèÖÃHello PacketµÄ¼ä¸ôÃëÊý \lab@SRX-1#set hello-interval 5
# \ÉèÖóÖÐøÎªÊÕµ½Hello£¬È϶¨ÁÚ¾ÓΪdownµÄÃëÊý\lab@SRX-1#set dead-interval 10
# \ÉèÖÃÈÏÖ¤·½Ê½ºÍÃÜÂ룬ÈÏÖ¤·½Ê½·ÖΪMDFºÍsimple-password \lab@SRX-1#set authentication simple-password \
# \½«Âß¼¶Ë¿ÚÉèÖÃΪ±»¶¯¶Ë£¬¼ÙÉège-0/0/11.0ÊÇÈý²ã¶Ë¿Ú\lab@SRX-1#set ge-0/0/11.0 passive
# \¶¨ÒåÐèÒª·¢²¼µÄ·ÓɲßÂÔ\
µÚ 21 Ò³ ¹² 26 Ò³
lab@SRX-1# top
{master}[edit]
lab@SRX-1#set policy-options policy-statement SRXp_ospf from protocol direct lab@SRX-1#set policy-options policy-statement SRXp_ospf then accept
1£® ·Ö±ðÔÚÈý̨½»»»»úÉϼì²éOSPF·ÓÉÐÒéÊÇ·ñÕý³££¬¼ì²éÃüÁ
show route
show ospf neighbor
½»»»»úFirewallÏÞÖÆ¹¦ÄÜ ÏÞÖÆIPµØ
#½¨Á¢¹ýÂ˲ßÂÔ
#\Ö¸¶¨¹ýÂËÌõ¼þ£ºÔ´IP\
set firewall family Ethernet-switching filter ipfilter term 1 from source-address 192.168.1.1
#\Ö¸¶¨¹ýÂË·ûºÏÌõ¼þ£ºÄ¿µÄIP\
set firewall family Ethernet-switching filter ipfilter term 1 from destination-address 192.168.1.254
#\Ö¸¶¨·ûºÏÌõ¼þµÄÁ÷Á¿Ëù×öµÄ¶¯×÷£ºaccept»òÕßdiscard\
set firewall family Ethernet-switching filter ipfilter term 1 then accept
#\Ö¸¶¨ÆäËü²»·ûºÏÌõ¼þµÄ¶¯×÷\
set firewall family Ethernet-switching filter ipfilter term 2 discard
#\½«¹ýÂËÌõ¼þÓ¦Óõ½¶Ë¿ÚÉÏ \
set interface ge-0/0/10 unit 0 family Ethernet-switching filter input ipfilter
ÏÞÖÆMACµØÖ·
#\½¨Á¢¹ýÂ˲ßÂÔ\
#\Ö¸¶¨¹ýÂËÌõ¼þ£ºÔ´MAC\
set firewall family Ethernet-switching filter macfilter term 1 from source-mac-address aa:aa:aa:aa:aa:aa
#\Ö¸¶¨¹ýÂË·ûºÏÌõ¼þ£ºÄ¿µÄMAC\
µÚ 22 Ò³ ¹² 26 Ò³
set firewall family Ethernet-switching filter macfilter term destination-mac-address bb:bb:bb:bb:bb:bb
#\Ö¸¶¨·ûºÏÌõ¼þµÄÁ÷Á¿Ëù×öµÄ¶¯×÷£ºaccept»òÕßdiscard\
set firewall family Ethernet-switching filter macfilter term 1 then accept
#\Ö¸¶¨ÆäËü²»·ûºÏÌõ¼þµÄ¶¯×÷\
set firewall family Ethernet-switching filter macfilter term 2 discard
#\½«¹ýÂËÌõ¼þÓ¦Óõ½¶Ë¿ÚÉÏ \
set interface ge-0/0/10 unit 0 family Ethernet-switching filter input macfilter
1 from
Èý¡¢SRX·À»ðǽ³£¹æ²Ù×÷Óëά»¤ 3.2 É豸¹Ø»ú
SRXÒòΪÖ÷¿Ø°åÉÏÓдóÈÝÁ¿´æ´¢£¬Îª·ÀֹǿÐÐ¶Ïµç¹Ø»úÔì³ÉÓ²¼þ¹ÊÕÏ£¬ÒªÇóÉ豸¹Ø»ú±ØÐë°´ÕÕÏÂÃæµÄ²½Öè½øÐвÙ×÷£º
1. ¹ÜÀíÖÕ¶ËÁ¬½ÓSRX console¿Ú¡£
2. ʹÓþßÓÐ×㹻ȨÏÞµÄÓû§ÃûºÍÃÜÂëµÇ½CLIÃüÁîÐнçÃæ¡£ 3. ÔÚÌáʾ·ûÏÂÊäÈëÏÂÃæµÄÃüÁ
user@host> request system halt
¡
The operating system has halted.
Please press any key to reboot(³ý·ÇÐèÒªÖØÆôÉ豸£¬´Ëʱ²»ÒªÇÃÈκμü£¬·ñÔòÉ豸½«½øÐÐÖØÆô)
4. µÈ´ýconsoleÊä³öÉÏÃæÌáʾÐÅÏ¢ºó£¬È·ÈϲÙ×÷ϵͳÒÑÍ£Ö¹ÔËÐУ¬¹Ø±Õ»úÏä±³ºóµçÔ´Ä£
¿éµçÔ´¡£
3.3 Éè±¸ÖØÆô
SRXÖØÆô±ØÐë°´ÕÕÏÂÃæµÄ²½Öè½øÐвÙ×÷£º 1. ¹ÜÀíÖÕ¶ËÁ¬½ÓSRX console¿Ú¡£
2. ʹÓþßÓÐ×㹻ȨÏÞµÄÓû§ÃûºÍÃÜÂëµÇ½CLIÃüÁîÐнçÃæ¡£
µÚ 23 Ò³ ¹² 26 Ò³
3. ÔÚÌáʾ·ûÏÂÊäÈëÏÂÃæµÄÃüÁ
user@host> request system reboot 4. µÈ´ýconsoleÉ豸µÄÊä³ö£¬²Ù×÷ϵͳÒÑ¾ÖØÐÂÆô¶¯¡£
3.4 É豸ÅäÖõ¹Èë
1£©£ºÓû§Ä£Ê½ÏÂÊäÈë configure ½øÈëÅäÖÃģʽ Àý£ºlab@SRX3400> configure »Ø³µ
2£©£ºÊäÈë load merge terminal £¬²¢½«¸½¼þÖеĽű¾Õ³Ìù½øÈ¥(´ò¿ªÅäÖýű¾Ê±ÇëÈ¡Ïû¼Çʱ¾ÀïµÄ¡°¸ñʽ-×Ô¶¯»»ÐС±)
Àý£ºlab@SRX3400#load merge terminal //Ŀ¼Ê÷ģʽµÄÅäÖõ¹Èë
Õ³ÌùÍê±ÏºóÇûسµ¼ü£¬²¢°´ctrl+DÍê³ÉÕ³Ìù »òÕß
ÊäÈëload set terminalÃüÁ²¢½«¸½¼þÖеĽű¾Õ³Ìù½øÈ¥(´ò¿ªÅäÖýű¾Ê±ÇëÈ¡Ïû¼Çʱ¾ÀïµÄ¡°¸ñʽ-×Ô¶¯»»ÐС±)
Àý£ºlab@SRX3400#load set terminal //setÃüÁîģʽµÄÅäÖõ¹Èë
Õ³ÌùÍê±ÏºóÇûسµ¼ü£¬²¢°´ctrl+DÍê³ÉÕ³Ìù
4£©£º×îºóÔÚÅäÖÃģʽÏÂÊäÈëcommit ÃüÁʹÅäÖÃÉúЧ²¢±£´æ
Àý£ºlab@SRX3400#commit
×¢Ò⣺ÅäÖÃģʽÏÂÊäÈë load factory-default Çå¿ÕÏÖÓÐÅäÖÃ
Àý£ºlab@SRX3400# load factory-default (»Ö¸´³ö³§ÉèÖÃ)
3.5 É豸ץ°ü
Ö÷Òª½â¾öÒµÎñÁ÷Á¿ÊÇ·ñ´©Ô½·À»ðǽ£¬ÅäÖÃÃüÁîÈçÏ£º set security flow traceoptions file flow-test set security flow traceoptions file size 20m
set security flow traceoptions file world-readable set security flow traceoptions flag basic-datapath
set security flow traceoptions packet-filter packet source-prefix xxxx destination-prefix xxxx commit
show log flow-test
3.6 ²Ù×÷ϵͳÉý¼¶
SRX²Ù×÷ϵͳÈí¼þÉý¼¶±ØÐë°´ÕÕÏÂÃæµÄ²½Öè½øÐвÙ×÷£º
1. ¹ÜÀíÖÕ¶ËÁ¬½ÓSRX console¿Ú£¬±ãÓÚÉý¼¶¹ý³ÌÖв鿴Éè±¸ÖØÆôºÍÈí¼þ¼ÓÔØ×´Ì¬¡£ 2. SRXÉÏ¿ªÆôFTP·þÎñ£¬²¢Ê¹ÓþßÓг¬¼¶Óû§È¨Ï޵ķÇrootÓû§Í¨¹ýFTP¿Í»§¶Ë½«ÏÂ
µÚ 24 Ò³ ¹² 26 Ò³