Juniper SRX ·À»ðǽÅäÖùÜÀíÊÖ²á

Step3£ºÅäÖÃOSPF

#ÉèÖÃrooter id£¬Í¨³£ÉèÖÃΪloopbackµØÖ· lab@SRX-1# top [edit]

lab@SRX-1#set routing-options router-id 192.168.1.254 # ¡°ÉèÖÃrouter-id \lab@SRX-1#edit protocols ospf

lab@SRX-1#set preference 200 # ¡°µ÷ÕûOSPFµÄ¹ÜÀí¾àÀ룬ȱʡΪ10 \

# \½«²ßÂÔÖеÄÖ¸¶¨Â·ÓÉ·¢²¼¸øOSPFÁÚ¾Ó£¬SRXp_ospfÊDzßÂÔÃû×Ö£¬ÔÚºóÃæ¶¨Òå\lab@SRX-1#se SRXport SRXp_ospf

# \ÉèÖÃËͳöpurged LSAµÄÃëÊý£¬È±Ê¡ÊÇ30Ãë\

lab@SRX-1# set graceful-restart notify-duration 100

# \ÉèÖÃÖØÐ½¨Á¢fullÁÚ¾ÓµÄÃëÊý£¬È±Ê¡ÊÇ180Ãë\

lab@SRX-1#set graceful-restart restart-duration 200

# \ÉèÖÃarea0²ÎÊý\

lab@SRX-1#edit area 0

{master}[edit protocols ospf area 0.0.0.0]

# \ÉèÖÃOSPF¶Ë¿ÚÓÅÏÈֵΪ100£¬È±Ê¡ÊÇ128 \lab@SRX-1#edit interface vlan.10

# \ÉèÖÃOSPFµ±Ã»ÓÐÊÕµ½LS ACKʱ£¬ÖØÐÂËͳöLSAµÄÃëÊý£¬È±Ê¡ÊÇ5Ãë\lab@SRX-1#set retransmit-interval 10

# \ÉèÖÃHello PacketµÄ¼ä¸ôÃëÊý \lab@SRX-1#set hello-interval 5

# \ÉèÖóÖÐøÎªÊÕµ½Hello£¬È϶¨ÁÚ¾ÓΪdownµÄÃëÊý\lab@SRX-1#set dead-interval 10

# \ÉèÖÃÈÏÖ¤·½Ê½ºÍÃÜÂ룬ÈÏÖ¤·½Ê½·ÖΪMDFºÍsimple-password \lab@SRX-1#set authentication simple-password \

# \½«Âß¼­¶Ë¿ÚÉèÖÃΪ±»¶¯¶Ë£¬¼ÙÉège-0/0/11.0ÊÇÈý²ã¶Ë¿Ú\lab@SRX-1#set ge-0/0/11.0 passive

# \¶¨ÒåÐèÒª·¢²¼µÄ·ÓɲßÂÔ\

µÚ 21 Ò³ ¹² 26 Ò³

lab@SRX-1# top

{master}[edit]

lab@SRX-1#set policy-options policy-statement SRXp_ospf from protocol direct lab@SRX-1#set policy-options policy-statement SRXp_ospf then accept

1£® ·Ö±ðÔÚÈý̨½»»»»úÉϼì²éOSPF·ÓÉЭÒéÊÇ·ñÕý³££¬¼ì²éÃüÁ

show route

show ospf neighbor

½»»»»úFirewallÏÞÖÆ¹¦ÄÜ ÏÞÖÆIPµØ

#½¨Á¢¹ýÂ˲ßÂÔ

#\Ö¸¶¨¹ýÂËÌõ¼þ£ºÔ´IP\

set firewall family Ethernet-switching filter ipfilter term 1 from source-address 192.168.1.1

#\Ö¸¶¨¹ýÂË·ûºÏÌõ¼þ£ºÄ¿µÄIP\

set firewall family Ethernet-switching filter ipfilter term 1 from destination-address 192.168.1.254

#\Ö¸¶¨·ûºÏÌõ¼þµÄÁ÷Á¿Ëù×öµÄ¶¯×÷£ºaccept»òÕßdiscard\

set firewall family Ethernet-switching filter ipfilter term 1 then accept

#\Ö¸¶¨ÆäËü²»·ûºÏÌõ¼þµÄ¶¯×÷\

set firewall family Ethernet-switching filter ipfilter term 2 discard

#\½«¹ýÂËÌõ¼þÓ¦Óõ½¶Ë¿ÚÉÏ \

set interface ge-0/0/10 unit 0 family Ethernet-switching filter input ipfilter

ÏÞÖÆMACµØÖ·

#\½¨Á¢¹ýÂ˲ßÂÔ\

#\Ö¸¶¨¹ýÂËÌõ¼þ£ºÔ´MAC\

set firewall family Ethernet-switching filter macfilter term 1 from source-mac-address aa:aa:aa:aa:aa:aa

#\Ö¸¶¨¹ýÂË·ûºÏÌõ¼þ£ºÄ¿µÄMAC\

µÚ 22 Ò³ ¹² 26 Ò³

set firewall family Ethernet-switching filter macfilter term destination-mac-address bb:bb:bb:bb:bb:bb

#\Ö¸¶¨·ûºÏÌõ¼þµÄÁ÷Á¿Ëù×öµÄ¶¯×÷£ºaccept»òÕßdiscard\

set firewall family Ethernet-switching filter macfilter term 1 then accept

#\Ö¸¶¨ÆäËü²»·ûºÏÌõ¼þµÄ¶¯×÷\

set firewall family Ethernet-switching filter macfilter term 2 discard

#\½«¹ýÂËÌõ¼þÓ¦Óõ½¶Ë¿ÚÉÏ \

set interface ge-0/0/10 unit 0 family Ethernet-switching filter input macfilter

1 from

Èý¡¢SRX·À»ðǽ³£¹æ²Ù×÷Óëά»¤ 3.2 É豸¹Ø»ú

SRXÒòΪÖ÷¿Ø°åÉÏÓдóÈÝÁ¿´æ´¢£¬Îª·ÀֹǿÐÐ¶Ïµç¹Ø»úÔì³ÉÓ²¼þ¹ÊÕÏ£¬ÒªÇóÉ豸¹Ø»ú±ØÐë°´ÕÕÏÂÃæµÄ²½Öè½øÐвÙ×÷£º

1. ¹ÜÀíÖÕ¶ËÁ¬½ÓSRX console¿Ú¡£

2. ʹÓþßÓÐ×㹻ȨÏÞµÄÓû§ÃûºÍÃÜÂëµÇ½CLIÃüÁîÐнçÃæ¡£ 3. ÔÚÌáʾ·ûÏÂÊäÈëÏÂÃæµÄÃüÁ

user@host> request system halt

¡­

The operating system has halted.

Please press any key to reboot(³ý·ÇÐèÒªÖØÆôÉ豸£¬´Ëʱ²»ÒªÇÃÈκμü£¬·ñÔòÉ豸½«½øÐÐÖØÆô)

4. µÈ´ýconsoleÊä³öÉÏÃæÌáʾÐÅÏ¢ºó£¬È·ÈϲÙ×÷ϵͳÒÑÍ£Ö¹ÔËÐУ¬¹Ø±Õ»úÏä±³ºóµçÔ´Ä£

¿éµçÔ´¡£

3.3 Éè±¸ÖØÆô

SRXÖØÆô±ØÐë°´ÕÕÏÂÃæµÄ²½Öè½øÐвÙ×÷£º 1. ¹ÜÀíÖÕ¶ËÁ¬½ÓSRX console¿Ú¡£

2. ʹÓþßÓÐ×㹻ȨÏÞµÄÓû§ÃûºÍÃÜÂëµÇ½CLIÃüÁîÐнçÃæ¡£

µÚ 23 Ò³ ¹² 26 Ò³

3. ÔÚÌáʾ·ûÏÂÊäÈëÏÂÃæµÄÃüÁ

user@host> request system reboot 4. µÈ´ýconsoleÉ豸µÄÊä³ö£¬²Ù×÷ϵͳÒѾ­ÖØÐÂÆô¶¯¡£

3.4 É豸ÅäÖõ¹Èë

1£©£ºÓû§Ä£Ê½ÏÂÊäÈë configure ½øÈëÅäÖÃģʽ Àý£ºlab@SRX3400> configure »Ø³µ

2£©£ºÊäÈë load merge terminal £¬²¢½«¸½¼þÖеĽű¾Õ³Ìù½øÈ¥(´ò¿ªÅäÖýű¾Ê±ÇëÈ¡Ïû¼Çʱ¾ÀïµÄ¡°¸ñʽ-×Ô¶¯»»ÐС±)

Àý£ºlab@SRX3400#load merge terminal //Ŀ¼Ê÷ģʽµÄÅäÖõ¹Èë

Õ³ÌùÍê±ÏºóÇûسµ¼ü£¬²¢°´ctrl+DÍê³ÉÕ³Ìù »òÕß

ÊäÈëload set terminalÃüÁ²¢½«¸½¼þÖеĽű¾Õ³Ìù½øÈ¥(´ò¿ªÅäÖýű¾Ê±ÇëÈ¡Ïû¼Çʱ¾ÀïµÄ¡°¸ñʽ-×Ô¶¯»»ÐС±)

Àý£ºlab@SRX3400#load set terminal //setÃüÁîģʽµÄÅäÖõ¹Èë

Õ³ÌùÍê±ÏºóÇûسµ¼ü£¬²¢°´ctrl+DÍê³ÉÕ³Ìù

4£©£º×îºóÔÚÅäÖÃģʽÏÂÊäÈëcommit ÃüÁʹÅäÖÃÉúЧ²¢±£´æ

Àý£ºlab@SRX3400#commit

×¢Ò⣺ÅäÖÃģʽÏÂÊäÈë load factory-default Çå¿ÕÏÖÓÐÅäÖÃ

Àý£ºlab@SRX3400# load factory-default (»Ö¸´³ö³§ÉèÖÃ)

3.5 É豸ץ°ü

Ö÷Òª½â¾öÒµÎñÁ÷Á¿ÊÇ·ñ´©Ô½·À»ðǽ£¬ÅäÖÃÃüÁîÈçÏ£º set security flow traceoptions file flow-test set security flow traceoptions file size 20m

set security flow traceoptions file world-readable set security flow traceoptions flag basic-datapath

set security flow traceoptions packet-filter packet source-prefix xxxx destination-prefix xxxx commit

show log flow-test

3.6 ²Ù×÷ϵͳÉý¼¶

SRX²Ù×÷ϵͳÈí¼þÉý¼¶±ØÐë°´ÕÕÏÂÃæµÄ²½Öè½øÐвÙ×÷£º

1. ¹ÜÀíÖÕ¶ËÁ¬½ÓSRX console¿Ú£¬±ãÓÚÉý¼¶¹ý³ÌÖв鿴Éè±¸ÖØÆôºÍÈí¼þ¼ÓÔØ×´Ì¬¡£ 2. SRXÉÏ¿ªÆôFTP·þÎñ£¬²¢Ê¹ÓþßÓг¬¼¶Óû§È¨Ï޵ķÇrootÓû§Í¨¹ýFTP¿Í»§¶Ë½«ÏÂ

µÚ 24 Ò³ ¹² 26 Ò³

ÁªÏµ¿Í·þ£º779662525#qq.com(#Ìæ»»Îª@)