aaa group server tacacs+ ise
server-private 1.1.1.1 key 7 1234
ip tacacs source-interface FastEthernet0/1
!
aaa authentication attempts login 5
aaa authentication password-prompt "Local password: "
aaa authentication username-prompt "Local username: "
aaa authentication login console group ise enable
aaa authentication login sshlogin group ise local
aaa authentication enable default enable
aaa authorization console
aaa authorization config-commands
aaa authorization exec bociise group ise if-authenticated
aaa authorization exec console group ise if-authenticated
aaa authorization commands 1 console group ise none
aaa authorization commands 1 bociise group ise if-authenticated
aaa authorization commands 15 console group ise none
aaa authorization commands 15 sshlogin group ise if-authenticated
aaa accounting exec default start-stop group ise
aaa accounting commands 1 default start-stop group ise
aaa accounting commands 15 default start-stop group ise
!
aaa session-id common
!
line vty 0 4
access-class 12 in
authorization commands 1 sshlogin
authorization commands 15 sshlogin
authorization exec sshlogin
login authentication sshlogin
ip nat inside source list 134 pool OMS overload
int gi0/0
ip accounting output-packets
no ip mroute-cache
load-interval 30
hold-queue 4096 out
no ip unreachables
!
service tcp-keepalives-in
service tcp-keepalives-out
!
enable secret 5 $1$Ruh5$iOV1CprHFdjjCSimCETrA0
!
scheduler allocate 20000 1000
ntp clock-period 17180098
!
logging buffered 16000 debugging
logging console critical
!
ip forward-protocol nd
!
router bgp 1111
no synchronization
bgp dampening 5
(0)
思科路由器和华三路由器的配置语法和逻辑有一些差异,因此需要进行一些调整和修改。下面是一个简单的示例,将您提供的思科路由器的配置转换为华三路由器的配置:
思科路由器的配置
aaa group server tacacs+ ise
server-private 1.1.1.1 key 7 1234
ip tacacs source-interface FastEthernet0/1
华三路由器的配置
tacacs-server template ise
tacacs-server authentication 1.1.1.1 key cipher 1234
tacacs-server source-interface FastEthernet0/1
思科路由器的配置
aaa authentication attempts login 5
aaa authentication password-prompt "Local password: "
aaa authentication username-prompt "Local username: "
aaa authentication login console group ise enable
aaa authentication login sshlogin group ise local
aaa authentication enable default enable
华三路由器的配置
local-user password wrong retry-times 5
local-user password prompt "Local password: "
local-user name prompt "Local username: "
authentication-scheme console
authentication-mode tacacs ise
authentication-scheme sshlogin
authentication-mode tacacs ise local
authentication-scheme default
authentication-mode enable
思科路由器的配置
aaa authorization console
aaa authorization config-commands
aaa authorization exec bociise group ise if-authenticated
aaa authorization exec console group ise if-authenticated
aaa authorization commands 1 console group ise none
aaa authorization commands 1 bociise group ise if-authenticated
aaa authorization commands 15 console group ise none
aaa authorization commands 15 sshlogin group ise if-authenticated
华三路由器的配置
authorization-scheme console
authorization-mode tacacs
authorization-scheme bociise
authorization-mode tacacs
authorization-scheme sshlogin
authorization-mode tacacs
authorization-scheme default
authorization-mode none
思科路由器的配置
aaa accounting exec default start-stop group ise
aaa accounting commands 1 default start-stop group ise
aaa accounting commands 15 default start-stop group ise
华三路由器的配置
accounting-scheme default
accounting-mode tacacs
accounting start-fail online
思科路由器的配置
aaa session-id common
华三路由器的配置
tacacs-server session-id common
思科路由器的配置
line vty 0 4
access-class 12 in
authorization commands 1 sshlogin
authorization commands 15 sshlogin
authorization exec sshlogin
login authentication sshlogin
华三路由器的配置
user-interface vty 0 4
acl 12 inbound
authentication-scheme sshlogin
authorization-scheme sshlogin
accounting-scheme default
思科路由器的配置
ip nat inside source list 134 pool OMS overload
华三路由器的配置
nat address-group 1 172.16.10.1 172.16.10.63
interface GigabitEthernet0/0
nat outbound 134 address-group 1
思科路由器的配置
int gi0/0
ip accounting output-packets
no ip mroute-cache
load-interval 30
hold-queue 4096 out
no ip unreachables
华三路由器的配置
interface GigabitEthernet0/0
ip accounting output-packets
undo ip fast-forwarding
load-interval 30
queue-length 4096
undo icmp send-unreachables
思科路由器的配置
service tcp-keepalives-in
service tcp-keepalives-out
华三路由器的配置
tcp keepalive enable
思科路由器的配置
enable secret 5 $1$Ruh5$iOV1CprHFdjjCSimCETrA0
华三路由器的配置
super password level 3 cipher $1$Ruh5$iOV1CprHFdjjCSimCETrA0
思科路由器的配置
scheduler allocate 20000 1000
华三路由器的配置
cpu-defend policy policy1
car packet-type arp cir 20000 cbs 1000
cpu-defend-policy policy1 global
思科路由器的配置
ntp clock-period 17180098
华三路由器的配置
clock frequency 17180098
思科路由器的配置
logging buffered 16000 debugging
logging console critical
华三路由器的配置
info-center source default channel 0 log level debugging
info-center source default channel 1 log level critical
info-center buffer-size 16000
思科路由器的配置
ip forward-protocol nd
华三路由器的配置
ip forward-broadcast nd
思科路由器的配置
router bgp 1111
no synchronization
bgp dampening 5
华三路由器的配置
bgp 1111
undo synchronization
route-dampening enable half-life 5
(4)
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论