A: Define a vlan 2 and name it ShiPinJianKong.
Define a super vlan and add 1498- 1499 to it.
B: define the login user name and password.
Encrypt all plaintext passwords.
The latter two items are usually included in IOS.
The Ssh version is version 2.
C: define an extended ACL named qos-BMYWZXT.
The following entry is an ACL to control access, which basically allows any host to access some hosts using tcp protocol.
D: define an extended ACL named qos-video.
The following entries are ACL to control access, which basically allows some network segments to access some network segments using ip protocol.
(The specific purpose can only be known under the actual topology)
Cpu Topology-Limit 70 When the cpu utilization of the device exceeds 70, the system will generate a topology protection notice.
Logging trap notifications saves restricted notifications in the server log.
Log server 10.0.3. 18
Log server 10.0.4. 137 Log server address.
Enable password configuration
Enable the service ssh-server to open the ssh server.
E: class mapping qos manager
Matching access group qos manager
Class mapping QoS- video
Matching access group qos video
Class mapping qos-ZHDD
Matching access group qos-ZHDD
Class mapping qos-OA
Matching access group qos-OA
Class mapping qos-GIS
Matching access group qos-GIS
Class mapping QoS-scjh &; XXFB
Matching access group QoS-scjh &; XXFB
Class mapping qos-BMYWZXT
Matching access group qos-BMYWZXT
Class mapping QoS- Other
Matching Access Group QoS- Other
These are the qos policies that have been set before, so that hosts that meet the relevant entries can access them.
F: The host name THT-SW-2-0 1 defines the device display name.
Gigabit Ethernet interface11
No switch port
The peer-to-peer network type of Ip ospf network is P2P.
The Ip OSPF authentication message digest provides the authentication method.
Ip OSPF message digest key 1md5gz20 10 authentication key.
No ip proxy -arp turns off the proxy -arp function of g11.
The Ip address10.254.132.2 255.255.252 defines the interface address.
Describe the description interface of "Connect to th-SW- 1-0 1g6/4 and fw" for viewing purposes.
!
Gigabit Ethernet 2/ 16 interface
!
Gigabit Ethernet 2/ 17 interface
Switch port access vlan 3999
Shutdown added 2/ 17 to vlan3999, but it has been shut down.
!
Interface loopback 0
The Ip address10.255.132.1255.255 defines a switchback interface.
!
Interface VLAN 2
No ip proxy -arp
Ip address10.132.2.254 255.255.255.0
Describe ShiPinJianKong definition and describe the IP address of vlan2, and turn off the proxy-arp function.
!
Router ospf 100 enables ospf protocol, and the domain is 100.
Router-id10.255.132.1specifies the RD address.
Automatic cost reference-bandwidth 10000 bandwidth setting
Passive interface default
Gigabit Ethernet without passive interface11g11has no passive interface, so as to send notifications when topology problems occur.
Nssa in area 60
Network10.132.2.254 0.0.0 area 60
Network10.132.3.254 0.0.0 area 60
Network10.132.4.254 0.0.0 area 60
Network10.132.5.254 0.0.0 area 60
Network10.254.132.2 0.0.0 area 60
Network10.255.132.10.0.0 Area 60
Network10.255.132.9 0.0.0 area 60
Network10.255.132.254 0.0.0 Area 60 specifies the network routing of ospf protocol.