|
|
楼主 |
发表于 2022-5-15 22:33:31
|
显示全部楼层
Console口设置密码
1 j7 Q. d' U- ?8 }/ P; _$ P5 O( ~交换机Console口设置密码
/ ?4 N. o9 ^3 M/ o[sw1]user-interface console 0% N: C6 }5 z) R. Q
[sw1-ui-console0]authentication-mode password
- x3 F( u8 G8 L# }[sw1-ui-console0]set authentication password ?* B+ S. D w( w& K2 ?: K, O
cipher Set the password with cipher text #密码用密码文本设置密码% _8 r3 N8 u" B+ F3 |
simple Set the password in plain text #简单地设置明文密码
5 l2 S; N7 Q8 f- t8 R2 u[sw1-ui-console0]set authentication password simple 123
% i$ E- h- ]5 O8 c* T+ Y
9 O) Y5 l+ P4 A! N+ s, T5 U, `, e路由器Console口设置密码
' ]0 X9 }# E) n: ]) J, _[R1]user-interface console 06 G) H; o" ^0 ~6 [$ d6 Z
[R1-ui-console0]authentication-mode password
/ G; F* D9 x6 E, _4 w* tPlease configure the login password (maximum length 16):123
+ B: t3 r9 B$ B! J, X0 y[R1-ui-console0]/ P1 c& x4 K+ w* R4 u6 r
[R1-ui-console0]q, D7 n6 C$ n& ~+ H8 H) y
[R1]q
$ L, z# T( g/ V& ?$ c<R1>q w9 _3 ?% H2 J+ T2 n1 s, }
Configuration console exit, please press any key to log on
8 n. a0 E* E, @; E: I% y
8 v7 y& |& S- k1 E9 N7 W7 y( fLogin authentication2 f/ Y* a- `: k+ K' P" o
8 J% K4 u5 v& M/ b. F
Password:输入123
( m8 k, b6 K% F* i" u<R1>sys
8 z% \- z1 |9 c3 fEnter system view, return user view with Ctrl+Z.0 K1 K+ B9 H9 C6 Z* E( |/ I
u0 _0 _2 ]" Q# ^8 s3 g8 c* |( k! C, s( V6 A. Q' S( t! i* ^
配置用户通过Telnet登录设备(真机演示)
+ ?$ j1 d9 t8 x+ k% y* R7 [5 Y[Huawei]int g0/0/0
4 a" Z: a3 X, d4 s, ^2 Z) N[Huawei-GigabitEthernet0/0/0]ip add 192.168.100.252 24 #先给需要接口设置IP
+ R0 l0 L. p, V' t$ v[Huawei]telnet server enable #全局开启telnet3 S' R) c/ h+ e6 I
Info: Telnet is insecure, recommended to use stelnet with encryption features.
" f( |7 C' E& ]: U4 H/ u[Huawei]aaa
. V% U' X6 D3 Y. ^, y[Huawei-aaa]local-user pok password irreversible-cipher 123456 #创建本地用户,用户名:pok、密码:123456
" j0 S% w3 b9 M1 k: aInfo: Add a new user.
- P+ h4 n4 h/ A3 Z( ][Huawei-aaa]local-user pok service-type telnet #配置本地用户pok的接入类型为telnet6 D/ f" d' e" u+ S" K1 T5 Z" K
[Huawei-aaa]local-user pok privilege level 3 #设置用户等级,远程用户缺省的级别都是0级,可修改Telnet用户登录后的用户级别为管理员3
9 B' l! u( J8 o0 ?3 E2 m6 SWarning: This operation may affect online users, are you sure to change the user privilege level ?[Y/N]y 确定& N1 y% ?# T X# f$ Y
[Huawei-aaa]q+ l2 A2 N8 y# @
[Huawei]user-interface vty 0 4 #进入VTY0~VTY4用户界面视图
% A. c+ q2 J0 u[Huawei-ui-vty0-4]authentication-mode aaa #配置VTY类型用户界面的验证方式为AAA! H) N- ?5 F% X4 f1 b8 [% S
& G# x. q( T4 Y1 r: t7 [7 g8 }( b2 V) A( }9 L2 n0 D
配置用户通过web登录设备(真机演示): s) a* h- Z: f6 _! U( X: \
web登陆其实和上面基本是一样的。只是将上面代码中的:0 w. v6 z- y9 t1 d" ^% p# d
local-user pokes service-type telnet
- r& E6 }0 C: \* z. E7 ?$ _7 x2 g) {6 d
替换成
0 |# d# B* s& a4 _8 d! Qlocal-user pokes service-type http ssh web, e. p% L( g N* Q8 r) ]
' ^- X- {7 j5 K+ p( a( A7 G[Huawei]int g0/0/0; r5 I# C# S& F( d. V
[Huawei-GigabitEthernet0/0/0]ip add 192.168.100.252 24 #先给需要接口设置IP; f4 X B& D1 y1 \! Q3 E- w
[Huawei]http server enable #全局开启telnet! Y9 ^5 \, A" p% O3 A. A( K
Info: Telnet is insecure, recommended to use stelnet with encryption features.
2 c V8 l, h- t3 ?6 d# a3 g) y# i[Huawei]aaa6 L5 p6 V c" E% b
[Huawei-aaa]local-user pok password irreversible-cipher 123456 #创建本地用户,用户名:pok、密码:123456( W0 ?8 b) F- Z: R
Info: Add a new user.
7 H# l' M" {. ] H[Huawei-aaa]local-user pok service-type http #配置本地用户pok的接入类型为telnet
* [- R/ f$ X4 g; u: T[Huawei-aaa]local-user pok privilege level 3 #设置用户等级,远程用户缺省的级别都是0级,可修改Telnet用户登录后的用户级别为管理员3
) `* D1 ` }% r0 a" Q; k' r/ |Warning: This operation may affect online users, are you sure to change the user privilege level ?[Y/N]y 确定
! J' E: y2 h4 k U" B( C[Huawei-aaa]q
" T; B4 O. U6 W$ K[Huawei]user-interface vty 0 4 #进入VTY0~VTY4用户界面视图" o: z2 a- s% M
[Huawei-ui-vty0-4]authentication-mode aaa #配置VTY类型用户界面的验证方式为AAA
9 ?3 I1 E. G, m. k2 X0 i/ @7 s9 @& r, @# f M2 t L* }
' z. e0 N" A# V% ~! M2 g
说明:有个问题需要注意一下,替换完成之后就只能web登陆,不能同时登陆web和telnet。如果还需要web登陆,就需要再新建另一个用户。! l8 b& O; _) j1 l" B
重点华为设备出厂的时候,对web访问的接口做了限制,我们必须查出来哪个接口可以web访问
' j& a3 b' y8 `display current-configuration filter http serve #查询哪个接口允许web访问
/ [' y- f. d- E* _4 \#( z+ e7 r8 Q) B1 I- P X
post-system4 s" t6 m' R$ N O3 [0 _2 Z, Y
http server enable
& O3 m3 } v @! j6 Q# G9 r http server permit interface GigabitEthernet0/0/1 #这个接口可以访问5 K! d; K# x2 Z7 K0 q' L& c
#
+ W, O; m9 y2 }9 x9 `return. @4 W+ B7 l7 i5 e) `
6 J0 F5 L s" }5 z
解决办法有两种:2 J; u1 m5 |* E5 }" @$ b, N
undo http server permit interface #删除限制
+ U- i8 k2 z4 h Xhttp server permit interface e0/0/0 #允许你的接口访问web
* V/ D% p( j; J9 k, f% Y: e; T
在这里我想说的是,华为的web界面真的是很差,我用的真机AR1220,不知道新版的怎么样。建议还是用命令把。1 |1 _% q9 {% E& B2 }
- P6 \$ a @+ t- W
|
|