informatique:extreme_networks
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| informatique:extreme_networks [2023/09/07 10:09] – mgmt port pteu | informatique:extreme_networks [2025/10/15 15:30] (current) – [authentification par mac] pteu | ||
|---|---|---|---|
| Line 90: | Line 90: | ||
| Dillinger Version: | Dillinger Version: | ||
| - | # afficher | + | # x695 |
| + | Slot 1 Version Information: | ||
| + | Branch | ||
| + | Version: | ||
| + | Card type: X695-48Y-8C rev 0 | ||
| + | MAC--1: | ||
| + | Saved Chip Data: | ||
| + | CPU Core: | ||
| + | CPU Memory Size: 16384 MB | ||
| + | Alternate Bootrom Version: | ||
| + | Default Bootrom Version: | ||
| + | </ | ||
| + | |||
| + | Afficher | ||
| + | <code bash> | ||
| debug hal show optic-info slot 1 port 52 | debug hal show optic-info slot 1 port 52 | ||
| Line 111: | Line 125: | ||
| Configurer une adresse IP sur le port de management '' | Configurer une adresse IP sur le port de management '' | ||
| + | |||
| + | Vérifier le DHCP : | ||
| <code bash> | <code bash> | ||
| - | configure vlan Mgmt ipaddress 10.0.0.1 255.255.255.0 | + | show dhcp-client ipv4 state |
| + | Client VLAN | ||
| + | --------------- -------- --------------- --------------------------------------- | ||
| + | Default | ||
| + | Mgmt None 0.0.0.0 | ||
| + | # désactiver le DHCP (au besoin) | ||
| + | disable dhcp vlan all | ||
| + | </ | ||
| + | |||
| + | <code bash> | ||
| + | # configurer l'IP du port de Management | ||
| + | configure vlan Mgmt ipaddress 10.0.0.1 255.255.255.0 | ||
| # configurer sa route par défaut | # configurer sa route par défaut | ||
| configure iproute add default 10.0.0.254 vr VR-Mgmt | configure iproute add default 10.0.0.254 vr VR-Mgmt | ||
| </ | </ | ||
| + | |||
| + | Parfois, ça bug et on ne peut toujours pas configurer d' | ||
| + | <code bash> | ||
| + | sh vlan | ||
| + | Untagged ports auto-move: Inform | ||
| + | ----------------------------------------------------------------------------------------------- | ||
| + | Name VID Protocol Addr | ||
| + | ----------------------------------------------------------------------------------------------- | ||
| + | Mgmt 4095 169.254.120.0 | ||
| + | ----------------------------------------------------------------------------------------------- | ||
| + | ! | ||
| + | disable dhcp vlan all | ||
| + | WARNING: VLAN " | ||
| + | ! | ||
| + | unconfigure vlan Mgmt ipaddress | ||
| + | Error: Dhcp/Bootp configured IP address cannot be removed on VLAN Mgmt | ||
| + | ! | ||
| + | conf vlan Mgmt ipaddress 10.0.0.1 255.255.0.0 | ||
| + | Error: DHCP/BOOTP is enabled on the VLAN | ||
| + | |||
| + | # contournement | ||
| + | enable dhcp vlan Mgmt | ||
| + | disable dhcp vlan Mgmt | ||
| + | unconf vlan Mgmt ipaddress | ||
| + | ! | ||
| + | conf vlan Mgmt ipaddress 10.0.0.1 255.255.0.0 | ||
| + | IP interface for VLAN Mgmt has been created. | ||
| + | </ | ||
| + | |||
| Ce port est affecté au vlan Mgmt, lui-même attribué au VR-Mgmt. Cela signifie qu'il est indépendant de la configuration des autres ports et routes du switch, ce qui permet d' | Ce port est affecté au vlan Mgmt, lui-même attribué au VR-Mgmt. Cela signifie qu'il est indépendant de la configuration des autres ports et routes du switch, ce qui permet d' | ||
| Line 519: | Line 575: | ||
| ====Firmware==== | ====Firmware==== | ||
| - | Pour obtenir la version d'EXOS (ici 21.1.1.4) : | + | Pour obtenir la version d' |
| <code bash> | <code bash> | ||
| show version | show version | ||
| Line 534: | Line 590: | ||
| </ | </ | ||
| Cette commande retourne également la liste des commutateurs de la stack et les modules additionnels, | Cette commande retourne également la liste des commutateurs de la stack et les modules additionnels, | ||
| + | |||
| + | Consulter la page [[https:// | ||
| ===MAJ firmware=== | ===MAJ firmware=== | ||
| Line 541: | Line 599: | ||
| <code bash> | <code bash> | ||
| download image 1.1.1.1 < | download image 1.1.1.1 < | ||
| + | </ | ||
| + | |||
| + | Téléchargement sur la partition inactive + installation + reboot (all-in-one) | ||
| + | <code bash> | ||
| + | download image 1.1.1.1 summitX-31.7.2.28-patch1-38.xos vr VR-Mgmt install reboot | ||
| </ | </ | ||
| * via clé USB | * via clé USB | ||
| + | |||
| + | ref: [[https:// | ||
| + | |||
| + | Avant EXOS 31.1: | ||
| <code bash> | <code bash> | ||
| - | # puis vérifier qu' | + | # vérifier qu' |
| show memorycard | show memorycard | ||
| Line 554: | Line 621: | ||
| This image will be used only after rebooting the switch! | This image will be used only after rebooting the switch! | ||
| </ | </ | ||
| + | |||
| + | Depuis la version EXOS 31.1 | ||
| + | <code bash> | ||
| + | # vérifier que la clé USB est reconnue et montée (elle doit être en FAT32) | ||
| + | show switch mounts | ||
| + | Memory storage is present. | ||
| + | ! | ||
| + | show switch usb | ||
| + | USB port: Disabled | ||
| + | # Si KO, activer la prise en chagre de l'USB | ||
| + | enable switch usb | ||
| + | This setting will take effect at the next system reboot | ||
| + | |||
| + | # la clé USB est montée ici: | ||
| + | ls / | ||
| + | -rwxrwxr-- | ||
| + | [..] | ||
| + | |||
| + | # copier l' | ||
| + | download url file:/// | ||
| + | </ | ||
| + | |||
| + | Puis '' | ||
| * via scp | * via scp | ||
| Line 587: | Line 677: | ||
| * '' | * '' | ||
| L' | L' | ||
| + | |||
| + | * autre erreur TFTP quand on passe de la 30.1 à la 30.3 : '' | ||
| + | | ||
| + | |||
| ====Commandes UNIX-like==== | ====Commandes UNIX-like==== | ||
| Line 723: | Line 817: | ||
| # Utiliser un filtre de famille de fonctionnalités (ici la partie DNS/ | # Utiliser un filtre de famille de fonctionnalités (ici la partie DNS/ | ||
| show configuration nettools | show configuration nettools | ||
| + | </ | ||
| + | |||
| + | Lorsqu' | ||
| + | <code bash> | ||
| + | * Slot-1 toto.3 # show conf difference | ||
| + | --- primary.cfg | ||
| + | +++ Running Configuration | ||
| + | @@ -1,7 +1,7 @@ | ||
| + | # | ||
| + | # Module devmgr configuration. | ||
| + | # | ||
| + | -configure snmp sysName " | ||
| + | +configure snmp sysName " | ||
| + | [...] | ||
| </ | </ | ||
| Line 1104: | Line 1212: | ||
| configure mac-locking ports 47 static [add | enable | disable] @MAC | configure mac-locking ports 47 static [add | enable | disable] @MAC | ||
| </ | </ | ||
| + | |||
| + | ====authentification par mac==== | ||
| + | |||
| + | On peut également faire vérifier l' | ||
| + | |||
| + | ===Configuration côté switch=== | ||
| + | <code bash> | ||
| + | # création du VLAN d' | ||
| + | create vlan v10_Users tag 10 | ||
| + | create vlan v666_Accueil tag 666 | ||
| + | ! | ||
| + | # configuration du serveur Radius | ||
| + | configure radius netlogin primary server 10.4.1.1 1814 client-ip 10.5.255.253 vr VR-Default | ||
| + | configure radius netlogin primary shared-secret encrypted " | ||
| + | ! | ||
| + | # configuration de l' | ||
| + | |||
| + | configure netlogin vlan v666_Accueil | ||
| + | enable netlogin mac | ||
| + | configure netlogin mac authentication database-order radius | ||
| + | # on active la protection MAC sur les port 1 à 8 (arbitraire) | ||
| + | enable netlogin ports 1-8 mac | ||
| + | configure netlogin add mac-list ff: | ||
| + | ! | ||
| + | enable radius | ||
| + | enable radius netlogin | ||
| + | </ | ||
| + | |||
| + | NB: le VLAN d' | ||
| + | |||
| + | ===Configuration côté serveur Radius=== | ||
| + | Dans le cas de freeradius, il faut : | ||
| + | * ajouter l'IP du switch (10.5.255.253) et son " | ||
| + | * activer le plugin **authorized_macs** | ||
| + | * peupler le fichier **authorized_macs** avec la liste des adresses MAC permises (format 00-11-22-33-44-55) | ||
| + | * dans la section authorize de la configuration du site : | ||
| + | <file site-enabled/ | ||
| + | [...] | ||
| + | authorize { | ||
| + | | ||
| + | # convertir l'@ mAC dans le bon format | ||
| + | | ||
| + | # | ||
| + | | ||
| + | if (ok) { | ||
| + | # The MAC address was found, so update Auth-Type to accept this auth. | ||
| + | update control { | ||
| + | | ||
| + | } | ||
| + | update reply { | ||
| + | | ||
| + | | ||
| + | | ||
| + | } | ||
| + | } | ||
| + | } | ||
| + | [...] | ||
| + | </ | ||
| + | |||
| =====Spanning-tree===== | =====Spanning-tree===== | ||
| Line 1536: | Line 1703: | ||
| * [[https:// | * [[https:// | ||
| * et particulièrement : [[https:// | * et particulièrement : [[https:// | ||
| + | * [[https:// | ||
| ====Divers==== | ====Divers==== | ||
| Line 1717: | Line 1885: | ||
| show bgp neighbor 10.55.200.92 accepted-routes all | show bgp neighbor 10.55.200.92 accepted-routes all | ||
| show bgp neighbor 10.55.200.92 rejected-routes all | show bgp neighbor 10.55.200.92 rejected-routes all | ||
| + | [...] | ||
| + | BGP Route Statistics | ||
| + | Total Rxed Routes : 8 | ||
| + | Rejected Routes | ||
| + | Unfeasible Routes : 0 | ||
| ! | ! | ||
| show bgp neighbor 10.55.200.92 transmitted-routes all | show bgp neighbor 10.55.200.92 transmitted-routes all | ||
| Line 1728: | Line 1901: | ||
| show bgp neighbor 10.55.200.92 suppressed-routes all | show bgp neighbor 10.55.200.92 suppressed-routes all | ||
| </ | </ | ||
| + | |||
| + | <WRAP center round important 80%> | ||
| + | Les commandes précédentes n' | ||
| + | </ | ||
| ===Suppression de la conf BGP=== | ===Suppression de la conf BGP=== | ||
informatique/extreme_networks.1694081340.txt.gz · Last modified: 2023/09/07 10:09 by pteu