2013年9月10日星期二

H3C S3100 switch: Configuration of the SSH login configuration key + password authentication

Do you know how to confugurate of JG304A the SSH login configuration key + password authentication? Here are the Configuration:

S3100-SI]public-key local create RSA / / generate local RSA key pair
[S3100-SI]local-user H3C
[S3100-SI-luser-h3c]password cipher H3C
[S3100-SI-luser-h3c]service-type SSH Level 3 / / create a local user servicetype SSH
The following are generated by the puttygen RSA key pair, the public and private key file, while the public key file Gongyao file upload to the switch,then the following configuration
[S3100-SI]public-key peer XX import sshkey Gongyao
/ / building import putty from file Gongyao public key and named XX
[S3100-SI]ssh user H3C assign publickey XX / / SSH H3C user public key for XX
[S3100-SI]ssh user H3C service-type stelnet / / setting the SSH user H3Clogin type stelnet
[S3100-SI]ssh user H3C authentication-type password-publickey
/ / type validation set SSH user H3C for public key encryption and password verification
At this time, open the putty, the private key file before introduction in the SSH menu under the auth generated by puttygen, input the IP address of the switch in the session tab, select the type:SSH, then SSH can log on to the switch.

o� 4 e H � �� class=apple-converted-space> chain type network, also canform a ring network, support single bidirectional path protection, linear multiplex section protection.

Network management

OptiX iManager T2000 can be centralized operation, maintenance andmanagement of OptiX Metro 500 (OAM), realize the allocation andscheduling circuit, ensure the safe operation of the network, but alsosupport the Web Server localization JG305A management. The above is Huaweitransmission equipment ----Metro 500 product characteristics.
More information about switch and router, please view :http://en.netlog.com/music000

What are the differents of the Fixed ports to the H3C S3600V2 series switches models ?

The Fixed ports to the H3C S3600V2 series switches models:
1, S3600V2-28TP-SI / S3600V2- 28TP-EI /S3600V2-28TP-PWR-EI: (1) 24 10/100 BASE-TX Ethernet ports
(2) 1 console port JE074A
(3) 2 1000 Base-T and 1000 Base-X SFP combo ports
(4) 2 1000 Base-X SFP ports 

2, S3600V2-52TP-SI / S3600V2-52TP-EI / S3600V2-52TP-PWR-EI:
(1) 48 10/100 BASE-TX Ethernet ports
(2) 1 console port
(3) 2 1000 Base-T and 1000 Base-X SFP combo ports
(4) 2 1000 Base-X SFP ports
3, S3600V2-28F-EI:
(1) 24 100 BASE-FX SFP ports
(2) 2 1000 Base-T and 1000 Base-X SFP combo ports
(3) 2 1000 Base-X SFP ports

(4) 1 console port  HP JE072A 
More information about switch and router, please view :http://chime.in/user/h3cswitch

2013年9月5日星期四

The network application of the H3C MSR 930 router

MSR 930 router as the integrated JF241A access of small and medium-size denterprises and institutions of the gateway equipment, providing datanetworking function in enterprise interior, providing access to the Internetapplication for internal users internal server function, also can pass device to provide for foreign companies to provide WEB or FTP service.
MSR 930 is a gateway which the router is exchange integrate,  4 built-in Ethernet interface, can be directly connected to four PC or other IP devices
WLAN wireless access MSR 930 device part model built in 802.11n mode,can be connected to PC or other IP devices through wireless
MSR 930 devices with embedded WiNet intelligent network management platform, can achieve LAN equipment management, and user accessauthentication and access control
The MSR 930 series routers can be used as the access gatewaygovernment industry branches, such as social security, industry and commerce, taxation, streets, public security and other departments,government industry for high security requirements of network access and data transmission, MSR 930 devices can provide comprehensive securityscheme.
Convergence Router branch of MSR 930 device with headquarters in using DVPN to connect to ensure data and access security, DVPN can not onlyrealize the communication between branch units and higher headquarters,also can realize the communication between the branch unit, in addition tothe expansion of flexible, simple and convenient maintenance
H3C company headquarters through BiMS of branch of MSR 930 equipmentremote centralized management, and equipment may be zero configuration
The branch of MSR 930 device with endpoint admission defense functionwith the center iMC server (EAD), ensure that only safe and meet the requirements of the PC can access to the network
VPN network of commercial chain enterprises
The commercial chain enterprises, MSR 930 is the most ideal branchesand outlets of the access gateway product, the network can use MSR Series Router Network, branches with MSR 930 router as a branch ofaccess equipment, Convergence Router equipment and with theheadquarters of interconnection, can not only achieve real-time synchronization branch office and headquarters can access the Internet.
Schematic diagram of VPN application of commercial chain enterprises
Between the branches and the headquarters can use IPSec VPN to connect, also can use dynamic VPN (DVPN) network, the DVPN can realize the communication between the branches
H3C company headquarters through BiMS of branch of MSR 930 equipmentremote centralized management, and equipment may be zero configuration
Wireless 3G can meet the rapid deployment of on-line (as a temporaryreplacement for wired link during the) needs and communication link backup, can be independently used as a communication link up
MSR 930 is suitable for gateway products in finance from line network and ATM access, because of the support of the built-in 3G module and antennaline extension function, ensure that the ATM can realize the safe, stable and reliable wireless communication, in addition, the series of the dimensions of the device is also suitable for placement in the ATM machines.
From the application of dot and line financial ATM machine diagram
MSR 930 router supports multiple fixed Ethernet interface, can connect with several ATM machine
Placed in the ATM inside the MSR 930 router and center equipment using IPsec VPN connection, to ensure the data security and access
MSR 930 supports the iron absorption type or ceiling to extend the antenna,the 3G module signal in ATM chassis was shielding problem
Remote BiMS solution is used to implement MSR 930 router centralized management and zero configuration
The application of vehicle or expatriate business
The MSR 930 series routers to provide 3G wireless communication function, safe and reliable, and can be widely applied to mobile facility orexpatriate business such as cable resources cannot obtain the scene, such as automobile and ship, banks and enterprises overseas business, offshore drilling platform and training camp and so on. The antenna for MSR 930 series routers to support a variety of formats to extend the line scheme, can effectively guarantee the use in signal shielding vehicles or ships in the environment, the application requirements of high safety requirements,network can use IPSec VPN to ensure the security of the application.
Mobile branch point MSR 930 device with headquarters convergence devices using IPSec VPN to connect, to ensure the data security andaccess
Remote BiMS solution is used to JF283A implement MSR 930 router centralized management and zero configuration.
More information about switch and router, please view :https://www.pereza.info/es/user


Built-in 3G module, what function is the huawei MSR 930 series routers

Questiion: Built-in 3G module, HP MSR900 what function is the huawei MSR 930 series routers ?
Answer: Built in China Unicom standard 3G module, HSPA, 21Mbps rate
Built in China Telecom standard 3G module, the CDMA 2000 Evdo
At the same time, built-in Telecom and Unicom standard 3G module
Support binding SIM/USIM card and equipment function
Support multiple factor binding authentication functions under VPDN,realizing the username / password /SIM card number / serial number or MAC address binding authentication
Support GPS base station positioning function
Supports message start and alarm

Support rod / roof / ceiling antenna HP MSR20 iron three ways to extend the line.
More information about switch and router, please view :http://hometuitionvideo.com/members/manageBlog.php

2013年9月3日星期二

DHCP relay configuration of H3C switches

DHCP relay configuration of H3C switches HP JE073A price 
Environmental science:
H3C core layer three switches, divided into two VLAN, respectively
Vlan20 (ip:192.168.1.250)
Vlan30 (ip:10.10.0.1)
Vlan20 is a win2008 server to provide DHCP services, DHCP contains two fields are 192.168.1.0 and 10.10.0.0. To make DHCP server DHCP servicealso provides VLAN20 and VLAN30, required in H3C core switchconfiguration DHCP relay.
Command reference:
System model: DHCP enable
System model: DHCP relay server-group 1 IP x.x.x.x //x for the DHCP server IP address
Int VLAN 30
Interface mode: DHCP select relay

Interface mode: DHCP relay server-select 1 HP JE074A price 
More information about switch and router, please view :http://www.indyarocks.com/profile/7040916/emma-lee

2013年9月2日星期一

The configration of the H3C switches DHCP

H3C switches installed DHCP relay description:
H3C switches installed DHCP relay, JG311A price with the Linux server provides DHCP address allocation for multi service VLAN, an example: using Linux to do a DHCP server, using H3CS7506R do relay switch, provide DHCP service fortwo VLAN, after testing the effect of two months of very good.
H3C switches installed DHCP server procedures
1) Linux installed operating system, I use the release version is CentOS5.2.
2) the following network parameter setting server:
IP address: 192.168.6.7
The subnet mask: 255.255.255.0
Gateway: 192.168.6.254
DNS:192.168.6.10
3) install DHCP service
CentOS and RedHatEnterpriseLinux system default does not install the DHCP service. Use this command to check whether the system has to install the DHCP service: RPM – qdhcp, if return to prompt"packagedhcpisnotinstalled", the DHCP service is not installed. The CentOSDVD installation CD into the drive, execute the following command:
Cd/media/CentOS_5.2_Final/CentOS
RPM - ivhdhcp-3.0.5-13.el5.i386.rpm
The system installation schedule, after the success of the installation again performed "RPM - qdhcp" command, the system will return the message "dhcp-3.0.5-13.el5", the DHCP service is installed correctly.
4) the configuration file template copy of dhcpd.conf, the configuration of the DHCP service by editing the /etc/dhcpd.conf to. DHCP service programdefault does not establish the dhcpd.conf configuration file, but with aconfiguration template, just a little change can be used. The implementation of the "cp/usr/share/doc/dhcp-3.0.5/dhcpd.conf.sample/etc/dhcpd.conf"command, the system comes with the template configuration files arecopied to the /etc directory and rename it to dhcpd.conf.
5) "vi/etc/dhcpd.conf" command to edit the configuration file as follows:
Quote.
#cat/etc/dhcpd.conf
Ddns-update-styleinterim;
Ignoreclient-updates;
Default-lease-time86400;
Max-lease-time86400;
Subnet192.168.6.0netmask255.255.255.0{
Range192.168.6.1192.168.6.253;
Optionrouters192.168.6.254;
Optionsubnet-mask255.255.255.0;
Optiondomain-name-servers192.168.6.10,10.20.6.10;
Optionnetbios-name-servers192.168.6.10,10.20.6.10;
Optiontime-offset-18000;
Default-lease-time86400;
Max-lease-time86400;
}
Subnet192.168.25.0netmask255.255.255.0{
Range192.168.25.1192.168.25.253;
Optionrouters192.168.25.254;
Optionsubnet-mask255.255.255.0;
Optiondomain-name-servers192.168.6.10,10.20.6.10;
Optionnetbios-name-servers192.168.6.10,10.20.6.10;
Optiontime-offset-18000;
Default-lease-time86400;
Max-lease-time86400;
}
Subnet192.168.30.0netmask255.255.255.0{
Range192.168.30.1192.168.30.253;
Optionrouters192.168.30.254;
Optionsubnet-mask255.255.255.0;
Optiondomain-name-servers192.168.6.10,10.20.6.10;
Optionnetbios-name-servers192.168.6.10,10.20.6.10;
Optiontime-offset-18000;
Default-lease-time86400;
Max-lease-time86400;
}
6) create an empty DHCP customers lease database file. Command:"touch/var/lib/dhcpd/dhcpd.leases"
7) the implementation of "servicedhcpdstart" to start the DHCP service.
8) to set the server to automatically start the DHCP service. The implementation of the "ntsysv" command, find the "dhcpd" in the dialog box,press the space for its marked with "*", press "Tab" key to select the "set" button and press enter.
9) if the server installation opening the network firewall, need to change thefirewall settings, open the server configuration UDP67 and port 68 to thisserver is completed. Need to pay attention to in the course of the server configuration:
1) dhcpd.conf in addition to need DHCP services VLAN network segment, it must include the server's network card information can be. When I am in the configuration of the dhcpd.conf, start with "this two wordsubnet192.168.25.0netmask255.255.255.0{}" and"subnet192.168.30.0netmask255.255.255.0{}" network, the implementation of "servicedhcpdstart" command to start the dhcpd service is alwaysprompt failure. Then the implementation of "/etc/init.d/dhcpdstart" command,carefully read the error message that dhcpd.conf file must contain a server in the network information can be. To add dhcpd.conf"subnet192.168.6.0netmask255.255.255.0{}" after a period of service can be a normal start.
2) parameters inside the dhcp.conf that should be relatively easy to understand, the time I do not explain.

3) I found information it said firewall to open UDP67 port 68, HP JG312A  but also it said 68 can also be.
More information about switch and router, please view :http://bloxster.net/wp-admin/edit.php

H3C Router: how to set the time on the Internet and access network content

At present, a family with more than one HP JC694A  computer, basic every child knows how to use the Internet to learn or play games, this let parents very headache, when a child is unable to know a lot in learning or playing a game, we need a can access control functions, such as surfing time and access network content, here we have to H3C routing to introduce this knowledge.
A, now many families to users through the telecom ADSL or othercompanies to provide similar types of broadband Internet access. Because the cost of broadband and low, and for most don't have a lot of datadownload home users, a person or a computer have a ADSL a waste ofresources, so many people now use routers to share a broadband Internet access.
In general, the following two Internet sharing method: telephone line - voice separator -ADSL cat - Broadband Router, switch, hub - computer, in this case through the appropriate settings for the broadband router can access control, the steps are as follows:
1, IP and MAC addresses for all users in lan.
In 2, IP in many ways, recommend the use of LAN see, online to search onthe.
3, method for obtaining MAC address: WIN+R, enter the CMD, seeNBTSTAT -A IP address.
4, method of acquiring computer IP and MAC: WIN+R, CMD input,IPCONFIG view /ALL.
5, landing broadband router, open the IE, enter the 192.168.1.1, there will be landing window, enter the account number and password, login will appear after the broadband router settings page, in the interface we can be set.
Three, in order to give you a better understanding, we take an example to illustrate it, here we assume that only allows your computer to the Internet,the steps are as follows:
1, set the page -DHCP server - static address allocation - the IP addressand MAC address binding themselves.
2, set the page - Security Settings - firewall settings - select firewall, open the IP address filtering, open the MAC address filtering three - choice that do not meet the IP address filtering rules have a packet, the router and allow only ban is enabled MAC address list of MAC address to access the Internet.
3, set the page - the security settings of -IP address filtering - add new entries to your IP address filled in, and choose to make all the entry into force.
4, set the page - the security settings of -MAC address filtering - add new entries to your MAC address filled in, and choose to make all the entry into force.
With this setting, except you, no one can be on the outside, but can access the internal LAN, Internet control successfully, if you want to stand acomputer on the Internet, then in the settings page - security settings of -MAC address filtering - add new entries - the ban on network computer MAC address filled in, and select the entry into force, which banned JC694A  Internetcomputer can not access the net, but can access the internal LAN.
More information, please view :
http://lilirouter.soup.io/