undo am user-bind mac-addr 6c62-6d82-163d ip-addr 10.1.151.141 interface Ethernet1/0/8
interface Ethernet1/0/5
shutdown
interface Ethernet1/0/7
shutdown
interface Ethernet1/0/8
shutdown
interface Ethernet1/0/9
shutdown
interface Ethernet1/0/10
绑定电脑MAC地址到交换机端口的需求:
1、交换机各端口和电脑MAC地址绑定,使其它电脑接入到此端口,设成相同IP地址也不能连接到局域网;
2、空余端口shutdown掉;
3、对部分端口限定不可上外网,只可接入局域网;
sys
inter vlan 1
ip add 10.20.1.141
undo
undo am user-bind mac-add 6C62-6D54-02C7 ip-addr 10.1.151.19 interface E1/0/22
undo am user-bind mac-add 6C62-6DA1-45B5 ip-addr 10.1.151.23 interface E1/0/17
#
interface Ethernet1/0/25
port access vlan 151
loopback-detection enable
#
interface Ethernet1/0/26
port access vlan 151
loopback-detection enable
#
interface Ethernet1/0/20
port access vlan 151
loopback-detection enable
#
interface Ethernet1/0/21
port access vlan 151
loopback-detection enable
shutdown
interface Ethernet1/0/20
shutdown
interface Ethernet1/0/21
shutdown
interface Ethernet1/0/22
interface Ethernet1/0/23
shutdown
quit
配置完成,登陆用户名xxx,密码yyy。
如再不通,再用这条命令:ip rout 0.0.0.0 0.0.0.0 10.30.1.2
步骤1:
绑定某MAC地址到交换机端口:
先查看某主机在交换机的哪个端口上:
dis mac-add 6c62-6dab-183a
取消绑定:
#
interface Ethernet1/0/29
#
interface Ethernet1/0/23
port access vlan 151
loopback-detection enable
#
interface Ethernet1/0/24
port access vlan 151
loopback-detection enable
s3100 端口和MAC绑定的命令:
mac-address static 6c62-6d9f-a4c5 int e1/0/22 vlan 78
int1/0/22
port-security port-mode secure
mac-add 6c62-6d9f-a4c5 int e1/0/22 vlan 78 这个里面有接口,就不要进接口配置。。这样方便。
undo am user-bind mac-add 6c62-6da9-e581 ip-addr 10.1.153.20 interface E1/0/7
绑定命令:
am user-bind mac-add 6c62-6dab-181b ip-addr 10.1.153.46 interface E1/0/27
interface Ethernet1/0/28
shutdown
interface Ethernet1/0/29
shutdown
interface Ethernet1/0/30
shutdown
interface Ethernet1/0/31
shutdown
interface Ethernet1/0/32
步骤2:
设定限制交换机端口可学习的最大MAC地址数为1:
interface E1/0/11
mac-address max-mac-count 1
interface E1/0/31
mac-address max-mac-count 1
interface E1/0/33
am user-bind mac-add 6C62-6DA1-45B5 ip-addr 10.1.151.23 interface E1/0/17
am user-bind mac-add 6C62-6D4A-AE6E ip-addr 10.1.151.25 interface E1/0/16
quit
telnet service enable
user-interface vty 0 4
authentication-mode scheme
quit
local-user h3c
password simple h3c
service-type telnet
user privilege level 3
shutdown
interface Ethernet1/0/11
shutdown
interface Ethernet1/0/12
shutdown
interface Ethernet1/0/13
shutdown
interface Ethernet1/0/14
ቤተ መጻሕፍቲ ባይዱ
关闭46端口
int e1/0/46
shutdown
开启46端口
int e1/0/46
undo shutdown
步骤4:
批量关掉不用的口,先查看交换机端口信息,再复制出来整理后统一执行:
shutdown
interface Ethernet1/0/45
以下是杂项操作:
port access vlan 151
loopback-detection enable
#
interface Ethernet1/0/22
mac-address max-mac-count 1
port access vlan 151
loopback-detection enable
am user-bind mac-addr 6c62-6d54-02c7 ip-addr 10.1.151.19
mac-address max-mac-count 1
interface E1/0/37
mac-address max-mac-count 1
删除最大MAC限制:
interface E1/0/11
#
interface Ethernet1/0/27
port access vlan 151
loopback-detection enable
#
interface Ethernet1/0/28
port access vlan 151
loopback-detection enable
步骤3:
关闭不用的端口:
dis brief interface
查看那些端口是 down ,表示这个端口现在没有用。
如:46口为down,可以shutdown这个端口。
Eth1/0/46 DOWN A A access 159
shutdown
interface Ethernet1/0/37
shutdown
interface Ethernet1/0/38
shutdown
interface Ethernet1/0/39
shutdown
undo mac-address max-mac-count
interface E1/0/31
undo mac-address max-mac-count
interface E1/0/33
shutdown
interface Ethernet1/0/15
shutdown
interface Ethernet1/0/16
interface Ethernet1/0/17
interface Ethernet1/0/18
shutdown
interface Ethernet1/0/19
删除绑定:
undo am user-bind mac-add 76c62-6d81-dc64 ip-addr 10.1.154.131 interface E1/0/24
interface Ethernet1/0/40
shutdown
interface Ethernet1/0/41