WorldSkills éåã¯ãçŸä»£ã®åŽååžå Žã§æ±ããããäž»ã«å®è·µçãªã¹ãã«ãåå è ã«æäŸããããšãç®çãšããŠããŸãã ããããã¯ãŒã¯ãšã·ã¹ãã 管çãã³ã³ããã³ã·ãŒã¯ããããã¯ãŒã¯ãWindowsãLinux ã® XNUMX ã€ã®ã¢ãžã¥ãŒã«ã§æ§æãããŸãã ã¿ã¹ã¯ã¯ãã£ã³ããªã³ã·ããããšã«å€ããã競æã®æ¡ä»¶ãå€ãããŸãããã¿ã¹ã¯ã®æ§é ã¯ã»ãšãã©å€ãããŸããã
Network Island ã¯ãLinux ã Windows ã¢ã€ã©ã³ãã«æ¯ã¹ãŠã·ã³ãã«ã§ãããããæåã®ãã®ã«ãªããŸãã
ãã®èšäºã§ã¯æ¬¡ã®ã¿ã¹ã¯ã«ã€ããŠèª¬æããŸãã
- ããããžãŒã«åŸã£ãŠãã¹ãŠã®ããã€ã¹ã®ååãèšå®ããŸã
- ãã¡ã€ã³å wsrvuz19.ru ããã¹ãŠã®ããã€ã¹ã«å²ãåœãŠãŸã
- ãã¹ãŠã®ããã€ã¹äžã«ãã¹ã¯ãŒã cisco ã䜿çšããŠãŠãŒã¶ãŒ wsrvuz19 ãäœæããŸã
- ãŠãŒã¶ãŒã®ãã¹ã¯ãŒãã¯ãããã·ã¥é¢æ°ã®çµæãšããŠæ§æã«ä¿åããå¿ èŠããããŸãã
- ãŠãŒã¶ãŒã¯æ倧ã¬ãã«ã®æš©éãæã£ãŠããå¿ èŠããããŸãã
- ãã¹ãŠã®ããã€ã¹ã« AAA ã¢ãã«ãå®è£
ããŸãã
- ãªã¢ãŒã ã³ã³ãœãŒã«ã§ã®èªèšŒã¯ãããŒã«ã« ããŒã¿ããŒã¹ã䜿çšããŠå®è¡ããå¿ èŠããããŸã (RTR1 ããã³ RTR2 ããã€ã¹ãé€ã)ã
- èªèšŒãæåããåŸããªã¢ãŒã ã³ã³ãœãŒã«ãããã°ã€ã³ããå ŽåããŠãŒã¶ãŒã¯ããã«æ倧ã¬ãã«ã®ç¹æš©ãæã€ã¢ãŒãã«å ¥ãå¿ èŠããããŸãã
- ããŒã«ã« ã³ã³ãœãŒã«ã§èªèšŒã®å¿ èŠæ§ãæ§æããŸãã
- ããŒã«ã« ã³ã³ãœãŒã«ãžã®èªèšŒãæåãããšããŠãŒã¶ãŒã¯æå°éã®æš©éãæã€ã¢ãŒãã«ãªããŸãã
- BR1 ã§ã¯ãããŒã«ã« ã³ã³ãœãŒã«ã§èªèšŒãæåãããšããŠãŒã¶ãŒã¯æ倧ã¬ãã«ã®ç¹æš©ãæã€ã¢ãŒãã«ãªãå¿ èŠããããŸãã
- ãã¹ãŠã®ããã€ã¹ã§ãç¹æš©ã¢ãŒãã«å
¥ãããã« wsr ãã¹ã¯ãŒããèšå®ããŸãã
- ãã¹ã¯ãŒãã¯ãããã·ã¥é¢æ°ã®çµæãšããŠã§ã¯ãªããèšå®ã«ä¿åããå¿ èŠããããŸãã
- æ§æå ã®ãã¹ãŠã®ãã¹ã¯ãŒããæå·åããã圢åŒã§ä¿åãããã¢ãŒããæ§æããŸãã
ç©çå±€ã®ãããã¯ãŒã¯ ããããžã次ã®å³ã«ç€ºããŸãã
1. ããããžã«åŸã£ãŠãã¹ãŠã®ããã€ã¹ã®ååãèšå®ããŸã
ããã€ã¹åïŒãã¹ãåïŒãèšå®ããã«ã¯ãã°ããŒãã« ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ ã¢ãŒãããã³ãã³ããå
¥åããå¿
èŠããããŸãã hostname SW1
ã代ããã« SW1 課é¡ã«æå®ãããæ©åšã®ååãå¿
ãèšå
¥ããŠãã ããã
ããªã»ããã®ä»£ããã«èšå®ãèŠèŠçã«ç¢ºèªããããšãã§ããŸã ã¹ã€ãã ã ã£ã SW1:
Switch(config)# hostname SW1
SW1(config)#
èšå®ãè¡ã£ãåŸã®äž»ãªã¿ã¹ã¯ã¯ãæ§æãä¿åããããšã§ãã
ããã¯ãã°ããŒãã« ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ ã¢ãŒããã次ã®ã³ãã³ãã䜿çšããŠå®è¡ã§ããŸãã do write
:
SW1(config)# do write
Building configuration...
Compressed configuration from 2142 bytes to 1161 bytes[OK]
ãŸãã¯ãã³ãã³ãã䜿çšããŠç¹æš©ã¢ãŒããã write
:
SW1# write
Building configuration...
Compressed configuration from 2142 bytes to 1161 bytes[OK]
2. ãã¡ã€ã³å wsrvuz19.ru ããã¹ãŠã®ããã€ã¹ã«å²ãåœãŠãŸãã
次ã®ã³ãã³ãã䜿çšããŠãã°ããŒãã« ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ ã¢ãŒãããããã©ã«ãã®ãã¡ã€ã³å wsrvuz19.ru ãèšå®ã§ããŸãã ip domain-name wsrvuz19.ru
.
ãã§ãã¯ã¯ãã°ããŒãã« ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ ã¢ãŒããã do show hosts summary ã³ãã³ãã䜿çšããŠå®è¡ãããŸãã
SW1(config)# ip domain-name wsrvuz19.ru
SW1(config)# do show hosts summary
Name lookup view: Global
Default domain is wsrvuz19.ru
...
3. ãã¹ãŠã®ããã€ã¹äžã«ãã¹ã¯ãŒã cisco ã䜿çšããŠãŠãŒã¶ãŒ wsrvuz19 ãäœæããŸãã
æ倧ã¬ãã«ã®æš©éãæã€ãŠãŒã¶ãŒãäœæããå¿
èŠãããããã¹ã¯ãŒãã¯ããã·ã¥é¢æ°ãšããŠä¿åãããŸãã ããããã¹ãŠã®æ¡ä»¶ãããŒã ã«ãã£ãŠèæ
®ãããŸã username wsrvuz19 privilege 15 secret cisco
.
ããã«ïŒ
username wsrvuz19
- ãŠãŒã¶ãŒå;
privilege 15
â ç¹æš©ã®ã¬ãã« (0 â æå°ã¬ãã«ã15 â æ倧ã¬ãã«)ã
secret cisco
â ãã¹ã¯ãŒãã MD5 ããã·ã¥é¢æ°ãšããŠä¿åããŸãã
showã³ãã³ã running-config
çŸåšã®æ§æã®èšå®ã確èªã§ããŸããè¿œå ããããŠãŒã¶ãŒãå«ãŸããè¡ãèŠã€ããŠããã¹ã¯ãŒããæå·åããã圢åŒã§ä¿åãããŠããããšã確èªã§ããŸãã
SW1(config)# username wsrvuz19 privilege 15 secret cisco
SW1(config)# do show running-config
...
username wsrvuz19 privilege 15 secret 5 $1$EFRK$RNvRqTPt5wbB9sCjlBaf4.
...
4. ãã¹ãŠã®ããã€ã¹ã« AAA ã¢ãã«ãå®è£ ãã
AAA ã¢ãã«ã¯ãèªèšŒãèªå¯ãããã³ã€ãã³ãèšé²ã®ã·ã¹ãã ã§ãã ãã®ã¿ã¹ã¯ãå®äºããã«ã¯ãæåã®ã¹ããããšã㊠AAA ã¢ãã«ãæå¹ã«ããããŒã«ã« ããŒã¿ããŒã¹ã䜿çšããŠèªèšŒãå®è¡ãããããã«æå®ããŸãã
SW1(config)# aaa new-model
SW1(config)# aaa authentication login default local
ïœïŒ ãªã¢ãŒã ã³ã³ãœãŒã«ã§ã®èªèšŒã¯ãããŒã«ã« ããŒã¿ããŒã¹ã䜿çšããŠå®è¡ããå¿
èŠããããŸã (RTR1 ããã³ RTR2 ããã€ã¹ãé€ã)ã
ã¿ã¹ã¯ã¯ãããŒã«ã«ãšãªã¢ãŒãã® XNUMX çš®é¡ã®ã³ã³ãœãŒã«ãå®çŸ©ããŸãã ãªã¢ãŒã ã³ã³ãœãŒã«ã䜿çšãããšãSSH ãããã³ã«ã Telnet ãããã³ã«ãªã©ãä»ããŠãªã¢ãŒãæ¥ç¶ãå®è£
ã§ããŸãã
ãã®ã¿ã¹ã¯ãå®äºããã«ã¯ã次ã®ã³ãã³ããå ¥åããå¿ èŠããããŸãã
SW1(config)# line vty 0 4
SW1(config-line)# login authentication default
SW1(config-line)# exit
SW1(config)#
ããŒã line vty 0 4
ä»®æ³ç«¯æ«åç· 0 ãã 4 ã®èšå®ã«ç§»è¡ããŸãã
ããŒã login authentication default
ä»®æ³ã³ã³ãœãŒã«ã§ããã©ã«ãã®èªèšŒã¢ãŒããæå¹ã«ããŸããããã©ã«ã ã¢ãŒãã¯ãåã®ã¿ã¹ã¯ã§ã³ãã³ãã䜿çšããŠèšå®ãããŸããã aaa authentication login default local
.
ãªã¢ãŒã ã³ã³ãœãŒã« ã»ããã¢ãã ã¢ãŒããçµäºããã«ã¯ã次ã®ã³ãã³ãã䜿çšããŸãã exit
.
ä¿¡é Œã§ãããã¹ãã¯ãããããã€ã¹ããå¥ã®ããã€ã¹ãžã® Telnet çµç±ã®ãã¹ãæ¥ç¶ã§ãã ãã®ããã«ã¯ãéžæããæ©åšäžã§åºæ¬çãªã¹ã€ããã³ã°ãš IP ã¢ãã¬ãã·ã³ã°ãèšå®ããå¿ èŠãããããšãèæ ®ãã䟡å€ããããŸãã
SW3#telnet 2001:100::10
User Access Verification
Username: wsrvuz19
Password:
SW1>
b. èªèšŒãæåããåŸããªã¢ãŒã ã³ã³ãœãŒã«ãããã°ã€ã³ããå ŽåããŠãŒã¶ãŒã¯ããã«æ倧ã¬ãã«ã®ç¹æš©ãæã€ã¢ãŒãã«å
¥ãå¿
èŠããããŸãã
ãã®åé¡ã解決ããã«ã¯ãä»®æ³ç«¯æ«åç·ã®èšå®ã«æ»ãã次ã®ã³ãã³ãã§ç¹æš©ã¬ãã«ãèšå®ããå¿
èŠããããŸãã privilege level 15
ããã§ã 15 ãæ倧ã¬ãã«ã0 ãæå°ç¹æš©ã¬ãã«ã§ãã
SW1(config)# line vty 0 4
SW1(config-line)# privilege level 15
SW1(config-line)# exit
SW1(config)#
ãã¹ãã¯ãåã®ãµããã©ã°ã©ãã®è§£æ±ºçãã€ãŸã Telnet çµç±ã®ãªã¢ãŒãæ¥ç¶ã«ãªããŸãã
SW3#telnet 2001:100::10
User Access Verification
Username: wsrvuz19
Password:
SW1#
èªèšŒåŸããŠãŒã¶ãŒã¯éç¹æš©ã¢ãŒãããã€ãã¹ããŠçŽã¡ã«ç¹æš©ã¢ãŒãã«å ¥ããŸããããã¯ãã¿ã¹ã¯ãæ£ããå®äºããããšãæå³ããŸãã
CDã ããŒã«ã« ã³ã³ãœãŒã«ã§å¿
èŠæ§ãæ§æããèªèšŒãæåãããšããŠãŒã¶ãŒã¯æå°éã®æš©éã¬ãã«ã§ã¢ãŒãã«å
¥ãå¿
èŠããããŸãã
ãããã®ã¿ã¹ã¯ã®ã³ãã³ãã®æ§é ã¯ã以åã«è§£æ±ºãããã¿ã¹ã¯ 4.a ããã³ 4.b ãšäžèŽããŸãã ããŒã line vty 0 4
ã«çœ®ãæãããã console 0
:
SW1(config)# line console 0
SW1(config-line)# login authentication default
SW1(config-line)# privilege level 0
SW1(config-line)# exit
SW1(config)#
ãã§ã«è¿°ã¹ãããã«ãæå°ç¹æš©ã¬ãã«ã¯æ°å€ 0 ã«ãã£ãŠæ±ºãŸããŸãããã§ãã¯ã¯æ¬¡ã®ããã«å®è¡ã§ããŸãã
SW1# exit
User Access Verification
Username: wsrvuz19
Password:
SW1>
èªèšŒåŸãã¿ã¹ã¯ã«èšèŒãããŠããããã«ããŠãŒã¶ãŒã¯éç¹æš©ã¢ãŒãã«å ¥ããŸãã
e. BR1 ã§ã¯ãããŒã«ã« ã³ã³ãœãŒã«ã§èªèšŒãæåãããšããŠãŒã¶ãŒã¯æ倧ã¬ãã«ã®ç¹æš©ãæã€ã¢ãŒãã«ãªãå¿
èŠããããŸãã
BR1 ã§ã®ããŒã«ã« ã³ã³ãœãŒã«ã®ã»ããã¢ããã¯æ¬¡ã®ããã«ãªããŸãã
BR1(config)# line console 0
BR1(config-line)# login authentication default
BR1(config-line)# privilege level 15
BR1(config-line)# exit
BR1(config)#
ãã§ãã¯ã¯åã®æ®µèœãšåãæ¹æ³ã§å®è¡ãããŸãã
BR1# exit
User Access Verification
Username: wsrvuz19
Password:
BR1#
èªèšŒåŸãç¹æš©ã¢ãŒãã«ç§»è¡ããŸãã
5. ãã¹ãŠã®ããã€ã¹ã§ãç¹æš©ã¢ãŒãã«å ¥ãããã« wsr ãã¹ã¯ãŒããèšå®ããŸãã
ã¿ã¹ã¯ã§ã¯ãç¹æš©ã¢ãŒãã®ãã¹ã¯ãŒããæšæºãšããŠã¯ãªã¢ ããã¹ãã§ä¿åããå¿
èŠããããšèšèŒãããŠããŸããããã¹ãŠã®ãã¹ã¯ãŒãã®æå·åã¢ãŒãã§ã¯ãã¹ã¯ãŒããã¯ãªã¢ ããã¹ãã§è¡šç€ºã§ããŸããã ç¹æš©ã¢ãŒãã«å
¥ããã¹ã¯ãŒããèšå®ããã«ã¯ã次ã®ã³ãã³ãã䜿çšããŸãã enable password wsr
ã ããŒã¯ãŒãã䜿çšãã password
ããã¹ã¯ãŒããä¿åãããã¿ã€ãã決å®ããŸãã ãŠãŒã¶ãŒã®äœææã«ãã¹ã¯ãŒããæå·åããå¿
èŠãããå ŽåãããŒã¯ãŒãã¯åèªã§ããã secret
ããªãŒãã³ã¹ãã¬ãŒãžã«äœ¿çšãããŸã password
.
çŸåšã®æ§æã衚瀺ããŠèšå®ã確èªã§ããŸãã
SW1(config)# enable password wsr
SW1(config)# do show running-config
...
enable password wsr
!
username wsrvuz19 privilege 15 secret 5 $1$5I66$TB48YmLoCk9be4jSAH85O0
...
ã¿ã¹ã¯ã«èšèŒãããŠããããã«ããŠãŒã¶ãŒã®ãã¹ã¯ãŒãã¯æå·åããã圢åŒã§ä¿åãããç¹æš©ã¢ãŒãã«å
¥ããã¹ã¯ãŒãã¯ã¯ãªã¢ ããã¹ãã§ä¿åãããŠããããšãããããŸãã
ãã¹ãŠã®ãã¹ã¯ãŒããæå·åãããŠä¿åãããŠããããšã確èªããã«ã¯ã次ã®ã³ãã³ãã䜿çšããŸãã service password-encryption
ã çŸåšã®æ§æã衚瀺ãããšã次ã®ããã«ãªããŸãã
SW1(config)# do show running-config
...
enable password 7 03134819
!
username wsrvuz19 privilege 15 secret 5 $1$5I66$TB48YmLoCk9be4jSAH85O0
...
ãã¹ã¯ãŒãã¯å¹³æã§ã¯è¡šç€ºãããªããªããŸãã
åºæïŒ habr.com