ANTON
|
2012-07-04 11:10:54, Á¶È¸ : 190, Ãßõ : 52 |
½Ã½ºÄÚ ¶ó¿ìÅÍ´Â ·¹º§ 1¿¡¼ ·¹º§ 15±îÁö 15 ´Ü°èÀÇ ±ÇÇÑ ¼öÁØÀÌ ÀÖ´Ù.
enable ¸í·É¾î¸¦ »ç¿ëÇÏ¿© privileged EXEC ¸ðµå·Î ·¹º§À» º¯°æÇϸé Á¶È¸»Ó¸¸ ¾Æ´Ï¶ó ¼³Á¤ º¯°æ µîÀÇ ÀÛ¾÷À»ÇÒ ¼ö ÀÖ´Ù.
privileged EXEC ¸ðµå·Î º¯°æÇÒ ¶§ »ç¿ëÇÏ´Â enable Æнº¿öµå¸¦ ¼³Á¤Çϱâ À§Çؼ´Â enable password¿Í enable secretÀÇ µÎ °¡Áö ¸í·É¾î¸¦ »ç¿ëÇÒ ¼ö ÀÖ´Ù.
enable password ¸í·É¾î´Â ±âº»ÀûÀ¸·Î Æнº¿öµå¸¦ ¾ÏÈ£ÈÇÏÁö ¾Ê´Â´Ù. enable password ¸í·ÉÀ» ½ÇÇàÇÑ ´ÙÀ½ service password-encryption ¸í·ÉÀ» »ç¿ëÇϸé Æнº¿öµå¸¦ ¾ÏÈ£ÈÇÒ ¼ö ÀÖÁö¸¸ ¾ÏÈ£È ¹æ¹ýÀÌ ºñ±³Àû Ãë¾àÇÏ¿© º¸¾È À¯Áö°¡ ¾î·Æ´Ù. enable password ¸í·É¾î ¸¦ »ç¿ëÇÏ¿© Æнº¿öµå¸¦ ¼³Á¤Çϱâ À§Çؼ´Â ¾Æ·¡¿Í °°Àº ¸í·ÉÀ» »ç¿ëÇÑ´Ù.
enable secret
enable secret´Â MD5 ¾Ë°í¸®ÁòÀ» ÀÌ¿ëÇÏ¿© ¾ÏÈ£ÈµÈ Æнº¿öµå¸¦ ¼³Á¤ÇÑ´Ù.
enable pssword [»ç¿ëÀ» ¿øÇÏ´Â Æнº¿öµå]
service password-encryption
Service password-encryption [¸ðµç Æнº¿öµå¸¦ MD5·Î ¾ÏÈ£È]
Line consol 0
Password ºñ¹ø
Login
ÄÜ¼Ö ¿¬°á½Ã Password¸¦ ¹¯µµ·Ï ¼³Á¤
Logging synchronous
¸í·É¾î ÀÔ·ÂÁß ½Ã½ºÅÛ ¸Þ½ÃÁö°¡ ¶ß¸é ÀÚµ¿À¸·Î ÁÙÀ» ¹Ù²Ù¾î ÀÔ·ÂÁßÀÎ ¸í·É¾î¸¦ ´Ù½Ã Ç¥½ÃÇÑ´Ù.
Exec-timeout 30
30ºÐµ¿¾È ÀÔ·ÂÀÌ ¾øÀ¸¸é Session Á¾·á
Access-list 23 permit 1.1.1.1
Access-list 23 deny any
ÅÚ³Ý Á¢ÃËÀ» À§ÇÑ ACL
Exec-timeout 30
30ºÐµ¿¾È ÀÔ·Â ¾øÀ¸¸é ²÷¾î¹ö¸®±â
Transport input telnet
telnet protocol ¸¸ Çã¿ëÇÏ°Ú´Ù.
Password ºñ¹ø
Åڳݺñ¹ø ¼³Á¤
Access-class 23 in : 23¹ø ACL Àû¿ë
IP ÁÖ¼Ò ÇÊÅ͸µÀ» ÅëÇÑ ÅÚ³Ý ¿¬°á Á¦ÇÑ
VTY Æ÷Æ®´Â ±âº»ÀûÀ¸·Î ¿ÜºÎÀÇ ¿¬°á ½Ãµµ¸¦ ¸ðµÎ ¹Þ¾ÆµéÀ̹ǷΠ¿¬°áÀ» ½ÃµµÇÏ´Â ÆÐŶÀÇ IP ÁÖ¼Ò¸¦ ÇÊÅ͸µÇÏ¿© Çã°¡µÈ IP¿¡°Ô¸¸ ¿¬°á ½Ãµµ¸¦ Çã¿ëÇϵµ·Ï ÇÏ¿©¾ß ÇÑ´Ù. ´ÙÀ½Àº 172.16.5.105, 172.16.5.106 IP ÁÖ¼Ò¸¸ VTY Æ÷Æ®·Î Á¢¼ÓÇÒ ¼ö ÀÖ°Ô ÇÏ´Â ACLÀ» »ý¼ºÇÏ°íÀû¿ëÇÏ´Â ¹æ¹ýÀÌ´Ù.
¾ÈÀüÇÑ ÅÚ³Ý ¿¬°áÀ» À§ÇÑ Ãß°¡ ¼³Á¤
Ãß°¡ÀûÀ¸·Î VTY Á¢¼ÓÀ» º¸´Ù ¾ÈÀüÇÏ°Ô Çϱâ À§Çؼ ¾Æ·¡ÀÇ ¸í·É¾î°¡ »ç¿ëµÉ ¼ö ÀÖ´Ù.
exec-timeout [ºÐ] [ÃÊ]
service tcp-keepalives-in ¸í·É¾î¸¦ »ç¿ëÇÏ¸é ¶ó¿ìÅÍÀÇ ¸ðµç ¿¬°áÀ» °è¼Ó ¸ð´ÏÅ͸µÇÏ¿© ºñÁ¤»óÀûÀ¸·Î Á¾·áµÈ ¼¼¼ÇÀ» ¹ß°ßÇϸé À̸¦ Á¾·á½ÃŲ´Ù. ¸í·É¾îÀÇ »ç¿ë¹ýÀº ¾Æ·¡¿Í °°´Ù.
service tcp-keepalives-in
¾Æ·¡ ȸéÀº VTY ¶óÀο¡ service tcp-keepalives-in ¸í·ÉÀ» Àû¿ëÇÏ°í exec-timeoutÀ» 5ºÐ 0ÃÊ·Î Àû¿ëÇÏ´Â ¿¹¸¦ º¸¿©ÁØ´Ù.
SSH¸¦ »ç¿ëÇÑ ÅÚ³Ý Á¢¼Ó
SSH¸¦ ¼³Á¤ÇÏ´Â ¹æ¹ýÀº ´ÙÀ½°ú °°´Ù
Router(config)# hostname [router name]
Router-name(config)# ip domain-name [domain name]
Router-name(config)# crypto key generate rsa
Router-name(config)# ip ssh time-out [time out value]
Router-name(config)# ip ssh authentication-retries [retries value]
Router-name(config)# line vty 0 4
Router-name(config-line)# transport input ssh
|
|
|