Download presentation
Presentation is loading. Please wait.
Published byMark Sherman Modified over 9 years ago
1
© 1999, Cisco Systems, Inc. 11-1 第十一章 配置 Novell IPX
2
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-2 通过本章的学习,您应该掌握以下内容: 描述 IPX 协议的基本作用 确定 IPX 网络的网络号和端口的封装类型 启用 Novell IPX 协议 查看 IPX 协议的连接状态 配置 IPX 访问列表和 SAP 数据过滤 本章目标
3
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-3 NetWare File Server NetWare File Server NetWare 网络中的 Cisco 路由器
4
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-4 Novell NetWare 协议族 1 2 3 4 5 6 7 Media Access Protocols (Ethernet, Token Ring, WAN, others) Physical Data Link Network Session Transport Presentation Application Novell NetWare 协议 OSI 参考模型 IPX (Internetwork Packet Exchange) SPX SA P RIP NLSP NETBIOSAPPLICATIONS NCP
5
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-5 80 位的地址 ( 网络. 主机 ) 端口的 MAC 地址是其逻辑地址的一部分 每个端口可以有多个局域网封装类型 缺生路由协议是 IPX RIP 用 SAP 宣告 Novell 服务 NetWare 客户端使用 GNS 数据包查找服务 Novell NetWare 主要特性
6
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-6 0000.0c56.de33 Novell IPX 地址 E0 E1 S0 48 bits (from MAC) Node 0000.0c56.de34 0000.0c56.de33
7
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-7 Novell IPX 地址 4a1d.0c56.de33 E0 E1 S0 48 bits (from MAC) Network.Node 3f.0c56.de34 2c.0c56.de33 Network 4a1d Network 3f Network 2c Up to 32 bits
8
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-8 NetWare 基本作用 NW File Server
9
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-9 NetWare 基本作用 NW File Server 0080.C712.3456-Layer2 Mac NIC
10
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-10 NetWare 基本作用 NW File Server 1a.0080.C712.3456-Layer3 Net NIC
11
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-11 NW File Server NetWare 基本作用 1a.0080.C712.3456-Layer3 Net NetWare Services 2b.0000.0000.0001-Internal Net NIC
12
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-12 - NW Software Router NetWare 基本作用 1a.0080.C712.3456 NetWare Services 2b.0000.0000.0001 NIC
13
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-13 NetWare 基本作用 1a.0080.C712.3456 NetWare Services 2b.0000.0000.0001 2b 1a... 2b 1a... NIC Routing Table
14
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-14 NetWare 基本作用 File Server - 4 Print Server - 47 1a.0080.C712.3456 NetWare Services 2b.0000.0000.0001 2b 1a... 2b 1a... Services Table 4 47 …... 4 47 …... NIC Routing Table
15
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-15 NetWare 基本作用 File Server - 4 Print Server - 47 1a.0080.C712.3456 NetWare Services 2b.0000.0000.0001 2b 1a... 2b 1a... Services Table 4 47 …... 4 47 …... Periodic Broadcasts on 1a.FFFF.FFFF.FFFF NIC Routing Table
16
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-16 1a.0080.C712.3456 NetWare Services 2b 1a... 2b 1a... Services Table 4 47 …... 4 47 …... Periodic Broadcasts on 1a.FFFF.FFFF.FFFF 0000.0C12.3456 - Layer2 Mac e0 NIC Routing Table 2b.0000.0000.0001 NetWare 基本作用
17
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-17 Network and Encapsulation must match Network and Encapsulation must match 1a.0080.C712.3456 NetWare Services 2b 1a... 2b 1a... Services Table 4 47 …... 4 47 …... Periodic Broadcasts on 1a.FFFF.FFFF.FFFF 1a. 0000.0C12.3456 - Layer3 Net e0 s0 NIC Routing Table 2b.0000.0000.0001 NetWare 基本作用
18
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-18 Network and Encapsulation must match Network and Encapsulation must match 1a.0080.C712.3456 NetWare Services 2b 1a... 2b 1a... Services Table 4 47 …... 4 47 …... Periodic Broadcasts on 1a.FFFF.FFFF.FFFF 1a. 0000.0C12.3456 - Layer3 Net e0 s0 1b. 0000.0C12.3456 Routing Table 1a 1b 2b... 1a 1b 2b... NIC Routing Table 2b.0000.0000.0001 NetWare 基本作用
19
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-19 1a.0080.C712.3456 NetWare Services 2b 1a 1b... 2b 1a 1b... Services Table 4 47 …... 4 47 …... Periodic Broadcasts on 1a.FFFF.FFFF.FFFF 1a. 0000.0C12.3456 e0 s0 1b. 0000.0C12.3456 Routing Table 1a 1b 2b... 1a 1b 2b... NIC Routing Table 2b.0000.0000.0001 NetWare 基本作用
20
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-20 1a.0080.C712.3456 NetWare Services 2b 1a 1b... 2b 1a 1b... Services Table 4 47 …... 4 47 …... Periodic Broadcasts on 1a.FFFF.FFFF.FFFF e0 s0 Routing Table 1a 1b 2b... 1a 1b 2b... 4 47 …... 4 47 …... Services Table NIC Routing Table 1a. 1b. 2b.0000.0000.0001 NetWare 基本作用
21
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-21 1a.0080.C712.3456 NetWare Services 2b.0000.0000.0001 2b 1a 1b... 2b 1a 1b... Services Table 4 47 …... 4 47 …... Periodic Broadcasts on 1a.FFFF.FFFF.FFFF e0 s0 Routing Table 1a 1b 2b... 1a 1b 2b... 4 47 …... 4 47 …... Services Table NW Client NIC 1a.0010.5A12.3456 GNS Routing Table 1a. 1b. NetWare 基本作用
22
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-22 Routing Table 1a.0080.C712.3456 NetWare Services 2b.0000.0000.0001 (IPX Internal Network) 2b 1a 1b... 2b 1a 1b... Services Table 4 47 …... 4 47 …... Periodic Broadcasts on 1a.FFFF.FFFF.FFFF e0 s0 Routing Table 1a 1b 2b... 1a 1b 2b... 4 47 …... 4 47 …... Services Table NW Client NIC 1a.0010.5A12.3456 GNS GNS Resp 1a. 1b. NetWare 基本作用
23
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-23 IPX Network 网络号 询问管理员
24
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-24 IPX Network 网络号 cdp 询问管理员 通过命令查看网络号
25
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-25 IPX Network 网络号 询问管理员 通过命令查看网络号 使用 NetWare 命令查看网络号 NetWare config cdp
26
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-26 Ethernet_802.3 (default for NetWare 3.11 or earlier) 802.3 IPX Novell 多种封装类型 以太网四种帧类型 Novell Name Framing Structure
27
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-27 Ethernet_802.2 (default for NetWare 3.12 and later ) 802.3802.2 LLCIPX Ethernet_802.3 (default for NetWare 3.11 and earlier) 802.3 IPX Novell 多种封装类型 以太网四种帧类型 Novell Name Framing Structure
28
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-28 Ethernet_802.2 (default for NetWare 3.12 and later ) 802.3802.2 LLCIPX Ethernet_802.3 (default for NetWare 3.11 and earlier) 802.3 IPX Novell 多种封装类型 以太网四种帧类型 Ethernet_II Ethernet IPX Novell Name Framing Structure
29
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-29 Ethernet_802.2 (default for NetWare 3.12 and later versions ) 802.3802.2 LLCIPX Ethernet_SNAP 802.3802.2 LLCSNAPIPX Ethernet_802.3 (default for NetWare 3.11 and earlier versions) 802.3 IPX Novell 多种封装类型 Ethernet_II Ethernet IPX Novell Name Framing Structure 以太网四种帧类型
30
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-30 Cisco 封装类型 Novell IPX 名称 Cisco IOS 名称 Ethernet Token Ring FDDI FDDI_SNAP FDDI_802.2 FDDI_Raw Ethernet_802.3 Ethernet_802.2 Ethernet_II Ethernet_SNAP Token-Ring Token-Ring_SNAP
31
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-31 Novell IPX 名称 Cisco IOS 名称 Token-Ring Token-Ring_SNAP Ethernet Token Ring FDDI FDDI_SNAP FDDI_802.2 FDDI_Raw Ethernet_802.3 Ethernet_802.2 Ethernet_II Ethernet_SNAP Cisco 封装类型 当配置 IPX 网络时要指明端口封装类型 novell-ether sap arpa snap sap snap sap novell-fddi
32
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-32 练 习: IPX 参数设置 Encapsulation Network Address R3 Interface Name S0 S1 E1 写出路由器 3 的端口封装类型 S0 hdlc Network b001 E0 SAP E1 S1 S1 hdlc S0 Network c0b0 Network d100 Network b1b0 E0 novell-ether R3 R4 E1 R2 R1
33
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-33 练 习: IPX 参数设置 Encapsulation Network Address R3 Interface Name S0 S1 E1 d100 写出路由器 3 的端口封装类型 S0 hdlc Network b001 E0 SAP E1 S1 S1 hdlc S0 Network c0b0 Network d100 Network b1b0 E0 novell-ether R3 R4 E1 R2 R1
34
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-34 练 习: IPX 参数设置 Encapsulation Network Address R3 Interface Name S0hdlc S1 E1 d100 写出路由器 3 的端口封装类型 S0 hdlc Network b001 E0 SAP E1 S1 S1 hdlc S0 Network c0b0 Network d100 Network b1b0 E0 novell-ether R3 R4 E1 R2 R1
35
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-35 练 习: IPX 参数设置 Encapsulation Network Address R3 Interface Name S0hdlc S1 E1 c0b0 d100 写出路由器 3 的端口封装类型 S0 hdlc Network b001 E0 SAP E1 S1 S1 hdlc S0 Network c0b0 Network d100 Network b1b0 E0 novell-ether R3 R4 E1 R2 R1
36
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-36 练 习: IPX 参数设置 Encapsulation Network Address R3 Interface Name S0hdlc S1hdlc E1 c0b0 d100 写出路由器 3 的端口封装类型 S0 hdlc Network b001 E0 SAP E1 S1 S1 hdlc S0 Network c0b0 Network d100 Network b1b0 E0 novell-ether R3 R4 E1 R2 R1
37
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-37 练 习: IPX 参数设置 Encapsulation Network Address R3 Interface Name S0hdlc S1hdlc E1b1b0 c0b0 d100 写出路由器 3 的端口封装类型 S0 hdlc Network b001 E0 SAP E1 S1 S1 hdlc S0 Network c0b0 Network d100 Network b1b0 E0 novell-ether R3 R4 E1 R2 R1
38
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-38 写出路由器 3 的端口封装类型 Encapsulation Network Address R3 Interface Name S0hdlc S1hdlc E1 novell-ether 练 习: IPX 参数设置 S0 hdlc Network b001 E0 SAP E1 S1 S1 hdlc S0 Network c0b0 Network d100 Network b1b0 E0 novell-ether R3 R4 E1 b1b0 c0b0 d100 R2 R1
39
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-39 Novell 的 IPX RIP 路由协议 使用 ticks (1/18 sec.) 和跳数 ( 最大值 15 跳 ) 缺省情况下, RIP 每隔 60 秒向相邻的路由器广播路由信息 缺省情况下, SAP 每隔 60 秒向相邻的路由器广播 NetWare 服务信息 RIP SAP Tables RIP SAP Tables RIP SAP Tables RIP SAP Tables DCBA
40
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-40 Server advertises file service SAP 数据包在 NetWare 网络中宣告服务 服务宣告协议 (service advertising protocol) Server advertises print service Server advertises file service Client A
41
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-41 SAP SAP 数据包在 NetWare 网络中宣告服务 在网络中增加了额外的流量 Server advertises print service Server advertises file service Router A listens to SAPs SAP SAP table Client A 服务宣告协议 (SAP)
42
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-42 得到最近服务协议 (get nearest server) File Server NetWare Client
43
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-43 得到最近服务协议 (GNS) File Server NetWare Client GNS request GNS 是客户端向服务器发出的广播帧
44
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-44 得到最近服务协议 (GNS) File Server NetWare Client GNS request GNS 是客户端向服务器发出的广播帧 NetWare 服务器和 Cisco 路由其可以得到 SAP 数据包
45
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-45 得到最近服务协议 (GNS) GNS 是客户端向服务器发出的广播帧 NetWare 服务器和 Cisco 路由其可以得到 SAP 数据包 NetWare 服务器提供 GNS 响应 File Server NetWare Client GNS request GNS reply
46
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-46 配置 Novell IPX 全局配置 IPX 路由 RIP IPX
47
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-47 配置 Novell IPX 全局配置 IPX 路由 负载共享 RIP IPX
48
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-48 RIP Network 9e encap arpa Network 4a encap snap IPX 配置 Novell IPX 全局配置 IPX 路由 负载共享 端口配置 网络号 封装类型
49
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-49 Novell IPX 的全局配置 ipx routing [ node ] Router(config)# 启用 Novell IPX 路由
50
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-50 Router(config)# ipx maximum-paths paths Novell IPX 的全局配置 配置负载共享 缺省 = 1 Router(config)# ipx routing [ node ] 启用 Novell IPX 路由
51
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-51 Novell IPX 的端口配置 Router(config-if)# ipx network network [ encapsulation encapsulation type ] 在端口上启用 IPX 路由 分配 IPX 网络号 指明端口的封装类型
52
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-52 FS1 NW 3.11 FS2 NW 4.11 e0.1 NIC 1a.0080.C712.3456 1b.0080.C712.3457 Ethernet_802.3 Ethernet_802.2 1a - novell-ether 1b - sap e0.2 NetWare 子端口
53
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-53 Novell IPX 端口配置 Router(config-if)# ipx network network [ encapsulation encapsulation-type ] [ secondary ] 分配主要和次要的网络号和各自的封装类型 Router(config)# interface type number.subinterface-number 建立子端口, 启用 IPX 路由,指明端口的封装类型 或者 Router(config-subif)# ipx network network [ encapsulation encapsulation type ]
54
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-54 Novell IPX 配置举例 A Network 9e Network 1 E0 E1 S0 Network 4a Network 6c S1 9e.0800.4313.df56 Encapsulation = novell-ether 4a.1234.0000.abcd Encapsulation = sap 6c.0800.1213.13de Encapsulation = sap Network 3 B C
55
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-55 ipx routing ipx maximum-paths 2 interface ethernet 0.1 ipx network 9e encapsulation novell-ether interface ethernet 0.2 ipx network 6c encapsulation sap interface ethernet 1 ipx network 4a encapsulation sap interface serial 0 ipx network 1 Interface serial 1 ipx network 3 Novell IPX 配置举例 A Network 9e Network 1 E0 E1 S0 Network 4a Network 6c S1 9e.0800.4313.df56 Encapsulation = novell-ether 4a.1234.0000.abcd Encapsulation = sap 6c.0800.1213.13de Encapsulation = sap Network 3 B C
56
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-56 查 看 IPX show ipx interface show ipx route show ipx servers show ipx traffic Monitoring Commands
57
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-57 查 看 IPX show ipx interface show ipx route show ipx servers show ipx traffic Monitoring Commands Troubleshooting Commands debug ipx routing activity debug ipx sap activity ping ipx
58
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-58 查 看 IPX 端口状态 wg_ro_a#show ipx interface e0 Ethernet0 is up, line protocol is up IPX address is ABC.00e0.1e5d.ae2f, NOVELL-ETHER [up] Delay of this IPX network, in ticks is 1 throughput 0 link delay 0 IPXWAN processing not enabled on this interface. IPX SAP update interval is 60 seconds IPX type 20 propagation packet forwarding is disabled Incoming access list is not set Outgoing access list is not set IPX helper access list is not set SAP GNS processing enabled, delay 0 ms, output filter list is not set SAP Input filter list is not set SAP Output filter list is not set SAP Router filter list is not set Input filter list is not set Output filter list is not set Router filter list is not set Netbios Input host access list is not set Netbios Input bytes access list is not set Netbios Output host access list is not set Netbios Output bytes access list is not set Updates each 60 seconds aging multiples RIP: 3 SAP: 3 SAP interpacket delay is 55 ms, maximum size is 480 bytes
59
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-59 查看 IPX 路由表 wg_ro_a#show ipx route Codes: C - Connected primary network, c - Connected secondary network S - Static, F - Floating static, L - Local (internal), W - IPXWAN R - RIP, E - EIGRP, N - NLSP, X - External, A - Aggregate s - seconds, u - uses, U - Per-user static 2 Total IPX routes. Up to 1 parallel paths and 16 hops allowed. No default route known. C ABC (NOVELL-ETHER), Et0 R DEF [02/01] via ABC.00e0.1e5d.c860, 40s, Et0
60
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-60 查看 IPX 服务器 wg_ro_a#show ipx server Codes: S - Static, P - Periodic, E - EIGRP, N - NLSP, H - Holddown, + = detail U - Per-user static 2 Total IPX Servers Table ordering is based on routing and server info Type Name Net Address Port Route Hops Itf p 4 fs1 11.0000.0000.0001:0451 4/03 4 Et0 p 4 fs2 21.0000.0000.0001:0451 4/03 4 Et0
61
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-61 查看 IPX 通信量 wg_ro_a#show ipx traffic System Traffic for 0.0000.0000.0001 System-Name: wg_ro_a Rcvd: 15 total, 0 format errors, 0 checksum errors, 0 bad hop count, 0 packets pitched, 15 local destination, 0 multicast Bcast: 13 received, 6 sent Sent: 6 generated, 0 forwarded 0 encapsulation failed, 0 no route SAP: 1 Total SAP requests, 0 Total SAP replies, 0 servers 1 SAP general requests, 0 ignored, 0 replies 0 SAP Get Nearest Server requests, 0 replies 0 SAP Nearest Name requests, 0 replies 0 SAP General Name requests, 0 replies 0 SAP advertisements received, 0 sent 0 SAP flash updates sent, 0 SAP format errors RIP: 1 RIP requests, 0 ignored, 0 RIP replies, 2 routes 13 RIP advertisements received, 0 sent 0 RIP flash updates sent, 0 RIP format errors Echo: Rcvd 0 requests, 0 replies Sent 0 requests, 0 replies 0 unknown: 0 no socket, 0 filtered, 0 no helper 0 SAPs throttled, freed NDB len 0 Watchdog: 0 packets received, 0 replies spoofed
62
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-62 wg_ro_a#debug ipx routing activity IPX routing debugging is on IPXRIP: positing full update to 3010.ffff.ffff.ffff via Ethernet0 (broadcast) IPXRIP: positing full update to 3000.ffff.ffff.ffff via Ethernet1 (broadcast) IPXRIP: positing full update to 3020.ffff.ffff.ffff via Serial0 (broadcast) IPXRIP: positing full update to 3021.ffff.ffff.ffff via Serial1 (broadcast) IPXRIP: sending update to 3020.ffff.ffff.ffff via Serial0 IPXRIP: src=3020.0000.0c03.14d8, dst=3020.ffff.ffff.ffff, packet sent network 3021, hops 1, delay 6 network 3010, hops 1, delay 6 network 3000, hops 1, delay 6 IPXRIP: sending update to 3021.ffff.ffff.ffff via Serial1 IPXRIP: src=3021.0000.0c03.14d8, dst=3021.ffff.ffff.ffff, packet sent network 3020, hops 1, delay 6 network 3010, hops 1, delay 6 network 3000, hops 1, delay 6 IPXRIP: sending update to 3010.ffff.ffff.ffff via Ethernet0 IPXRIP: src=3010.aa00.0400.0284, dst=3010.ffff.ffff.ffff, packet sent network 3030, hops 2, delay 7 network 3020, hops 1, delay 1 network 3021, hops 1, delay 1 network 3000, hops 1, delay 1 IPXRIP: sending update to 3000.ffff.ffff.ffff via Ethernet1 IPX 路由排错
63
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-63 wg_ro_a#debug ipx sap activity IPX service debugging is on wg_ro_a# 05:31:18: IPXSAP: positing update to 1111.ffff.ffff.ffff via Ethernet0 (broadcast) (full) 05:31:18: IPXSAP: Update type 0x2 len 288 src:1111.00e0.1e5d.ae2f dest:1111.ffff.ffff.ffff(452) 05:31:18: type 0x7, ”ps21", 21.0000.0000.0001(451), 2 hops 05:31:18: type 0x4, "fs31", 31.0000.0000.0001(451), 2 hops 05:31:18: type 0x4, "fs41", 41.0000.0000.0001(451), 2 hops 05:31:18: type 0x7, "ps51", 51.0000.0000.0001(451), 2 hops wg_ro_a# IPX SAP 排错
64
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-64 IPX Ping wg_ro_a# ping ipx 211.0000.0c01.f4cf Type escape sequence to abort. Sending 5, 100-byte IPXcisco Echoes to 211.0000.0c01.f4cf, timeout is 2 seconds. !!!!! Success rate is 100 percent (0/5)
65
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-65 Use access list 800-899 for standard Deny Permit Destination Address Source Address An Example Using an IPX Packet Data Packet (IPX header) Frame Header (for example, novell-ether) 用访问列表检测信息
66
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-66 Use access list 900-999 for extended Deny Permit Destination Address Source Address Data Packet (IPX header) Frame Header (for example, novell-ether) Protocol, Socket Number 用访问列表检测信息
67
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-67 Use access list 1000-1099 for SAP filtering Deny Permit Service Advertisement An Example Using an IPX Packet Data Packet (IPX header) Frame Header (for example, novell-ether) 用访问列表检测信息
68
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-68 Service Advertisement Use ACL 800-899 standard 900-999 extended 1000-1099 SAP Deny Permit Destination Address Source Address An Example Using an IPX Packet Data Packet (IPX header) Frame Header (for example, novell-ether) 用访问列表检测信息 Protocol, Socket Number
69
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-69 IPX 访问列表的主要特性 IPX 地址格式为 网络. 主机 Socket 号代表上层应用 标准访问列表 (800-899) 能过滤源地址和目标地址 扩展访问列表 (900-999) 能过滤特定的协议和 socket 号所代表的上层应用 SAP 访问列表 (1000-1099) 能够过滤网络中的 SAP 数据包
70
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-70 频繁的升级信息会占用数据传输的带宽 控制 IPX Server SAP RIP Router SAP RIP SAP RIP WAN Link Flooded with Overhead Traffic Client GNS
71
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-71 Step 1: 设置访问列表的参数 Router(config)# access-list access-list-number { deny | permit } { test conditions } Step 2: 在端口上应用访问列表 Router(config-if)# ipx access-group access-list-number | name [ in | out ] 访问列表配置命令 800-899 – 标准 900-999 – 扩展
72
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-72 设置访问列表的参数 标准访问列表的编号为 800 到 899 Router(config)# access-list access-list-number { deny | permit } source-network [.source-node [ source-node-mask ]] [ destination-network ] [.destination-node [ destination-node-mask ]]] IPX 标准访问列表的配置
73
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-73 IPX 标准访问列表的配置 Router(config-if)# ipx access-group access-list-number [ in | out ] 在端口上应用访问列表 设置访问列表的参数 标准访问列表的编号为 800 到 899 Router(config)# access-list access-list-number { deny | permit } source-network [.source-node [ source-node-mask ]] [ destination-network ] [.destination-node [ destination-node-mask ]]]
74
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-74 标准 IPX 访问列表配置举例 Client Server Client E0 E2 E1 Network 2b Network 3c Network 4d access-list 800 permit 2b 4d (implicit deny all) int e 0 ipx network 4d ipx access-group 800 out int e 1 ipx network 3c int e 2 ipx network 2b int e3 ipx network 1a Server E3 Network 1a
75
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-75 IPX 扩展访问列表的配置 Router(config)# access-list access-list-number { deny | permit } protocol [ source-network ] [[[.source-node ] source-node-mask ] | [.source-node source-network-mask. source-node-mask ]] [ source-socket ] [ destination.network ] [[[.destination-node ] destination-node-mask ] | [.destination-node destination-network-mask. destination-nodemask ]] [ destination-socket ] [ log ] 设置访问列表的参数 扩展访问列表的编号范围为 900 到 999
76
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-76 IPX 扩展访问列表的配置 Router(config-if)# ipx access-group access-list-number [ in | out ] 在端口上应用访问列表 Router(config)# access-list access-list-number { deny | permit } protocol [ source-network ] [[[.source-node ] source-node-mask ] | [.source-node source-network-mask. source-node-mask ]] [ source-socket ] [ destination.network ] [[[.destination-node ] destination-node-mask ] | [.destination-node destination-network-mask. destination-nodemask ]] [ destination-socket ] [ log ] 设置访问列表的参数 扩展访问列表的编号范围为 900 到 999
77
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-77 IPX SAP 作用 路由器不会转发 SAP 广播 Server/ Router C Server/ Router D Client 2 A Large IPX Network Server/ Router A Client 1 Server/ Router B
78
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-78 IPX SAP 作用 路由器不会转发 SAP 广播 IPX 路由器每隔 60 秒发送 SAP 表 SAP Table Server/ Router C Server/ Router D Client 2 A Large IPX Network Server/ Router A Client 1 Server/ Router B SAP Table
79
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-79 在端口应用输入或输出的 SAP 过滤 输出过滤 : 不将收到的 SAP 数据添加到送出的 SAP 表中 如何使用 SAP 过滤 输入过滤 : 不将收到的 SAP 数据添加到 SAP 表中 SAP SAP Table SAP SAP Table SAP
80
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-80 SAP 配置 Router(config)# access-list access-list-number { deny | permit } network [.node ] [ network-mask. node-mask ] [ service-type [ server-name ]] 创建 SAP 访问列表
81
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-81 Router(config)# access-list access-list-number { deny | permit } network [.node ] [ network-mask. node-mask ] [ service-type [ server-name ]] Router(config-if)# ipx output-sap-filter access-list-number Router(config-if)# ipx input-sap-filter access-list-number SAP 配置 创建 SAP 访问列表 在端口的输出方向应用访问列表 在端口的输入方向应用访问列表
82
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-82 E0 FS-A FS-B Internal IPX Network 1a Internal IPX Network 2a FS-C FS-D Network 11b Internal IPX Network cc Internal IPX Network dd Network 4a Network 9e Network 12b E0 E1 S0 Cisco B Cisco A SAP 配置举例 1
83
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-83 SAP 配置举例 1 access-list 1000 permit 1a 4 access-list 1000 permit 2a 4 interface ethernet 0 ipx network 11b interface serial 0 ipx network 12b ipx output-sap-filter 1000 Only file services from FS-A and FS-B are advertised across router Cisco B’s S0 interface E0 FS-A FS-B Internal IPX Network 1a Internal IPX Network 2a FS-C FS-D Network 11b Internal IPX Network cc Internal IPX Network dd Network 4a Network 9e Network 12b E0 E1 S0 Cisco B Cisco A
84
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-84 SAP 配置举例 2 access-list 1001 deny -1 7 access-list 1001 permit -1 interface ethernet 0 ipx network 9e interface ethernet 1 ipx network 4a interface ethernet 2 ipx network 1 ipx input-sap-filter 1001 Print services from Server A and B are not entered into the SAP table of router Cisco A Network 1 Network 3d E2 To0 E1 Cisco B Network 7f E0 Network 4a Network 9e E0 E1 Cisco A A B
85
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-85 查看 IPX 访问列表 wg_ro_a#show ipx int e0 Ethernet0 is up, line protocol is up IPX address is 11.00e0.1e5d.ae2f, NOVELL-ETHER [up] Delay of this IPX network, in ticks is 1 throughput 0 link delay 0 IPXWAN processing not enabled on this interface. IPX SAP update interval is 60 seconds IPX type 20 propagation packet forwarding is disabled Incoming access list is 801 Outgoing access list is not set IPX helper access list is not set SAP GNS processing enabled, delay 0 ms, output filter list is not set SAP Input filter list is not set SAP Output filter list is not set SAP Router filter list is not set Input filter list is not set Output filter list is not set Router filter list is not set Netbios Input host access list is not set wg_ro_a#show ipx access-list IPX standard access list 801 permit 12 FFFFFFFF permit 22 FFFFFFFF
86
© 1999, Cisco Systems, Inc. www.cisco.com 10-86 练 习
87
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-87 podwg_ro’s s0wg_ro’s e0 A11A11 B12A12 C13A13 D14A14 E15A15 F16A16 G17A17 H18A18 I19A19 J20A20 K21A21 L22A22 s1/0 - s2/3 IPX Network 11 … 22 IPX Network 3bbb IPX Network 11A IPX Network 22A core_ server wg_sw_a wg_sw_l wg_pc_a wg_pc_l wg_ro_a e0/1 e0/2 e0/1 e0 fa0/23 core_sw_a wg_ro_l core_ro fa0/24fa0/0 LL s0 IPX Network 11 s0 IPX Network 22... 可视化目标
88
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-88 s1/0 - s2/3 IPX Network 11 … 22 IPX Network 3bbb IPX Network 11A IPX Network 22A 可视化目标 core_ server wg_sw_a wg_sw_l wg_pc_a wg_pc_l wg_ro_a e0/1 e0/2 e0/1 e0 fa0/23 core_sw_a wg_ro_l core_ro fa0/24fa0/0 LL s0 IPX Network 11 s0 IPX Network 22... SAP X X X X FS2 PS2 SAP FS2 PS2
89
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-89 完成本章的学习后,你应该能够掌握: 描述 IPX 协议的基本作用 确定 IPX 网络的网络号和端口的封装类型 启用 Novell IPX 协议 查看 IPX 协议的连接状态 配置 IPX 访问列表和 SAP 数据过滤 本章总结
90
© 1999, Cisco Systems, Inc. www.cisco.com ICND—11-90 问题回顾 1. IPX 网络地址有多少位 ? 2. IPX 主机地址有多少位 ? 3. 在 IPX RIP 路由协议中 metric 参数是什么 ? 4. 什么命令可以在端口上起用 IPX RIP 协议 ? 5. 标准的 IPX 访问列表可以过滤那些条目 ?
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.