{"id":1079,"date":"2019-08-08T10:36:53","date_gmt":"2019-08-08T16:36:53","guid":{"rendered":"https:\/\/ugit.siua.ac.cr\/?p=1079"},"modified":"2019-09-25T14:41:31","modified_gmt":"2019-09-25T20:41:31","slug":"configuracion-de-switch-de-comunicaciones-ugit","status":"publish","type":"post","link":"https:\/\/sada.services\/?p=1079","title":{"rendered":"CISCO: Configuraci\u00f3n de Switch de comunicaciones UGIT"},"content":{"rendered":"\n<p>Se ingresa al equipo conectando el cable serial, en modo de configuraci\u00f3n privilegiado<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">CONFIGURACI\u00d3N SSH<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Se define nombre de host, dominio y se generan las claves de encryptacion<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch(config)#hostname &lt;Nombre del equipo>\nSwitch(config)#ip domain-name &lt;siua.ac.cr>\nSwitch(config)#crypto key generate rsa              ----> se define la longitud en 1024<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Creaci\u00f3n de usuarios locales<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch(config)#username &lt;ugit> secret &lt;AdA0> \no  \nSwitch(config)#username &lt;ugit> privilege 15 secret &lt;AdA0><\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Se define el time-out, numero de intentos de login y version ssh la 2 es m\u00e1s segura<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch(config)#ip ssh version 2\nSwitch(config)#ip ssh authentication-retries 2\nSwitch(config)#ip ssh time-out 120\nSwitch(config)#ip ssh port 6573 rotary 1 -----> NOTA\nSwitch(config)#ip ssh source-interface Vlan250<\/code><\/pre>\n\n\n\n<p>NOTA: Algunos catalyst 2960 no permiten cambiar el puerto ssh<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Lista de acceso para bloquear el ssh en el puerto 22<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch(config)#ip access-list extended DENY_SSH_PORT_22\nSwitch(config)#deny   tcp any any eq 22\nSwitch(config)#deny   udp any any eq 22\nSwitch(config)#permit tcp any any\nSwitch(config)#permit udp any any<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Configuraci\u00f3n de la l\u00edneas<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch(config)#line vty 0 15\nSwitch(config)#transport input ssh                 (solo permite ssh deniega telnet)\nSwitch(config)#login local                         (login con usuarios locales)\nSwitch(config)#access-class DENY_SSH_PORT_22 in\nSwitch(config)#rotary 1<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Configuraci\u00f3n de la interfaz la administrativa: vlan 250<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch(config)#interface vlan250\nSwitch(config)#description INTERFAZ ADMINISTRATIVA ##ACTIVO##\nSwitch(config)#ip address 10.20.250.xx 255.255.255.0pu\nSwitch(config)#ip access-group DENY_SSH_PORT_22 in<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Definimos el default gateway del switch<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch(config)#ip default-gateway 10.20.250.1<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Guardamos la configraci\u00f3n<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch#copy run startup-config<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>El comando \"who\" muestra las lineas con conexiones activas\nshow ip ssh muestra la configuraci\u00f3n de ssh\n<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">Configuraciones generales<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Poner contrase\u00f1a al modo Exec Provilegiado<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch(config)#enable secret &lt;AA3><\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Encriptar las contrase\u00f1as<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch(config)#service password-encryption<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Deshabilitar los servidores web<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch(config)#no ip http server\nSwitch(config)#no ip http secure-server<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Deshabilitar la traducci\u00f3n de dominios<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch(config)#no ip domain-lookup<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">Configuraci\u00f3n de VTP<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch(config)#Vtp domain &lt;UGIT>\nSwitch(config)#vtp password &lt;AA3>\nSwitch(config)#vtp mode server, client, transparent<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Se guarda la configuraci\u00f3n<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch#copy run startup-config<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">Configuraci\u00f3n SNMP v3<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Nos logeamos por ssh, entramos a modo de configuraci\u00f3n privilegiado<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>Borramos la configuraci\u00f3n SNMP si la hubiera<\/li><li>Definimos el engine ID, como F24012018F &#8212;-&gt; (F-fecha del dia-F) debe ser almenos 10 n\u00fameros HEXADECIMALES<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch(config)#snmp-server engineID local F24012018F <\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Definimos el grupo SNMP<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch(config)#snmp-server group SIUA v3 priv<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Definimos la versi\u00f3n SNMP , el usuario, los algoritmos y las contrase\u00f1as<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch(config)#snmp-server user ugit SIUA v3 auth sha CA2 priv aes 128 AdA0<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Guardamos la configuraci\u00f3n<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Switch#copy run startup-config<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Configuraci\u00f3n de los conmutadores UGIT<\/p>\n","protected":false},"author":1,"featured_media":2051,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[37],"tags":[56,38,58,60,57,55,59],"class_list":["post-1079","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cisco","tag-catalyst","tag-cisco","tag-config-switch","tag-conmutador","tag-snmp","tag-ssh","tag-switch"],"blocksy_meta":{"styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":6}},"_links":{"self":[{"href":"https:\/\/sada.services\/index.php?rest_route=\/wp\/v2\/posts\/1079","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sada.services\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sada.services\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sada.services\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sada.services\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1079"}],"version-history":[{"count":8,"href":"https:\/\/sada.services\/index.php?rest_route=\/wp\/v2\/posts\/1079\/revisions"}],"predecessor-version":[{"id":2111,"href":"https:\/\/sada.services\/index.php?rest_route=\/wp\/v2\/posts\/1079\/revisions\/2111"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sada.services\/index.php?rest_route=\/wp\/v2\/media\/2051"}],"wp:attachment":[{"href":"https:\/\/sada.services\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1079"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sada.services\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1079"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sada.services\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1079"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}