TB 1 CCNA Preparation
ROUTER CONFIG
router, switch, pc, cable straight
Router>enable
Router#configure terminal
Router(config)#interface fa0/0
Router(config-if)#ip address 192.168.1.1 255.255.255.0
Router(config-if)#no shutdown
masukin ip address dan default gateway di setiap pc
CONSOLE
hubungkan pc ke router menggunakan cable console (pc rs232, router console)
klik pc, desktop, terminal. udah deh terkoneksi ke router bisa config router
melakukan remote ke router ataupun switch pake line console 0
hastajkt>ena
hastajkt#conf t
hastajkt(config)#line console 0
hastajkt(config-line)#password cisco
hastajkt(config-line)#login
hastajkt(config-line)#exit
hastajkt(config)#enable secret cisco
hastajkt(config)#do show run
hastajkt(config)#line vty 0 15
masuk ke dalam telnet
TELNET
hastajkt(config-line)#password cisco
hastajkt(config-line)#login
hastajkt(config-line)#exit
hastajkt(config)#interface fa0/0
hastajkt(config-if)#ip address 192.168.1.1 255.255.255.0
hastajkt(config-if)#no shutdown
ganti kabel cross dari pc ke router (fast ethernet 0/0) kenapa pake cross? krn
mereka sama-sama di layer 3
masukin ip address dan default gateway di pc
coba masuk telnet (pc, desktop, command prompt)
C:\>telnet 192.168.1.1
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~
NOTE
-enkripsi password di conf t
hastajkt(config)#service password-encryption
-kasih banner untuk deskripsi router
hastajkt(config)#banner motd # ini adalah router gwej #
-simpan konfigurasi supaya ga ilang ketika di reload
hastajkt#copy running-config startup-config
-reset konfigurasi
hastajkt#reload
-melihat interface dlm router
hastajkt#show ip interface brief
Interface IP-Address OK? Method Status Protocol
FastEthernet0/0 192.168.1.1 YES manual up up
FastEthernet0/1 unassigned YES unset administratively down down
Vlan1 unassigned YES unset administratively down down
-DHCP Server
router, switch, server, pc, cable straight
dari router (fa 0/0) ke switch (fa0/1)
dari switch (fa0/2) ke pc (fa0)
dari switch (fa0/3) ke server (fa0)
LANJUT SETTING SERVER
klik server, service, dhcp, pilih on
masukkan default gateway pake ip router 192.168.1.1
start ip address 192.168.1.3
save
klik desktop masukkan ipv4 address 192.168.1.2
masukkan subnet mask dan default gateway
LANJUT REQ IP ADDRESS BUAT PC
klik pc, desktop, ip config, klik dhcp (nanti bakal dapet ip address yg dimulai dr
192.168.1.3)
-SSH (perpanjangan telnet, secure socket shell, ada uname dan pass)
router, switch, pc, cable straight
hastajkt(config)#security password min-length 5
hastajkt(config)#login block-for 120 attempts 3 within 60
//artinya tidak bole membiarkan layar komputer selama >120s, tidak bole salah
sebanyak 3x, tida bole dibiarkan selama >60s
hastajkt(config)#line vty 0 4
hastajkt(config-line)#password cisco
hastajkt(config-line)#exec-timeout 5 30
//artinya timeoutnya 5min 30s
hastajkt(config-line)#transport input ssh
hastajkt(config-line)#end
hastajkt(config)#ip domain name cisco.com
//DNS(domain name service)
hastajkt(config)#crypto key generate rsa general-keys modulus 1024
//artinya passwordnya dimasukkan ke dalam algoritma kriptografi, algoritma rsa,
dengan kombinasi rsa 1024 bit
hastajkt(config)#username cisco secret class
hastajkt(config)#line vty 0 4
hastajkt(config-line)#login local
hastajkt(config-line)#transport input ssh
hastajkt(config-line)#exit
COBA MASUK SSH
ssh -l uname iprouter
ssh -l cisco 192.168.1.1
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
NOTE
-user exec mode >
memonitor informasi yang ada dalam router dan switch
-privileged exec mode #
konfigurasi disimpan di dalam enviram
os disimpan dlm flash
``````````````````````````````````````````````````````````````````````````````````
TB1
Router>enable
Router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#hostname Hasta
Hasta(config)#banner motd # Ini router Hasta #
Hasta(config)#line console 0
Hasta(config-line)#password cisco
Hasta(config-line)#login
Hasta(config-line)#exit
Hasta(config)#enable secret cisco
Hasta(config)#line vty 0 15
Hasta(config-line)#password cisco
Hasta(config-line)#login
Hasta(config-line)#exit
Hasta(config)#interface fa0/0
Hasta(config-if)#ip address 192.168.5.1 255.255.255.0
Hasta(config-if)#no shutdown
Hasta(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/0, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to
up
Hasta(config-if)#exit
Hasta(config)#service password-encryption
Hasta(config)#exit
Hasta#
%SYS-5-CONFIG_I: Configured from console by console
Hasta#copy running-config startup-config
Destination filename [startup-config]?
Building configuration...
[OK]
Hasta#
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to
down
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to
up
Hasta#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Hasta(config)#security password min-length 5
Hasta(config)#login block-for 120 attempts 3 within 60
Hasta(config)#line vty 0 4
Hasta(config-line)#password cisco
Hasta(config-line)#exec-timeout 5 30
Hasta(config-line)#transport input all
Hasta(config-line)#end
Hasta#
%SYS-5-CONFIG_I: Configured from console by console
Hasta#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Hasta(config)#ip domain name cisco.com
Hasta(config)#crypto key generate rsa general-keys modulus 1024
The name for the keys will be: Hasta.cisco.com
% The key modulus size is 1024 bits
% Generating 1024 bit RSA keys, keys will be non-exportable...[OK]
*Mar 1 0:19:1.772: %SSH-5-ENABLED: SSH 1.99 has been enabled.
Hasta(config)#username hasta secret cisco
Hasta(config)#line vty 0 4
Hasta(config-line)#login local
Hasta(config-line)#transport input all
Hasta(config-line)#exit
Hasta(config)#