A.Pengertian
Konfigurasi Managing Router Cisco,sebelumnya saya sudah membahas dasar-dasarnya,kali ini saya akan mengkonfigurasi dan memberikan langkah-langkahnya,konfigurasi ini akan menjelaskan bagaimana cara menghubungkan antara ssh di R1 dan R2,backup dan restore konfigurasi router,dan cara menampilkan informasi software dan hardware router.
B.Latar Belakang
Membuat Projek selama 1 minggu,dihari ketiga ini mempelajari tentang Managing Router,untuk mempelajari dan memahami fungsi dari salah satu simulasi Cisco Packet Tracer.
C.Alat dan Bahan
1.Laptop.
2.Cisco Packet Tracer.
D.Tujuan
Tujuanya yaitu untuk meningkatkan keamanan akses router, karena
dengan SSH komunikasi antar Laptop dan router dienkripsi sehingga menyulitkan proses sniffing password dengan menggunakan packet sniffer.
www.nixtrain.com Page 9Setelah kita mensetting basic router dan router sudah berjalan operasional, langkah selanjutnya yaitu melakukan backup konfigurasi.
Untuk menyimpan hasil backup ini dibutuhkan server TFTP.Proses backup tidak hanya untuk file konfigurasi, namun bisa juga dilakukan untuk backup Cisco IOS. Keuntungan melakukan backup yaitu jika suatu saat konfigurasi missing atua Cisco IOS corrupt, maka kita bisa dengan mudah melakukan restore konfigurasi atau Cisco IOS yang sudah kita simpan di server TFTP sebelumnya.Agar tidak terjadi kehilangan konfigurasi router, biasakan setelah mensetting router untuk menjalankan command copy run start atau write memory untuk menyimpan konfigurasi.Untuk mengetahui informasi hardware dan software router kita bisa menggunakan beberapa command, contohnya show version atau show interface.Hasil output command tersebut berupa informasi Ethernet cable, RAM, NVRAM, dan masih banyak lainnya.
E.Tahapan Pelaksanaan
Langsung saja berikut cara tutorial dan cara-caranya :
Login console ke R1 atau R2 untuk mempraktikkan Lab 3-Managing Router Configuration.
1.Setting SSH di router R1 dan R2.
Langkah mengaktifkan SSH di router:
1. Setting domain router
2. Setting username dan password login
3. Setting transport input ssh di line vty
4. Generate crypto rsa key 1024
llllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
Masuk CLI Router 1 dan atur :
R1>enable
R1#configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
R1(config)#ip domain-name NIXTRAIN.com
R1(config)#username admin secret ciscossh
R1(config)#line vty 0 4
R1(config-line)#transport input ssh
R1(config-line)#login local
R1(config-line)#exit
R1(config)#crypto key generate rsa
The name for the keys will be: R1.NIXTRAIN.com
Choose the size of the key modulus in the range of 360 to 2048 for your
General Purpose Keys. Choosing a key modulus greater than 512 may take
a few minutes.
How many bits in the modulus [512]: 1024
% Generating 1024 bit RSA keys, keys will be non-exportable...[OK]
R1(config)#exit
*Mar 3 2:27:58.564:%SSH-5-ENABLED: SSH 1.99 has been enabled
R1#
Backup Konfigurasi R1
Pastikan koneksi antara router 1 dan TFTP-Svr1 tidak ada masalah.
Lanjutkan Ekseusi dengan Command di R1.
llllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
Lakukan backup pada R1 berikut :
R1#copy running-config tftp
Address or name of remote host []? 192.168.1.11
Destination filename [R1-confg]?
Writing running-config....!!
[OK - 828 bytes]
828 bytes copied in 3.005 secs (275 bytes/sec)
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
Backup Cisco IOS R1
Untuk melihat penyimpanan :
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
R1#show flashSystem flash directory:
File Length Name/status
3 5571584 pt1000-i-mz.122-28.bin
2 28282 sigdef-category.xml
1 227537 sigdef-default.xml
[5827403 bytes used, 58188981 available, 64016384 total]
63488K bytes of processor board System flash (Read/Write)
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
Proses Backup IOS R1
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
R1#copy flash tftpSource filename []? pt1000-i-mz.122-28.bin
Address or name of remote host []? 192.168.1.11
Destination filename [pt1000-i-mz.122-28.bin]?
Writing pt1000-i-mz.122-28.bin...!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
[OK - 5571584 bytes]
5571584 bytes copied in 0.29 secs (4402126 bytes/sec)
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
NB :ulangi langkah yang sama untuk backup config dan Cisco IOS di R2.
2.Restore konfigurasi R1
Perbedaan proses backup dan restore, kalo backup menyimpan konfigurasi router ke TFTP, sedangkan restore yaitu download konfigurasi dari TFTP ke router.
Misalkan kita ingin mengconfig router dengan konfigurasi yang identik, maka kita bisa menggunakan konfigurasi yang sudah disimpan di TFTP. Dengan mensetting koneksi TFTP dan router, maka kita bisa mendownload config di TFTP diarahkan ke router dan mengubah settingan yang berbeda kemudian disesuaikan dengan konfigurasi yang sudah direncanakan.
Yang perlu diingat dari backup dan restore ini adalah source dan destination. Kalo backup berarti sourcenya router dan destinationnya TFTP, sedangkan restore yang berfungsi sebagai sourcenya TFTP dan destinationnya router.
Command restore di R1
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
R1#copy tftp running-config
Address or name of remote host []? 192.168.1.11
Source filename []? R1-confg
Destination filename [running-config]?
NB:Ulangi PadaRouter2
Accessing tftp://192.168.1.11/R1-confg...
Loading R1-confg from 192.168.1.11: !
[OK - 828 bytes]
828 bytes copied in 0.001 secs (828000 bytes/sec)
R1#
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
3.Remote login SSH ke R1 dan R2
Setelah mensetting SSH di router R1 dan R2, gunakan putty untuk melakukan koneksi SSH ke router dari Laptop1 dan Laptop2 jika menggunakan real device.
- Ketikkan IP address R1 dan R2 pada bagian Hostname (or IP address)
- Pilih connection type SSH
- Klik Open
Remote Akses Laptop1 ke R1
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
aptop1>ipconfig
FastEthernet0 Connection:(default port)
Link-local IPv6 Address.........: FE80::201:43FF:FE3A:AEC2
IP Address......................: 192.168.1.1
Subnet Mask.....................: 255.255.255.0
Default Gateway................. 192.168.1.254
llllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
llllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
Laptop1>ssh -l admin 192.168.1.254
Open
Password:
Unauthorized access prohibited! NB:Ulangi Pada Router 2.
R1#show users
Line User Host(s) Idle Location
0 con 0 idle 00:01:49
*134 vty 0 admin idle 00:00:00
Interface User Mode Idle Peer Address
R1#
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
Konfigurasi Manajement (Managing) Router Cisco Packet Tracer
Reviewed by R_Maulana_M
on
8/10/2016 04:08:00 PM
Rating:
Tidak ada komentar: