<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>yaoge123 Blog &#187; Cisco</title>
	<atom:link href="http://www.yaoge123.com/blog/archives/category/computer/cisco/feed" rel="self" type="application/rss+xml" />
	<link>http://www.yaoge123.com/blog</link>
	<description>丰刀</description>
	<lastBuildDate>Mon, 26 Jul 2010 10:03:54 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Cisco 6500 SUP720/MSFC3 双引擎全面升级</title>
		<link>http://www.yaoge123.com/blog/archives/416</link>
		<comments>http://www.yaoge123.com/blog/archives/416#comments</comments>
		<pubDate>Tue, 29 Jun 2010 01:13:24 +0000</pubDate>
		<dc:creator>yaoge123</dc:creator>
				<category><![CDATA[Cisco]]></category>

		<guid isPermaLink="false">http://www.yaoge123.com/blog/?p=416</guid>
		<description><![CDATA[upgrade rom-monitor slot 6 sp file tftp://192.168.1.2/c6ksup720-rm2.srec.8-5-4.srec   //升级CatOS ROMMON
upgrade rom-monitor slot 6 rp file tftp://192.168.1.2/c6msfc3-rm2.srec.122-17r.SX7   //升级IOS ROMMON Software
upgrade rom-monitor slot 5 sp file tftp://192.168.1.2/c6ksup720-rm2.srec.8-5-4.srec
upgrade rom-monitor slot 5 rp file tftp://192.168.1.2/c6msfc3-rm2.srec.122-17r.SX7
<span class="readmore"><a href="http://www.yaoge123.com/blog/archives/416" title="Cisco 6500 SUP720/MSFC3 双引擎全面升级" target="_blank">阅读全文——共1692字</a></span>]]></description>
		<wfw:commentRss>http://www.yaoge123.com/blog/archives/416/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco WLC 导入SSL证书</title>
		<link>http://www.yaoge123.com/blog/archives/409</link>
		<comments>http://www.yaoge123.com/blog/archives/409#comments</comments>
		<pubDate>Tue, 01 Jun 2010 03:27:22 +0000</pubDate>
		<dc:creator>yaoge123</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Certificate]]></category>
		<category><![CDATA[WLC]]></category>

		<guid isPermaLink="false">http://www.yaoge123.com/blog/?p=409</guid>
		<description><![CDATA[首先生成私钥和证书请求：
openssl req -new -newkey rsa:2048 -nodes -keyout key.pem -out req.pem
将req.pem发给CA，CA将返回证书文件cert.cer。
将私钥和证书合并成PKCS12并转换成pem文件：
<span class="readmore"><a href="http://www.yaoge123.com/blog/archives/409" title="Cisco WLC 导入SSL证书" target="_blank">阅读全文——共364字</a></span>]]></description>
		<wfw:commentRss>http://www.yaoge123.com/blog/archives/409/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco ASA 为SSL VPN导入证书</title>
		<link>http://www.yaoge123.com/blog/archives/402</link>
		<comments>http://www.yaoge123.com/blog/archives/402#comments</comments>
		<pubDate>Tue, 01 Jun 2010 01:41:25 +0000</pubDate>
		<dc:creator>yaoge123</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[ASA]]></category>
		<category><![CDATA[Certificate]]></category>

		<guid isPermaLink="false">http://www.yaoge123.com/blog/?p=402</guid>
		<description><![CDATA[首先生成私钥和证书请求：
openssl genrsa -des3 -out ssl.key 2048
openssl req -new -key ssl.key -out ssl.csr
将ssl.csr发给CA，CA将返回证书文件ssl.cer。
<span class="readmore"><a href="http://www.yaoge123.com/blog/archives/402" title="Cisco ASA 为SSL VPN导入证书" target="_blank">阅读全文——共673字</a></span>]]></description>
		<wfw:commentRss>http://www.yaoge123.com/blog/archives/402/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco MARS 重新生成SSL证书</title>
		<link>http://www.yaoge123.com/blog/archives/399</link>
		<comments>http://www.yaoge123.com/blog/archives/399#comments</comments>
		<pubDate>Tue, 01 Jun 2010 01:00:45 +0000</pubDate>
		<dc:creator>yaoge123</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Certificate]]></category>
		<category><![CDATA[MARS]]></category>

		<guid isPermaLink="false">http://www.yaoge123.com/blog/?p=399</guid>
		<description><![CDATA[SSH到MARS后执行sslcert可重新产生ssl证书，CN必须输入MARS的域名或者IP，其它的都无所谓，这样再访问MARS的时候将证书安装到“受信任的根证书颁发机构”中，则以后访问MARS的时候就不会出现安全警告了。这样的证书是自签名的，如果想用其它CA来签名证书的话，估计只能用其它系统挂载MARS硬盘去修改/opt/janus/jboss/bin/ssl/的文件了。
]]></description>
		<wfw:commentRss>http://www.yaoge123.com/blog/archives/399/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco MARS 推荐使用命令行方式升级</title>
		<link>http://www.yaoge123.com/blog/archives/391</link>
		<comments>http://www.yaoge123.com/blog/archives/391#comments</comments>
		<pubDate>Fri, 28 May 2010 10:27:47 +0000</pubDate>
		<dc:creator>yaoge123</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[xNix]]></category>
		<category><![CDATA[MARS]]></category>

		<guid isPermaLink="false">http://www.yaoge123.com/blog/?p=391</guid>
		<description><![CDATA[当前Cisco MARS版本为6.0.6.3368，通过Web界面上传csmars-6.0.7.3404.zip升级失败，升级日志中错误一会是“Upgrade package acquisition error.”，一会是“Failed to pass the version dependency test.”，根本不知道到底什么错误。
SSH登陆到MARS后，使用命令行pnupgrade ftp://192.168.1.2/csmars-6.0.7.3404.zip升级，报错则很清晰了：
[Error][check_dependency/547]: minimal allowed version(6.0.6.3368.35) &#62; current version(6.0.6.3368.34).
<span class="readmore"><a href="http://www.yaoge123.com/blog/archives/391" title="Cisco MARS 推荐使用命令行方式升级" target="_blank">阅读全文——共673字</a></span>]]></description>
		<wfw:commentRss>http://www.yaoge123.com/blog/archives/391/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco MDS 系列交换机无中断软件升级</title>
		<link>http://www.yaoge123.com/blog/archives/316</link>
		<comments>http://www.yaoge123.com/blog/archives/316#comments</comments>
		<pubDate>Tue, 02 Feb 2010 05:41:45 +0000</pubDate>
		<dc:creator>yaoge123</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[MDS]]></category>

		<guid isPermaLink="false">http://www.yaoge123.com/blog/?p=316</guid>
		<description><![CDATA[整个升级过程业务无任何中断，具体过程如下：
MDS9134# show version
Cisco Nexus Operating System (NX-OS) Software
TAC support: http://www.cisco.com/tac
<span class="readmore"><a href="http://www.yaoge123.com/blog/archives/316" title="Cisco MDS 系列交换机无中断软件升级" target="_blank">阅读全文——共6918字</a></span>]]></description>
		<wfw:commentRss>http://www.yaoge123.com/blog/archives/316/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VMware ESXi 的VLAN支持</title>
		<link>http://www.yaoge123.com/blog/archives/277</link>
		<comments>http://www.yaoge123.com/blog/archives/277#comments</comments>
		<pubDate>Wed, 07 Oct 2009 16:02:32 +0000</pubDate>
		<dc:creator>yaoge123</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[VLAN]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://www.yaoge123.com/blog/?p=277</guid>
		<description><![CDATA[　　ESXi主机和交换机用trunk连接，在vSphere Client的主机网络配置中，虚拟机端口组的VLAN ID留空则虚拟机只可访问native VLAN (这里是VLAN 1)；如果填写了ID则虚拟机只可访问对应的VLAN；如果ID填写4095则透传trunk，由虚拟机OS来完成VLAN区分(如PROSet)。
以上配置在此环境下测试通过：服务器为IBM X3650，安装ESXi 4.0.0 193498，双网卡均直接连接到6506的WS-X6748-GE-TX，IOS版本：s72033_rp Software (s72033_rp-ADVIPSERVICESK9_WAN-VM), Version 12.2(33)SXI, RELEASE SOFTWARE (fc2)
<span class="readmore"><a href="http://www.yaoge123.com/blog/archives/277" title="VMware ESXi 的VLAN支持" target="_blank">阅读全文——共434字</a></span>]]></description>
		<wfw:commentRss>http://www.yaoge123.com/blog/archives/277/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>使用 DHCP Snooping 和 DAI 防止ARP攻击和私设IP地址</title>
		<link>http://www.yaoge123.com/blog/archives/194</link>
		<comments>http://www.yaoge123.com/blog/archives/194#comments</comments>
		<pubDate>Thu, 30 Apr 2009 01:57:38 +0000</pubDate>
		<dc:creator>yaoge123</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[DAI]]></category>
		<category><![CDATA[DHCP]]></category>

		<guid isPermaLink="false">http://www.yaoge123.com/blog/?p=194</guid>
		<description><![CDATA[　　使用DHCP Snooping防止私设DHCP Server并获得MAC-IP-端口绑定表，使用DAI对所有的ARP包进行检查。Cisco 6500做核心无需特别的配置，在接入交换机3560上做如下配置：
!
ip dhcp snooping vlan 5-10 //在5-10这些vlan上使用DHCP Snooping
no ip dhcp snooping information option
<span class="readmore"><a href="http://www.yaoge123.com/blog/archives/194" title="使用 DHCP Snooping 和 DAI 防止ARP攻击和私设IP地址" target="_blank">阅读全文——共1108字</a></span>]]></description>
		<wfw:commentRss>http://www.yaoge123.com/blog/archives/194/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>令人疑惑的 Cisco IOS Release 12.2(50)SE</title>
		<link>http://www.yaoge123.com/blog/archives/190</link>
		<comments>http://www.yaoge123.com/blog/archives/190#comments</comments>
		<pubDate>Tue, 24 Mar 2009 02:57:15 +0000</pubDate>
		<dc:creator>yaoge123</dc:creator>
				<category><![CDATA[Cisco]]></category>

		<guid isPermaLink="false">http://www.yaoge123.com/blog/?p=190</guid>
		<description><![CDATA[　　以 &#8220;Release Notes for the Catalyst 3750, 3560, and 2960 Switches, Cisco IOS Release 12.2(50)SE&#8221; &#1084;&#1077;&#1073;&#1077;&#1083;&#1080; &#1089;&#1086;&#1092;&#1080;&#1103;为例。
　　在 &#8220;Deciding Which Files to Use&#8221; 中提到 &#8220;For IPv6 capability on the Catalyst 3750 or 3560 switch or on the Cisco EtherSwitch service modules, you must order the advanced IP services image upgrade from Cisco. &#8221; 并在紧接着的表中有 &#8220;c3750-advipservicesk9-tar.122-50.SE.tar&#8221; 和 &#8220;c3560-advipservicesk9-tar.122-50.SE.tar&#8221;。但是在 &#8220;New Software Features&#8221; 的 &#8220;Catalyst 3750 and 3560 Switches&#8221; 中注明了 &#8220;These IPv6 features are now supported in the IP services and IP base software images:&#8221; 和 &#8220;The advanced IP services image is now end-of-sale (EOS) and end-of-life (EOL).&#8221;
<span class="readmore"><a href="http://www.yaoge123.com/blog/archives/190" title="令人疑惑的 Cisco IOS Release 12.2(50)SE" target="_blank">阅读全文——共763字</a></span>]]></description>
		<wfw:commentRss>http://www.yaoge123.com/blog/archives/190/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco Secure ACS 数据同步配置</title>
		<link>http://www.yaoge123.com/blog/archives/166</link>
		<comments>http://www.yaoge123.com/blog/archives/166#comments</comments>
		<pubDate>Wed, 26 Nov 2008 13:26:44 +0000</pubDate>
		<dc:creator>yaoge123</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[ACS]]></category>

		<guid isPermaLink="false">http://www.yaoge123.com/blog/?p=166</guid>
		<description><![CDATA[　　使用ACS作为身份验证服务器时，对ACS提出了高可用性的要求，在WLC中可以同时设置三台ACS互为热备，那么这就必然涉及到ACS服务器间数据同步的问题。
　　首先配置好主ACS，确保可以完成要求的功能，然后安装备ACS，但暂时不要做任何配置。在两个ACS的 Network Configuation 的 AAA Servers 互相添加对方，就是在主ACS中添加备ACS的信息，在备ACS中添加主ACS的信息，两个的key要完全相同。
　　先配置主ACS的同步设置，在 System Configuation 中找到 ACS Internal Database Replication ，在 Replication Components 中可以设置服务器Send数据或Receive数据哪些数据，对于主ACS为Send。在 Outbound Replication 的 Scheduling 中可以设置同步的时间，在同步的时候ACS服务会暂时停止，因此尽量选择业务最空闲的时候来同步，选项 Automatically triggered cascade  最后再解释。下面的 Partners 中是设置要把数据发送给哪些ACS服务器，左侧 AAA Servers 列表里的都是在 Network Configuation 里面添加的，需要把备ACS添加到右侧栏里。
<span class="readmore"><a href="http://www.yaoge123.com/blog/archives/166" title="Cisco Secure ACS 数据同步配置" target="_blank">阅读全文——共1092字</a></span>]]></description>
		<wfw:commentRss>http://www.yaoge123.com/blog/archives/166/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
