<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.hobby.nl/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=2A05%3AF080%3A0%3A300%3AC832%3A5B8A%3A9BB3%3AA4AE</id>
	<title>Hobbynet Admin Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.hobby.nl/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=2A05%3AF080%3A0%3A300%3AC832%3A5B8A%3A9BB3%3AA4AE"/>
	<link rel="alternate" type="text/html" href="https://wiki.hobby.nl/index.php/Special:Contributions/2A05:F080:0:300:C832:5B8A:9BB3:A4AE"/>
	<updated>2026-05-14T15:47:10Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.40.1</generator>
	<entry>
		<id>https://wiki.hobby.nl/index.php?title=Switches&amp;diff=78832</id>
		<title>Switches</title>
		<link rel="alternate" type="text/html" href="https://wiki.hobby.nl/index.php?title=Switches&amp;diff=78832"/>
		<updated>2020-10-30T08:53:11Z</updated>

		<summary type="html">&lt;p&gt;2A05:F080:0:300:C832:5B8A:9BB3:A4AE: /* basis switch configuratie */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= basis switch configuratie =&lt;br /&gt;
== uitschakelen macro&#039;s ==&lt;br /&gt;
Marco&#039;s zij heel irritant die wille je helpen de switch automatische te configuren, en jouw config dan overullen ik dacht het niet. met volgende commando in config mode:&lt;br /&gt;
   macro auto disabled&lt;br /&gt;
== uitschakelen green ethernet ==&lt;br /&gt;
   no eee enable&lt;br /&gt;
== schakel bojour uit ==&lt;br /&gt;
   no bonjour enable&lt;br /&gt;
   no bonjour interface range vlan&lt;br /&gt;
== activeer ssh == &lt;br /&gt;
ip ssh server&lt;br /&gt;
ip ssh password-auth&lt;br /&gt;
ip ssh pubkey-auth auto-login&lt;br /&gt;
=== inlezen ssh-key&#039;s  ===&lt;br /&gt;
== snmp == &lt;br /&gt;
   snmp-server server&lt;br /&gt;
   snmp-server location &amp;quot;Rack 14.3 BIT-2a&amp;quot;&lt;br /&gt;
   snmp-server contact beheer@hobby.nl&lt;br /&gt;
   snmp-server community hobbynet-ro ro 172.31.1.6 view Default&lt;br /&gt;
   snmp-server community hobbynet-ro ro 2a02:968:ffff:999:172:31:1:6 view Default&lt;br /&gt;
&lt;br /&gt;
= certificaten =&lt;br /&gt;
Dit is de juiste procedure om certificaten aan maken &lt;br /&gt;
== aanmaken met openssl ==&lt;br /&gt;
=== san.cnf ===&lt;br /&gt;
Om te zorgen dat je het cerificaat goed kan aanmaken, moet je zorgen dat je alt subjects goed hebt staan, daar voor config file nodig ie er zo uit ziet:&lt;br /&gt;
   [ req ]&lt;br /&gt;
   default_bits       = 2048&lt;br /&gt;
   distinguished_name = req_distinguished_name&lt;br /&gt;
   req_extensions     = req_ext&lt;br /&gt;
   [ req_distinguished_name ]&lt;br /&gt;
   countryName                 = NL&lt;br /&gt;
   stateOrProvinceName         = Noord-Holland&lt;br /&gt;
   localityName               = Haarlem&lt;br /&gt;
   organizationName           = HCC&lt;br /&gt;
   commonName                 = Common Name (e.g. server FQDN or YOUR name)&lt;br /&gt;
   [ req_ext ]&lt;br /&gt;
   subjectAltName = @alt_names&lt;br /&gt;
   [alt_names]&lt;br /&gt;
   DNS.1   = cisco-sw-st-02.hobby.nl&lt;br /&gt;
   DNS.2   = cisco-sw-st-02.network.hobby.nl&lt;br /&gt;
   IP.1    = 172.31.1.114&lt;br /&gt;
   IP.2    = 2a02:968:ffff:999:172:31:1:114&lt;br /&gt;
   IP.3    = 192.168.200.156&lt;br /&gt;
   IP.4    = 192.168.200.157&lt;br /&gt;
&lt;br /&gt;
Bij dns naam vul nog keer de aanvraag dns naam in, en je vult eventuele aliassen in, ook voeg je ip addressen toe, hier staan 2 192.168.200.* adressen in omdat ze bij mijn thuis geconfigureerd zijn en zo had ik geen last van foutmeldingen. Vergeet het IPv6 adres niet!&lt;br /&gt;
=== maak het certificaat request ===&lt;br /&gt;
&#039;&#039;&#039;De key mag maximaal 2048 zijn&#039;&#039;&#039;&lt;br /&gt;
   bas@pc-bas:/mnt/c/Users/bas/certs$ openssl req -out cisco-sw-st-02.csr -new -newkey rsa:2048 -sha256 -nodes -keyout cisco-sw-st-02.key -config ./san.cnf&lt;br /&gt;
   Generating a RSA private key&lt;br /&gt;
   ......................................................++++&lt;br /&gt;
   ..........................................................................................................................................++++&lt;br /&gt;
   writing new private key to &#039;cisco-sw-st-02.key&#039;&lt;br /&gt;
   -----&lt;br /&gt;
   You are about to be asked to enter information that will be incorporated&lt;br /&gt;
   into your certificate request.&lt;br /&gt;
   What you are about to enter is what is called a Distinguished Name or a DN.&lt;br /&gt;
   There are quite a few fields but you can leave some blank&lt;br /&gt;
   For some fields there will be a default value,&lt;br /&gt;
   If you enter &#039;.&#039;, the field will be left blank.&lt;br /&gt;
   -----&lt;br /&gt;
   NL []:&lt;br /&gt;
   Noord-Holland []:&lt;br /&gt;
   Haarlem []:&lt;br /&gt;
   HCC []:&lt;br /&gt;
   Common Name (e.g. server FQDN or YOUR name) []:cisco-sw-st-02.network.hobby.nl&lt;br /&gt;
Voltooi de aanvraag via windows ad http://ad1.ad.hobby.nl/certsrv (ja http) &amp;lt;br&amp;gt;&lt;br /&gt;
Request a certificate --&amp;gt; advanced certificate request&amp;lt;br&amp;gt;&lt;br /&gt;
kies bij template webserver&amp;lt;br&amp;gt;&lt;br /&gt;
paste de inhoud van csr file (certificate request)&amp;lt;br&amp;gt;&lt;br /&gt;
klik op submint&amp;lt;br&amp;gt;&lt;br /&gt;
zet rondje op Base 64 encoded&amp;lt;br&amp;gt;&lt;br /&gt;
en klik op download certficate&amp;lt;br&amp;gt;&lt;br /&gt;
zet gedownload bestand bij de andere cerificate files bij voorkeur met zelfde naam en extentie cer&lt;br /&gt;
&lt;br /&gt;
=== zet de private key om naar RSA private key ===&lt;br /&gt;
   openssl rsa -in cisco-sw-st-02.key -outform pem &amp;gt;cisco-sw-st-02.rsakey&lt;br /&gt;
&lt;br /&gt;
=== zet het certificaat om in public RSA keys ===&lt;br /&gt;
   openssl x509 -pubkey -noout -in ./cisco-sw-st-02.cer  &amp;gt;./cisco-sw-st-02.pubkey&lt;br /&gt;
Nu moeten we nog wat gaan versleutelen aan de public key hier moet de eerste 32 tekens weg meestal is dat:&lt;br /&gt;
   MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A&lt;br /&gt;
Daarnaast de opening header worden aangepast&amp;lt;br&amp;gt;&lt;br /&gt;
van:&lt;br /&gt;
   -----BEGIN PUBLIC KEY-----&lt;br /&gt;
naar:&lt;br /&gt;
   -----BEGIN RSA PUBLIC KEY-----&lt;br /&gt;
en van:&lt;br /&gt;
   -----END PUBLIC KEY-----&lt;br /&gt;
naar: &lt;br /&gt;
   -----END RSA PUBLIC KEY-----&lt;br /&gt;
=== bestanden samen voegen en importeren ===&lt;br /&gt;
met het volgende cat commando krijg je alle bestanden in goede volgorde als output op je scherm:&lt;br /&gt;
   cat cisco-sw-st-02.rsakey cisco-sw-st-02.pubkey cisco-sw-st-02.cer&lt;br /&gt;
Deze output moet later pasten in de switch &lt;br /&gt;
Je kan certificaat op postie 1 of 2 opslaan je kan bestaande niet overschrijven, default is in 1 in gebruik bij switch met fact defaults.&amp;lt;br&amp;gt;&lt;br /&gt;
login op de switch en ga naar config prompt en geef volgende commando:&lt;br /&gt;
   cisco-sw-st-02#conf t&lt;br /&gt;
   cisco-sw-st-02(config)#crypto certificate 2 import&lt;br /&gt;
plak nu de inhoud van de cat&amp;lt;br&amp;gt;&lt;br /&gt;
als goed is gegaan krijg je hier na het volgende resultaat:&lt;br /&gt;
&lt;br /&gt;
 .&lt;br /&gt;
 Certificate imported successfully&lt;br /&gt;
  Issued by : DC=nl, DC=hobby, DC=ad, CN=ad-AD1-CA&lt;br /&gt;
  Valid From: Oct 26 18:00:45 2020 GMT&lt;br /&gt;
  Valid to: Oct 26 18:00:45 2022 GMT&lt;br /&gt;
  Subject: CN=cisco-sw-st-02.network.hobby.nl&lt;br /&gt;
  SHA Fingerprint: AC12A474 585D6E34 AB1576B4 69A4EBDD 4FF01089&lt;br /&gt;
=== activeer certificaat ===&lt;br /&gt;
* login op webinterface nu nog met http&lt;br /&gt;
* zet rechts boven in display mode op advanced&lt;br /&gt;
* ga naar security --&amp;gt; ssl server --&amp;gt; SSL Server Authentication Settings&lt;br /&gt;
* Selecteer het goede certificaat en klik op apply  (nr dat je bij import hebt gebruikt&lt;/div&gt;</summary>
		<author><name>2A05:F080:0:300:C832:5B8A:9BB3:A4AE</name></author>
	</entry>
</feed>