{"id":493,"date":"2019-01-18T14:50:00","date_gmt":"2019-01-18T05:50:00","guid":{"rendered":""},"modified":"2020-10-02T22:28:00","modified_gmt":"2020-10-02T13:28:00","slug":"cisco%e3%83%ab%e3%83%bc%e3%82%bf%e3%81%aeconfig%e3%82%92netconf%e3%81%a7%e5%8f%96%e5%be%97%e3%81%99%e3%82%8b","status":"publish","type":"post","link":"https:\/\/wp.zassoul.com\/?p=493","title":{"rendered":"Cisco\u30eb\u30fc\u30bf\u306eConfig\u3092netconf\u3067\u53d6\u5f97\u3059\u308b"},"content":{"rendered":"<p>Cisco\u30eb\u30fc\u30bf\u306eConfig\u3092netconf\u3092\u4f7f\u3063\u3066\u53d6\u5f97\u3057\u3088\u3046\u3068\u3044\u3046\u8a66\u307f\u3002<br \/>\u5bfe\u8c61\u6a5f\u5668\u306fCisco841M\u3002IOS\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u306f15.8\u3002<\/p>\n<h3>netconf \u3068\u306f<\/h3>\n<p>\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u6a5f\u5668\u3092\u30ea\u30e2\u30fc\u30c8\u3067\u8a2d\u5b9a\u5909\u66f4\u30fb\u66f4\u65b0\u30fb\u60c5\u5831\u53d6\u5f97\u3059\u308b\u305f\u3081\u306e\u30d7\u30ed\u30c8\u30b3\u30eb\u3002<br \/>\u5236\u5fa1\u5185\u5bb9\u3092XML\u3067\u8a18\u8ff0\u3059\u308b\u3002<a href=\"https:\/\/tools.ietf.org\/html\/rfc6241\" target=\"_blank\" rel=\"noopener noreferrer\">RFC6241<\/a>\u3067\u898f\u5b9a\u3002<\/p>\n<p>Cisco\u3067\u306fSSH(v2)\u3067\u30eb\u30fc\u30bf\u3068\u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u5f35\u3063\u3066, \u305d\u306e\u4e2d\u3067\u3084\u308a\u3068\u308a\u3092\u884c\u3046\u3002<\/p>\n<p>\u3053\u3061\u3089\u300c<a href=\"https:\/\/codeout.hatenablog.com\/entry\/2014\/10\/24\/230013\" target=\"_blank\" rel=\"noopener noreferrer\">\u77e5\u3063\u305f\u304b\u3076\u308a\u3057\u306a\u3044 NETCONF<\/a>\u300d\u3067\u308f\u304b\u308a\u3084\u3059\u304f\u307e\u3068\u3081\u3089\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<h3>\u30eb\u30fc\u30bf\u306e\u8a2d\u5b9a<\/h3>\n<div>\u53c2\u8003)<a href=\"https:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/ios-xml\/ios\/cns\/configuration\/15-mt\/cns-15-mt-book\/netconf-sshv2.html#GUID-7DB3155E-180B-4BD8-AB5B-9CF852B33019\" target=\"_blank\" rel=\"noopener noreferrer\"> NETCONF over SSHv2(Cisco Networking Services Configuration Guide, Cisco IOS Release 15M&amp;T)<\/a><\/div>\n<div><\/div>\n<h3>\u624b\u9806<\/h3>\n<p>1. SSH\u8a2d\u5b9a<br \/>2. netconf\u8a2d\u5b9a<br \/>3. netconf\u7528\u30e6\u30fc\u30b6\u4f5c\u6210<br \/>4. \u8a66\u884c<\/p>\n<h3>1. SSH\u8a2d\u5b9a<\/h3>\n<pre>(config)#ip domain name example.com<br \/>(config)#crypto key generate rsa<br \/>(config)#ip ssh version 2<br \/><\/pre>\n<p><\/p>\n<h3>2. netconf\u8a2d\u5b9a<\/h3>\n<pre>(config)#netconf ssh<br \/><\/pre>\n<p><\/p>\n<h3>3. netconf \u30e6\u30fc\u30b6\u4f5c\u6210<\/h3>\n<pre>(config)#username netconf privilege 15    !\u6a29\u9650\u306f15<br \/>(config)#ip ssh pubkey-chain<br \/>(conf-ssh-pubkey)#username netconf <br \/>(conf-ssh-pubkey-user)#key-string         !pubkey \u8cbc\u308a\u4ed8\u3051<br \/>(conf-ssh-pubkey-user)#exit<br \/>(conf-ssh-pubkey)#end<br \/><\/pre>\n<h4>\u3082\u308d\u3082\u308d\u8a2d\u5b9a\u78ba\u8a8d<\/h4>\n<pre>#show ip ssh<br \/>SSH Enabled - version 2.0<br \/>#show netconf session<br \/>Netconf Sessions: 0 open, maximum is 4<br \/><\/pre>\n<h3>4. \u8a66\u884c<\/h3>\n<p>SSH\u3067\u30eb\u30fc\u30bf\u3078\u63a5\u7d9a\u3059\u308b\u3002netconf over SSHv2\u3068\u3044\u3046\u3053\u3068\u3067-s \u30aa\u30d7\u30b7\u30e7\u30f3\u3067netconf\u3092\u547c\u3073\u51fa\u3059\u3002<\/p>\n<pre>$ssh -s -l netconf -i netconf_key 192.168.1.2 netconf<br \/><\/pre>\n<p>\u76f4\u3050\u306b\u30eb\u30fc\u30bf\u304b\u3089\u306ehello\u304c\u5c4a\u304f\u3002 <\/p>\n<pre># \u30eb\u30fc\u30bf\u304b\u3089\u306ehello<br \/>&lt;?xml version=\"1.0\" encoding=\"UTF-8\"?&gt;  <capabilities><br \/><\/capabilities>  &lt;hello xmlns=\"urn:ietf:params:xml:ns:netconf:base:1.0\"&gt;<br \/>    &lt;capabilities&gt;<br \/>      &lt;capability&gt;urn:ietf:params:netconf:base:1.0&lt;\/capability&gt;<br \/>      &lt;capability&gt;urn:ietf:params:netconf:capability:writeable-running:1.0&lt;\/capability&gt;<br \/>      &lt;capability&gt;urn:ietf:params:netconf:capability:startup:1.0&lt;\/capability&gt;<br \/>      &lt;capability&gt;urn:ietf:params:netconf:capability:url:1.0&lt;\/capability&gt;<br \/>      &lt;capability&gt;urn:cisco:params:netconf:capability:pi-data-model:1.0&lt;\/capability&gt;<br \/>      &lt;capability&gt;urn:cisco:params:netconf:capability:notification:1.0&lt;\/capability&gt;<br \/>    &lt;\/capabilities&gt;<br \/>    &lt;session-id&gt;49242144&lt;\/session-id&gt;<br \/>  &lt;\/hello&gt;<br \/>]]&gt;]]&gt;<br \/><\/pre>\n<p>session-id\u3092\u6d88\u3057\u3066\u5fdc\u7b54\u3092\u8fd4\u305b\u3070, \u3053\u3053\u304b\u3089\u5236\u5fa1\u304c\u53ef\u80fd\u306b\u306a\u308b\u3002 <\/p>\n<pre># \u30eb\u30fc\u30bf\u3078\u306e\u5fdc\u7b54<br \/>&lt;?xml version=\"1.0\" encoding=\"UTF-8\"?&gt;<br \/>  &lt;hello xmlns=\"urn:ietf:params:xml:ns:netconf:base:1.0\"&gt;<br \/>    &lt;capabilities&gt;<br \/>      &lt;capability&gt;urn:ietf:params:netconf:base:1.0&lt;\/capability&gt;<br \/>      &lt;capability&gt;urn:ietf:params:netconf:capability:writeable-running:1.0&lt;\/capability&gt;<br \/>      &lt;capability&gt;urn:ietf:params:netconf:capability:startup:1.0&lt;\/capability&gt;<br \/>      &lt;capability&gt;urn:ietf:params:netconf:capability:url:1.0&lt;\/capability&gt;<br \/>      &lt;capability&gt;urn:cisco:params:netconf:capability:pi-data-model:1.0&lt;\/capability&gt;<br \/>      &lt;capability&gt;urn:cisco:params:netconf:capability:notification:1.0&lt;\/capability&gt;<br \/>    &lt;\/capabilities&gt;<br \/>  &lt;\/hello&gt;<br \/>]]&gt;]]&gt;<\/pre>\n<p>show run\u3092\u53d6\u5f97\u3057\u3066\u307f\u308b\u3002 <\/p>\n<pre>#\u9001\u4ed8\u3059\u308b\u30ea\u30af\u30a8\u30b9\u30c8<br \/>&lt;?xml version=\"1.0\" encoding=\"UTF-8\"?&gt;<br \/>&lt;rpc xmlns=\"urn:ietf:params:xml:ns:netconf:base:1.0\" xmlns:cpi=\"http:\/\/www.cisco.com\/cpi_10\/schema\" message-id=\"101\"&gt;<br \/>    &lt;get-config&gt;<br \/>        &lt;source&gt;<br \/>            &lt;running\/&gt;<br \/>        &lt;\/source&gt;<br \/>    &lt;\/get-config&gt;<br \/>&lt;\/rpc&gt;]]&gt;]]&gt;<br \/><\/pre>\n<pre>#\u53d7\u3051\u53d6\u3063\u305f\u7d50\u679c<br \/>&lt;?xml version=\"1.0\" encoding=\"UTF-8\"?&gt;&lt;rpc-reply message-id=\"101\" xmlns=\"urn:ietf:params:xml:ns:netconf:base:1.0\"&gt;&lt;data&gt;&lt;cli-config-data-block&gt;!<br \/>! Last configuration change at 14:42:05 JST Fri Jan 18 2019 by netconf<br \/>! NVRAM config last updated at 12:22:11 JST Fri Jan 18 2019 by netconf<br \/>!<br \/>version 15.8<br \/>service timestamps debug datetime msec localtime show-timezone<br \/>service timestamps log datetime msec localtime show-timezone<br \/>no service password-encryption<br \/>service internal<br \/>!<br \/>\uff5e\u7565\uff5e<br \/>ntp server ntp.nict.jp prefer<br \/>netconf ssh<br \/>!<br \/>&lt;\/cli-config-data-block&gt;&lt;\/data&gt;&lt;\/rpc-reply&gt;]]&gt;]]&gt;<br \/><\/pre>\n<p>XML\u5f62\u5f0f\u3067\u51fa\u529b\u3092\u5f97\u308b\u5834\u5408\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u6295\u3052\u308b\u3002 <\/p>\n<pre>&lt;?xml version=\"1.0\" encoding=\"UTF-8\"?&gt;<br \/>&lt;rpc xmlns=\"urn:ietf:params:xml:ns:netconf:base:1.0\" xmlns:cpi=\"http:\/\/www.cisco.com\/cpi_10\/schema\" message-id=\"101\"&gt;<br \/>  &lt;get-config&gt;<br \/>    &lt;source&gt;<br \/>      &lt;running\/&gt;<br \/>    &lt;\/source&gt;<br \/>    &lt;filter&gt;<br \/>      &lt;config-format-xml\/&gt;<br \/>    &lt;\/filter&gt;<br \/>  &lt;\/get-config&gt;<br \/>&lt;\/rpc&gt;<br \/>]]&gt;]]&gt;<br \/><\/pre>\n<p>\u7d42\u4e86\u3059\u308b\u3068\u304d\u306fCtrl-c\u3067\u7d42\u4e86\u3002<\/p>\n<div>\u6b21\u306fssh\u30b3\u30de\u30f3\u30c9\u3067\u306f\u306a\u304fncclient\u3092\u4f7f\u3063\u3066\u898b\u3088\u3046\u3002<\/div>\n<p><\/p>\n<h3>\u4f59\u8ac7<\/h3>\n<div>\u3061\u306a\u307f\u306b, Config\u306e\u51fa\u529b\u3092XML\u5f62\u5f0f\u3067\u53d6\u5f97\u3057\u305f\u3044\u5834\u5408\u306f<\/p>\n<pre>show run | format<br \/><\/pre>\n<p>\u3067\u53d6\u5f97\u3067\u304d\u308b\u3002<\/p>\n<p>\u307e\u305f, Config\u53d6\u5f97\u3067all \u30aa\u30d7\u30b7\u30e7\u30f3\u3092\u4f7f\u3044\u305f\u3044\u3068\u304d\u306fGet\u30e1\u30bd\u30c3\u30c9\u3092\u4f7f\u3046\u3068\u3067\u304d\u308b\u3002<\/p>\n<pre>&lt;?xml version=\"1.0\" encoding=\"UTF-8\"?&gt;<br \/>&lt;rpc xmlns=\"urn:ietf:params:xml:ns:netconf:base:1.0\"xmlns:cpi=\"http:\/\/www.cisco.com\/cpi_10\/schema\" message-id=\"101\"&gt;<br \/>  &lt;get&gt;<br \/>    &lt;filter&gt;<br \/>      &lt;oper-data-format-text-block&gt;<br \/>        &lt;show&gt;<br \/>          run all<br \/>        &lt;\/show&gt;<br \/>      &lt;\/oper-data-format-text-block&gt;<br \/>    &lt;\/filter&gt;<br \/>  &lt;\/get&gt;<br \/>&lt;\/rpc&gt;<br \/>]]&gt;]]&gt;<br \/><\/pre>\n<p>\u3053\u306e\u51fa\u529b\u3092XML\u3067\u53d6\u308a\u305f\u3044\u306a\u3068\u601d\u3063\u305f\u306e\u3060\u304c, \u3069\u3046\u3084\u3089C841M\u3067\u306f\u5bfe\u5fdc\u3057\u3066\u3044\u306a\u3044\u3063\u307d\u3044\u3002spec\u30d5\u30a1\u30a4\u30eb\u3092\u6e96\u5099\u3057\u306a\u3044\u3068\u99c4\u76ee\u306a\u306e\u304b\u306a\u3002<\/div>\n<pre>#show format<br \/>The following CLI are supported in built-in<br \/>show inventory<br \/>show ip interface brief<br \/>show waas token<br \/>show waas statistics peer<br \/>show waas statistics pass-through<br \/>show waas statistics lz<br \/>show waas statistics global<br \/>show waas statistics dre<br \/>show waas statistics dre peer<br \/>show waas statistics class*<br \/>show waas statistics aoim<br \/>show waas statistics auto-discovery<br \/>show waas statistics auto-discovery blacklist<br \/>show waas statistics application*<br \/>show waas alarms<br \/>show waas status extended<br \/>show waas status<br \/>show waas connection*<br \/>show waas auto-discovery list<br \/>show parameter-map type waas*<br \/>show class-map type waas*<br \/>show policy-map type waas*<br \/>show waas auto-discovery blacklist<br \/>show waas statistics errors<br \/>show waas accelerator<br \/>show waas accelerator detail<br \/>show waas accelerator ssl-express<br \/>show waas statistics accelerator ssl-express ciphers<br \/>show waas statistics accelerator ssl-express<br \/>show waas statistics accelerator ssl-express peering<br \/>show waas accelerator cifs-express<br \/>show waas statistics accelerator cifs-express<br \/>show waas statistics accelerator cifs-express detail<br \/>show waas accelerator http-express<br \/>show waas statistics accelerator http-express<br \/>show waas statistics accelerator http-express detail<br \/>show waas statistics accelerator http-express https<br \/>show waas cache http-express metadatacache*<br \/>show waas statistics accelerator http-express debug<br \/>show waas cache http metadatacache*<br \/><\/pre>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cisco\u30eb\u30fc\u30bf\u306eConfig\u3092netconf\u3092\u4f7f\u3063\u3066\u53d6\u5f97\u3057\u3088\u3046\u3068\u3044\u3046\u8a66\u307f\u3002\u5bfe\u8c61\u6a5f\u5668\u306fCisco841M\u3002IOS\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u306f15.8\u3002 netconf \u3068\u306f \u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u6a5f\u5668\u3092\u30ea\u30e2\u30fc\u30c8\u3067\u8a2d\u5b9a\u5909\u66f4\u30fb\u66f4\u65b0\u30fb\u60c5\u5831\u53d6\u5f97\u3059\u308b\u305f\u3081\u2026 <span class=\"read-more\"><a href=\"https:\/\/wp.zassoul.com\/?p=493\">\u7d9a\u304d\u3092\u8aad\u3080 &raquo;<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,19,6,39,15,8],"tags":[],"class_list":["post-493","post","type-post","status-publish","format-standard","hentry","category-cisco","category-ios","category-it","category-netconf","category-network","category-8"],"_links":{"self":[{"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=\/wp\/v2\/posts\/493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=493"}],"version-history":[{"count":1,"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=\/wp\/v2\/posts\/493\/revisions"}],"predecessor-version":[{"id":630,"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=\/wp\/v2\/posts\/493\/revisions\/630"}],"wp:attachment":[{"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}