Dell OS10 Basic Switch Management: CLI Configuration Guide - 夜莺博客

Dell OS10 Basic Switch Management: CLI Configuration Guide

Dell PowerSwitch OS10 switches ship with a factory default configuration where the management interface obtains an address via DHCP, which is rarely what you want in a production network. This guide walks through the exact CLI steps to set a static IP on the management interface, add a management route, create an admin-level user with the correct role, and save everything so it survives a reboot. Every command is shown as typed on the switch, from the default admin/admin login to final verification.

OS10 is a Linux-based network operating system, and the CLI reflects that heritage. It borrows the mode hierarchy and the configure terminal convention from the enterprise networking world, while the configuration files underneath are ordinary text files that can be copied, diffed and archived like any other Linux artifact. Knowing where you are in that hierarchy removes most of the friction from a first configuration session.

Prerequisites for OS10 Management Configuration

The steps assume your S-series switch is at factory defaults. Log in to privileged exec mode with the default credentials (admin/admin) using the console or a management IP, then verify the current management interface state with show running-configuration interface mgmt 1/1/1.

On a factory default switch that output will show ip address dhcp, which is the state to change. Before making any edits, it also helps to confirm which software version you are running and what the startup configuration currently looks like:

OS10# show version
OS10# show boot
OS10# show running-configuration
OS10# show startup-configuration

Comparing the running and startup configurations at the start and at the end of the session is the simplest habit that prevents "my config disappeared" surprises later.

Understanding the OS10 CLI Modes

OS10 uses a nested mode structure. Every command belongs to exactly one mode, and most configuration errors during a first session are simply commands typed in the wrong place.

  • EXEC mode (OS10#) — show commands, file operations, ping and traceroute. This is where you land after login.
  • Global configuration mode (OS10(config)#) — reached with configure terminal. Hostname, users, routes, AAA and everything that is not interface-specific live here.
  • Interface configuration mode (OS10(conf-if-...)#) — reached with interface. The prompt tells you exactly which interface you are editing, which is worth reading every time.
  • Interface range mode (OS10(conf-range-...)#) — reached with interface range, for applying one change to many ports.
OS10# configure terminal
OS10(config)# interface range ethernet 1/1/1-1/1/8
OS10(conf-range-eth1/1/1-1/1/8)# description Uplink-to-Core
OS10(conf-range-eth1/1/1-1/1/8)# exit
OS10(config)# end
OS10#

Navigation is uniform: exit moves up one level, end jumps straight back to EXEC mode from anywhere, and do lets you run an EXEC-level show command without leaving configuration mode — do show running-configuration interface mgmt 1/1/1 is far faster than exiting and re-entering.

Configuring a Static Management IP

Enter configuration mode and configure the management interface with a static address, removing DHCP first:

OS10# configure terminal
OS10(config)# interface mgmt 1/1/1
OS10(conf-if-ma-1/1/1)# no ip address dhcp
OS10(conf-if-ma-1/1/1)# ip address 1.1.1.1/24
OS10(conf-if-ma-1/1/1)# exit

Then create a default management route pointing at the forwarding router:

OS10(config)# management route 0.0.0.0/0 1.1.1.2
OS10(config)# end

The next hop must sit on the same subnet as the management interface. A management route with an unreachable next hop is accepted by the CLI without complaint and then never used, which makes it a quiet failure rather than a loud one — always confirm the route with a ping sourced from the switch rather than from your workstation.

Verifying the Management Configuration

Confirm both the interface and the route are correct:

OS10# show running-configuration interface mgmt 1/1/1
! interface mgmt1/1/1
 no shutdown
 no ip address dhcp
 ip address 1.1.1.1/24
 ipv6 address autoconfig

OS10# show running-configuration management-route
! management route 0.0.0.0/0 1.1.1.2

Note the ipv6 address autoconfig line: if you do not intend to use IPv6 for management, removing it with no ipv6 address autoconfig keeps the interface exactly as documented and avoids an address that drifts when router advertisements change. Then confirm live state rather than stored configuration:

OS10# show interface mgmt 1/1/1
OS10# show ip interface brief
OS10# show ip route management
OS10# ping 1.1.1.2 source 1.1.1.1

Creating an Admin-Level User

OS10 role-based access control lets you assign one of four roles: sysadmin, netoperator, secadmin and netadmin. Create a sysadmin user as follows:

OS10# configure terminal
OS10(config)# username test password P@ssw0rd!123 role sysadmin
OS10(config)# end
OS10# show running-configuration users
username test password **** role sysadmin priv-lvl 15

The four roles differ in what they can change, not just in what prompts they can see. sysadmin has full control including user and file management. netadmin configures network functions — interfaces, VLANs, routing — but cannot touch security policy. secadmin owns AAA, certificates and user accounts but not the data-plane protocols. netoperator is a monitoring role: show commands and limited maintenance operations, no configuration changes. A sensible production set is one break-glass sysadmin, netadmin for the network team, secadmin for whoever owns AAA, and netoperator for monitoring systems and the NOC.

The **** in the output is deliberate: OS10 stores a hash and never displays the password, so a credential is changed by applying a new statement rather than by reading the old one back. Also remember that the default admin account should be renamed or given a strong unique password, and that factory default credentials on a reachable management interface are the single most common finding in any network audit.

Saving and Managing Configuration Files

Persist the running configuration to startup configuration with write memory:

OS10# write memory

This is equivalent to copy running-configuration startup-configuration, and both forms are accepted. OS10 is explicit about the distinction: the running configuration is what the switch is using right now, and it is held in memory; the startup configuration is what the switch loads at boot. An unsaved change is real until the next reload and gone afterwards, which is why the first thing to check when configuration "reverts by itself" is whether anyone ran write memory.

OS10# copy running-configuration startup-configuration
OS10# show startup-configuration
OS10# copy running-configuration flash://config-backup-2026.txt

Keeping a dated copy on flash before a significant change is a cheap rollback path, and exporting the same content off-box to a repository is cheaper still. For changes large enough to warrant review, OS10's transaction-based configuration mode lets you stage edits and inspect the diff before committing, which is far safer than typing live on a switch that is forwarding traffic.

Troubleshooting a First Configuration Session

Three problems account for almost every failed first session on OS10, and each has a specific tell.

The command is rejected as invalid even though it looks right. You are almost always in the wrong mode. The prompt in front of the cursor tells you where you are: OS10# is EXEC, OS10(config)# is global configuration, and anything with conf-if or conf-range is scoped to interfaces. A username command typed at OS10# fails; the same command at OS10(config)# succeeds.

The management interface has an address but cannot reach anything. Check the management route first, then the next hop, then the upstream switch. show ip route management plus ping <gateway> source <mgmt-address> isolates the fault in two commands. A route whose next hop is off-subnet is accepted silently and never used, which is the trap most worth remembering.

The configuration reverts after a reload. Nobody ran write memory, or the change was made in a configuration session that was never committed. Compare show startup-configuration against show running-configuration; the difference is exactly what will be lost at the next reload.

Recovering Access to an OS10 Switch

If the management address is unknown or the admin password has been lost, recovery starts at the console. Log in over serial with the terminal settings OS10 expects — 115200 baud, 8 data bits, no parity, 1 stop bit, no flow control — and if the credentials are unknown, interrupt the boot process and select the factory reset option from the boot menu. That returns the switch to defaults, which restores admin/admin and DHCP on the management interface but also erases the stored configuration, so it is a last resort on a device that is already carrying traffic. Where a configuration backup exists on flash or on a server, restoring that file after the reset is far faster than rebuilding by hand — one more argument for copying the configuration off-box after every significant change.

For a switch that is reachable but behaving oddly, show logging and show alarms are the first two commands to run. They surface certificate problems, AAA failures and interface faults that never appear in a configuration diff but explain the symptom you are chasing. Reaching that point with a saved configuration, a documented management address and a working out-of-band path is the difference between a five-minute fix and a physical site visit.

Verification Checklist After First Configuration

Before declaring the switch ready, run through the following and confirm each answer is the one you expect: the management interface is up with the static address and no DHCP; the management route points at a reachable next hop; a sourced ping to the default gateway succeeds; SSH is enabled and Telnet is disabled; the named admin account exists with the intended role; NTP is configured so log timestamps are trustworthy; syslog is pointed at a collector; and show startup-configuration matches show running-configuration. That last check is the one that catches the mistake everybody makes once, which is finishing a session without saving it. Run it against the startup configuration, not just the running one — they are two different files, and only one of them survives a power cycle.

Related Reading

For related open-networking and management topics, check our guides on SONiC troubleshooting and getting started with Mellanox switches, plus setting the management IP on Dell EMC ME4084. If you are rolling out OS10 at scale, the zero-touch provisioning guide shows how to automate exactly these commands across a fleet.

原文链接:https://www.dell.com/support/kbdoc/en-us/000201924/dell-emc-networking-os10-basic-switch-management-configuration