Dell OS10 Basic Switch Management: IP, Routes and Users - 夜莺博客

Dell OS10 Basic Switch Management: IP, Routes and Users

Dell PowerSwitch 系列交换机出厂默认 OS10 管理接口使用 DHCP,而生产环境通常需要固定管理地址。本文根据 Dell 官方知识库整理 OS10 基础管理配置全流程:为管理接口配置静态 IP、添加默认管理路由、创建管理员用户,并提供验证命令,适合刚上手 OS10 的网络工程师快速完成设备初始化。

This walkthrough follows Dell KB 000201924 and expands it into the full initialisation procedure: what the dedicated management interface is, the two supported addressing models, why the management route is configured separately from the data-plane routing table, how to create role-based administrative accounts, how to enable secure remote access, and the verification steps that confirm you can put the console cable away. It applies to the S-series and Z-series PowerSwitch platforms running OS10, whether the unit is factory-fresh or has just been reset.

前置条件 / Prerequisites

交换机为出厂默认配置,通过 console 口登录,默认凭据为 admin/admin。

Before you start, confirm the following:

  • Console access. The RJ45 console port on the switch, a USB-to-serial adapter, and a terminal at 115200 8N1. On a factory-default unit this is the only guaranteed way in.
  • Default credentials. OS10 ships with admin / admin as the sysadmin account and linuxadmin / linuxadmin for the Linux shell. Both should be changed as part of this procedure.
  • A management plan. Decide the management subnet, the switch's static address, the default gateway for that subnet, and the hostname before you type anything.
  • Out-of-band reachability. A jump host on the management network so you can test SSH immediately after configuring it.

If the switch has been reset rather than shipped new, the reset procedure is covered in OS10 factory reset and startup configuration deletion and in the newer OS10 factory reset methods and management setup walkthrough.

管理接口概览 / The Management Interface in OS10

OS10 exposes a dedicated out-of-band management interface named mgmt1/1/1. It is a first-class interface with its own addressing, its own routing table (populated by management route statements rather than by the data-plane routing protocols), and its own default state: DHCP for IPv4 and IPv6 autoconfiguration, both enabled, with the interface administratively up.

That separation is deliberate and worth understanding, because it explains most of the "the switch has a default route, why can't I reach the management IP" questions. A data-plane default route installed by OSPF or a static ip route 0.0.0.0/0 does not make the management interface reachable; you need a management route for that, and vice versa. Keeping the two planes apart means a routing misconfiguration in the production network cannot cut your management path, and also that the management network does not appear in the data-plane RIB.

配置管理接口静态 IP / Configure the Management Interface Static IP

先查看当前管理接口配置:

OS10# show running-configuration interface mgmt 1/1/1
interface mgmt1/1/1
  no shutdown
  ip address dhcp
  ipv6 address autoconfig

That is the factory-default output: the interface is up, IPv4 addressing is DHCP, and IPv6 autoconfiguration is on. The show running-configuration interface mgmt 1/1/1 form is the one to remember — the running configuration is the ground truth, and the interface name in the output loses the space (mgmt1/1/1) because that is how OS10 writes configuration text.

进入配置模式并配置静态地址:

OS10# configure terminal
OS10(config)# interface mgmt 1/1/1
OS10(conf-if-ma-1/1/1)# no ip address dhcp
OS10(conf-if-ma-1/1/1)# ip address 1.1.1.1/24

The order matters: stop the DHCP client with no ip address dhcp before assigning the static address, otherwise the DHCP lease and the manual address race for the interface. A successful add is confirmed by a syslog line on the console, for example an %IP_ADDRESS_ADD message reporting that the address was added in the management VRF. If you prefer to keep DHCP in an environment with reliable reservations, that is a perfectly valid design — but pin the lease to the switch's MAC on the DHCP server so the management address is deterministic.

A representative sequence with the peripheral steps in place looks like this:

OS10# configure terminal
OS10(config)# hostname sw-core-01
OS10(config)# interface mgmt 1/1/1
OS10(conf-if-ma-1/1/1)# no ip address dhcp
OS10(conf-if-ma-1/1/1)# ip address 10.10.10.21/24
OS10(conf-if-ma-1/1/1)# no ipv6 address autoconfig
OS10(conf-if-ma-1/1/1)# exit

添加默认管理路由 / Add the Default Management Route

OS10(config)# management route 0.0.0.0/0 1.1.1.2

The syntax is management route <destination prefix> <next-hop>. The next hop must be a device that is reachable on the management subnet and that knows how to return traffic to wherever you will be connecting from. Use 0.0.0.0/0 for "everything else goes here"; you can also install more specific management routes for things like a TFTP or syslog server sitting on a different management segment, and the longest-prefix match rules apply within the management table.

OS10(config)# management route 0.0.0.0/0 10.10.10.1
OS10(config)# management route 172.16.0.0/16 10.10.10.254
OS10(config)# end

验证配置 / Verify the Configuration

OS10# show running-configuration interface mgmt 1/1/1
OS10# show running-configuration management-route

Expected output after the change: the interface no longer shows ip address dhcp, and instead shows the static address you configured, while the management route appears on its own line in the route output:

OS10# show running-configuration interface mgmt 1/1/1
!
interface mgmt1/1/1
 no shutdown
 no ip address dhcp
 ip address 10.10.10.21/24
!
OS10# show running-configuration management-route
!
management route 0.0.0.0/0 10.10.10.1

Then test the plane you actually care about. From a host on the management network, ping the switch and open an SSH session; from the switch, confirm name resolution and reachability to your infrastructure services once the route is in place. Do this before you configure anything else, because the management plane is the path you will depend on for every later change.

OS10# show version
OS10# show ip interface brief
OS10# show running-configuration users

创建管理员用户 / Create an Administrative User

在 config 模式创建带管理员权限的本地用户(示例):

OS10(config)# username admin2 password admin2-secret role sysadmin
OS10(config)# username admin2 privilege 15

The important part of that pair is the role. OS10 is role-based: role sysadmin is the full administrative role equivalent to the built-in admin account, and it is what you want for a break-glass local account. Other roles (such as network administrator or security administrator roles) exist for environments that need least-privilege operational accounts. The privilege keyword refines the privilege level of the account for CLI access; on newer releases the role assignment is the recommended way to express authorisation, so treat the privilege line as legacy-compatible sugar rather than a substitute for a proper role.

The recommended end state is: create at least one named sysadmin account, verify you can log in with it over SSH, and then either change the default admin password or remove the default account entirely.

OS10(config)# username admin password <new-strong-password> role sysadmin
OS10(config)# exit
OS10# write memory
OS10# show running-configuration users

If configuration appears to be locked, the switch may be in the middle of Zero Touch Deployment. OS10 reports the lock explicitly, and you cancel it before configuring users:

OS10(config)# username admin password <new-strong-password> role sysadmin
% Error: ZTD is in progress(configuration is locked).
OS10# ztd cancel
OS10# configure terminal
OS10(config)# username admin password <new-strong-password> role sysadmin

启用远程管理 / Enable SSH for Remote Management

如需远程管理,还可启用 SSH 服务并绑定 VTY:

OS10(config)# ip ssh server enable
OS10(config)# line vty 0 4
OS10(conf-line-vty)# transport input ssh

SSH is the only remote protocol you should enable. Where the platform still offers Telnet, disable it explicitly and tighten the SSH server so brute-force attempts against the management interface are less attractive:

OS10(config)# ip ssh server enable
OS10(config)# ip ssh server max-auth-tries 4
OS10(config)# no ip telnet server enable
OS10(config)# end
OS10# write memory

If you want to restrict which management hosts may even reach the SSH port, apply an ACL to the management service rather than relying on the upstream firewall alone:

OS10(config)# ip access-list mgmt-permit
OS10(config-ipv4-acl)# permit ip 10.10.0.0/16 any
OS10(config-ipv4-acl)# exit

Then test from the jump host with a real login, not just a TCP connect. The ip ssh server enable command takes effect immediately, so the test can follow the configuration without a save in between — but save anyway, so a reload does not undo your work.

保存与备份 / Save and Back Up

Everything above lives in the running configuration until you persist it. On a freshly initialised switch this is the step that is most often forgotten, and it is the one that costs a physical trip to the rack.

OS10# copy running-configuration startup-configuration
OS10# write memory
OS10# show startup-configuration | head
OS10# copy running-configuration tftp://10.10.10.50/sw-core-01-baseline.cfg

The two save forms are equivalent; write memory is simply shorter. Backing the file up off-box gives you a rollback path that does not depend on the console port, and the management configuration you have just built is exactly the kind of baseline worth versioning.

常见问题 / Common Problems

  • Management interface unreachable after the change. Almost always a missing management route, or a next hop that is not on the management subnet. Remember that data-plane routes do not apply here.
  • Both DHCP and a static address appear configured. You assigned the address before stopping the DHCP client with no ip address dhcp.
  • SSH refused. ip ssh server enable was never issued, or a VTY access-class is filtering your source address.
  • Configuration commands rejected with a lock error. ZTD is running; cancel it with ztd cancel.
  • New user cannot log in. The account exists but was never saved, or you are testing with a username that differs in case from the one you created. Check show running-configuration users.
  • Everything worked until the reload. The configuration was never saved to the startup configuration.

Acceptance Checklist After Initialisation

Once the management plane is up, run through this short checklist before you declare the switch ready. It takes five minutes and catches every mistake that would otherwise surface at the worst possible moment.

  1. Console access still works with the default account, and the new named sysadmin account also works. Keep one working account you have actually logged in with.
  2. From the jump host: ping the management address, then ssh into the switch and confirm the hostname in the prompt matches the one you configured.
  3. The running configuration shows the static address, the management route and the user accounts; the startup configuration matches it after the save.
  4. A copy of the configuration exists on a server outside the switch, timestamped and named after the device.
  5. Documented facts: management IP, gateway, hostname, software version from show version, and the service tag, stored wherever your team keeps device records.

Only after that checklist passes should you move on to data-plane work such as VLANs, port-channels and spanning tree. Building the management plane first means every subsequent change can be made remotely, reviewed, and rolled back without a physical visit.

相关阅读 / Related Reading

OS10 的 LACP 端口聚合配置见本站 Dell OS10 Port-Channel Configuration: LACP Step-by-Step;同一硬件平台跑 SONiC 的方法见 Install SONiC on Dell S5212F-ON;SONiC 版基础管理见 Dell S-Series SONiC 4.0: Basic Switch Management。

Continue with OS10 management interface configuration for the interface-level detail, OS10 default gateway and management route configuration for gateway designs, OS10 out-of-band management interface and VRF configuration for separating the management plane, and OS10 SNMPv3 configuration for monitoring once the switch is reachable.

原文链接:https://www.dell.com/support/kbdoc/en-us/000201924/dell-emc-networking-os10-basic-switch-management-configuration