中文字幕在线一区二区在线,久久久精品免费观看国产,无码日日模日日碰夜夜爽,天堂av在线最新版在线,日韩美精品无码一本二本三本,麻豆精品三级国产国语,精品无码AⅤ片,国产区在线观看视频

      H3C防火墻2區(qū)域配置案例

      時(shí)間:2024-08-24 05:25:16 H3C認(rèn)證 我要投稿
      • 相關(guān)推薦

      H3C防火墻2區(qū)域配置案例

        基于多年參與電力行業(yè)信息化的經(jīng)驗(yàn),H3C公司推出電力信息網(wǎng)絡(luò)安全加固解決方案,該解決方案主要由對(duì)終端安全防護(hù)和安全管理中心等關(guān)鍵部件組成。那么H3C防火墻2區(qū)域是怎么配置的呢?下面跟yjbys小編一起來看看!

        1、配置要求

        1)防火墻的E0/2接口為TRUST區(qū)域,ip地址是:192.168.254.1/29;

        2)防火墻的E1/2接口為UNTRUST區(qū)域,ip地址是:202.111.0.1/27;

        3)內(nèi)網(wǎng)服務(wù)器對(duì)外網(wǎng)做一對(duì)一的地址映射,192.168.254.2、192.168.254.3分別映射為202.111.0.2、202.111.0.3;

        4)內(nèi)網(wǎng)服務(wù)器訪問外網(wǎng)不做限制,外網(wǎng)訪問內(nèi)網(wǎng)只放通公網(wǎng)地址211.101.5.49訪問192.168.254.2的1433端口和192.168.254.3的80端口。

        2、防火墻的配置腳本如下

        dis cur

        #

        sysname H3CF100A

        #

        super password level 3 cipher 6aQ>Q57-$.I)0;4:\(I41!!!

        #

        firewall packet-filter enable

        firewall packet-filter default permit

        #

        insulate

        #

        nat static inside ip 192.168.254.2 global ip 202.111.0.2

        nat static inside ip 192.168.254.3 global ip 202.111.0.3

        #

        firewall statistic system enable

        #

        radius scheme system

        server-type extended

        #

        domain system

        #

        local-user net1980

        password cipher ######

        service-type telnet

        level 2

        #

        aspf-policy 1

        detect h323

        detect sqlnet

        detect rtsp

        detect http

        detect smtp

        detect ftp

        detect tcp

        detect udp

        #

        object address 192.168.254.2/32 192.168.254.2 255.255.255.255

        object address 192.168.254.3/32 192.168.254.3 255.255.255.255

        #

        acl number 3001

        description out-inside

        rule 1 permit tcp source 211.101.5.49 0 destination 192.168.254.2 0destination-port eq 1433

        rule 2 permit tcp source 211.101.5.49 0 destination 192.168.254.3 0destination-port eq www

        rule 1000 deny ip

        acl number 3002

        description inside-to-outside

        rule 1 permit ip source 192.168.254.2 0

        rule 2 permit ip source 192.168.254.3 0

        rule 1000 deny ip

        #

        interface Aux0

        async mode flow

        #

        interface Ethernet0/0

        shutdown

        #

        interface Ethernet0/1

        shutdown

        #

        interface Ethernet0/2

        speed 100

        duplex full

        description to server

        ip address 192.168.254.1 255.255.255.248

        firewall packet-filter 3002 inbound

        firewall aspf 1 outbound

        #

        interface Ethernet0/3

        shutdown

        #

        interface Ethernet1/0

        shutdown

        #

        interface Ethernet1/1

        shutdown

        #

        interface Ethernet1/2

        speed 100

        duplex full

        description to internet

        ip address 202.111.0.1 255.255.255.224

        firewall packet-filter 3001 inbound

        firewall aspf 1 outbound

        nat outbound static

        #

        interface NULL0

        #

        firewall zone local

        set priority 100

        #

        firewall zone trust

        add interface Ethernet0/2

        set priority 85

        #

        firewall zone untrust

        add interface Ethernet1/2

        set priority 5

        #

        firewall zone DMZ

        add interface Ethernet0/3

        set priority 50

        #

        firewall interzone local trust

        #

        firewall interzone local untrust

        #

        firewall interzone local DMZ

        #

        firewall interzone trust untrust

        #

        firewall interzone trust DMZ

        #

        firewall interzone DMZ untrust

        #

        ip route-static 0.0.0.0 0.0.0.0 202.111.0.30 preference 60

        #

        user-interface con 0

        user-interface aux 0

        user-interface vty 0 4

        authentication-mode scheme

        #

      【H3C防火墻2區(qū)域配置案例】相關(guān)文章:

      H3C認(rèn)證GRE典型配置案例12-28

      H3C交換機(jī)簡(jiǎn)單配置案例08-16

      在Cisco IOS中配置IPv6防火墻案例教程12-31

      H3C用戶認(rèn)證配置08-25

      h3c交換機(jī)配置telnet配置教程07-31

      h3c路由器配置01-22

      思科與H3C配置命令對(duì)比10-13

      H3C常用查詢配置命令大全01-22

      H3C核心交換機(jī)配置09-07

      主站蜘蛛池模板: 精品亚洲男人天堂av| 沁水县| 操B小视频国产| 厦门市| av无码一区二区三| 青春草在线观看播放网站| 亚洲欧洲日产国码无码av野外| 国产亚洲欧美日韩国产片| 人妖另类综合视频网站| 亚洲无码图| 马鞍山市| 成人影院免费观看在线播放视频| 亚洲av粉色一区二区三区| 亚洲精品色婷婷一区二区| 辽中县| 最新国产美女一区二区三区| 亚洲综合国产成人丁香五月小说| 欧美精品v欧洲高清| 房产| 封开县| 广河县| 一区二区视频高清在线观看| 亚洲精品白浆高清久久| 日韩在线不卡一区在线观看| 一区二区中文字幕视频| 国产麻豆放荡av激情演绎| 亚洲国产一区久久yourpan| 嘉黎县| 阳山县| 漳浦县| 韩日无码不卡| 熟妇与小伙子露脸对白| 偃师市| 彩票| 国产成人综合久久精品推荐免费 | 日本最新在线一区二区| 久久99久久99精品免观看女同| 玉溪市| 凤城市| 久操加勒比视频在线观看| 久久婷婷国产综合精品|