<dfn id="w48us"></dfn><ul id="w48us"></ul>
  • <ul id="w48us"></ul>
  • <del id="w48us"></del>
    <ul id="w48us"></ul>
  • H3C防火墻2區(qū)域配置案例

    時(shí)間:2024-08-24 05:25:16 H3C認(rèn)證 我要投稿
    • 相關(guān)推薦

    H3C防火墻2區(qū)域配置案例

      基于多年參與電力行業(yè)信息化的經(jīng)驗(yàn),H3C公司推出電力信息網(wǎng)絡(luò)安全加固解決方案,該解決方案主要由對終端安全防護(hù)和安全管理中心等關(guān)鍵部件組成。那么H3C防火墻2區(qū)域是怎么配置的呢?下面跟yjbys小編一起來看看!

      1、配置要求

      1)防火墻的E0/2接口為TRUST區(qū)域,ip地址是:192.168.254.1/29;

      2)防火墻的E1/2接口為UNTRUST區(qū)域,ip地址是:202.111.0.1/27;

      3)內(nèi)網(wǎng)服務(wù)器對外網(wǎng)做一對一的地址映射,192.168.254.2、192.168.254.3分別映射為202.111.0.2、202.111.0.3;

      4)內(nèi)網(wǎng)服務(wù)器訪問外網(wǎng)不做限制,外網(wǎng)訪問內(nèi)網(wǎng)只放通公網(wǎng)地址211.101.5.49訪問192.168.254.2的1433端口和192.168.254.3的80端口。

      2、防火墻的配置腳本如下

      dis cur

      #

      sysname H3CF100A

      #

      super password level 3 cipher 6aQ>Q57-$.I)0;4:\(I41!!!

      #

      firewall packet-filter enable

      firewall packet-filter default permit

      #

      insulate

      #

      nat static inside ip 192.168.254.2 global ip 202.111.0.2

      nat static inside ip 192.168.254.3 global ip 202.111.0.3

      #

      firewall statistic system enable

      #

      radius scheme system

      server-type extended

      #

      domain system

      #

      local-user net1980

      password cipher ######

      service-type telnet

      level 2

      #

      aspf-policy 1

      detect h323

      detect sqlnet

      detect rtsp

      detect http

      detect smtp

      detect ftp

      detect tcp

      detect udp

      #

      object address 192.168.254.2/32 192.168.254.2 255.255.255.255

      object address 192.168.254.3/32 192.168.254.3 255.255.255.255

      #

      acl number 3001

      description out-inside

      rule 1 permit tcp source 211.101.5.49 0 destination 192.168.254.2 0destination-port eq 1433

      rule 2 permit tcp source 211.101.5.49 0 destination 192.168.254.3 0destination-port eq www

      rule 1000 deny ip

      acl number 3002

      description inside-to-outside

      rule 1 permit ip source 192.168.254.2 0

      rule 2 permit ip source 192.168.254.3 0

      rule 1000 deny ip

      #

      interface Aux0

      async mode flow

      #

      interface Ethernet0/0

      shutdown

      #

      interface Ethernet0/1

      shutdown

      #

      interface Ethernet0/2

      speed 100

      duplex full

      description to server

      ip address 192.168.254.1 255.255.255.248

      firewall packet-filter 3002 inbound

      firewall aspf 1 outbound

      #

      interface Ethernet0/3

      shutdown

      #

      interface Ethernet1/0

      shutdown

      #

      interface Ethernet1/1

      shutdown

      #

      interface Ethernet1/2

      speed 100

      duplex full

      description to internet

      ip address 202.111.0.1 255.255.255.224

      firewall packet-filter 3001 inbound

      firewall aspf 1 outbound

      nat outbound static

      #

      interface NULL0

      #

      firewall zone local

      set priority 100

      #

      firewall zone trust

      add interface Ethernet0/2

      set priority 85

      #

      firewall zone untrust

      add interface Ethernet1/2

      set priority 5

      #

      firewall zone DMZ

      add interface Ethernet0/3

      set priority 50

      #

      firewall interzone local trust

      #

      firewall interzone local untrust

      #

      firewall interzone local DMZ

      #

      firewall interzone trust untrust

      #

      firewall interzone trust DMZ

      #

      firewall interzone DMZ untrust

      #

      ip route-static 0.0.0.0 0.0.0.0 202.111.0.30 preference 60

      #

      user-interface con 0

      user-interface aux 0

      user-interface vty 0 4

      authentication-mode scheme

      #

    【H3C防火墻2區(qū)域配置案例】相關(guān)文章:

    H3C認(rèn)證GRE典型配置案例12-28

    H3C交換機(jī)簡單配置案例08-16

    在Cisco IOS中配置IPv6防火墻案例教程12-31

    H3C用戶認(rèn)證配置08-25

    h3c交換機(jī)配置telnet配置教程07-31

    h3c路由器配置01-22

    思科與H3C配置命令對比10-13

    H3C常用查詢配置命令大全01-22

    H3C核心交換機(jī)配置09-07

    主站蜘蛛池模板: 亚洲日韩精品一区二区三区无码| 欧美精品国产精品| 99久久精品国产一区二区三区| 久久精品无码一区二区三区| 欧美精品一区二区在线精品| 伊人久久无码精品中文字幕| 久久99国产综合精品女同| 成人无码精品1区2区3区免费看| 91国内外精品自在线播放| 日韩精品无码Av一区二区| 久久精品国产亚洲av影院| 精品国产香蕉伊思人在线在线亚洲一区二区 | 国语自产精品视频| 精品国产一区二区三区久久| 一级成人精品h| 欧美亚洲日本久久精品| 亚洲精品自产拍在线观看动漫| 亚洲AV无码久久精品蜜桃| 99视频精品全部在线观看| 中文字幕无码精品三级在线电影 | 国产精品无码一区二区在线| 日韩精品一区二区三区在线观看| 久久精品国产一区| 99精品在线观看| 国产欧美日韩综合精品二区| 国产精品亚洲片在线va| 久久www免费人成精品香蕉| 亚洲国产一成人久久精品| 免费精品99久久国产综合精品| 精品9E精品视频在线观看| 国产精品高清在线观看| 亚洲精品无码专区久久同性男| 国产精品无码久久综合网| 91精品视频在线| 四虎影视永久在线观看精品| 亚洲精品无码专区久久同性男| 亚洲国产精品无码久久久久久曰 | 99久久精品无码一区二区毛片| 久久亚洲国产午夜精品理论片| 国产精品成人va在线观看| 大伊香蕉精品视频在线导航|