肥宅钓鱼网
当前位置: 首页 钓鱼百科

h3c防火墙配置实例(防火墙配置域间策略脚本)

时间:2023-06-29 作者: 小编 阅读量: 1 栏目名: 钓鱼百科

version7.1.064,Release9304P05#sysnameUNIS#contextAdminid1#ipvpn-instancemanagementroute-distinguisher1000000000:1vpn-target1000000000:1import-extcommunityvpn-target1000000000:1export-extcommunity#teln

version 7.1.064, Release 9304P05

#

sysname UNIS

#

context Admin id 1

#

ip vpn-instance management

route-distinguisher 1000000000:1

vpn-target 1000000000:1 import-extcommunity

vpn-target 1000000000:1 export-extcommunity

#

telnet server enable

#

irf mac-address persistent timer

irf auto-update enable

undo irf link-delay

irf member 1 priority 1

#

security-zone intra-zone default permit

#

password-recovery enable

#

vlan 1

#

vlan 49 to 50

#

vlan 70

#

vlan 255

#

object-group ip address DNC服务器

0 network host address 10.100.80.10

#

object-group ip address DNC机床

description DNC机床

0 network subnet 10.100.50.0 255.255.255.0

#

object-group ip address test

#

object-group ip address 机加一分厂触摸屏控制台

0 network host address 10.100.50.193

#

object-group service 123

0 service icmp 0 0

#

object-group service DNC机床-服务器端口策略

0 service icmp 0 0

10 service tcp destination eq 21

20 service tcp destination range 600 1023

30 service udp destination eq 2049

40 service udp destination eq 111

50 service tcp destination eq 2049

60 service tcp destination eq 111

70 service tcp destination eq 19000

80 service udp destination range 8192 8193

90 service tcp destination range 8192 8193

100 service tcp destination eq 502

#

object-group service 机加一分厂触摸屏控制台-服务器

0 service icmp 0 0

10 service tcp destination eq 8889

20 service tcp destination eq 8000

30 service tcp destination eq 1521

#

interface NULL0

#

interface Vlan-interface255

ip address 10.100.255.40 255.255.255.0

#

interface GigabitEthernet1/0/0

port link-mode route

ip binding vpn-instance management

ip address 192.168.0.1 255.255.255.0

#

interface GigabitEthernet1/0/16

port link-mode route

#

interface GigabitEthernet1/0/17

port link-mode route

#

interface GigabitEthernet1/0/18

port link-mode route

#

interface GigabitEthernet1/0/19

port link-mode route

#

interface GigabitEthernet1/0/20

port link-mode route

#

interface GigabitEthernet1/0/21

port link-mode route

#

interface GigabitEthernet1/0/22

port link-mode route

#

interface GigabitEthernet1/0/23

port link-mode route

#

interface GigabitEthernet1/0/1

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/2

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/3

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/4

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/5

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/6

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/7

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/8

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/9

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/10

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/11

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/12

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/13

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/14

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/15

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

object-policy ip Any-Any

rule 0 pass logging counting

#

object-policy ip Trust-Untrust

rule 0 pass source-ip DNC机床 destination-ip DNC服务器 service DNC机床-服务器端

口策略 logging counting

rule 1 pass source-ip 机加一分厂触摸屏控制台 destination-ip DNC服务器 service

右环殖Тッ量刂铺?服务器 logging counting

#

security-zone name Local

#

security-zone name Trust

import interface GigabitEthernet1/0/8 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/9 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/10 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/11 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/12 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/13 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/14 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/15 vlan 1 49 to 50 70 80 255

#

security-zone name DMZ

#

security-zone name Untrust

import interface Vlan-interface255

import interface GigabitEthernet1/0/1 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/2 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/3 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/4 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/5 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/6 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/7 vlan 1 50 70 80 255

#

security-zone name Management

import interface GigabitEthernet1/0/0

#

zone-pair security source Any destination Any

object-policy apply ip Any-Any

packet-filter 2000

#

zone-pair security source Trust destination Untrust

object-policy apply ip Trust-Untrust

#

scheduler logfile size 16

#

line class aux

user-role network-operator

#

line class console

user-role network-admin

#

line class vty

user-role network-operator

#

line aux 0

user-role network-admin

#

line con 0

authentication-mode scheme

user-role network-admin

#

line vty 0 4

user-role level-15

user-role network-admin

set authentication password hash $h$6$FXcqr ZUfkzh0xpf$FoUxGIL0XT92tC90K2jVEkPb

95M33o675GIBswGHmY1iFfkmEoA/5m37Bn8aOnghK8bXPJZRbEd6P9VLjopCdg==

protocol inbound telnet

#

line vty 5 63

authentication-mode scheme

user-role network-admin

#

ip route-static 0.0.0.0 0 10.100.255.254

#

info-center logbuffer size 1024

#

ssh server enable

#

acl basic 2000

rule 0 permit

rule 0 permit

#

domain system

#

aaa session-limit ftp 16

aaa session-limit telnet 16

aaa session-limit ssh 16

domain default enable system

#

role name level-0

description Predefined level-0 role

#

role name level-1

description Predefined level-1 role

#

role name level-2

description Predefined level-2 role

#

role name level-3

description Predefined level-3 role

#

role name level-4

description Predefined level-4 role

#

role name level-5

description Predefined level-5 role

#

role name level-6

description Predefined level-6 role

#

role name level-7

description Predefined level-7 role

#

role name level-8

description Predefined level-8 role

#

role name level-9

description Predefined level-9 role

#

role name level-10

description Predefined level-10 role

#

role name level-11

description Predefined level-11 role

#

role name level-12

description Predefined level-12 role

#

role name level-13

description Predefined level-13 role

#

role name level-14

description Predefined level-14 role

#

user-group system

#

local-user admin class manage

password hash $h$6$9R/xrcOboMeyKx5C$0bPaw7Q41dLHQp2X8AAdmTLTU8RGFVplQmWdU7VZG95

n 3Dh2SQlKUn nIIVZflQSgIhMWZzVFEqlXFMeecodQ==

service-type ssh terminal https

authorization-attribute user-role level-3

authorization-attribute user-role network-admin

authorization-attribute user-role network-operator

#

local-user h3c class manage

service-type https

authorization-attribute user-role level-3

authorization-attribute user-role network-admin

authorization-attribute user-role network-operator

#

local-user i class manage

authorization-attribute user-role network-operator

#

ip https enable

#

ips policy default

#

anti-virus policy default

#

return

    推荐阅读
  • 附子理中丸的副作用 附子理中丸的副作用和禁忌人群

    药物都有两面性的,虽然药物治疗疾病是有很好的效果,但是它的副作用对人体的伤害也是相当大的,所以大家在用药的时候就特别的小心,附子理中丸也不例外,下面我们就一起来看一看附子理中丸有什么副作用吧!附子理中丸的注意事项1、忌不易消化食物。

  • 699是什么意思(699指代什么)

    699是什么意思699工作制699工作制和996工作制是一样的,就是每周工作6天,每天早上9点上班,晚上9点下班,总计每天工作时长10个小时以上,这种工作制普遍存在于互联网公司,代表着中国互联网企业盛行的加班文化。但这是是一种违反了《中华人民共和国劳动法》的延长法定工作时间的工作制度。爱情数字密码是人们利用数字的谐音而编出来的和爱情有关的文字或短语,也是人们为了更好的表达爱意的一种符号。

  • 如何有效又快速的减肚子的肉(肚子肉太多人会变傻)

    肚子肉太多人会变傻肥胖,始终是困扰很多人的问题不知道大家有没有注意过,胖其实也分两种类型:有些人是全身哪里都胖,属于胖得比较均匀;而有些人表面上看着并不胖,但是一掀开衣服,小肚子立马就露出来了同样都是凭实力胖起来的,为。

  • 生日朋友圈文案文艺范(生日朋友圈文艺范的文案有哪些)

    以下内容大家不妨参考一二希望能帮到您!生日朋友圈文案文艺范今天又与这值得的人间多相处了一年。成长不期而遇,生日如期而至。无事绊心弦所念皆如愿xx岁幸會。生日快乐愿以后的我多一点小幸运。来了来了,她带着愿望来了……愿以后的日子里,眼里都是阳光,笑里满是坦荡,祝我生日快乐!

  • 烟雨楼的来历(烟雨楼的来历介绍)

    以下内容大家不妨参考一二希望能帮到您!烟雨楼的来历相传,嘉定年间,当时的“烟雨楼”之楼名取自唐代大诗人杜牧《七绝?江南春》中“南朝四百八十寺,多少楼台烟雨中”的意境。由于此诗在宋代广泛传播,烟雨楼美名远扬,成为当时观赏湖光的最佳去处。官僚地主、文人墨客,登楼赋诗饮酒,日夜笙歌不绝。

  • 小红本和小黄本出国必须办吗(被小红书坑惨了的留学生)

    被小红书坑惨了的留学生六月已经来了,暑假还会远吗?暑假来了,就证明着一年一度的留学猎杀时刻又要开始了,没错,又到了收拾行李的环节!每逢这个季节,也是小各个“学长”“学姐”的活跃时刻,我以为推荐电饭锅已经够离谱了,没想到还是。

  • 大人国安息日是哪天(安息日是为人而设的)

    《旧约》中有许多严苛的戒律,谨守安息日是其中之一。譬如说,在某个周末休息日,有一个门徒路过麦田时摘了麦穗,法利赛人要求严惩。对于上帝设立安息日的本意,其实是可以做不同的解释的。因此,人们虽然可以也应该在安息日休息或礼拜,但不必把这当作绝对的戒律,完全有权酌情变通。事实上,耶稣自己就常常在安息日为人治病,为此而遭法利赛人攻击,但仍坚定不移。

  • 巨石阵真实身世之谜(巨石阵的起源之谜)

    诸如巨石阵等上千个古代石头建筑出现在欧洲。相关成果日前发表于美国《国家科学院院刊》。为确定哪种观点是对的,瑞典哥德堡大学的BettinaSchulzPaulsson分析了欧洲2000多块巨石的建造时间。随后,这一传统在2000年的时间里沿着地中海和大西洋沿岸的海上路线在欧洲扩散,主要是在沿海地区。SchulzPaulsson介绍说,这符合其进行的关于布列塔尼巨石艺术研究的结果。据了解,诸如石圈和地下通道式坟墓等3500多个巨石,仍存在于从撒丁岛到斯堪的纳维亚半岛的整个欧洲。

  • 高考祝福自己的话简短(给自己的高考祝福语)

    以下内容希望对你有帮助!高考祝福自己的话简短高考一切顺利,超常发挥,金榜题名!一定能考上理想的大学!全国高考日到了,愿你执才高八斗生辉笔,饮才思万千智慧水,带气定神闲满面笑,拥胸中成竹满怀志,书锦绣嫣然好答卷,定折取桂冠来题名。面对目标,信心百倍,人生能有几次搏?面对成绩,心胸豁达,条条大路通罗马。立志高远,脚踏实地;刻苦钻研,勤学苦思;稳定心态,不馁不弃;全力以赴,夺取胜利。

  • 729车牌是什么意思(729车牌的意思)

    不过朝鲜的727车牌确实是高官才能使用的,727车牌的样式为白底红星,属于朝鲜的特权车牌。或者可以说朝鲜的特权车牌都是由白底红星加三个字母组成。朝鲜车牌一般分为海内和海外两种,号牌前两个数字可以代表具体的单位。26代表外务省;39代表运输部分;47代表商业机构;86则代表新闻单位。蓝底黑字表示是使馆车辆,打头是朝鲜文字标明的“外”字,表明是外国车辆。