肥宅钓鱼网
当前位置: 首页 钓鱼百科

h3c防火墙配置实例(防火墙配置域间策略脚本)

时间:2023-06-29 作者: 小编 阅读量: 1 栏目名: 钓鱼百科

version7.1.064,Release9304P05#sysnameUNIS#contextAdminid1#ipvpn-instancemanagementroute-distinguisher1000000000:1vpn-target1000000000:1import-extcommunityvpn-target1000000000:1export-extcommunity#teln

version 7.1.064, Release 9304P05

#

sysname UNIS

#

context Admin id 1

#

ip vpn-instance management

route-distinguisher 1000000000:1

vpn-target 1000000000:1 import-extcommunity

vpn-target 1000000000:1 export-extcommunity

#

telnet server enable

#

irf mac-address persistent timer

irf auto-update enable

undo irf link-delay

irf member 1 priority 1

#

security-zone intra-zone default permit

#

password-recovery enable

#

vlan 1

#

vlan 49 to 50

#

vlan 70

#

vlan 255

#

object-group ip address DNC服务器

0 network host address 10.100.80.10

#

object-group ip address DNC机床

description DNC机床

0 network subnet 10.100.50.0 255.255.255.0

#

object-group ip address test

#

object-group ip address 机加一分厂触摸屏控制台

0 network host address 10.100.50.193

#

object-group service 123

0 service icmp 0 0

#

object-group service DNC机床-服务器端口策略

0 service icmp 0 0

10 service tcp destination eq 21

20 service tcp destination range 600 1023

30 service udp destination eq 2049

40 service udp destination eq 111

50 service tcp destination eq 2049

60 service tcp destination eq 111

70 service tcp destination eq 19000

80 service udp destination range 8192 8193

90 service tcp destination range 8192 8193

100 service tcp destination eq 502

#

object-group service 机加一分厂触摸屏控制台-服务器

0 service icmp 0 0

10 service tcp destination eq 8889

20 service tcp destination eq 8000

30 service tcp destination eq 1521

#

interface NULL0

#

interface Vlan-interface255

ip address 10.100.255.40 255.255.255.0

#

interface GigabitEthernet1/0/0

port link-mode route

ip binding vpn-instance management

ip address 192.168.0.1 255.255.255.0

#

interface GigabitEthernet1/0/16

port link-mode route

#

interface GigabitEthernet1/0/17

port link-mode route

#

interface GigabitEthernet1/0/18

port link-mode route

#

interface GigabitEthernet1/0/19

port link-mode route

#

interface GigabitEthernet1/0/20

port link-mode route

#

interface GigabitEthernet1/0/21

port link-mode route

#

interface GigabitEthernet1/0/22

port link-mode route

#

interface GigabitEthernet1/0/23

port link-mode route

#

interface GigabitEthernet1/0/1

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/2

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/3

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/4

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/5

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/6

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/7

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/8

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/9

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/10

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/11

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/12

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/13

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/14

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/15

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

object-policy ip Any-Any

rule 0 pass logging counting

#

object-policy ip Trust-Untrust

rule 0 pass source-ip DNC机床 destination-ip DNC服务器 service DNC机床-服务器端

口策略 logging counting

rule 1 pass source-ip 机加一分厂触摸屏控制台 destination-ip DNC服务器 service

右环殖Тッ量刂铺?服务器 logging counting

#

security-zone name Local

#

security-zone name Trust

import interface GigabitEthernet1/0/8 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/9 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/10 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/11 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/12 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/13 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/14 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/15 vlan 1 49 to 50 70 80 255

#

security-zone name DMZ

#

security-zone name Untrust

import interface Vlan-interface255

import interface GigabitEthernet1/0/1 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/2 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/3 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/4 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/5 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/6 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/7 vlan 1 50 70 80 255

#

security-zone name Management

import interface GigabitEthernet1/0/0

#

zone-pair security source Any destination Any

object-policy apply ip Any-Any

packet-filter 2000

#

zone-pair security source Trust destination Untrust

object-policy apply ip Trust-Untrust

#

scheduler logfile size 16

#

line class aux

user-role network-operator

#

line class console

user-role network-admin

#

line class vty

user-role network-operator

#

line aux 0

user-role network-admin

#

line con 0

authentication-mode scheme

user-role network-admin

#

line vty 0 4

user-role level-15

user-role network-admin

set authentication password hash $h$6$FXcqr ZUfkzh0xpf$FoUxGIL0XT92tC90K2jVEkPb

95M33o675GIBswGHmY1iFfkmEoA/5m37Bn8aOnghK8bXPJZRbEd6P9VLjopCdg==

protocol inbound telnet

#

line vty 5 63

authentication-mode scheme

user-role network-admin

#

ip route-static 0.0.0.0 0 10.100.255.254

#

info-center logbuffer size 1024

#

ssh server enable

#

acl basic 2000

rule 0 permit

rule 0 permit

#

domain system

#

aaa session-limit ftp 16

aaa session-limit telnet 16

aaa session-limit ssh 16

domain default enable system

#

role name level-0

description Predefined level-0 role

#

role name level-1

description Predefined level-1 role

#

role name level-2

description Predefined level-2 role

#

role name level-3

description Predefined level-3 role

#

role name level-4

description Predefined level-4 role

#

role name level-5

description Predefined level-5 role

#

role name level-6

description Predefined level-6 role

#

role name level-7

description Predefined level-7 role

#

role name level-8

description Predefined level-8 role

#

role name level-9

description Predefined level-9 role

#

role name level-10

description Predefined level-10 role

#

role name level-11

description Predefined level-11 role

#

role name level-12

description Predefined level-12 role

#

role name level-13

description Predefined level-13 role

#

role name level-14

description Predefined level-14 role

#

user-group system

#

local-user admin class manage

password hash $h$6$9R/xrcOboMeyKx5C$0bPaw7Q41dLHQp2X8AAdmTLTU8RGFVplQmWdU7VZG95

n 3Dh2SQlKUn nIIVZflQSgIhMWZzVFEqlXFMeecodQ==

service-type ssh terminal https

authorization-attribute user-role level-3

authorization-attribute user-role network-admin

authorization-attribute user-role network-operator

#

local-user h3c class manage

service-type https

authorization-attribute user-role level-3

authorization-attribute user-role network-admin

authorization-attribute user-role network-operator

#

local-user i class manage

authorization-attribute user-role network-operator

#

ip https enable

#

ips policy default

#

anti-virus policy default

#

return

    推荐阅读
  • 家有女儿一定要告诉她十件事(家有女儿要懂得避开)

    不仅仅是跟爸爸妈妈的沟通少了,女儿的学习成绩也是波动很大。倘若女孩在家中是排名老大,那么女孩还会被要求充当“妈妈”的角色,早早学会照顾弟弟妹妹,替爸爸妈妈分担养育孩子的责任。倘若生了一个女孩,爸爸妈妈就会把女儿当做公主一般的照顾和养育,生怕女孩受到一点委屈。我认识的一位朋友就是如此,夫妻二人中年得女,生女儿的时候妈妈已经36岁了,爸爸40岁,所以夫妻二人对女儿真的是特别心疼。

  • 周公解梦做生意跟客户争吵(梦见和客户吵架好不好)

    但是行动往往落后一步。怀孕的人梦见跟客户吵架,预示生男,春占生女延后几天分娩。做生意的人梦见跟客户吵架,代表行案竞争,未能稳定,有盗宝之损失。梦见和客户吵架的吉凶宜忌梦见跟客户吵架的吉凶:得部下拥载,及长辈引进,而得成功发展,易得财利、名誉、事业隆昌,长寿少病之兆。梦见跟客户吵架的宜忌:「宜」宜洗车,宜爬山,宜装病。「忌」忌主动埋单,忌吃醋,忌替人受过。

  • 徐帆个人资料简介(关于徐帆的介绍)

    徐帆个人资料简介徐帆,1967年8月16日出生于湖北省武汉市江汉区,中国内地影视女演员,北京人民艺术剧院演员,国家一级演员,北京市人大代表,中国民主促进会(民进)会员,中国文学艺术界联合会第十届全委会委员。1995年,因主演话剧《阮玲玉》获得第十三届梅花奖。1998年,凭借电影《不见不散》获第5届中国电影华表奖最佳女演员奖。2019年,主演电影《只有芸知道》。

  • 牛尾不能和什么一起吃(牛尾骨的功效与营养)

    抗老美颜:牛尾骨所含的胶原蛋白、氨基酸、维生素等成分,食用后对皮肤所缺失的胶原蛋白会有一定的充盈效果,使皮肤皱褶相对减少,皮肤也会细腻有弹性。

  • 徐州汉画像石艺术馆2022年春节假期开放公告

    参观过程中,须全程佩戴口罩,请与其他游客、讲解员保持1米以上距离。友情提示:因徐州汉画像石艺术馆南馆实施技防提升和电器维修,2021年11月1日起临时闭馆,拟于2022年4月1日恢复对外开放。在此期间,祝各位观众在徐州汉画像石艺术馆北馆游览愉快!

  • 岩茶

    第二步,用茶匙取大约5克左右的岩茶,放到准备好的茶壶里。冲泡后的岩茶,散发着浓郁的清香。其实岩茶是属于乌龙茶,也是乌龙茶的一种,而且它能够有着非常好的调理身体机能的作用,比如说可以消除疲劳。可以说还是非常好的,对于大家调节身体机能来说,因此在日常生活中就可以备用一些岩茶,绝对会有很好的效果。

  • 立冬时节的注意事项是什么(立冬时节需要注意什么)

    人在这样的环境中会出现头昏、疲劳、恶心、食欲不振等症状。另外,冬季是一氧化碳中毒事件的多发季节,因此一定要保持室内空气流通、新鲜。摄取足够的动物性食品和大豆,以满足优质蛋白质的需求,适当增加油脂,其中植物油最好达到一半以上。此外,蔬菜、水果和奶类摄取量也需充足,这样子对身体的抗寒有很大的帮助。

  • 关于谷雨的物候特征(谷雨的物候特征有哪些)

    关于谷雨的物候特征?布谷鸟之所以称之为布谷鸟,是因为它的叫声是近似于“布谷”“布谷”的样儿。另外“布谷”又与“播谷”谐音、近义,有提示人们不要耽误农时播种的意思。戴胜鸟飞临桑树的枝头。

  • 开封八朝古都都有什么(走进八朝古都开封)

    王景被沈良打动,于是下令,今后治河,无论绅士、兵民、工匠、民工,凡有一言可取,一事可行者,莫不虚心采择,以期得当。经过这次大规模治理,黄河开封段此后很久没有发生过大的水患。于谦治水,修筑堤防1430年,33岁的于谦被任命为河南、山西巡抚。治水有功的于谦,被开封百姓尊为水神。长大之后,闫庆彦如愿来到了开封黄河河务局工作,同样奋战在治理黄河的第一线,成为第二代“治黄人”。

  • 澳门有什么值得买的(去澳门必买的伴手礼)

    澳门有什么值得买的当中最值得一提的是老佛爷饼店,号称澳门最好吃的面包,以制作香浓的起司蛋糕驰名港澳,是购买半手礼的热门首选。位于七楼的老佛爷以每天新鲜制造的蛋糕、法式西饼及面包而闻名港澳。莫义记大菜糕,此店在澳门经营大菜糕已经超过五十年,经过多年尝试,老板将大菜糕不断改良,希望令其味道变得更加多元化。钜记饼家最初在街头一角,以推车仔卖花生糖及姜糖为主。