肥宅钓鱼网
当前位置: 首页 钓鱼百科

h3c防火墙配置实例(防火墙配置域间策略脚本)

时间:2023-06-29 作者: 小编 阅读量: 1 栏目名: 钓鱼百科

version7.1.064,Release9304P05#sysnameUNIS#contextAdminid1#ipvpn-instancemanagementroute-distinguisher1000000000:1vpn-target1000000000:1import-extcommunityvpn-target1000000000:1export-extcommunity#teln

version 7.1.064, Release 9304P05

#

sysname UNIS

#

context Admin id 1

#

ip vpn-instance management

route-distinguisher 1000000000:1

vpn-target 1000000000:1 import-extcommunity

vpn-target 1000000000:1 export-extcommunity

#

telnet server enable

#

irf mac-address persistent timer

irf auto-update enable

undo irf link-delay

irf member 1 priority 1

#

security-zone intra-zone default permit

#

password-recovery enable

#

vlan 1

#

vlan 49 to 50

#

vlan 70

#

vlan 255

#

object-group ip address DNC服务器

0 network host address 10.100.80.10

#

object-group ip address DNC机床

description DNC机床

0 network subnet 10.100.50.0 255.255.255.0

#

object-group ip address test

#

object-group ip address 机加一分厂触摸屏控制台

0 network host address 10.100.50.193

#

object-group service 123

0 service icmp 0 0

#

object-group service DNC机床-服务器端口策略

0 service icmp 0 0

10 service tcp destination eq 21

20 service tcp destination range 600 1023

30 service udp destination eq 2049

40 service udp destination eq 111

50 service tcp destination eq 2049

60 service tcp destination eq 111

70 service tcp destination eq 19000

80 service udp destination range 8192 8193

90 service tcp destination range 8192 8193

100 service tcp destination eq 502

#

object-group service 机加一分厂触摸屏控制台-服务器

0 service icmp 0 0

10 service tcp destination eq 8889

20 service tcp destination eq 8000

30 service tcp destination eq 1521

#

interface NULL0

#

interface Vlan-interface255

ip address 10.100.255.40 255.255.255.0

#

interface GigabitEthernet1/0/0

port link-mode route

ip binding vpn-instance management

ip address 192.168.0.1 255.255.255.0

#

interface GigabitEthernet1/0/16

port link-mode route

#

interface GigabitEthernet1/0/17

port link-mode route

#

interface GigabitEthernet1/0/18

port link-mode route

#

interface GigabitEthernet1/0/19

port link-mode route

#

interface GigabitEthernet1/0/20

port link-mode route

#

interface GigabitEthernet1/0/21

port link-mode route

#

interface GigabitEthernet1/0/22

port link-mode route

#

interface GigabitEthernet1/0/23

port link-mode route

#

interface GigabitEthernet1/0/1

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/2

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/3

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/4

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/5

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/6

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/7

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/8

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/9

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/10

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/11

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/12

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/13

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/14

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/15

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

object-policy ip Any-Any

rule 0 pass logging counting

#

object-policy ip Trust-Untrust

rule 0 pass source-ip DNC机床 destination-ip DNC服务器 service DNC机床-服务器端

口策略 logging counting

rule 1 pass source-ip 机加一分厂触摸屏控制台 destination-ip DNC服务器 service

右环殖Тッ量刂铺?服务器 logging counting

#

security-zone name Local

#

security-zone name Trust

import interface GigabitEthernet1/0/8 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/9 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/10 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/11 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/12 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/13 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/14 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/15 vlan 1 49 to 50 70 80 255

#

security-zone name DMZ

#

security-zone name Untrust

import interface Vlan-interface255

import interface GigabitEthernet1/0/1 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/2 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/3 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/4 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/5 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/6 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/7 vlan 1 50 70 80 255

#

security-zone name Management

import interface GigabitEthernet1/0/0

#

zone-pair security source Any destination Any

object-policy apply ip Any-Any

packet-filter 2000

#

zone-pair security source Trust destination Untrust

object-policy apply ip Trust-Untrust

#

scheduler logfile size 16

#

line class aux

user-role network-operator

#

line class console

user-role network-admin

#

line class vty

user-role network-operator

#

line aux 0

user-role network-admin

#

line con 0

authentication-mode scheme

user-role network-admin

#

line vty 0 4

user-role level-15

user-role network-admin

set authentication password hash $h$6$FXcqr ZUfkzh0xpf$FoUxGIL0XT92tC90K2jVEkPb

95M33o675GIBswGHmY1iFfkmEoA/5m37Bn8aOnghK8bXPJZRbEd6P9VLjopCdg==

protocol inbound telnet

#

line vty 5 63

authentication-mode scheme

user-role network-admin

#

ip route-static 0.0.0.0 0 10.100.255.254

#

info-center logbuffer size 1024

#

ssh server enable

#

acl basic 2000

rule 0 permit

rule 0 permit

#

domain system

#

aaa session-limit ftp 16

aaa session-limit telnet 16

aaa session-limit ssh 16

domain default enable system

#

role name level-0

description Predefined level-0 role

#

role name level-1

description Predefined level-1 role

#

role name level-2

description Predefined level-2 role

#

role name level-3

description Predefined level-3 role

#

role name level-4

description Predefined level-4 role

#

role name level-5

description Predefined level-5 role

#

role name level-6

description Predefined level-6 role

#

role name level-7

description Predefined level-7 role

#

role name level-8

description Predefined level-8 role

#

role name level-9

description Predefined level-9 role

#

role name level-10

description Predefined level-10 role

#

role name level-11

description Predefined level-11 role

#

role name level-12

description Predefined level-12 role

#

role name level-13

description Predefined level-13 role

#

role name level-14

description Predefined level-14 role

#

user-group system

#

local-user admin class manage

password hash $h$6$9R/xrcOboMeyKx5C$0bPaw7Q41dLHQp2X8AAdmTLTU8RGFVplQmWdU7VZG95

n 3Dh2SQlKUn nIIVZflQSgIhMWZzVFEqlXFMeecodQ==

service-type ssh terminal https

authorization-attribute user-role level-3

authorization-attribute user-role network-admin

authorization-attribute user-role network-operator

#

local-user h3c class manage

service-type https

authorization-attribute user-role level-3

authorization-attribute user-role network-admin

authorization-attribute user-role network-operator

#

local-user i class manage

authorization-attribute user-role network-operator

#

ip https enable

#

ips policy default

#

anti-virus policy default

#

return

    推荐阅读
  • 木耳泡多久最好呢(泡木耳的最佳时间)

    木耳泡多久最好呢经过3~4小时的浸泡,水慢慢地渗透到木耳中,木耳又恢复到半透明状即为发好。这样泡发的木耳,不但数量增多,而且质量好。木耳,主要生长在中国和日本。中国大部分是东北木耳和秦岭木耳。色泽黑褐,质地柔软呈胶质状,薄而有弹性,湿润时半透明,干燥时收缩变为脆硬的角质近似革质。味道鲜美,可素可荤,营养丰富。

  • 钢铁是怎样炼成的读后感400字(范文有吗?)

    钢铁是怎样炼成的读后感400字寒假中,我在爸爸的指导下读了《钢铁是怎样炼成的》这本书,我被书中主人公保尔的故事深深打动了。保尔出生穷苦,在参加革命过程中历尽磨难,最后成了一个坚强盲人革命作家,非常了不起。保尔是个普通的人,他的优秀事迹却非常令人感动,他给我们树立了榜样,我一定向他学习,长大以后做一个对社会有贡献的人。

  • 六一儿童节寄语(六一儿童节祝福)

    六一儿童节寄语六一至,世界超龄儿童协会发来贺电,祝你:天真烂漫、童心不改,红光满面、童颜大悦,活蹦乱跳、返老还童,童心荡漾、童趣无限。心愿是风,快乐是帆,祝福是船。六一儿童节到来之际,祝愿曾经是孩子的你:青春不老,保持一颗纯真的心,拥有甜美的微笑,孩童般的皮肤,无忧无虑的生活状态,对未来抱有幻想和憧憬。谁不说咱童年好,无忧无虑无烦恼。儿童节,愿美好时光明媚你心情。

  • a2驾驶证怎么考取(a2驾驶证考取的方法)

    a2驾驶证怎么考取a2驾驶证不允许初次申领只能通过增驾。已持有机动车驾驶证,申请增加准驾车型,应在本记分周期和申请前。正在接受全日制驾驶职业教育的学生,已在校取得驾驶小型汽车准驾车型资格。有下列情形之一,不得申请大型客车,牵引车、城市公交车、中型客车、大型货车准驾车型。发生交通事故,造成人员死亡,承担同等以上责任的。还有醉酒后驾驶机动车,被吊销或者撤销机动车驾驶证未满十年的,不允许考取驾照。

  • 7月二十二财神节朋友圈说说(七月二十二财神节祝福语)

    2.各路财神来报到,东路财神为你招宝,西路财神为你纳珍,南路财神为你招财,北路财神为你利市,中路财神为你护财,祝大家财源滚滚!

  • 海豹多肉怎么养才长得好(海豹多肉养植方法)

    海豹多肉怎么养才长得好多晒太阳多肉海豹是非常喜光的,在光照足的环境下可更好的进行光合作用,从而积攒更多的养分,状态会更美观。若长期时间缺光,叶子会萎蔫、易徒长,会出现多种生长不良情况。适量浇水海豹多肉内部含有较多的水分,耐旱。夏季加强通风,及时遮光,适当降温处理。冬季则要将海豹多肉搬到室内,最好控温在10℃以上,最低不可低于5℃。

  • 宁夏的美食和著名旅游景点(坐着高铁游宁夏)

    3月18日至19日,宁夏文化和旅游厅由厅领导带队,赴陕进行大型旅游推介和路演活动,邀请陕西城乡群众“坐着高铁游宁夏,给心灵放个假”。宁夏各族人民,其美食以西北面食为主,牛羊肉是主要的食用肉类。民族汤碗被中国烹饪协会评选为宁夏榜的“中国地域十大名小吃”。

  • 黄豆凉瓜煮鲍鱼怎么做(黄豆凉瓜煮鲍鱼的烹饪方法)

    黄豆凉瓜煮鲍鱼怎么做?以下内容大家不妨参考一二希望能帮到您!黄豆洗净,用清水浸泡3个小时,备用。鲍鱼去内脏冲洗干净,备用。开锅,下黄豆和浸泡黄豆的水,烧开,下凉瓜、姜片、鱼露、盐,中火煮15分钟,最后下鲍鱼,大火煮2分钟即可。

  • 对什么有好处英语(关于对什么有好处用英语说)

    对什么有好处-翻译begoodfor词典:begoodfor,今天小编就来说说关于对什么有好处英语?下面更多详细答案一起来看看吧!对什么有好处英语对什么有好处-翻译begoodfor。

  • 颈淋巴结分区图案(颈部淋巴结分区)

    舌骨水平CT增强图像横白线划在胸锁乳突肌后缘。白线前为III区淋巴结,后为V区淋巴结。女性,45岁,淋巴瘤。显示双侧腮腺区、左侧咽后区淋巴结增大,病变无融合倾向。女性,56岁,箭头显示右侧颈部ⅡA区转移性低分化癌。显示左侧Ⅲ区颈部淋巴结转移。黑箭显示双侧锁骨上窝淋巴结增大。