肥宅钓鱼网
当前位置: 首页 钓鱼百科

h3c防火墙配置实例(防火墙配置域间策略脚本)

时间:2023-06-29 作者: 小编 阅读量: 1 栏目名: 钓鱼百科

version7.1.064,Release9304P05#sysnameUNIS#contextAdminid1#ipvpn-instancemanagementroute-distinguisher1000000000:1vpn-target1000000000:1import-extcommunityvpn-target1000000000:1export-extcommunity#teln

version 7.1.064, Release 9304P05

#

sysname UNIS

#

context Admin id 1

#

ip vpn-instance management

route-distinguisher 1000000000:1

vpn-target 1000000000:1 import-extcommunity

vpn-target 1000000000:1 export-extcommunity

#

telnet server enable

#

irf mac-address persistent timer

irf auto-update enable

undo irf link-delay

irf member 1 priority 1

#

security-zone intra-zone default permit

#

password-recovery enable

#

vlan 1

#

vlan 49 to 50

#

vlan 70

#

vlan 255

#

object-group ip address DNC服务器

0 network host address 10.100.80.10

#

object-group ip address DNC机床

description DNC机床

0 network subnet 10.100.50.0 255.255.255.0

#

object-group ip address test

#

object-group ip address 机加一分厂触摸屏控制台

0 network host address 10.100.50.193

#

object-group service 123

0 service icmp 0 0

#

object-group service DNC机床-服务器端口策略

0 service icmp 0 0

10 service tcp destination eq 21

20 service tcp destination range 600 1023

30 service udp destination eq 2049

40 service udp destination eq 111

50 service tcp destination eq 2049

60 service tcp destination eq 111

70 service tcp destination eq 19000

80 service udp destination range 8192 8193

90 service tcp destination range 8192 8193

100 service tcp destination eq 502

#

object-group service 机加一分厂触摸屏控制台-服务器

0 service icmp 0 0

10 service tcp destination eq 8889

20 service tcp destination eq 8000

30 service tcp destination eq 1521

#

interface NULL0

#

interface Vlan-interface255

ip address 10.100.255.40 255.255.255.0

#

interface GigabitEthernet1/0/0

port link-mode route

ip binding vpn-instance management

ip address 192.168.0.1 255.255.255.0

#

interface GigabitEthernet1/0/16

port link-mode route

#

interface GigabitEthernet1/0/17

port link-mode route

#

interface GigabitEthernet1/0/18

port link-mode route

#

interface GigabitEthernet1/0/19

port link-mode route

#

interface GigabitEthernet1/0/20

port link-mode route

#

interface GigabitEthernet1/0/21

port link-mode route

#

interface GigabitEthernet1/0/22

port link-mode route

#

interface GigabitEthernet1/0/23

port link-mode route

#

interface GigabitEthernet1/0/1

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/2

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/3

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/4

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/5

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/6

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/7

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/8

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/9

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/10

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/11

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/12

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/13

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/14

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/15

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

object-policy ip Any-Any

rule 0 pass logging counting

#

object-policy ip Trust-Untrust

rule 0 pass source-ip DNC机床 destination-ip DNC服务器 service DNC机床-服务器端

口策略 logging counting

rule 1 pass source-ip 机加一分厂触摸屏控制台 destination-ip DNC服务器 service

右环殖Тッ量刂铺?服务器 logging counting

#

security-zone name Local

#

security-zone name Trust

import interface GigabitEthernet1/0/8 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/9 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/10 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/11 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/12 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/13 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/14 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/15 vlan 1 49 to 50 70 80 255

#

security-zone name DMZ

#

security-zone name Untrust

import interface Vlan-interface255

import interface GigabitEthernet1/0/1 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/2 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/3 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/4 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/5 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/6 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/7 vlan 1 50 70 80 255

#

security-zone name Management

import interface GigabitEthernet1/0/0

#

zone-pair security source Any destination Any

object-policy apply ip Any-Any

packet-filter 2000

#

zone-pair security source Trust destination Untrust

object-policy apply ip Trust-Untrust

#

scheduler logfile size 16

#

line class aux

user-role network-operator

#

line class console

user-role network-admin

#

line class vty

user-role network-operator

#

line aux 0

user-role network-admin

#

line con 0

authentication-mode scheme

user-role network-admin

#

line vty 0 4

user-role level-15

user-role network-admin

set authentication password hash $h$6$FXcqr ZUfkzh0xpf$FoUxGIL0XT92tC90K2jVEkPb

95M33o675GIBswGHmY1iFfkmEoA/5m37Bn8aOnghK8bXPJZRbEd6P9VLjopCdg==

protocol inbound telnet

#

line vty 5 63

authentication-mode scheme

user-role network-admin

#

ip route-static 0.0.0.0 0 10.100.255.254

#

info-center logbuffer size 1024

#

ssh server enable

#

acl basic 2000

rule 0 permit

rule 0 permit

#

domain system

#

aaa session-limit ftp 16

aaa session-limit telnet 16

aaa session-limit ssh 16

domain default enable system

#

role name level-0

description Predefined level-0 role

#

role name level-1

description Predefined level-1 role

#

role name level-2

description Predefined level-2 role

#

role name level-3

description Predefined level-3 role

#

role name level-4

description Predefined level-4 role

#

role name level-5

description Predefined level-5 role

#

role name level-6

description Predefined level-6 role

#

role name level-7

description Predefined level-7 role

#

role name level-8

description Predefined level-8 role

#

role name level-9

description Predefined level-9 role

#

role name level-10

description Predefined level-10 role

#

role name level-11

description Predefined level-11 role

#

role name level-12

description Predefined level-12 role

#

role name level-13

description Predefined level-13 role

#

role name level-14

description Predefined level-14 role

#

user-group system

#

local-user admin class manage

password hash $h$6$9R/xrcOboMeyKx5C$0bPaw7Q41dLHQp2X8AAdmTLTU8RGFVplQmWdU7VZG95

n 3Dh2SQlKUn nIIVZflQSgIhMWZzVFEqlXFMeecodQ==

service-type ssh terminal https

authorization-attribute user-role level-3

authorization-attribute user-role network-admin

authorization-attribute user-role network-operator

#

local-user h3c class manage

service-type https

authorization-attribute user-role level-3

authorization-attribute user-role network-admin

authorization-attribute user-role network-operator

#

local-user i class manage

authorization-attribute user-role network-operator

#

ip https enable

#

ips policy default

#

anti-virus policy default

#

return

    推荐阅读
  • 电脑菜单栏一直闪怎么回事(电脑任务栏一直闪动怎么取消?)

    跟着小编一起来看一看吧!电脑菜单栏一直闪怎么回事电脑下方任务栏一直闪动,看下是不是电脑自动启动了“360软件小助手”。如果确认电脑启动了“360软件小助手”,那么在任务栏该软件图标处,点击右键--退出,即可。在弹出的右键对话框“开机启动”选项前的对勾√一定要去掉,这样,下次就不会出现“电脑任务栏左右闪动”的问题。电脑任务栏左右闪动的问题完美解决。

  • 十大不值得入手的洗面奶(别再跟风踩雷了)

    但是官方宣称的“烟酰胺”也根本查不到,而且还有4种致痘成分,3种防腐剂,1种香精。资生堂洗颜专科洗面奶含有4种皂基成分、5种致痘成分、3种防腐剂、并且含有酒精。含46.5%纯氨基酸成分,用着也不怕刺激皮肤,现在基本素颜出门。sk2洗面奶油性皮肤的福音,油皮的人用它的使用感会更好,是一款氨基酸洗面奶,长期使用还可以有助于祛除黑头和粉刺。内含的椰油苹果氨基酸能够给肌肤增加保湿力,洗完脸也是滋润不紧绷,很清爽。

  • 最适合男孩使用的英文名字(适合男孩的英文名字)

    最适合男孩使用的英文名字Ben:希伯来语“儿子”的意思;所有Ben开头名字的简写。Ben的意义是高大,强壮的黑发男子,用它来取名字代表可爱而又随和的性格。Mark是爱好运动的意思,而作为名字可以解释为非常英俊的男人,风趣且爱好自由,而且是个细心的朋友。

  • 微博被禁言要多久才能恢复?(禁言时间微博)

    我们一起去了解并探讨一下这个问题吧!微博被禁言要多久才能恢复首先,看你是不是头一次被禁言了,如果是头一次的话等一个礼拜就好了。第二次违规,对微博账号进行警告并禁言30天。第三次违规:对微博账号严重警告、取消认证并禁言30天。

  • 祝福语句句暖心女朋友(给女朋友日常暖心祝福语)

    祝福语句句暖心女朋友?以下内容希望对你有帮助!风飞扬,落叶黄,天气凉凉凉;工作累,心疲惫,日子忙忙忙;朋友情,遥相寄,思念长长长。天凉加衣裳,身体多保养,心情要开朗,愿你幸福强强强。缘分不浅,祝福更深:朋友,深秋时节,记得添衣,好好照顾自己。相识的缘分最珍贵,思念的心情最美丽,牵挂的心动最真挚,问候的声音最动听。漫漫人生路,我将所有祝福送给你,希望你快乐!

  • 四喜丸子是不是就是肉圆子(四喜丸子是哪四喜)

    自然界自产生了人类,就有了饮食之需。从原始人类采摘野果、茹毛饮血开始,到人们逐渐学会烧烤烹煮、种植粮食,在漫长的历史演进过程中,人类的食谱不断发生新的变化。中国的饮食文化独树一帜、非常丰富、博大精深,例如中国许多菜名就很有来历和说道,表现了深厚的文化意蕴。

  • 春见粑粑柑功效(春见粑粑柑功效介绍)

    我们一起去了解并探讨一下这个问题吧!耙耙柑富含维生素C与柠檬酸,不仅具有美白作用,还可消除疲劳、促进血液循环、使新陈代谢顺畅,并且对对防止心血管硬化,高血压有一定的作用。耙耙柑味甘酸、性凉,具有顺气、止咳、健胃、化痰、消肿、止痛、疏肝理气等多种功效,是很好的中药材,临床上常用来治疗坏血病、夜盲症、皮肤角化、呕吐胃寒、胸闷胁痛、肋间神经痛、疝气、乳汁不通、睾丸肿痛等病症。

  • 剃刀边缘的主演都有谁(剃刀边缘中最帅的日本人)

    最近在看文章与马伊琍主演的《剃刀边缘》,可能是看多了国产谍战片的缘故,说真的感觉剧情也就一般,虽然感觉剧情老套,但是我却实打实的被一个配角圈粉了。没错就是被这个日本人圈粉了,帅气威武,完完全全就是这部剧的颜值担当。实际上他是一个中国演员扮演的,名字叫做芦芳生。和张若昀合作电视剧《黑狐》中,芦芳生饰演一个日本人松本弥二。看到他在《剃刀边缘》的这个迷人的眼神杀,瞬间吸引了我!

  • 开公司好还是个体户好(北京注册公司)

    开公司好还是个体户好云翼(北京)企业管理有限公司,致力于广大中小企业的工商、税务、商标等一站式服务,十多年的财税与企业服务经验,工商局批准经营工商代理,财政局备案代理记账机构,国家商标局备案代理单位,社保代理专业机构,为企业从公司注册创建,注册营业执照、到财税处理咨询,企业管理经营,再到产品商标注册、知识产权维护,我们全程为您服务一条龙服务。

  • bj60为什么没适时四驱(想要100万以内最舒适的越野SUV)

    想要100万以内最舒适的越野SUV预售首日订单破3000!8月26日,第二十五届成都国际车展开幕,作为2022年度最受关注的车型之一,家玩豪华越野SUV——BJ60在车展预售即火爆23.98万起的预售价比之前网上盛传的25起又低了1万。