肥宅钓鱼网
当前位置: 首页 钓鱼百科

h3c防火墙配置实例(防火墙配置域间策略脚本)

时间:2023-06-29 作者: 小编 阅读量: 1 栏目名: 钓鱼百科

version7.1.064,Release9304P05#sysnameUNIS#contextAdminid1#ipvpn-instancemanagementroute-distinguisher1000000000:1vpn-target1000000000:1import-extcommunityvpn-target1000000000:1export-extcommunity#teln

version 7.1.064, Release 9304P05

#

sysname UNIS

#

context Admin id 1

#

ip vpn-instance management

route-distinguisher 1000000000:1

vpn-target 1000000000:1 import-extcommunity

vpn-target 1000000000:1 export-extcommunity

#

telnet server enable

#

irf mac-address persistent timer

irf auto-update enable

undo irf link-delay

irf member 1 priority 1

#

security-zone intra-zone default permit

#

password-recovery enable

#

vlan 1

#

vlan 49 to 50

#

vlan 70

#

vlan 255

#

object-group ip address DNC服务器

0 network host address 10.100.80.10

#

object-group ip address DNC机床

description DNC机床

0 network subnet 10.100.50.0 255.255.255.0

#

object-group ip address test

#

object-group ip address 机加一分厂触摸屏控制台

0 network host address 10.100.50.193

#

object-group service 123

0 service icmp 0 0

#

object-group service DNC机床-服务器端口策略

0 service icmp 0 0

10 service tcp destination eq 21

20 service tcp destination range 600 1023

30 service udp destination eq 2049

40 service udp destination eq 111

50 service tcp destination eq 2049

60 service tcp destination eq 111

70 service tcp destination eq 19000

80 service udp destination range 8192 8193

90 service tcp destination range 8192 8193

100 service tcp destination eq 502

#

object-group service 机加一分厂触摸屏控制台-服务器

0 service icmp 0 0

10 service tcp destination eq 8889

20 service tcp destination eq 8000

30 service tcp destination eq 1521

#

interface NULL0

#

interface Vlan-interface255

ip address 10.100.255.40 255.255.255.0

#

interface GigabitEthernet1/0/0

port link-mode route

ip binding vpn-instance management

ip address 192.168.0.1 255.255.255.0

#

interface GigabitEthernet1/0/16

port link-mode route

#

interface GigabitEthernet1/0/17

port link-mode route

#

interface GigabitEthernet1/0/18

port link-mode route

#

interface GigabitEthernet1/0/19

port link-mode route

#

interface GigabitEthernet1/0/20

port link-mode route

#

interface GigabitEthernet1/0/21

port link-mode route

#

interface GigabitEthernet1/0/22

port link-mode route

#

interface GigabitEthernet1/0/23

port link-mode route

#

interface GigabitEthernet1/0/1

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/2

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/3

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/4

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/5

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/6

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/7

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/8

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/9

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/10

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/11

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/12

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/13

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/14

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/15

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

object-policy ip Any-Any

rule 0 pass logging counting

#

object-policy ip Trust-Untrust

rule 0 pass source-ip DNC机床 destination-ip DNC服务器 service DNC机床-服务器端

口策略 logging counting

rule 1 pass source-ip 机加一分厂触摸屏控制台 destination-ip DNC服务器 service

右环殖Тッ量刂铺?服务器 logging counting

#

security-zone name Local

#

security-zone name Trust

import interface GigabitEthernet1/0/8 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/9 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/10 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/11 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/12 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/13 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/14 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/15 vlan 1 49 to 50 70 80 255

#

security-zone name DMZ

#

security-zone name Untrust

import interface Vlan-interface255

import interface GigabitEthernet1/0/1 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/2 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/3 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/4 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/5 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/6 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/7 vlan 1 50 70 80 255

#

security-zone name Management

import interface GigabitEthernet1/0/0

#

zone-pair security source Any destination Any

object-policy apply ip Any-Any

packet-filter 2000

#

zone-pair security source Trust destination Untrust

object-policy apply ip Trust-Untrust

#

scheduler logfile size 16

#

line class aux

user-role network-operator

#

line class console

user-role network-admin

#

line class vty

user-role network-operator

#

line aux 0

user-role network-admin

#

line con 0

authentication-mode scheme

user-role network-admin

#

line vty 0 4

user-role level-15

user-role network-admin

set authentication password hash $h$6$FXcqr ZUfkzh0xpf$FoUxGIL0XT92tC90K2jVEkPb

95M33o675GIBswGHmY1iFfkmEoA/5m37Bn8aOnghK8bXPJZRbEd6P9VLjopCdg==

protocol inbound telnet

#

line vty 5 63

authentication-mode scheme

user-role network-admin

#

ip route-static 0.0.0.0 0 10.100.255.254

#

info-center logbuffer size 1024

#

ssh server enable

#

acl basic 2000

rule 0 permit

rule 0 permit

#

domain system

#

aaa session-limit ftp 16

aaa session-limit telnet 16

aaa session-limit ssh 16

domain default enable system

#

role name level-0

description Predefined level-0 role

#

role name level-1

description Predefined level-1 role

#

role name level-2

description Predefined level-2 role

#

role name level-3

description Predefined level-3 role

#

role name level-4

description Predefined level-4 role

#

role name level-5

description Predefined level-5 role

#

role name level-6

description Predefined level-6 role

#

role name level-7

description Predefined level-7 role

#

role name level-8

description Predefined level-8 role

#

role name level-9

description Predefined level-9 role

#

role name level-10

description Predefined level-10 role

#

role name level-11

description Predefined level-11 role

#

role name level-12

description Predefined level-12 role

#

role name level-13

description Predefined level-13 role

#

role name level-14

description Predefined level-14 role

#

user-group system

#

local-user admin class manage

password hash $h$6$9R/xrcOboMeyKx5C$0bPaw7Q41dLHQp2X8AAdmTLTU8RGFVplQmWdU7VZG95

n 3Dh2SQlKUn nIIVZflQSgIhMWZzVFEqlXFMeecodQ==

service-type ssh terminal https

authorization-attribute user-role level-3

authorization-attribute user-role network-admin

authorization-attribute user-role network-operator

#

local-user h3c class manage

service-type https

authorization-attribute user-role level-3

authorization-attribute user-role network-admin

authorization-attribute user-role network-operator

#

local-user i class manage

authorization-attribute user-role network-operator

#

ip https enable

#

ips policy default

#

anti-virus policy default

#

return

    推荐阅读
  • 千里茶道(万里茶道香飘依旧)

    2015年,国际茶叶委员会命名赤壁市为“万里茶道源头”城市,羊楼洞则被授名为“世界茶业第一古镇”。今年开年,一场突如其来的新冠肺炎疫情打乱了千百年的传承。茶厂停工、茶庄歇业、出口订单取消,给当地茶企造成了很大损失。作为一家出口企业,乾泰恒兄弟茶业近两年已经打通了俄罗斯市场的通道。曹勇告诉记者,即使在俄罗斯疫情期间,砖茶作为健康饮品,依然在超市里正常销售。2019年10月,第七届世界军运会在武汉举办。

  • 澳洲国宝鸸鹋蛋(300元5000元这不是普通的鸸鹋蛋)

    位于昌吉市二六工镇的新基鸸鹋养殖有限公司于2008年开始饲养鸸鹋以来,经过十几年的发展,鸸鹋数量已达180余只。同时,该公司还研发出了鸸鹋精油、手霜、面膜等多种产品,在新疆、广东等地进行销售。近年来,昌吉市二六工镇利用辖区资源优势,把特色养殖与旅游相结合,促进农民持续增收。每枚鸸鹋蛋售价在300元左右,但经过雕刻成工艺品后售价直接上升到5000元以上天山网记者李瑞摄4月24日,游客在鸸鹋投喂饲料。

  • 怎么锻炼可以减肚子(肚子为什么会大)

    怎么锻炼可以减肚子?下面内容希望能帮助到你,我们来一起看看吧!饮食及锻炼两方面同时去做,会快速达到一个比较有效的效果。长期缺少锻炼,久坐,暴饮暴食都会引起腹部脂肪过多,引起肥胖,这些都是生理性的因素,都是可以通过调整好生活作息,饮食习惯慢慢的改善的。

  • 束花石斛的养殖方法及注意事项(束花石斛的养殖方法及注意事项有哪些)

    以下内容大家不妨参考一二希望能帮到您!束花石斛的养殖方法及注意事项束花石斛需将其养殖在透气排水性良好的土壤,还要给足阳光需求,平时每隔2~3天浇一次水,每隔半个月施一次液肥,还可以进行扦插法繁殖束花石斛。每当冬季时需将温度控制在5℃以上,夏季还要做好病虫防治,避免降低其观赏价值。

  • 辐射低的手机品牌(辐射水平最高的10款智能手机)

    排在第五和第六位的是GooglePixel3XL和GooglePixel4a。智能手机辐射是已被确定与癌症有关的罪魁祸首之一。由于癌症病例占优势,现在对其病原体进行了取缔。值得注意的是,许多国家都对SAR水平进行了密切监测,甚至存在辐射不能超过标准的水平。这是因为手机会发射射频波,而目前所有的智能手机都会发射电磁波频谱内的射频波。最新的5G智能手机发射高达约80GHz的射频波。射频辐射的高癌症风险是由于不能改变DNA的低能量。

  • 牛杂怎么煮(牛杂怎么煮好吃)

    牛杂怎么煮材料:鲜牛骨、牛杂、辣椒油、酱油各150克,花椒面25克,八角4克,味精、花椒、肉桂各5克,精盐125克,白酒50克。将牛骨、牛杂洗净。加入味精、辣椒油、酱油、花椒面调成味汁。将晾凉的牛杂分别切成4厘米长、2厘米宽、0.2厘米厚的片,混合在一起,淋入汤汁

  • 降血脂的野菜(它是天然的血管清道夫)

    岳宏北京市营养源研究所副研究员为你找到食物里的养生秘诀“咬”住健康好啦,咱们话不多说一起来看今天的主角来源:CCTV生活圈

  • 微信怎么保存视频(微信存放视频的教程)

    微信怎么保存视频?打开视频播放,等待缓存完,之后长按视频,点击,下面我们就来聊聊关于微信怎么保存视频?接下来我们就一起去了解一下吧!执行MicroMsg/最长后缀名称文件夹/video,找到视频文件。复制视频文件,粘贴到目标文件夹即可。

  • 魔兽世界装备分解错了怎么找回(装备误删自助找回冷却时间由90天下调至7天)

    我经历过,很绝望。在官网有一个装备恢复的系统,可以让你把你已经销毁的装备找回,而这个系统有着90天的冷却,每90天只能使用一次。如图,这是我最近失去的装备,我可以直接选择恢复哪一件。值得一提的是:1.一次只能找回最多3件装备。

  • 大便不成形是什么造成的(大便不成型是因为什么)

    大便不成型可能导致大量水分丧失,使人体处于脱水状态,导致血容量减少,血液粘稠度增加,血流缓慢,容易形成血栓并堵塞血管。当然,肠炎也不排除于滥用药物、病毒感染等。中医认为,大便不成形属于“濡泄”范畴,其本质原因是脾虚湿盛,其中脾虚为本,湿盛为标。脾虚又分为脾气虚和脾阳虚两种,其均能引起运化失常,而致便溏濡泄。据此,一旦发生大便不成型应引起重视,就要及时看医生,服用药物调治。