肥宅钓鱼网
当前位置: 首页 钓鱼百科

h3c防火墙配置实例(防火墙配置域间策略脚本)

时间:2023-06-29 作者: 小编 阅读量: 1 栏目名: 钓鱼百科

version7.1.064,Release9304P05#sysnameUNIS#contextAdminid1#ipvpn-instancemanagementroute-distinguisher1000000000:1vpn-target1000000000:1import-extcommunityvpn-target1000000000:1export-extcommunity#teln

version 7.1.064, Release 9304P05

#

sysname UNIS

#

context Admin id 1

#

ip vpn-instance management

route-distinguisher 1000000000:1

vpn-target 1000000000:1 import-extcommunity

vpn-target 1000000000:1 export-extcommunity

#

telnet server enable

#

irf mac-address persistent timer

irf auto-update enable

undo irf link-delay

irf member 1 priority 1

#

security-zone intra-zone default permit

#

password-recovery enable

#

vlan 1

#

vlan 49 to 50

#

vlan 70

#

vlan 255

#

object-group ip address DNC服务器

0 network host address 10.100.80.10

#

object-group ip address DNC机床

description DNC机床

0 network subnet 10.100.50.0 255.255.255.0

#

object-group ip address test

#

object-group ip address 机加一分厂触摸屏控制台

0 network host address 10.100.50.193

#

object-group service 123

0 service icmp 0 0

#

object-group service DNC机床-服务器端口策略

0 service icmp 0 0

10 service tcp destination eq 21

20 service tcp destination range 600 1023

30 service udp destination eq 2049

40 service udp destination eq 111

50 service tcp destination eq 2049

60 service tcp destination eq 111

70 service tcp destination eq 19000

80 service udp destination range 8192 8193

90 service tcp destination range 8192 8193

100 service tcp destination eq 502

#

object-group service 机加一分厂触摸屏控制台-服务器

0 service icmp 0 0

10 service tcp destination eq 8889

20 service tcp destination eq 8000

30 service tcp destination eq 1521

#

interface NULL0

#

interface Vlan-interface255

ip address 10.100.255.40 255.255.255.0

#

interface GigabitEthernet1/0/0

port link-mode route

ip binding vpn-instance management

ip address 192.168.0.1 255.255.255.0

#

interface GigabitEthernet1/0/16

port link-mode route

#

interface GigabitEthernet1/0/17

port link-mode route

#

interface GigabitEthernet1/0/18

port link-mode route

#

interface GigabitEthernet1/0/19

port link-mode route

#

interface GigabitEthernet1/0/20

port link-mode route

#

interface GigabitEthernet1/0/21

port link-mode route

#

interface GigabitEthernet1/0/22

port link-mode route

#

interface GigabitEthernet1/0/23

port link-mode route

#

interface GigabitEthernet1/0/1

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/2

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/3

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/4

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/5

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/6

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/7

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/8

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/9

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/10

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/11

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/12

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/13

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/14

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/15

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

object-policy ip Any-Any

rule 0 pass logging counting

#

object-policy ip Trust-Untrust

rule 0 pass source-ip DNC机床 destination-ip DNC服务器 service DNC机床-服务器端

口策略 logging counting

rule 1 pass source-ip 机加一分厂触摸屏控制台 destination-ip DNC服务器 service

右环殖Тッ量刂铺?服务器 logging counting

#

security-zone name Local

#

security-zone name Trust

import interface GigabitEthernet1/0/8 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/9 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/10 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/11 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/12 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/13 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/14 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/15 vlan 1 49 to 50 70 80 255

#

security-zone name DMZ

#

security-zone name Untrust

import interface Vlan-interface255

import interface GigabitEthernet1/0/1 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/2 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/3 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/4 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/5 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/6 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/7 vlan 1 50 70 80 255

#

security-zone name Management

import interface GigabitEthernet1/0/0

#

zone-pair security source Any destination Any

object-policy apply ip Any-Any

packet-filter 2000

#

zone-pair security source Trust destination Untrust

object-policy apply ip Trust-Untrust

#

scheduler logfile size 16

#

line class aux

user-role network-operator

#

line class console

user-role network-admin

#

line class vty

user-role network-operator

#

line aux 0

user-role network-admin

#

line con 0

authentication-mode scheme

user-role network-admin

#

line vty 0 4

user-role level-15

user-role network-admin

set authentication password hash $h$6$FXcqr ZUfkzh0xpf$FoUxGIL0XT92tC90K2jVEkPb

95M33o675GIBswGHmY1iFfkmEoA/5m37Bn8aOnghK8bXPJZRbEd6P9VLjopCdg==

protocol inbound telnet

#

line vty 5 63

authentication-mode scheme

user-role network-admin

#

ip route-static 0.0.0.0 0 10.100.255.254

#

info-center logbuffer size 1024

#

ssh server enable

#

acl basic 2000

rule 0 permit

rule 0 permit

#

domain system

#

aaa session-limit ftp 16

aaa session-limit telnet 16

aaa session-limit ssh 16

domain default enable system

#

role name level-0

description Predefined level-0 role

#

role name level-1

description Predefined level-1 role

#

role name level-2

description Predefined level-2 role

#

role name level-3

description Predefined level-3 role

#

role name level-4

description Predefined level-4 role

#

role name level-5

description Predefined level-5 role

#

role name level-6

description Predefined level-6 role

#

role name level-7

description Predefined level-7 role

#

role name level-8

description Predefined level-8 role

#

role name level-9

description Predefined level-9 role

#

role name level-10

description Predefined level-10 role

#

role name level-11

description Predefined level-11 role

#

role name level-12

description Predefined level-12 role

#

role name level-13

description Predefined level-13 role

#

role name level-14

description Predefined level-14 role

#

user-group system

#

local-user admin class manage

password hash $h$6$9R/xrcOboMeyKx5C$0bPaw7Q41dLHQp2X8AAdmTLTU8RGFVplQmWdU7VZG95

n 3Dh2SQlKUn nIIVZflQSgIhMWZzVFEqlXFMeecodQ==

service-type ssh terminal https

authorization-attribute user-role level-3

authorization-attribute user-role network-admin

authorization-attribute user-role network-operator

#

local-user h3c class manage

service-type https

authorization-attribute user-role level-3

authorization-attribute user-role network-admin

authorization-attribute user-role network-operator

#

local-user i class manage

authorization-attribute user-role network-operator

#

ip https enable

#

ips policy default

#

anti-virus policy default

#

return

    推荐阅读
  • 孕妇梦见摘豆角是什么意思(孕妇梦见摘豆角梦境解析)

    下面更多详细答案一起来看看吧!孕妇梦见摘豆角是什么意思做生意的孕妇梦见摘豆角,代表守旧不变动为佳,有财利、宜薄利多销。出行的孕妇梦见摘豆角,遇风雨延期出发,注意防寒。恋爱中的孕妇梦见摘豆角,说明速战速决,马上行动可成。本命年的孕妇梦见摘豆角,意味着多施舍,只问耘耘不问收获,则平安无事。

  • 苹果手机没有声音是怎么回事(苹果手机没有声音是什么原因)

    下面内容希望能帮助到你,我们来一起看看吧!苹果手机没有声音是怎么回事查看手机左侧是否将“静音键”开启。点击“取消静音”。也可点击“设置”选择“勿扰模式”,看是否开启了勿扰模式;也有可能是手机进入耳机模式还未恢复,稍等几秒即可。

  • 电话卡暂停服务怎么回事 新买的电话卡暂停服务怎么回事

    2、在加油站或者加气站这样的地方一定要避免使用手机,因为手机发出的电磁波有可能引起静电,继而引发火灾。

  • 雪里红菜的功效与作用(雪里红菜的功效与作用有哪些)

    雪里红菜的功效与作用?下面内容希望能帮助到你,我们来一起看看吧!雪里红菜的功效与作用雪里红菜的功效与作用:解毒消肿,开胃消食,温中利气。主治疮痈肿痛,胸隔满闷,咳嗽痰多,耳目失聪,牙龈肿烂,便秘等病症。雪里红在中国北方地区,到了秋冬季节叶子会变为紫红色故名“雪里红”。在中国南方地区,因为很少见到变为紫红色的“雪里红”,所以也被误传为“雪里蕻”。常被用作腌菜食用。

  • 绝地求生竞技模式有多少名队伍(规定不能超过三个字母)

    大家好,这里是cc聊游戏。国外资料网站Liquidpedia主编hesketh2在个人推特上透露,受绝地求生全球统一赛事规则的影响,多支战队的赛事简称都发生了变化。规则中称“全球所有赛区参赛队伍简称不得超过三个字母”,因此像FaZe、Navi、ENCE、Liquid等赛事简称或将不复存在。留心FGS巅峰联赛的观众会有所察觉,欧洲冠军ENCE已经将自己的简称改为EZ4、Liquid的简称变为TL。而在目前进行的PEL联赛Kick-Off杯上,FaZe的战队简称变成了FC,Navi的简称变成了NV

  • 秋天来了苹果丰收了(京城校园秋收忙)

    近日,丰台区外国语学校举办了第一届“丰收节”活动,二年级的学生们迎来了人生中第一场“大丰收”。一小时的“丰收节”在老师、学生和家长们的欢声笑语、加油鼓劲中落下帷幕。热气腾腾的南瓜汤和香甜可口的玉米、地瓜将本次“丰收节”推向高潮。9月23日,北京市怀柔区宝山镇中心小学、宝山镇中心幼儿园联合举行第二届“喜迎二十大情系丰收节”庆祝活动。

  • 去张家界先玩哪里比较好一点呢(第一次去张家界怎么玩)

    张家界是湖南省地级市,位于湖南西北部,属武陵山区腹地。因旅游建市,是中国最重要的旅游城市之一。武陵源风景名胜区,是张家界的核心景区,是世界自然遗产,国家首批世界地质公园,首批国家5A级旅游景区。百龙天梯不仅是通往张家界核心景区的最佳途径,更是最具代表性的人造奇观,目前以“世界最高户外观光电梯”荣誉而被载入吉尼斯世界纪录。这“千年神秘,一台大戏”的帷幕,渐渐拉开。雨停了,表演也接近尾声。

  • 光阳赛艇s350大灯怎么关 光阳赛艇s350大灯怎么关不了

    光阳赛艇s350将灯光按钮旋转到OFF位置即可关闭,ON是打开灯光,OFF是关闭。光阳赛艇s350保留了车头的鸟嘴设计,并且手把护弓也有可能标配,这就给想玩跨界风的车友,创造了一个好底子。摩托车,由汽油机驱动,靠手把操纵前轮转向的两轮或三轮车,轻便灵活,行驶迅速,广泛用于巡逻、客货运输等,也用作体育运动器械。装有内燃发动机。有两轮和三轮摩托车。

  • 善终对一个人来说是多大的幸运(生命的最后时刻)

    在她的强烈要求下,手术最终被放弃,回到家中自行疗养。临终并不仅是徒然等待死亡的到来,而是为临终者给予身心上的支持。柴田久美子在日本发起的“善终守护师”协会,主要依赖志愿者协助,并依靠部分政策提供的临终关怀补助。目前来说,国内的安宁疗护主要划分为四种模式:综合医院临终病房模式、宁养院模式、社区医院模式和家庭病床模式。柴田久美子女士正是因为父亲的离世,种下了让老人幸福善终的理想。

  • 如何把iphone上的短信转到平板上(短信即时同步到iPad)

    如何让让iPhone上收到的短信,即时同步到iPad、Mac上?iPhone通过过信息转寄功能,让你从此以后要输入短信验证码时,再也不用掏手机查看,直接在iPad、Mac上就看得到。首先要确定手边的所有装置都是以相同的iOS、iPadOS检查iMessage账号:Mac检查iMessage账号:iPhone设置开启信息转寄功能确认没问题后,就可以在iPhone上开启讯息转寄功能。信息转寄设置完成后,只要iPhone已开机且连线至Wi-Fi或行动网络,即可在iPad、Mac上即时接收和传送短信。