肥宅钓鱼网
当前位置: 首页 钓鱼百科

h3c防火墙配置实例(防火墙配置域间策略脚本)

时间:2023-06-29 作者: 小编 阅读量: 1 栏目名: 钓鱼百科

version7.1.064,Release9304P05#sysnameUNIS#contextAdminid1#ipvpn-instancemanagementroute-distinguisher1000000000:1vpn-target1000000000:1import-extcommunityvpn-target1000000000:1export-extcommunity#teln

version 7.1.064, Release 9304P05

#

sysname UNIS

#

context Admin id 1

#

ip vpn-instance management

route-distinguisher 1000000000:1

vpn-target 1000000000:1 import-extcommunity

vpn-target 1000000000:1 export-extcommunity

#

telnet server enable

#

irf mac-address persistent timer

irf auto-update enable

undo irf link-delay

irf member 1 priority 1

#

security-zone intra-zone default permit

#

password-recovery enable

#

vlan 1

#

vlan 49 to 50

#

vlan 70

#

vlan 255

#

object-group ip address DNC服务器

0 network host address 10.100.80.10

#

object-group ip address DNC机床

description DNC机床

0 network subnet 10.100.50.0 255.255.255.0

#

object-group ip address test

#

object-group ip address 机加一分厂触摸屏控制台

0 network host address 10.100.50.193

#

object-group service 123

0 service icmp 0 0

#

object-group service DNC机床-服务器端口策略

0 service icmp 0 0

10 service tcp destination eq 21

20 service tcp destination range 600 1023

30 service udp destination eq 2049

40 service udp destination eq 111

50 service tcp destination eq 2049

60 service tcp destination eq 111

70 service tcp destination eq 19000

80 service udp destination range 8192 8193

90 service tcp destination range 8192 8193

100 service tcp destination eq 502

#

object-group service 机加一分厂触摸屏控制台-服务器

0 service icmp 0 0

10 service tcp destination eq 8889

20 service tcp destination eq 8000

30 service tcp destination eq 1521

#

interface NULL0

#

interface Vlan-interface255

ip address 10.100.255.40 255.255.255.0

#

interface GigabitEthernet1/0/0

port link-mode route

ip binding vpn-instance management

ip address 192.168.0.1 255.255.255.0

#

interface GigabitEthernet1/0/16

port link-mode route

#

interface GigabitEthernet1/0/17

port link-mode route

#

interface GigabitEthernet1/0/18

port link-mode route

#

interface GigabitEthernet1/0/19

port link-mode route

#

interface GigabitEthernet1/0/20

port link-mode route

#

interface GigabitEthernet1/0/21

port link-mode route

#

interface GigabitEthernet1/0/22

port link-mode route

#

interface GigabitEthernet1/0/23

port link-mode route

#

interface GigabitEthernet1/0/1

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/2

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/3

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/4

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/5

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/6

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/7

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/8

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/9

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/10

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/11

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/12

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/13

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/14

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/15

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

object-policy ip Any-Any

rule 0 pass logging counting

#

object-policy ip Trust-Untrust

rule 0 pass source-ip DNC机床 destination-ip DNC服务器 service DNC机床-服务器端

口策略 logging counting

rule 1 pass source-ip 机加一分厂触摸屏控制台 destination-ip DNC服务器 service

右环殖Тッ量刂铺?服务器 logging counting

#

security-zone name Local

#

security-zone name Trust

import interface GigabitEthernet1/0/8 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/9 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/10 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/11 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/12 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/13 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/14 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/15 vlan 1 49 to 50 70 80 255

#

security-zone name DMZ

#

security-zone name Untrust

import interface Vlan-interface255

import interface GigabitEthernet1/0/1 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/2 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/3 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/4 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/5 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/6 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/7 vlan 1 50 70 80 255

#

security-zone name Management

import interface GigabitEthernet1/0/0

#

zone-pair security source Any destination Any

object-policy apply ip Any-Any

packet-filter 2000

#

zone-pair security source Trust destination Untrust

object-policy apply ip Trust-Untrust

#

scheduler logfile size 16

#

line class aux

user-role network-operator

#

line class console

user-role network-admin

#

line class vty

user-role network-operator

#

line aux 0

user-role network-admin

#

line con 0

authentication-mode scheme

user-role network-admin

#

line vty 0 4

user-role level-15

user-role network-admin

set authentication password hash $h$6$FXcqr ZUfkzh0xpf$FoUxGIL0XT92tC90K2jVEkPb

95M33o675GIBswGHmY1iFfkmEoA/5m37Bn8aOnghK8bXPJZRbEd6P9VLjopCdg==

protocol inbound telnet

#

line vty 5 63

authentication-mode scheme

user-role network-admin

#

ip route-static 0.0.0.0 0 10.100.255.254

#

info-center logbuffer size 1024

#

ssh server enable

#

acl basic 2000

rule 0 permit

rule 0 permit

#

domain system

#

aaa session-limit ftp 16

aaa session-limit telnet 16

aaa session-limit ssh 16

domain default enable system

#

role name level-0

description Predefined level-0 role

#

role name level-1

description Predefined level-1 role

#

role name level-2

description Predefined level-2 role

#

role name level-3

description Predefined level-3 role

#

role name level-4

description Predefined level-4 role

#

role name level-5

description Predefined level-5 role

#

role name level-6

description Predefined level-6 role

#

role name level-7

description Predefined level-7 role

#

role name level-8

description Predefined level-8 role

#

role name level-9

description Predefined level-9 role

#

role name level-10

description Predefined level-10 role

#

role name level-11

description Predefined level-11 role

#

role name level-12

description Predefined level-12 role

#

role name level-13

description Predefined level-13 role

#

role name level-14

description Predefined level-14 role

#

user-group system

#

local-user admin class manage

password hash $h$6$9R/xrcOboMeyKx5C$0bPaw7Q41dLHQp2X8AAdmTLTU8RGFVplQmWdU7VZG95

n 3Dh2SQlKUn nIIVZflQSgIhMWZzVFEqlXFMeecodQ==

service-type ssh terminal https

authorization-attribute user-role level-3

authorization-attribute user-role network-admin

authorization-attribute user-role network-operator

#

local-user h3c class manage

service-type https

authorization-attribute user-role level-3

authorization-attribute user-role network-admin

authorization-attribute user-role network-operator

#

local-user i class manage

authorization-attribute user-role network-operator

#

ip https enable

#

ips policy default

#

anti-virus policy default

#

return

    推荐阅读
  • 广州大佛寺在哪里(广州大佛寺的简介)

    以下内容大家不妨参考一二希望能帮到您!广州大佛寺在哪里广州大佛寺坐落于广东省广州市越秀区惠福东路惠新中街21号(北京路西侧、广州百货大楼正南方。大佛寺,始建于南汉,名新藏寺,为南汉王刘龑上应天上二十八宿而建。大佛寺,明代扩建为龙藏寺,后改为巡按公署。清顺治元年公署毁于火。平南王尚可喜于康熙二年春,自捐王俸,仿京师官庙制式,兼具岭南地方风格重建殿宇,具有较高的文化艺术观赏价值。

  • csgo如何成为一个优秀的突破手(高玩们竟靠它在CSGO里呼风唤雨)

    CSGO作为一款团队游戏,队友之间交流沟通、互相配合的重要性不言而喻。反之,信息收集不足,信息收集错误都会直接影响胜负走向。当玩家在游戏中被击杀后的3秒内,仍然可以通过第三人称视角观察自己尸体周围的场景。这些信息可以直接帮助队友做出战术上的针对,从而反败为胜。另外,在处理1V1,1V2等残局时,除了报告一些重要信息,死亡的玩家请尽量不要开麦讲话,以免干扰活着队友的注意力,或者影响他们听脚步声等。

  • 甜宠文男主偏执霸道小说推荐(5本都市甜宠文推荐)

    在男主指点下女主逐渐成长,公司走上正轨,后公司被男主合并。然而女主却没有强大的自信,和男主在一起,中间有波折,结局最终相伴一生。女主和男主妹妹是高中同学,女主高中的时候对男主一见钟情默默暗恋,男主对女主也有好感。一次醉酒两人419了,女主怀孕了。女主不想用这个束缚男主,本来想偷偷打掉孩子,但是没狠下心,最后和男主结婚了。男主传媒业大拿,女主银行业高管,专业有所涉及,后期还有揭露一些社会不好的现象。

  • 板栗和牛肉能一起吃吗(板栗和牛肉为什么不能一起吃)

    板栗和牛肉能一起吃吗栗子和牛肉最好不要一起吃,板栗中富含维生素C,每100克板栗中含有40毫克的维生素C。然而,牛肉中含有的胡萝卜素、B族维生素还有脂肪酸。板栗中的维生素C会与牛肉中的微量元素发生化学反应,从而丢掉了板栗原有的营养价值。而且,食用板栗和牛肉会引起腹胀呕吐不消化的症状。牛肉性温,它具有补脾胃壮腰脚、补中益气的功效;而板栗属于咸而温,具有补肾气、益气厚肠胃的作用。

  • 微信隐私密码忘了应该怎么办答案也忘了怎么办(这里有具体的操作介绍)

    微信隐私密码忘了应该怎么办答案也忘了怎么办?下面希望有你要的答案,我们一起来看看吧!然后在设置页面中,点击。然后会弹出一个小窗口,点击按钮。最后再点击微信右上角的按钮即可。

  • 冰块冷藏的正确方法(关于冰块冷藏的正确方法)

    冰块冷藏的正确方法?以下内容大家不妨参考一二希望能帮到您!冰块冷藏的正确方法只能放在冰箱冷冻层,可以用干净的塑料袋把冰块包裹起来放进去就可以了,也可以把冰块放到塑料保温箱再放到冰柜里,这样更干净些。冰块放置在冰箱里时,一定要与其他生鲜果蔬和鱼肉等食物分开,且这些生鲜果蔬和鱼肉类在放入冰箱时,也应该用食品袋进行包装。只有这样,才能避免冰块受到不必要的污染,或令冰块产生异味。

  • 经常吃生吃胡萝卜有什么好处(经常生吃胡萝卜)

    而胡萝卜确实是一种可以生吃的蔬菜,质地硬口感脆而甜,但不建议大家这样做。生吃胡萝卜虽然能让机体吸收营养物质,但得到完全保留的维生素C含量较少。从中国食物成分表中不难看出,每百克红胡萝卜品种,其维生素C含量为13mg;每百克黄胡萝卜品种,维生素C含量为16mg。然而胡萝卜较为突出的地方,则是在于其中丰富的维生素A以及β-胡萝卜素,它们都是保护眼睛视网膜的重要营养成分。

  • 不锈钢香掉牙千层饼(白鹤亮翅金沙江)

    2021年6月28日,白鹤滩水电站首批机组正式投产发电,金沙江上临空而起的巨闸,让奔涌的江水依照科学规划,转化成强大的电能。当白鹤滩水电站全部机组投产后,每年可节约标准煤约1968万吨,减少排放二氧化碳5160万吨!东方电气集团白鹤滩项目现场调试总指挥赵永智说。转子吊装2021年6月28日,白鹤滩水电站首批机组投产发电,全球单机容量最大功率百万千瓦水轮发电机组,实现了我国高端装备制造的重大突破。

  • 制备固体分散体时应如何选择载体(固体分散剂的制备技术之喷雾干燥法)

    由于这种药物的溶解度偏低,生物利用度偏低,固体分散体技术的应用可以改善难溶于水的药物化合物的性质,改善药物的溶出速率和生物利用度。固体分散体指的是药物以分子、无定形、微晶等状态均匀分散在某一固态载体物质中所形成的分散体系,喷雾干燥是用于制备固体分散剂的一种较为常用的技术。对于制备固体分散体而言,一般是将聚合物和难溶性药物溶于适当的溶剂中,再喷干,使药物以无定型态高度分散在聚合物中。

  • 宝利通Group310拆解(宝利通310详细连接图)

    另外一根绿绿HDMI线是宝利通310设备的输入HDMI线。投影仪一边投文档,电视一边投会议人员。