肥宅钓鱼网
当前位置: 首页 钓鱼百科

h3c防火墙配置实例(防火墙配置域间策略脚本)

时间:2023-06-29 作者: 小编 阅读量: 3 栏目名: 钓鱼百科

version7.1.064,Release9304P05#sysnameUNIS#contextAdminid1#ipvpn-instancemanagementroute-distinguisher1000000000:1vpn-target1000000000:1import-extcommunityvpn-target1000000000:1export-extcommunity#teln

version 7.1.064, Release 9304P05

#

sysname UNIS

#

context Admin id 1

#

ip vpn-instance management

route-distinguisher 1000000000:1

vpn-target 1000000000:1 import-extcommunity

vpn-target 1000000000:1 export-extcommunity

#

telnet server enable

#

irf mac-address persistent timer

irf auto-update enable

undo irf link-delay

irf member 1 priority 1

#

security-zone intra-zone default permit

#

password-recovery enable

#

vlan 1

#

vlan 49 to 50

#

vlan 70

#

vlan 255

#

object-group ip address DNC服务器

0 network host address 10.100.80.10

#

object-group ip address DNC机床

description DNC机床

0 network subnet 10.100.50.0 255.255.255.0

#

object-group ip address test

#

object-group ip address 机加一分厂触摸屏控制台

0 network host address 10.100.50.193

#

object-group service 123

0 service icmp 0 0

#

object-group service DNC机床-服务器端口策略

0 service icmp 0 0

10 service tcp destination eq 21

20 service tcp destination range 600 1023

30 service udp destination eq 2049

40 service udp destination eq 111

50 service tcp destination eq 2049

60 service tcp destination eq 111

70 service tcp destination eq 19000

80 service udp destination range 8192 8193

90 service tcp destination range 8192 8193

100 service tcp destination eq 502

#

object-group service 机加一分厂触摸屏控制台-服务器

0 service icmp 0 0

10 service tcp destination eq 8889

20 service tcp destination eq 8000

30 service tcp destination eq 1521

#

interface NULL0

#

interface Vlan-interface255

ip address 10.100.255.40 255.255.255.0

#

interface GigabitEthernet1/0/0

port link-mode route

ip binding vpn-instance management

ip address 192.168.0.1 255.255.255.0

#

interface GigabitEthernet1/0/16

port link-mode route

#

interface GigabitEthernet1/0/17

port link-mode route

#

interface GigabitEthernet1/0/18

port link-mode route

#

interface GigabitEthernet1/0/19

port link-mode route

#

interface GigabitEthernet1/0/20

port link-mode route

#

interface GigabitEthernet1/0/21

port link-mode route

#

interface GigabitEthernet1/0/22

port link-mode route

#

interface GigabitEthernet1/0/23

port link-mode route

#

interface GigabitEthernet1/0/1

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/2

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/3

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/4

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/5

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/6

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/7

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/8

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/9

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/10

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/11

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/12

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/13

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/14

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

interface GigabitEthernet1/0/15

port link-mode bridge

port link-type trunk

port trunk permit vlan all

port trunk pvid vlan 255

#

object-policy ip Any-Any

rule 0 pass logging counting

#

object-policy ip Trust-Untrust

rule 0 pass source-ip DNC机床 destination-ip DNC服务器 service DNC机床-服务器端

口策略 logging counting

rule 1 pass source-ip 机加一分厂触摸屏控制台 destination-ip DNC服务器 service

右环殖Тッ量刂铺?服务器 logging counting

#

security-zone name Local

#

security-zone name Trust

import interface GigabitEthernet1/0/8 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/9 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/10 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/11 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/12 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/13 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/14 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/15 vlan 1 49 to 50 70 80 255

#

security-zone name DMZ

#

security-zone name Untrust

import interface Vlan-interface255

import interface GigabitEthernet1/0/1 vlan 1 49 to 50 70 80 255

import interface GigabitEthernet1/0/2 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/3 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/4 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/5 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/6 vlan 1 50 70 80 255

import interface GigabitEthernet1/0/7 vlan 1 50 70 80 255

#

security-zone name Management

import interface GigabitEthernet1/0/0

#

zone-pair security source Any destination Any

object-policy apply ip Any-Any

packet-filter 2000

#

zone-pair security source Trust destination Untrust

object-policy apply ip Trust-Untrust

#

scheduler logfile size 16

#

line class aux

user-role network-operator

#

line class console

user-role network-admin

#

line class vty

user-role network-operator

#

line aux 0

user-role network-admin

#

line con 0

authentication-mode scheme

user-role network-admin

#

line vty 0 4

user-role level-15

user-role network-admin

set authentication password hash $h$6$FXcqr ZUfkzh0xpf$FoUxGIL0XT92tC90K2jVEkPb

95M33o675GIBswGHmY1iFfkmEoA/5m37Bn8aOnghK8bXPJZRbEd6P9VLjopCdg==

protocol inbound telnet

#

line vty 5 63

authentication-mode scheme

user-role network-admin

#

ip route-static 0.0.0.0 0 10.100.255.254

#

info-center logbuffer size 1024

#

ssh server enable

#

acl basic 2000

rule 0 permit

rule 0 permit

#

domain system

#

aaa session-limit ftp 16

aaa session-limit telnet 16

aaa session-limit ssh 16

domain default enable system

#

role name level-0

description Predefined level-0 role

#

role name level-1

description Predefined level-1 role

#

role name level-2

description Predefined level-2 role

#

role name level-3

description Predefined level-3 role

#

role name level-4

description Predefined level-4 role

#

role name level-5

description Predefined level-5 role

#

role name level-6

description Predefined level-6 role

#

role name level-7

description Predefined level-7 role

#

role name level-8

description Predefined level-8 role

#

role name level-9

description Predefined level-9 role

#

role name level-10

description Predefined level-10 role

#

role name level-11

description Predefined level-11 role

#

role name level-12

description Predefined level-12 role

#

role name level-13

description Predefined level-13 role

#

role name level-14

description Predefined level-14 role

#

user-group system

#

local-user admin class manage

password hash $h$6$9R/xrcOboMeyKx5C$0bPaw7Q41dLHQp2X8AAdmTLTU8RGFVplQmWdU7VZG95

n 3Dh2SQlKUn nIIVZflQSgIhMWZzVFEqlXFMeecodQ==

service-type ssh terminal https

authorization-attribute user-role level-3

authorization-attribute user-role network-admin

authorization-attribute user-role network-operator

#

local-user h3c class manage

service-type https

authorization-attribute user-role level-3

authorization-attribute user-role network-admin

authorization-attribute user-role network-operator

#

local-user i class manage

authorization-attribute user-role network-operator

#

ip https enable

#

ips policy default

#

anti-virus policy default

#

return

    推荐阅读
  • 伤感的句子说说心情2021 伤感的句子说说心情2022

    1、我笑的如此做作,却没有人能读懂。那一抹,泪带走了,好空,好空。 2、就怕突然出现一个,什么都比我好的女孩,跟你聊天你们聊的很嗨,最后你说对不起,我说没关系。 3、心情不好的时候,我只想一个人安安安静的待着。 4

  • 电脑版本低怎么升级到win7(教你怎么轻松安装)

    电脑版本低怎么升级到win7?开始安装win7系统:下载完适合自己电脑的系统之后,就可以开始安装了,推荐给大家的Ghost版本的系统十分方便安装,点击一键安装就可以了。

  • 炉石传说卡包规则(炉石传说官方插件上线)

    网易这次下了大功夫来制作这个插件,可见是要想暴雪证明自己的实力,也可能暗示暴雪尽快推出这些功能。从之前的每年都有的炉石大数据看来,网易在公布数据这方面比暴雪显然是用心的多。特别是这次还原度如此高的录像功能,能为炉石传说这个游戏带来更便利的游戏体验。

  • 适合新手养的超可爱的小仓鼠(萌仓鼠的养成可以如此简单)

    萌仓鼠的养成可以如此简单最近有一些朋友问小编仓鼠是怎么养的如此肉肉,可爱的,小编今天就来写一下仓鼠的养成仓鼠对温度很是敏感,所以最适宜温度20-28℃,夏季最好不开空调,因为空调的开和关会使温差过大,容易感冒,冬天放在室外仓。

  • 如新集团创新产品(践行可持续发展理念)

    宁怀恩表示,如新已处于领先地位。截至目前,已捐赠爱心厨房63套,受益儿童超过12,000人。持续深耕中国市场是如新的长期发展战略自2020年新冠肺炎疫情发生以来,全球经济发展及国际形势面临着巨大的挑战。疫情期间,如新通过各地协同的生产和调配,积极推进线上业务,布局数字化转型,保证了市场供应和消费者的需求,为消费者带来不一样的消费体验,从而推动市场的消费需求。截至目前,如新集团已在中国建成5大生产基地和一个研发中心。

  • 电磁炉出现e1如何修理(进来看看)

    下面希望有你要的答案,我们一起来看看吧!电磁炉出现e1如何修理电磁炉出现E1的修理方法:先更换锅具,如果仍然不行,检查内部线路是否有东西干扰内部硬件的运行。如果内部硬件设施没有问题,而且锅具都符合标准,那就将电磁炉返回厂家修理,不要擅自改装或擅自拆分。“E0内部线路故障E1无锅具或锅具不适用于电磁炉E2IGBT功率管过热保护E3过载保护E4欠压保护E5传感器开路E6炉面温度过热保护。

  • 辣根是什么 辣根是什么东西

    由于它的价格比较便宜,因此我们食用比较便宜的芥末里面,都会含有辣根成分。辣根是什么1、辣根是一种作为配料的食材,在我国种植的并不是很多。因为中国人爱吃辣,都是以放辣椒为主,所以辣根在中国菜中并不多见。由于辣根比较便宜,所以是许多日料店代替山葵的调料品。不过由于它比辛辣,不适合肠胃比较敏感的人群大量食用,所以食用含辣根配料的时候最好不要放太多。

  • 雪拼音怎么拼写(雪拼音是什么)

    跟着小编一起来看一看吧!雪拼音怎么拼写雪拼音:[xuě]雪是汉语常用字,初文见于商代甲骨文。雪的古字形由表示落下的“雨”和羽毛状的雪花组成,本义指天空中飘落的白色结晶体,是天空中的水蒸气冷至摄氏零度以下凝结而成的。因雪的颜色是白色的,所以“雪”字又可引申为:雪白、雪糕、雪亮。雪可以化为水,有清洗作用,所以“雪”字有除尘、洗刷的意思,如:雪耻、雪冤、昭雪。

  • 女人多少岁绝经是正常的 女人多少岁绝经是正常的呢

    所以,绝经后的女性患心脑血管疾病的几率会增加。长期坚持使用黑豆打豆浆喝,是非常安全的补充植物性雌激素,对子宫和卵巢保养有很好的疗效。

  • 保温杯需要多久换一次(保温杯多长时间换一次?)

    下面更多详细答案一起来看看吧!保温杯需要多久换一次保温杯的没有固定更换时间,根据使用情况,保温杯不再保温时需要及时更换即可。保温杯的保养方法:在使用过程中要避免碰撞和冲击,以免碰坏杯体或塑料,造成保温失效或漏水。拧紧螺塞时用力要适当,不要过力旋转,以免螺扣失效。经常饮用咖啡、茶或饮料时,内胆会变色这是正常现象,用牙膏牙刷即可清除。