如果您无法下载资料,请参考说明:
1、部分资料下载需要金币,请确保您的账户上有足够的金币
2、已购买过的文档,再次下载不重复扣费
3、资料包下载后请先用软件解压,在使用对应软件打开
2022H3C防火墙2区域配置案例H3C防火墙2区域配置案例基于多年参加电力行业信息化的阅历,H3C公司推出电力信息网络平安加固解决方案,该解决方案主要由对终端平安防护和平安管理中心等关键部件组成。那么H3C防火墙2区域是怎么配置的呢?下面跟yjbys我一起来看看!1、配置要求1)防火墙的E0/2接口为TRUST区域,ip地址是:192.168.254.1/29;2)防火墙的E1/2接口为UNTRUST区域,ip地址是:202.111.0.1/27;3)内网服务器对外网做一对一的地址映射,192.168.254.2、192.168.254.3分别映射为202.111.0.2、202.111.0.3;4)内网服务器访问外网不做限制,外网访问内网只放通公网地址211.101.5.49访问192.168.254.2的`1433端口和192.168.254.3的80端口。2、防火墙的配置脚本如下discur#sysnameH3CF100A#superpasswordlevel3cipher6aQ>Q57-$.I)0;4:\(I41!!!#firewallpacket-filterenablefirewallpacket-filterdefaultpermit#insulate#natstaticinsideip192.168.254.2globalip202.111.0.2natstaticinsideip192.168.254.3globalip202.111.0.3#firewallstatisticsystemenable#radiusschemesystemserver-typeextended#domainsystem#local-usernet1980passwordcipher######service-typetelnetlevel2#aspf-policy1detecth323detectsqlnetdetectrtspdetecthttpdetectsmtpdetectftpdetecttcpdetectudp#objectaddress192.168.254.2/32192.168.254.2255.255.255.255objectaddress192.168.254.3/32192.168.254.3255.255.255.255#aclnumber3001descriptionout-insiderule1permittcpsource211.101.5.490destination192.168.254.20destination-porteq1433rule2permittcpsource211.101.5.490destination192.168.254.30destination-porteqwwwrule1000denyipaclnumber3002descriptioninside-to-outsiderule1permitipsource192.168.254.20rule2permitipsource192.168.254.30rule1000denyip#interfaceAux0asyncmodeflow#interfaceEthernet0/0shutdown#interfaceEthernet0/1shutdown#interfaceEthernet0/2speed100duplexfulldescriptiontoserveripaddress192.168.254.1255.255.255.248firewallpacket-filter3002inboundfirewallaspf1outbound#interfaceEthernet0/3shutdown#interfaceEthernet1/0shutdown#interfaceEthernet1/1shutdown#interfaceEthernet1/2speed100duplexfulldescriptiontointernetipaddress202.111.0.1255.255.255.224firewallpacket-filter3001inboundfirewallaspf1outboundnatoutboundstatic#interfaceNULL0#firewallzonelocalsetpriority100#firewallzonetrustaddinterfaceEthernet0/2setpriority85#firewallzon
努力****妙风
实名认证
内容提供者
最近下载