华为USG2200系列防火墙配置案例

更新时间:2023-05-06 02:28:46 阅读: 评论:0

华为USG2200系列防火墙配置案例
<xagl_USG2200>display cur
12:06:25  2012/06/06
#
sysname xagl_USG2200
#
firewall packet-filter default permit interzone local trust direction inbound
firewall packet-filter default permit interzone local trust direction outbound
firewall packet-filter default permit interzone local untrust direction inbound
firewall packet-filter default permit interzone local untrust direction outboun
d
firewall packet-filter default permit interzone local dmz direction inbound
firewall packet-filter default permit interzone local dmz direction outbound
firewall packet-filter default permit interzone local untrust1 direction inboun
d
firewall packet-filter default permit interzone local untrust1 direction outbou
nd
firewall packet-filter default permit interzone trust untrust direction inbound
firewall packet-filter default permit interzone trust untrust direction outboun
d
firewall packet-filter default permit interzone trust dmz direction inbound
firewall packet-filter default permit interzone trust dmz direction outbound
firewall packet-filter default permit interzone trust untrust1 direction inboun
d
firewall packet-filter default permit interzone trust untrust1 direction outbou
nd
firewall packet-filter default permit interzone dmz untrust direction inbound
firewall packet-filter default permit interzone dmz untrust direction outbound
#
nat address-group 0 124.114.156.211 124.114.156.212
nat address-group 1 113.200.77.235 113.200.77.236
#
firewall ipv6 ssion link-state check
#
firewall ssion link-state check
#
firewall defend ip-sweep enable
firewall defend large-icmp enable
firewall defend syn-flood enable
firewall defend land enable
firewall defend ip-sweep max-rate 1000
firewall defend ip-sweep blacklist-timeout 30
firewall defend large-icmp max-length 3600
firewall defend syn-flood interface Ethernet3/0/0 alert-rate 1000 max-rate 5000
00
firewall defend syn-flood interface GigabitEthernet0/0/0 alert-rate 1000 max-ra
te 500000
#
web-manager enable
#
acl number 2001
rule 1 permit source 192.168.2.100 0
#
interface Cellular0/1/0
link-protocol ppp
#
interface Ethernet3/0/0
description tu liantong
ip address 113.200.77.234 255.255.255.248
#
interface GigabitEthernet0/0/0
description to dianxin
ip address 124.114.156.210 255.255.255.248
#
interface GigabitEthernet0/0/1
description to wangkang's WAN
ip address 192.168.1.3 255.255.255.0
#
interface NULL0
#
firewall zone local
t priority 100
#
firewall zone trust
t priority 85
add interface GigabitEthernet0/0/1
#
firewall zone untrust
t priority 5
add interface GigabitEthernet0/0/0
#
firewall zone dmz
t priority 50
#
firewall zone name untrust1
t priority 6
add interface Ethernet3/0/0
#
aaa
local-ur admin password cipher ]MQ;4\]B+4Z,YWX*NZ55OA!!
local-ur admin rvice-type web terminal
local-ur admin level 3
authentication-scheme default
#
authorization-scheme default
#
accounting-scheme default
#
domain default
domain dot1x
#
#
nqa-jitter tag-version 1
#
ip route-static 0.0.0.0 0.0.0.0 124.114.156.209
ip route-static 0.0.0.0 0.0.0.0 113.200.77.233 preference 70
#
snmp-agent
snmp-agent local-engineid 000007DB7F00000100006E55
snmp-agent community read  Usg2200 acl 2001
snmp-agent sys-info version all
#
banner enable
#
ur-interface con 0
authentication-mode local ur admin password simple mimashi1983#^^#
ur-interface tty 2
authentication-mode none
modem both
ur-interface vty 0 4
ur privilege level 3
t authentication password cipher I$'4!VBZ8B;^2/\%98C4@A!!
#
slb
#
cwmp
#
right-manager rver-group
#
nat-policy interzone trust untrust outbound
policy 1
  action source-nat
  policy source 192.168.10.0 0.0.0.255
  address-group 0
#
nat-policy interzone trust untrust1 outbound
policy 2
  action source-nat
  policy source 192.168.100.0 0.0.0.255
  policy source 192.168.200.0 0.0.0.255
  policy source 192.168.1.0 0.0.0.255
  policy source 192.168.2.0 0.0.0.255
  policy source 192.168.3.0 0.0.0.255
  address-group 1
#
return
<xagl_USG2200

本文发布于:2023-05-06 02:28:46,感谢您对本站的认可!

本文链接:https://www.wtabcd.cn/fanwen/fan/89/859725.html

版权声明:本站内容均来自互联网,仅供演示用,请勿用于商业和其他非法用途。如果侵犯了您的权益请与我们联系,我们将在24小时内删除。

标签:防火墙   配置   案例
相关文章
留言与评论(共有 0 条评论)
   
验证码:
推荐文章
排行榜
Copyright ©2019-2022 Comsenz Inc.Powered by © 专利检索| 网站地图