华为H3C防火墙配置手册.docx





《华为H3C防火墙配置手册.docx》由会员分享,可在线阅读,更多相关《华为H3C防火墙配置手册.docx(18页珍藏版)》请在淘文阁 - 分享文档赚钱的网站上搜索。
1、华为H3C防火墙配置手册 - 1 - 要求:通过配置华为防火墙实现本地 telnet 服务器能够通过 NAT 上网.并且,访问电信网络 链路时走电信,访问网通链路时走网通. 具体配置如下: 华为 US G 2000 Username:admin Password:Admin123 system-view USG2205BSRsysname huawei huaweiinterface GigabitEthernet 0/0/0 T - 2 - huawei-GigabitEthernet0/0/0ip address 202.100.1.1 255.255.255.0 huawei-Gigab
2、itEthernet0/0/0undo shutdown huawei-Gigab itEthernet0/0/0quit huaweiinterface GigabitEthernet 0/0/1 huawei-GigabitEthernet0/0/1description #conn to yidong link# huawei-GigabitEthernet0/0/1ip address 202.200.1.1 255.255.255.0 huawei-GigabitEthernet0/0/1undo shutdown huawei-Gigab itEthernet0/0/1quit h
3、uaweiinterface Vlanif 1 huawei-Vlanif1description #conn to local# huawei-Vlanif1ip address 192.168.1.1 255.255.255.0 huawei-Vlanif1undo shutdown huawei-Vlanif1quit 专注高端,技术为王 TEL:0592-* - 3 - huawei-zone-trustundo add interface GigabitEthernet 0/0/1 huawei-zone-trustadd interface Vlanif 1 huaweifirew
4、all zone name Dianxin huawei-zone-dianxinset priority 4 huawei-zone-dianxinadd interface GigabitEthernet 0/0/0 huawei-zone-dianxinquit huawei-zone-yidongset priority 3 huawei-zone-yidongadd interface GigabitEthernet 0/0/1 huawei-zone-yidongquit huaweiacl number 2000 huawei-acl-basic-2000rule 10 perm
5、it source 192.168.1.0 0.0.0.255 专注高端,技术为王 TEL:0592-* - 4 - huawei-acl-basic-2000quit huaweifirewall interzone trust dianxin huawei-interzone-trust-dianxinpacket-filter 2000 outbound huawei-interzone-trust-dianxinnat outbound 2000 interface GigabitEthernet 0/0/0 huawei-interzone-trust-dianxinquit hua
6、wei-interzone-trust-yidongnat outbound 2000 interface GigabitEthernet 0/0/1 huawei-interzone-trust-yidongquit huaweiuser-interface vty 0 4 huawei-ui-vty0-4authentication-mode password huawei-ui-vty0-4quit huaweiip route-static 0.0.0.0 0.0.0.0 202.100.1.2 huaweiip route-static 202.200.1.2 huaweiip ro
7、ute-static 222.160.0.0 255.252.0.0 202.200.1.2 专注高端,技术为王 TEL:0592-* - 5 - huawei firewall packet-filter default permit interzone local dianxin direction outbound huawei firewall packet-filter default permit interzone trust dianxin direction inbound huawei firewall packet-filter default permit interz
8、one trust dianxin direction outbound huawei firewall packet-filter default permit interzone local yidong direction inbound huawei firewall packet-filter default permit interzone local yidong direction outbound huawei firewall packet-filter default permit interzone trust yidong direction inbound huaw
9、ei firewall packet-filter default permit interzone trust yidong direction outbound 如图:电信网络、网通网络和 telnet 服务器配置 略! 验证: 内网 192.168.1.2 分别 PING 电信与网通. inside#ping 202.100.1.2 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 202.100.1.2, timeout is 2 seconds: ! Success rate is 100 percent
10、 (5/5), round-trip min/avg/max = 4/4/4 ms inside#ping 202.200.1.2 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 202.200.1.2, timeout is 2 seconds: ! TEL:0592-* - 6 - 专注高端,技术为王 Current total sessions: 3 icmp VPN: public - public 192.168.1.2:3202.100.1.1:23088-202.100.1.2:3 tcp VPN:
11、 public - public 192.168.1.1:1024-192.168.1.2:23 icmp VPN: public - public 192.168.1.2:4202.200.1.1:43288-202.200.1.2:4 验证成功! huaweidisplay current-configuration 11:54:30 2022/11/06 # acl number 2000 rule 10 permit source 192.168.1.0 0.0.0.255 # sysname huawei # super password level 3 cipher S*H+DFH
12、FSQ=QMAF41! # web-manager enable # info-center timestamp debugging date # firewall packet-filter defau lt permit interzone local trust direction inbound firewall packet-filter defau lt permit interzone local trust direction outbound firewall packet-filter defau lt permit interzone local untrust dire
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- 华为 H3C 防火墙 配置 手册

限制150内