H3C S9500E 系列路由交换机IRF与FW ACG IPS插卡典型配置指导.docx
《H3C S9500E 系列路由交换机IRF与FW ACG IPS插卡典型配置指导.docx》由会员分享,可在线阅读,更多相关《H3C S9500E 系列路由交换机IRF与FW ACG IPS插卡典型配置指导.docx(33页珍藏版)》请在淘文阁 - 分享文档赚钱的网站上搜索。
1、H3C S9500E系歹U路由交换机IRF与FW ACG IPS插卡典型配置指导关键词:IPS、ACG、FW、典型配置指导摘 要:介绍在95E堆叠下,FW&ACG&IPS插卡的推荐组网应用方案及典型配置指导。缩略语:缩略语英文全名中文解释IPSIntrusion Prevention System入侵防御系统OAAOpen Application Architecture开放应用架构ACGApplication Control Gateway应用控制网关FWFireWall防火墙Comware Software, Version 5.20, Release 3102P13Comware Pla
2、tform Software Version COMWAREV500R002B51D010H3C SecBlade FW Software Version V300R001B01D126Copyright (c) 2004-2009 Hangzhou H3C Tech. Co., Ltd. All rights reserved.Compiled Jun 24 2009 14:13:17, RELEASE SOFTWAREH3C SecBlade FW uptime is 0 week, 0 day, 0 hour, 1 minute4.4配置步骤酉已置 S9500E1.配置步骤95E上acl
3、的配置:105dis acl allAdvanced ACL 3000, named -none-, 1 rule, 用来匹配源IP为奇数的流量ACLs step is 5Advanced ACL 3001, named -none-, 1 rule, 用来匹配目的IP为奇数的流量ACUs step is 5Advanced ACL 3100, named -none-, 1 rule, 用来匹配所有IP流量ACUs step is 5rule 0 permit IPAdvanced ACL 3200, named -none-, 2 rules,用来匹配各服务区内部互访流量ACUs step
4、 is 5rule 0 permit IP destination 10.1.1.0 0.0.0.255 Ethernet frame ACL 4000, named -none-, 1 rule,用来匹配ARP流量ACLs step is 5rule 0 deny type 0806 ffffEthernet frame ACL 4001, named -none-, 1 rule, 用来匹配所有流量ACLs step is 5rule 0 permit95E上端口0112的配置105dis cur int g2/6/0/15#interface GigabitEthernet2/6/0/1
5、5port link-type trunkundo port trunk permit vlan 1port trunk permit vlan 10qos apply policy 1 inbound#return105dis qos policy in g 2/6/0/15Interface: GigabitEthernet2/6/0/15Direction: InboundPolicy: 1Classifier: local服务区内部互访流量不上OAA插卡Operator: ANDRule(s) : If-match acl 3200Behavior: localFilter Enabl
6、e: permitClassifier: 1vlantag为10,三层流量,源IP为奇数的流量走IPS1Operator: ANDRule(s) : lf-match acl 3000If-match service-vlan-id 10lf-match forwarding-layer routeBehavior: 1Redirect enable:Redirect type: interfaceRedirect destination: Ten-GigabitEthernet2/5/0/1Classifier: 2 vlan tag为10,三层流量,IPS1插卡在位时,源IP为偶数的流量走
7、IPS2;Operator: ANDIPS1插卡不在位时,所有流量都走IPS2,负载分担和备份;Rule(s) : If-match acl 3100If-match service-vlan-id 10If-match forwarding-layer routeBehavior: 2Redirect enable:Redirect type: interfaceRedirect destination: Ten-GigabitEthernet1 /4/0/1Classifier: 21vlan tag为10,三层流量,IPS2插卡不在位时,所有流量都走IPS1Operates: ANDRu
8、le(s) : If-match acl 3100If-match service-vlan-id 10If-match forwarding-layer routeBehavior: 1Redirect enable:Redirect type: interfaceRedirect destination: Ten-GigabitEthernet2/5/0/195E上与IPS1插卡相连的接口配置105 dis cur int te2/5/0/1#interface T en-GigabitEthernet2/5/0/1port link-type trunkport trunk permit
9、 vlan 1 10 20 to 21qos apply policy 2 inboundmac-address max-mac-count 0#return105dis qos policy int t2/5/0/1Interface: Ten-GigabitEthernet2/5/0/1Direction: InboundPolicy: 2Classifier: 1 vlan tag为10,三层流量,源IP为奇数的流量走ACG1Operator: ANDRule(s) : If-match acl 3000If-match service-vlan-id 10If-match forwar
10、ding-layer routeBehavior: 3Redirect enable:Redirect type: interfaceRedirect destination: Ten-GigabitEthernet2/4/0/1Class币er:2vlan tag为10,三层流量,ACG1插卡在位时,源IP为偶数的流量走ACG2;Operator: AND ACG1插卡不在位时,所有流量都走ACG2,负载分担和备份;Rule(s) : If-match acl 3100If-match service-vlan-id 10If-match forwarding-layer routeBeha
11、vior: 4Redirect enable:Redirect type: interfaceRedirect destination: Ten-GigabitEthernet1 /3/0/1Classifier: 21 vlan tag为10,三层流量,ACG2插卡不在位时,所有流量都走ACG1Operator: ANDRule(s) : If-match acl 3100If-match service-vlan-id 10If-match forwarding-layer routeBehavior: 3Redirect enable:Redirect type: interfaceRe
12、direct destination: Ten-GigabitEthernet2/4/0/1Classifier: arpClassifier: arp过滤二层报文Operator: ANDRule(s) : If-match forwarding-layer bridgeIf-match acl 4001Behavior: arpFilter Enable: denyClassifier: arp1过滤arp报文Operator: ANDRule(s) : If-match acl 4000Behavior: arp1Filter Enable: deny95E上与IPS2插卡相连的接口配置
13、,与IPS1插卡的QoS配置完全一样105dis cur int te 1/4/0/1#interface T en-GigabitEthernet1 /4/0/1port link-type trunkport trunk permit vlan 1 10 20 to 21qos apply policy 2 inboundmac-address max-mac-count 0#return105dis qos policy int t1/4/0/1Interface: Ten-GigabitEthernet1 /4/0/1Direction: InboundPolicy: 2vlan ta
14、g为10,三层流量,源IP为奇数的流量走ACG1Classifier: 1Operator: ANDRule(s) : If-match acl 3000If-match service-vlan-id 10If-match forwarding-layer routeBehavior: 3Redirect enable:Redirect type: interfaceRedirect destination: Ten-GigabitEthernet2/4/0/1Classifier: 2vlan tag为10,三层流量,ACG1插卡在位时,源IP为偶数的流量走ACG2;Operator: A
15、NDACG1插卡不在位时,所有流量都走ACG2,负载分担和备份;Rule(s) : If-match acl 3100If-match service-vlan-id 10If-match forwarding-layer routeBehavior: 4Redirect enable:Redirect type: interfaceRedirect destination: Ten-GigabitEthernet1 /3/0/1Classifier: 21 一 一vlan tag为10,三层流量,ACG2插卡不在位时,所有流量都走ACG1Operator: ANDRule(s) : If-m
16、atch acl 3100If-match service-vlan-id 10If-match forwarding-layer routeBehavior: 3Redirect enable:Redirect type: interfaceRedirect destination: Ten-GigabitEthernet2/4/0/1Classifier: arp过滤二层报文Operator*: ANDRule(s) : If-match forwarding-layer bridgeIf-match acl 4001Behavior: arpFilter Enable: denyClas
17、sifier: arp1过滤arp报文Operator: ANDRule(s) : If-match acl 4000Behavior: arp1Filter Enable: deny95E上与ACG1相连的接口配置105dis cur int te2/4/0/1#interface Ten-GigabitEthernet2/4/0/1port link-type trunkport trunk permit vlan 1 10 20 to 21qos apply policy 5 inboundmac-address max-mac-count 0return105dis qos polic
18、y int t2/4/0/1Interface: Ten-GigabitEthernet2/4/0/1Direction: InboundPolicy: 5Classifier: a vlantag为20,三层流量,目的IP为奇数的流量走IPS1Operator: ANDRule(s) : lf-match acl 3001If-match service-vlan-id 20lf-match forwarding-layer routeBehavior: 1Redirect enable:Redirect type: interfaceRedirect destination: Ten-Gi
19、gabitEthernet2/5/0/1Classifier: c vlan tag为21,三层流量,目的IP为奇数的流量走IPS1Operator: ANDRule(s) : If-match acl 3001If-match service-vlan-id 21If-match forwarding-layer routeBehavior: 1Redirect enable:Redirect type: interfaceRedirect destination: Ten-GigabitEthernet2/5/0/1Classifier: b vlantag为20,三层流量,IPS1插卡在
20、位时,目的IP为偶数的流量走IPS2;Operator: AND IPS1插卡不在位时,所有流量都走IPS2,负载分担和备份;Rule(s) : lf-match acl 3100lf-match service-vlan-id 20lf-match forwarding-layer routeBehavior: 2Redirect enable:Redirect type: interfaceRedirect destination: Ten-GigabitEthernet1 /4/0/1Classifier: d vlantag为21,三层流量,IPS1插卡在位时,目的IP为偶数的流量走I
21、PS2;Operator: AND IPS1插卡不在位时,所有流量都走IPS2,负载分担和备份;Rule(s) : lf-match acl 3100lf-match service-vlan-id 21lf-match forwarding-layer routeBehavior: 2Redirect enable:Redirect type: interfaceRedirect destination: Ten-GigabitEthernet1 /4/0/1Classifier: b1 vlan tag为20,三层流量,IPS2插卡不在位时,所有流量都走IPS1Operator: ANDR
22、ule(s) : lf-match acl 3100lf-match service-vlan-id 20lf-match forwarding-layer routeBehavior: 11特性简介32应用场合53注意事项54配置举例54.1 组网需求54.2 配置思路84.3 软件版本84.4 配置步骤10配置 S9500E104.4.1 配置FW29配置IPS/ACG304.4.2 OAA定位参考31445验证结果325相关资料375.1 相关协议和标准375.2 其它相关资料37Redirect enable:Redirect type: interfaceRedirect desti
23、nation: Ten-GigabitEthernet2/5/0/1Classifier: d1 vlan tag为21,三层流量,IPS2插卡不在位时,所有流量都走IPS1Operator: ANDRule(s) : lf-match acl 3100If-match service-vlan-id 21lf-match forwarding-layer routeBehavior: 1Redirect enable:Redirect type: interfaceRedirect destination: Ten-GigabitEthernet2/5/0/1Classifier: arp过
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- H3C S9500E 系列路由交换机IRF与FW ACG IPS插卡典型配置指导 系列 路由 交换机 IRF FW IPS 插卡 典型 配置 指导
限制150内