监控安装 ERP

系统集成论坛

 找回密码
 注册通行证

QQ登录

只需一步,快速开始

路由器交换机防火墙系统集成商城 优质产品采购平台
查看: 4677|回复: 10
打印 上一主题 下一主题

以前做过的小项目

  [复制链接]

0

主题

1

帖子

29

积分

实习生

QQ
跳转到指定楼层
1
发表于 2010-8-12 16:35:04 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
华为金牌代理


MASTER


18:13:24  2010/07/03
#
sysname USG5360
#
web-manager enable
web-manager security enable
#
hrp enable
hrp mirror session enable
hrp interface GigabitEthernet0/0/3
#
firewall packet-filter default permit interzone local trust direction inbound
firewall packet-filter default permit interzone local trust direction outbound
firewall packet-filter default permit interzone local untrust direction inbound
firewall packet-filter default permit interzone local untrust direction outbound
firewall packet-filter default permit interzone local dmz direction inbound
firewall packet-filter default permit interzone local dmz direction outbound
firewall packet-filter default permit interzone local vzone direction inbound
firewall packet-filter default permit interzone local vzone direction outbound
firewall packet-filter default permit interzone trust untrust direction inbound
firewall packet-filter default permit interzone trust untrust direction outbound
firewall packet-filter default permit interzone trust dmz direction inbound
firewall packet-filter default permit interzone trust dmz direction outbound
firewall packet-filter default permit interzone trust vzone direction inbound
firewall packet-filter default permit interzone trust vzone direction outbound
firewall packet-filter default permit interzone dmz untrust direction inbound
firewall packet-filter default permit interzone dmz untrust direction outbound
firewall packet-filter default permit interzone untrust vzone direction inbound
firewall packet-filter default permit interzone untrust vzone direction outbound
firewall packet-filter default permit interzone dmz vzone direction inbound
firewall packet-filter default permit interzone dmz vzone direction outbound
#
nat address-group 1 192.168.2.9 192.168.2.9 vrrp 1
#
firewall statistic system enable
#
interface GigabitEthernet0/0/0
ip address 192.168.2.7 255.255.255.240
vrrp vrid 1 virtual-ip 192.168.2.9 master
hrp track master
#
interface GigabitEthernet0/0/1
ip address 192.168.0.254 255.255.255.0
vrrp vrid 2 virtual-ip 192.168.0.250 master
hrp track master
#
interface GigabitEthernet0/0/2
#                                         
interface GigabitEthernet0/0/3
ip address 1.1.1.2 255.255.255.0
vrrp vrid 3 virtual-ip 1.1.1.1 master
hrp track master
#
interface NULL0
#
firewall zone local
set priority 100
#
firewall zone trust
set priority 85
add interface GigabitEthernet0/0/1
#
firewall zone untrust
set priority 5
add interface GigabitEthernet0/0/0
#
firewall zone dmz
set priority 50
add interface GigabitEthernet0/0/3
#                                         
firewall zone vzone
set priority 0
#
nat-policy interzone trust untrust outbound
policy 1
action source-nat
policy source 192.168.0.0 0.0.0.255
address-group 1
#
aaa
local-user admin password cipher ]MQ;4\]B+4Z,YWX*NZ55OA!!
local-user admin service-type web terminal telnet
local-user admin level 3
authentication-scheme default
#
authorization-scheme default
#
accounting-scheme default
#
domain default
#
#
right-manager server-group               
#
slb
#
ospf 1
#
ip route-static 0.0.0.0 0.0.0.0 192.168.2.1
#
user-interface con 0
user-interface vty 0 4
authentication-mode aaa
#
return
HRP_M[USG5360]









SLAVE



18:14:07  2010/07/03
#
sysname USG5360
#
web-manager enable
web-manager security enable
#
hrp enable
hrp mirror session enable
hrp interface GigabitEthernet0/0/3
#
firewall packet-filter default permit interzone local trust direction inbound
firewall packet-filter default permit interzone local trust direction outbound
firewall packet-filter default permit interzone local untrust direction inbound
firewall packet-filter default permit interzone local untrust direction outbound
firewall packet-filter default permit interzone local dmz direction inbound
firewall packet-filter default permit interzone local dmz direction outbound
firewall packet-filter default permit interzone local vzone direction inbound
firewall packet-filter default permit interzone local vzone direction outbound
firewall packet-filter default permit interzone trust untrust direction inbound
firewall packet-filter default permit interzone trust untrust direction outbound
firewall packet-filter default permit interzone trust dmz direction inbound
firewall packet-filter default permit interzone trust dmz direction outbound
firewall packet-filter default permit interzone trust vzone direction inbound
firewall packet-filter default permit interzone trust vzone direction outbound
firewall packet-filter default permit interzone dmz untrust direction inbound
firewall packet-filter default permit interzone dmz untrust direction outbound
firewall packet-filter default permit interzone untrust vzone direction inbound
firewall packet-filter default permit interzone untrust vzone direction outbound
firewall packet-filter default permit interzone dmz vzone direction inbound
firewall packet-filter default permit interzone dmz vzone direction outbound
#
nat address-group 1 192.168.2.9 192.168.2.9 vrrp 1
#
firewall statistic system enable
#
interface GigabitEthernet0/0/0
ip address 192.168.2.8 255.255.255.240
vrrp vrid 1 virtual-ip 192.168.2.9 slave
hrp track slave
#
interface GigabitEthernet0/0/1
ip address 192.168.0.253 255.255.255.0
vrrp vrid 2 virtual-ip 192.168.0.250 slave
hrp track slave
#
interface GigabitEthernet0/0/2
#                                         
interface GigabitEthernet0/0/3
ip address 1.1.1.3 255.255.255.0
vrrp vrid 3 virtual-ip 1.1.1.1 slave
hrp track slave
#
interface NULL0
#
firewall zone local
set priority 100
#
firewall zone trust
set priority 85
add interface GigabitEthernet0/0/1
#
firewall zone untrust
set priority 5
add interface GigabitEthernet0/0/0
#
firewall zone dmz
set priority 50
add interface GigabitEthernet0/0/3
#                                         
firewall zone vzone
set priority 0
#
nat-policy interzone trust untrust outbound
policy 1
action source-nat
policy source 192.168.0.0 0.0.0.255
address-group 1
#
aaa
local-user admin password cipher ]MQ;4\]B+4Z,YWX*NZ55OA!!
local-user admin service-type web terminal telnet
local-user admin level 3
authentication-scheme default
#
authorization-scheme default
#
accounting-scheme default
#
domain default
#
#
right-manager server-group               
#
slb
#
ip route-static 0.0.0.0 0.0.0.0 192.168.2.1
#
user-interface con 0
user-interface vty 0 4
authentication-mode aaa
#
return

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?注册通行证

x

评分

1

查看全部评分

华为赛门铁克安全存储全行业解决方案
2
发表于 2010-8-12 22:49:37 | 只看该作者
华为金牌代理
感谢分享!
我分享,我成长!系统集成 XTJC.COM

0

主题

48

帖子

48

积分

实习生

3
发表于 2010-9-18 07:45:47 | 只看该作者
华为金牌代理
来看看 有什么热闹的?嘻嘻

0

主题

10

帖子

33

积分

实习生

4
发表于 2011-7-13 15:33:26 | 只看该作者
看看

0

主题

2

帖子

22

积分

实习生

5
发表于 2011-7-15 12:57:06 | 只看该作者
回复 1# ludi


   非常谢谢分享

0

主题

36

帖子

38

积分

实习生

6
发表于 2011-8-23 10:16:35 | 只看该作者
看了 不错 这个自己实践一遍就记住了

0

主题

5

帖子

25

积分

实习生

7
发表于 2011-8-23 15:52:55 | 只看该作者
人人为我,那会使人堕入地狱,
我为人人,就是人间天使!

0

主题

4

帖子

24

积分

实习生

8
发表于 2011-9-27 16:36:29 | 只看该作者
灰常感谢,了解了解

0

主题

123

帖子

134

积分

实习生

QQ
9
发表于 2011-11-3 12:47:37 | 只看该作者
have a look
宇川网络 大唐电信总代 华为金牌代理www.gzycc.com
13640864068

0

主题

2

帖子

22

积分

实习生

10
发表于 2011-11-26 14:26:06 | 只看该作者
那些代码没看懂·~!
您需要登录后才可以回帖 登录 | 注册通行证

本版积分规则

联系我们| 手机版|系统集成论坛 ( 京ICP备11008917号 )

GMT+8, 2025-7-20 20:32 , Processed in 0.042202 second(s), 26 queries .

系统集成论坛

BBS.XTJC.COM

快速回复 返回顶部 返回列表