这是华为的配置:
0 z1 B7 n6 Y! i K' s: `#
6 g; T0 j. M( M4 t% zacl number 2000; u3 W; e1 w) x; S4 m
rule 0 permit source 172.16.14.1 0
. m2 G. m7 o. g7 ]- X rule 1 permit source 172.16.1.0 0.0.0.2556 A' ?( k* J- @1 w7 W9 X
rule 3 permit source 172.16.2.1 0% Z) W- Z1 |/ `
rule 4 permit source 172.16.2.13 0
+ O* M: A) e+ K4 P; c% ~ rule 5 permit source 172.16.10.0 0.0.0.255
0 J2 L/ o# M% j0 } rule 6 permit source 172.16.16.2 0
5 o0 `, `- r- f. K- T rule 7 permit source 172.16.2.2 0
4 P2 ? |6 h0 s) |0 [4 R& | rule 8 permit source 172.16.14.50 0
2 ?% i, I, W; e$ b rule 10 deny- q, q1 N7 `5 {0 P. K0 r
acl number 2001
G) L# `* a% [- N rule 0 permit source 172.16.12.51 0
$ ~! \ {7 q) k2 R! o7 y: p) E rule 5 deny
( f+ ?! |% {) |. ]7 G) Oacl number 2002
+ f4 D! r( ~: P& b2 j3 K rule 0 permit source 172.16.12.61 0
4 q4 Q6 F6 C& `3 X3 r rule 5 deny
- ]: e% {+ `' {, t' Z0 r/ wacl number 2003
# K/ {) q) d% s8 j) p/ ] rule 0 permit source 172.15.10.4 0
6 @: X( E: U. Y* | rule 5 deny) ?1 z8 q9 X* o! _7 j/ y" z4 _7 H
#
0 Z% J2 }2 {" jacl number 30004 ?& W( t5 Y4 i( W4 j# t0 E
description dmz-trust: a% x: I- E) a4 g2 ^* U- G0 @
rule 0 permit tcp source 172.16.12.61 0 destination 172.16.10.71 0 destination-port eq 4008
0 ^) z4 n3 @/ K6 h. U- L rule 1 permit tcp source 172.16.12.61 0 destination 172.16.10.71 0 destination-port eq 8898, P# {* i7 |% w' T* K6 B
rule 2 permit tcp source 172.16.12.61 0 destination 172.16.10.71 0 destination-port eq 8868$ Z7 g( g# q. @
rule 3 permit tcp source 172.16.12.61 0 destination 172.16.10.71 0 destination-port eq 8858- ]; j! h" R1 T5 \% I
rule 4 permit tcp source 172.16.12.61 0 destination 172.16.14.155 0 destination-port eq 4008; A6 L9 ^$ L9 M6 M1 u) J$ z
rule 5 permit tcp source 172.16.12.61 0 destination 172.16.14.155 0 destination-port eq 8898
! z; I j' o' `4 H2 L; ] rule 6 permit tcp source 172.16.12.61 0 destination 172.16.14.155 0 destination-port eq 8868
5 S3 B( Y- D' M' \ rule 7 permit tcp source 172.16.12.61 0 destination 172.16.14.155 0 destination-port eq 8858% Q3 i; i% @8 S5 ?0 ]+ x
rule 8 permit tcp source 172.16.12.51 0 destination 172.16.10.71 0 destination-port eq 4003. @- f4 o1 p: S+ U
rule 9 permit tcp source 172.16.12.61 0 destination 172.16.10.71 0 destination-port eq ftp8 |: q V1 i: D) y1 ?* g
rule 10 permit tcp source 172.16.12.61 0 destination 172.16.10.51 0 destination-port eq ftp
; M& `5 Z! R' i9 A0 r rule 11 permit tcp source 172.16.12.61 0 destination 172.16.14.155 0 destination-port eq ftp, |, l. W& h& ]0 K0 V
rule 12 permit tcp source 172.16.12.51 0 destination 172.16.14.155 0 destination-port eq ftp! O$ u# N; ^) }+ Z
rule 13 permit tcp source 172.16.12.51 0 destination 172.16.10.71 0 destination-port eq ftp- u7 v0 P# h+ p9 u1 X# u
rule 14 permit tcp source 172.16.12.51 0 destination 172.16.10.51 0 destination-port eq ftp* F& r- {% X: [
rule 15 permit tcp source 172.16.12.51 0 destination 172.16.14.155 0 destination-port eq 4003
3 o1 }! {0 H% Y4 z rule 16 permit ospf4 a, q! B- G0 L5 p8 e) B
rule 17 permit tcp source 172.16.12.51 0 destination 172.16.10.101 0 destination-port eq 8
: G' J8 b& t2 H" G/ h' G2 ] rule 18 deny tcp
& ?# ~$ g e) ~& V9 D+ p. N1 Eacl number 3001
, g5 I3 i2 [: V description For Untrust-dmz, ^4 o$ ^/ c( c# A8 N* z
rule 0 permit tcp source 172.16.20.0 0.0.0.255 destination 172.16.12.51 0 destination-port eq 5000
; U0 S/ Z- s" V( O rule 5 permit icmp
$ D; \" ]- K+ g9 h: F: V- J rule 10 permit ospf * f4 I. _! X" C8 V5 w, {
rule 15 deny tcp source 172.16.20.0 0.0.0.2559 A. V/ l. G3 h* i9 S2 m
acl number 30020 x. t% ?8 X1 g# R [& A+ g
description To_Yinlian
5 o+ i0 t; \1 C4 c m4 P7 p+ K rule 0 permit ip source 9.234.21.63 0 destination 144.234.97.33 08 P/ }. X& K% m
rule 5 permit ip source 9.234.21.64 0 destination 144.234.97.33 0( {9 @8 b+ A5 @5 [7 [/ E2 ~
rule 10 permit ip source 9.234.21.66 0 destination 144.234.97.33 09 G" [* b$ w% f" L7 l
rule 15 deny ip
4 V% ?( q- |. A$ q9 Dacl number 3003+ f+ ^: z) r8 H3 f, n% A
description for Untrust-Trust+ z3 H& A9 ?- G& Y* E
rule 0 permit ip source 10.78.72.70 0 destination 172.15.10.4 0" A# Q& W6 O# D: ^. m" d3 G% t
rule 1 permit ip source 172.16.2.26 0 destination 172.16.10.111 0
+ O0 v, f, \9 | rule 2 permit ip source 172.16.2.26 0 destination 172.16.14.1 0
0 ]7 f4 o x/ ] rule 3 permit ip source 10.78.72.153 0 destination 172.15.10.4 0
6 f U! e& k' J' X rule 4 permit ip source 10.78.72.157 0 destination 172.15.10.4 0
, J& ^' E/ }6 @) E, T; B rule 5 permit ip source 192.168.100.43 0 destination 172.15.10.4 0. S# |! j0 W. A8 g2 l' B0 w; s
rule 6 permit ip source 10.16.2.7 0 destination 172.15.10.4 0
2 Q0 o' I' T4 U) O2 K% t, ` rule 7 permit ip source 10.16.2.5 0 destination 172.15.10.4 08 v, ~8 V% K! `6 j" `3 R
rule 8 permit ip source 10.16.2.6 0 destination 172.15.10.4 0
; Q( A4 P+ y/ R5 f! L- x5 Z rule 9 permit ip source 10.16.2.8 0 destination 172.15.10.4 0+ j9 ?. T1 w# Z5 s3 m2 |# x
rule 11 permit ip source 10.139.25.26 0 destination 172.15.10.4 0
3 i* r1 h) T" E* s rule 13 permit ip source 10.143.10.183 0 destination 172.15.10.4 0
3 ]' I+ E x* y5 R4 w rule 50 deny ip
# y" T+ a' @: z; [acl number 3004 1 o! G2 G% Y7 k, F) v
rule 0 permit ip source 172.16.1.7 0 destination 172.16.10.111 0
% Q# D- o' y" J8 o9 Xacl number 30058 W5 W3 X5 k0 n& v3 N
description TO_dudubao
6 R" }9 y0 z- R rule 0 permit tcp destination 172.15.10.4 0 destination-port eq 6868
. c5 E' n! i! c. \9 r rule 1 permit tcp destination 172.15.10.4 0 destination-port eq ftp-data& G- A5 I. ~1 @! b3 \3 P! m( @. n. |( k
rule 2 permit tcp destination 172.15.10.4 0 destination-port eq ftp _% _$ }8 d0 y+ R( s
acl number 3006
7 f3 X. \2 }- p8 i" I6 v rule 0 permit ip source 172.16.12.0 0.0.0.255 destination 10.0.1.0 0.0.0.255) Y0 ? A! k* Z4 ^" [( X+ j! i# c3 q
acl number 3007 B: z' Z' F" `& E# H& ?
rule 0 deny ip source 172.16.12.0 0.0.0.255 destination 10.0.1.0 0.0.0.255 K" }) |/ j; `* N4 `+ Y4 l
rule 1 permit ip source 172.16.12.0 0.0.0.2559 N3 ^- o1 G4 a# @
#
' Z- W( A& d s sysname NB_Eudemon300-A
: l. j+ S# e8 ~ U; ~: ?- z#
5 z) P& o0 F/ r1 _4 t super password level 3 cipher '._1D9P1YCQ=^Q`MAF4<1!! }4 J1 \4 s8 ]
#
8 D; z6 v6 ^$ C I; |$ y! ] info-center loghost 172.16.10.192
7 f. W+ n! e8 L info-center loghost 172.16.10.111, ]. x: a% g6 M8 \
#- c4 |9 X" U& N3 h" C- i
hrp enable
. p5 d* {9 |. C, N& W& J hrp interface Ethernet2/0/7
8 H: p$ B. U6 G! t/ J#& W1 b7 w5 M* z7 `) K
router id 172.16.1.3 $ \" r: M3 t$ w$ F9 [
#4 S0 l: r6 k$ E8 ~- z7 f% t
firewall packet-filter default permit interzone local trust direction inbound
# _1 p+ `$ p8 i$ r( Y firewall packet-filter default permit interzone local trust direction outbound* b _8 ^( Q+ E* K- H. e; C
firewall packet-filter default permit interzone local untrust direction inbound
8 }$ { P& {& W3 A firewall packet-filter default permit interzone local untrust direction outbound
6 R0 O" Q+ c, d: {0 E4 S! I firewall packet-filter default permit interzone local dmz direction inbound
: D, W- f; B! ? firewall packet-filter default permit interzone local dmz direction outbound
6 p5 g5 e- H) R) c6 h firewall packet-filter default permit interzone local hrp direction inbound
2 ~* E' E5 J; ^* D8 L1 l5 t firewall packet-filter default permit interzone local hrp direction outbound* y: W9 Y) S! K# {: l: `
firewall packet-filter default permit interzone local gprs direction inbound% W6 @$ T3 E Y5 z! ~$ X
firewall packet-filter default permit interzone local gprs direction outbound4 F3 H# Q( W+ m2 ?5 k. b
firewall packet-filter default permit interzone local dudubao direction inbound
2 h6 ?3 l) \0 ^+ z0 {+ L firewall packet-filter default permit interzone local dudubao direction outbound, G1 M- {7 n& U
firewall packet-filter default permit interzone trust untrust direction outbound8 ]/ `% ? C6 I; z+ w
firewall packet-filter default permit interzone trust dmz direction inbound0 E* F& V9 X8 G! o- t2 W
firewall packet-filter default permit interzone trust dmz direction outbound# t' |- Y& M/ R
firewall packet-filter default permit interzone trust gprs direction inbound* D2 c( C) U( H5 M
firewall packet-filter default permit interzone trust gprs direction outbound( V5 Z6 z$ c" O
firewall packet-filter default permit interzone trust dudubao direction inbound
( r2 @! ?8 A2 S x firewall packet-filter default permit interzone trust dudubao direction outbound
' B8 E1 N+ e$ ]+ } firewall packet-filter default permit interzone dmz untrust direction inbound& k' w8 U$ Q& l4 y7 O
firewall packet-filter default permit interzone dmz untrust direction outbound; u: v, n0 d, i- p/ E
firewall packet-filter default permit interzone dmz gprs direction inbound7 v6 O/ I, P0 J3 S5 J. n
firewall packet-filter default permit interzone dmz gprs direction outbound
; X3 T- Z0 p; p6 }+ ? firewall packet-filter default permit interzone dmz dudubao direction inbound# x1 k- x+ r! _( A7 d* p) D2 T n2 y
firewall packet-filter default permit interzone dmz dudubao direction outbound
" `# H5 p1 p' O+ d ^) H#, ~/ O; c* W! G
nat address-group 3 145.234.97.33 145.234.97.33) x2 k9 W' @* r& Y. i
nat address-group 5 144.234.97.33 144.234.97.33) X2 D. E% S" |0 ~* j" B: X
nat server zone gprs global 144.234.97.33 inside 172.16.12.612 f g; h6 q" ?$ P3 j+ G5 d
#1 u" r4 d$ F* ^) l
bypass switch-back auto7 o6 R- z2 P( S
#
/ |. P% H! \4 j6 W9 { firewall mode route4 O" y. w. [% u/ ?
#
' [3 n' }# Z/ | ^ o4 ~ firewall defend ip-spoofing enable# G: R1 Y- i% A9 p" A- o
firewall defend land enable
: T, ?* Y& A: G firewall defend smurf enable
2 j& W5 S! b6 J' w& s6 I+ M e$ j) T firewall defend fraggle enable2 _9 H3 M* T: D, ?- g& a2 w
firewall defend winnuke enable/ u' A0 S$ s9 D* E0 j; k0 w9 a: ~
firewall defend syn-flood enable0 B0 X" h% E* x: |- F8 b- H- y
firewall defend udp-flood enable2 x2 {! ]3 ?' z
firewall defend icmp-redirect enable& B# h7 f0 r" k- F0 a4 V
firewall defend icmp-unreachable enable$ r! U K3 _8 ^/ y; L' o
firewall defend ip-sweep enable + w. C3 b1 |2 g& ^# d% ~0 ~
firewall defend port-scan enable
$ p7 X' K& _6 q% Q4 Z, w* y firewall defend route-record enable
% V6 A# p7 z" i. S6 i6 r) W) i firewall defend ping-of-death enable; I- C- l0 o% ^5 R7 b
firewall defend teardrop enable
# _3 f6 {4 i1 B) X/ G+ |" d5 D firewall defend tcp-flag enable
- I$ d5 U' |* |' |% }& l2 Q( { firewall defend large-icmp enable
: s' E) i& X0 I( H6 ?9 T#1 A7 i) `+ }3 g0 N$ p. R0 h$ k' Z
firewall statistic system enable( t3 I5 S/ ?; I- K) g
# V/ M! Z$ n2 N) k
ike proposal 1
6 U: F% g$ X( m- A#0 B) h! d; F& L$ d2 z
ike peer a1 F2 P' O) e/ E4 u* I N l
pre-shared-key cnnbtk
( Y( G# M" j% S% X# [: T ike-proposal 10 i8 |' c* s* y: I3 ^
remote-address 119.57.5.5. @# U. R% D' ~& P1 N0 n: H- O
#
5 x; D2 A0 c, a5 sipsec proposal tran1. R2 W6 G5 g5 Y( V& U2 }
#" o1 J9 J- q2 _+ R, q7 u
ipsec policy map1 1 isakmp0 {) f9 u. Q' u, W3 z) ]
security acl 3006
t5 W1 K0 q# k- c } pfs dh-group2( H+ |1 i6 U% X* c- w0 K
ike-peer a* B* `9 |6 v; C9 o2 s8 ]
proposal tran1
' y* Q" ^4 s. j8 r local-address 60.12.194.14/ h7 \4 s* W \0 \6 r
#
# }6 f. {6 o6 [7 Q* Qinterface Aux0
9 j7 q# _0 u- U async mode flow
! q# W# H) J7 u6 M link-protocol ppp
* H( F1 `2 k4 d1 |% R, ?6 |#! E! m$ h: }, b$ [
interface Ethernet0/0/0: b* I, `+ j# @8 V0 j4 ^3 p( K
#. j: h/ u3 o8 k/ f4 b! @# n2 R
interface Ethernet0/0/1
! }1 S* [' a/ [5 L3 ?9 n; S! X#! u. O! y# d( z' o- C/ Q6 ]
interface Ethernet2/0/0" m' j4 V; d) g7 S- C( }. E' e
description To_S5624-A(1/0/24)
$ I+ S' @2 T5 N- \+ s ip address 172.16.2.9 255.255.255.252
) }4 ~% y* L' z) W: G ospf cost 100! e9 r7 |# ]& U+ d9 E" ]5 ~
#
- d/ L/ n5 v* A$ x( ~interface Ethernet2/0/1" L7 r- ~8 N5 [ z4 Q0 m4 E
description To_Yinlian9 o; {+ p& V' `3 J
ip address 145.234.132.154 255.255.255.252
& H$ H% l. | l2 M! r4 x. X#6 g. u/ m x6 e# q3 p2 W
interface Ethernet2/0/2+ z" n/ P; g& k/ C# Y1 P8 I
description To_S6506R_A(7/0/48)" r% U* V& Z% n+ K3 ~
ip address 172.16.2.2 255.255.255.252) O0 u' h0 Z H8 a
ospf cost 100
/ O c/ e# J. J#
7 `! U! S/ H( I) w' Z0 Finterface Ethernet2/0/3# _1 g+ p. P/ H/ z3 |2 a
description To-dudubao' D3 [; h5 `$ e% @; x; [
ip address 60.12.194.14 255.255.255.2400 T: G: @0 s5 F5 S" [
ipsec policy map1
6 e) x( f4 V( Y5 d. j#7 t+ M" S0 f# m+ l# q
interface Ethernet2/0/45 V) h3 w+ V6 V/ M1 r8 q+ s+ b: l
#
( l9 j7 N w* n& H2 E5 s* Uinterface Ethernet2/0/5* U- S5 J# x, D; o# ~0 E$ t
#
* `2 ]+ N. k$ j; X* S- Zinterface Ethernet2/0/6
1 I& i5 s/ i, N, W _0 k3 _#
2 ?. ]% q, T% h; m: ]interface Ethernet2/0/7
4 g6 q0 M( B z" O3 b description To_Eudemon300-B_E2/0/7
4 q b6 @* O a4 q9 B+ w8 C; e ip address 172.16.2.201 255.255.255.2487 D; L0 C1 ]4 U4 X+ m
vrrp vrid 1 virtual-ip 172.16.2.203
F$ D- l) ]: r vrrp vrid 1 priority 150
7 H5 |& D# T9 q# W8 Z5 i vrrp vrid 1 preempt-mode timer delay 60
1 y5 ]- n1 w) j9 x8 y0 ` vrrp vrid 2 virtual-ip 172.16.2.204% z* i$ U# s- M0 W* ^: h
#/ u! ]' i# f' T% Z; C+ C
interface GigabitEthernet1/0/0
Z( d. u( m2 ^2 f6 O& D" x shutdown , l# L& Q$ E& e$ m! V4 M+ C2 N
#
) q0 G6 K+ h1 K) H; v. uinterface GigabitEthernet1/0/1: s$ a; ]2 `8 i2 K( V+ d
description To_S5624-B(1/0/25)
( Q7 c2 R- Q+ j ip address 172.16.2.25 255.255.255.252
# S1 U1 p7 j5 {3 V* ` ospf cost 500" I I+ E$ |7 p, v+ } |
# M# k# S3 b1 K( t2 o- z
interface NULL0
) O$ F4 L0 ~* p5 `/ I8 m2 Q" d#/ j+ n) j3 u) K: ~; I+ K
interface LoopBack0
, O9 W* r1 p8 V6 \; j ip address 172.16.1.3 255.255.255.2551 d I- P4 {4 x" U6 X/ D9 [6 |, \
#
1 o' M2 P4 K0 ]+ l4 I/ H: }firewall zone local# C8 Y6 y2 T; R! i
set priority 100
' i' i2 [5 b+ U. u5 X% `2 z#
2 O) ~+ T+ B2 N) _: r- {* r% qfirewall zone trust! f! m4 X5 v- F! I+ J+ R
set priority 85
( v# s8 l' U4 [ detect ftp. ~, Z/ A7 [ j) o1 v5 J
add interface Ethernet2/0/2
. _. R8 [& L" S% ^- k3 x#6 J( {3 B; h y& `, U/ l
firewall zone untrust
" c& D$ N5 ?7 x7 e" f% f set priority 5
& I- H4 I, W, r, n0 E. ]4 Q- I% [ detect ftp * ?) v& E; w- d9 k
add interface GigabitEthernet1/0/1
' W1 x+ z ^8 ` k2 C! N% L7 Z/ |#
; t! g. f0 V/ C$ d( F8 U7 y) Nfirewall zone dmz
- w' C7 m# Z; U9 ]0 S1 U2 C5 X8 x# a1 t set priority 50
2 E) g# F2 |% Q0 P. H add interface Ethernet2/0/0
" m) P1 X1 _$ @% P/ b#
3 `5 ?% G+ |1 Kfirewall zone name hrp
. q2 n- L$ U3 A4 ^. Z+ H( C8 Q& v$ d set priority 40
$ Z: D; R" P& r7 \) K* y! c. Q add interface Ethernet2/0/7
4 T# H6 W6 m; r2 J: [& S$ V#
% T" \# ~) x* b s$ ^8 [7 mfirewall zone name gprs
# F/ e; S, j/ b/ M9 n set priority 4
% g. ?# |: ]0 w5 ~9 z" g8 K detect ftp
+ Y' ], l+ V, z2 m: }- [" M add interface Ethernet2/0/1
0 t) l |( K$ n+ d5 B; f0 H7 G#
" ^) D9 r3 h+ T2 gfirewall zone name dudubao& A& N2 Z4 `4 z i8 [' M8 u$ U8 w
set priority 3
/ V( m$ `( n4 M7 t. l# Z" [ detect ftp: ]2 A2 D* t7 @( C
add interface Ethernet2/0/3
0 Z3 ]0 L! ^% E#
4 o+ `9 s& f- D9 E0 Ffirewall interzone local trust
$ T+ }1 O. |9 q5 A& d8 V( n1 @) w#$ _# `& e" E7 D, ?) _7 |4 f
firewall interzone local untrust ) G- i! f- s7 t) k
#7 \1 E* g: u' \* V$ |0 I9 S7 [' |/ X
firewall interzone local dmz( ]- [# D H6 {& o {" `
#
% Q6 ~3 [: M5 D. dfirewall interzone local hrp
5 @5 j/ X4 D/ ?+ @#8 c1 Z X7 F, K8 @" y) ?
firewall interzone local gprs6 l3 q& ^0 K$ V e; y" E Y
## a! B* A2 [1 n9 z8 A
firewall interzone local dudubao
9 M- C$ }$ ~5 ^4 P: S#
# @. ?- p; R6 D6 zfirewall interzone trust untrust
& |" }( ?3 P8 U. c6 U packet-filter 3003 inbound
0 X5 m N% R) X4 \0 ? detect ftp( m# N1 |. g9 v; D
#
$ ^8 v7 k P* @4 s$ Dfirewall interzone trust dmz, G: O! V( |2 Q k2 _" a5 p
#
1 w& ^, a2 A7 x2 q! U' tfirewall interzone trust hrp+ h5 z) V4 C. X3 \7 J% c
#
' ], E: J0 M0 J$ w, @: R& q" ofirewall interzone trust gprs4 _ Q6 j, |0 _) V* t. H9 ~
nat outbound 2003 address-group 3
% g0 E+ D0 r; V& I# d, Q% U detect ftp
* r% P! ?8 @; i7 B# v3 N, {#
7 E; [& o5 i4 \% O$ Vfirewall interzone trust dudubao4 z0 K9 |8 W+ p3 D5 b5 F
packet-filter 3005 inbound % b# v( j, Q/ e6 Y% Z/ X' }9 g
detect ftp1 J) s/ Y0 @1 `! j( B2 n
#
2 Z/ W$ d% i& O! I6 \4 vfirewall interzone dmz untrust
' N. B5 C) |6 z/ M#+ ?: n2 _, U0 X6 O
firewall interzone hrp untrust, P C0 A5 \- m! L4 O5 K, R- Y5 F
#
$ |& l5 W7 @* Hfirewall interzone untrust gprs3 `1 x' r t9 _: ? T! r' B! s5 H
#
- G' Y8 S2 e( c" ~firewall interzone untrust dudubao& `1 E, H6 D* k d* h
# b8 I" }5 `( s0 v. [. D
firewall interzone dmz hrp
: O/ X" K' @( z. l& r$ O& P#5 `( i; ]1 e# C) b
firewall interzone dmz gprs
4 u. z' N" P5 V$ J packet-filter 3002 inbound8 x% J _8 m9 _: |
nat outbound 2002 address-group 5
. g5 O" Y: m' M! T0 J1 h4 l detect ftp
5 P# H, h% n" O, D$ d7 f#
3 o% S2 I& S. {% x9 K4 Qfirewall interzone dmz dudubao6 n8 i4 c: t5 v& K- ~. @
packet-filter 3006 outbound6 ?: I" v* ]7 R' P+ F' A2 k
#- Y( W6 E9 ]2 k( C1 U0 R5 Q
firewall interzone hrp gprs
! G8 z7 U6 r6 s. Q/ U$ J4 v## H O" `2 F4 F' {' @0 h: {. N
firewall interzone hrp dudubao
$ f1 V! `, e2 g* p#
% w0 k. @& j. r- a' |( xfirewall interzone gprs dudubao
7 S: L" i# v" G* [ e7 a#
- Z- R5 ~, A" b" d/ K3 J* Wvrrp group 1
0 R' W+ |, t1 R+ a) s1 D* ` add interface Ethernet2/0/7 vrrp vrid 1 data5 ?2 |$ g( Y/ J3 ~* K, p
vrrp-group enable
8 x3 J8 I* \ b4 C% p4 R. K& w0 \: ^ vrrp-group priority 105# F" T3 S9 D# }! U- S
vrrp-group preempt delay 60
8 W, \! E* A: w$ `3 v* t+ ~ undo vrrp-group group-send
9 s* h( R- L0 v, n/ \4 dvrrp group 2. S% k, B& B6 J/ G% K- O
add interface Ethernet2/0/7 vrrp vrid 2 data
9 Y; X% @ X7 w- q8 @/ E! R vrrp-group enable8 i, J+ T9 a/ k% N& c
undo vrrp-group preempt
9 E6 C' p% v5 a! Y! i undo vrrp-group group-send
% E# }" I9 f! N#
# j, L* H2 M' j6 R1 l: yaaa' ~5 B; ^" `8 V7 E" O# u- ?
local-user huawei password cipher 1_`%CO&$8@7"+C5`;6XL!!!
, J' j% G+ \+ N- ?$ ~/ B local-user huawei service-type terminal telnet ssh5 [7 d% z5 u4 B3 \7 T
local-user huawei level 1, q _2 w$ e( y2 @1 ~9 [. `$ `9 v! C9 w
authentication-scheme default; q1 g2 T: I6 A3 x
#
3 p9 J$ J! |) y; ^$ }) L; @2 J7 K6 ] authorization-scheme default
' |7 P3 x5 x- D* C# $ ?" n' Z' T% U$ W2 T ?0 O
accounting-scheme default
7 N5 O% C2 V; r#
; j# O, _/ I6 m# Y3 N domain default
9 U1 t2 n/ r% i+ j/ B#; V, k( B* z% b% d
#
2 Q. d# E" X+ C4 b& d1 @ospf 1" P/ H8 E, G" G8 |; U
import-route static7 C) I3 ^+ l7 {; N
area 0.0.0.0
& Q& o/ H" t e network 172.16.1.3 0.0.0.0
7 K) J3 ?8 F3 Z! C* G# o' @$ }: v' u0 _ network 172.16.2.0 0.0.0.3, j0 ]& B7 }- i: F9 X, O7 p$ D
network 172.16.2.8 0.0.0.35 |" f- a! T0 I2 E
network 172.16.2.24 0.0.0.39 T+ T7 C5 r3 Q7 z1 u
#
* x0 z5 o7 |" E% a) n9 D# W ip route-static 9.234.21.0 255.255.255.0 145.234.132.153
5 q. F- m; j$ p) ]9 N1 h ip route-static 10.0.1.0 255.255.255.0 60.12.194.129
, i3 ?9 f T1 J4 N7 R2 R ip route-static 61.14.10.218 255.255.255.255 60.12.194.129
8 c. [, |+ {3 @ ip route-static 119.57.5.0 255.255.255.0 60.12.194.1299 Z7 U$ C0 Z8 D
ip route-static 172.15.10.4 255.255.255.255 172.16.2.1
: \# r# W( y# \2 M ip route-static 221.136.75.25 255.255.255.255 60.12.194.1296 d3 s; {4 a) J; ?( Y+ d/ D" }2 k
#
, T8 h- Z& M' x( a# [! o+ i0 ]8 K snmp-agent* } u% I/ v& i; {$ X
snmp-agent local-engineid 000007DB7F00000100001BEE
6 b: g; I4 u L. N5 ~ snmp-agent community read nbcardro
" i+ g' b6 k' P% K snmp-agent sys-info version all& I8 U0 M* @) x( K& ~
#, `& B; D/ h& L( e$ ?, P
ssh server timeout 30
6 ^7 n, G( D- {/ c3 p2 [* e E( @/ q ssh server rekey-interval 24
* p+ _# R9 B4 h* p Y ssh user huawei authentication-type password: D2 K0 ~5 r( p& Y4 K+ V4 R
#4 \" \* T2 f- f4 I
user-interface con 0
( M0 {! J- \0 }+ [+ k2 q% F$ o authentication-mode aaa
: n0 p- @! J* @. G1 l0 suser-interface aux 0
8 N0 a3 t `3 _" d- o* H/ P authentication-mode none- f( M) W/ f% \ \% A; q% G
user-interface vty 0 44 \" Y# f2 F c: o5 ~1 ~2 |
acl 2000 inbound; {# C6 r! u/ T( B1 n3 \; b3 {
authentication-mode aaa, r! w# e2 I3 ~4 S1 F) m* y
idle-timeout 5 0, m: Q$ W) P N: E' }6 x; g2 A; `$ C
#& l6 [5 [$ p, q+ i3 @
return |