欢迎来到天天文库
浏览记录
ID:23301404
大小:489.00 KB
页数:12页
时间:2018-11-06
《配置juniper-ssg》由会员上传分享,免费在线阅读,更多相关内容在应用文档-天天文库。
1、简述环境:1.双ISP,两个服务器6.6和6.8对外开放17991端口2.trust-vr和untrust-vr同在,zoneuntrust被修改到untrust-vr中3.6.6VIP180的地址,6.8MIP221的地址,应用源路由其实东西也不多,不过没配过的我开始真不知道如何配置juniper的地址转换setclockntpsetclocktimezone8setclockdstrecurringstart-weekday20302:00end-weekday101102:00setvroutertrust-vrsharablesetvrouter"untrust-vr"ex
2、itsetvrouter"trust-vr"unsetauto-route-exportexit------------------------------------------------------------------------------若防火墙里没有你所用的服务就自己加吧-------------------------------------------------------------------------------------------------setservice"17991"protocoltcpsrc-port0-65535dst-port17
3、991-17991setservice"3389"protocoltcpsrc-port0-65535dst-port3389-3389setalgappleichatenableunsetalgappleichatre-assemblyenablesetalgsctpenablesetauth-server"Local"id0setauth-server"Local"server-name"Local"setauthdefaultauthserver"Local"setauthradiusaccountingport1646setadminname"netscreen"setad
4、minpassword"nJqNNxrLGyrLc0lEtsCBqfDtDMA/Pn"setadminuser"hongyuan"password"nNnfG0rrJIWDcc8EysvMuSCt+LBiDn"privilege"all"-----------------------------------------------------------------------------------------如果要添加管理ip,别忘了添加内部网段地址,第一次我只加了远端的公网地址,导致内部要配置却进不去,只能console了。--------------------------
5、------------------------------------------------------------------------setadminmanager-ip192.168.6.0255.255.255.0setadminmanager-ip114.255.150.140255.255.255.255setadminmanager-ip219.141.171.130255.255.255.255setadminauthwebtimeout10setadminauthserver"Local"setadminformatdossetzone"Trust"vrou
6、ter"trust-vr"-------------------------------------------------------------------------------------------------"Untrust"默认是在"trust-vr"里的,我给改了--------------------------------------------------------------------------------------------------setzone"Untrust"vrouter"untrust-vr"setzone"DMZ"vrouter"t
7、rust-vr"setzone"VLAN"vrouter"trust-vr"setzone"Untrust-Tun"vrouter"trust-vr"setzone"Trust"tcp-rstsetzone"Untrust"blockunsetzone"Untrust"tcp-rstsetzone"MGT"blocksetzone"DMZ"tcp-rstsetzone"VLAN"blockunsetzone"VLAN"tcp-rstsetzone"Trust"scre
此文档下载收益归作者所有