欢迎来到天天文库
浏览记录
ID:47863456
大小:29.00 KB
页数:3页
时间:2019-07-04
《USG50配置命令》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、TOP内网192.168.1.1----------------USG50----------外网X.X.X.X--------[USG50]discurr#sysnameUSG50#web-managerenable启用WEB管理#firewallpacket-filterdefaultpermitinterzonetrustuntrustdirectioninboundfirewallpacket-filterdefaultpermitinterzonetrustuntrustdirectionoutbound允许U到T,t到U的流量通过
2、,记住是双向的^#natalgenableftpnatalgenablednsnatalgenableicmpnatalgenablenetbiosundonatalgenableh323undonatalgenablehwccundonatalgenableilsundonatalgenablepptpundonatalgenableqqundonatalgenablemsnundonatalgenableuser-defineundonatalgenablesip undonatalgenablertspf
3、irewallpermitsub-ip#firewallstatisticsystemenable#dhcpserverip-pooltest_poolnetwork192.168.1.0mask255.255.255.0gateway-list192.168.1.1dns-list210.22.70.3domain-namehuawei.comexpiredday8 DHCP地址池,没设置成功,问400.400说是不支持!郁闷#interfaceEthernet0/0/0ipaddre
4、ssX.X.X.1255.255.255.248外部地址#interfaceEthernet0/0/1ipaddress192.168.1.1255.255.255.0内部#interfaceNULL0#aclnumber3001rule5permitipsource192.168.1.00.0.0.255 ACL策略做NAT用aclnumber3002 rule0permitudpsource-porteqbootpsaclnumber3003rule0permitudpsource-po
5、rteqbootps#firewallzonelocal |setpriority10 |# |firewallzonetrust |setpriority85 |addinterfaceEthernet0/0/1 |#firewallzoneuntrust |设置各个区域的安全级别setpriority5addinterfaceEthernet0/0/0 | #firewallzon
6、edmz |setpriority50 |#firewallinterzonelocaltrustpacket-filter3002inboundpacket-filter3003outbound DHCP#firewallinterzonelocaluntrust #firewallinterzonelocaldmz#firewallinterzonetrustuntrustpacket-filter3001inbound natoutbound3001interfaceEthe
7、rnet0/0/0 应用ACL3001关联到外部接口#firewallinterzonetrustdmz#firewallinterzonedmzuntrust#aaalocal-userusg50passwordcipherF=9L.J$Z6=CQ=^Q`MAF4<1!!local-userusg50level3local-userusg50ftp-directoryflash:/authentication-schemedefault TELNET访问密码#authorization-schemedefault#accounting
8、-schemedefault#domaindefault# #dhcpenable#
此文档下载收益归作者所有