欢迎来到天天文库
浏览记录
ID:50128714
大小:22.21 KB
页数:7页
时间:2020-03-04
《FortiGate 防火墙常用配置命令.doc》由会员上传分享,免费在线阅读,更多相关内容在行业资料-天天文库。
1、FortiGate常用配置命令一、命令结构 config Configureobject. 对策略,对象等进行配置 get Getdynamicandsysteminformation. 查看相关关对象的参数信息 show Showconfiguration. 查看配置文件 diagnose Diagnosefacility. 诊断命令 execut
2、e Executestaticcommands. 常用的工具命令,如ping exit ExittheCLI. 退出 二、常用命令 1、配置接口地址: FortiGate#configsysteminterface FortiGate(interface)#editlan FortiGate(lan)#setip192.168.100.99/24 FortiGate(lan)#end 2、配置静
3、态路由 FortiGate(static)#edit1 FortiGate(1)#setdevicewan1 FortiGate(1)#setdst10.0.0.0255.0.0.0 FortiGate(1)#setgateway192.168.57.1 FortiGate(1)#end 3、配置默认路由 FortiGate(1)#setgateway192.168.57.1 FortiGate(1)#setdevicewan1 FortiGa
4、te(1)#end 4、添加地址 FortiGate#configfirewalladdress FortiGate(address)#editclientnet newentry'clientnet'added FortiGate(clientnet)#setsubnet192.168.1.0255.255.255.0 FortiGate(clientnet)#end 5、添加ip池 FortiGate(ippool)#editnat-pool
5、 newentry'nat-pool'added FortiGate(nat-pool)#setstartip100.100.100.1 FortiGate(nat-pool)#setendip100.100.100.100 FortiGate(nat-pool)#end 6、添加虚拟ip FortiGate#configfirewallvip FortiGate(vip)#editwebserver newentry'webserver'added
6、FortiGate(webserver)#setextip202.0.0.167 FortiGate(webserver)#setextintfwan1 FortiGate(webserver)#setmappedip192.168.0.168 FortiGate(webserver)#end 7、配置上网策略 FortiGate#configfirewallpolicy FortiGate(policy)#edit1 FortiGate(1)#setsr
7、cintfinternal//源接口 FortiGate(1)#setdstintfwan1 //目的接口 FortiGate(1)#setsrcaddrall //源地址 FortiGate(1)#setdstaddrall //目的地址 FortiGate(1)#setactionaccept //动作 FortiGate(1)#setschedulealways //时间 FortiGate(1)#setserviceALL //服务 FortiGat
8、e(1)#setlogtrafficdisable //日志开关 FortiGate(1)#setnatenable //开启nat end 8、配置映射策略 FortiGate#configfirewallpolicy FortiGate
此文档下载收益归作者所有