<H3C>dis cu
# version 5.20, Release 2311, Basic
#
sysname H3C
#
nat address-group 1 172.18.136.24 172.18.136.24 配置IP地址池1
#
domain default enable system
#
telnet server enable
#
dar p2p signature-file cfa0:/p2p_default.mtd
#
port-security enable
#
undo ip http enable
#
acl number 3000 配置访问控制列表3000
rule 0 permit ip source 172.16.1.0 0.0.0.255 仅允许内部网络中172.16.1.0 0.0.0.255网段的用户可以访问Internet。
#
vlan 1
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
user-group system
group-attribute allow-guest
#
local-user admin
password cipher $c$3$ZjPtj+Oe+oEiqWDR74o699KIju1RhhkP
authorization-attribute level 3
service-type telnet
#
interface Aux0
async mode flow
link-protocol ppp
#
interface Cellular0/0
async mode protocol
link-protocol ppp
#
interface Ethernet0/0
port link-mode route
ip address 10.0.0.1 255.255.255.252
#
interface Ethernet0/1
port link-mode route
nat outbound 3000 address-group 1 在出接口Ethernet0/1上配置ACL 2001与IP地址池1相关联。
ip address 172.18.136.24 255.255.255.0
#
interface Virtual-Ethernet1
ip address 172.16.1.4 255.255.255.0
#
interface NULL0
#
ip route-static 0.0.0.0 0.0.0.0 172.18.136.1
ip route-static 172.16.1.0 255.255.255.0 10.0.0.2
#
snmp-agent
snmp-agent local-engineid 800063A20374258A3685C8
snmp-agent community write public
snmp-agent community read private
snmp-agent sys-info version all
#
dhcp enable
#
load xml-configuration
#
user-interface con 0
user-interface tty 13
user-interface aux 0
user-interface vty 0 4
authentication-mode scheme
#
return
(0)
最佳答案
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论