#
version 7.1.064, Release 8860P18
#
sysname H3C
#
clock protocol none
#
context Admin id 1
#
telnet server enable
#
irf mac-address persistent timer
irf auto-update enable
undo irf link-delay
irf member 1 priority 1
#
nat address-group 0
address 10.7.22.2 10.7.22.2
#
nat log enable
nat log flow-begin
nat log flow-end
#
dns server 8.8.8.8
dns server 114.114.114.114
#
password-recovery enable
#
vlan 1
#
object-group ip address nei
0 network subnet 10.0.10.0 255.255.255.0
#
object-group service 106
0 service tcp destination eq 22106
#
object-group service 107
0 service tcp destination eq 22107
#
object-group service 116
0 service tcp destination eq 8001
#
object-group service 118
0 service tcp destination eq 22118
#
object-group service 119
0 service tcp destination eq 22119
#
object-group service 127
0 service tcp destination eq 22127
#
interface NULL0
#
interface GigabitEthernet1/0/0
port link-mode route
ip address 10.0.10.253 255.255.255.0
#
interface GigabitEthernet1/0/22
port link-mode route
combo enable fiber
ip address 10.7.22.2 255.255.255.0
manage http inbound
manage http outbound
manage https inbound
manage https outbound
manage netconf-http inbound
manage netconf-https inbound
manage netconf-ssh inbound
manage ping inbound
manage ping outbound
manage ssh inbound
manage ssh outbound
manage telnet inbound
manage telnet outbound
#
#
security-zone name Local
#
security-zone name Trust
import interface GigabitEthernet1/0/0
#
security-zone name DMZ
#
security-zone name Untrust
import interface GigabitEthernet1/0/22
#
security-zone name Management
import interface M-GigabitEthernet1/0/0
import interface M-GigabitEthernet1/0/1
#
scheduler logfile size 16
#
line class aux
user-role network-operator
#
line class console
authentication-mode scheme
user-role network-admin
#
#
ip route-static 0.0.0.0 0 GigabitEthernet1/0/22 10.7.22.1
#
info-center loghost 127.0.0.1 port 3301 format default
info-center source CFGLOG loghost level informational
#
performance-management
#
ssh server enable
#
arp ip-conflict log prompt
#
domain system
#
domain default enable system
#
#
ipsec logging negotiation enable
#
nat global-policy
rule name rule1
service 116
source-zone untrust
destination-ip host 10.0.10.116
action dnat ip-address 10.7.22.2 local-port 8001
rule name 118
service 118
source-zone untrust
destination-ip host 10.7.22.2
action dnat ip-address 10.0.10.118 local-port 9528
rule name 119
service 119
source-zone untrust
destination-ip host 10.7.22.2
action dnat ip-address 10.0.10.119 local-port 9528
rule name 106
service 106
source-zone untrust
destination-ip host 10.7.22.2
action dnat ip-address 10.0.10.106 local-port 9528
rule name 107
service 107
source-zone untrust
destination-ip host 10.7.22.2
action dnat ip-address 10.0.10.107 local-port 9528
rule name 127
service 127
source-zone untrust
destination-ip host 10.7.22.2
action dnat ip-address 10.0.0.127 local-port 9528
rule name 104to224
action snat address-group 0
#
ike logging negotiation enable
#
ip https enable
#
loadbalance isp file sda0:/lbispinfo_v1.5.tp
#
security-policy ip
rule 0 name untrust-trust
action pass
source-zone untrust
destination-zone trust
destination-ip-host 10.0.10.106
destination-ip-host 10.0.10.107
destination-ip-host 10.0.10.116
destination-ip-host 10.0.10.118
destination-ip-host 10.0.10.119
destination-ip-host 10.0.10.127
rule 1 name trust-untrust
action pass
source-zone trust
destination-zone untrust
rule 2 name untrust-local
action pass
source-zone Untrust
destination-zone Local
rule 3 name trust-local
action pass
source-zone Trust
destination-zone Local
#
cloud-management server domain opstunnel-seccloud.h3c.com
#
return
下接一个傻瓜交换机,其他设备没了