zone name Management id 0
priority 100
import interface GigabitEthernet0/2
zone name Local id 1
priority 100
zone name Trust id 2
priority 85
import interface Vlan-interface11
zone name DMZ id 3
priority 50
zone name Untrust id 4
priority 5
import interface Vlan-interface10
switchto vd Root
object service ms_rpc_epm
service tcp destination-port 135
zone name Management id 0
ip virtual-reassembly
zone name Local id 1
ip virtual-reassembly
zone name Trust id 2
ip virtual-reassembly
zone name DMZ id 3
ip virtual-reassembly
zone name Untrust id 4
ip virtual-reassembly
interzone source Trust destination Untrust
rule 0 permit
source-ip any_address
destination-ip any_address
service any_service
rule enable
interzone source Untrust destination Trust
rule 1 deny logging
source-ip any_address
destination-ip any_address
service ms_rpc_epm
service nbname
service netbios-tcp
service netbios-udp
service smb
rule enable
rule 0 permit
source-ip any_address
destination-ip any_address
service any_service
rule enable
从核心交换机里的一个防火墙板卡 扒的数据,之前是V5版本的,现在要换成V7版本的,这几个是什么意思,怎么配置V7
(0)
最佳答案
域间策略
参考:
security-zone name Management
import interface GigabitEthernet0/2
#
security-zone name Local
#
security-zone name Trust
import interface Vlan-interface11
#
security-zone name DMZ
#
security-zone name Untrust
import interface Vlan-interface10
#
object-group service ms_rpc_epm
0 service tcp destination eq 135
#
security-policy ip
rule 0 name Trust_Untrust_0
action pass
source-zone Trust
destination-zone Untrust
rule 10 name Untrust_Trust_1
action drop
source-zone Untrust
destination-zone Trust
service ms_rpc_epm
service nbname
service netbios-tcp
service netbios-udp
service smb
rule 20 name Untrust_Trust_0
action pass
source-zone Untrust
destination-zone Trust
#
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论