@weijianing 大神帮我查一下,我上面的问题在哪里,设备不能上网
<H3C SecPath U200-A>disp cu
version 5.20, Release 5116P02
sysname H3C SecPath U200-A
ftp
server enable
undo
voice vlan mac-address 00e0-bb00-0000
undo
info-center enable
ike
local-name H3C
#
domain default enable system
#
dns resolve
#
telnet server enable
#
time-range xzsw from 00:00 1/1/1970 to 24:00 12/31/2100
#
acl number 3000
rule 0 permit tcp source 0.0.0.0 0 destination 0.0.0.0 0
acl number 3001
rule 0 permit tcp source 0.0.0.0 0 destination 0.0.0.0 0
#
vlan 1
#
vlan 2 to 7
#
radius scheme system
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
pki domain default
crl check disable
#
ike peer nas-h3c_peer
exchange-mode aggressive
pre-shared-key cipher 2z9CfOYzatM7H7BjA44l0Q==
id-type name
nat traversal
#
ike peer nas_h3c_peer
exchange-mode aggressive
pre-shared-key cipher 2z9CfOYzatM7H7BjA44l0Q==
id-type name
nat traversal
#
ipsec proposal nas-h3c_prop
#
ipsec proposal nas_h3c_prop
#
ipsec policy-template nas_h3c_temp 1
ike-peer nas_h3c_peer
proposal nas_h3c_prop
#
ipsec policy nas_h3c_poli 1 isakmp template nas_h3c_temp
#
dhcp server ip-pool 1
network 192.168.1.0 mask 255.255.255.0
gateway-list 192.168.1.254
dns-list 221.228.255.1
#
dhcp server ip-pool 192.168.0.254
network 192.168.0.0 mask 255.255.255.0
gateway-list 192.168.0.254
dns-list 192.168.0.254
#
user-group system
#
local-user admin
password cipher 17<P"%P9-<W/*=IX>V,IWQ!!
authorization-attribute level 3
service-type telnet
#
ssl server-policy default
pki-domain default
#
ddns policy czjsqj
url oray://czjsqj:welcome888888@***.***:
#
interface Dialer5
nat outbound 3001
link-protocol ppp
ppp chap user czz991236
ppp chap password simple 084553
ppp pap local-user czz991236 password simple 084553
ppp ipcp dns request
ip address ppp-negotiate
dialer user pppoeclient
dialer-group 5
dialer bundle 5
ipsec policy nas_h3c_poli
#
interface NULL0
#
interface LoopBack1
#
interface LoopBack2
#
interface Vlan-interface1
ip address 10.168.2.241 255.255.255.0
#
interface Vlan-interface2
#
interface GigabitEthernet0/0
port link-mode route
ip address 192.168.0.254 255.255.255.0
#
interface GigabitEthernet0/1
port link-mode route
ip address 192.168.1.254 255.255.255.0
#
interface GigabitEthernet0/2
port link-mode route
ip address 192.168.2.254 255.255.255.0
#
interface GigabitEthernet0/3
port link-mode route
ip address 192.168.3.254 255.255.255.0
#
interface GigabitEthernet0/4
port link-mode route
ip address 192.168.4.254 255.255.255.0
#
interface GigabitEthernet0/5
port link-mode route
pppoe-client dial-bundle-number 5
ip address 192.168.5.254 255.255.255.0
ddns apply policy czjsqj
#
interface GigabitEthernet1/0
port link-mode route
#
interface GigabitEthernet1/1
port link-mode route
#
interface GigabitEthernet1/2
port link-mode route
#
interface GigabitEthernet1/3
port link-mode route
#
dhcp enable
#
ntp-service source-interface Dialer5
ntp-service refclock-master 127.127.1.1 1
ntp-service unicast-server 120.25.115.20
#
ssh server enable
sftp server enable
#
ip https ssl-server-policy default
ip https enable
#
dialer-rule 5 ip permit
#
load xml-configuration
#
user-interface con 0
user-interface vty 0 4
authentication-mode scheme
#
return
(0)
最佳答案
能否帮忙在有问题的地方帮我命令行改正,在#这里标出我要改的地方,谢谢
只能回答一次,各位大佬麻烦把命令行加上,我这里来改一下
(0)
从配置上来看,配置上有些问题: 1、缺少默认路由指向拨号口、 2、安全域直接没有打通,拨号口应该加到untrust安全域里面,而且安全域直接需要相互打通
从配置上来看,配置上有些问题: 1、缺少默认路由指向拨号口、 2、安全域直接没有打通,拨号口应该加到untrust安全域里面,而且安全域直接需要相互打通
从配置上来看,配置上有些问题:
1、缺少默认路由指向拨号口、
2、安全域直接没有打通,拨号口应该加到untrust安全域里面,而且安全域直接需要相互打通
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明