#
version 5.20, Release 3731
#
sysname F1000-S
#
password-control login-attempt 5 exceed lock-time 15
#
super password level 3 cipher $c$3$T7OVjWCpqyAZ/hsPF+58cW//dfADDH8uuXwNYpUdOw==
#
#
undo voice vlan mac-address 00e0-bb00-0000
#
domain default enable system
#
dns resolve
dns server 222.172.200.68
dns server 61.166.150.123
#
router id 1.2.3.4
#
ip http acl 2000
ip http port 1025
#
undo alg dns
undo alg rtsp
undo alg h323
undo alg sip
undo alg sqlnet
undo alg pptp
undo alg ils
undo alg nbt
undo alg msn
undo alg qq
undo alg tftp
undo alg sccp
undo alg gtp
#
session synchronization enable
#
password-recovery enable
#
blacklist enable
#
acl number 2000
rule 5 permit source 192.168.0.0 0.0.255.255
acl number 2001
rule 5 permit source 192.168.0.0 0.0.255.255
#
acl number 3000
rule 5 permit ip source 192.168.0.0 0.0.255.255 destination 114.117.123.52 0
#
vlan 1
#
vlan 504
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
public-key peer 192.168.10.253
public-key-code begin
308201B83082012C06072A8648CE3804013082011F02818100D757262C4584C44C211F18BD
96E5F061C4F0A423F7FE6B6B85B34CEF72CE14A0D3A5222FE08CECE65BE6C265854889DC1E
DBD13EC8B274DA9F75BA26CCB987723602787E922BA84421F22C3C89CB9B06FD60FE01941D
DD77FE6B12893DA76EEBC1D128D97F0678D7722B5341C8506F358214B16A2FAC4B36895038
7811C7DA33021500C773218C737EC8EE993B4F2DED30F48EDACE915F0281810082269009E1
4EC474BAF2932E69D3B1F18517AD9594184CCDFCEAE96EC4D5EF93133E84B47093C52B20CD
35D02492B3959EC6499625BC4FA5082E22C5B374E16DD00132CE71B020217091AC717B6123
91C76C1FB2E88317C1BD8171D41ECB83E210C03CC9B32E810561C21621C73D6DAAC028F4B1
585DA7F42519718CC9B09EEF0381850002818100CA031B87B5FB5F1E4420FF01A16AEF80A6
7B0BB07EEEC8BD055D7E815B2C7B3D8055EE031B34116BC338DB15DB7367C6107CCC79DD62
22E68EDD3F494D2DA64BB783EA9BBCB1CF7CD46ABDAFEB949B4AFDA7DD796C0EFEC54F1F7D
FFF7057D345A7DFD6CC2D4FC3B282C25DC2A850851E181E53D4E9245C532A33BE46BE60521
public-key-code end
peer-public-key end
#
pki domain default
crl check disable
#
user-group system
group-attribute allow-guest
#
local-user mzzwgl
password cipher $c$3$2SzRsHQvvH5VxM68FWlEgPPxyoqJ1lmeVX6QSFXM
authorization-attribute level 3
service-type ssh terminal
service-type web
local-user mzzwmo
password cipher $c$3$i2S1C2Ql/iWptPBdCqg6vBbe2mmyWgBHjT1MShBb
authorization-attribute level 1
service-type ssh terminal
service-type web
local-user mzzwvi
password cipher $c$3$gdw0TeEODUKBcBH0yrDG4HP7hAhxWtsz406lD/AB
service-type ssh terminal
service-type web
#
interface NULL0
#
interface GigabitEthernet0/0
port link-mode route
ip address 192.168.0.1 255.255.255.0
#
interface GigabitEthernet0/1
port link-mode route
description TO-WAN
nat outbound 2000
nat server protocol tcp global 114.117.123.52 www inside 192.168.16.249 www
nat server protocol tcp global 114.117.123.52 43794 inside 192.168.10.100 443
nat server protocol tcp global 114.117.123.52 43793 inside 172.16.0.2 443
combo enable fiber
ip address 114.117.123.52 255.255.255.240
#
interface GigabitEthernet0/2
port link-mode route
description TO-S7506E
nat outbound 2000
nat server protocol tcp global 114.117.123.52 www inside 192.168.16.249 www
combo enable fiber
ip address 192.168.10.254 255.255.255.0
#
interface GigabitEthernet0/3
port link-mode route
description TO-ZhengWuJu
nat outbound 2001
combo enable fiber
ip address 59.216.111.3 255.255.255.248
#
interface GigabitEthernet0/3.1
vlan-type dot1q vid 504
ip address 10.254.254.158 255.255.255.252
#
interface GigabitEthernet0/4
port link-mode route
combo enable fiber
#
interface GigabitEthernet0/5
port link-mode route
ip address 10.254.171.254 255.255.255.0
#
interface GigabitEthernet0/6
port link-mode route
#
interface GigabitEthernet0/7
port link-mode route
#
interface GigabitEthernet0/8
port link-mode route
#
interface GigabitEthernet0/9
port link-mode route
#
interface GigabitEthernet0/10
port link-mode route
#
interface GigabitEthernet0/11
port link-mode route
#
vd Root id 1
#
zone name Management id 0
priority 100
import interface GigabitEthernet0/0
zone name Local id 1
priority 100
zone name Trust id 2
priority 85
import interface GigabitEthernet0/2
import interface GigabitEthernet0/3
import interface GigabitEthernet0/3.1
import interface GigabitEthernet0/5
zone name DMZ id 3
priority 50
zone name Untrust id 4
priority 5
import interface GigabitEthernet0/1
switchto vd Root
object network host budongchan-web-server
host address 172.16.0.2
host address 192.168.10.100
host address 192.168.16.249
object service mstsc
service tcp destination-port 111
zone name Management id 0
ip virtual-reassembly
zone name Local id 1
ip virtual-reassembly
zone name Trust id 2
ip virtual-reassembly
zone name DMZ id 3
ip virtual-reassembly
zone name Untrust id 4
ip virtual-reassembly
interzone source Trust destination Untrust
rule 0 permit
comment lan-to-wan
source-ip any_address
destination-ip any_address
service any_service
rule enable
interzone source Untrust destination Trust
rule 0 permit logging
comment wan-to-lan
source-ip any_address
destination-ip budongchan-web-server
service any_service
rule enable
#
ip route-static 0.0.0.0 0.0.0.0 114.117.123.33
ip route-static 0.0.0.0 0.0.0.0 59.216.111.1 preference 80
ip route-static 10.254.0.0 255.255.0.0 10.254.254.157 preference 80
ip route-static 172.16.0.0 255.255.255.252 192.168.10.253
ip route-static 192.168.0.0 255.255.0.0 192.168.10.253
ip route-static 192.168.55.0 255.255.255.0 59.216.111.1
#
info-center loghost source GigabitEthernet0/2
info-center loghost 192.168.10.100
#
ssh server enable
ssh client authentication server 192.168.10.253 assign publickey 192.168.10.253
#
ip https enable
#
load xml-configuration
#
load tr069-configuration
#
user-interface con 0
user-interface vty 0 4
authentication-mode scheme
idle-timeout 5 0
#
return
以上为f1000-s防火墙配置,以前可以通过:https:\\114.117.123.52 登录,或者通过管理口http:\\192.168.0.1登录,感觉配置没有动过,怎么现在用上面哪两个地址却登不了web了呢?
(0)
最佳答案
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明