某公司内通过在 Device 上配置安全策略实现对内网主机访问 Internet 的控制,仅允许内网用户访问 Internet 的微信应用,并记录安全策略匹配
报文的日志,最终将日志通过快速日志方式输出到日志主机。
图-1 安全策略输出快速日志配置组网图
DMZ配置思路
若需要实现发送安全策略快速日志到日志主机的目的,需要先开启安全策略规则的日志记录功能,再配置输出安全策略快速日志到日志主机。
关键步骤如下:
<Device> system-view
[Device] security-policy ip
[Device-security-policy-ip] rule name trust-untrust
[Device-security-policy-ip-0-trust-untrust] logging enable
[Device-security-policy-ip-0-trust-untrust] quit
[Device] customlog format packet-filter
[Device] customlog host 10.0.1.2 port 514 export packet-filter
配置步骤
1. 配置接口 IP 地址
# 根据组网图中规划的信息,配置各接口的 IP 地址,具体配置步骤如下。
<Device> system-view
[Device] interface gigabitethernet 1/0/1
[Device-GigabitEthernet1/0/1] ip address 10.0.1.1 255.255.255.0
[Device-GigabitEthernet1/0/1] quit
请参考以上步骤配置其他接口的 IP 地址,具体配置步骤略。
2. 配置接口加入安全域
2# 请根据组网图中规划的信息,创建安全域,并将接口加入对应的安全域,具体配置步骤如下。
[Device] security-zone name DMZ
[Device-security-zone-DMZ] import interface gigabitethernet 1/0/1
[Device-security-zone-DMZ] quit
[Device] security-zone name Trust
[Device-security-zone-Trust] import interface gigabitethernet 1/0/2
[Device-security-zone-Trust] quit
[Device] security-zone name Untrust
[Device-security-zone-Untrust] import interface gigabitethernet 1/0/3
[Device-security-zone-Untrust] quit
3. 配置安全策略
# 配置名称为 trust-untrust 的安全策略规则,允许内网用户访问外网的微信应用,并开启记录日志功能,具体配置步骤如下。
[Device] security-policy ip
[Device-security-policy-ip] rule name trust-untrust
[Device-security-policy-ip-0-trust-untrust] source-zone trust
[Device-security-policy-ip-0-trust-untrust] destination-zone untrust
[Device-security-policy-ip-0-trust-untrust] application wechat
[Device-security-policy-ip-0-trust-untrust] logging enable
[Device-security-policy-ip-0-trust-untrust] action pass
[Device-security-policy-ip-0-trust-untrust] quit
# 配置名称为 trust-untrust2 的安全策略规则,禁止内网用户访问外网的其他资源,并开启记录日志功能,具体配置步骤如下。
[Device-security-policy-ip] rule name trust-untrust2
[Device-security-policy-ip-1-trust-untrust2] source-zone trust
[Device-security-policy-ip-1-trust-untrust2] destination-zone untrust
[Device-security-policy-ip-1-trust-untrust2] logging enable
[Device-security-policy-ip-1-trust-untrust2] action drop
[Device-security-policy-ip-1-trust-untrust2] quit
# 配置名称为 loglocalout 的安全策略规则,允许 Device 向日志主机发送快速日志,具体配置步骤如下。
[Device-security-policy-ip] rule name loglocalout
[Device-security-policy-ip-2-loglocalout] source-zone local
3[Device-security-policy-ip-2-loglocalout] destination-zone dmz
[Device-security-policy-ip-2-loglocalout] destination-ip-host 10.0.1.2
[Device-security-policy-ip-2-loglocalout] action pass
[Device-security-policy-ip-2-loglocalout] quit
# 激活安全策略规则的加速功能,具体配置步骤如下。
[Device-security-policy-ip] accelerate enhanced enable
[Device-security-policy-ip] quit
4. 配置快速日志输出功能
# 开启快速日志输出安全策略匹配日志功能,配置将安全策略匹配日志输出到日志主机,具体配置步骤如下。
[Device] customlog format packet-filter
[Device] customlog host 10.0.1.2 port 514 export packet-filter
验证配置
以上配置完成后,可在快速日志主机上接收到设备发送的快速日志
暂无评论