打开端口8,然后就断网了。
#
version 7.1.064, Release 9514P1801
#
sysname H3C
#
context Admin id 1
#
irf mac-address persistent timer
irf auto-update enable
undo irf link-delay
irf member 1 priority 1
#
nat static outbound 10.10.10.1 58.62.172.194 acl 3000 reversible
#
dhcp enable
#
dns proxy enable
dns server 223.5.5.5
dns server 114.114.114.114
#
password-recovery enable
#
vlan 1
#
vlan 1000
#
object-group ip address zhuji
0 network host name ***.***
10 network host name ***.***
#
object-group ip address 核心防火墙
0 network host address 192.168.111.12
#
object-group ip address 酒店
0 network host address 172.16.35.100
#
object-group service 22端口
0 service tcp destination eq 22
#
object-group service 8090端口
0 service tcp destination eq 8090
#
policy-based-route 10 permit node 10
if-match acl 3100
apply next-hop 172.16.36.1 direct
#
interface NULL0
#
interface GigabitEthernet1/0/0
port link-mode route
combo enable copper
ip address 192.168.0.1 255.255.255.0
#
interface GigabitEthernet1/0/1
port link-mode route
combo enable fiber
ip address 10.10.10.1 255.255.255.248
nat hairpin enable
#
interface GigabitEthernet1/0/2
port link-mode route
ip address 192.168.111.1 255.255.255.0
#
interface GigabitEthernet1/0/3
port link-mode route
#
interface GigabitEthernet1/0/4
port link-mode route
#
interface GigabitEthernet1/0/5
port link-mode route
#
interface GigabitEthernet1/0/6
port link-mode route
#
interface GigabitEthernet1/0/7
port link-mode route
ip policy-based-route 10
#
interface GigabitEthernet1/0/8
port link-mode route
description GuideLan Interface
shutdown
ip address 172.16.36.221 255.255.255.0
undo dhcp select server
#
interface GigabitEthernet1/0/9
port link-mode route
description GuideWan Interface
ip address 58.249.2.212 255.255.255.248
dns server 202.96.128.86
dns server 202.96.128.166
nat outbound description GuideNat
nat server protocol tcp global 58.249.2.212 65022 inside 192.168.111.12 22
nat server protocol tcp global 58.249.2.212 65080 inside 172.16.35.100 8090
#
security-zone name Local
#
security-zone name Trust
import interface GigabitEthernet1/0/1
import interface GigabitEthernet1/0/2
#
security-zone name DMZ
#
security-zone name Untrust
import interface GigabitEthernet1/0/8
import interface GigabitEthernet1/0/9
#
security-zone name Management
import interface GigabitEthernet1/0/0
#
scheduler logfile size 16
#
line class aux
user-role network-operator
#
line class console
authentication-mode scheme
user-role network-admin
#
line class vty
user-role network-operator
#
line aux 0
user-role network-admin
#
line con 0
user-role network-admin
#
line vty 0 63
authentication-mode scheme
user-role network-admin
#
ip route-static 0.0.0.0 0 GigabitEthernet1/0/9 58.249.2.209
ip route-static 10.10.10.0 24 10.10.10.2
ip route-static 172.0.0.0 8 10.10.10.2
#
ssh server enable
#
acl basic 2000
rule 0 permit source object-group zhuji
rule 5 permit
#
acl advanced 3000
description NAT
#
acl advanced 3100
rule 0 permit ip source object-group zhuji
#
domain system
#
aaa session-limit ftp 16
aaa session-limit telnet 16
aaa session-limit ssh 16
domain default enable system
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role
#
role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
user-group system
(0)
最佳答案
policy-based-route 10 permit node 10
if-match acl 3100
apply next-hop 172.16.36.1 direct
这条策略看看
(0)
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论