配置如下:
<YW-FW-1>dis cu
#
version 7.1.064, Release 8660P41
#
sysname YW-FW-1
#
clock timezone Beijing add 08:00:00
clock protocol ntp context 1
#
context Admin id 1
#
irf mac-address persistent timer
irf auto-update enable
undo irf link-delay
irf member 1 priority 1
irf member 2 priority 1
#
security-zone intra-zone default permit
#
ospf 1
area 0.0.0.0
#
ip unreachables enable
ip ttl-expires enable
#
dns server 8.8.8.8
dns server 61.139.2.69
dns server 114.114.114.114
#
lldp global enable
#
password-recovery enable
#
vlan 1
#
vlan 14
#
vlan 4094
#
irf-port 1/2
port group interface Ten-GigabitEthernet1/0/20
port group interface Ten-GigabitEthernet1/0/21
#
irf-port 2/1
port group interface Ten-GigabitEthernet2/0/20
port group interface Ten-GigabitEthernet2/0/21
#
object-group service 22
#
object-group service 4433
0 service tcp destination eq 4433
#
interface Route-Aggregation1
description to YW-RT
ip address 10.1.100.2 255.255.255.252
ospf network-type p2p
ospf 1 area 0.0.0.0
#
interface NULL0
#
interface Vlan-interface14
description to SWXWGL
ip address 10.1.100.9 255.255.255.252
ospf network-type p2p
ospf 1 area 0.0.0.0
nat hairpin enable
#
interface Vlan-interface4094
description MAD
mad bfd enable
mad ip address 1.1.1.5 255.255.255.252 member 1
mad ip address 1.1.1.6 255.255.255.252 member 2
#
interface GigabitEthernet1/0/0
port link-mode route
#
interface GigabitEthernet1/0/1
port link-mode route
#
interface GigabitEthernet1/0/2
port link-mode route
#
interface GigabitEthernet1/0/3
port link-mode route
#
interface GigabitEthernet1/0/4
port link-mode route
#
interface GigabitEthernet1/0/5
port link-mode route
#
interface GigabitEthernet1/0/6
port link-mode route
#
interface GigabitEthernet1/0/7
port link-mode route
#
interface GigabitEthernet1/0/8
port link-mode route
#
interface GigabitEthernet1/0/9
port link-mode route
#
interface GigabitEthernet1/0/10
port link-mode route
#
interface GigabitEthernet1/0/11
port link-mode route
#
interface GigabitEthernet1/0/12
port link-mode route
#
interface GigabitEthernet1/0/13
port link-mode route
#
interface GigabitEthernet1/0/22
port link-mode route
#
interface GigabitEthernet1/0/23
port link-mode route
#
interface GigabitEthernet1/0/24
port link-mode route
#
interface GigabitEthernet1/0/25
port link-mode route
#
interface GigabitEthernet1/0/26
port link-mode route
#
interface GigabitEthernet1/0/27
port link-mode route
#
interface GigabitEthernet1/0/28
port link-mode route
#
interface GigabitEthernet1/0/29
port link-mode route
#
interface GigabitEthernet2/0/0
port link-mode route
#
interface GigabitEthernet2/0/1
port link-mode route
#
interface GigabitEthernet2/0/2
port link-mode route
#
interface GigabitEthernet2/0/3
port link-mode route
#
interface GigabitEthernet2/0/4
port link-mode route
#
interface GigabitEthernet2/0/5
port link-mode route
#
interface GigabitEthernet2/0/6
port link-mode route
#
interface GigabitEthernet2/0/7
port link-mode route
#
interface GigabitEthernet2/0/8
port link-mode route
#
interface GigabitEthernet2/0/9
port link-mode route
#
interface GigabitEthernet2/0/10
port link-mode route
#
interface GigabitEthernet2/0/11
port link-mode route
#
interface GigabitEthernet2/0/12
port link-mode route
#
interface GigabitEthernet2/0/13
port link-mode route
#
interface GigabitEthernet2/0/22
port link-mode route
#
interface GigabitEthernet2/0/23
port link-mode route
#
interface GigabitEthernet2/0/24
port link-mode route
#
interface GigabitEthernet2/0/25
port link-mode route
#
interface GigabitEthernet2/0/26
port link-mode route
#
interface GigabitEthernet2/0/27
port link-mode route
#
interface GigabitEthernet2/0/28
port link-mode route
#
interface GigabitEthernet2/0/29
port link-mode route
#
interface M-GigabitEthernet1/0/0
ip address 192.168.0.1 255.255.255.0
#
interface M-GigabitEthernet1/0/1
ip address 192.168.1.1 255.255.255.0
#
interface Ten-GigabitEthernet1/0/15
port link-mode route
description RAGG1
port link-aggregation group 1
#
interface Ten-GigabitEthernet1/0/16
port link-mode route
description RAGG1
port link-aggregation group 1
#
interface Ten-GigabitEthernet1/0/17
port link-mode route
#
interface Ten-GigabitEthernet1/0/18
port link-mode route
#
interface Ten-GigabitEthernet2/0/15
port link-mode route
description RAGG1
port link-aggregation group 1
#
interface Ten-GigabitEthernet2/0/16
port link-mode route
description RAGG1
port link-aggregation group 1
#
interface Ten-GigabitEthernet2/0/17
port link-mode route
#
interface Ten-GigabitEthernet2/0/18
port link-mode route
#
interface Ten-GigabitEthernet1/0/14
port link-mode bridge
description to SWXWGL
port access vlan 14
#
interface Ten-GigabitEthernet1/0/19
port link-mode bridge
description MAD
port access vlan 4094
undo stp enable
#
interface Ten-GigabitEthernet2/0/14
port link-mode bridge
description to SWXWGL
port access vlan 14
#
interface Ten-GigabitEthernet2/0/19
port link-mode bridge
description MAD
port access vlan 4094
undo stp enable
#
interface Ten-GigabitEthernet1/0/20
description IRF
#
interface Ten-GigabitEthernet1/0/21
description IRF
#
interface Ten-GigabitEthernet2/0/20
description IRF
#
interface Ten-GigabitEthernet2/0/21
description IRF
#
interface SSLVPN-AC1
mtu 1400
ip address 10.1.250.254 255.255.255.0
#
security-zone name Local
#
security-zone name Trust
import interface SSLVPN-AC1
import interface Vlan-interface14
#
security-zone name DMZ
#
security-zone name Untrust
import interface Route-Aggregation1
#
security-zone name Management
import interface M-GigabitEthernet1/0/0
import interface M-GigabitEthernet1/0/1
#
scheduler logfile size 16
#
line class console
user-role network-admin
#
line class vty
user-role network-operator
#
line con 0 1
authentication-mode scheme
user-role network-admin
#
line vty 0 63
authentication-mode scheme
user-role network-admin
#
performance-management
#
ssh server enable
#
ntp-service enable
ntp-service source Route-Aggregation1
ntp-service unicast-server 10.1.100.1
#
acl advanced 3000
description SSLVPN
rule 0 permit ip
#
undo password-control blacklist all-line
#
domain system
#
domain default enable system
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role
#
role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
user-group system
#
local-user admin class manage
password hash $h$6$ePLoK9bWPdexk2Ia$5qht8Y5MENJ8ip8+sZRE7vjs4zI++/lru1DiwFQdPfpf3Q96ijMEo4t5qklTZ9CGUWXipDYppqUwQdPpwJrE2Q==
service-type ssh terminal https
authorization-attribute user-role level-3
authorization-attribute user-role network-admin
authorization-attribute user-role network-operator
#
local-user admin class network
password cipher $c$3$uIIFIpZuLsmMm/OWEhgpp2lkYBjvDZZhiWslhTXe
service-type sslvpn
authorization-attribute user-role network-operator
authorization-attribute sslvpn-policy-group SSLVPNZIYUAN
#
ssl renegotiation disable
ssl version ssl3.0 disable
ssl version tls1.0 disable
#
session statistics enable
session synchronization enable
session synchronization dns http
#
ipsec logging negotiation enable
#
ike logging negotiation enable
#
ip https enable
#
loadbalance isp file flash:/lbispinfo_v1.5.tp
#
sslvpn ip address-pool SSLPOOL 10.1.250.1 10.1.250.253
#
sslvpn gateway SSLVPNGW
ip address 10.1.100.2 port 4433
service enable
#
sslvpn context SSLVPN
gateway SSLVPNGW
ip-tunnel interface SSLVPN-AC1
ip-tunnel address-pool SSLPOOL mask 255.255.255.0
ip-tunnel dns-server primary 61.139.2.69
ip-route-list NEIWANG
include 10.0.0.0 255.0.0.0
include 172.16.0.0 255.255.0.0
include 192.168.0.0 255.255.0.0
policy-group SSLVPNZIYUAN
filter ip-tunnel acl 3000
ip-tunnel access-route ip-route-list NEIWANG
service enable
#
security-policy ip
rule 0 name all
action pass
counting enable
source-zone local
source-zone Trust
source-zone Untrust
destination-zone local
destination-zone Trust
destination-zone Untrust
#
cloud-management server domain opstunnel-seccloud.h3c.com
#
return
INdoe能连上,但是无法ping通内网地址,之前配置了之后能正常使用,但是过了一段时间一会手机热点可以正常使用,一会家里的网可以正常使用,但是最近都不能ping通内网了,各位大佬这是为什么呢?
(0)
最佳答案
您好,在出现故障时,可使用dis logbuffer看下防火墙是否有相应的错误日志提示。同时SSL VPN是否能链接上。
另外在故障出现时,查看CPU、内存、接口利用率是否高。同时检查下会话数是否已满。
(0)
是能正常连上,就是不能ping通内网
我来回答,最近跨运营商常常带宽满了就丢包,最近我常常碰到。
测试方法,直接一直ping你的ssl vpn的网关IP(互联网的)、和不通的内网IP。
看是不是内网不通的时候网关IP也不通,如果是,那就是互联网问问题。
打电话投诉相关运营商,不行就工信部投诉。
(0)
ssl vpn的网关一直能通,只是不通内网ip
ssl vpn的网关一直能通,只是不通内网ip
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
是能正常连上,就是不能ping通内网