[H3C]dis cu # version 5.20, Release 5501P36 # sysname H3C # irf mac-address persistent timer irf auto-update enable undo irf link-delay # domain default enable system # mirroring-group 1 local # password-recovery enable # ip vpn-instance DMZ_VPN # acl number 3100 rule 5 deny tcp destination-port eq 135 rule 10 deny tcp destination-port eq 137 rule 15 deny tcp destination-port eq 138 rule 20 deny tcp destination-port eq 139 rule 25 deny tcp destination-port eq 445 rule 30 deny tcp destination-port eq 3389 rule 35 deny udp destination-port eq 135 rule 40 deny udp destination-port eq netbios-ns rule 45 deny udp destination-port eq netbios-dgm rule 50 deny udp destination-port eq netbios-ssn rule 55 deny udp destination-port eq 445 rule 60 deny udp destination-port eq 3389 rule 65 deny tcp destination-port eq ftp rule 70 deny tcp destination-port eq telnet rule 75 deny tcp destination-port eq www rule 80 deny tcp destination-port eq smtp rule 85 deny udp destination-port eq 21 rule 90 deny udp destination-port eq 23 rule 95 deny udp destination-port eq 80 rule 100 deny udp destination-port eq 25 rule 105 deny tcp destination-port eq login rule 110 deny udp destination-port eq who # vlan 1 # vlan 10 # vlan 20 description OMS1.0&sanke # domain system access-limit disable state active idle-cut disable self-service-url disable # traffic classifier anti-GWDK operator and if-match acl 3100 traffic classifier anti_GWDK operator and # traffic behavior anti_GWDK1 filter deny # qos policy anti_GWDK2 classifier anti_GWDK behavior anti_GWDK1 # user-group system group-attribute allow-guest # local-user DyLdgfz password cipher $c$3$2wb+sOIxz1yCkvA+yAGTgK+jXkK3PqY3Cq73vwUt service-type ssh local-user DyLdgfz01 password cipher $c$3$oN8J8HWfjEll7V/+MAQByj6XP2K8TvbstOKH4T0m authorization-attribute user-role security-audit service-type terminal local-user DyLdgfz02 password cipher $c$3$uRgYhpNMozOckT9uhKKX6l3p3aPi4+pjJ5eljGAg authorization-attribute level 3 service-type ssh terminal # ssh server enable undo ssh server compatible-ssh1x ssh user DyLdgfz service-type stelnet authentication-type password # load xml-configuration # load tr069-configuration # user-interface aux 0 authentication-mode password set authentication password cipher $c$3$FsLwDfDiOQRYFvEb+19z3sp3HViXyo/jPuc7zMLu user-interface vty 0 4 authentication-mode scheme user privilege level 3 protocol inbound ssh user-interface vty 5 15 # return
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论