暂无评论
system-view
security-zone name ZONE-A
import interface GigabitEthernet 0/0
security-zone name ZONE-B
import interface GigabitEthernet 0/1
acl advanced 3000
# A→B禁止ping:拒绝ICMP请求报文
rule deny icmp source 192.168.0.0 0.0.0.255 destination 192.168.1.0 0.0.0.255 echo
# B→A禁止ping:反向也拦截
rule deny icmp source 192.168.1.0 0.0.0.255 destination 192.168.0.0 0.0.0.255 echo
# 放行TCP/UDP等业务流量
rule permit ip source 192.168.0.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
rule permit ip source 192.168.1.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
# ZONE-A去往ZONE-B调用ACL
zone-pair security source ZONE-A destination ZONE-B
packet-filter acl 3000 inbound
# ZONE-B去往ZONE-A调用同一条ACL
zone-pair security source ZONE-B destination ZONE-A
packet-filter acl 3000 inbound
security-policy ip
# A→B禁ping,全通业务
rule 1 name A-B-NO-PING
source-zone ZONE-A
destination-zone ZONE-B
source-address 192.168.0.0 mask 255.255.255.0
destination-address 192.168.1.0 mask 255.255.255.0
service icmp echo
action deny
rule 2 name A-B-ALLOW-OTHER
source-zone ZONE-A
destination-zone ZONE-B
source-address 192.168.0.0 mask 255.255.255.0
destination-address 192.168.1.0 mask 255.255.255.0
action permit
# B→A反向配置
rule 3 name B-A-NO-PING
source-zone ZONE-B
destination-zone ZONE-A
source-address 192.168.1.0 mask 255.255.255.0
destination-address 192.168.0.0 mask 255.255.255.0
service icmp echo
action deny
rule 4 name B-A-ALLOW-OTHER
source-zone ZONE-B
destination-zone ZONE-A
source-address 192.168.1.0 mask 255.255.255.0
destination-address 192.168.0.0 mask 255.255.255.0
action permit
display zone-pair security filter
display acl 3000
display security-policy hit
暂无评论
system-view
# 自定义两个安全域(不要混用trust/untrust,方便管控)
zone name Zone0
zone-member interface GigabitEthernet 0/0
zone name Zone1
zone-member interface GigabitEthernet 0/1
display zone,确认接口在对应域内。V7 域间策略必须双向配置:Zone0→Zone1、Zone1→Zone0,只配单方向 Ping 照样通(ICMP 请求 + 应答来回两条流量)H3C。
# 1、创建高级ACL匹配ICMP(ping)
acl advanced 3000
rule deny icmp source 192.160.0.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
rule permit ip source 192.160.0.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
acl advanced 3001
rule deny icmp source 192.168.1.0 0.0.0.255 destination 192.160.0.0 0.0.0.255
rule permit ip source 192.168.1.0 0.0.0.255 destination 192.160.0.0 0.0.0.255
# 2、域间策略绑定ACL(关键:双向两个域间实例)
interzone policy source Zone0 destination Zone1
packet-filter acl 3000
interzone policy source Zone1 destination Zone0
packet-filter acl 3001
规则逻辑:先 deny ICMP,再 permit 所有 IP,其余 TCP/UDP 业务正常通行,仅干掉 ping。
# 进入两个域间视图关闭ICMP的ASPF探测
interzone policy source Zone0 destination Zone1
undo aspf apply all
interzone policy source Zone1 destination Zone0
undo aspf apply all
ASPF 开启后:源侧发 ICMP 请求,防火墙自动生成回程放行规则,域间 deny 无效H3C。
display interzone policy all
# 查看default默认策略,不能是permit ip any any
interzone policy default
packet-filter default deny
display session table verbose source 192.160.0 destination 192.168.1 icmp
# 无ICMP会话=策略生效;有会话=策略没匹配
security-policy ip
rule 1 drop source-zone Zone0 destination-zone Zone1 service icmp
rule 2 pass source-zone Zone0 destination-zone Zone1
rule 3 drop source-zone Zone1 destination-zone Zone0 service icmp
rule 4 pass source-zone Zone1 destination-zone Zone0
D022 及以后版本支持 security-policy,D012 老版本只能用 interzone+acl 方案。
acl advanced 3000
rule deny icmp source 192.160.0.0 0.0.0.255 destination 192.168.1.0 0.0.0.255 echo-request
rule permit ip any any暂无评论
1display current-configuration | include security-policysecurity-policy disable:说明设备当前正在使用域间策略模式。你需要在域间策略中进行配置(见步骤2)。Trust 域,1 口在 Untrust 域,配置如下:1<H3C> system-view
2# 1. 创建一条高级ACL,匹配ICMP协议(Ping的底层协议)
3[H3C] acl advanced 3000
4[H3C-acl-ipv4-adv-3000] rule 0 deny icmp
5[H3C-acl-ipv4-adv-3000] quit
6
7# 2. 创建域间策略,并引用该ACL
8[H3C] object-policy ip Trust-Untrust-Deny-Ping
9[H3C-object-policy-ip-Trust-Untrust-Deny-Ping] rule 1 deny
10[H3C-object-policy-ip-Trust-Untrust-Deny-Ping] rule 1 match acl 3000
11[H3C-object-policy-ip-Trust-Untrust-Deny-Ping] quit
12
13# 3. 将策略应用在 Trust 到 Untrust 的域间(双向均需配置才能彻底禁Ping)
14[H3C] zone-pair security source Trust destination Untrust
15[H3C-zone-pair-security-Trust-Untrust] object-policy apply ip Trust-Untrust-Deny-Ping
16[H3C-zone-pair-security-Trust-Untrust] quit
17
18[H3C] zone-pair security source Untrust destination Trust
19[H3C-zone-pair-security-Untrust-Trust] object-policy apply ip Trust-Untrust-Deny-Ping
20[H3C-zone-pair-security-Untrust-Trust] quit1<H3C> system-view
2# 1. 切换到安全策略模式(如果当前是域间策略模式)
3[H3C] undo security-policy disable
4
5# 2. 创建安全策略,直接拒绝 Trust 和 Untrust 之间的 ICMP 流量
6[H3C] security-policy ip
7[H3C-security-policy-ip] rule name Deny-Ping-Trust-Untrust
8[H3C-security-policy-ip-0-Deny-Ping-Trust-Untrust] action deny
9[H3C-security-policy-ip-0-Deny-Ping-Trust-Untrust] source-zone Trust
10[H3C-security-policy-ip-0-Deny-Ping-Trust-Untrust] destination-zone Untrust
11[H3C-security-policy-ip-0-Deny-Ping-Trust-Untrust] service icmp
12[H3C-security-policy-ip-0-Deny-Ping-Trust-Untrust] quit
13
14# 3. 配置反向策略(Untrust 到 Trust)
15[H3C-security-policy-ip] rule name Deny-Ping-Untrust-Trust
16[H3C-security-policy-ip-1-Deny-Ping-Untrust-Trust] action deny
17[H3C-security-policy-ip-1-Deny-Ping-Untrust-Trust] source-zone Untrust
18[H3C-security-policy-ip-1-Deny-Ping-Untrust-Trust] destination-zone Trust
19[H3C-security-policy-ip-1-Deny-Ping-Untrust-Trust] service icmp
20[H3C-security-policy-ip-1-Deny-Ping-Untrust-Trust] quitaction pass(允许)且范围更大的策略(例如 any to any 全放通)。如果有,禁 Ping 策略将永远不会被匹配到,你需要调整策略的优先级顺序。source-zone Trust destination-zone Local 的放通策略。暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论