WEB管理页面无法访问哪里设置有问题
hostname XX-ACG230-0067
switch keep-order auto
authorized-table admin
description Default authority table with all authority enable
authorized read all
authorized write all
!
authorized-table audit
description Default authority table used for audit administrator
authorized read all
!
app-file-size threshold 10
app-file-num threshold 100000
app-file-space threshold 30
app-file-write-sleep 30
app-file-write-timeout threshold 5
https audit predefine
application bypass memory threshold 85
ucc enable
ucc bypass enable
!user-am
!
!user-srun
!
!user-sols
!
admin password 8
user administrator admin local secret spyt9AaM6JCdBtHcV9+t3kz2jih0g1RT8aNe/5zNKAlD5NDdwSLpDlcO1tj4/CC authorized-table admin
user administrator admin authorized-address first 0.0.0.0/0
user administrator dnms local secret bPSfs3ABs877qlkybwDNOLVhgJQgXBlKdm5Tkt3feyZ4bPZJPHQgrOJMANPGWsC authorized-table admin
user administrator dnms authorized-address first 0.0.0.0/0
user administrator h3cyunwei local secret dTpa8US1TtdQSgdV3Hr/TA7rdBP8pToGSWV0sE7lXKzHnbINoWUyjS+ptNFYczJ authorized-table admin
user administrator h3cyunwei authorized-address first 0.0.0.0/0
user administrator h3cyunwei force-chgpwd 1
radius nas-port-type ethernet
!
app-ident mode smart
!policy-group
timezone 57
ntp ***.*** 5
ntp auxiliary time.asia.apple.com
!
ftp timeout 5
wxfj-place 64
!
admin encrypt_auth disable
!
pki ca crl update-period 30
!
!
!
!
lcd sceensaver timer 60 1
!
https port 22443
!
!
application bypass threshold 80
application session change user enable
application terminal identify enable
app-ident nego-timer sip 60
app-ident nego-timer h323 60
app-ident nego-timer h245 60
interface bvi1
allow access https
allow access ping
allow access ssh
allow access center-monitor
!
interface ge0
ip address 192.168.200.200/24
allow access https
allow access http
allow access ping
!
interface ge1
!
interface ge2
description T-联髯专线
traffic-mode extern
ip address 125.40.199.248/24
allow access https
allow access ping
allow access center-monitor
!
interface ge3
!
interface ge4
!
interface ge5
!
interface ge6
!
interface ge7
!
interface ge8
!
interface ge9
!
interface ge10
!
interface ge11
!
interface ge12
description T-网肚
ip address 10.10.10.1/24
allow access https
allow access http
allow access ping
allow access ssh
allow access telnet
allow access center-monitor
!
interface ge13
description To-F1000-G7
ip address 10.10.20.2/24
allow access https
allow access http
allow access ping
allow access ssh
allow access telnet
allow access center-monitor
!
!address
!
address officeIP
ip subnet 10.10.0.0/19
!
!address6
!
!address-group
!
!service
!
service 40443
tcp dst-port 40443 40443 src-port 0 65535
!
service 6331
tcp dst-port 6331 6331 src-port 0 65535
!
service 2212
tcp dst-port 2212 2212 src-port 0 65535
!
service 2233
tcp dst-port 2233 2233 src-port 0 65535
!
service 12443
tcp dst-port 12443 12443 src-port 0 65535
!
service 22443
tcp dst-port 22443 22443 src-port 0 65535
!
!service-group
!
!schedule-day
!
!schedule-week
!
!schedule-month
!
!schedule-once
!
!user-group
!
!
!user
!
!
!attribute-group
!
!
!user-policy
!
user-policy listen authentication disable
user-policy https-portal enable
!user-syn
!
sync-task start
sync-task end
!zone
!
!
!
!
!
!track
!
!
!track-group
!
!
!
!
sslvpn dup-login disable
sslvpn disable
sslvpn keepalive 10 12
sslvpn security disable
!sslvpn-resource
!sslvpn-user-ip-binding
!policy route
proute rematch enable
!
policy default-action permit
policy white-list enable
!
!policy-decrypt
!
sslproxy-optimize disable
policy listen block disable
policy analyze daily
policy analyze disable
!
audit_policy any any any any any always web_access any 1
audit-behaviour network_community
audit-behaviour web_search
audit-behaviour send_web_mail
audit-behaviour http_send_file
audit-behaviour http_download_file
audit-behaviour send_mail
audit-behaviour receive_mail
audit-behaviour im_audit
audit-behaviour ftp
audit-behaviour recreation
audit-behaviour stock
audit-behaviour other_app
audit-behaviour im_web_weixin
audit-behaviour im_feixin
audit-behaviour im_other
audit-behaviour receive_web_mail
audit-behaviour web_mail_upload_attachment
audit-behaviour web_mail_download_attachment
audit-behaviour web_disk_upload_file
audit-behaviour web_disk_download_file
other-app category IM_Software
other-app category P2P_Software
other-app category Online_Game
other-app category File_Transfer
other-app category Search_Engine
other-app category Network_Community
other-app category Database_Software
other-app category Ecommerce
other-app category Network_Protocol
other-app category E_Mail
other-app category Remote_Control
other-app category Life_Services
other-app category Network_Proxy
other-app category Enterprise_Software
other-app category Software_Update
other-app category Other_Software
other-app category Finance_Login
other-app category Finance_Info
other-app category Finance_Deal
other-app category P2P_Media
other-app category Other_Media
other-app category Cloud_Storage
other-app category Weibo
other-app category Portals
other-app category Recruit_Info
other-app category Literature_Info
other-app category Electric_Bank
other-app category Virtual_Currency
log level info
audit associate enable
!
snmp
community secret fMIV/kvbDP5P1yuvINib/U9TNjKZb7kAlnq3/02zcAN/1YW3x/UoQsxoXHgymNF
write-community secret fMIV/kvbDP5F+OqSEFgwUV7mX9Udx0KbZT+XnYqEBwiIw11onNoVtciBKMTRYZ0
syslocation Hangzhou, China
syscontact New H3C Tech. Co., Ltd.
!
dhcp
!
report
set storage space 137 percent 80
set global rank_user 50 week_start sunday
!
!
ip route 0.0.0.0/0 125.40.199.1
ip route 10.10.0.0/19 10.10.20.1
ip route 10.10.11.0/24 10.10.20.1
ip route 10.10.12.0/24 10.10.20.1
ip route 10.10.13.0/24 10.10.20.1
ip route 10.10.14.0/24 10.10.20.1
ip route 10.10.15.0/24 10.10.20.1
ip route 10.10.16.0/24 10.10.20.1
ip route 10.10.17.0/24 10.10.20.1
ip route 10.10.18.0/24 10.10.20.1
ip route 10.10.19.0/24 10.10.20.1
!
route rcache-inherit enable
!
mllb session-persistence enable
smtp-config
ssl enable
!
auto-update
update enable
weekly sun mon tue wed thu fri sat
time hour 23 minute 0
!auto-execute
!
!
tcpstack enable
sip flush expectation disable
!user-param
!
user-param threshold 10000
user mac-sensitive enable
!user-webauth
!
user-webauth jump-access-web
!user-wechat
!
user-wechat name-type ip
!user-portal-server
!
user-portal-server mac-sensitive enable
!user-portal-escape
!
!user-sso
!
user-adsso timeouts 3
no user-adsso key
!user-imc
!
!user-app-server
!
!user-sms-server
!
user-sms jump-access-web
!user-mix-server
!
user-mix jump-access-web
!
!user-qrcode-auth
user-qrcode audit-type indirectly
user-qrcode jump-access-web
!
!user-free-server
!
user-free jump-access-web
pppoe user-snooper age 15
user-radius-listen disable
user-radius-listen authentication port 1812
user-radius-listen accounting port 1813
!
user-web-listen group /authen-method/Web-user
user-web-listen check success
!
user-radius-listen timeout 15
!urlcate_user_label_switch
!
!urlcate_user_label_imc
!
!urlcate_user_label
!
!ip session limit
!
dns disable
dns proxy disable
dns cache disable
dns session disable
dns proxy balance priority
dns server 114.114.114.114 202.102.224.68
!
ddns disable
!
ip nat source port fast-match enable
ip nat pool unreach-route enable
ip nat clean-mode smart
ip nat pool 10.10.20.254
ip address 10.10.20.254 10.10.20.254
ip nat pool 10.10.20.1
ip address 10.10.20.1 10.10.20.1
ip nat pool 10.10.20.2
ip address 10.10.20.2 10.10.20.2
!
ip nat source ge2 any any any interface 1
!
!
ip nat destination ge2 any any 12443 10.10.20.254 service 443 1
!
!
!
!
wxfj-upload-encryp enable
!
wxfj-rzx-cszt disable
!
wxfj-pass-switch disable
!
anony_user log disable
ap ipmac enable
!
!flow-account
!
log servconn_policy server disable
log server addr 39.102.233.5
log server port 515
log server enable
!
set dplog time disable
set dplog send time 23
!
!interface track
!
!
!rzx gam-audit
!
!
user-share check disable
user-share action disable
user-share terminal-count 2
user-share log switch off
!service-quality
!
!
alarm-email disable
!
alarm-email quote disable
!
user-radius-ap-mac disable
!
!
assets disable
!
brute-force service oracle 60 120
brute-force service mysql 60 120
brute-force service postgres 60 120
brute-force service mssql 60 120
!
!
cloud url ***.***
cloud https port 8443
cloud protocol https
cloud type cmtunnel
!
!
!
policy6 default-action permit
!
ha-config
!
!
!ads-obj
!
!
!
!ad-policy
!
!
server-out-connect study num 500
mobile-manage
disable
trust-user disable
freeze disable
frozen-time 5
!
behavior-model
!
!end
根据你提供的配置,Web页面无法访问的问题,很可能出在接口配置和路由上。以下是为您整理的排查思路,你可以按照这个顺序逐一检查。
这是最基础的一点。你提供的配置显示,interface ge0、ge12、ge13等接口都已配置了allow access https和http,这说明从配置上看,Web访问是放通的。
确认管理地址:设备管理口(ge0)的默认地址是 192.168.1.1/24,默认允许 HTTPS 访问。请确保你尝试访问的是正确的接口IP。
确认访问协议:ACG1000的Web管理界面仅支持HTTPS方式登录,请检查你访问时是否使用了 https:// 前缀。
这是你当前配置中最可能存在问题的地方。
检查路由表:你从办公网访问设备,数据包的往返路径必须一致且可达。
从办公网(如 10.10.0.0/19)访问设备某个接口IP(如 10.10.10.1)时,请求数据包能到达设备。
但设备回复的数据包呢? 查看你的静态路由:
这条路由意味着,设备在回复来自办公网的请求时,会将回包全部扔给下一跳 10.10.20.1。
问题可能就在这里:你需要确认 10.10.20.1 这个网关,是否有正确的路由能将数据包送回你的办公电脑。如果这个网关的路由配置有误,你的浏览器就永远收不到设备的回应,表现为“无法访问”。
检查连通性:在办公电脑上执行 ping 和 tracert,确认到设备IP的网络路径是通的。
有时问题出在终端上,建议进行以下尝试:
检查管理员IP限制:配置中的 user administrator admin authorized-address first 0.0.0.0/0 表示未限制登录IP。但请确认是否有其他访问控制列表(ACL)或策略限制了你的IP。
检查并发会话数:设备默认的Web管理员登录会话数有限,如果之前有未注销的会话,可能导致新登录失败。
尝试重启:如果以上都无效,且设备在运行中,可以尝试通过Console口重启设备,看是否能恢复Web访问。
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论