• 全部
  • 经验案例
  • 典型配置
  • 技术公告
  • FAQ
  • 漏洞说明
  • 全部
  • 全部
  • 大数据引擎
  • 知了引擎
产品线
搜索
取消
案例类型
发布者
是否解决
是否官方
时间
搜索引擎
匹配模式
高级搜索

ACG1000 AK230WEB页面无法访问

1天前提问
  • 0关注
  • 0收藏,48浏览
粉丝:0人 关注:0人

问题描述:

WEB管理页面无法访问哪里设置有问题

hostname XX-ACG230-0067

switch keep-order auto

authorized-table admin

    description Default authority table with all authority enable

    authorized read all

    authorized write all

!

authorized-table audit

    description Default authority table used for audit administrator

    authorized read all

!

app-file-size threshold  10

app-file-num threshold 100000

app-file-space threshold 30

app-file-write-sleep 30

app-file-write-timeout threshold 5

https audit predefine

application bypass memory threshold 85

ucc enable

ucc bypass enable

!user-am

!

!user-srun

!

!user-sols

!

admin password 8

user administrator admin local secret spyt9AaM6JCdBtHcV9+t3kz2jih0g1RT8aNe/5zNKAlD5NDdwSLpDlcO1tj4/CC authorized-table admin

user administrator admin authorized-address first 0.0.0.0/0

user administrator dnms local secret bPSfs3ABs877qlkybwDNOLVhgJQgXBlKdm5Tkt3feyZ4bPZJPHQgrOJMANPGWsC authorized-table admin 

user administrator dnms authorized-address first 0.0.0.0/0

user administrator h3cyunwei local secret dTpa8US1TtdQSgdV3Hr/TA7rdBP8pToGSWV0sE7lXKzHnbINoWUyjS+ptNFYczJ authorized-table admin

user administrator h3cyunwei authorized-address first 0.0.0.0/0

user administrator h3cyunwei force-chgpwd 1

radius nas-port-type ethernet

!

app-ident mode smart

!policy-group

timezone 57

ntp ***.*** 5

ntp auxiliary time.asia.apple.com

!

ftp timeout 5

wxfj-place 64

!

admin encrypt_auth disable

!

pki ca crl update-period 30

!

!

!

!

lcd sceensaver timer 60 1

!

https port 22443

!

!

application bypass threshold 80

application session change user enable

application terminal identify enable

app-ident nego-timer sip 60

app-ident nego-timer h323 60

app-ident nego-timer h245 60

interface bvi1

 allow access https

 allow access ping

 allow access ssh

 allow access center-monitor

!

interface ge0

 ip address 192.168.200.200/24

 allow access https

allow access http

 allow access ping

!

interface ge1

!

interface ge2

 description T-联髯专线

 traffic-mode extern

 ip address 125.40.199.248/24

 allow access https

 allow access ping

 allow access center-monitor

!

interface ge3

!

interface ge4

!

interface ge5

!

interface ge6

!

interface ge7

!

interface ge8

!

interface ge9

!

interface ge10

!

interface ge11

!

interface ge12

 description T-网肚

 ip address 10.10.10.1/24

 allow access https

 allow access http

 allow access ping

 allow access ssh

 allow access telnet

 allow access center-monitor

!

interface ge13

 description To-F1000-G7

 ip address 10.10.20.2/24

 allow access https

 allow access http

 allow access ping

 allow access ssh

 allow access telnet

 allow access center-monitor

!

!address

!

address officeIP

 ip subnet 10.10.0.0/19

!

!address6

!

!address-group

!

!service

!

service 40443

 tcp dst-port 40443 40443 src-port 0 65535

!

service 6331

 tcp dst-port 6331 6331 src-port 0 65535

!

service 2212

 tcp dst-port 2212 2212 src-port 0 65535

!

service 2233

 tcp dst-port 2233 2233 src-port 0 65535

!

service 12443

 tcp dst-port 12443 12443 src-port 0 65535

!

service 22443

 tcp dst-port 22443 22443 src-port 0 65535

!

!service-group

!

!schedule-day

!

!schedule-week

!

!schedule-month

!

!schedule-once

!

!user-group

!

!

!user

!

!

!attribute-group

!

!

!user-policy

!

user-policy listen authentication disable

user-policy https-portal enable

!user-syn

!

sync-task start

sync-task end

!zone

!

!

!

!

!

!track

!

!

!track-group

!

!

!

!

sslvpn dup-login disable

sslvpn disable

sslvpn keepalive 10 12

sslvpn security disable

!sslvpn-resource

!sslvpn-user-ip-binding

!policy route

proute rematch enable

!

policy default-action permit

policy white-list enable

!

!policy-decrypt

!

sslproxy-optimize disable

policy listen block disable

policy analyze daily

policy analyze disable

!

audit_policy any any any any any always web_access any 1

    audit-behaviour network_community

    audit-behaviour web_search

    audit-behaviour send_web_mail

    audit-behaviour http_send_file

    audit-behaviour http_download_file

    audit-behaviour send_mail

    audit-behaviour receive_mail

    audit-behaviour im_audit

    audit-behaviour ftp

    audit-behaviour recreation

    audit-behaviour stock

    audit-behaviour other_app

    audit-behaviour im_web_weixin

    audit-behaviour im_feixin

    audit-behaviour im_other

    audit-behaviour receive_web_mail

    audit-behaviour web_mail_upload_attachment

    audit-behaviour web_mail_download_attachment

    audit-behaviour web_disk_upload_file

    audit-behaviour web_disk_download_file

    other-app category IM_Software

    other-app category P2P_Software

    other-app category Online_Game

    other-app category File_Transfer

    other-app category Search_Engine

    other-app category Network_Community

    other-app category Database_Software

    other-app category Ecommerce

    other-app category Network_Protocol

    other-app category E_Mail

    other-app category Remote_Control

    other-app category Life_Services

    other-app category Network_Proxy

    other-app category Enterprise_Software

    other-app category Software_Update

    other-app category Other_Software

    other-app category Finance_Login

    other-app category Finance_Info

    other-app category Finance_Deal

    other-app category P2P_Media

    other-app category Other_Media

    other-app category Cloud_Storage

    other-app category Weibo

    other-app category Portals

    other-app category Recruit_Info

    other-app category Literature_Info

    other-app category Electric_Bank

    other-app category Virtual_Currency

    log level info

audit associate enable

!

snmp

 community secret fMIV/kvbDP5P1yuvINib/U9TNjKZb7kAlnq3/02zcAN/1YW3x/UoQsxoXHgymNF

 write-community secret fMIV/kvbDP5F+OqSEFgwUV7mX9Udx0KbZT+XnYqEBwiIw11onNoVtciBKMTRYZ0

 syslocation Hangzhou, China

 syscontact New H3C Tech. Co., Ltd.

!

dhcp

!

report

  set storage space 137 percent 80

  set global rank_user 50 week_start sunday

!

!

ip route 0.0.0.0/0 125.40.199.1

ip route 10.10.0.0/19 10.10.20.1

ip route 10.10.11.0/24 10.10.20.1

ip route 10.10.12.0/24 10.10.20.1

ip route 10.10.13.0/24 10.10.20.1

ip route 10.10.14.0/24 10.10.20.1

ip route 10.10.15.0/24 10.10.20.1

ip route 10.10.16.0/24 10.10.20.1

ip route 10.10.17.0/24 10.10.20.1

ip route 10.10.18.0/24 10.10.20.1

ip route 10.10.19.0/24 10.10.20.1

!

route rcache-inherit enable

!

mllb session-persistence enable

smtp-config

    ssl enable

!

auto-update

 update enable

 weekly sun mon tue wed thu fri sat

 time hour 23 minute 0

!auto-execute

!

!

tcpstack enable

sip flush expectation disable

!user-param

!

user-param threshold 10000

user mac-sensitive enable

!user-webauth

!

user-webauth jump-access-web

!user-wechat

!

user-wechat name-type ip

!user-portal-server

!

user-portal-server mac-sensitive enable

!user-portal-escape

!

!user-sso

!

user-adsso timeouts 3

no user-adsso key

!user-imc

!

!user-app-server

!

!user-sms-server

!

user-sms jump-access-web

!user-mix-server

!

user-mix jump-access-web

!

!user-qrcode-auth

user-qrcode audit-type indirectly

user-qrcode jump-access-web

!

!user-free-server

!

user-free jump-access-web

pppoe user-snooper age 15

user-radius-listen disable

user-radius-listen authentication port 1812

user-radius-listen accounting port 1813

!

user-web-listen group /authen-method/Web-user

user-web-listen check success

!

user-radius-listen timeout 15

!urlcate_user_label_switch

!

!urlcate_user_label_imc

!

!urlcate_user_label

!

!ip session limit

!

dns disable

dns proxy disable

dns cache disable

dns session disable

dns proxy balance priority

dns server 114.114.114.114 202.102.224.68

!

ddns disable

!

ip nat source port fast-match enable

ip nat pool unreach-route enable

ip nat clean-mode smart

ip nat pool 10.10.20.254

 ip address 10.10.20.254 10.10.20.254

ip nat pool 10.10.20.1

 ip address 10.10.20.1 10.10.20.1

ip nat pool 10.10.20.2

 ip address 10.10.20.2 10.10.20.2

!

ip nat source ge2 any any any interface 1

!

!

ip nat destination ge2 any any 12443 10.10.20.254 service 443 1

!

!

!

!

wxfj-upload-encryp enable

!

wxfj-rzx-cszt disable

!

wxfj-pass-switch disable

!

anony_user log disable

ap ipmac enable

!

!flow-account

!

log servconn_policy server disable

log server addr 39.102.233.5

log server port 515

log server enable

!

set dplog time disable

set dplog send time 23

!

!interface track

!

!

!rzx gam-audit

!

!

user-share check disable

user-share action disable

user-share terminal-count 2

user-share log switch off

!service-quality

!

!

alarm-email disable

!

alarm-email quote disable

!

user-radius-ap-mac disable

!

!

 assets disable

!

brute-force service oracle 60 120

brute-force service mysql 60 120

brute-force service postgres 60 120

brute-force service mssql 60 120

!

!

cloud url ***.***

cloud https port 8443

cloud protocol https

cloud type cmtunnel

!

!

!

policy6 default-action permit

!

 

ha-config

 

!

!

!ads-obj

!

!

!

!ad-policy

!

!

server-out-connect study num 500

mobile-manage

  disable

  trust-user disable

  freeze disable

  frozen-time 5

!

behavior-model

!

!end

 

2 个回答
粉丝:13人 关注:9人

排查步骤:
1. 检查ACG管理IP与PC是否同网段,PC能否ping通ACG管理IP。命令:ping [ACG管理IP](PC端);ACG端display ip interface brief确认管理口IP配置。
2. 检查WEB服务是否开启。ACG命令:display web-manager,若未开启则执行web-manager enable。
3. 检查访问权限是否限制。ACG命令:display authorized-table admin确认admin表有read/write all权限;display acl查看是否有ACL限制管理IP访问。
4. 检查端口是否被占用或防火墙拦截。ACG命令:display tcp status | include 80(默认WEB端口80),确认端口监听;PC端关闭防火墙或临时允许访问。
5. 尝试重启WEB服务。ACG命令:undo web-manager enable后web-manager enable。
6. 若仍无法访问,检查是否配置了HTTPS,尝试用https://[ACG管理IP]访问,ACG命令web-manager security enable开启HTTPS。

暂无评论

粉丝:27人 关注:1人

根据你提供的配置,Web页面无法访问的问题,很可能出在接口配置路由上。以下是为您整理的排查思路,你可以按照这个顺序逐一检查。

🔍 排查步骤

1. 检查接口的Web访问权限

这是最基础的一点。你提供的配置显示,interface ge0ge12ge13等接口都已配置了allow access httpshttp,这说明从配置上看,Web访问是放通的。

  • 确认管理地址:设备管理口(ge0)的默认地址是 192.168.1.1/24,默认允许 HTTPS 访问。请确保你尝试访问的是正确的接口IP。

  • 确认访问协议:ACG1000的Web管理界面仅支持HTTPS方式登录,请检查你访问时是否使用了 https:// 前缀。

2. 检查路由与连通性(关键!)

这是你当前配置中最可能存在问题的地方。

  • 检查路由表:你从办公网访问设备,数据包的往返路径必须一致且可达

    • 从办公网(如 10.10.0.0/19)访问设备某个接口IP(如 10.10.10.1)时,请求数据包能到达设备。

    • 但设备回复的数据包呢? 查看你的静态路由:

      text
      ip route 10.10.0.0/19 10.10.20.1

      这条路由意味着,设备在回复来自办公网的请求时,会将回包全部扔给下一跳 10.10.20.1

    • 问题可能就在这里:你需要确认 10.10.20.1 这个网关,是否有正确的路由能将数据包送回你的办公电脑。如果这个网关的路由配置有误,你的浏览器就永远收不到设备的回应,表现为“无法访问”。

  • 检查连通性:在办公电脑上执行 ping 和 tracert,确认到设备IP的网络路径是通的。

3. 检查浏览器与客户端环境

有时问题出在终端上,建议进行以下尝试:

  • 更换浏览器:尝试使用 Chrome(版本75及以上)、Firefox(版本6.0及以上)等浏览器,并清理缓存或使用无痕模式

  • 检查代理设置:确保你的浏览器没有启用代理服务器

  • 检查本地防火墙:暂时关闭电脑的防火墙或安全软件进行测试

  • 更换测试终端:尝试用其他电脑访问,以排除当前电脑的问题

4. 检查登录限制与安全策略

  • 检查管理员IP限制:配置中的 user administrator admin authorized-address first 0.0.0.0/0 表示未限制登录IP。但请确认是否有其他访问控制列表(ACL)或策略限制了你的IP

  • 检查密码复杂度:Web界面对密码复杂度有要求,如果密码包含特殊字符可能导致登录失败

  • 检查并发会话数:设备默认的Web管理员登录会话数有限,如果之前有未注销的会话,可能导致新登录失败。

5. 检查设备状态与版本

  • 检查CPU/内存:通过Console口登录设备,使用命令检查CPU和内存使用率是否过高,这可能导致Web服务无响应

  • 检查软件版本:确认设备运行的软件版本是否存在已知的Web界面问题

  • 尝试重启:如果以上都无效,且设备在运行中,可以尝试通过Console口重启设备,看是否能恢复Web访问。

🛠️ 快速验证与临时恢复

  • Console口验证:通过Console口登录设备是排查问题的最可靠方式。如果Web始终无法访问,请先通过Console口执行上述检查。

  • 恢复默认配置:如果配置混乱,可以考虑通过Console口重置管理员密码或恢复出厂配置

  • 使用默认管理口:将电脑直接连接到设备的 ge0 口,并配置同网段IP(如 192.168.1.2/24),然后尝试访问 https://192.168.1.1。如果能成功,则说明问题出在现有网络的路由或策略上。

暂无评论

编辑答案

你正在编辑答案

如果你要对问题或其他回答进行点评或询问,请使用评论功能。

分享扩散:

提出建议

    +

亲~登录后才可以操作哦!

确定

亲~检测到您登陆的账号未在http://hclhub.h3c.com进行注册

注册后可访问此模块

跳转hclhub

你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作

举报

×

侵犯我的权益 >
对根叔社区有害的内容 >
辱骂、歧视、挑衅等(不友善)

侵犯我的权益

×

泄露了我的隐私 >
侵犯了我企业的权益 >
抄袭了我的内容 >
诽谤我 >
辱骂、歧视、挑衅等(不友善)
骚扰我

泄露了我的隐私

×

您好,当您发现根叔知了上有泄漏您隐私的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您认为哪些内容泄露了您的隐私?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)

侵犯了我企业的权益

×

您好,当您发现根叔知了上有关于您企业的造谣与诽谤、商业侵权等内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到 pub.zhiliao@h3c.com 邮箱,我们会在审核后尽快给您答复。
  • 1. 您举报的内容是什么?(请在邮件中列出您举报的内容和链接地址)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
  • 3. 是哪家企业?(营业执照,单位登记证明等证件)
  • 4. 您与该企业的关系是?(您是企业法人或被授权人,需提供企业委托授权书)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

抄袭了我的内容

×

原文链接或出处

诽谤我

×

您好,当您发现根叔知了上有诽谤您的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您举报的内容以及侵犯了您什么权益?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

对根叔社区有害的内容

×

垃圾广告信息
色情、暴力、血腥等违反法律法规的内容
政治敏感
不规范转载 >
辱骂、歧视、挑衅等(不友善)
骚扰我
诱导投票

不规范转载

×

举报说明