9口外网。1口内网
1口关闭动态地址学习
ip+mac地址绑定了
没开启arp是可以上外网的,开启后缺省丢弃,上不去外网,也访问不了1口。0口管理地址
========
[H3C]dis cu # version 7.1.064, Ess 9524P08 #
sysname H3C
# context Admin id 1
# irf mac-address persistent timer irf auto-update enable undo irf link-delay irf member 1 priority 1
# password-recovery enable
# vlan 1
# controller Cellular1/0/0
# interface NULL0
# interface GigabitEthernet1/0/0 port link-mode route ip address 192.168.0.1 255.255.255.0
# interface GigabitEthernet1/0/1
port link-mode route description GuideLan
Interface ip address 192.168.100.1 255.255.255.0
arp max-learning-num 0 undo dhcp select server
# interface GigabitEthernet1/0/2
port link-mode route ip address 192.168.1.1 255.255.255.0
# interface GigabitEthernet1/0/3 port link-mode route
# interface GigabitEthernet1/0/4 port link-mode route
# interface GigabitEthernet1/0/5 port link-mode route
# interface GigabitEthernet1/0/6 port link-mode route
# interface GigabitEthernet1/0/7
port link-mode route description GuideWan
Interface ip address 192.168.10.189 255.255.255.0
dns server 202.102.134.68
nat outbound description GuideNat
# security-zone name Local
# security-zone name Trust import interface GigabitEthernet1/0/1
# security-zone name DMZ
# security-zone name Untrust import interface GigabitEthernet1/0/7
# security-zone name Management import interface GigabitEthernet1/0/0 import interface GigabitEthernet1/0/2
# scheduler logfile size 16
# line class aux user-role network-operator
# line class console authentication-mode scheme user-role network-admin
# line class usb user-role network-admin
# line class vty user-role network-operator
# line aux 0 user-role network-admin
# line con 0 user-role network-admin
# line vty 0 63 authentication-mode scheme user-role network-admin
# ip route-static 0.0.0.0 0 GigabitEthernet1/0/7 192.168.10.1
# ssh server enable # domain system # domain default enable system
# role name level-0 description Predefined level-0 role
# role name level-1 description Predefined level-1 role
# role name level-2 description Predefined level-2 role
# role name level-3 description Predefined level-3 role
# role name level-4 description Predefined level-4 role
# role name level-5 description Predefined level-5 role
# role name level-6 description Predefined level-6 role
# role name level-7 description Predefined level-7 role
# role name level-8 description Predefined level-8 role
# role name level-9 description Predefined level-9 role
# role name level-10 description Predefined level-10 role
# role name level-11 description Predefined level-11 role
# role name level-12 description Predefined level-12 role
# role name level-13 description Predefined level-13 role
# role name level-14 description Predefined level-14 role
# user-group system
# local-user admin class manage password hash $h$6$UbIhNnPevyKUwfpm$LqR3+yg1IjNct39MkOR0H0iQXLkYB3jMqM4vbAeoXOhbabIIFnjJPEGR00YiYA1Sz4LiY3FmEdru2fOLMb1shQ== service-type ssh terminal https authorization-attribute user-role level-3 authorization-attribute user-role network-admin authorization-attribute user-role network-operator
# ipsec logging negotiation enable
# ike logging negotiation enable
# ip https enable webui log enable
# ip-mac binding enable
ip-mac binding no-match action deny
ip-mac binding ipv4 192.168.10.1 mac-address 0022-aa9d-0746
ip-mac binding ipv4 192.168.10.28 mac-address 9ce3-3f02-59d6
ip-mac binding ipv4 192.168.10.31 mac-address 483b-3892-3696
ip-mac binding ipv4 192.168.100.3 mac-address 00e0-4c36-005b
# security-policy ip rule 0 name GuideSecPolicy action pass source-zone Trust destination-zone Untrust destination-zone DMZ rule 1 name 44 action pass
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论