防火墙配置
#
version 7.1.064, Release 9514P1801
#
sysname H3C
#
context Admin id 1
#
telnet server enable
#
irf mac-address persistent timer
irf auto-update enable
undo irf link-delay
irf member 1 priority 1
#
port-mapping application 媒体服务器 port 19207 protocol TCP
#
dns server 202.99.160.68
#
password-recovery enable
#
vlan 1
#
object-group service 媒体服务
0 service tcp destination range 11020 11030
10 service tcp destination eq 19207
20 service tcp destination eq 19027
30 service tcp destination eq 19209
40 service tcp destination eq 19029
50 service tcp destination eq 9224
60 service tcp destination eq 8088
#
object-group service 广播服务器
0 service tcp destination range 30041 30043
10 service tcp destination eq 30045
20 service tcp destination eq 30048
30 service tcp destination eq 8299
#
interface NULL0
#
interface GigabitEthernet1/0/0
port link-mode route
combo enable copper
duplex full
speed 100
ip address 61.182.134.54 255.255.255.252
nat outbound 3000
nat server protocol tcp global current-interface 8088 inside 172.16.25.100 8088
nat server protocol tcp global current-interface 8299 inside 172.16.25.11 80
nat server protocol tcp global current-interface 9224 inside 172.16.25.100 9224
nat server protocol tcp global current-interface 11020 inside 172.16.25.5 11020
nat server protocol tcp global current-interface 11021 inside 172.16.25.5 11021
nat server protocol tcp global current-interface 11022 inside 172.16.25.5 11022
nat server protocol tcp global current-interface 11023 inside 172.16.25.5 11023
nat server protocol tcp global current-interface 11024 inside 172.16.25.5 11024
nat server protocol tcp global current-interface 11025 inside 172.16.25.5 11025
nat server protocol tcp global current-interface 11026 inside 172.16.25.5 11026
nat server protocol tcp global current-interface 11027 inside 172.16.25.5 11027
nat server protocol tcp global current-interface 11028 inside 172.16.25.5 11028
nat server protocol tcp global current-interface 11029 inside 172.16.25.5 11029
nat server protocol tcp global current-interface 11030 inside 172.16.25.5 11030
nat server protocol tcp global current-interface 19027 inside 172.16.25.110 19027
nat server protocol tcp global current-interface 19029 inside 172.16.25.100 19029
nat server protocol tcp global current-interface 19207 inside 172.16.25.100 19207
nat server protocol tcp global current-interface 19209 inside 172.16.25.100 19209
nat server protocol tcp global current-interface 30041 inside 172.16.25.11 30041
nat server protocol tcp global current-interface 30042 inside 172.16.25.11 30042
nat server protocol tcp global current-interface 30045 inside 172.16.25.11 30045
nat server protocol tcp global current-interface 30048 inside 172.16.25.11 30048
#
interface GigabitEthernet1/0/1
port link-mode route
combo enable copper
ip address 10.10.10.1 255.255.255.252
#
interface GigabitEthernet1/0/2
port link-mode route
ip address 192.168.1.1 255.255.255.0
#
interface GigabitEthernet1/0/3
port link-mode route
#
interface GigabitEthernet1/0/4
port link-mode route
#
interface GigabitEthernet1/0/5
port link-mode route
#
interface GigabitEthernet1/0/6
port link-mode route
#
interface GigabitEthernet1/0/7
port link-mode route
#
interface GigabitEthernet1/0/8
port link-mode route
#
interface GigabitEthernet1/0/9
port link-mode route
#
interface GigabitEthernet1/0/10
port link-mode route
#
interface GigabitEthernet1/0/11
port link-mode route
#
security-zone name Local
#
security-zone name Trust
import interface GigabitEthernet1/0/1
#
security-zone name DMZ
#
security-zone name Untrust
import interface GigabitEthernet1/0/0
#
security-zone name Management
import interface GigabitEthernet1/0/2
#
scheduler logfile size 16
#
line class aux
user-role network-operator
#
line class console
authentication-mode scheme
user-role network-admin
#
line class vty
user-role network-operator
#
line aux 0
user-role network-admin
#
line con 0
user-role network-admin
#
line vty 0 4
authentication-mode scheme
user-role network-admin
protocol inbound telnet
#
line vty 5 63
authentication-mode scheme
user-role network-admin
#
ip route-static 0.0.0.0 0 61.182.134.53
ip route-static 172.16.25.0 24 10.10.10.2
ip route-static 192.168.102.0 24 10.10.10.2
#
ssh server enable
#
acl advanced 3000
rule 0 permit ip source 192.168.0.0 0.0.255.255
rule 1 permit ip source 172.0.0.0 0.255.255.255
#
domain system
#
aaa session-limit ftp 16
aaa session-limit telnet 16
aaa session-limit ssh 16
domain default enable system
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role
#
role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
user-group system
#
local-user admin class manage
password hash adfggghvvfddghj
service-type ssh telnet terminal https
authorization-attribute user-role level-3
authorization-attribute user-role network-admin
authorization-attribute user-role network-operator
#
apr signature auto-update
update schedule daily start-time 02:00:00 tingle 120
#
ip https enable
webui log enable
#
url-filter signature auto-update
update schedule daily start-time 02:00:00 tingle 120
#
ips signature auto-update
update schedule daily start-time 02:00:00 tingle 120
#
security-policy ip
rule 0 name 放通防火墙到三层交换机数据包
action pass
source-zone local
destination-zone trust
rule 1 name 放通三层交换机到防火墙的数据报文
action pass
source-zone Trust
destination-zone Local
rule 2 name 放通防火墙到互联网数据包
action pass
source-zone local
destination-zone untrust
rule 3 name 放通内部网络到外部网络数据包
action pass
source-zone Trust
destination-zone Untrust
rule 4 name 放通telnet
action pass
source-zone Untrust
destination-zone Local
application telnet
rule 5 name 放通媒体服务器端口
action pass
logging enable
counting enable
source-zone Untrust
destination-zone Trust
service 媒体服务
rule 6 name 放通广播服务器端口
action pass
logging enable
counting enable
source-zone Untrust
destination-zone Trust
service 广播服务器
#
anti-virus signature auto-update
update schedule daily start-time 02:00:00 tingle 120
#
retun
配置安全策略放通试试 rule 10 name 放通 action pass logging enable counting enable source-zone Untrust destination-zone Trust