<H3C>dis cu
#
version 7.1.064, Release 0707P16
#
sysname H3C
#
telnet server enable
#
nat address-group 1
address 116.55.48.54 116.55.48.54
#
nat address-group 2
address 192.168.100.2 192.168.100.2
#
dhcp enable
dhcp server always-broadcast
#
dns proxy enable
#
password-recovery enable
#
vlan 1
#
dhcp server ip-pool lan1
gateway-list 192.168.0.1
network 192.168.0.0 mask 255.255.254.0 address range 192.168.1.2 192.168.1.254 dns-list 192.168.0.1
#
controller Cellular0/0
#
interface NULL0
#
interface Vlan-interface1
ip address 2.2.2.100 255.255.255.0
#
interface GigabitEthernet0/0
port link-mode route
combo enable fiber
ip address 192.168.10.1 255.255.255.0
#
interface GigabitEthernet0/1
port link-mode route
combo enable copper
duplex full
ip address 192.168.100.2 255.255.255.0
nat outbound 3006 address-group 2
#
interface GigabitEthernet0/2
port link-mode route
combo enable copper
ip address 116.55.48.54 255.255.255.0
nat outbound 3005 address-group 1
nat server protocol tcp global 116.55.48.54 58080 inside 192.168.104.253 58080
nat server protocol udp global 116.55.48.54 58080 inside 192.168.104.253 58080
#interface GigabitEthernet0/3
port link-mode route
combo enable copper
nat outbound
#
interface GigabitEthernet0/4
port link-mode route
#
interface GigabitEthernet0/5
port link-mode route
#
scheduler logfile size 16
#
line class console
user-role network-admin
#
line class tty
user-role network-operator
#
line class usb
user-role network-admin
#
line class vty
user-role network-operator
#
line con 0
user-role network-admin
#
line vty 0 63
authentication-mode scheme
user-role network-operator
#
ip route-static 0.0.0.0 0 116.55.48.1 permanent tag 59
ip route-static 0.0.0.0 0 GigabitEthernet0/3 116.55.49.1
ip route-static 10.0.0.0 8 192.168.100.1
ip route-static 172.19.0.0 16 192.168.100.1
ip route-static 172.168.0.0 16 192.168.10.2 ip route-static 192.0.0.0 8 192.168.100.1
ip route-static 192.168.100.0 22 192.168.10. 2
ip route-static 192.168.104.0 24 192.168.10. 2
#
acl advanced 3005
rule 1 permit ip source 172.168.0.0 0.0.255. 255
rule 2 permit ip source 192.168.101.0 0.0.0. 255
rule 3 permit ip source 192.168.102.0 0.0.0. 255
rule 4 permit ip source 192.168.103.0 0.0.0. 255
rule 5 permit ip source 192.168.104.0 0.0.0. 255
rule 6 permit ip source 192.168.10.0 0.0.0. 255
rule 7 deny ip source 192.168.0.0 0.0.0.255
#
acl advanced 3006
rule 0 permit ip source 192.168.0.0 0.0.255.
255
rule 1 permit ip source 172.168.0.0 0.0.255. 255
#
password-control enable
undo password-control aging enable
undo password-control history enable password-control length 6
password-control login-attempt 3 exceed lock-time 10
password-control update-interval 0 password-control login idle-time 0
password-control complexity user-name check
#
domain system
#
domain default enable system
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role
#
role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
user-group system
#
local-user admin class manage
service-type telnet terminal http authorization-attribute user-role level-3 authorization-attribute user-role network-admin
authorization-attribute user-role network-operato
authorization-attribute user-role network-operator
#
nat server-group 1
#
ip http enable
#
wlan global-configuration
#
wlan ap-group default-group vlan 1
#
cloud-management server domain oasis.h3c.com
#
return
OK,谢谢大神