h3c防火墙nat配置,h3c防火墙nat配置命令

http://www.itjxue.com  2023-01-17 05:31  来源:未知  点击次数: 

H3C防火墙怎么设置

1、首先我们进入H3C防火墙界面,接着进入WEB将接口改为二层模式,

2、在将二层模式的接口划到Trust安全域中。

3、点击界面左侧快捷菜单栏里的防火墙选项。

4、进行配置安全策略,安全策略配置完如图。

5、配置其他网段只能访问其中的服务器

6、DHCP 要启用 DHCP中继dhcp-relay,这样配置就完成了。

h3c防火墙怎么样设置

1、配置要求

1)防火墙的E0/2接口为TRUST区域,ip地址是:192.168.254.1/29;

2)防火墙的E1/2接口为UNTRUST区域,ip地址是:202.111.0.1/27;

3)内网服务器对外网做一对一的地址映射,192.168.254.2、192.168.254.3分别映射为202.111.0.2、202.111.0.3;

4)内网服务器访问外网不做限制,外网访问内网只放通公网地址211.101.5.49访问192.168.254.2的1433端口和192.168.254.3的80端口。

2、防火墙的配置脚本如下

H3CF100Adis cur

#

sysname H3CF100A

#

super password level 3 cipher 6aQQ57-$.I)0;4:\(I41!!!

#

firewall packet-filter enable

firewall packet-filter default permit

#

insulate

#

nat static inside ip 192.168.254.2 global ip 202.111.0.2

nat static inside ip 192.168.254.3 global ip 202.111.0.3

#

firewall statistic system enable

#

radius scheme system

server-type extended

#

domain system

#

local-user net1980

password cipher ######

service-type telnet

level 2

#

aspf-policy 1

detect h323

detect sqlnet

detect rtsp

detect http

detect smtp

detect ftp

detect tcp

detect udp

#

object address 192.168.254.2/32 192.168.254.2 255.255.255.255

object address 192.168.254.3/32 192.168.254.3 255.255.255.255

#

acl number 3001

description out-inside

rule 1 permit tcp source 211.101.5.49 0 destination 192.168.254.2 0 destination-port eq 1433

rule 2 permit tcp source 211.101.5.49 0 destination 192.168.254.3 0 destination-port eq www

rule 1000 deny ip

acl number 3002

description inside-to-outside

rule 1 permit ip source 192.168.254.2 0

rule 2 permit ip source 192.168.254.3 0

rule 1000 deny ip

#

interface Aux0

async mode flow

#

interface Ethernet0/0

shutdown

#

interface Ethernet0/1

shutdown

#

interface Ethernet0/2

speed 100

duplex full

description to server

ip address 192.168.254.1 255.255.255.248

firewall packet-filter 3002 inbound

firewall aspf 1 outbound

#

interface Ethernet0/3

shutdown

#

interface Ethernet1/0

shutdown

#

interface Ethernet1/1

shutdown

#

interface Ethernet1/2

speed 100

duplex full

description to internet

ip address 202.111.0.1 255.255.255.224

firewall packet-filter 3001 inbound

firewall aspf 1 outbound

nat outbound static

#

interface NULL0

#

firewall zone local

set priority 100

#

firewall zone trust

add interface Ethernet0/2

set priority 85

#

firewall zone untrust

add interface Ethernet1/2

set priority 5

#

firewall zone DMZ

add interface Ethernet0/3

set priority 50

#

firewall interzone local trust

#

firewall interzone local untrust

#

firewall interzone local DMZ

#

firewall interzone trust untrust

#

firewall interzone trust DMZ

#

firewall interzone DMZ untrust

#

ip route-static 0.0.0.0 0.0.0.0 202.111.0.30 preference 60

#

user-interface con 0

user-interface aux 0

user-interface vty 0 4

authentication-mode scheme

#

h3c f100-c-ei防火墙怎么设置路由和DHCP功能?

初始化配置

〈H3C〉system-view

开启防火墙功能,并默认允许所有数据包通过

[H3C]firewall packet-filter enable

[H3C]firewall packet-filter default permit

分配端口区域(untrust外网,trust内网;端口号请参照实际情况)

[H3C] firewall zone untrust

[H3C-zone-untrust] add interface Ethernet0/0

[H3C] firewall zone trust

[H3C-zone-trust] add interface Ethernet0/1

工作模式,默认为路由模式

[H3C] firewall mode route

开启所有防范功能

[H3C] firewall defend all

配置内网LAN口IP(内网IP地址请参考实际情况)

[H3C] interface Ethernet0/1

[H3C-interface] ip address 192.168.1.1 255.255.255.0

配置外网IP(也就是电信给你们的IP和子网掩码)

[H3C] interface Ethernet0/0

[H3C-interface] ip address X.X.X.X X.X.X.X.X

配置NAT地址池(填写电信给你们的IP地址,填写两次)

[H3C]nat address-group 1 X.X.X.X X.X.X.X.X

配置默认路由(出外网的路由,字母代表的是电信分配你们的外网网关地址,不知道就问电信)

[H3C]ip route-static 0.0.0.0 0.0.0.0 Y.Y.Y.Y preference 60

配置访问控制列表(上网必须配置)

[H3C]acl number 2001

[H3C-ACL]rule 1 permit source 192.168.1.0 0.0.0.255

应用访问控制列表到端口,并开启NAT上网功能

[H3C]interface Ethernet1/0

[H3C-interface]nat outbound 2001 address-group 1

配置DHCP

[H3C] dhcp enable

[H3C-dhcp] dhcp server ip-pool 0

[H3C-dhcp] network 192.1681.0 mask 255.255.255.0

[H3C-dhcp] gateway-list 192.168.1.1

[H3C-dhcp] dns-list X.X.X.X(配置你们这里的DNS服务器地址)

其它配置:

允许网页配置

[H3C] undo ip http shutdown

添加WEB用户

[H3C] local-user admin

[H3C-luser-admin] password simple admin

[H3C-luser-admin] service-type telnet

[H3C-luser-admin] level 3

配置telnet远程登录

[H3C-vty] user-interface vty 0 4

[H3C-vty] authentication-mode schem/password

[H3C-vty] user privilage 3

完成某项配置之后要回到[H3C] 提示符下面请按q再回车

如果还是不明白就打H3C 800电话吧,希望能够帮到你。

(责任编辑:IT教学网)

更多

推荐图片影音文章