h3c防火墙nat配置,h3c防火墙nat配置命令
H3C防火墙怎么设置
1、首先我们进入H3C防火墙界面,接着进入WEB将接口改为二层模式,
2、在将二层模式的接口划到Trust安全域中。
3、点击界面左侧快捷菜单栏里的防火墙选项。
4、进行配置安全策略,安全策略配置完如图。
5、配置其他网段只能访问其中的服务器。
6、DHCP 要启用 DHCP中继dhcp-relay,这样配置就完成了。
h3c防火墙怎么样设置
1、配置要求
1)防火墙的E0/2接口为TRUST区域,ip地址是:192.168.254.1/29;
2)防火墙的E1/2接口为UNTRUST区域,ip地址是:202.111.0.1/27;
3)内网服务器对外网做一对一的地址映射,192.168.254.2、192.168.254.3分别映射为202.111.0.2、202.111.0.3;
4)内网服务器访问外网不做限制,外网访问内网只放通公网地址211.101.5.49访问192.168.254.2的1433端口和192.168.254.3的80端口。
2、防火墙的配置脚本如下
H3CF100Adis cur
#
sysname H3CF100A
#
super password level 3 cipher 6aQQ57-$.I)0;4:\(I41!!!
#
firewall packet-filter enable
firewall packet-filter default permit
#
insulate
#
nat static inside ip 192.168.254.2 global ip 202.111.0.2
nat static inside ip 192.168.254.3 global ip 202.111.0.3
#
firewall statistic system enable
#
radius scheme system
server-type extended
#
domain system
#
local-user net1980
password cipher ######
service-type telnet
level 2
#
aspf-policy 1
detect h323
detect sqlnet
detect rtsp
detect http
detect smtp
detect ftp
detect tcp
detect udp
#
object address 192.168.254.2/32 192.168.254.2 255.255.255.255
object address 192.168.254.3/32 192.168.254.3 255.255.255.255
#
acl number 3001
description out-inside
rule 1 permit tcp source 211.101.5.49 0 destination 192.168.254.2 0 destination-port eq 1433
rule 2 permit tcp source 211.101.5.49 0 destination 192.168.254.3 0 destination-port eq www
rule 1000 deny ip
acl number 3002
description inside-to-outside
rule 1 permit ip source 192.168.254.2 0
rule 2 permit ip source 192.168.254.3 0
rule 1000 deny ip
#
interface Aux0
async mode flow
#
interface Ethernet0/0
shutdown
#
interface Ethernet0/1
shutdown
#
interface Ethernet0/2
speed 100
duplex full
description to server
ip address 192.168.254.1 255.255.255.248
firewall packet-filter 3002 inbound
firewall aspf 1 outbound
#
interface Ethernet0/3
shutdown
#
interface Ethernet1/0
shutdown
#
interface Ethernet1/1
shutdown
#
interface Ethernet1/2
speed 100
duplex full
description to internet
ip address 202.111.0.1 255.255.255.224
firewall packet-filter 3001 inbound
firewall aspf 1 outbound
nat outbound static
#
interface NULL0
#
firewall zone local
set priority 100
#
firewall zone trust
add interface Ethernet0/2
set priority 85
#
firewall zone untrust
add interface Ethernet1/2
set priority 5
#
firewall zone DMZ
add interface Ethernet0/3
set priority 50
#
firewall interzone local trust
#
firewall interzone local untrust
#
firewall interzone local DMZ
#
firewall interzone trust untrust
#
firewall interzone trust DMZ
#
firewall interzone DMZ untrust
#
ip route-static 0.0.0.0 0.0.0.0 202.111.0.30 preference 60
#
user-interface con 0
user-interface aux 0
user-interface vty 0 4
authentication-mode scheme
#
h3c f100-c-ei防火墙怎么设置路由和DHCP功能?
初始化配置
〈H3C〉system-view
开启防火墙功能,并默认允许所有数据包通过
[H3C]firewall packet-filter enable
[H3C]firewall packet-filter default permit
分配端口区域(untrust外网,trust内网;端口号请参照实际情况)
[H3C] firewall zone untrust
[H3C-zone-untrust] add interface Ethernet0/0
[H3C] firewall zone trust
[H3C-zone-trust] add interface Ethernet0/1
工作模式,默认为路由模式
[H3C] firewall mode route
开启所有防范功能
[H3C] firewall defend all
配置内网LAN口IP(内网IP地址请参考实际情况)
[H3C] interface Ethernet0/1
[H3C-interface] ip address 192.168.1.1 255.255.255.0
配置外网IP(也就是电信给你们的IP和子网掩码)
[H3C] interface Ethernet0/0
[H3C-interface] ip address X.X.X.X X.X.X.X.X
配置NAT地址池(填写电信给你们的IP地址,填写两次)
[H3C]nat address-group 1 X.X.X.X X.X.X.X.X
配置默认路由(出外网的路由,字母代表的是电信分配你们的外网网关地址,不知道就问电信)
[H3C]ip route-static 0.0.0.0 0.0.0.0 Y.Y.Y.Y preference 60
配置访问控制列表(上网必须配置)
[H3C]acl number 2001
[H3C-ACL]rule 1 permit source 192.168.1.0 0.0.0.255
应用访问控制列表到端口,并开启NAT上网功能
[H3C]interface Ethernet1/0
[H3C-interface]nat outbound 2001 address-group 1
配置DHCP
[H3C] dhcp enable
[H3C-dhcp] dhcp server ip-pool 0
[H3C-dhcp] network 192.1681.0 mask 255.255.255.0
[H3C-dhcp] gateway-list 192.168.1.1
[H3C-dhcp] dns-list X.X.X.X(配置你们这里的DNS服务器地址)
其它配置:
允许网页配置
[H3C] undo ip http shutdown
添加WEB用户
[H3C] local-user admin
[H3C-luser-admin] password simple admin
[H3C-luser-admin] service-type telnet
[H3C-luser-admin] level 3
配置telnet远程登录
[H3C-vty] user-interface vty 0 4
[H3C-vty] authentication-mode schem/password
[H3C-vty] user privilage 3
完成某项配置之后要回到[H3C] 提示符下面请按q再回车
如果还是不明白就打H3C 800电话吧,希望能够帮到你。