H3C SecPath F100-C 防火墙配置

上一篇 / 下一篇  2008-10-31 07:22:33

下边是一个项目中的文档
fw100>dis cur
#
sysname fw100
#
super password level 3 simple asdasd
#
l2tp enable
#
ip pool 1 10.10.10.2 10.10.10.50
#
ike local-name jzcdc-vpn
#
firewall packet-filter enable
firewall packet-filter default permit
#
insulate
#
connection-limit enable
connection-limit default permit
connection-limit default amount upper-limit 50 lower-limit 20
#
nat address-group 1 start ip add end ip add
#
firewall statistic system enable
#

radius scheme system
server-type extended
#
domain system
#
local-user asdf
password cipher >T2OET:6,>OQ=^Q`MAF4<1!!
service-type telnet
level 3
#
ike peer 1
pre-shared-key lllll
#
ipsec proposal 1
encapsulation-mode transport
#
ipsec policy-template temp 1
ike-peer 1
proposal 1
#
ipsec policy 1 1 isakmp template temp
#
ipsec policy jzcdc 100 isakmp template temp
#
acl number 2001
rule 0 permit source 192.168.0.0 0.0.255.255
rule 1 permit source 10.0.0.0 0.0.0.255
#
acl number 3002
rule 0 deny tcp source-port eq 3127
rule 1 deny tcp source-port eq 1025
rule 2 deny tcp source-port eq 5554
rule 3 deny tcp source-port eq 9996
rule 4 deny tcp source-port eq 1068
rule 5 deny tcp source-port eq 135
rule 6 deny udp source-port eq 135
rule 7 deny tcp source-port eq 137
rule 8 deny udp source-port eq netbios-ns
rule 9 deny tcp source-port eq 138
rule 10 deny udp source-port eq netbios-dgm
rule 11 deny tcp source-port eq 139
rule 12 deny udp source-port eq netbios-ssn
rule 13 deny tcp source-port eq 593
rule 14 deny tcp source-port eq 4444
rule 15 deny tcp source-port eq 5800
rule 16 deny tcp source-port eq 5900
rule 18 deny tcp source-port eq 8998
rule 19 deny tcp source-port eq 445
rule 20 deny udp source-port eq 445
rule 21 deny udp source-port eq 1434
rule 30 deny tcp destination-port eq 3127
rule 31 deny tcp destination-port eq 1025
rule 32 deny tcp destination-port eq 5554
rule 33 deny tcp destination-port eq 9996
rule 34 deny tcp destination-port eq 1068
rule 35 deny tcp destination-port eq 135
rule 36 deny udp destination-port eq 135
rule 37 deny tcp destination-port eq 137
rule 38 deny udp destination-port eq netbios-ns
rule 39 deny tcp destination-port eq 138
rule 40 deny udp destination-port eq netbios-dgm
rule 41 deny tcp destination-port eq 139
rule 42 deny udp destination-port eq netbios-ssn
rule 43 deny tcp destination-port eq 593
rule 44 deny tcp destination-port eq 4444
rule 45 deny tcp destination-port eq 5800
rule 46 deny tcp destination-port eq 5900
rule 48 deny tcp destination-port eq 8998
rule 49 deny tcp destination-port eq 445
rule 50 deny udp destination-port eq 445
rule 51 deny udp destination-port eq 1434
rule 52 deny tcp destination-port eq telnet
acl number 3003
rule 0 permit icmp
rule 1 permit tcp source-port eq telnet
rule 5 permit tcp destination-port eq telnet
#
interface Virtual-Template1
ppp authentication-mode pap
ip address 10.10.10.1 255.255.255.0
#
interface Aux0
async mode flow
#
interface Ethernet0/0
description link to luyouqi
ip address 10.0.0.1 255.255.255.252
firewall packet-filter 3003 inbound
firewall packet-filter 3003 outbound
#
interface Ethernet0/1
#
interface Ethernet0/2
#
interface Ethernet0/3
description link to fuwuqi dmz
ip address 10.0.0.129 255.255.255.128
#
interface Ethernet1/0
description link to internet
ip address 1.1.1.1 255.255.255.224
firewall packet-filter 3002 inbound
nat outbound 2001 address-group 1
nat server protocol tcp global 1.1.1.1 ftp inside 10.0.0.130 ftp
#
interface Ethernet1/1
#
interface Ethernet1/2
#
interface NULL0
#
firewall zone local
set priority 100
#
firewall zone trust
add interface Ethernet0/0
add interface Virtual-Template1
set priority 85
#
firewall zone untrust
add interface Ethernet1/0
set priority 5
#
firewall zone DMZ
add interface Ethernet0/3
set priority 50
#
firewall interzone local trust
#
firewall interzone local untrust
#
firewall interzone local DMZ
#
firewall interzone trust untrust
#
firewall interzone trust DMZ
#
firewall interzone DMZ untrust
#
l2tp-group 1
undo tunnel authentication
allow l2tp virtual-template 1
#
ip route-static 0.0.0.0 0.0.0.0 9.9.9.9 preference 60
ip route-static 192.168.1.0 255.255.255.0 10.0.0.2 preference 60

#
firewall defend ip-spoofing
firewall defend land
firewall defend smurf
firewall defend fraggle
firewall defend winnuke
firewall defend icmp-redirect
firewall defend icmp-unreachable
firewall defend source-route
firewall defend route-record
firewall defend tracert
firewall defend ping-of-death
firewall defend tcp-flag
firewall defend ip-fragment
firewall defend large-icmp
firewall defend teardrop
firewall defend ip-sweep
firewall defend port-scan
firewall defend arp-spoofing
firewall defend arp-reverse-query
firewall defend arp-flood
firewall defend frag-flood
firewall defend syn-flood enable
firewall defend udp-flood enable
firewall defend icmp-flood enable
#
user-interface con 0
user-interface aux 0
user-interface vty 0 4
authentication-mode scheme
accounting commands scheme
set authentication password simple asdfasfd
idle-timeout 3 0
#
return

TAG: Secpath SecPath SECPATH 防火墙

 

评分:0

我来说两句

显示全部

:loveliness: :handshake :victory: :funk: :time: :kiss: :call: :hug: :lol :'( :Q :L ;P :$ :P :o :@ :D :( :)

日历

« 2009-01-10  
    123
45678910
11121314151617
18192021222324
25262728293031

我的存档

数据统计

  • 访问量: 581
  • 日志数: 14
  • 建立时间: 2008-10-31
  • 更新时间: 2008-10-31

RSS订阅

Open Toolbar