2021-08-20 154219.png

syst
int g0/0/0
dhcp select interface
 dhcp server gateway-list 192.168.0.1
 dhcp server dns-list 100.100.2.100

int g0/0/1
ip add 100.100.100.1 24

int g0/0/2
ip add 172.16.1.1 24
q
firewall zone untrust 
 add int g0/0/1
q
firewall zone dmz 
 add interface g0/0/2
q
policy interzone trust untrust outbound 
policy 1
action permit
q
policy interzone untrust dmz inbound 
policy 2
action permit
q
ip route-s 0.0.0.0 0.0.0.0 100.100.100.2

user-interf con 0
idle-t 0 0
q

syst
sysn SW
vlan ba 2 3 4 10
int vlan 10
ip add 100.100.100.2 24
int vlan 1
ip add 100.100.1.1 24
int vlan 2
ip add 100.100.2.1 24
int vlan 3
ip add 100.100.3.1 24
int vlan 4
ip add 100.100.4.1 24

int eth 0/0/10
port link-t ac
port default vlan 10 
int eth 0/0/1
port link-t ac
port default vlan 1 
int eth 0/0/2
port link-t ac
port default vlan 2 
int eth 0/0/3
port link-t ac
port default vlan 3 
int eth 0/0/4
port link-t ac
port default vlan 4 

user-interf con 0
idle-t 0 0
q

映射内部(DMZ)服务器

nat server protocol tcp global 100.100.100.172 80 inside 172.16.1.101 80
nat server protocol tcp global 100.100.100.172 21 inside 172.16.1.101 21
dis nat server

sys
firew interzone untrust dmz
 detect ftp
firew interzone trust untrust
 detect qq

dis firew server-map

1.


sys
firew blacklist item 192.168.0.2 timeout 2
firew blacklist enable
dis firew blacklist item

2.

firewall defend ip-sweep enable
firewall defend ip-sweep max-rate 2
firewall defend ip-sweep blacklist-timeout 20
firewall blacklist enable
dis firew blacklist item

最后修改:2023 年 05 月 02 日
如果觉得我的文章对你有用,请随意赞赏