首页 科技问答 GzFQ4O,H3C F1000-C-G防火墙与三层交换机连接 不通

GzFQ4O,H3C F1000-C-G防火墙与三层交换机连接 不通

科技问答 208
1682004024,CRM论坛(CRMbbs.com)——一个让用户更懂CRM的垂直性行业内容平台,CRM论坛致力于互联网、客户管理、销售管理、SCRM私域流量内容输出5年。 如果您有好的内容,欢迎向我们投稿,共建CRM多元化生态体系,创建CRM客户管理一体化生态解决方案。内容来源:知了社区

问题描述:

 

[H3C]dis cu

#

version 5.

#

sysname H3C

#

undo voice vlan mac-address 00e0-bb00-0000

#

domain default enable system

#

undo alg dns

undo alg rtsp

undo alg h323

undo alg sip

undo alg sqlnet

undo alg pptp

undo alg ils

undo alg nbt

undo alg msn

undo alg qq

undo alg tftp

undo alg sccp

undo alg gtp

#

session synchronization enable

#

password-recovery enable

#

acl number

rule 0 permit source 192.168.0.0 0.0.255.255

#

vlan 1

#

domain system

access-limit disable

state active

idle-cut disable

self-service-url disable

#

pki domain default

 crl check disable

#

user-group system

group-attribute allow-guest

#

local-user admin

password cipher $c$3$2Ko3oPVrZaI8l6Cty3405PBdUt2daTtE

authorization-attribute level 3

service-type telnet

service-type web

#

interface NULL0

#

interface GigabitEthernet0/0

port link-mode route

ip address 192.168.0.1 255.255.255.0

#

interface GigabitEthernet0/1

port link-mode route

nat outbound

ip address 192.168.1.2 255.255.255.0

#

interface GigabitEthernet0/2

port link-mode route

ip address 192.168.100.1 255.255.255.0

#

interface GigabitEthernet0/3

port link-mode route

#

interface GigabitEthernet0/4

port link-mode route

#

interface GigabitEthernet0/5

port link-mode route

#

interface GigabitEthernet0/6

port link-mode route

#

interface GigabitEthernet0/7

port link-mode route

#

interface GigabitEthernet0/8

port link-mode route

#

interface GigabitEthernet0/9

port link-mode route

#

interface GigabitEthernet0/10

port link-mode route

#

interface GigabitEthernet0/11

port link-mode route

#

vd Root id 1

#

zone name Management id 0

priority 100

import interface GigabitEthernet0/0

zone name Local id 1

priority 100

zone name Trust id 2

priority 85

zone name DMZ id 3

priority 50

zone name Untrust id 4

priority 5

switchto vd Root

zone name Management id 0

ip virtual-reassembly

zone name Local id 1

ip virtual-reassembly

zone name Trust id 2

ip virtual-reassembly

zone name DMZ id 3

ip virtual-reassembly

zone name Untrust id 4

ip virtual-reassembly

#

ip route-static 0.0.0.0 0.0.0.0 192.168.1.1

ip route-static 192.168.0.0 255.255.0.0 192.168.100.2

#

load xml-configuration

#

load tr069-configuration

#

user-interface con 0

user-interface vty 0 4

authentication-mode scheme

#

return

[H3C]

1小时前提问

没放策略

1小时前回答

接口加入安全域并放通策略

1小时前回答

我这个版本的防火墙 怎么没有安全域命令

没有这个security-zone

哪到哪不通,怎么测试的

1小时前回答

你正在,H3C F1000-C-G防火墙与三层交换机连接 不通