syst
int g0/0/0
dhcp select interface
dhcp server gateway-list 192.168.0.1
dhcp server dns-list 100.100.2.100
int g0/0/1
ip add 100.100.100.1 24
int g0/0/2
ip add 172.16.1.1 24
q
firewall zone untrust
add int g0/0/1
q
firewall zone dmz
add interface g0/0/2
q
policy interzone trust untrust outbound
policy 1
action permit
q
policy interzone untrust dmz inbound
policy 2
action permit
q
ip route-s 0.0.0.0 0.0.0.0 100.100.100.2
user-interf con 0
idle-t 0 0
q
syst
sysn SW
vlan ba 2 3 4 10
int vlan 10
ip add 100.100.100.2 24
int vlan 1
ip add 100.100.1.1 24
int vlan 2
ip add 100.100.2.1 24
int vlan 3
ip add 100.100.3.1 24
int vlan 4
ip add 100.100.4.1 24
int eth 0/0/10
port link-t ac
port default vlan 10
int eth 0/0/1
port link-t ac
port default vlan 1
int eth 0/0/2
port link-t ac
port default vlan 2
int eth 0/0/3
port link-t ac
port default vlan 3
int eth 0/0/4
port link-t ac
port default vlan 4
user-interf con 0
idle-t 0 0
q
映射内部(DMZ)服务器
nat server protocol tcp global 100.100.100.172 80 inside 172.16.1.101 80
nat server protocol tcp global 100.100.100.172 21 inside 172.16.1.101 21
dis nat server
sys
firew interzone untrust dmz
detect ftp
firew interzone trust untrust
detect qq
dis firew server-map
1.
sys
firew blacklist item 192.168.0.2 timeout 2
firew blacklist enable
dis firew blacklist item
2.
firewall defend ip-sweep enable
firewall defend ip-sweep max-rate 2
firewall defend ip-sweep blacklist-timeout 20
firewall blacklist enable
dis firew blacklist item
1 条评论
哈哈哈,写的太好了https://www.lawjida.com/