
syst
int g0/0/0
dhcp select interface
 dhcp server gateway-list 192.168.0.1
 dhcp server dns-list 100.100.2.100
int g0/0/1
ip add 100.100.100.1 24
int g0/0/2
ip add 172.16.1.1 24
q
firewall zone untrust 
 add int g0/0/1
q
firewall zone dmz 
 add interface g0/0/2
q
policy interzone trust untrust outbound 
policy 1
action permit
q
policy interzone untrust dmz inbound 
policy 2
action permit
q
ip route-s 0.0.0.0 0.0.0.0 100.100.100.2
user-interf con 0
idle-t 0 0
qsyst
sysn SW
vlan ba 2 3 4 10
int vlan 10
ip add 100.100.100.2 24
int vlan 1
ip add 100.100.1.1 24
int vlan 2
ip add 100.100.2.1 24
int vlan 3
ip add 100.100.3.1 24
int vlan 4
ip add 100.100.4.1 24
int eth 0/0/10
port link-t ac
port default vlan 10 
int eth 0/0/1
port link-t ac
port default vlan 1 
int eth 0/0/2
port link-t ac
port default vlan 2 
int eth 0/0/3
port link-t ac
port default vlan 3 
int eth 0/0/4
port link-t ac
port default vlan 4 
user-interf con 0
idle-t 0 0
q映射内部(DMZ)服务器
nat server protocol tcp global 100.100.100.172 80 inside 172.16.1.101 80
nat server protocol tcp global 100.100.100.172 21 inside 172.16.1.101 21
dis nat serversys
firew interzone untrust dmz
 detect ftp
firew interzone trust untrust
 detect qq
dis firew server-map1.
sys
firew blacklist item 192.168.0.2 timeout 2
firew blacklist enable
dis firew blacklist item2.
firewall defend ip-sweep enable
firewall defend ip-sweep max-rate 2
firewall defend ip-sweep blacklist-timeout 20
firewall blacklist enable
dis firew blacklist item 
                             
                            
1 条评论
哈哈哈,写的太好了https://www.lawjida.com/