
1.启动设备
2.配置Cloud1
网卡选择8
开启一台win10
设置IP地址为192.168.1.10

启用Telnet功能

3.配置防火墙
第一次登陆时需要输入默认用户名和密码(默认用户名为admin,默认密码为Admin@123)

配置防火墙接口的IP地址
[USG6000V1]int g0/0/0
[USG6000V1-GigabitEthernet0/0/0]ip add 192.168.1.20 24
[USG6000V1-GigabitEthernet0/0/0]q
打开防火墙的Telnet功能
[USG6000V1]telnet server enable
配置防火墙允许远程管理
[USG6000V1]int g0/0/0
[USG6000V1-GigabitEthernet0/0/0]service-manage enable //开启接口管理模式
[USG6000V1-GigabitEthernet0/0/0]service-manage telnet permit //允许Telnet
[USG6000V1-GigabitEthernet0/0/0]q
将防火墙的g0/0/0接口加入安全区域中
[USG6000V1]firewall zone trust
[USG6000V1-zone-trust]add interface g0/0/0
[USG6000V1-zone-trust]q
将防火墙配置域间包过滤,以保证网络基本通信正常。因为 Telnet流量属于防火墙自身收发,所以需要配置 Trust区域到Local区域的安全策略。
[USG6000V1]security-policy
[USG6000V1-policy-security]rule name allow_Telnet //配置规则,allow_Telnet是规则名
[USG6000V1-policy-security-rule-allow_Telnet]source-zone trust
[USG6000V1-policy-security-rule-allow_Telnet]destination-zone local
[USG6000V1-policy-security-rule-allow_Telnet]action permit
[USG6000V1-policy-security-rule-allow_Telnet]q
[USG6000V1-policy-security]q
配置认证模式及本地用户信息。将VTY(Virtual Type Terminal) 用户接口的验证方式配置为AAA, Telnet用户名配置为demo,密码配置为demo@123, 密码的存储方式配置为密文方式(cipher),级别配置为level15。
[USG6000V1]user-interface vty 0 4
[USG6000V1-ui-vty0-4]authentication-mode aaa
[USG6000V1-ui-vty0-4]protocol inbound telnet //允许Telnet连接虚拟终端
[USG6000V1-ui-vty0-4]q
[USG6000V1]aaa
[USG6000V1-aaa]manager-user demo //配置本地用户demo
[USG6000V1-aaa-manager-user-demo]password cipher demo@1234 //配置密码
[USG6000V1-aaa-manager-user-demo]service-type telnet //配置服务类型
[USG6000V1-aaa-manager-user-demo]level 15 //配置用户权限级别
[USG6000V1-aaa-manager-user-demo]q
[USG6000V1-aaa]q
验证:
win10打开cmd输入telnet 192.168.1.20

输入用户名和密码连接防火墙

实验二

实验要求:
按照拓扑图部署网络环境,将防火墙接口加入相应的区域,添加区域访问规则使内网 trust 区域可以访问dmz区域的 web 服务器和 untrust 区域的FTP服务器。
1.启动设备
2.配置IP地址
其他设备略
防火墙:
[USG6000V1]int g0/0/0
[USG6000V1-GigabitEthernet0/0/0]undo ip binding vpn-instance default
[USG6000V1-GigabitEthernet0/0/0]undo alias
[USG6000V1-GigabitEthernet0/0/0]q
[USG6000V1]int g0/0/0
[USG6000V1-GigabitEthernet0/0/0]ip add 192.168.1.1 24
[USG6000V1-GigabitEthernet0/0/0]int g1/0/0
[USG6000V1-GigabitEthernet1/0/0]ip add 192.168.2.1 24
[USG6000V1-GigabitEthernet1/0/0]int g1/0/1
[USG6000V1-GigabitEthernet1/0/1]ip add 202.1.1.1 24
[USG6000V1-GigabitEthernet1/0/1]q
3.给防火墙划分区域
[USG6000V1]firewall zone trust
[USG6000V1-zone-trust]add int
[USG6000V1-zone-trust]add interface g0/0/0
[USG6000V1-zone-trust]q
[USG6000V1]firewall zone dmz
[USG6000V1-zone-dmz]add interface g1/0/0
[USG6000V1-zone-dmz]q
[USG6000V1]firewall zone untrust
[USG6000V1-zone-untrust]add int
[USG6000V1-zone-untrust]add interface g1/0/1
[USG6000V1-zone-untrust]q
4.配置HTTP服务器
5.配置防火墙策略(允许Client访问和pingHTTP服务器)
[USG6000V1]security-policy
[USG6000V1-policy-security]rule name trust2dmz
[USG6000V1-policy-security-rule-trust2dmz]source-zone trust
[USG6000V1-policy-security-rule-trust2dmz]destination-zone dmz
[USG6000V1-policy-security-rule-trust2dmz]service http
[USG6000V1-policy-security-rule-trust2dmz]service https
[USG6000V1-policy-security-rule-trust2dmz]service icmp
[USG6000V1-policy-security-rule-trust2dmz]action permit
[USG6000V1-policy-security-rule-trust2dmz]q
[USG6000V1-policy-security]q
Client可以访问和pingHTTP服务器
6.配置FTP服务器
7.配置防火墙策略(允许Client访问和pingFTP服务器)
[USG6000V1]security-policy
[USG6000V1-policy-security]rule name trust2untrust
[USG6000V1-policy-security-rule-trust2untrust]source-zone trust
[USG6000V1-policy-security-rule-trust2untrust]destination-zone untrust
[USG6000V1-policy-security-rule-trust2untrust]service ftp
[USG6000V1-policy-security-rule-trust2untrust]service icmp
[USG6000V1-policy-security-rule-trust2untrust]action permit
[USG6000V1-policy-security-rule-trust2untrust]q
[USG6000V1-policy-security]q
8.配置OSPF
[AR1]ospf 1
[AR1-ospf-1]area 0
[AR1-ospf-1-area-0.0.0.0]network 61.1.1.0 0.0.0.255
[AR1-ospf-1-area-0.0.0.0]network 202.1.1.0 0.0.0.255
[USG6000V1]ospf 1
[USG6000V1-ospf-1]area 0
[USG6000V1-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255
[USG6000V1-ospf-1-area-0.0.0.0]network 192.168.2.0 0.0.0.255
[USG6000V1-ospf-1-area-0.0.0.0]network 202.1.1.0 0.0.0.255
[USG6000V1-ospf-1-area-0.0.0.0]q
[USG6000V1-ospf-1]q
[USG6000V1]ip service-set 89 type object
[USG6000V1-object-service-set-89]service 0 protocol 89
验证:
使用Client测试:




Client可以访问和pingHTTP服务器、FTP服务器

273

被折叠的 条评论
为什么被折叠?



