华为

一、配置步骤
示例:pandas 是基于NumPy 的一种工具,该工具是为了解决数据分析任务而创建的。
1.区域绑定
将指定接口绑定对应区域:
[FW1]firewall zone trust
[FW1-zone-trust]set priority 85
[FW1-zone-trust]add interface GigabitEthernet1/0/0
[FW1]firewall zone dmz
[FW1-zone-dmz]set priority 50
[FW1-zone-dmz]add interface GigabitEthernet1/0/1
[FW1-zone-dmz]add interface GigabitEthernet1/0/2
[FW1]firewall zone untrust
[FW1-zone-dmz]set priority 5
[FW1-zone-untrust]add interface GigabitEthernet1/0/4
2.IP地址绑定
给Firewall接口添加IP地址:
[FW1]interface GigabitEthernet1/0/0
[FW1-GigabitEthernet1/0/0]ip address 192.168.0.254 24
[FW1]interface GigabitEthernet1/0/1
[FW1-GigabitEthernet1/0/1]ip address 192.168.1.254 24
[FW1]interface GigabitEthernet1/0/2
[FW1-GigabitEthernet1/0/2]ip address 192.168.2.254 24
[FW1]interface GigabitEthernet1/0/4
[FW1-GigabitEthernet1/0/4]ip address 192.168.80.2 24
3.创建安全策略
创建Client1访问Web和FTP的安全策略:
security-policy
rule name C1-WEB
source-zone trust
destination-zone dmz
source-address 192.168.0.0 mask 255.255.255.0
destination-address 192.168.1.1 mask 255.255.255.255
service http
action permit
rule name C1-FTP
source-zone trust
destination-zone dmz
source-address 192.168.0.0 mask 255.255.255.0
destination-address 192.168.2.1 mask 255.255.255.255
service ftp
service icmp
action permit
rule name C1-untru
source-zone trust
destination-zone untrust
service icmp
action permit
4.服务器IP地址的绑定
略
5.访问DMZ区域的FTP服务器
下图为Client1操作界面,可以实现本地上传文件和服务器下载文件:

抓取FTP上数据包,可以清楚的看到Client1的IP地址
给出接口添加NAT转换,能够有效隐藏内部IP地址
nat-policy
rule name Esay_ip
source-zone trust
egress-interface GigabitEthernet1/0/1
egress-interface GigabitEthernet1/0/2
egress-interface GigabitEthernet1/0/4
source-address 192.168.0.0 mask 255.255.255.0
action source-nat easy-ip

6.访问DMZ区域的WEB服务器


7.访问Untrust区域

思科







1605

被折叠的 条评论
为什么被折叠?



