五月天青色头像情侣网名,国产亚洲av片在线观看18女人,黑人巨茎大战俄罗斯美女,扒下她的小内裤打屁股

歡迎光臨散文網(wǎng) 會員登陸 & 注冊

HCIE Datacom培訓(xùn)快速學(xué)習(xí)考試?yán)碚摷夹g(shù)-虛擬防火墻-WOLFLAB實驗室

2023-04-06 18:09 作者:WOLFLAB網(wǎng)絡(luò)技術(shù)實驗室  | 我要投稿

關(guān)注【W(wǎng)OLFLAB網(wǎng)絡(luò)技術(shù)實驗室】華為認(rèn)證HCIE Datacom培訓(xùn)階段提供1v1技術(shù)輔導(dǎo),考試資訊聯(lián)系WOLFLAB!

虛擬防火墻:就是防火墻的vpn-instance

實驗:

需求一:

①兩個部門都可以經(jīng)過FW訪問internet

②部門之間不能互相訪問

[SW1]dis current-configuration?

#

sysname SW1

#

vlan batch 10 20 200 to 204

#

ip vpn-instance caiwu

?ipv4-family

route-distinguisher 1:1

#

ip vpn-instance renshi

?ipv4-family

? route-distinguisher 1:2

#

interface Vlanif10

?ip binding vpn-instance caiwu

?ip address 192.168.10.254 255.255.255.0

#

interface Vlanif20

?ip binding vpn-instance renshi

?ip address 192.168.20.254 255.255.255.0

#

interface Vlanif200

?ip address 1.1.20.1 255.255.255.0

#

interface Vlanif201

?ip address 1.1.21.1 255.255.255.0

#

interface Vlanif202

?ip address 1.1.22.1 255.255.255.0

#

interface Vlanif203

?ip binding vpn-instance caiwu

?ip address 1.1.23.1 255.255.255.0

#

interface Vlanif204

?ip binding vpn-instance renshi

?ip address 1.1.24.1 255.255.255.0

#

interface Eth-Trunk1

?port link-type trunk

?port trunk allow-pass vlan 201 to 204

?mode lacp-static

#

interface GigabitEthernet0/0/1

?port link-type access

?port default vlan 10

#

interface GigabitEthernet0/0/2

?port link-type access

?port default vlan 20

#

interface GigabitEthernet0/0/3

?eth-trunk 1

#

interface GigabitEthernet0/0/4

?eth-trunk 1

#

interface GigabitEthernet0/0/5

?port link-type access

?port default vlan 200

#

ip route-static 0.0.0.0 0.0.0.0 1.1.20.2

ip route-static 192.168.10.0 255.255.255.0 1.1.21.2

ip route-static 192.168.20.0 255.255.255.0 1.1.22.2

ip route-static vpn-instance caiwu 0.0.0.0 0.0.0.0 1.1.23.2

ip route-static vpn-instance renshi 0.0.0.0 0.0.0.0 1.1.24.2

[USG6000V1]?

#

sysname USG6000V1

#

vlan batch 201 to 204

#

?vsys enable? ? ? ? ? ? ? ? ? ? ? ? ? ? ? //開啟虛擬防火墻的功能

#

vsys name caiwu 1? ? ? ? ? ? ? ? ? ? ? ?//創(chuàng)建虛擬防火墻財務(wù)

?assign vlan 201? ? ? ? ? ? ? ? ? ? ? ? ?//將接口vlan201劃入到該虛墻?

?assign vlan 203

#

vsys name renshi 2

?assign vlan 202

?assign vlan 204

#

interface Vlanif201

?ip binding vpn-instance caiwu

?ip address 1.1.21.2 255.255.255.0

#

interface Vlanif202

?ip binding vpn-instance renshi

?ip address 1.1.22.2 255.255.255.0

#

interface Vlanif203

?ip binding vpn-instance caiwu

?ip address 1.1.23.2 255.255.255.0

#

interface Vlanif204

?ip binding vpn-instance renshi

?ip address 1.1.24.2 255.255.255.0

#

interface Eth-Trunk1

?portswitch

?port link-type trunk

?port trunk allow-pass vlan 201 to 204

?mode lacp-static

#

interface GigabitEthernet1/0/0

?undo shutdown

?eth-trunk 1

#

interface GigabitEthernet1/0/1

?undo shutdown

?eth-trunk 1

#

interface Virtual-if0? ? ?//虛擬接口是自動生成的,public是0,按照創(chuàng)建虛墻的順序依次是1、2

#

interface Virtual-if1

#

interface Virtual-if2

#

switch vsys caiwu? ? ? ?//進(jìn)入到虛墻caiwu下

#

interface Vlanif201

?ip binding vpn-instance caiwu

?ip address 1.1.21.2 255.255.255.0

#

interface Vlanif203

?ip binding vpn-instance caiwu

?ip address 1.1.23.2 255.255.255.0

#

interface Virtual-if1

#

firewall zone trust? ? ? ? ? ? ? ? ? //將接口劃入到虛墻的安全區(qū)域

?set priority 85

?add interface Vlanif203

#

firewall zone untrust

?set priority 5

?add interface Vlanif201

#

security-policy? ? ? ? ? ? ? ? ? ? ? ?//創(chuàng)建安全策略

?rule name caiwu_to_internet

? source-zone trust

? destination-zone untrust

? source-address 192.168.10.0 mask 255.255.255.0

? action permit

#

ip route-static 0.0.0.0 0.0.0.0 1.1.21.1

ip route-static 192.168.10.0 255.255.255.0 1.1.23.1

#

return

#

switch vsys renshi?

#

interface Vlanif202

?ip binding vpn-instance renshi

?ip address 1.1.22.2 255.255.255.0

#

interface Vlanif204

?ip binding vpn-instance renshi

?ip address 1.1.24.2 255.255.255.0

#

interface Virtual-if2

#

firewall zone trust

?set priority 85

?add interface Vlanif204

#

firewall zone untrust

?set priority 5

?add interface Vlanif202

#

security-policy

?rule name renshi_to_internet

? source-zone trust

? destination-zone untrust

? source-address 192.168.20.0 mask 255.255.255.0

? action permit

#

ip route-static 0.0.0.0 0.0.0.0 1.1.22.1

ip route-static 192.168.20.0 255.255.255.0 1.1.24.1

#

return??

HCIE Datacom培訓(xùn)實戰(zhàn)練習(xí)需求二:

①兩個部門都可以經(jīng)過訪問internet

②部門之間可以互相訪問但是要經(jīng)過FW

[SW1]ip route-static vpn-instance caiwu 192.168.20.0 24 1.1.23.2

[SW1]ip route-static vpn-instance renshi 192.168.10.0 24 1.1.24.2

[USG6000V1-caiwu-zone-trust]dis this?


2022-12-07 09:08:59.260?

#

firewall zone trust

?set priority 85

?add interface Virtual-if1

[USG6000V1-renshi-zone-trust]dis this?

2022-12-07 09:09:24.790?

#

firewall zone trust

?set priority 85

?add interface Virtual-if2

?add interface Vlanif204

[USG6000V1]ip route-static vpn-instance caiwu 192.168.20.0 24 vpn-instance renshi

[USG6000V1]ip route-static vpn-instance renshi 192.168.10.0 24 vpn-instance caiwu

HCIE Datacom咨詢聯(lián)系WOLFLAB網(wǎng)絡(luò)技術(shù)實驗室

歡迎關(guān)注WOLFLAB(沃爾夫)網(wǎng)絡(luò)實驗室,華為認(rèn)證HCIE認(rèn)證講師:崔志鵬

HCIE Datacom培訓(xùn)快速學(xué)習(xí)考試?yán)碚摷夹g(shù)-虛擬防火墻-WOLFLAB實驗室的評論 (共 條)

分享到微博請遵守國家法律
罗甸县| 闽清县| 卢龙县| 台山市| 边坝县| 余江县| 资阳市| 永泰县| 保定市| 莲花县| 巫溪县| 北流市| 会理县| 贵港市| 连城县| 漾濞| 新干县| 镇远县| 白玉县| 阳朔县| 安龙县| 滁州市| 唐河县| 泰顺县| 苍南县| 德惠市| 华阴市| 安龙县| 承德县| 沙湾县| 天峻县| 定南县| 平山县| 称多县| 隆化县| 太和县| 金坛市| 朔州市| 麻江县| 云林县| 沐川县|