您的位置 首页 > 数码极客

「手机防火墙如何更改设置方法」oppo手机防火墙在哪里设置方法!

设置区域:

1、进入到对应区域

2、将对应接口添加到该区域

检查区域接口命令 display zone

防火墙接口下开启ping service-manage ping permit

防火墙接口下开启https service-manage https permit

策略配置:

数据中心

trus和untrust域间:允许内网访问外网

允许源地址192.168.0.0 24的网段报文通过

[SRG]policy interzone trust untrust outbound

[SRG-policy-interzone-trust-untrust-outbound]policy 1

[SRG-policy-interzone-trust-untrust-outbound-1]policy source 192.168.0.0 0.0.255.255

[SRG-policy-interzone-trust-untrust-outbound-1]action permit

[SRG]firewall packet-filter default permit interzone trust untrust direction out

bound 允许所有内网地址访问公网//必须

DMZ和untrust域间:公网访问内网服务器

policy 2:允许目的地址为10.1.1.0 目的端口为21的报文通过

[SRG]policy interzone untrust dmz inbound

[SRG-policy-interzone-dmz-untrust-inbound]policy 2

[SRG-policy-interzone-dmz-untrust-inbound-2]policy destination 10.1.1.10 0

[SRG-policy-interzone-dmz-untrust-inbound-2]policy service service-set http

trus和DMZ域间:允许内网访问外网

policy 3:允许源地址192.168.0.0 24的网段报文通过

[SRG]policy interzone trust dmz outbound

[SRG-policy-interzone-trust-dmz-outbound]policy 3

[SRG-policy-interzone-trust-dmz-outbound-3]policy source 192.168.0.0 0.0.255.255

[SRG-policy-interzone-trust-dmz-outbound-3]action permit

[SRG-policy-interzone-trust-dmz-outbound]q

服务器配置:

[SRG]nat server protocol tcp global 200.1.1.1 80 inside 10.1.1.10 http

NAT配置:

[SRG]nat-policy interzone trust untrust outbound

[SRG-nat-policy-interzone-trust-untrust-outbound]policy 0

[SRG-nat-policy-interzone-trust-untrust-outbound-0]policy source 192.168.1.0 0.0.0.255

[SRG-nat-policy-interzone-trust-untrust-outbound-0]action source-nat

[SRG-nat-policy-interzone-trust-untrust-outbound-0]easy-ip GigabitEthernet 0/0/2

[SRG-nat-policy-interzone-trust-untrust-outbound]q

[SRG]interface g0/0/2

[SRG-GigabitEthernet0/0/2]nat enable

网络工程师 单选 0人 0% 华为 0人 0% 思科 投票

责任编辑: 鲁达

1.内容基于多重复合算法人工智能语言模型创作,旨在以深度学习研究为目的传播信息知识,内容观点与本网站无关,反馈举报请
2.仅供读者参考,本网站未对该内容进行证实,对其原创性、真实性、完整性、及时性不作任何保证;
3.本站属于非营利性站点无毒无广告,请读者放心使用!

“手机防火墙如何更改设置方法,oppo手机防火墙在哪里设置方法,手机防火墙在哪里设置方法,vivo手机防火墙在哪里设置方法”边界阅读