- 需求
- VLAN2属于办公区;VLAN3属于生产区。
- 办公区PC在工作日时间(周一到周五,早8到玩6)可以正常访问OA server,其他时间不允许。
- 办公区PC可以在任意时刻访问web server。
- 生产去PC可以在任意时刻访问OA server,但是不能访问web server。
- 特例:生产区PC可以在每周一早10到早11访问web server,用来更新企业最新产品信息
- 分析
- 配置IP地址,增加子接口,划分区域
- 进行vlan划分
- 配置安全策略
- 配置
- vlan划分
-
[lsw1]interface g0/0/2 [lsw1-GigabitEthernet0/0/2]port link-a [lsw1-port-group-link-a]port default vlan 2 [lsw1]interface g0/0/3 [lsw1-GigabitEthernet0/0/3]port link-a [lsw1-port-group-link-a]port default vlan 3 [lsw1]interface g0/0/4 [lsw1-GigabitEthernet0/0/4]port link-a [lsw1-port-group-link-a]port default vlan 3 [lsw1]interface g0/0/1 [lsw1-GigabitEthernet0/0/1]port link-a [lsw1-port-group-link-a]port trunk allow-pass vlan 2
- 接口IP地址 区域划分
-
[FW1]interface g1/0/1.1 [FW1-GigabitEthernet1/0/1.1]ip address 192.168.1.126 25 [FW1-GigabitEthernet1/0/1.1]interface g1/0/1.2 [FW1-GigabitEthernet1/0/1.2]ip address 192.168.1.254 25 [FW1-GigabitEthernet1/0/1.2]vlan-type dot1q 3 [FW1-GigabitEthernet1/0/1.2]interface g1/0/1.1 [FW1-GigabitEthernet1/0/1.1]vlan-type dot1q 2 [FW1]firewall zone trust [FW1-zone-trust]add interface GigabitEthernet 1/0/1.1 [FW1-zone-trust]add interface GigabitEthernet 1/0/1.2 [FW1]interface g1/0/0 [FW1-GigabitEthernet1/0/0]ip add 10.0.0.254 24 [FW1]firewall zone dmz [FW1-zone-dmz]add interface g1/0/0
-
- 安全策略
- 命令
- 办公区PC在工作日时间(周一到周五,早8到玩6)可以正常访问OA server,其他时间不允许
-
[FW1]ip address-set BG [FW1-object-address-set-BG]address 192.168.1.0 mask 25 [FW1]ip address-set OA-Server [FW1-object-address-set-OA-Server]address 10.0.0.1 mask 32 [FW1]time-range working-time [FW1-time-range-working-time]period-range 08:00:00 to 18:00:00 working-day [FW1]security-policy [FW1-policy-security]rule name policy_1 [FW1-policy-security-rule-policy_1]description BGtoOA [FW1-policy-security-rule-policy_1]source-zone trust [FW1-policy-security-rule-policy_1]destination-zone dmz [FW1-policy-security-rule-policy_1]source-address address-set BG [FW1-policy-security-rule-policy_1]destination-address address-set OA-server [FW1-policy-security-rule-policy_1]time-range working-time [FW1-policy-security-rule-policy_1]action permit
- 办公区PC可以在任意时刻访问web server
-
[FW1]security-policy [FW1-policy-security]rule name policy_2 [FW1-policy-security-rule-policy_2]description BGtoWeb [FW1-policy-security-rule-policy_2]source-zone trust [FW1-policy-security-rule-policy_2]destination-zone dmz [FW1-policy-security-rule-policy_2]source-address address-set BG [FW1-policy-security-rule-policy_2]destination-address 10.0.0.2 mask 255.255.255 .255 [FW1-policy-security-rule-policy_2]action permit
- 生产去PC可以在任意时刻访问OA server,但是不能访问web server
-
[FW1]ip address-set SC [FW1-object-address-set-SC]address 192.168.1.128 mask 25 [FW1]security-policy [FW1-policy-security]rule name policy_3 [FW1-policy-security-rule-policy_3]source-zone trust [FW1-policy-security-rule-policy_3]destination-zone dmz [FW1-policy-security-rule-policy_3]source-address address-set SC [FW1-policy-security-rule-policy_3]destination-address address-set OA-server [FW1-policy-security-rule-policy_3]description SCtoOA [FW1-policy-security-rule-policy_3]action permit
- 特例:生产区PC可以在每周一早10到早11访问web server,用来更新企业最新产品信息
-
[FW1]time-range special_time [FW1-time-range-special_time]period-range 10:0:0 to 11:0:0 Mon [FW1]security-policy [FW1-policy-security]rule name policy_4 [FW1-policy-security-rule-policy_4]description SCtoWeb_special [FW1-policy-security-rule-policy_4]source-zone trust [FW1-policy-security-rule-policy_4]destination-zone dmz [FW1-policy-security-rule-policy_4]source-address 192.168.1.130 mask 255.255.255 .255 [FW1-policy-security-rule-policy_4]destination-address 10.0.0.2 mask 255.255.255 .255 [FW1-policy-security-rule-policy_4]time-range special_time [FW1-policy-security-rule-policy_4]action permit
- web
- 办公区PC在工作日时间(周一到周五,早8到玩6)可以正常访问OA server,其他时间不允许
- 办公区PC可以在任意时刻访问web server
- 生产去PC可以在任意时刻访问OA server,但是不能访问web server
- 特例:生产区PC可以在每周一早10到早11访问web server,用来更新企业最新产品信息
- 设置时间
- 交换policy_4与policy_5的顺序
- 办公区PC在工作日时间(周一到周五,早8到玩6)可以正常访问OA server,其他时间不允许
- 命令
- 测试
安全策略配置
最新推荐文章于 2025-05-29 19:20:56 发布