一、实验拓扑,实验要求

二、需求分析
-
创建
VLAN 2:办公区
VLAN 3:生产区 -
访问控制列表 (ACL):
办公区PC访问OA Server:
允许VLAN 2在周一至周五的8:00至18:00访问OA Server。
拒绝VLAN 2在其他时间访问OA Server。
办公区PC访问Web Server:
允许VLAN 2在任何时间访问Web Server。
生产区PC访问OA Server:
允许VLAN 3在任何时间访问OA Server。
生产区PC访问Web Server:
拒绝VLAN 3访问Web Server,除了PC3在每周一的10:00至11:00。
三、实验配置
1.配置vlan与access、truck接口
[sw1]vlan 2
[sw1]vlan 3
[sw1]interface GigabitEthernet 0/0/1
[sw1-GigabitEthernet0/0/1]port link-type trunk
[sw1-GigabitEthernet0/0/1]port trunk allow-pass vlan all
[sw1-GigabitEthernet0/0/1]interface GigabitEthernet 0/0/2
[sw1-GigabitEthernet0/0/2]port link-type access
[sw1-GigabitEthernet0/0/2]port default vlan 2
[sw1-GigabitEthernet0/0/2]interface GigabitEthernet 0/0/3
[sw1-GigabitEthernet0/0/3]port link-type access
[sw1-GigabitEthernet0/0/3]port default vlan 3
[sw1-GigabitEthernet0/0/3]interface GigabitEthernet 0/0/4
[sw1-GigabitEthernet0/0/4]port link-type access
[sw1-GigabitEthernet0/0/4]port default vlan 3
2.web




[FW]interface GigabitEthernet 1/0/1.1
[FW-GigabitEthernet1/0/1.1]service-manage ping permit
[FW-GigabitEthernet1/0/1.1]interface GigabitEthernet 1/0/1.2
[FW-GigabitEthernet1/0/1.2]service-manage ping permit
3.安全策略
办公区PC在工作日时间可以正常访问OA区其他时间不允许




办公区pc可以任意时刻访问Web区


生产区pc可以任意时刻访问oa,但是不能访问web


生产区pc可以在每周一早10-11访问Web,用来更新企业最新产品信息


使用ensp完成的方法
接口配置
[FW]interface GigabitEthernet 1/0/0
[FW-GigabitEthernet1/0/0]ip address 10.0.0.254 24
[FW]interface GigabitEthernet 1/0/1.1
[FW-GigabitEthernet1/0/1.1]ip address 192.168.1.126 25
[FW-GigabitEthernet1/0/1.1]vlan-type dot1q 2
[FW-GigabitEthernet1/0/1.1]interface GigabitEthernet 1/0/1.2
[FW-GigabitEthernet1/0/1.2]ip address 192.168.1.254 25
[FW-GigabitEthernet1/0/1.2]vlan-type dot1q 3
[FW]firewall zone dmz
[FW-zone-dmz]add interface GigabitEthernet 1/0/0
[FW]firewall zone trust
[FW-zone-trust]add interface GigabitEthernet 1/0/1.1
[FW-zone-trust]add interface GigabitEthernet 1/0/1.2
[FW]display zone
[FW]interface GigabitEthernet 1/0/1.1
[FW-GigabitEthernet1/0/1.1]service-manage ping permit
[FW-GigabitEthernet1/0/1.1]interface GigabitEthernet 1/0/1.2
[FW-GigabitEthernet1/0/1.2]service-manage ping permit
安全策略配置
[FW]ip address-set BGQ
[FW-object-address-set-BGQ]address 192.168.1.0 mask 25
[FW]ip address-set OAS
[FW-object-address-set-OAS]address 10.0.0.1 mask 32
[FW]time-range work
[FW-time-range-work]period-range 08:00:00 to 18:00:00 working-day
[FW]security-policy
[FW-policy-security]rule name polic1
[FW-policy-security-rule-polic1]description BGQ_to_OAS
[FW-policy-security-rule-polic1]source-zone trust
[FW-policy-security-rule-polic1]destination-zone dmz
[FW-policy-security-rule-polic1]source-address address-set BGQ
[FW-policy-security-rule-polic1]destination-address address-set OAS
[FW-policy-security-rule-polic1]time-range work
[FW-policy-security-rule-polic1]action permit
办公区pc可以任意时刻访问web区
[FW]ip address-set Web
[FW-object-address-set-Web]address 10.0.0.2 mask 32
[FW]security-policy
[FW-policy-security]rule name polic2
[FW-policy-security-rule-polic2]description BGQ_to_Web
[FW-policy-security-rule-polic2]source-zone trust
[FW-policy-security-rule-polic2]destination-zone dmz
[FW-policy-security-rule-polic2]source-address address-set BGQ
[FW-policy-security-rule-polic2]destination-address address-set Web
[FW-policy-security-rule-polic2]action permit
生产区pc可以任意时刻访问oa,但是不能访问web
[FW]ip address-set SCQ
[FW-object-address-set-sc]address 192.168.1.128 mask 25
[FW]security-policy
[FW-policy-security]rule name polic3
[FW-policy-security-rule-polic3]description SCQ_to_OAS
[FW-policy-security-rule-polic3]source-zone trust
[FW-policy-security-rule-polic3]destination-zone dmz
[FW-policy-security-rule-polic3]source-address address-set SCQ
[FW-policy-security-rule-polic3]destination-address address-set OAS
10.0.0.1 32)
[FW-policy-security-rule-polic3]action permit
生产区pc可以在每周一早10-11访问web,用来更新企业最新产品信息
[FW]time-range update
[FW-time-range-update]period-range 10:00:00 to 11:00:00 Mon
[FW]security-policy
[FW-policy-security]rule name polic4
[FW-policy-security-rule-polic4]description SCQ_to_Web
[FW-policy-security-rule-polic4]source-zone trust
[FW-policy-security-rule-polic4]destination-zone dmz
[FW-policy-security-rule-polic4]source-address address-set SCQ
[FW-policy-security-rule-polic4]destination-address address-set Web
[FW-policy-security-rule-polic4]time-range update
[FW-policy-security-rule-polic4]action permit
四、结果测试
1.办公区PC访问OA Server
工作时间:成功

其他时间:失败

2.办公区PC访问Web Server
任意时间:成功

3.生产区PC访问OA Server
任意时间:成功


4.生产区PC访问Web Server
周一早10-11:成功


其他时间:失败


查看会话表和server-map表


636

被折叠的 条评论
为什么被折叠?



