eNSP—防火墙基本操作3

本文档详细介绍了防火墙的基本配置,包括不同接口的IP地址设置及区域划分。接着,为满足特定需求,配置了多个策略:1) 允许Client1访问Client2的ICMP服务;2) 允许PC1访问PC2的HTTP和FTP服务;3) 只允许Client2访问HTTP服务;4) 客户端通过DNS服务访问100.1.1.1。这些配置确保了网络间的安全通信和访问控制。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

拓扑如下:
在这里插入图片描述

【1】防火墙的基本配置:

[SRG]int g0/0/1
[SRG-GigabitEthernet0/0/1]ip add 10.1.1.254 24
[SRG-GigabitEthernet0/0/1]int g0/0/4
[SRG-GigabitEthernet0/0/4]ip add 10.1.2.254 24
[SRG-GigabitEthernet0/0/4]int g0/0/3
[SRG-GigabitEthernet0/0/3]ip add 100.1.1.254 24
[SRG-GigabitEthernet0/0/3]int g0/0/2
[SRG-GigabitEthernet0/0/2]ip add 20.1.1.254 24
[SRG-GigabitEthernet0/0/2]int g0/0/5
[SRG-GigabitEthernet0/0/5]ip add 20.1.2.254 24
[SRG-GigabitEthernet0/0/5]quit
[SRG]firewall zone trust 
[SRG-zone-trust]add int g0/0/4
[SRG-zone-trust]add int g0/0/1
[SRG-zone-trust]quit
[SRG]firewall zone name dmz1
[SRG-zone-dmz1]set priority 59
[SRG-zone-dmz1]add int g0/0/3
[SRG-zone-dmz1]quit
[SRG]firewall zone untrust 
[SRG-zone-untrust]add int g0/0/2
[SRG-zone-untrust]add int g0/0/5

【2】要求1( client1 可以访问client2 ICMP服务)的配置:

[SRG]policy interzone trust untrust outbound 	
[SRG-policy-interzone-trust-untrust-outbound]policy 1
[SRG-policy-interzone-trust-untrust-outbound-1]policy source 10.1.1.1 0
[SRG-policy-interzone-trust-untrust-outbound-1]policy destination 20.1.1.1 0
[SRG-policy-interzone-trust-untrust-outbound-1]policy service service-set icmp
[SRG-policy-interzone-trust-untrust-outbound-1]action permit 

在这里插入图片描述

【3】要求2(PC1 可以访问PC2 ICMP服务)的配置:

[SRG]policy interzone trust dmz1 outbound 
[SRG-policy-interzone-trust-dmz1-outbound]policy 1
[SRG-policy-interzone-trust-dmz1-outbound-1]policy source 10.1.1.1 0	
[SRG-policy-interzone-trust-dmz1-outbound-1]policy destination 100.1.1.1 0
[SRG-policy-interzone-trust-dmz1-outbound-1]policy service service-set http
[SRG-policy-interzone-trust-dmz1-outbound-1]action permit 
[SRG-policy-interzone-trust-dmz1-outbound-1]quit
[SRG-policy-interzone-trust-dmz1-outbound]policy 2
[SRG-policy-interzone-trust-dmz1-outbound-2]policy source 10.1.1.1 0
[SRG-policy-interzone-trust-dmz1-outbound-2]policy destination 100.1.1.1 0
[SRG-policy-interzone-trust-dmz1-outbound-2]policy service service-set ftp 
[SRG-policy-interzone-trust-dmz1-outbound-2]action permit 
[SRG-policy-interzone-trust-dmz1-outbound-2]quit
[SRG-policy-interzone-trust-dmz1-outbound]quit
[SRG]firewall interzone trust dmz1
[SRG-interzone-trust-dmz1]detect ftp

在这里插入图片描述
在这里插入图片描述

4、要求3(client2只允许访问HTTP服务)的配置:

[SRG]policy interzone untrust dmz1 inbound 
[SRG-policy-interzone-dmz1-untrust-inbound]policy 1
[SRG-policy-interzone-dmz1-untrust-inbound-1]policy source 20.1.1.1 0
[SRG-policy-interzone-dmz1-untrust-inbound-1]policy destination 100.1.1.1 0
[SRG-policy-interzone-dmz1-untrust-inbound-1]policy service service-set http
[SRG-policy-interzone-dmz1-untrust-inbound-1]action permit 

在这里插入图片描述

5、要求4(client1可以通过域名来访问100.1.1.1)的配置:

[SRG-policy-interzone-trust-dmz1-outbound]policy 3
[SRG-policy-interzone-trust-dmz1-outbound-3]policy source 10.1.1.1 0
[SRG-policy-interzone-trust-dmz1-outbound-3]policy destination 100.1.1.1 0	
[SRG-policy-interzone-trust-dmz1-outbound-3]policy service service-set dns	
[SRG-policy-interzone-trust-dmz1-outbound-3]action permit 

在这里插入图片描述

在这里插入图片描述
在这里插入图片描述

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值