一、基础网络配置
1. VLAN划分与交换机配置
核心交换机(LSW1)配置:
enable
configure terminal
! 创建VLAN
vlan 2
name OFFICE
vlan 3
name PRODUCTION
! 配置VLAN接口IP
interface Vlan2
ip address 192.168.1.4 255.255.255.0
!
interface Vlan3
ip address 192.168.1.5 255.255.255.0
! 分配接入端口到VLAN
interface Ethernet0/0/1
switchport mode access
switchport access vlan 2
description PC2_Office
!
interface GEO0/0/1
switchport mode access
switchport access vlan 3
description PC_Production
! 配置Trunk端口
interface GE0/0/1
switchport mode trunk
switchport trunk allowed vlan 2,3
description To_FW1
!
end
write memory
接入交换机(LSW2)配置:
enable
configure terminal
vlan 2
name OFFICE
vlan 3
name PRODUCTION
! 服务器端口配置
interface Ethernet0/0/0
switchport mode access
switchport access vlan 2
description OA_Server
!
interface GE0/0/2
switchport mode access
switchport access vlan 2
description Web_Server
! 生产区端口配置
interface GE0/0/3
switchport mode access
switchport access vlan 3
description Production_PC
! 上联Trunk配置
interface GE0/0/1
switchport mode trunk
switchport trunk allowed vlan 2,3
description To_LSW1
!
end
write memory
2. 路由配置
防火墙(FW1)路由配置:
enable
configure terminal
! 内部接口配置
interface GE0/0/0
ip address 10.0.0.254 255.255.255.0
zone trust
!
interface GB1/0/1
ip address 192.168.1.1 255.255.255.0
zone trust
! 静态路由
ip route 10.0.0.0 255.255.255.0 10.0.0.254
ip route 192.168.1.0 255.255.255.0 192.168.1.1
!
end
write memory
二、访问控制策略实现
1. 时间对象定义
time-range WORKTIME
periodic weekdays 8:00 to 18:00
2. ACL策略配置
办公区访问控制:
access-list OFFICE-ACCESS extended permit tcp 192.168.1.0 255.255.255.0 host 10.0.0.1 eq www time-range WORKTIME
access-list OFFICE-ACCESS extended permit ip 192.168.1.0 255.255.255.0 host 10.0.0.2
生产区访问控制:
access-list PRODUCTION-ACCESS extended permit ip 192.168.1.0 255.255.255.0 host 10.0.0.1
access-list PRODUCTION-ACCESS extended deny ip 192.168.1.0 255.255.255.0 host 10.0.0.2
access-list PRODUCTION-ACCESS extended permit ip 192.168.1.0 255.255.255.0 host 10.0.0.2 time-range MONDAY_UPDATE
3. 防火墙策略应用
interface GE0/0/0
ip access-group OFFICE-ACCESS in
ip access-group PRODUCTION-ACCESS in
三、服务器网络配置
OA服务器(10.0.0.1)配置:
sudo nmcli con mod eth0 ipv4.addresses 10.0.0.1/24
sudo nmcli con mod eth0 ipv4.gateway 10.0.0.254
sudo nmcli con mod eth0 ipv4.dns "8.8.8.8"
sudo nmcli con up eth0
sudo iptables -A INPUT -s 192.168.1.0/24 -p tcp --dport 80 -j ACCEPT
sudo iptables -A INPUT -s 192.168.1.0/24 -p tcp --dport 443 -j ACCEPT
sudo iptables -P INPUT DROP
Web服务器(10.0.0.2)配置:
sudo nmcli con mod eth0 ipv4.addresses 10.0.0.2/24
sudo nmcli con mod eth0 ipv4.gateway 10.0.0.254
sudo nmcli con mod eth0 ipv4.dns "8.8.8.8"
sudo nmcli con up eth0
sudo iptables -A INPUT -s 192.168.1.0/24 -p tcp --dport 80 -m time --timestart 16:00 --timestop 11:00 --weekdays Mon -j ACCEPT
sudo iptables -A INPUT -s 192.168.1.4/32 -p tcp --dport 80 -j ACCEPT
sudo iptables -P INPUT DROP
584

被折叠的 条评论
为什么被折叠?



