[SecPath]display current-configuration
#
sysname SecPath
#
d*** service enable
#
firewall packet-filter enable
firewall packet-filter default deny
#
nat address-group 1 100.1.1.60 100.1.1.61
nat static 172.16.1.2 100.1.1.2
#
firewall statistic system enable
#
radius scheme system
#
domain system
#
interface Aux0
async mode flow
#
interface Ethernet0/0
description OUTSIDE
ip address 100.1.1.10 255.255.255.0
firewall packet-filter 3999 inbound
nat outbound static
nat outbound 3000 address-group 1
nat server protocol tcp global 100.1.1.3 www inside 10.1.1.3 www
#
interface Ethernet1/0
description INSIDE
ip address 192.168.1.10 255.255.255.0
firewall packet-filter 3333 inbound
#
interface Ethernet1/1
#
interface Ethernet1/2
#
interface NULL0
#
acl number 3000
rule 0 permit ip source 192.168.1.0 0.0.0.255
acl number 3333
rule 0 permit ip source 192.168.1.0 0.0.0.255
rule 1 permit ip source 172.16.1.0 0.0.0.255
rule 2 permit ip source 10.1.1.0 0.0.0.255
acl number 3999
rule 0 permit icmp
rule 1 permit tcp destination 100.1.1.3 0 destination-port eq www
#
firewall zone local
set priority 100
#
firewall zone trust
add interface Ethernet1/0
set priority 85
#
firewall zone untrust
add interface Ethernet0/0
set priority 5
#
firewall zone DMZ
set priority 50
#
firewall interzone local trust
#
firewall interzone local untrust
#
firewall interzone local DMZ
#
firewall interzone trust untrust
#
firewall interzone trust DMZ
#
firewall interzone DMZ untrust
#
ospf 1
default-route-advertise always
area 0.0.0.0
network 192.168.1.0 0.0.0.255
#
user-interface con 0
user-interface aux 0
user-interface vty 0 4
#
sysname SecPath
#
d*** service enable
#
firewall packet-filter enable
firewall packet-filter default deny
#
nat address-group 1 100.1.1.60 100.1.1.61
nat static 172.16.1.2 100.1.1.2
#
firewall statistic system enable
#
radius scheme system
#
domain system
#
interface Aux0
async mode flow
#
interface Ethernet0/0
description OUTSIDE
ip address 100.1.1.10 255.255.255.0
firewall packet-filter 3999 inbound
nat outbound static
nat outbound 3000 address-group 1
nat server protocol tcp global 100.1.1.3 www inside 10.1.1.3 www
#
interface Ethernet1/0
description INSIDE
ip address 192.168.1.10 255.255.255.0
firewall packet-filter 3333 inbound
#
interface Ethernet1/1
#
interface Ethernet1/2
#
interface NULL0
#
acl number 3000
rule 0 permit ip source 192.168.1.0 0.0.0.255
acl number 3333
rule 0 permit ip source 192.168.1.0 0.0.0.255
rule 1 permit ip source 172.16.1.0 0.0.0.255
rule 2 permit ip source 10.1.1.0 0.0.0.255
acl number 3999
rule 0 permit icmp
rule 1 permit tcp destination 100.1.1.3 0 destination-port eq www
#
firewall zone local
set priority 100
#
firewall zone trust
add interface Ethernet1/0
set priority 85
#
firewall zone untrust
add interface Ethernet0/0
set priority 5
#
firewall zone DMZ
set priority 50
#
firewall interzone local trust
#
firewall interzone local untrust
#
firewall interzone local DMZ
#
firewall interzone trust untrust
#
firewall interzone trust DMZ
#
firewall interzone DMZ untrust
#
ospf 1
default-route-advertise always
area 0.0.0.0
network 192.168.1.0 0.0.0.255
#
user-interface con 0
user-interface aux 0
user-interface vty 0 4
转载于:https://blog.51cto.com/426440/98767