[Quidway-acl-102]rule deny ip source any destination any
[Quidway]acl 103
[Quidway-acl-103]rule permit tcp source any destination 10.0.0.1 0.0.0.0 destination-port equal ftp
[Quidway-acl-103]rule permit tcp source any destination 10.0.0.2 0.0.0.0 destination-port equal www
[Quidway]firewall enable
[Quidway]firewall default permit|deny
[Quidway]int e0
[Quidway-Ethernet0]firewall packet-filter 101 inbound|outbound
地址转换配置举例
[Quidway]firewall enable
[Quidway]firewall default permit
[Quidway]acl 101
[Quidway-acl-101]rule deny ip source any destination any
[Quidway-acl-101]rule permit ip source 129.38.1.4 0 destination any
[Quidway-acl-101]rule permit ip source 129.38.1.1 0 destination any
[Quidway-acl-101]rule permit ip source 129.38.1.2 0 destination any
[Quidway-acl-101]rule permit ip source 129.38.1.3 0 destination any
[Quidway]acl 102
[Quidway-acl-102]rule permit tcp source 202.39.2.3 0 destination 202.38.160.1 0
[Quidway-acl-102]rule permit tcp source any destination 202.38.160.1 0 destination-port great-than
1024
[Quidway-Ethernet0]firewall packet-filter 101 inbound
[Quidway-Serial0]firewall packet-filter 102 inbound
[Quidway]nat address-group 202.38.160.101 202.38.160.103 pool1
[Quidway]acl 1
[Quidway-acl-1]rule permit source 10.110.10.0 0.0.0.255
[Quidway-acl-1]rule deny source any
[Quidway-acl-1]int serial 0
[Quidway-Serial0]nat outbound 1 address-group pool1
[Quidway-Serial0]nat server global 202.38.160.101 inside 10.110.10.1 ftp tcp
[Quidway-Serial0]nat server global 202.38.160.102 inside 10.110.10.2 www tcp
[Quidway-Serial0]nat server global 202.38.160.102 8080 inside 10.110.10.3 www tcp
[Quidway-Serial0]nat server global 202.38.160.103 inside 10.110.10.4 smtp udp
PPP验证:
主验方:pap|chap
[Quidway]local-user u2 password {simple|cipher} aaa
[Quidway]interface serial 0
[Quidway-serial0]ppp authentication-mode {pap|chap}
[Quidway-serial0]ppp chap user u1 //pap时,不用此句
pap被验方:
[Quidway]interface serial 0
[Quidway-serial0]ppp pap local-user u2 password {simple|cipher} aaa
chap被验方:
[Quidway]interface serial 0
[Quidway-serial0]ppp chap user u1
[Quidway-serial0]local-user u2 password {simple|cipher} aaa
H3C路由器配置方案注解
2010-06-19 22:44
#
version 5.20, Release 1719 //版本信息,自动显示
#
sysname H3C //给设备命名为H3C
#
super password level 3 cipher 7WC1<3E`[Y)./a!1$H@GYA!! //设置super密码
#
domain default enable system
#
telnet server enable
#
vlan 1
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
user-group system //从此以上未标注的为默认配置,不用去理解
#
local-user admin //添加用户名为admin的用户
password cipher .]@USE=B,53Q=^Q`MAF4<1!! //设置密码(密文)
authorization-attribute level 3 //设置用户权限为3级(最高)
service-type telnet //设置用户的模式为telnet用户
local-user share //从此往下四行同上
password cipher [HM$GH8P1GSQ=^Q`MAF4<1!!
authorization-attribute level 1
service-type telnet
#
controller E1 0/0 //进入E1物理端口(两兆口)
using e1 //设置端口模式为E1(设置后下面会出现interface Serial0/0:0)
#
interface Aux0 //从此以下三行为主控板aux口默认配置
async mode flow
link-protocol ppp
#
interface Ethernet0/0 //进入E0/0接口(以太网口)
port link-mode route //配置该接口为路由模式
#
interface Serial0/0:0 //进入Serial0/0:0端口(前面用using e1命令后产生,对应E1端口)
推荐阅读
- iPad Pro 2018评测 ipad2018pro参数配置
- 完美经典服血法可以炸怪练级吗
- 轩逸车手刹卡死怎么办 轩逸经典手刹车怎么调
- 按配置推荐笔记本电脑,行家帮忙指导一下-笔记本电脑配
- 蝴蝶与鲸鱼经典语录
- 巴斯光年的经典语录
- 求SJ 电脑主题安装包,尤其是李特的,要经典耐用的~~~
- 牛吃草问题基本公式经典题目
- 红手指云手机配置怎么看
- 大众朗行13款车怎么样 大众朗行2022款配置