![](https://i-blog.csdnimg.cn/direct/dbca4792653e4d5eb45e8e4d3b000676.png)
一、需求分析
1.防火墙上配置DHCP服务,完成接口配置
2.用户建立以及认证策略建立
3.安全策略建立
二、详细配置
DHCP配置
[FW1]dhcp enable
[FW1]int g1/0/1.1
[FW1-GigabitEthernet1/0/1.1]dhcp select interface
[FW1]int g1/0/1.2
[FW1-GigabitEthernet1/0/1.2]dhcp select interface
![](https://i-blog.csdnimg.cn/direct/d6fa2af59a9c43979f69f8c2e60a87ce.png)
![](https://i-blog.csdnimg.cn/direct/79bc2c49651e43ecbfc9498b1202c65f.png)
![](https://i-blog.csdnimg.cn/direct/73a7efb3f2f54d8cb904d6e3b493bcb4.png)
![](https://i-blog.csdnimg.cn/direct/463f4a3c67ac4a1ea323a0669f92f6d6.png)
防火墙地址组信息
DMZ Server建立
![](https://i-blog.csdnimg.cn/direct/d5c19ed155114ea8aa8b88c6f62b81db.png)
Trust_A_address建立
![](https://i-blog.csdnimg.cn/direct/f16af34526224969b21b6f73aa6971dd.png)
Trust_B_address建立
![](https://i-blog.csdnimg.cn/direct/2f282607ab3444539d1604f06a948958.png)
OA Server建立
![](https://i-blog.csdnimg.cn/direct/80fd93898f8b4d5db522a1cad32708f7.png)
Web Server建立
![](https://i-blog.csdnimg.cn/direct/6420366f25a24211ba5acd79eb22f83a.png)
DNS Server建立
![](https://i-blog.csdnimg.cn/direct/d19152f264c0471bbbe30f3067f5a56c.png)
Client1、2、3建立
![](https://i-blog.csdnimg.cn/direct/d651c5e4c64e4aa18393c0541a0fa81b.png)
![](https://i-blog.csdnimg.cn/direct/da695a79807d43a29b360d9d7b110646.png)
![](https://i-blog.csdnimg.cn/direct/62cb058e15e044c1bc98f22f9b0a25da.png)
PC1、2建立
![](https://i-blog.csdnimg.cn/direct/2dbc572c95bf4c6c96e4679bfe6fabb9.png)
![](https://i-blog.csdnimg.cn/direct/d6622337d1bb4da6a79e1f56786c507d.png)
管理员建立
![](https://i-blog.csdnimg.cn/direct/52b9f1dd6b2f42509297da4de66d439d.png)
![](https://i-blog.csdnimg.cn/direct/bf6248b941f3437a894f86a903f5b42d.png)
telnet配置
[FW1]telnet server enable
[FW1]user-interface vty 0 4
[FW1-ui-vty0-4]protocol inbound telnet
用户认证配置
认证域建立
![](https://i-blog.csdnimg.cn/direct/dfb08274016948d9b313b6ff4599533d.png)
![](https://i-blog.csdnimg.cn/direct/15cccc8365c1490ead3db532e67a15c6.png)
![](https://i-blog.csdnimg.cn/direct/ebba2cd6058540e69e1e64d634e8bc12.png)
用户组建立
![](https://i-blog.csdnimg.cn/direct/dc3d0671f255408a9fcaec3fb89c56d4.png)
![](https://i-blog.csdnimg.cn/direct/0564117d902e4f8cafb5936ce0db1eda.png)
![](https://i-blog.csdnimg.cn/direct/f4267afac679466a9eda44a7cbe84b92.png)
用户建立
![](https://i-blog.csdnimg.cn/direct/79c1ca7dac774b0d967713f2856607f8.png)
![](https://i-blog.csdnimg.cn/direct/b8b39df11f0e45efbf89fbcbdb04e6c6.png)
![](https://i-blog.csdnimg.cn/direct/0ea5f5f0ebaa4ed5a056793e2eaaa098.png)
![](https://i-blog.csdnimg.cn/direct/ba4a83d9445d4697a81393684e3d4509.png)
![](https://i-blog.csdnimg.cn/direct/2cde0fb7aba747cf9750ef97787bc5c8.png)
![](https://i-blog.csdnimg.cn/direct/b7085123abd24de39b1be52880aadd23.png)
![](https://i-blog.csdnimg.cn/direct/0892e5b2445e404faa42b6a4a74f6866.png)
认证策略
![](https://i-blog.csdnimg.cn/direct/17590a0c7d21471eaa6c7429b4bf00e8.png)
![](https://i-blog.csdnimg.cn/direct/47cc9106215449c0ab8b4d56dd04a49e.png)
![](https://i-blog.csdnimg.cn/direct/0c9f2e9454c4433e962617bf835a285d.png)
![](https://i-blog.csdnimg.cn/direct/7602c306b0cd4daebac5a92f65c18d26.png)
![](https://i-blog.csdnimg.cn/direct/ba5b438c9fae44049083bca086a8a73d.png)
![](https://i-blog.csdnimg.cn/direct/ca5a38abed234264a693b0b01330f75f.png)
![](https://i-blog.csdnimg.cn/direct/25985831d1084008a1b72dedea47f31d.png)
安全策略
policy_1-11
![](https://i-blog.csdnimg.cn/direct/f4a484796e814b4b96088ac2b0fff9ef.png)
![](https://i-blog.csdnimg.cn/direct/6af34fbffa2f445cadeaca5b3bcdcfbd.png)
![](https://i-blog.csdnimg.cn/direct/798f3ae9c8024d3f98f321da1ca0c670.png)
![](https://i-blog.csdnimg.cn/direct/b59f7508e1934220a78a51736e1f4425.png)
![](https://i-blog.csdnimg.cn/direct/7b08d81726c84aef9f8135089b45e3f2.png)
![](https://i-blog.csdnimg.cn/direct/aa9fd09e5db84311923f1251e3642484.png)
![](https://i-blog.csdnimg.cn/direct/177b719b3cab461086db47bfef673056.png)
![](https://i-blog.csdnimg.cn/direct/045f8f3fc8284579b497526029e0f451.png)
![](https://i-blog.csdnimg.cn/direct/a3f36941794e4429a2411769d9a88d3a.png)
![](https://i-blog.csdnimg.cn/direct/8dafe05ffb2a444ca58626d6fea4a7ee.png)
![](https://i-blog.csdnimg.cn/direct/d5afc3b400454615989f1012a5883b9b.png)
![](https://i-blog.csdnimg.cn/direct/09dfb5fa4ae34cd78c92c83512e5828e.png)
![](https://i-blog.csdnimg.cn/direct/cbc73e30e0cf4e0ca4004f334cfdd653.png)
![](https://i-blog.csdnimg.cn/direct/e009352bbd0d4c9ead24008682414780.png)
三、测试
dhcp测试
![](https://i-blog.csdnimg.cn/direct/14b3aba3e69e47b8984a8f5211ad53ee.png)
地址列表![](https://i-blog.csdnimg.cn/direct/0e5689a22acb401d9b57c8ac887b3114.png)
管理员测试
![](https://i-blog.csdnimg.cn/direct/c957a2ce2a5d451eb725d338128874fe.png)
用户组列表
![](https://i-blog.csdnimg.cn/direct/448ab2179a264cda9fa9a748e35297c4.png)
用户列表
![](https://i-blog.csdnimg.cn/direct/bb58e374836e447d8a48e3db1dc45537.png)
安全策略列表
![](https://i-blog.csdnimg.cn/direct/f5f175def289466cbb88eafbf616e902.png)