【网工】华为配置专题进阶篇④

目录

■防火墙配置

▲实验



■防火墙配置

▲实验

配置要求

①防火墙接口的IP地址如拓扑所示,将接口划入相应的安全区域

②内网主机PC1可以主动访问Internet,但Internet无法主动访问PC1。

③出口防火墙进行NAT,NAT公网地址池100.1.1.10 - 100.1.1.20

④Internet可以通过公网地址100.1.1.100/24访问目的地址为192.168.2.100/24 的内部Web服务。

  • Internet

<Huawei>system-view

Huaweisysname Internet

Internetinterface GigabitEthernet 0/0/0

Internet-GigabitEthernet0/0/0ip add 100.1.1.2 24

Internet-GigabitEthernet0/0/0quit

Internet

  • Firewall

<USG6000V1>system-view

USG6000V1]sysname Firewall

Firewall

Firewallinterface GigabitEthernet 1/0/1

Firewall-GigabitEthernet1/0/1ip address 192.168.1.254 24

Firewall-GigabitEthernet1/0/1quit

Firewall linterface GigabitEthernet 1/0/2

Firewall-GigabitEthernet1/0/2ip address 192.168.2.254 24

Firewall-GigabitEthernet1/0/2quit

Firewall interface GigabitEthernet 1/0/3

Firewall-GigabitEthernet1/0/3ip address 100.1.1.1 24

Firewall-GigabitEthernet1/0/3quit

Firewall

Firewallfirewall zone untrust

Firewall-zone-untrustadd interface GigabitEthernet 1/0/3

Firewall-zone-untrustquit

Firewall

Firewallfirewall zone trust

Firewall-zone-trustadd interface GigabitEthernet 1/0/1

Firewall-zone-trustquit

Firewallfirewall zone dmz

Firewall-zone-dmz add interface GigabitEthernet 1/0/2

Firewall-zone-dmzquit

Firewall

Firewallsecurity-policy

Firewall-policy-securityrule name trust_to_untrust

Firewall-policy-security-rule-trust_to_untrustsource-zone trust

Firewall-policy-security-rule-trust_to_untrustdestination-zone untrust

Firewall-policy-security-rule-trust_to_untrustsource-address 192.168.1.0 24

Firewall-policy-security-rule-trust_to_untrustdestination-address any

Firewall-policy-security-rule-trust_to_untrustaction permit

Firewall-policy-security-rule-trust_to_untrustquit

Firewall

配置NAT地址池,开启端口转换。

Firewallnat addr e ss- g roup addressgroupl

Firewall-address-qroup-addressgroup1mode pat

Firewall-address-group-addressgrouplsection 0 100.1.1.10 100.1.1.20

Firewall-address-group-addresagrouplquit

Firewall

配置源NAT策略1,实现私网指定网段访问Internet时自动进行源地址转换。

Firewall nat-policy

Firewall-policy-nat rule name policy_natl

Firewall-policy-nat-rule-policy natlsource-zone trust

Firewall-policy-nat-rule-policy natl destination-zone untrust

Firewall-policy-nat-rule-policy natl source-address192.168.1.0 24

Firewall-policy-nat-rule-policy natl destination-address any

Firewall-policy-nat-rule-policy natl action source-nat address-group addressgroup1

Firewallsecurity-policy

Firewall-policy-securityrule name trust_to_dmz

Firewall-policy-security-rule-trust_to_dmzsource-zone trust

Firewall-policy-security-rule-trust_to_dmzdestination-zone dmz

Firewall-policy-security-rule-trust_to_dmzaction permit

Firewall-policy-security-rule-trust_to_dmzquit

配置NAT Server功能,把内网Web服务映射到公网地址。

Firewall nat server policy_web protocol tcp globa l 100.1.1.100 80 inside 192.168.2.100 80

Firewalldisplay firewall session table

Firewallsecurity-policy

Firewall-policy-securityrule name untrust_to_dmz

Firewall-policy-security-rule-untrust_to_dmzsource-zone untrust

Firewall-policy-security-rule-untrust_to_dmzdestination-zone dmz

Firewall-policy-security-rule-untrust_to_dmzdestination-address 192.168.2.100 32

Firewall-policy-security-rule-untrust_to_dmzaction permit

至此,本文的内容就结束了。

相关推荐
qq_19582165几秒前
6. 应用层协议实现:CoE协议栈集成、对象字典配置、PDO映射
java·服务器·网络
程序猿零零漆21 分钟前
Python核心进阶三连:闭包装饰器、深浅拷贝、网络编程从原理到实战
网络·python
袖手蹲39 分钟前
K10 百炼 AI 语音助手从网络配置到全链路语音交互的嵌入式实战
网络·人工智能·交互
liulilittle40 分钟前
KCC: An Exploration Along the Lines of BBR
网络·tcp/ip·计算机网络·bbr·通信·拥塞控制·kcc
星野爱8951 小时前
云顶之弈7周年新版本!手机随时随地畅玩周年时光机派对
网络·智能手机·电脑
AI科技星1 小时前
第六卷:量天尺传奇(几何学)
网络·人工智能·算法·概率论·学习方法·几何学·拓扑学
酉鬼女又兒1 小时前
零基础入门IPv4地址:从基本概念、分类编址、子网划分到无分类编址与应用规划全解
网络·网络协议·计算机网络·考研·职场和发展·分类·智能路由器
未来侦察班1 小时前
网络协议 数据链路层,“帧”建立统一新秩序
网络·网络协议
ICT系统集成阿祥1 小时前
校园网络准入认证建设与运维经验
运维·网络·智慧校园·经验总结
浮芷.1 小时前
鸿蒙 6.1 新特性-60fps流畅人物跳跃功能算法深度解析-鸿蒙PC端正弦值计算法
算法·华为·harmonyos·鸿蒙·鸿蒙系统