华为SRG 2200配置模板

#
sysname SQqingnianyishengpeixun
#
l2tp domain suffix-separator @
#
nat address-group 1 183.196.225.207 183.196.225.207
#
undo firewall ipv6 session link-state check
#
dns resolve
#
undo firewall session link-state check
#
#
dns proxy enable
#
license-server domain https://www.360docs.net/doc/bf4014903.html,
#
web-manager enable
#
interface Cellular0/1/0
link-protocol ppp
#
interface GigabitEthernet0/0/0
ip address 192.168.1.254 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 183.196.225.207 255.255.255.224
#
interface NULL0
#
firewall zone local
set priority 100
#
firewall zone trust
set priority 85
detect ftp
add interface GigabitEthernet0/0/0
#
firewall zone untrust
set priority 5
detect ftp
add interface GigabitEthernet0/0/1
#
firewall zone dmz
set priority 50
detect ftp
#
firewall interzone local trust
detect ftp
#
firewall interzone local untrust
detect ftp
#
firewall interzone local dmz
detect ftp
#
firewall interzone trust untrust
detect ftp
#
firewall interzone trust dmz
detect ftp
#
firewall interzone dmz untrust
detect ftp
#
#
aaa
local-user nongmuju password cipher nongmuju123
local-user nongmuju service-type telnet
local-user nongmuju level 15
authentication-scheme default
#
authorization-scheme default
#
accounting-scheme default
#
domain default
domain dot1x
#
#
nqa-jitter tag-version 1

#
load-balance flow source
#
ip route-static 0.0.0.0 0.0.0.0 183.196.225.193
#
banner enable
#
user-interface con 0
user-interface tty 2
authentication-mode none
modem both
user-interface vty 0 4
authentication-mode aaa
protocol inbound all
#
slb
#
cwmp
#
right-manager server-group
#
nat-policy interzone trust untrust outbound
policy 0
action source-nat
policy source 192.168.1.0 mask 255.255.255.0
easy-ip GigabitEthernet0/0/1
#
return

相关主题
相关文档
最新文档