已阅读5页,还剩2页未读 继续免费阅读




1、一、实验拓扑:二、pc 的配置#sysname pc dhcp enable dns resolvedns server #interface gigabitethernet0/0/0 ip address dhcp-alloc三、网关路由器的配置#sysname gw #dhcp enable dns resolvedns server #acl number 3000rule 5 permit ip source 55acl number 3001rule 5 deny icmp icmp-type echorule

2、10 permit ip #firewall zone trust priority 10#firewall zone untrust priority 5#firewall zone local priority 15#firewall interzone trust untrust firewall enablepacket-filter 3001 inbound detect aspf ftpdetect aspf sip detect aspf rtsp detect aspf httpdetect aspf http java-blocking detect aspf http ac

3、tivex-blocking #interface gigabitethernet0/0/0ip address zone trustdhcp select interfacedhcp server dns-list #interface gigabitethernet0/0/1ip address nat outbound 3000 zone untrust#ip route-static gigabitethernet0/0/1 211.1.1.

4、1 #user-interface vty 0 4 authentication-mode passwordset authentication password cipher huawei user privilege level 3四、公网路由器的配置#sysname internet #ip host 00 ip host 00 #dns resolvedns server dns proxy enable #interface gigabitethernet0/

5、0/0ip address #interface null0 #interface loopback0ip address 00 #interface loopback1ip address 00 #interface loopback100ip address #user-interface vty 0 4 authentication-mode passwordset authenticati

6、on password cipher huawei user privilege level 3#五、测试 pc 上网ping ping : 56 data bytes, press ctrl_c to breakreply from 00: bytes=56 sequence=1 ttl=254 time=20 ms reply from 00: bytes=56 sequence=2 ttl=254 time=20 ms reply from 00: byt

7、es=56 sequence=3 ttl=254 time=10 ms reply from 00: bytes=56 sequence=4 ttl=254 time=10 ms reply from 00: bytes=56 sequence=5 ttl=254 time=30 ms- ping statistics - 5 packet(s) transmitted5 packet(s) received0.00% packet lossround-trip min/avg/max = 10/18/30 ms

8、telnet press ctrl_ to quit telnet mode trying 00 .connected to 00 . login authenticationpassword:huaweidis access-user info: no online user.dis ip inter bri*down: administratively downdown: standby (l): loopback (s): spoofingthe number of interface that is up i

9、n physical is 5 the number of interface that is down in physical is 1 the number of interface that is up in protocol is 5 the number of interface that is down in protocol is 1interfaceip address/maskphysical protocol gigabitethernet0/0/0/24upup gigabitethernet0/0/1unassigneddowndown loopbac

10、k000/24 upup(s)loopback100/24 upup(s)loopback100/24upup(s) null0unassignedupup(s)六、测试网关的状态gwdis nat session allnat session table information: protocol: icmp(1)srcaddr vpn: 54 destaddr vpn: 00type code icmpid : 0 8 43997 nat-infonew srcaddr: 2

11、new destaddr: -new icmpid10255protocol: tcp(6)srcaddr port vpn : 54 46273destaddr port vpn : 00 5888 nat-infonew srcaddr: new srcport10253new destaddr: -new destport: -protocol: udp(17)srcaddr port vpn : 54 7109destaddr port vpn : 13568na

12、t-infogwdis firewall session allfirewall session table information: protocol: tcp(6)srcaddr port vpn : 54 46273destaddr port vpn : 00 5888 firewall-infoinzone: trustoutzone: untrustprotocol: udp(17)srcaddr port vpn : 54 7109destaddr port vpn : 13568firewal

13、l-infoinzone: trustoutzone: untrustprotocol: udp(17)srcaddr port vpn : 54 2245destaddr port vpn : 13568firewall-infoinzone: trustoutzone: untrustprotocol: udp(17)srcaddr port vpn : 54 33990destaddr port vpn : 13568firewall-infoinzone: trustoutzone: untrustprotoc

14、ol: udp(17)srcaddr port vpn : 54 4806destaddr port vpn : 13568firewall-infoinzone: trustoutzone: untrustprotocol: udp(17)srcaddr port vpn : 54 4038destaddr portfirewall-info inzonevpn : : trust13568outzoneprotocol: untrust: tcp(6)srcaddr port vpn : 5

15、4 21700destaddr port vpn : 00 5888 firewall-info“”“”at the end, xiao bian gives you a passage. minand once said, people who learn to learn are very happy people. in every wonderful life, learning is an eternal theme. as a professional clerical and teaching position, i understand the importance of continuous learning, life is diligent, nothing can be gained, only continuous learning can achieve better self. only by constantly learning and mastering the latest relevant knowledge, can employees from all w


  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。


