SecPath防火墙双机热备典型配置_第1页
SecPath防火墙双机热备典型配置_第2页
SecPath防火墙双机热备典型配置_第3页
SecPath防火墙双机热备典型配置_第4页
SecPath防火墙双机热备典型配置_第5页
已阅读5页,还剩52页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

图3)命令行配置:f1000E01:#version5.20,Feature3101#sysnamefw01#undovoicevlanmac-address00e0-bb00-0000#domaindefaultenablesystem#vlan1#domainsystemaccess-limitdisablestateactiveidle-cutdisableself-service-urldisable#user-groupsystem#local-userh3cpasswordcipherG`M^B<SDBB[Q=^Q`MAF4<1!!authorization-attributelevel3service-typetelnet#interfaceAux0asyncmodeflowlink-protocolppp#interfaceNULL0#interfaceGigabitEthernet0/0portlink-moderouteipaddress1#interfaceGigabitEthernet0/2portlink-moderouteipaddress1vrrpvrid11virtual-ipvrrpvrid11priority105vrrpvrid11trackinterfaceGigabitEthernet0/3#interfaceGigabitEthernet0/3portlink-moderouteipaddress1vrrpvrid122virtual-ip#interfaceGigabitEthernet1/1portlink-moderoute#interfaceGigabitEthernet1/2portlink-moderoute#interfaceGigabitEthernet1/3portlink-moderoute#interfaceGigabitEthernet1/4portlink-moderoute#interfaceGigabitEthernet1/5portlink-moderoute#interfaceGigabitEthernet1/6portlink-moderoute#interfaceGigabitEthernet1/7portlink-moderoute#iproute-static54#arptimeraging1440#loadxml-configuration#user-interfacecon0idle-timeout00user-interfaceaux0user-interfacevty04F1000e02:#version5.20,Feature3101#sysnamefw02#undovoicevlanmac-address00e0-bb00-0000#domaindefaultenablesystem#vlan1#domainsystemaccess-limitdisablestateactiveidle-cutdisableself-service-urldisable#user-groupsystem#local-userh3cpasswordcipherG`M^B<SDBB[Q=^Q`MAF4<1!!authorization-attributelevel3service-typetelnet#interfaceAux0asyncmodeflowlink-protocolppp#interfaceNULL0#interfaceGigabitEthernet0/0portlink-moderouteipaddress2#interfaceGigabitEthernet0/2portlink-moderouteipaddress2vrrpvrid11virtual-ip#interfaceGigabitEthernet0/3portlink-moderouteipaddress2vrrpvrid122virtual-ipvrrpvrid122priority105vrrpvrid122trackinterfaceGigabitEthernet0/2#interfaceGigabitEthernet1/1portlink-moderoute#interfaceGigabitEthernet1/2portlink-moderoute#interfaceGigabitEthernet1/3portlink-moderoute#interfaceGigabitEthernet1/4portlink-moderoute#interfaceGigabitEthernet1/5portlink-moderoute#interfaceGigabitEthernet1/6portlink-moderoute#interfaceGigabitEthernet1/7portlink-moderoute#iproute-static54#loadxml-configuration#user-interfacecon0idle-timeout00user-interfaceaux0user-interfacevty04数据流向:WEB配置:验证结果pc1从serverhttp/ftp、方式get文件,连接不中断;VRRP状态:<fw01>disvrrpIPv4StandbyInformation:RunMethod:VIRTUAL-MACTotalnumberofvirtualrouters:2InterfaceVRIDStateRunAdver.AuthVirtualPriTimeTypeIPGE0/211Master1051NONEGE0/3122Backup1001NONE[fw02-GigabitEthernet0/3]disvrrpIPv4StandbyInformation:RunMethod:VIRTUAL-MACTotalnumberofvirtualrouters:2InterfaceVRIDStateRunAdver.AuthVirtualPriTimeTypeIPGE0/211Backup1001NONEGE0/3122Master1051NONE注意事项本配置完成,清除防火墙中所做的配置,以防对其他配置产生影响。路由模式+负载分担模式+支持非对称路径功能简述(F1000E为例)通过Vlan虚接口实现三层转发。典型配置步骤(组网4)命令行配置:#F1000E-1:#version5.20,Feature3101#sysnamefw01#undovoicevlanmac-address00e0-bb00-0000#nataddress-group154level1nataddress-group254level1#domaindefaultenablesystem#aclnumber3000rule0permitipsource0aclnumber3001rule0permitipsource0#vlan1#domainsystemaccess-limitdisablestateactiveidle-cutdisableself-service-urldisable#user-groupsystem#local-userh3cpasswordcipherG`M^B<SDBB[Q=^Q`MAF4<1!!authorization-attributelevel3service-typetelnet#interfaceAux0asyncmodeflowlink-protocolppp#interfaceNULL0#interfaceGigabitEthernet0/0portlink-moderouteipaddress1#interfaceGigabitEthernet0/2portlink-moderouteipaddress1vrrpvrid11virtual-ipvrrpvrid11priority105vrrpvrid11trackinterfaceGigabitEthernet0/3vrrpvrid111virtual-ip#interfaceGigabitEthernet0/3portlink-moderoutenatoutbound3001address-group2trackvrrp12natoutbound3000address-group1trackvrrp122ipaddress1vrrpvrid12virtual-ipvrrpvrid12priority105vrrpvrid12trackinterfaceGigabitEthernet0/2vrrpvrid122virtual-ip#interfaceGigabitEthernet1/1portlink-moderoute#interfaceGigabitEthernet1/2portlink-moderoute#interfaceGigabitEthernet1/3portlink-moderoute#interfaceGigabitEthernet1/4portlink-moderoute#interfaceGigabitEthernet1/5portlink-moderoute#interfaceGigabitEthernet1/6portlink-moderoute#interfaceGigabitEthernet1/7portlink-moderoute#iproute-static54#arptimeraging1440#loadxml-configuration#user-interfacecon0idle-timeout00user-interfaceaux0user-interfacevty04#returnF1000E-2:#version5.20,Feature3101#sysnamefw02#undovoicevlanmac-address00e0-bb00-0000#ikesanat-keepalive-timerinterval0#nataddress-group154level1nataddress-group254level1#domaindefaultenablesystem#aclnumber3000rule0permitipsource0aclnumber3001rule0permitipsource0#vlan1#domainsystemaccess-limitdisablestateactiveidle-cutdisableself-service-urldisable#user-groupsystem#local-userh3cpasswordcipherG`M^B<SDBB[Q=^Q`MAF4<1!!authorization-attributelevel3service-typetelnet#interfaceAux0asyncmodeflowlink-protocolppp#interfaceNULL0#interfaceGigabitEthernet0/0portlink-moderouteipaddress2#interfaceGigabitEthernet0/2portlink-moderouteshutdownipaddress2vrrpvrid11virtual-ipvrrpvrid111virtual-ipvrrpvrid111priority105vrrpvrid111trackinterfaceGigabitEthernet0/3#interfaceGigabitEthernet0/3portlink-moderoutenatoutbound3001address-group2trackvrrp12natoutbound3000address-group1trackvrrp122ipaddress2vrrpvrid12virtual-ipvrrpvrid122virtual-ipvrrpvrid122priority105vrrpvrid122trackinterfaceGigabitEthernet0/2#interfaceGigabitEthernet1/1portlink-moderoute#interfaceGigabitEthernet1/2portlink-moderoute#in

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论