发布网友 发布时间:2022-04-23 09:26
共1个回答
热心网友 时间:2023-10-09 11:54
#
sysname Quidway
#
super password level 3 cipher xxxxxxx
#
FTP server enable
#
d* service enable
#
firewall packet-filter enable
#
firewall url-filter parameter add ^select^
firewall url-filter parameter add ^insert^
firewall url-filter parameter add ^update^
firewall url-filter parameter add ^delete^
firewall url-filter parameter add ^drop^
firewall url-filter parameter add --
firewall url-filter parameter add '
firewall url-filter parameter add ^exec^
firewall url-filter parameter add %27
#
firewall statistic system enable
#
firewall defend ip-spoofing
firewall defend smurf
firewall defend ping-of-death
firewall defend port-scan
firewall defend arp-spoofing
firewall defend arp-flood
firewall defend icmp-flood enable
#
radius scheme system
#
domain system
#
local-user admin
password cipher xxxxxx
service-type telnet terminal
#
aspf-policy 1
detect h323
detect rtsp
detect http
detect smtp
detect ftp
detect tcp
detect udp
#
interface Ethernet1/0
ip address 192.168.100.1 255.255.255.0
firewall packet-filter 3000 inbound
firewall packet-filter 3000 outbound
#
interface Ethernet1/1
#
interface Ethernet1/2
#
interface Ethernet1/3
#
interface Ethernet1/4
#
interface Ethernet2/0
speed 10
plex full
ip address x.x.x.x 255.255.255.0
firewall packet-filter 2001 inbound
firewall aspf 1 outbound
nat outbound 2000
#
interface NULL0
#
acl number 2000
rule 0 deny source 192.168.6.0 0.0.0.255
rule 1 deny source 192.168.5.0 0.0.0.255
acl number 2001
rule 0 deny
#
acl number 3000
rule 0 deny udp destination-port eq tftp
rule 1 deny tcp destination-port eq 4444
rule 2 deny tcp destination-port eq 135
rule 3 deny udp destination-port eq 135
rule 4 deny udp destination-port eq netbios-ns
rule 5 deny udp destination-port eq netbios-dgm
rule 6 deny tcp destination-port eq 139
rule 7 deny udp destination-port eq netbios-ssn
rule 8 deny tcp destination-port eq 445
rule 9 deny udp destination-port eq 445
rule 10 deny udp destination-port eq 593
rule 11 deny tcp destination-port eq 593
rule 12 deny tcp destination-port eq 5554
rule 13 deny tcp destination-port eq 9995
rule 14 deny tcp destination-port eq 9996
rule 15 deny udp destination-port eq 1434
#
firewall zone local
set priority 100
#
firewall zone trust
add interface Ethernet1/0
set priority 85
#
firewall zone untrust
add interface Ethernet2/0
set priority 5
#
firewall zone DMZ
set priority 50
#
firewall interzone local trust
#
firewall interzone local untrust
#
firewall interzone local DMZ
#
firewall interzone trust untrust
#
firewall interzone trust DMZ
#
firewall interzone DMZ untrust
#
ip route-static 192.168.2.0 255.255.255.0 192.168.100.254 preference 60
ip route-static 192.168.3.0 255.255.255.0 192.168.100.254 preference 60
ip route-static 192.168.4.0 255.255.255.0 192.168.100.254 preference 60
ip route-static 192.168.7.0 255.255.255.0 192.168.100.254 preference 60
#
user-interface con 0
authentication-mode scheme
user-interface vty 0 4
authentication-mode scheme
#
return
希望对你有帮助!