新华三集团是业界领先的数字化解决方案领导者,致力于成为客户业务创新、数字化转型最可信赖的合作伙伴。主营产品有路由器,大数据,交换机,物联网,云计算,服务器,SDN,NFV,智慧城市,数字经济,数字化转型,数据中心
object object-id description text 缺省情况下,对象没有描述信息。 1.5 配置IPv4地址对象组 (1) 进入系统视图。 system-view (2) 创建IPv4地址对象组,并进入对象组视图。 object-group ip { address | address-yundi } object-group-name 缺省情况下,存在系统默认的IPv4地址对象组,名称为any。 (3) (可选)配...
[H3C]object-group ip address trust1[H3C-obj-grp-ip-trust1]network subnet 192.168.0.0 24[H3C-obj-grp-ip-trust1]quit[H3C]object-group ip address untrust1[H3C-obj-grp-ip-untrust1]network subnet 192.168.10.0 24[H3C-obj-grp-ip-untrust1]quit ...
rule [ rule-id ] { deny | permit } protocol [ { { ack ack-value | fin fin-value | psh psh-value | rst rst-value | syn syn-value | urg urg-value } | established } | counting | destination { object-group address-group-name | dest-address dest-wildcard | any } | destination-...
[H3C]object-group service 8081端口 [H3C-obj-grp-service-8081端口]service tcp destination eq 8081 [H3C-obj-grp-service-8081端口]quit 创建安全策略并放通trust到trust和Untrust到trust的目的地址为OA服务器、目的端口为8081端口的安全策略。 [H3C]security-policy ip ...
Object-groupipaddressclient 1networkhostaddress5# Object-groupipaddressglobal 1networkhostaddress# Object-groupipaddressserver 1networkhostaddress# 为了实现公网主机可以正常访问服务器以下哪个安全策略规则配置是正确的? A、rule1nameclient_to_server Actionpasssource-zoneuntrustdestination-zonetrustsource-ipglobal...
[H3C-zone-pair-security-Trust-Untrust]object-policy apply ip pass [H3C-zone-pair-security-Trust-Untrust]quit 7,配置DHCP服务#开启DHCP服务并指定动态下发的地址以及网关等参数。 [H3C]dhcp enable [H3C]dhcp server ip-pool1[H3C-dhcp-pool-1]network192.168.10.0mask255.255.255.0[H3C-dhcp-pool-1]gatewa...
nataddress-group1address192.168.88.88192.168.88.89quit(7)#在出接口GigabitEthernet1/0/2上配置ACL2001与IP地址池1相关联。PAT方式:进行源地址转换,同时转换源端口interfacegigabitethernet1/0/1natoutbound2001address-group1port-preservedquit6.3验证配置(1)上述配置完成后,内网主机可以访问外网服务器。通过查看如下...
[H3C]object-group ip address trust1[H3C-obj-grp-ip-trust1]network subnet 192.168.0.0 24[H3C-obj-grp-ip-trust1]quit[H3C]object-group ip address untrust1[H3C-obj-grp-ip-untrust1]network subnet 192.168.10.0 24[H3C-obj-grp-ip-untrust1]quit ...
[F1070]display redundancygroupaaa [F1070]display rethintreth2[F1070]display rethintreth2<F1070>reboot slot1(主框) 6、通过display system stable state确认主框板卡正常后,通过 security-policy switch-from object-policy startup.cfg xx.cfg实 现对象策略转换为安全策略,再次重启设备 ...