透明网桥模式防火墙配置
发布时间:2011-02-17 14:35:13
发布时间:2011-02-17 14:35:13
1、使用超级终端,名称任意,连接com端口,回车,出现
2、输入一系列配置命令如下:
[H3C]firewall packet-filter enable
[H3C]firewall packet-filter default permit
[H3C]firewall zone trust
[H3C-zone-trust]add interface ethernet0/0
The interface has been added to trust security zone.
[H3C-zone-trust]add interface ethernet0/1
The interface has been added to trust security zone.
[H3C-zone-trust]add interface ethernet0/2
The interface has been added to trust security zone.
[H3C-zone-trust]quit
[H3C]bridge enable
Bridge module has been activated
[H3C]bridge 1 enable
Bridge set has been activated
[H3C]interface bridge-template 1
[H3C-Bridge-template1]ip address 192.168.1.188 255.255.255.0
[H3C-Bridge-template1]quit
[H3C]interface ethernet0/0
[H3C-Ethernet0/0]bridge-set 1
The port has been in the set
[H3C-Ethernet0/0]quit
[H3C]interface ethernet0/1
[H3C-Ethernet0/1]bridge-set 1
The port has been in the set
[H3C-Ethernet0/1]interface ethernet0/2
[H3C-Ethernet0/2]bridge-set 1
The port has been in the set
[H3C-Ethernet0/2]quit
[H3C]firewall zone trust
[H3C-zone-trust]add interface bridge-template 1
The interface has been added to trust security zone.
[H3C-zone-trust]quit
[H3C]save
The configuration will be written to the device.
Are you sure?[Y/N]y
Now saving current configuration to the device.
Saving configuration flash:/config.cfg. Please wait...
................
Current configuration has been saved to the device successfully.
[H3C]
3、进入WEB页面配置IP地址:192.168.1.122 子网掩码:255.255.255.0
IE地址栏:http:// 192.168.1.185(省调项目) 188(SIS网的防火墙)
用户名:Admin 密码:Admin
我们在web页面配置下,没有什么重要的配置,只是要勾选下所有的攻击类型。禁止QQ聊天工具的选项不能选,会导致网页无法浏览!