HCL和eve-ng中都有H3C的防火墙,但是都要经过一些配置才能使用web进行管理
下面整理一个无错版,记录一下
system-view
interface GigabitEthernet1/0
ip address 192.168.8.101 24
quit
security-zone name Trust
import interface GigabitEthernet1/0
object-policy ip manage
rule pass
quit
zone-pair security source trust destination local
object-policy apply ip manage
ip http enable
ip https enable
local-user admin class manage
password simple admin
service-type http https
authorization-attribute user-role network-admin
===命令解释
1 system-view //全局视图
2 interface GigabitEthernet1/0/1 //接口ip,根据所连接的网卡进行改动
3 ip address 192.168.0.1 24
4 security-zone name Trust //安全域
5 import interface GigabitEthernet1/0/1 //把接口加入安全域
6 object-policy ip manage //创建对象策略
7 rule pass //规则动作
8 zone-pair security source trust destination local //域间应用
9 object-policy apply ip manage
10 ip http enable //启用http和https的功能
11 ip https enable
12 local-user admin class manage //创建登入web的用户名和密码
13 password simple admin
14 service-type http https
15 authorization-attribute user-role network-admin