cisco

sh run

Building configuration...

 

Current configuration : 6229 bytes

!

version 12.2

no service pad

service timestamps debug uptime

service timestamps log uptime

no service password-encryption

!

hostname WS-C3750G-24T

!

logging buffered 50000 debugging

enable secret 5 $1$r/L/$czg1LCjBagQfO5xFNymm2/

!

username cisco password 0 pasateb4

switch 1 provision ws-c3750g-24ts

ip subnet-zero

ip routing

!

!

mls qos

spanning-tree mode pvst

no spanning-tree optimize bpdu transmission

 --More-- _________        _________spanning-tree extend system-id

!

!

!

!

!

interface GigabitEthernet1/0/1

 switchport access vlan 3

!

interface GigabitEthernet1/0/2

 switchport access vlan 3

!

interface GigabitEthernet1/0/3

 switchport access vlan 3

!

interface GigabitEthernet1/0/4

 switchport access vlan 3

!

interface GigabitEthernet1/0/5

 switchport access vlan 3

!

interface GigabitEthernet1/0/6

 switchport access vlan 3

 --More-- _________        _________!

interface GigabitEthernet1/0/7

 switchport access vlan 3

!

interface GigabitEthernet1/0/8

 switchport access vlan 3

!

interface GigabitEthernet1/0/9

 switchport access vlan 3

!

interface GigabitEthernet1/0/10

 switchport access vlan 3

!

interface GigabitEthernet1/0/11

 switchport access vlan 3

!

interface GigabitEthernet1/0/12

 switchport access vlan 3

!

interface GigabitEthernet1/0/13

 switchport access vlan 2

!

interface GigabitEthernet1/0/14

 --More-- _________        _________ switchport access vlan 2

!

interface GigabitEthernet1/0/15

 switchport access vlan 2

!

interface GigabitEthernet1/0/16

 switchport access vlan 2

!

interface GigabitEthernet1/0/17

 switchport access vlan 2

!

interface GigabitEthernet1/0/18

 switchport access vlan 2

!

interface GigabitEthernet1/0/19

 switchport access vlan 2

!

interface GigabitEthernet1/0/20

 switchport access vlan 2

!

interface GigabitEthernet1/0/21

 switchport access vlan 4

!

 --More-- _________        _________interface GigabitEthernet1/0/22

 switchport access vlan 5

!

interface GigabitEthernet1/0/23

 description to pix (backup)

!

interface GigabitEthernet1/0/24

 description to pix DMZ (backup)

 switchport access vlan 3

!

interface GigabitEthernet1/0/25

 description Backup

!

interface GigabitEthernet1/0/26

!

interface GigabitEthernet1/0/27

!

interface GigabitEthernet1/0/28

!

interface Vlan1

 description VLAN OF network manage

 ip address 192.168.1.254 255.255.255.0

 ip access-group acl-for-vlan1 in

 ip policy route-map pbr2

 --More-- _________        _________!

interface Vlan2

 description VLAN of inside server

 ip address 192.168.2.254 255.255.255.0

 ip access-group acl-for-vlan2 in

!

interface Vlan3

 description vlan of outside server

 ip address 192.168.3.254 255.255.255.0

 ip access-group acl-for-vlan3 in

 ip policy route-map pbr2

!

interface Vlan4

 description vlan of office user

 ip address 192.168.4.254 255.255.255.0

 ip access-group acl-for-vlan4 in

 ip policy route-map pbr2

!

interface Vlan5

 description vlan of inside user

 ip address 192.168.5.254 255.255.255.0

 ip access-group acl-for-vlan5 in

!

 --More-- _________        _________interface Vlan7

 ip address 192.168.7.254 255.255.255.0

!

ip classless

ip route 0.0.0.0 0.0.0.0 192.168.1.252

ip http server

ip http access-class 30

!

!

ip access-list extended acl-for-vlan1

 permit ip 192.168.1.0 0.0.0.255 192.168.5.224 0.0.0.15

 deny   ip 192.168.1.0 0.0.0.255 192.168.4.0 0.0.0.255

 deny   ip 192.168.1.0 0.0.0.255 192.168.5.0 0.0.0.255

 permit ip any any

ip access-list extended acl-for-vlan2

 permit tcp 192.168.2.0 0.0.0.255 any established

 permit tcp 192.168.2.0 0.0.0.255 any syn

 permit ip 192.168.2.0 0.0.0.255 192.168.5.224 0.0.0.15

 permit tcp 192.168.2.0 0.0.0.255 any ack

 permit tcp 192.168.2.0 0.0.0.255 eq 1433 any

 permit udp 192.168.2.0 0.0.0.255 eq domain any

 deny   ip 192.168.3.0 0.0.0.255 192.168.4.0 0.0.0.255

 deny   ip 192.168.3.0 0.0.0.25 192.168.5.0 0.0.0.255

 --More-- _________        _________ permit ip any any

ip access-list extended acl-for-vlan3

 permit tcp 192.168.3.0 0.0.0.255 any established

 permit tcp 192.168.3.0 0.0.0.255 any ack

 permit tcp 192.168.3.0 0.0.0.255 any syn

 permit udp 192.168.3.0 0.0.0.255 eq domain any

 permit ip 192.168.3.0 0.0.0.255 192.168.5.224 0.0.0.15

 permit tcp 192.168.3.0 0.0.0.255 eq www any

 deny   ip 192.168.3.0 0.0.0.25 192.168.5.0 0.0.0.255

 deny   ip 192.168.3.0 0.0.0.255 192.168.4.0 0.0.0.255

 permit ip any any

ip access-list extended acl-for-vlan4

 permit tcp 192.168.4.0 0.0.0.255 192.168.3.0 0.0.0.255 eq www

 permit tcp 192.168.4.0 0.0.0.255 192.168.3.0 0.0.0.255 eq 1494

 permit tcp 192.168.4.0 0.0.0.255 192.168.3.0 0.0.0.255 eq domain

 permit udp 192.168.4.0 0.0.0.255 192.168.3.0 0.0.0.255 eq domain

 permit tcp 192.168.4.0 0.0.0.255 192.168.2.0 0.0.0.255 eq domain

 permit udp 192.168.4.0 0.0.0.255 192.168.2.0 0.0.0.255 eq domain

 permit tcp 192.168.4.0 0.0.0.255 192.168.2.0 0.0.0.255 eq 1433

 deny   ip 192.168.4.0 0.0.0.255 192.168.1.0 0.0.0.255

 deny   ip 192.168.4.0 0.0.0.255 192.168.2.0 0.0.0.255

 deny   ip 192.168.4.0 0.0.0.255 192.168.3.0 0.0.0.255

 permit ip any any

 --More-- _________        _________ip access-list extended acl-for-vlan5

 permit ip 192.168.5.224 0.0.0.15 192.168.3.0 0.0.0.255

 permit ip 192.168.5.224 0.0.0.15 192.168.2.0 0.0.0.255

 permit ip 192.168.5.224 0.0.0.15 192.168.1.0 0.0.0.255

 permit tcp 192.168.5.0 0.0.0.255 192.168.3.0 0.0.0.255 eq 1494

 permit tcp 192.168.5.0 0.0.0.255 192.168.2.0 0.0.0.255 eq domain

 permit udp 192.168.5.0 0.0.0.255 192.168.2.0 0.0.0.255 eq domain

 permit tcp 192.168.5.0 0.0.0.255 192.168.2.0 0.0.0.255 eq 1433

 permit tcp 192.168.5.0 0.0.0.255 192.168.3.0 0.0.0.255 eq www

 deny   ip 192.168.5.0 0.0.0.255 192.168.1.0 0.0.0.255

 deny   ip 192.168.5.0 0.0.0.255 192.168.2.0 0.0.0.255

 deny   ip 192.168.5.0 0.0.0.255 192.168.3.0 0.0.0.255

 permit ip any any

ip access-list extended acl-for-vsan4

 permit ip 192.168.4.0 0.0.0.255 host 192.168.1.252

ip access-list extended net_manage

 permit ip host 192.168.1.1 any

 permit ip host 192.168.1.253 any

 permit ip host 192.168.2.3 any

 permit ip 192.168.4.0 0.0.0.255 any

 permit ip any any

ip access-list extended pbr

 deny   ip 192.168.3.0 0.0.0.255 192.168.0.0 0.0.255.255

 permit ip 192.168.3.0 0.0.0.255 any

ip access-list extended v2

 permit ip any any

!

logging trap debugging

logging 192.168.1.1

access-list 30 permit 192.168.1.1

access-list 30 permit 192.168.5.1

access-list 30 permit 192.168.4.1

route-map pbr2 permit 10

 match ip address pbr

 set ip next-hop 192.168.3.252

!

!

control-plane

!

!

line con 0

line vty 0 4

 password pasateb4

 login local

line vty 5 15

 no login

 --More-- _________        _________!

ntp server 207.46.130.100

end

 

WS-C3750G-24T#wr mem

Building configuration...

[OK]

WS-C3750G-24T#

 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值