h3c路由器虚拟服务器一个80端口映射多台主机,内网80端口映射到路由器上,配置如下:麻烦高手给指点下...

该楼层疑似违规已被系统折叠 隐藏此楼查看此楼

配置如下:麻烦高手给指点

#

version 5.20, Release 2511P02

#

sysname H3C

#

super password level 3 hash cipher $h$6$S*********$ENKYXBOEJTv/w/nqKBv2U1lSmxZVH8gGMWaDs6mWlG9BusUrPYX9jR/4YT3BbDYI8AMc26HyroTuN/uZ/S+ffA==

#

tcp syn-cookie enable

tcp anti-naptha enable

tcp state closing connection-number 500

tcp state established connection-number 500

tcp state fin-wait-1 connection-number 500

tcp state fin-wait-2 connection-number 500

tcp state last-ack connection-number 500

tcp state syn-received connection-number 500

#

info-center source default channel 2 log level errors

info-center source default channel 9 log level errors

#

domain default enable system

#

dns resolve

dns proxy enable

dns server 202.96.64.68

dns server 202.96.69.38

dns spoofing 202.96.64.68

#

bridge enable

bridge 1 enable

#

telnet server enable

#

dar p2p signature-file flash:/p2p_default.mtd

#

port-security enable

#

ip http acl 199

ip http port 8080

#

password-recovery enable

#

blacklist enable

#

acl number 199

rule 0 deny ssid ChinaNet-B180

rule 65534 permit

#

acl number 3400

rule 0 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.1.11 0 destination-port eq www

#

vlan 1

arp-snooping enable

#

domain system

access-limit disable

state active

idle-cut disable

self-service-url disable

#

dhcp server ip-pool vlan1 extended

network ip range 192.168.1.100 192.168.1.254

network mask 255.255.255.0

gateway-list 192.168.1.1

dns-list 192.168.1.1 202.96.64.68

#

user-group system

#

local-user root

password hash cipher $h$6$6juXLvHOXXydYJwC$OQgAUUWuCU/Mm9PoH8c4x0q********/Q9URymWt0WNtFcBF2m9QCdwkjX05uyveIbu0lzf3JSHd69A==

authorization-attribute level 3

service-type telnet

service-type web

local-user guest

password hash cipher $h$6$WuU4XTszyGy7yDIR$AO2x/JjNO0j8b8dempVh9Bz6MMzCSW/FmpKz8rO8Jc/85sx*********ExbsKvpyLQuEDffhVuPk7/V7Q==

authorization-attribute level 3

service-type telnet terminal

service-type ftp

service-type ppp

service-type web

#

wlan rrm

dot11b mandatory-rate 1 2

dot11b supported-rate 5.5 11

dot11g mandatory-rate 1 2 5.5 11

dot11g supported-rate 6 9 12 18 24 36 48 54

#

wlan service-template 1 crypto

ssid family(xueer)

cipher-suite tkip

cipher-suite ccmp

security-ie rsn

security-ie wpa

service-template enable

#

cwmp

undo cwmp enable

#

attack-defense policy 1

signature-detect action drop-packet

signature-detect fraggle enable

signature-detect land enable

signature-detect winnuke enable

signature-detect tcp-flag enable

signature-detect icmp-unreachable enable

signature-detect icmp-redirect enable

signature-detect tracert enable

signature-detect smurf enable

signature-detect source-route enable

signature-detect route-record enable

signature-detect large-icmp enable

defense scan enable

defense scan add-to-blacklist

defense syn-flood enable

defense syn-flood action drop-packet

defense udp-flood enable

defense udp-flood action drop-packet

defense icmp-flood enable

defense icmp-flood action drop-packet

#

interface Aux0

async mode flow

link-protocol ppp

#

interface Cellular0/0

async mode protocol

link-protocol ppp

attack-defense apply policy 1

#

interface Dialer10

nat outbound

link-protocol ppp

ppp chap user fs_xc12345678

ppp chap password cipher $c$3$KA07FKEQdfaS/hzRLHySlUfrnLQXg3eIeb5A

ppp pap local-user fs_xc12345678 password cipher $c$3$6z/PJS**********c6AOPOYqGojgn

ppp ipcp dns admit-any

ppp ipcp dns request

mtu 1492

ip address ppp-negotiate

tcp mss 1024

dialer user username

dialer-group 10

dialer bundle 10

#

interface Ethernet0/0

nat outbound 3400

port link-mode route

nat server 1 protocol tcp global current-interface www inside 192.168.1.11 www

pppoe-client dial-bundle-number 10

#

interface NULL0

#

interface Vlan-interface1

nat outbound

ip address 192.168.1.1 255.255.255.0

dhcp server apply ip-pool vlan1

#

interface Ethernet0/1

port link-mode bridge

#

interface Ethernet0/2

port link-mode bridge

#

interface Ethernet0/3

port link-mode bridge

#

interface Ethernet0/4

port link-mode bridge

#

interface WLAN-BSS32

port link-type hybrid

port hybrid vlan 1 untagged

port-security port-mode psk

port-security tx-key-type 11key

port-security preshared-key pass-phrase cipher $c$3$Mw8HazhfwCVHvGWTUVoz+VQIgLdGuQSwbixItow=

#

interface WLAN-Radio2/0

radio-type dot11b

service-template 1 interface wlan-bss 32

#

#

voice-setup

#

sip

#

sip-server

#

call-rule-set

#

call-route

#

dial-program

#

aaa-client

#

gk-client

#

ip route-static 0.0.0.0 0.0.0.0 Dialer10

#

dhcp enable

#

dialer-rule 10 ip permit

#

nms primary monitor-interface Dialer10

#

load xml-configuration

#

load tr069-configuration

#

user-interface tty 12

user-interface aux 0

user-interface vty 0 4

authentication-mode scheme

#

return

  • 0
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值