本篇文章为“H3C防火墙开局基础配置”,主要涵盖配置管理地址、聚合端口、安全区域、安全策略、静态路由、ACL,WEB和SSH远程管理、Console、SNMP、NTP时钟、日志主机等内容,对比交换机配置开局,增加两处配置,安全区域和安全策略。方便调试人员远程管理、调试。
目录
#Step-1_设备名称配置:
system-view
sysname SecPath_F1000
#Step-2_邻居发现协议:
lldp global enable
#Step-3_VLAN配置:
vlan 100
#
vlan 100
description For_Device_Manage
#Step-4_管理IP配置:
interface Vlan-interface100
description For_DevManage_Vlanif
ip address 172.28.115.253 255.255.255.0
quit
interface GigabitEthernet 1/0/1
port link-mode bridge
port link-type access
port access vlan 100
#华三防火墙端口默认为路由口
#Step-5_链路聚接口配置:
interface Bridge-Aggregation 2
Quit
#
interface Ten-GigabitEthernet 1/0/20
port link-mode bridge
description To_Core_S7503X_XG5/0/47
port link-aggregation group 2
interface Ten-GigabitEthernet 1/0/21
port link-mode bridge
description To_Core_S7503X_XG5/0/48
port link-aggregation group 2
Quit
#
interface Bridge-Aggregation2
description To_Core_S7503X_BAGG1
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 100
link-aggregation mode dynamic
#Step-6_安全区域配置:
security-zone name Management
import interface Vlan-interface100
security-zone name Trust
import interface Bridge-Aggregation2 VLAN XXXX