本篇文章为“HUAWEI防火墙开局基础配置”,主要涵盖配置管理地址、聚合端口、安全区域、安全策略、静态路由、ACL,WEB和SSH远程管理、Console、SNMP、NTP时钟、日志主机等内容,对比交换机配置开局,增加两处配置,安全区域和安全策略。方便调试人员远程管理、调试。
区别于“H3C交换机开局基础配置”只是厂商间命令形式的差别,功能实现上一致;
目录
2、HUAWEI防火墙默认用户名admin,密码Admin@123
#Step-1_设备名称配置:
system-view
sysname FW
#Step-2_邻居发现协议:
lldp enable
#Step-3_VLAN配置:
vlan 100
#
vlan 100
description For_Device_Manage
#Step-4_管理IP配置:
interface Vlanif100
description For_DevManage_Vlanif
ip address 172.28.115.253 255.255.255.0
service-manage http permit
service-manage https permit
service-manage ping permit
service-manage ssh permit
service-manage snmp permit
quit
interface GigabitEthernet 1/0/1
undo shutdown
portswitch
port link-type access
port access vlan 100
#华为防火墙端口默认为路由口,默认手动关闭状态;
#Step-5_链路聚接口配置:
interface range G0/0/47 G0/0/48 G0/0/1 G0/0/2
undo shutdown
portswitch
Quit
#华为防火墙端口默认为路由口,默认手动关闭状态;
#
interface Eth-Trunk1
Quit
interface Eth-Trunk11
Quit
#
interface Eth-Trunk1
mode lacp
trunkport GigabitEthernet 0/0/47 to 0/0/48
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 100
#
interface Eth-Trunk11
mode lacp
trunkport GigabitEthernet 0/0/1 to 0/0/2
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 100
Quit
#Step-6_安全区域配置:
firewall zone trust
add interface Eth-Trunk1
add interfa