单臂路由小实验

该博客详细记录了华为设备的配置过程,涉及VLAN、接口配置、DHCP池设置、IP路由、ACL策略和NAT转换等,重点展示了UTM(统一威胁管理)的安全配置,如IP池管理、DHCP选择、访问控制列表和NAT应用。
摘要由CSDN通过智能技术生成

W1
Huawei>u t m
<Huawei>sys
[Huawei]vl b 100 200
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]p l a
[Huawei-GigabitEthernet0/0/1]p d v 100
[Huawei-GigabitEthernet0/0/1]int g0/0/2
[Huawei-GigabitEthernet0/0/2]p l a
[Huawei-GigabitEthernet0/0/2]p d v 200
[Huawei-GigabitEthernet0/0/2]int g0/0/3
[Huawei-GigabitEthernet0/0/3]p l t 
[Huawei-GigabitEthernet0/0/3]p t a v a
[Huawei-GigabitEthernet0/0/3]int g0/0/4
[Huawei-GigabitEthernet0/0/4]p l t
[Huawei-GigabitEthernet0/0/4]p t a v a
[Huawei-GigabitEthernet0/0/4]
W2
uawei>u t m
<Huawei>sys
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]q
[Huawei]vl b 100 200
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]p l a
[Huawei-GigabitEthernet0/0/1]p d v 100
[Huawei-GigabitEthernet0/0/1]int g0/0/2
[Huawei-GigabitEthernet0/0/2]p l a 
[Huawei-GigabitEthernet0/0/2]p d v 200
[Huawei-GigabitEthernet0/0/2]int g0/0/3
[Huawei-GigabitEthernet0/0/3]p l t
[Huawei-GigabitEthernet0/0/3]p t a v a
R1
<Huawei>u t m
<Huawei>sys
[Huawei]int g0/0/0.1    
[Huawei]dhcp enable 
[Huawei]ip pool 1
[Huawei-ip-pool-1]network 192.168.1.0 mask 26
[Huawei-ip-pool-1]gateway-list 192.168.1.62    
[Huawei-ip-pool-1]dns-list 8.8.8.8    
[Huawei-ip-pool-1]lease day 3
[Huawei-ip-pool-1]q
[Huawei]ip pool 2
[Huawei-ip-pool-2]network 192.168.1.64 m 26
[Huawei-ip-pool-2]gateway-list 192.168.1.126
[Huawei-ip-pool-2]dns-list 8.8.8.8    
[Huawei-ip-pool-2]lease day 3
[Huawei-ip-pool-2]q
[Huawei]int g0/0/0.1    
[Huawei-GigabitEthernet0/0/0.1]dot1q termination vid 100    
[Huawei-GigabitEthernet0/0/0.1]arp broadcast enable 
[Huawei-GigabitEthernet0/0/0.1]ip add 192.168.1.62 26    
[Huawei-GigabitEthernet0/0/0.1]dhcp select global 
[Huawei-GigabitEthernet0/0/0.1]q
[Huawei]int g0/0/0.2    
[Huawei-GigabitEthernet0/0/0.2]dot1q termination vid 200    
[Huawei-GigabitEthernet0/0/0.2]arp broadcast enable 
[Huawei-GigabitEthernet0/0/0.2]ip add 192.168.1.126 26    
[Huawei-GigabitEthernet0/0/0.2]dhcp select global 
[Huawei-GigabitEthernet0/0/0.2]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 10.1.1.1 24
[Huawei]ip route-static 0.0.0.0 0.0.0.0 10.1.1.2
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]q
[Huawei]acl 3000
[Huawei-acl-adv-3000]rule deny icmp source 192.168.1.0 0.0.0.63 destination 100.
1.1.1 0
[Huawei-acl-adv-3000]q    
[Huawei-GigabitEthernet0/0/1]traffic-filter outbound acl 3000
R2
Huawei>u t m
<Huawei>sys.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 10.1.1.2 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]ip route-static 192.168.1.0 24 10.1.1.1
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 200.1.1.1 24
[Huawei-GigabitEthernet0/0/1]q
[Huawei]ip route-static 0.0.0.0 0.0.0.0 200.1.1.2
[Huawei]acl 2000    
[Huawei-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[Huawei-acl-basic-2000]q
[Huawei]int g0/0/1    
[Huawei-GigabitEthernet0/0/1]nat outbound 2000
R3
Huawei>u t m
<Huawei>sys
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 200.1.1.2 24
[Huawei-GigabitEthernet0/0/0]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 100.1.1.254 24

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值