H3C3600详细配置及说明.docx
《H3C3600详细配置及说明.docx》由会员分享,可在线阅读,更多相关《H3C3600详细配置及说明.docx(20页珍藏版)》请在冰豆网上搜索。
H3C3600详细配置及说明
sysnameH3C
#
superpasswordlevel3simplezyg1949101设置串口连接的密码
#
radiusschemesystem
#
domainsystem说明性文字
#
local-user123
passwordsimplezyg1949101
service-typetelnet
level3
local-userzyg
passwordsimplezyg1949101
service-typetelnet
level3建立web账户密码和权限
#
aclnumber3001
rule0permittcpsource192.168.50.00.0.0.255destination192.168.1.00.0.0.255
rule1permittcpsource192.168.50.00.0.0.255destination192.168.2.00.0.0.255
rule2permittcpsource192.168.50.00.0.0.255destination192.168.10.00.0.0.255
rule3permittcpsource192.168.80.00.0.0.255destination192.168.1.00.0.0.255
rule4permittcpsource192.168.80.00.0.0.255destination192.168.2.00.0.0.255
rule5permittcpsource192.168.80.00.0.0.255destination192.168.10.00.0.0.255
rule6permittcpsource192.168.130.00.0.0.255destination192.168.1.00.0.0.255
rule7permittcpsource192.168.130.00.0.0.255destination192.168.2.00.0.0.255
rule8permittcpsource192.168.130.00.0.0.255destination192.168.10.00.0.0.255
rule9denytcpsource192.168.50.00.0.0.255destination192.168.20.00.0.0.255
rule10denytcpsource192.168.50.00.0.0.255destination192.168.30.00.0.0.255
rule11denytcpsource192.168.50.00.0.0.255destination192.168.40.00.0.0.255
rule12denytcpsource192.168.50.00.0.0.255destination192.168.50.00.0.0.255
rule13denytcpsource192.168.50.00.0.0.255destination192.168.60.00.0.0.255
rule14denytcpsource192.168.50.00.0.0.255destination192.168.70.00.0.0.255
rule15denytcpsource192.168.50.00.0.0.255destination192.168.80.00.0.0.255
rule16denytcpsource192.168.50.00.0.0.255destination192.168.130.00.0.0.255
rule17denytcpsource192.168.80.00.0.0.255destination192.168.20.00.0.0.255
rule18denytcpsource192.168.80.00.0.0.255destination192.168.30.00.0.0.255
rule19denytcpsource192.168.80.00.0.0.255destination192.168.40.00.0.0.255
rule20denytcpsource192.168.80.00.0.0.255destination192.168.50.00.0.0.255
rule21denytcpsource192.168.80.00.0.0.255destination192.168.60.00.0.0.255
rule22denytcpsource192.168.80.00.0.0.255destination192.168.70.00.0.0.255
rule23denytcpsource192.168.80.00.0.0.255destination192.168.80.00.0.0.255
rule24denytcpsource192.168.80.00.0.0.255destination192.168.90.00.0.0.255
rule25denytcpsource192.168.80.00.0.0.255destination192.168.130.00.0.0.255
rule26denytcpsource192.168.50.00.0.0.255destination192.168.90.00.0.0.255
rule27denytcpsource192.168.130.00.0.0.255destination192.168.20.00.0.0.255
rule28denytcpsource192.168.130.00.0.0.255destination192.168.30.00.0.0.255
rule29denytcpsource192.168.130.00.0.0.255destination192.168.40.00.0.0.255
rule30denytcpsource192.168.130.00.0.0.255destination192.168.50.00.0.0.255
rule31denytcpsource192.168.130.00.0.0.255destination192.168.60.00.0.0.255
rule32denytcpsource192.168.130.00.0.0.255destination192.168.70.00.0.0.255
rule33denytcpsource192.168.130.00.0.0.255destination192.168.80.00.0.0.255
rule34denytcpsource192.168.130.00.0.0.255destination192.168.90.00.0.0.255
rule35denytcpsource192.168.130.00.0.0.255destination192.168.130.00.0.0.255
aclnumber3002
rule0permittcpsource192.168.90.00.0.0.255destination192.168.2.00.0.0.255
rule1permittcpsource192.168.90.00.0.0.255destination192.168.40.00.0.0.255
rule2denytcpsource192.168.90.00.0.0.255destination192.168.1.00.0.0.255
rule3denytcpsource192.168.90.00.0.0.255destination192.168.10.00.0.0.255
rule4denytcpsource192.168.90.00.0.0.255destination192.168.20.00.0.0.255
rule5denytcpsource192.168.90.00.0.0.255destination192.168.30.00.0.0.255
rule6denytcpsource192.168.90.00.0.0.255destination192.168.50.00.0.0.255
rule7denytcpsource192.168.90.00.0.0.255destination192.168.60.00.0.0.255
rule8denytcpsource192.168.90.00.0.0.255destination192.168.70.00.0.0.255
rule9denytcpsource192.168.90.00.0.0.255destination192.168.80.00.0.0.255
rule10denytcpsource192.168.90.00.0.0.255destination192.168.130.00.0.0.255
建立高级访问控制列表定义子规则
#
vlan1
descriptionflieserver
#
vlan2
descriptionFanghuoqiang
#
vlan10
descriptionFuWUQi
#
vlan20
descriptionCaiWu
#
vlan30
descriptionWaiMaoKe
#
vlan40
descriptionDaBanGongShi
#
vlan50
descriptionJiShuBu
#
vlan60
descriptionCheJian
#
vlan70
descriptionHuaYi
#
vlan80
descriptionZongCai
----More----
#
vlan90
descriptionwebserver
#
vlan130
descriptionWuXianvlan连接区域说明
#
interfaceVlan-interface1
ipaddress192.168.1.1255.255.255.0
#
interfaceVlan-interface2
ipaddress192.168.2.2255.255.255.0
#
interfaceVlan-interface10
ipaddress192.168.10.1255.255.255.0
#
interfaceVlan-interface20
ipaddress192.168.20.1255.255.255.0
#
interfaceVlan-interface30
ipaddress192.168.30.1255.255.255.0
#
interfaceVlan-interface40
ipaddress192.168.40.1255.255.255.0
#
interfaceVlan-interface50
ipaddress192.168.50.1255.255.255.0
#
interfaceVlan-interface60
ipaddress192.168.60.1255.255.255.0
#
interfaceVlan-interface70
ipaddress192.168.70.1255.255.255.0
#
interfaceVlan-interface80
ipaddress192.168.80.1255.255.255.0
#
interfaceVlan-interface90
ipaddress192.168.90.1255.255.255.0
#
interfaceVlan-interface130
ipaddress192.168.130.1255.255.255.0配置vlan间路由
#
interfaceAux1/0/0
#
interfaceEthernet1/0/1定义端口到vlan
portaccessvlan10
#
interfaceEthernet1/0/2
portaccessvlan10
#
interfaceEthernet1/0/3
portaccessvlan10
line-rateinbound2048
#
interfaceEthernet1/0/4
portaccessvlan90
packet-filterinboundip-group3002rule0应用ACL规则到接口
packet-filterinboundip-group3002rule1
packet-filterinboundip-group3002rule2
packet-filterinboundip-group3002rule3
packet-filterinboundip-group3002rule4
packet-filterinboundip-group3002rule5
packet-filterinboundip-group3002rule6
packet-filterinboundip-group3002rule7
packet-filterinboundip-group3002rule8
packet-filterinboundip-group3002rule9
packet-filterinboundip-group3002rule10
line-rateinbound2048限制出去的带宽为2048kbs
#
interfaceEthernet1/0/5
portaccessvlan20
#
interfaceEthernet1/0/6
portaccessvlan20
#
interfaceEthernet1/0/7
portaccessvlan30
#
interfaceEthernet1/0/8
portaccessvlan30
#
interfaceEthernet1/0/9
portaccessvlan40
line-rateinbound1024
#
interfaceEthernet1/0/10
portaccessvlan40
line-rateinbound1024
#
interfaceEthernet1/0/11
portaccessvlan50
packet-filterinboundip-group3001rule0
packet-filterinboundip-group3001rule1
packet-filterinboundip-group3001rule2
packet-filterinboundip-group3001rule3
packet-filterinboundip-group3001rule4
packet-filterinboundip-group3001rule5
packet-filterinboundip-group3001rule6
packet-filterinboundip-group3001rule7
packet-filterinboundip-group3001rule8
packet-filterinboundip-group3001rule9
packet-filterinboundip-group3001rule10
packet-filterinboundip-group3001rule11
packet-filterinboundip-group3001rule12
packet-filterinboundip-group3001rule13
packet-filterinboundip-group3001rule14
packet-filterinboundip-group3001rule15
packet-filterinboundip-group3001rule16
packet-filterinboundip-group3001rule17
packet-filterinboundip-group3001rule18
packet-filterinboundip-group3001rule19
packet-filterinboundip-group3001rule20
packet-filterinboundip-group3001rule21
packet-filterinboundip-group3001rule22
packet-filterinboundip-group3001rule23
packet-filterinboundip-group3001rule24
packet-filterinboundip-group3001rule25
packet-filterinboundip-group3001rule26
packet-filterinboundip-group3001rule27
packet-filterinboundip-group3001rule28
packet-filterinboundip-group3001rule29
packet-filterinboundip-group3001rule30
packet-filterinboundip-group3001rule31
packet-filterinboundip-group3001rule32
packet-filterinboundip-group3001rule33
packet-filterinboundip-group3001rule34
packet-filterinboundip-group3001rule35应用ACL规则到接口
line-rateinbound1024限制进来的带宽为1024kbs
#
interfaceEthernet1/0/12
portaccessvlan50
packet-filterinboundip-group3001rule0
packet-filterinboundip-group3001rule1
packet-filterinboundip-group3001rule2
packet-filterinboundip-group3001rule3
packet-filterinboundip-group3001rule4
packet-filterinboundip-group3001rule5
packet-filterinboundip-group3001rule6
packet-filterinboundip-group3001rule7
packet-filterinboundip-group3001rule8
packet-filterinboundip-group3001rule9
packet-filterinboundip-group3001rule10
packet-filterinboundip-group3001rule11
packet-filterinboundip-group3001rule12
packet-filterinboundip-group3001rule13
packet-filterinboundip-group3001rule14
packet-filterinboundip-group3001rule15
packet-filterinboundip-group3001rule16
packet-filterinboundip-group3001rule17
packet-filterinboundip-group3001rule18
packet-filterinboundip-group3001rule19
packet-filterinboundip-group3001rule20
packet-filterinboundip-group3001rule21
packet-filterinboundip-group3001rule22
packet-filterinboundip-group3001rule23
packet-filterinboundip-group3001rule24
packet-filterinboundip-group3001rule25
packet-filterinboundip-group3001rule26
packet-filterinboundip-group3001rule27
packet-filterinboundip-g