华为Eudemon1000E配置实例

sysname Eudemon1000E
#
 l2tp enable
 l2tp domain suffix-separator @
#
 firewall packet-filter default permit interzone local trust direction inbound
 firewall packet-filter default permit interzone local trust direction outbound
 firewall packet-filter default permit interzone local untrust direction inbound
 firewall packet-filter default permit interzone local untrust direction outbound
 firewall packet-filter default permit interzone local dmz direction inbound
 firewall packet-filter default permit interzone local dmz direction outbound
 firewall packet-filter default permit interzone trust untrust direction inbound
 firewall packet-filter default permit interzone trust untrust direction outbound
 firewall packet-filter default permit interzone trust dmz direction inbound
 firewall packet-filter default permit interzone trust dmz direction outbound
 firewall packet-filter default permit interzone dmz untrust direction inbound
 firewall packet-filter default permit interzone dmz untrust direction outbound
#
 nat address-group 1 202.100.25.166 202.100.25.166
#
 ip df-unreachables enable
#
 firewall ipv6 session link-state check   
 firewall ipv6 statistic system enable
#
 dns resolve
 dns server 114.114.114.114
#
 vlan batch 1 10
#
 firewall statistic system enable
#
 dns proxy enable
#
 license-server domain lic.huawei.com
#
 web-manager enable
#
 user-manage web-authentication port 8888
#
interface Vlanif10
 description To_YongHu
 ip address 10.8.2.1 255.255.254.0
#
interface Cellular0/1/0
 link-protocol ppp                        
#
interface Virtual-Template1
 ppp authentication-mode chap
 ip address 10.1.1.1 255.255.255.0
 remote address pool 1
#
interface GigabitEthernet0/0/0
 alias GE0/MGMT
 ip address 192.168.0.1 255.255.255.0
 dhcp select interface
 dhcp server gateway-list 192.168.0.1
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
 description to  To_YongHu
 portswitch
 port link-type access
 port access vlan 10
#
interface GigabitEthernet0/0/3
 description to  To_YongHu
 portswitch                               
 port link-type access
 port access vlan 10
#
interface GigabitEthernet0/0/4
 description to  To_YongHu
 portswitch
 port link-type trunk
 port trunk pvid 10
 port trunk permit vlan 1 10
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
 combo enable fiber
 portswitch
 port link-type trunk
 port trunk permit vlan 1 10
#
interface GigabitEthernet0/0/8
 combo enable fiber
 ip address 202.100.25.166 255.255.255.192
 nat enable                               
 detect ftp
#
interface NULL0
#
firewall zone local
 set priority 100
#
firewall zone trust
 set priority 85
 add interface GigabitEthernet0/0/0
 add interface GigabitEthernet0/0/4
 add interface GigabitEthernet0/0/7
 add interface Virtual-Template1
 add interface Vlanif10
#
firewall zone untrust
 set priority 5
 add interface GigabitEthernet0/0/8
#
firewall zone dmz
 set priority 50
#
l2tp-group 1
 allow l2tp virtual-template 1 remote client1
 tunnel password cipher %$%$1BY!/0`C,9O>,,W$Lak)/ZQH%$%$
 tunnel name LNS
#
aaa
 local-user gzgl001 password cipher %$%$*[email protected]~IB^}[email protected]]ALE0NE<%$%$
 local-user hz password cipher %$%$q|IO*7I^M&%+/Z"oo1120C:1%$%$
 local-user aa password cipher %$%$[[email protected];QMj:;~j4kV_9.f301(|%$%$
 local-user admin password cipher %$%$a2ogP<;QB8R/,[email protected]{8$N^}tk%$%$
 local-user admin service-type web terminal telnet
 local-user admin level 15
 local-user vpdnuser password cipher %$%$R{u5NI=v"3vjvr9~:gjG/h_V%$%$
 local-user vpdnuser service-type ppp
 local-user vpdnuser level 15
 local-user huawei password cipher %$%$)}w=-M#{<:!o+|‘Mb}O5_D;2%$%$
 local-user huawei service-type telnet
 local-user huawei level 3
 local-user hzgl001 password cipher %$%$0(2c0~v<M1$6b:G‘/!O4/}tk%$%$
 local-user hzgl001 service-type ppp
 ip pool 1 10.1.1.2 10.1.1.100
 #
 authentication-scheme default
 authentication-scheme defauth
 #                                        
 authorization-scheme default
 #
 accounting-scheme default
 #
 domain default
 #
#
nqa-jitter tag-version 1

#
 ip route-static 0.0.0.0 0.0.0.0 GigabitEthernet0/0/8 202.100.25.165
#
 banner enable
#
user-interface con 0
user-interface tty 2
 authentication-mode password
 modem both
user-interface vty 0 4
 authentication-mode aaa
 protocol inbound all
#
 slb                                      
#
right-manager server-group
#
car-class yonghu_1m type per-ip
 car max 2000 guaranteed 1000
#
traffic-policy interzone trust untrust outbound per-ip
 policy 0
  action car
  policy source 10.8.2.0 mask 255.255.254.0
  policy destination 202.100.25.166 mask 32
  policy car-type source-ip
  policy car-class yonghu_1m
#
policy interzone trust untrust outbound
 policy 0
  action permit
#
nat-policy interzone trust untrust outbound
 policy 1
  action source-nat
  policy source 10.8.2.0 mask 255.255.254.0
  policy destination 202.100.25.166 mask 32
  easy-ip GigabitEthernet0/0/8

policy 0
 policy 0 disable
#
return
[Eudemon1000E]        
#
 l2tp enable
 l2tp domain suffix-separator @
#
 firewall packet-filter default permit interzone local trust direction inbound
 firewall packet-filter default permit interzone local trust direction outbound
 firewall packet-filter default permit interzone local untrust direction inbound
 firewall packet-filter default permit interzone local untrust direction outbound
 firewall packet-filter default permit interzone local dmz direction inbound
 firewall packet-filter default permit interzone local dmz direction outbound
 firewall packet-filter default permit interzone trust untrust direction inbound
 firewall packet-filter default permit interzone trust untrust direction outbound
 firewall packet-filter default permit interzone trust dmz direction inbound
 firewall packet-filter default permit interzone trust dmz direction outbound
 firewall packet-filter default permit interzone dmz untrust direction inbound
 firewall packet-filter default permit interzone dmz untrust direction outbound
#
 nat address-group 1 208.100.25.167 202.100.25.168
#
 ip df-unreachables enable
#
 firewall ipv6 session link-state check   
 firewall ipv6 statistic system enable
#
 dns resolve
 dns server 114.114.114.114
#
 vlan batch 1 10
#
 firewall statistic system enable
#
 dns proxy enable
#
 license-server domain lic.huawei.com
#
 web-manager enable
#
 user-manage web-authentication port 8888
#
interface Vlanif10
 description To_YongHu
 ip address 10.8.2.1 255.255.254.0
#
interface Cellular0/1/0
 link-protocol ppp                        
#
interface Virtual-Template1
 ppp authentication-mode chap
 ip address 10.1.1.1 255.255.255.0
 remote address pool 1
#
interface GigabitEthernet0/0/0
 alias GE0/MGMT
 ip address 192.168.0.1 255.255.255.0
 dhcp select interface
 dhcp server gateway-list 192.168.0.1
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
 description to  To_YongHu
 portswitch
 port link-type access
 port access vlan 10
#
interface GigabitEthernet0/0/3
 description to  To_YongHu
 portswitch                               
 port link-type access
 port access vlan 10
#
interface GigabitEthernet0/0/4
 description to  To_YongHu
 portswitch
 port link-type trunk
 port trunk pvid 10
 port trunk permit vlan 1 10
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
 combo enable fiber
 portswitch
 port link-type trunk
 port trunk permit vlan 1 10
#
interface GigabitEthernet0/0/8
 combo enable fiber
 ip address 208.100.25.167 255.255.255.192
 nat enable                               
 detect ftp
#
interface NULL0
#
firewall zone local
 set priority 100
#
firewall zone trust
 set priority 85
 add interface GigabitEthernet0/0/0
 add interface GigabitEthernet0/0/4
 add interface GigabitEthernet0/0/7
 add interface Virtual-Template1
 add interface Vlanif10
#
firewall zone untrust
 set priority 5
 add interface GigabitEthernet0/0/8
#
firewall zone dmz
 set priority 50
#
l2tp-group 1
 allow l2tp virtual-template 1 remote client1
 tunnel password cipher %$%$1BY!/0`C,9O>,,W$Lak)/ZQH%$%$
 tunnel name LNS
#
aaa
 local-user gzgl001 password cipher %$%$*[email protected]~IB^}[email protected]]ALE0NE<%$%$
 local-user hz password cipher %$%$q|IO*7I^M&%+/Z"oo1120C:1%$%$
 local-user aa password cipher %$%$[[email protected];QMj:;~j4kV_9.f301(|%$%$
 local-user admin password cipher %$%$a2ogP<;QB8R/,[email protected]{8$N^}tk%$%$
 local-user admin service-type web terminal telnet
 local-user admin level 15
 local-user vpdnuser password cipher %$%$R{u5NI=v"3vjvr9~:gjG/h_V%$%$
 local-user vpdnuser service-type ppp
 local-user vpdnuser level 15
 local-user huawei password cipher %$%$)}w=-M#{<:!o+|‘Mb}O5_D;2%$%$
 local-user huawei service-type telnet
 local-user huawei level 3
 local-user hzgl001 password cipher %$%$0(2c0~v<M1$6b:G‘/!O4/}tk%$%$
 local-user hzgl001 service-type ppp
 ip pool 1 10.1.1.2 10.1.1.100
 #
 authentication-scheme default
 authentication-scheme defauth
 #                                        
 authorization-scheme default
 #
 accounting-scheme default
 #
 domain default
 #
#
nqa-jitter tag-version 1

#
 ip route-static 0.0.0.0 0.0.0.0 GigabitEthernet0/0/8 208.100.25.169
#
 banner enable
#
user-interface con 0
user-interface tty 2
 authentication-mode password
 modem both
user-interface vty 0 4
 authentication-mode aaa
 protocol inbound all
#
 slb                                      
#
right-manager server-group
#
car-class yonghu_1m type per-ip
 car max 2000 guaranteed 1000
#
traffic-policy interzone trust untrust outbound per-ip
 policy 0
  action car
  policy source 10.8.2.0 mask 255.255.254.0
  policy destination 202.100.25.166 mask 32
  policy car-type source-ip
  policy car-class yonghu_1m
#
policy interzone trust untrust outbound
 policy 0
  action permit
#
nat-policy interzone trust untrust outbound
 policy 1
  action source-nat
  policy source 10.8.2.0 mask 255.255.254.0
  policy destination 202.100.25.166 mask 32
  easy-ip GigabitEthernet0/0/8

policy 0
 policy 0 disable
#
return

时间: 2024-10-14 17:08:10

华为Eudemon1000E配置实例的相关文章

详细讲解多个华为交换机配置实例

详细讲解多个华为交换机配置实例 交换机的配置是网络管理员的基本技能,本文以华为S5700交换机为例,结合使用sNSP模拟器,详细阐述VLAN配置.VLAN之间通信.跨交换机VLAN配置.跨交换机VLAN之间通信等.(备注:以下配置的都是基于交换机接口的VLAN) 一.单台交换机下VLAN配置 1.配置单个VLAN 华为S5700本身默认有个VLAN,若不另行配置,直接接入交换机的终端都属于默认的VLAN,其编号是1.若要手动配置一个指定编号为10的VLAN,可用eNSP创建如下拓扑. 其中LSW

华为MA5620配置宽带及语音实例

华为EPON配置实例 1.公共部分和宽带PPPOE部分 用串口 用户名密码 root/mduadmin MA5620E>enable MA5620E#config MA5620E(config)# MA5620E(config)#sysname  bigcow /给设备起名字/ ****之前为公共部 一. 建vlan和地址 bigcow(config)#vlan 100 /建onu的管理vlan/ bigcow(config)#vlan 3001 to 3016 /这个onu所用pppoe  v

华为stp多实例配置

stp mode mstp stp instance 1 priority 4096stp region-configuration instance 1 vlan 70 100 200 active region-configuration 华为stp多实例配置,布布扣,bubuko.com

交换机配置实例(DHCP、VLAN)

交换机配置实例(DHCP.VLAN) 1. 端口地址配置 int g0/0/1 ip add 172.16.131.5 255.255.255.0 2. 静态路由配置 目的IP 掩码 下一跳 0.0.0.0 0.0.0.0 X.X.X.X ip route-static 0.0.0.0 0.0.0.0 192.168.88.1 这条路由是所有的访问下一跳都是88.1 ip route-static 10.10.100.0 255.255.255.0 10.10.101.1 这条路由是10.10.

详解“FTP文件传输服务”安装配置实例

"FTP文件传输服务"安装配置实例 家住海边喜欢浪:zhang789.blog.51cto.com 目录 简介 ftp工作原理 常见的FTP服务 Vsftpd服务器的安装 Vsftpd.conf配置文件详解 配置FTP服务器实例 实例:配置匿名用户 实例:配置本地用户登录 实例:配置虚拟用户登录(MySQL认证) 实例:控制用户登录 实例:设置欢迎信息 分析vsftpd日志管理 FTP服务器配置与管理 简介 FTP 是File Transfer Protocol(文件传输协议)的英文简

java计划任务调度框架quartz结合spring实现调度的配置实例代码分享

点击链接加入群[JavaEE(SSH+IntelliJIDE+Maven)]:http://jq.qq.com/?_wv=1027&k=L2rbHv 一:quartz简介 OpenSymphony 的Quartz提供了一个比较完美的任务调度解决方案. Quartz 是个开源的作业调度框架,定时调度器,为在 Java 应用程序中进行作业调度提供了简单却强大的机制. Quartz中有两个基本概念:作业和触发器.作业是能够调度的可执行任务,触发器提供了对作业的调度 二:quartz spring配置详

Linux DNS服务器子域授权、转发器和转发域配置实例(三)

DNS子域授权: 这里我们只演示正向解析的子域授权   父域能够解析子域的A记录(不是权威的,因为不是自身解析的),  子域不能解析父域的A记录,如果非要解析父域中的地址过程是:先去找互联网的根域在层层到下查找.(但是我们可以在子域建立转发,使能够解析父域的A记录) 实例: 说明父域为:ning.com子域1为:ning1.ning.com 子域2为:ning2.ning.com  补充说明:父域和子域只要能通信即可,没有必要在同一网段,我们这里为了方便操作放在一个网段了..小伙伴们明白!  实

Keepalived 配置实例

Keepalived 是一款轻量级HA集群应用,它的设计初衷是为了做LVS集群的HA,即探测LVS健康情况,从而进行主备切换,不仅如此,还能够探测LVS代理的后端主机的健康状况,动态修改LVS转发规则. 当LVS进行主备切换的时候,对外提供服务的IP是如何做到切换的呢?这就依赖于keepalived 所应用的vrrp协议,即Virtual Reduntant  Routing Protocol,虚拟冗余路由协议.简单来讲,此协议是将IP设置在虚拟接口之上,根据一定的规则实现IP在物理主机上流动,

cisco冗余GETVPN配置实例

GCKS(config)#do show run Building configuration... Current configuration : 3260 bytes ! upgrade fpd auto version 12.4 service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption ! hostname GCKS ! boot-st