1、 j A A 3+ G 0; HCDP-IENP w 1 J 4 5 5 W 7- P 7 , j _ 9 L ( j ! aZ o % o0 Ick“(kxh U o“ 70 UkKo 10 Y go fo -o9 9U ) o ooyU“ oUC Uhk _ K(o! i x_ 8.)*6/+466b 4 ,/U ! i| xO “ system-view Enter system view, return user view with Ctrl+Z. Huaweisysname R1 R1interface GigabitEthernet 0/0/1 R1-GigabitEthernet
2、0/0/1ip address 10.0.10.1 24 R1-GigabitEthernet0/0/1interface loopback 0 R1-LoopBack0ip address 10.0.1.1 24 system-view Enter system view, return user view with Ctrl+Z. Huaweisysname R2 R2interface GigabitEthernet0/0/1 R2-GigabitEthernet0/0/1ip address 10.0.20.1 24 R2-GigabitEthernet0/0/1interface l
3、oopback 0 R2-LoopBack0ip address 10.0.2.2 24 system-view Enter system view, return user view with Ctrl+Z. Huaweisysname R3 R3interface GigabitEthernet 0/0/1 R3-GigabitEthernet0/0/1ip address 10.0.30.1 24 R3-GigabitEthernet0/0/1interface loopback 0 R3-LoopBack0ip address 10.0.3.3 24 F k h+ZNKXTKZNM8C
4、AENMkc F /6o F system-view Enter system view, return user view with Ctrl+Z. USG2100sysname FW FWvlan 12 FW-vlan-12quit FWinterface vlanif 12 FW-Vlanif12ip address 10.0.20.254 24 FW-Vlanif12quit FWinterface Ethernet 1/0/0 FW-Ethernet1/0/0port access vlan 12 FW-Ethernet1/0/0interface Ethernet 0/0/0 FW
5、-Ethernet0/0/0ip address 10.0.10.254 24 FW-Ethernet0/0/0interface ethernet 2/0/0 FW-Ethernet2/0/0ip address 10.0.30.254 24 FW-Ethernet2/0/0quit FWinterface Vlanif 1 FW-Vlanif1undo ip address AE 7 L# trust : inbound : default: permit; | IPv6-acl: null outbound : default: permit; | IPv6-acl: null loca
6、l - untrust : inbound : default: deny; | IPv6-acl: null outbound : default: permit; | IPv6-acl: null local - dmz : inbound : default: deny; | IPv6-acl: null outbound : default: permit; | IPv6-acl: null trust - untrust : inbound : default: deny; | IPv6-acl: null outbound : default: deny; | IPv6-acl:
7、null trust - dmz : inbound : default: deny; | IPv6-acl: null outbound : default: deny; | IPv6-acl: null dmz - untrust : inbound : default: deny; | IPv6-acl: null outbound : default: deny; | IPv6-acl: null packet-filter between VFW: Y P 0k .k2UIGR y:XYZ g C * k2UIGR y;TZXYZ gk2UIGRy*3 g * kU g C * o
8、$ *o;TZXYZ:XYZoping -a 10.0.1.1 10.0.2.2 PING 10.0.2.2: 56 data bytes, press CTRL_C to break HCDP-IENP 101 LbTZXYZ*3oping -a 10.0.1.1 10.0.3.3 PING 10.0.3.3: 56 data bytes, press CTRL_C to break Request time out Request time out Request time out Request time out Request time out - 10.0.3.3 ping stat
9、istics - 5 packet(s) transmitted 0 packet(s) received 100.00% packet loss :XYZ;TZXYZoping -a 10.0.2.2 10.0.1.1 PING 10.0.1.1: 56 data bytes, press CTRL_C to break Request time out Request time out Request time out Request time out Request time out - 10.0.1.1 ping statistics - 5 packet(s) transmitted
10、 0 packet(s) received 100.00% packet loss :XYZ*3oping -a 10.0.2.2 10.0.3.3 PING 10.0.3.3: 56 data bytes, press CTRL_C to break HCDP-IENP 101 LbTZXYZoping -a 10.0.3.3 10.0.1.1 PING 10.0.1.1: 56 data bytes, press CTRL_C to break Request time out Request time out Request time out Request time out Reque
11、st time out - 10.0.1.1 ping statistics - 5 packet(s) transmitted 0 packet(s) received 100.00% packet loss *3:XYZoping -a 10.0.3.3 10.0.2.2 PING 10.0.2.2: 56 data bytes, press CTRL_C to break Request time out Request time out Request time out Request time out Request time out - 10.0.2.2 ping statisti
12、cs - 5 packet(s) transmitted 0 packet(s) received 100.00% packet loss ,= y 8k8k8 *oFWping 10.0.10.1 HCDP-IENP 101 LbTZXYZ c /6+ g MTk + g 8o%/6 g4)xke +NI UJR /6G v Oo8Mk%xow F oR1interface LoopBack 1 R1-LoopBack1ip address 10.0.111.1 24 FWip route-static 10.0.111.0 24 10.0.10.1 F MTx 8k MTx y UY t
13、- d%oFWfirewall defend port-scan enable F /6T , f9 VVYo L f96c% ) /6 M J ,o , k U T ) MoFWfirewall defend port-scan max-rate 5000 F d% Uo x 8 d% n 1 Ue t oFWfirewall defend port-scan blacklist-timeout 30 d%$k/6 M 8 M * o y *oR1ping -a 10.0.111.1 10.0.3.3 PING 10.0.3.3: 56 data bytes, press CTRL_C to
14、 break Reply from 10.0.3.3: bytes=56 Sequence=1 ttl=254 time=4 ms Reply from 10.0.3.3: bytes=56 Sequence=2 ttl=254 time=3 ms Reply from 10.0.3.3: bytes=56 Sequence=3 ttl=254 time=3 ms HCDP-IENP 101 Lb9- TCa /69KIsystem-view Enter system view, return user view with Ctrl+Z. Huaweisysname R1 R1interfac
15、e GigabitEthernet 0/0/1 R1-GigabitEthernet0/0/1ip address 10.0.10.2 24 R1-GigabitEthernet0/0/1interface Serial 1/0/0 R1-Serial1/0/0ip address 10.0.12.1 24 R1-Serial1/0/0interface loopback 0 R1-LoopBack0ip address 10.0.1.1 24 system-view Enter system view, return user view with Ctrl+Z. Huaweisysname
16、R2 R2interface GigabitEthernet0/0/2 R2-GigabitEthernet0/0/2ip address 10.0.20.1 24 R2-GigabitEthernet0/0/2interface Serial 1/0/0 R2-Serial1/0/0ip address 10.0.12.2 24 R2-Serial1/0/0interface Serial2/0/0 R2-Serial2/0/0ip address 10.0.23.2 24 R2-Serial2/0/0interface loopback 0 R2-LoopBack0ip address 1
17、0.0.2.2 24 system-view Enter system view, return user view with Ctrl+Z. Huaweisysname R3 R3interface Serial2/0/0 R3-Serial2/0/0ip address 10.0.23.3 24 R3-Serial2/0/0interface loopback 0 R3-LoopBack0ip address 10.0.3.3 24 F ,=y,= NMosystem-view HCDP-IENP 101 LbTZXYZ G ty gkR;TZXYZG2UIGR G ty gkUgGv t W2oFW1firewall packet-filter default permit interzone trust untrust FW1firewall packet-filter default permit interzone local untrust