问答文章1 问答文章501 问答文章1001 问答文章1501 问答文章2001 问答文章2501 问答文章3001 问答文章3501 问答文章4001 问答文章4501 问答文章5001 问答文章5501 问答文章6001 问答文章6501 问答文章7001 问答文章7501 问答文章8001 问答文章8501 问答文章9001 问答文章9501

关于Juniper SSG-5-SB防火墙的配置实例或者视频教程?

发布网友 发布时间:2022-04-28 21:17

我来回答

2个回答

热心网友 时间:2022-06-23 05:55

ssg5-serial-> get config
Total Config size 3827:
set clock timezone 0
set vrouter trust-vr sharable
set vrouter "untrust-vr"
exit
set vrouter "trust-vr"
unset auto-route-export
exit
set auth-server "Local" id 0
set auth-server "Local" server-name "Local"
set auth default auth server "Local"
set auth radius accounting port 1646
set admin name "netscreen"
set admin password "nKVUM2rwMUzPcrkG5sWIHdCtqkAibn"
set admin auth timeout 10
set admin auth server "Local"
set admin format dos
set zone "Trust" vrouter "trust-vr"
set zone "Untrust" vrouter "trust-vr"
set zone "DMZ" vrouter "trust-vr"
set zone "VLAN" vrouter "trust-vr"
set zone "Untrust-Tun" vrouter "trust-vr"
set zone "Trust" tcp-rst
set zone "Untrust" block
unset zone "Untrust" tcp-rst
set zone "DMZ" tcp-rst
set zone "VLAN" block
unset zone "VLAN" tcp-rst
set zone "Untrust" screen tear-drop
set zone "Untrust" screen syn-flood
set zone "Untrust" screen ping-death
set zone "Untrust" screen ip-filter-src
set zone "Untrust" screen land
set zone "V1-Untrust" screen tear-drop
set zone "V1-Untrust" screen syn-flood
set zone "V1-Untrust" screen ping-death
set zone "V1-Untrust" screen ip-filter-src
set zone "V1-Untrust" screen land
set interface "ethernet0/0" zone "Untrust"
set interface "ethernet0/1" zone "DMZ"
set interface "ethernet0/2" zone "Trust"
set interface "bgroup0" zone "Trust"
set interface bgroup0 port ethernet0/3
set interface bgroup0 port ethernet0/4
set interface bgroup0 port ethernet0/5
set interface bgroup0 port ethernet0/6
unset interface vlan1 ip
set interface ethernet0/0 ip 10.160.144.201/24#出口接口IP
set interface ethernet0/0 nat
set interface bgroup0 ip 192.168.100.1/24#内网接口IP
set interface bgroup0 nat
unset interface vlan1 bypass-others-ipsec
unset interface vlan1 bypass-non-ip
set interface ethernet0/0 ip manageable
set interface bgroup0 ip manageable
set interface ethernet0/0 manage ping
set interface ethernet0/0 manage telnet
set interface ethernet0/0 manage web
set interface ethernet0/1 manage telnet
set interface ethernet0/1 manage web
set interface ethernet0/2 dhcp client enable
set interface ethernet0/6 dhcp client enable
unset interface ethernet0/2 dhcp client settings update-dhcpserver
unset interface ethernet0/6 dhcp client settings update-dhcpserver
set interface "serial0/0" modem settings "USR" init "AT&F"
set interface "serial0/0" modem settings "USR" active
set interface "serial0/0" modem speed 115200
set interface "serial0/0" modem retry 3
set interface "serial0/0" modem interval 10
set interface "serial0/0" modem idle-time 10
set flow tcp-mss
unset flow no-tcp-seq-check
set flow tcp-syn-check
unset flow tcp-syn-bit-check
set flow reverse-route clear-text prefer
set flow reverse-route tunnel always
set pki authority default scep mode "auto"
set pki x509 default cert-path partial
set ike respond-bad-spi 1
unset ike ikeid-enumeration
unset ike dos-protection
unset ipsec access-session enable
set ipsec access-session maximum 5000
set ipsec access-session upper-threshold 0
set ipsec access-session lower-threshold 0
set ipsec access-session dead-p2-sa-timeout 0
unset ipsec access-session log-error
unset ipsec access-session info-exch-connected
unset ipsec access-session use-error-log
set vrouter "untrust-vr"
exit
set vrouter "trust-vr"
exit
set url protocol websense
exit
set policy id 1 from "Trust" to "Untrust" "Any" "Any" "ANY" permit log count #设置允许上网
set policy id 1
exit
set nsmgmt bulkcli reboot-timeout 60
set ssh version v2
set config lock timeout 5
unset license-key auto-update
set snmp port listen 161
set snmp port trap 162
set vrouter "untrust-vr"
exit
set vrouter "trust-vr"
unset add-default-route
set route 0.0.0.0/0 interface ethernet0/0 gateway 10.160.144.254 #定义网关
exit
set vrouter "untrust-vr"
exit
set vrouter "trust-vr"
exit
ssg5-serial->

就几个打#号的地方配置了一下,就能上网了
我有一本“NetScreen 概念与范例
ScreenOS 参考指南”基本的命令都有,要的话M我好了,因为里面有网址,所以放不到wendang.baidu.com上

热心网友 时间:2022-06-23 05:56

最方便的是方式是通过web管理。SSG5的默认IP是192.168.1.1 用户名与密码是netscreen
声明声明:本网页内容为用户发布,旨在传播知识,不代表本网认同其观点,若有侵权等问题请及时与本网联系,我们将在第一时间删除处理。E-MAIL:11247931@qq.com
如何分别真金和仿金首饰 怎样区分真金和仿金首饰呢 小学生新年晚会主持人的串词!!(不要太多)急 大大后天就需要了!!!_百度... 周年晚会策划公司 奥格瑞玛传送门大厅在哪 奥格瑞玛传送门大厅怎么走 锻炼颈椎的几个动作 水多久能结冰 冰能在多长时间内形成 请问水低于0度会结冰吗? 如何防止脱发严重 嘴唇上有黑印用蜜蜡和棉线去除了胡须 防火墙做路由,GE1/0/X怎么设置dns win8系统下载谷歌浏览器显示找不到服务器dns地址,设置中高级那个选项 h3c F100c 防火墙配置内网连接 跪求好看的bl小说和漫画,游戏,图片等~~~~~~~~~~~~邮箱:licijiaobaby@163.com h3c防火墙做了映射,但是还是不能访问 10.10.1.52 1521这个端口额,求高手 因为我喜欢画漫画,但是经验不足想和大家一起讨论、交流一下经验 喜欢画漫画的请务必加入漫研社! 拳皇漫画里椎拳崇和谁交过手,结果如何? 网卡Flow control怎么设置网速快 有哪位朋友是漫画爱好者?交个朋友~~~ 如何开启juniper防火墙debug H3C F100-C防火墙配置后,客户机访问数据库很慢! 周星驰的电影? 求一部 动漫的名字 在搜索输入“san jiao mu ma”汉语拼音图片第二张图片动漫的名字 H3C F100防火墙上网问题 漫画《汗皂交香》,有什么值得看的亮点? 我有防火墙+路由+交换机,怎样设置网络(配置成功给100分) 为什么日本的动漫受到世界的称赞? 开罗游戏的《开心漫画道场》,创作时,知识点多少能满足交稿需要? 警告FLOW: IP spoofing attack:DROP 动漫 给你一jiao 表示什么意思? 信用卡交易单号查询 西瓜视频没有了小视频怎么办 中信银行信用卡怎么查询网上支付的订单号? 西瓜视频合集后为什么不能再发小视频了? 为什么别人的西瓜视频有视频动态专栏小视频我的没有? 交通银行信用卡 订单号 怎么查 西瓜视频的那些小版块咋没了 我办了一张信用卡怎么查快递单号速查 二姐小庆vlog在西瓜视频怎么没有作品了 信用卡单号怎么查 西瓜视频里的小视频搞掉了怎么补上去? 中信信用卡怎么查询网上支付的订单号? 民生银行信用卡怎么查询单号 有订单号怎么查信用卡还款记录 信用卡邮寄没有单号怎么查询 浦发信用卡邮寄单号怎么查 帮妈妈擦桌子作文七十字 帮妈妈擦桌子的感悟 家庭劳动 擦桌子50字的作文 帮妈妈扫地擦桌子作文三百个字