H3C华三 V7 防火墙开局配置举例

1)配置安全域

#接口加入该安全域中。


[DeviceA] security-zone name Trust
[DeviceA-security-zone- Trust] import interface gigabitethernet 1/0/0 #此处为管理口
[DeviceA-security-zone- Trust] quit

2)配置对象策略及规则

# 放通Trust都Local区域所有地址。


[DeviceA] object-policy ip Trust-Local
[DeviceA-object-policy-ip- Trust-Local] rule pass  
[DeviceA-object-policy-ip- Trust-Local] quit

3)配置安全域间实例并应用对象策略


[DeviceA] zone-pair security sourceTrust destination Local
[DeviceA-zone-pair-security- Trust-Local] object-policy apply ip Trust-Local
[DeviceA-zone-pair-security- Trust-Local] quit
点赞

发表评论

电子邮件地址不会被公开。 必填项已用*标注