少尉
- 注册时间
- 2012-10-12
- 金币
- 196 个
- 威望
- 0 个
- 荣誉
- 0 个
尚未签到
|
大家请先看我防火墙的配置如下,IP 192.168.0.1设置GigabitEthernet0/0 接口,本地电脑IP设置为192.168.0.2,用网线直通或着交叉线 PC---------防火墙,互相ping 不通,刚刚买回来按说明应该就可以WEB访问路由器了,但是不得ping不通,我用控制线进防火漆开机 ctrl+B,按6恢复出厂设置,再重新按下面配置也不得,本人只配过交换机,不懂防火墙需要什么配置才能访问,谢谢了....
" f8 l/ n1 a( E+ ?- ][H3C]display current-configuration , ^* g% \6 A! ~8 H
#
- S* p. s7 B$ J$ {7 P. y version 5.20, Release 3733
5 b& N; \8 i! s X n( ]#
+ ?. |1 Q3 b& Q J8 L% U sysname H3C& z8 f9 C" A: A b. Y1 k @1 K( t
#! g4 q! P r9 r
undo voice vlan mac-address 00e0-bb00-0000& F" c1 k7 v6 m+ w. Y% h8 h
#1 w& m- J" K+ ^: q
domain default enable system
5 M, [9 F0 x' L1 {8 Q# [ V#9 f" O& e) f! g& _9 V7 w
session synchronization enable
8 m# w0 q9 w$ ~#
( c8 s x% l0 j2 N' A+ F password-recovery enable, z5 K$ u7 Y4 R8 O
#
9 I5 D9 ^9 @! yvlan 1+ u/ |3 s- N6 q0 n) c
#
2 ]/ M) J6 y% o, t2 V$ }; y9 Udomain system
, n7 b( U/ K) O8 I* M access-limit disable
+ w% y# k6 Z9 y4 P1 |1 j state active
b& Q# Q8 |) @+ M, I, T idle-cut disable* H4 }% t4 |+ K
self-service-url disable
' x' w$ k4 L" f+ d1 J' R5 Z#5 F; A# [& P. @) S' w
user-group system
+ Q( r$ ~5 c5 h* }' ]: q9 v$ j3 L group-attribute allow-guest0 _ E+ v+ g4 |$ e
#
8 Z' p1 B, i! p: v7 ^. T& alocal-user admin6 {9 ~0 F5 p& L B6 V
password cipher $c$3$vDBhWvCODvo27kc09nrrWgwINWSuzdGx5 G. ?) j3 i- l. ~5 j
authorization-attribute level 3
( z1 {$ k. ]! F) E" } service-type web
& u7 [. [6 N9 f4 p/ e# . }7 C, M' A0 Z5 D) i8 M1 b
interface NULL0 ) |6 f" ?7 K% i7 q
# 6 q2 Y: P+ d) a2 F& p* Q. T
interface GigabitEthernet0/0' n! d( \& m6 u5 e0 U' G) y
port link-mode route& m1 X, x! o; [. G
ip address 192.168.0.1 255.255.255.07 {6 O& t3 J! E( {
# " Z! j5 p" n: k
interface GigabitEthernet0/10 h, \( }# o, R% G0 G! N3 G4 `5 S" z9 b
port link-mode route/ Z1 @* O% W _9 _* ^3 ~- x0 h4 L% h
#
7 R+ ~- X q% D# l6 b s3 einterface GigabitEthernet0/2% r8 J+ H' w. q
port link-mode route
7 r: S& A; _/ H8 s0 I, ~, N9 y# 2 t/ c9 ]* e J; }, _& x
interface GigabitEthernet0/3( q% W [2 Z, J2 J9 V+ _, y/ Q4 b& p- u
port link-mode route) @8 y- Q1 C% W7 ]8 z8 [
#
# W1 G/ ^. D/ {4 a1 Pinterface GigabitEthernet0/41 h; @: o+ J7 @2 p! X1 M
port link-mode route1 b8 t: S' _# R) ?# r2 c) w
# . E+ Y, W* Z2 v- M
interface GigabitEthernet0/5
/ ^ v& n' G" p; ^" A- a port link-mode route" s- l, A4 @9 W1 g3 p: @ \
#
8 `& d+ p4 ]/ L7 I/ Kinterface GigabitEthernet0/6
. c1 h# i9 A) [2 n+ p% c port link-mode route
: j j9 S/ L9 f( f# ' R& w: s! k/ z+ w
interface GigabitEthernet0/7# f: x2 c% D z' }- Y: d; ~5 o. j2 d
port link-mode route
8 N9 X3 ^, Q3 K# p2 g6 Z& x1 c# : n. ]/ N g: K
interface GigabitEthernet0/82 o; Y' G1 q/ \% V$ B' q
port link-mode route: R# k X7 |# M
# ( ]: ]5 U$ Y2 K9 q, M
interface GigabitEthernet0/9
( k8 k7 _. r5 K9 G8 f2 I0 b port link-mode route# c" |& b& a: ?7 R& a) M$ c$ G
# " ^" [6 E+ v! R1 s$ R
interface GigabitEthernet0/10
, b7 ^ x( n7 v port link-mode route
/ C/ \* ]1 r/ C x8 V, W/ Q, x5 M+ n#
# p C* U& H: ~: I3 V8 U2 Ginterface GigabitEthernet0/11
. W" a$ H$ F. C X7 E2 e0 ^ port link-mode route9 P+ `; B" W: r( R' D/ \
#
% L. O0 Q4 A h {vd Root id 1 * \8 ~5 K. x9 {; I6 d$ e
# 0 \/ W9 B8 C1 O' P5 K) L7 {
zone name Management id 0
4 D) ^2 e5 s* V z0 e6 \9 O. H priority 100
/ o+ d) U o8 n import interface GigabitEthernet0/0
/ Q" v. d# y* Q' I* o/ G8 g6 }4 x8 j" X% P import interface GigabitEthernet0/1% O; T4 j0 O) N
zone name Local id 12 ?; J* s# r2 _3 P* Y# z
priority 100 $ A$ [$ p. P& D2 U8 r
zone name Trust id 29 H- N$ \; s0 C e% S9 y
priority 85
" A. U* Y) N D8 m/ zzone name DMZ id 3
. I7 {; ~2 [2 P; y, C2 @4 n priority 50
" y$ x. F" @; z0 bzone name Untrust id 4
}+ w& {3 ]$ Q9 P' O7 t+ A priority 5
; U8 j/ h; N( @6 e+ Aswitchto vd Root
+ K0 G, e' c. @' B- X B0 E) B zone name Management id 0
- [; a% h2 g4 S" L, k6 S ip virtual-reassembly" J5 A, O$ N( H9 G# ?' }# d7 g
zone name Local id 1
( f5 ?0 ^1 C( g ip virtual-reassembly
2 O2 d5 Z( Z5 O3 I% ? zone name Trust id 2( m+ [4 } R& p6 p
ip virtual-reassembly
' J9 G; N7 w9 A6 P* f zone name DMZ id 3/ x0 G3 M6 U% v1 r; F4 J4 e2 M
ip virtual-reassembly
; n: l- P. [2 I, _# F zone name Untrust id 4
6 _) p# \- V f. u0 T5 t ip virtual-reassembly
* I% E! C) Q: O* R; ^, Q1 Z# 5 X6 \1 Q% Z7 _8 D
load xml-configuration
% u, @. J/ L, w2 ?$ g5 X- h/ E# % Q9 E, O* L; k( F3 O
load tr069-configuration! G; V% m* F" ?- S9 O
# : q' h% ?- A) `. K6 n) o
user-interface con 0
/ J# h5 e% l9 I9 g( Kuser-interface vty 0 4, K4 g5 S ]9 `, u. Y( B6 L
7 U# Z: T: N+ X& K- F
PC ping 之后可以用ARP命令看到防火墙的MAC地址,网线肯定没有问题,电脑也没有问题,互相PING不通请人指明,谢谢了...
; ?' D* m' i8 s$ Q9 s4 A9 \
, q1 J3 F" D3 c+ w# ! |0 c) ?5 }( ^* Y- [) ]8 q
|
|