华为防火墙小型企业边界网关配置实例
组网及规划:
华为USG6000作为边界网关实现企业内部网络出口,防火墙实现内部网络NAT功能实现访问Internet功能
实现公司财务部门访问内网服务器。
办公网络不能访问内网服务器,
办公室及财务部均可以访问外网。
外部网络可以通过NatServer实现外部网络通过8080端口访问内网服务器80端口。
网络规划:办公网地址段:192.168.10.0/24 VLAN:10
财务地址段:192.168.20.0/24 VLAN:20
服务器地址段:192.168.200.0/24
运营商固定IP地址:202.1.1.1/24
网络组网见下图:
sysname BanGong
#
vlan batch 10
#
interface Eth-Trunk1
port link-type trunk
port trunk allow-pass vlan 10
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 10
interface GigabitEthernet0/0/23
eth-trunk 1
#
interface GigabitEthernet0/0/24
eth-trunk 1
财务接入交换机配置:
sysname CaiWu
#
vlan batch 20
interface Eth-Trunk1
port link-type trunk
port trunk allow-pass vlan 20
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 20
interface GigabitEthernet0/0/23
eth-trunk 1
#
interface GigabitEthernet0/0/24
eth-trunk 1
#
核心交换机配置:
sysname SW
#
undo info-center enable
#
vlan batch 10 20 100
#
interface Vlanif10
ip address 192.168.10.254 255.255.255.0
#
interface Vlanif20
ip address 192.168.20.254 255.255.255.0
#
interface Vlanif100
ip address 192.168.100.1 255.255.255.0
#
interface Eth-Trunk1
port link-type trunk
port trunk allow-pass vlan 10
#
interface Eth-Trunk2
port link-type trunk
port trunk allow-pass vlan 20
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 100
#
interface GigabitEthernet0/0/21
eth-trunk 2
#
interface GigabitEthernet0/0/22
eth-trunk 2
#
interface GigabitEthernet0/0/23
eth-trunk 1
#
interface GigabitEthernet0/0/24
eth-trunk 1
#
ip route-static 0.0.0.0 0.0.0.0 192.168.100.2
#
防火墙配置:
acl number 2000
rule 5 permit source 192.168.10.0 0.0.0.255
#
interface GigabitEthernet0/0/0
undo shutdown
ip address 202.1.1.1 255.255.255.0
#
interface GigabitEthernet1/0/0
undo shutdown
ip address 192.168.100.2 255.255.255.0
#
interface GigabitEthernet1/0/1
undo shutdown
ip address 192.168.200.254 255.255.255.0
#
firewall zone local
set priority 100
#
firewall zone trust
set priority 85
add interface GigabitEthernet1/0/0
#
firewall zone untrust
set priority 5
add interface GigabitEthernet0/0/0
#
firewall zone dmz
set priority 50
add interface GigabitEthernet1/0/1
#
ip route-static 0.0.0.0 0.0.0.0 GigabitEthernet0/0/0 202.1.1.2
ip route-static 192.168.10.0 255.255.255.0 192.168.100.1
ip route-static 192.168.20.0 255.255.255.0 192.168.100.1
#
nat server 0 protocol tcp global 202.1.1.1 8080 inside 192.168.200.1 www
#
security-policy
rule name policy_ses_1
source-zone trust
destination-zone untrust
source-address 192.168.10.0 mask 255.255.255.0
action permit
rule name policy_ses_2
source-zone trust
destination-zone dmz
source-address 192.168.20.0 mask 255.255.255.0
action permit
rule name policy_ses_3
source-zone trust
destination-zone untrust
source-address 192.168.20.0 mask 255.255.255.0
action permit
rule name Untrust_DMA
source-zone untrust
destination-zone dmz
destination-address 192.168.200.1 mask 255.255.255.255
action permit
#
nat-policy
rule name policy_nat_1
source-zone trust
egress-interface GigabitEthernet0/0/0
source-address 192.168.10.0 mask 255.255.255.0
action source-nat easy-ip
rule name policy_nat_2
source-zone trust
egress-interface GigabitEthernet0/0/0
source-address 192.168.20.0 mask 255.255.255.0
action source-nat easy-ip
验证配置:办公PC可以访问Internet,不能访内网问服务器。
财务PC:可以访问Internet,也可以访问内网服务器。
外网PC可以通过NATSERVER实现访问内网服务器:
【推荐】国内首个AI IDE,深度理解中文开发场景,立即下载体验Trae
【推荐】编程新体验,更懂你的AI,立即体验豆包MarsCode编程助手
【推荐】抖音旗下AI助手豆包,你的智能百科全书,全免费不限次数
【推荐】轻量又高性能的 SSH 工具 IShell:AI 加持,快人一步
· winform 绘制太阳,地球,月球 运作规律
· 超详细:普通电脑也行Windows部署deepseek R1训练数据并当服务器共享给他人
· 上周热点回顾(3.3-3.9)
· TypeScript + Deepseek 打造卜卦网站:技术与玄学的结合
· AI 智能体引爆开源社区「GitHub 热点速览」