Network security firewall experience experiment

Network topology

Experimental operation:
 1. cloud configuration

 2. Firewall configuration

[USG6000V1]int GigabitEthernet 0/0/0
[USG6000V1-GigabitEthernet0/0/0]ip add 192.168.200.100 24

Turn on all services on the firewall

[USG6000V1-GigabitEthernet0/0/0]service-manage all permit

3. Enter the graphical interface configuration

4. Configure interface ip

Configure interface pair

 

Interface bundling

 

 Switch configuration

[Huawei]vlan 100

 [Huawei]interface Eth-Trunk 1

 [Huawei-Eth-Trunk1]trunkport g0/0/1
[Huawei-Eth-Trunk1]trunkport g0/0/2

 [Huawei-Eth-Trunk1]port link-type access

 [Huawei-Eth-Trunk1]port default vlan 100

Check the aggregation port configuration

[Huawei]display eth-trunk 
Eth-Trunk1's state information is:
WorkingMode: NORMAL         Hash arithmetic: According to SIP-XOR-DIP         
Least Active-linknumber: 1  Max Bandwidth-affected-linknumber: 8              
Operate status: up          Number Of Up Port In Trunk: 2                     
--------------------------------------------------------------------------------
PortName                      Status      Weight 
GigabitEthernet0/0/1          Up          1      
GigabitEthernet0/0/2          Up          1    

Configure pc test in dmz zone

 

 

 Switch configuration

[Huawei]interface g0/0/3

 [Huawei-GigabitEthernet0/0/3]port link-type access 

[Huawei-GigabitEthernet0/0/3]port default vlan 100

pc configuration

test

 5. Safe areas and non-safe areas

 

 Configure trust zone interface

 

 Configure untrust zone interface

 

Guess you like

Origin blog.csdn.net/weixin_45875361/article/details/132119937