笔记3
【摘要】 trust域[SRG]firewall zone trust[SRG-zone-trust]add interface GigabitEthernet 0/0/1untrust域[SRG]firewall zone untrust[SRG-zone-untrust]add interface GigabitEthernet 0/0/2turst到unturst ,放行地址段[SRG]poli...
trust域
[SRG]firewall zone trust
[SRG-zone-trust]add interface GigabitEthernet 0/0/1
untrust域
[SRG]firewall zone untrust
[SRG-zone-untrust]add interface GigabitEthernet 0/0/2
turst到unturst ,放行地址段
[SRG]policy interzone trust untrust outbound
[SRG-policy-interzone-trust-untrust-outbound]policy 1
[SRG-policy-interzone-trust-untrust-outbound-1]policy source 172.16.105.0 mask 24
[SRG-policy-interzone-trust-untrust-outbound-1]action permit
nat动态地址转换
SRG]nat-policy interzone trust untrust outbound
[SRG-nat-policy-interzone-trust-untrust-outbound]policy 1 策略 名字
[SRG-nat-policy-interzone-trust-untrust-outbound-2]policy source 192.168.10.0 mask 24 配置源IP地址
[SRG-nat-policy-interzone-trust-untrust-outbound-2]action source-nat 配置动作为源IP进行nat
[SRG-nat-policy-interzone-trust-untrust-outbound-2]easy-ip GigabitEthernet 0/0/1 配置要转换的地址为g/0/1
ac+ap
[AC-wlan-view]security-profile name internet 设置安全策略 +名字
[AC-wlan-sec-prof-internet]security wpa-wpa2 psk pass-phrase a1234567 aes 配置安全认证方式,配置密码
[AC-wlan-view]ssid-profile name internet 配置无线ssid+名字
[AC-wlan-ssid-prof-internet]ssid internet
[AC-wlan-view]vap-profile name internet 创建vap模板+名字
[AC-wlan-vap-prof-internet]service-vlan vlan-id 101 绑定业务vlan+名字
[AC-wlan-vap-prof-internet]security-profile internet 绑定安全策略
[AC-wlan-vap-prof-internet]ssid-profile internet 绑定ssid模板
[AC-wlan-view]ap-group name ap-group1 创建ap组,名称为ap-group+组名
[AC-wlan-ap-group-ap-group1]vap-profile internet wlan 1 radio 0 绑定vap模板到射频卡0
[AC-wlan-ap-group-ap-group1]vap-profile internet wlan 1 radio 1 绑定vap模板到射频卡1
【版权声明】本文为华为云社区用户转载文章,如果您发现本社区中有涉嫌抄袭的内容,欢迎发送邮件进行举报,并提供相关证据,一经查实,本社区将立刻删除涉嫌侵权内容,举报邮箱:
cloudbbs@huaweicloud.com
- 点赞
- 收藏
- 关注作者
评论(0)