欢迎您访问 最编程 本站为您分享编程语言代码,编程技术文章!
您现在的位置是: 首页

剖析USG6000V的初始设置与配置详情

最编程 2024-02-21 11:31:07
...
# 软件版本 !Software Version V500R005C10SPC300 # 设备名 sysname USG6000V1 # l2tp domain suffix-separator @ # ipsec sha2 compatible enable # undo telnet server enable undo telnet ipv6 server enable # clock timezone Beijing add 08:00:00 # update schedule location-sdb weekly Sun 01:15 # firewall defend action discard # banner enable # user-manage web-authentication security port 8887 undo privacy-statement english undo privacy-statement chinese page-setting user-manage security version tlsv1.1 tlsv1.2 password-policy level high user-manage single-sign-on ad user-manage single-sign-on tsm user-manage single-sign-on radius user-manage auto-sync online-user # web-manager security version tlsv1.1 tlsv1.2 web-manager enable web-manager security enable # firewall dataplane to manageplane application-apperceive default-action drop # dns server 1.1.1.1 dns proxy enable # dhcp enable # undo ips log merge enable # decoding uri-cache disable # update schedule ips-sdb daily 00:32 update schedule av-sdb daily 00:32 update schedule sa-sdb daily 00:32 update schedule cnc daily 00:32 update schedule file-reputation daily 00:32 # ip vpn-instance default ipv4-family # time-range worktime period-range 08:00:00 to 18:00:00 working-day # ike proposal default encryption-algorithm aes-256 aes-192 aes-128 dh group14 authentication-algorithm sha2-512 sha2-384 sha2-256 authentication-method pre-share integrity-algorithm hmac-sha2-256 prf hmac-sha2-256 # aaa authentication-scheme default authentication-scheme admin_local authentication-scheme admin_radius_local authentication-scheme admin_hwtacacs_local authentication-scheme admin_ad_local authentication-scheme admin_ldap_local authentication-scheme admin_radius authentication-scheme admin_hwtacacs authentication-scheme admin_ad authorization-scheme default accounting-scheme default domain default service-type internetaccess ssl-vpn l2tp ike internet-access mode password reference user current-domain manager-user audit-admin password cipher @%@%*=9-C5RiG11j,\=LmjI<]-ePfVm0(p_9j)Ob1,4D9zsV-eS]@%@% service-type web terminal level 15 manager-user api-admin password cipher @%@%=~HY8&ibu9;=Oh3FID<W@P7e7jGv:L8MM1/^&9%cT[c)P7h@@%@% level 15 manager-user admin password cipher @%@%#aU38*-Nz=mU46U:0U0->QW%UL-t:R]I\Oi"ul!w''H*QW(>@%@% service-type web terminal level 15 role system-admin role device-admin role device-admin(monitor) role audit-admin bind manager-user audit-admin role audit-admin bind manager-user admin role system-admin # l2tp-group default-lns # interface GigabitEthernet0/0/0 undo shutdown ip binding vpn-instance default ip address 192.168.154.100 255.255.255.0 alias GE0/METH service-manage http permit service-manage https permit service-manage ping permit service-manage ssh permit service-manage snmp permit service-manage telnet permit # interface GigabitEthernet1/0/0 undo shutdown ip address 192.168.1.1 255.255.255.0 # interface GigabitEthernet1/0/1 undo shutdown # interface GigabitEthernet1/0/2 undo shutdown ip address 192.168.100.254 255.255.255.0 dhcp select interface dhcp server ip-range 192.168.100.1 192.168.100.254 dhcp server dns-list 192.168.100.254 # interface GigabitEthernet1/0/3 undo shutdown # interface GigabitEthernet1/0/4 undo shutdown # interface GigabitEthernet1/0/5 undo shutdown # interface GigabitEthernet1/0/6 undo shutdown # interface Virtual-if0 # interface NULL0 # firewall zone local set priority 100 # firewall zone trust set priority 85 add interface GigabitEthernet0/0/0 add interface GigabitEthernet1/0/2 # firewall zone untrust set priority 5 add interface GigabitEthernet1/0/0 # firewall zone dmz set priority 50 # ip route-static 0.0.0.0 0.0.0.0 GigabitEthernet1/0/0 192.168.1.254 # undo ssh server compatible-ssh1x enable ssh authentication-type default password ssh server cipher aes256_ctr aes128_ctr ssh server hmac sha2_256 sha1 ssh client cipher aes256_ctr aes128_ctr ssh client hmac sha2_256 sha1 # firewall detect ftp # user-interface con 0 authentication-mode aaa user-interface vty 0 4 authentication-mode aaa protocol inbound ssh user-interface vty 16 20 # pki realm default # sa # location # multi-linkif mode proportion-of-weight # right-manager server-group # device-classification device-group pc device-group mobile-terminal device-group undefined-group # user-manage server-sync tsm # security-policy # auth-policy # traffic-policy # policy-based-route # nat-policy rule name GuideNat1583154648398 egress-interface GigabitEthernet1/0/0 action source-nat easy-ip # quota-policy # pcp-policy # dns-transparent-policy # rightm-policy # return