{"id":2387,"date":"2023-08-14T19:56:48","date_gmt":"2023-08-14T11:56:48","guid":{"rendered":"http:\/\/xinyixx.com\/?p=2387"},"modified":"2023-08-14T19:57:23","modified_gmt":"2023-08-14T11:57:23","slug":"hcie11","status":"publish","type":"post","link":"https:\/\/www.xinyixx.com\/index.php\/2023\/08\/14\/hcie11\/","title":{"rendered":"HCIE\u5b66\u4e60\u4e4b\u8def11\uff1a\u4e00\u4e2a\u9632\u706b\u5899\u7f51\u7edc\u5b9e\u9a8c"},"content":{"rendered":"<p>\u4eca\u5929\u4ee5\u534e\u4e3aUSG\u7cfb\u5217\u9632\u706b\u5899\u4e3a\u4f8b\uff0c\u5199\u4e00\u4e2a\u5728\u4f01\u4e1a\u51fa\u53e3\u914d\u7f6e\u9632\u706b\u5899\u7684\u7f51\u7edc\u5b9e\u9a8c\u3002<\/p>\n\n\n\n<p>\u9632\u706b\u5899\u4f5c\u4e3aVAS\u8bbe\u5907\uff0c\u5411\u79df\u6237\u63d0\u4f9b\u5b89\u5168\u7b56\u7565\u3001EIP\u3001\u6e90NAT\u3001IPSec\u3001\u5185\u5bb9\u5b89\u5168\u7b49\u589e\u503c\u5b89\u5168\u670d\u52a1\u3002\u4f5c\u4e3a\u6267\u884c\u5668\uff0c\u63a5\u6536\u63a7\u5236\u5668\u4e0b\u53d1\u7684\u9632\u5fa1\u7b56\u7565\uff0c\u53ca\u65f6\u963b\u65ad\u5a01\u80c1\u6d41\u91cf\u3002<\/p>\n\n\n\n<p>\u5e94\u7528\u9886\u57df\u5305\u62ec\uff1a\u6821\u56ed\u51fa\u53e3\u3001\u5e7f\u7535\u7f51\u7edc\u3001\u91d1\u878d\u4e2d\u5fc3\u3001\u4f01\u4e1a\u56ed\u533a\u3001\u4e91\u8ba1\u7b97\u7b49\u3002<\/p>\n\n\n\n<p>\u4ee5\u4f01\u4e1a\u56ed\u533a\u4e3a\u4f8b\uff1a\u9632\u706b\u5899\u90e8\u7f72\u5728\u5927\u4e2d\u578b\u4f01\u4e1a\u51fa\u53e3\u63d0\u4f9bInternet\u63a5\u5165\u3001VPN\u4e92\u8054\u548c\u5b89\u5168\u9632\u62a4\u529f\u80fd\uff0c\u4e3b\u8981\u4f7f\u7528\u53cc\u673a\u70ed\u5907\u3001NAT\u3001ISP\u667a\u80fd\u9009\u8def\u3001VPN\u3001\u653b\u51fb\u9632\u8303\u7b49\u529f\u80fd\u3002<\/p>\n\n\n\n<p>\u4e0b\u9762\u5217\u4e3e2\u4e2a\u5e94\u7528\u573a\u666f\u914d\u7f6e\uff1aCLI\u548cWeb<\/p>\n\n\n\n<p>\u7ba1\u7406\u5458\u767b\u5f55\u8bbe\u5907\u540e\uff0c\u9996\u5148\u8981\u5bf9\u8bbe\u5907\u8fdb\u884c\u7f51\u7edc\u57fa\u7840\u914d\u7f6e\uff0c\u4f7f\u8bbe\u5907\u5feb\u901f\u63a5\u5165\u7f51\u7edc\uff0c\u5982\u4e0b\u56fe\uff0c\u4f01\u4e1a\u8d2d\u4e70\u4e86FW\u4f5c\u4e3a\u4f01\u4e1a\u51fa\u53e3\u7f51\u5173\u3002\u7ba1\u7406\u5458\u5728\u767b\u5f55FW\u540e\uff0c\u9996\u5148\u9700\u8981\u5bf9FW\u8fdb\u884c\u7f51\u7edc\u57fa\u7840\u914d\u7f6e\uff0c\u5305\u62ec\u8bbe\u5907\u540d\u79f0\u3001\u65f6\u949f\u3001\u63a5\u53e3IP\u5730\u5740\u3001\u5b89\u5168\u533a\u57df\u3001\u7f3a\u7701\u8def\u7531\u53ca\u7f3a\u7701\u5305\u8fc7\u6ee4\u7684\u914d\u7f6e\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><noscript><img decoding=\"async\" width=\"484\" height=\"198\" src=\"http:\/\/xinyixx.com\/wp-content\/uploads\/2023\/08\/image-83.png\" alt class=\"wp-image-2391\" srcset=\"https:\/\/www.xinyixx.com\/wp-content\/uploads\/2023\/08\/image-83.png 484w, https:\/\/www.xinyixx.com\/wp-content\/uploads\/2023\/08\/image-83-300x123.png 300w\" sizes=\"(max-width: 484px) 100vw, 484px\"><\/noscript><img decoding=\"async\" width=\"484\" height=\"198\" src=\"data:image\/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%20viewBox%3D%220%200%20484%20198%22%3E%3C%2Fsvg%3E\" alt class=\"wp-image-2391 lazyload\" srcset=\"data:image\/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%20viewBox%3D%220%200%20484%20198%22%3E%3C%2Fsvg%3E 484w\" sizes=\"(max-width: 484px) 100vw, 484px\" data-srcset=\"https:\/\/www.xinyixx.com\/wp-content\/uploads\/2023\/08\/image-83.png 484w, https:\/\/www.xinyixx.com\/wp-content\/uploads\/2023\/08\/image-83-300x123.png 300w\" data-src=\"http:\/\/xinyixx.com\/wp-content\/uploads\/2023\/08\/image-83.png\"><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">CLI\u914d\u7f6e\u601d\u8def<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u914d\u7f6eFW\u7684\u8bbe\u5907\u540d\u79f0\u3002<\/li>\n\n\n\n<li>\u914d\u7f6eFW\u7684\u65f6\u949f\u3002<\/li>\n\n\n\n<li>\u914d\u7f6eFW\u5404\u4e1a\u52a1\u63a5\u53e3\u7684IP\u5730\u5740\u3002IP\u5730\u5740\u9700\u8981\u5728\u914d\u7f6e\u524d\u8fdb\u884c\u7edf\u4e00\u89c4\u5212\u3002<\/li>\n\n\n\n<li>\u5c06\u5404\u4e2a\u4e1a\u52a1\u63a5\u53e3\u52a0\u5165\u5b89\u5168\u533a\u57df\u3002\u4e00\u822c\u60c5\u51b5\u4e0b\uff0c\u8fde\u63a5\u5916\u7f51\u7684\u63a5\u53e3\u52a0\u5165\u5b89\u5168\u7ea7\u522b\u4f4e\u7684\u5b89\u5168\u533a\u57df\uff08\u4f8b\u5982untrust\u533a\u57df\uff09\uff0c\u8fde\u63a5\u5185\u7f51\u7684\u63a5\u53e3\u52a0\u5165\u5b89\u5168\u7ea7\u522b\u9ad8\u7684\u5b89\u5168\u533a\u57df\uff08\u4f8b\u5982trust\u533a\u57df\uff09\uff0c\u670d\u52a1\u5668\u53ef\u4ee5\u52a0\u5165DMZ\u533a\u57df\u3002<\/li>\n\n\n\n<li>\u914d\u7f6e\u7f3a\u7701\u8def\u7531\uff0c\u4e0b\u4e00\u8df3\u4e3aISP\u63d0\u4f9b\u7684\u63a5\u5165\u70b9\u3002<\/li>\n\n\n\n<li>\u6253\u5f00\u7f3a\u7701\u5305\u8fc7\u6ee4\uff0c\u4fdd\u8bc1FW\u80fd\u591f\u63a5\u5165Internet\u3002\u7f3a\u7701\u60c5\u51b5\u4e0b\uff0c\u7f3a\u7701\u5305\u8fc7\u6ee4\u5173\u95ed\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">CIL\u64cd\u4f5c\u6b65\u9aa4<\/h4>\n\n\n\n<p>1.\u914d\u7f6e\u8bbe\u5907\u540d\u79f0<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">&lt;FW&gt; system-view\n[FW] sysname FW_A\n[FW_A] quit<\/pre>\n\n\n\n<p>2.\u914d\u7f6e\u65f6\u949f\uff0c\u5305\u62ec\u5f53\u524d\u65f6\u95f4\u548c\u65f6\u533a\u3002<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">&lt;FW&gt; clock datetime 18:10:45 2023-08-14\n&lt;FW&gt; clock timezone BJ add 08:00:00<\/pre>\n\n\n\n<p>3.\u914d\u7f6e\u63a5\u53e3\u7684IP\u5730\u5740\u3002\u8fde\u63a5\u5916\u7f51\u7684\u63a5\u53e3IP\u5730\u5740\uff08\u672c\u4f8b\u4e3a10.1.1.1\/24\uff09\u9700\u8981\u4ece\u5f53\u5730ISP\u83b7\u53d6\u3002<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">&lt;FW_A&gt; system-view\n[FW_A] interface GigabitEthernet 0\/0\/0\n[FW_A-GigabitEthernet0\/0\/0] ip address 192.168.1.1 24\n[FW_A-GigabitEthernet0\/0\/0] quit\n[FW_A] interface GigabitEthernet 0\/0\/1\n[FW_A-GigabitEthernet0\/0\/1] ip address 10.1.1.1 24\n[FW_A-GigabitEthernet0\/0\/1] quit\n[FW_A] interface GigabitEthernet 0\/0\/2\n[FW_A-GigabitEthernet0\/0\/2] ip address 1.1.1.1 24\n[FW_A-GigabitEthernet0\/0\/2] quit<\/pre>\n\n\n\n<p>4.\u5c06\u5404\u4e2a\u4e1a\u52a1\u63a5\u53e3\u52a0\u5165\u5b89\u5168\u533a\u57df\u3002<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">[FW_A] firewall zone trust\n[FW_A-zone-trust] add interface GigabitEthernet 0\/0\/0\n[FW_A-zone-trust] quit\n[FW_A] firewall zone dmz\n[FW_A-zone-dmz] add interface GigabitEthernet 0\/0\/1\n[FW_A-zone-dmz] quit\n[FW_A] firewall zone untrust\n[FW_A-zone-untrust] add interface GigabitEthernet 0\/0\/2\n[FW_A-zone-untrust] quit<\/pre>\n\n\n\n<p>5.\u914d\u7f6e\u7f3a\u7701\u8def\u7531\u3002<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">[FW_A] ip route-static 0.0.0.0 0.0.0.0 1.1.1.254<\/pre>\n\n\n\n<p>6.\u6253\u5f00\u7f3a\u7701\u5305\u8fc7\u6ee4\uff0c\u4fdd\u8bc1FW\u80fd\u591f\u63a5\u5165Internet\u3002<\/p>\n\n\n\n<p>\u8fd9\u91cc\u540c\u6837\u53ef\u4ee5\u7528\u811a\u672c\u76f4\u63a5\u5bfc\u5165\u7684\u65b9\u5f0f\u5b9e\u73b0\u4e00\u952e\u914d\u7f6e\uff0c\u4ee5\u4e0b\u662f\u5b8c\u6574\u7684\u914d\u7f6e\u811a\u672c\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">#\n sysname FW_A\n#                                                                               \ninterface GigabitEthernet0\/0\/0\n ip address 192.168.1.1 255.255.255.0\n#                                                                               \ninterface GigabitEthernet0\/0\/1\n ip address 10.1.1.1 255.255.255.0\n#\ninterface GigabitEthernet0\/0\/2\n ip address 1.1.1.1 255.255.255.0\n#\nfirewall zone trust\n set priority 85\n add interface GigabitEthernet0\/0\/0\n#\nfirewall zone dmz\n set priority 50\n add interface GigabitEthernet0\/0\/1\n#\nfirewall zone untrust\n set priority 5\n add interface GigabitEthernet0\/0\/2\n#\nip route-static 0.0.0.0 0.0.0.0 1.1.1.254\n#                                                                               \nsecurity-policy                                                                 \n default action permit      \n#\nreturn<\/pre>\n\n\n\n<p><strong>Web\u914d\u7f6e\u601d\u8def<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u914d\u7f6eFW\u7684\u65f6\u949f\u3002<\/li>\n\n\n\n<li>\u914d\u7f6eFW\u5404\u4e1a\u52a1\u63a5\u53e3\u7684IP\u5730\u5740\u3002IP\u5730\u5740\u9700\u8981\u5728\u914d\u7f6e\u524d\u8fdb\u884c\u7edf\u4e00\u89c4\u5212\u3002<\/li>\n\n\n\n<li>\u5c06\u5404\u4e2a\u4e1a\u52a1\u63a5\u53e3\u52a0\u5165\u5b89\u5168\u533a\u57df\u3002\u4e00\u822c\u60c5\u51b5\u4e0b\uff0c\u8fde\u63a5\u5916\u7f51\u7684\u63a5\u53e3\u52a0\u5165\u5b89\u5168\u7ea7\u522b\u4f4e\u7684\u5b89\u5168\u533a\u57df\uff08\u4f8b\u5982untrust\u533a\u57df\uff09\uff0c\u8fde\u63a5\u5185\u7f51\u7684\u63a5\u53e3\u52a0\u5165\u5b89\u5168\u7ea7\u522b\u9ad8\u7684\u5b89\u5168\u533a\u57df\uff08\u4f8b\u5982trust\u533a\u57df\uff09\uff0c\u670d\u52a1\u5668\u53ef\u4ee5\u52a0\u5165DMZ\u533a\u57df\u3002<\/li>\n\n\n\n<li>\u914d\u7f6e\u7f3a\u7701\u8def\u7531\uff0c\u4e0b\u4e00\u8df3\u4e3aISP\u63d0\u4f9b\u7684\u63a5\u5165\u70b9\u3002<\/li>\n\n\n\n<li>\u6253\u5f00\u7f3a\u7701\u5305\u8fc7\u6ee4\uff0c\u4fdd\u8bc1FW\u80fd\u591f\u63a5\u5165Internet\u3002\u7f3a\u7701\u60c5\u51b5\u4e0b\uff0c\u7f3a\u7701\u5305\u8fc7\u6ee4\u5173\u95ed\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">Web\u64cd\u4f5c\u6b65\u9aa4<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u914d\u7f6e\u65f6\u949f\uff0c\u5305\u62ec\u5f53\u524d\u65f6\u95f4\u548c\u65f6\u533a\u3002\n<ol class=\"wp-block-list\" type=\"a\">\n<li>\u9009\u62e9\u201c\u7cfb\u7edf&nbsp;&gt;&nbsp;\u914d\u7f6e&nbsp;&gt;&nbsp;\u65f6\u949f\u914d\u7f6e\u201d\u3002<\/li>\n\n\n\n<li>\u5728\u201c\u914d\u7f6e\u65b9\u5f0f\u201d\u4e2d\u9009\u62e9\u201c\u624b\u52a8\u914d\u7f6e\u65f6\u95f4\u201d\u3002<\/li>\n\n\n\n<li>\u914d\u7f6e\u201c\u65f6\u533a\u201d\u3002<\/li>\n\n\n\n<li>\u914d\u7f6e\u201c\u65e5\u671f\u201d\u3002<\/li>\n\n\n\n<li>\u914d\u7f6e\u201c\u7cfb\u7edf\u65f6\u95f4\u201d\u3002<\/li>\n\n\n\n<li>\u5355\u51fb\u201c\u5e94\u7528\u201d\u3002<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>\u914d\u7f6e\u63a5\u53e30\u7684IP\u5730\u5740\u548c\u5b89\u5168\u533a\u57df\u3002\n<ol class=\"wp-block-list\" type=\"a\">\n<li>\u9009\u62e9\u201c\u7f51\u7edc&nbsp;&gt;&nbsp;\u63a5\u53e3\u201d\u3002<\/li>\n\n\n\n<li>\u5355\u51fbGE0\/0\/0\u3002<\/li>\n\n\n\n<li>\u6309\u5982\u4e0b\u53c2\u6570\u914d\u7f6e\u63a5\u53e3GE0\/0\/0\u3002\u5b89\u5168\u533a\u57dftrust\u7684IP\u5730\u5740192.168.1.1\/24<\/li>\n\n\n\n<li>\u5355\u51fb\u201c\u786e\u5b9a\u201d\u3002<\/li>\n\n\n\n<li>\u91cd\u590d\u4e0a\u8ff0\u6b65\u9aa4\u6309\u5982\u4e0b\u53c2\u6570\u914d\u7f6e\u63a5\u53e3GE0\/0\/1\u3002\u5b89\u5168\u533a\u57dfdmz\u7684IP\u5730\u574010.1.1.1\/24<\/li>\n\n\n\n<li>\u91cd\u590d\u4e0a\u8ff0\u6b65\u9aa4\u6309\u5982\u4e0b\u53c2\u6570\u914d\u7f6e\u63a5\u53e3GE0\/0\/2\u3002\u5b89\u5168\u533a\u57dfuntrust\u7684IP\u5730\u57401.1.1.1\/24<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>\u914d\u7f6e\u7f3a\u7701\u8def\u7531\u3002\n<ol class=\"wp-block-list\" type=\"a\">\n<li>\u9009\u62e9\u201c\u7f51\u7edc&nbsp;&gt;&nbsp;\u8def\u7531&nbsp;&gt;&nbsp;\u9759\u6001\u8def\u7531\u201d\u3002<\/li>\n\n\n\n<li>\u5355\u51fb\u201c\u65b0\u5efa\u201d\u3002<\/li>\n\n\n\n<li>\u6309\u5982\u4e0b\u53c2\u6570\u914d\u7f6e\u7f3a\u7701\u8def\u7531\u3002\u76ee\u7684\u5730\u57400.0.0.0\u63a9\u78010.0.0.0\u4e0b\u4e00\u8df31.1.1.254<\/li>\n\n\n\n<li>\u5355\u51fb\u201c\u786e\u5b9a\u201d\u3002<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>\u6253\u5f00\u7f3a\u7701\u5305\u8fc7\u6ee4\uff0c\u4fdd\u8bc1FW\u80fd\u591f\u63a5\u5165Internet\u3002\u4e00\u822c\u60c5\u51b5\u4e0b\u5efa\u8bae\u4fdd\u6301\u7f3a\u7701\u5305\u8fc7\u6ee4\u5173\u95ed\uff0c\u7136\u540e\u914d\u7f6e\u5177\u4f53\u5141\u8bb8\u54ea\u4e9b\u6570\u636e\u6d41\u901a\u8fc7\u7684\u5b89\u5168\u7b56\u7565\u3002\n<ol class=\"wp-block-list\" type=\"a\">\n<li>\u9009\u62e9\u201c\u7b56\u7565&nbsp;&gt;&nbsp;\u5b89\u5168\u7b56\u7565\u201d\u3002<\/li>\n\n\n\n<li>\u4fee\u6539default\u5b89\u5168\u7b56\u7565\u7684\u52a8\u4f5c\u4e3a\u5141\u8bb8\u3002<\/li>\n\n\n\n<li>\u5355\u51fb\u201c\u786e\u5b9a\u201d\u3002<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n\n\n\n<p>\u4ee5\u4e0a\u5c31\u662f\u4f01\u4e1a\u51fa\u53e3\u9632\u706b\u5899\u5178\u578b\u6848\u4f8b\u7684\u8be6\u7ec6\u914d\u7f6e\uff0c\u611f\u5174\u8da3\u7684\u540c\u5b66\u53ef\u4ee5\u5728ensp\u642d\u5efa\u62d3\u6251\u56fe\u8bd5\u4e00\u4e0b\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4eca\u5929\u4ee5\u534e\u4e3aUSG\u7cfb\u5217\u9632\u706b\u5899\u4e3a\u4f8b\uff0c\u5199\u4e00\u4e2a\u5728\u4f01\u4e1a\u51fa\u53e3\u914d\u7f6e\u9632\u706b\u5899\u7684\u7f51\u7edc\u5b9e\u9a8c\u3002 \u9632\u706b\u5899\u4f5c\u4e3aVAS\u8bbe\u5907\uff0c\u5411\u79df\u6237\u63d0\u4f9b\u5b89\u5168\u7b56 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_import_markdown_pro_load_document_selector":0,"_import_markdown_pro_submit_text_textarea":"","footnotes":""},"categories":[14,100],"tags":[69,95],"class_list":["post-2387","post","type-post","status-publish","format-standard","hentry","category-teacher","category-network","tag-learning","tag-net","entry"],"_links":{"self":[{"href":"https:\/\/www.xinyixx.com\/index.php\/wp-json\/wp\/v2\/posts\/2387","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.xinyixx.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.xinyixx.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.xinyixx.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.xinyixx.com\/index.php\/wp-json\/wp\/v2\/comments?post=2387"}],"version-history":[{"count":0,"href":"https:\/\/www.xinyixx.com\/index.php\/wp-json\/wp\/v2\/posts\/2387\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.xinyixx.com\/index.php\/wp-json\/wp\/v2\/media?parent=2387"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.xinyixx.com\/index.php\/wp-json\/wp\/v2\/categories?post=2387"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.xinyixx.com\/index.php\/wp-json\/wp\/v2\/tags?post=2387"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}