Îå¡¢É豸ѡÐÍ 1¡¢ ·À»ðǽ
H3C SecPath F100-M-G·À»ðǽ
Êг¡ÁìÏȵĻù´¡°²È«·À»¤
È«ÃæµÄ»ù´¡°²È«·À»¤£ºÌṩ°²È«ÇøÓò»®·Ö¡¢¾²Ì¬/¶¯Ì¬ºÚÃûµ¥¹¦ÄÜ¡¢MACºÍIP°ó¶¨¡¢·ÃÎÊ¿ØÖÆÁÐ±í£¨ACL£©ºÍ¹¥»÷·À·¶µÈ»ù±¾¹¦ÄÜ£¬»¹Ìṩ»ùÓÚ״̬µÄ¼ì²â¹ýÂË¡¢ÐéÄâ·À»ðǽ¡¢VLAN͸´«µÈ¹¦ÄÜ¡£Äܹ»·ÀÓùARPÆÛÆ¡¢TCP±¨Îıê־λ²»ºÏ·¨¡¢Large ICMP±¨ÎÄ¡¢SYN flood¡¢µØÖ·É¨ÃèºÍ¶Ë¿ÚɨÃèµÈ¶àÖÖ¶ñÒâ¹¥»÷
·á¸»µÄVPNÌØÐÔ£ºÖ§³ÖL2TP VPN¡¢GRE VPN¡¢IPSecVPN¼°SSL VPNµÈÔ¶³Ì°²È«½ÓÈ뷽ʽ£¬Í¬Ê±É豸¼¯³ÉÓ²¼þ¼ÓÃÜÒýÇæÊµÏÖ¸ßÐÔÄܵÄVPN´¦Àí
רҵµÄNATÓ¦ÓãºÌṩ¶à¶ÔÒ»¡¢¶à¶Ô¶à¡¢¾²Ì¬Íø¶Î¡¢Ë«Ïòת»» ¡¢Easy IPºÍDNSÓ³ÉäµÈNATÓ¦Ó÷½Ê½£»Ö§³Ö¶àÖÖÓ¦ÓÃÐÒéÕýÈ·´©Ô½NAT£¬ÌṩDNS¡¢¡¢NBTµÈNAT ALG¹¦ÄÜ
Áé»î¿ÉÀ©Õ¹µÄÉî¶È°²È«·À»¤
Óë»ù´¡°²È«·À»¤¸ß¶È¼¯³ÉµÄÒ»Ì廯°²È«ÒµÎñ´¦ÀíÆ½Ì¨
È«ÃæµÄÓ¦ÓòãÁ÷Á¿Ê¶±ðÓë¹ÜÀí£ºÍ¨¹ýH3C³¤ÆÚ»ýÀÛµÄ״̬»ú¼ì²â¡¢Á÷Á¿½»»¥¼ì²â¼¼Êõ£¬Äܾ«È·¼ì²âThunder/Web Thunder£¨Ñ¸À×/WebѸÀ×£©¡¢BitTorrent¡¢eMule£¨µçÂ⣩/eDonkey£¨µç¿£©¡¢QQ¡¢MSN¡¢PPLiveµÈP2P/IM/ÍøÂçÓÎÏ·/³´¹É/ÍøÂçÊÓÆµ/ÍøÂç¶àýÌåµÈÓ¦Óã»Ö§³ÖP2PÁ÷Á¿¿ØÖƹ¦ÄÜ£¬Í¨¹ý¶ÔÁ÷Á¿²ÉÓÃÉî¶È¼ì²âµÄ·½·¨£¬¼´Í¨¹ý½«ÍøÂ籨ÎÄÓëP2PÐÒ鱨ÎÄÌØÕ÷½øÐÐÆ¥Å䣬¿ÉÒÔ¾«È·µÄʶ±ðP2PÁ÷Á¿£¬ÒÔ´ïµ½¶ÔP2PÁ÷Á¿½øÐйÜÀíµÄÄ¿µÄ£¬Í¬Ê±¿ÉÌṩ²»Í¬µÄ¿ØÖƲßÂÔ£¬ÊµÏÖÁé»îµÄP2PÁ÷Á¿¿ØÖÆ
¸ß¾«¶È¡¢¸ßЧÂʵÄÈëÇÖ¼ì²âÒýÇæ¡£²ÉÓÃH3C¹«Ë¾×ÔÖ÷֪ʶ²úȨµÄFIRST£¨Full Inspection with Rigorous State Test£¬»ùÓÚ¾«È·×´Ì¬µÄÈ«Ãæ¼ì²â£©ÒýÇæ¡£FIRSTÒýÇæ¼¯³ÉÁ˶àÏî¼ì²â¼¼Êõ£¬ÊµÏÖÁË»ùÓÚ¾«È·×´Ì¬µÄÈ«Ãæ¼ì²â£¬¾ßÓм«¸ßµÄÈëÇÖ¼ì
²â¾«¶È£»Í¬Ê±£¬FIRSTÒýÇæ²ÉÓÃÁ˲¢Ðмì²â¼¼Êõ£¬Èí¡¢Ó²¼þ¿ÉÁé»îÊÊÅ䣬´ó´óÌá¸ßÁËÈëÇÖ¼ì²âµÄЧÂÊ
ʵʱµÄ²¡¶¾·À»¤£º²ÉÓÃKaspersky¹«Ë¾µÄÁ÷ÒýÇæ²é¶¾¼¼Êõ£¬´Ó¶øÑ¸ËÙ¡¢×¼È·²éÉ±ÍøÂçÁ÷Á¿ÖеIJ¡¶¾µÈ¶ñÒâ´úÂë
È«Ãæ¡¢¼°Ê±µÄ°²È«ÌØÕ÷¿â¡£Í¨¹ý¶àÄê¾ÓªÓë»ýÀÛ£¬H3C¹«Ë¾ÓµÓÐÒµ½ç×ÊÉîµÄ¹¥»÷ÌØÕ÷¿âÍŶӣ¬Í¬Ê±Å䱸ÓÐרҵµÄ¹¥·ÀʵÑéÊÒ£¬½ô¸úÍøÂ簲ȫÁìÓòµÄ×îж¯Ì¬£¬´Ó¶ø±£Ö¤ÌØÕ÷¿âµÄ¼°Ê±×¼È·¸üÐÂ
¼¼ÊõÁìÏȵÄIPv6
¹úÄÚÂÊÏÈÖ§³ÖIPv6״̬·À»ðǽ£¬ÕæÕýÒâÒåÉÏʵÏÖIPv6Ìõ¼þϵķÀ»ðǽ¹¦ÄÜ£¬Âú×ãÆÈÔÚü½ÞµÄIPv6Ó¦ÓÃÐèÇó
Ö§³ÖIPv4/IPv6Ë«ÐÒéÕ»£¬²¢Ö§³ÖIPv6Êý¾Ý±¨ÎÄת·¢¡¢¾²Ì¬Â·ÓÉ¡¢¶¯Ì¬Â·Óɼ°×鲥·Óɵȹ¦ÄÜ
Ö§³ÖIPv6¸÷ÖÖ¹ý¶É¼¼Êõ£¬°üÀ¨NAT-PT¡¢IPv6 Over IPv4 GREËíµÀ¡¢ÊÖ¹¤ËíµÀ¡¢6to4ËíµÀ¡¢IPv4¼æÈÝIPv6×Ô¶¯ËíµÀ¡¢ISATAPËíµÀµÈ Ö§³ÖIPv6 ACL¡¢RadiusµÈ°²È«¼¼Êõ
µçÐż¶É豸µÄ¸ß¿É¿¿ÐÔ
²ÉÓÃH3C¹«Ë¾ÓµÓÐ×ÔÖ÷֪ʶ²úȨµÄÈí¡¢Ó²¼þƽ̨¡£²úÆ·Ó¦ÓôӵçÐÅÔËÓªÉ̵½ÖÐСÆóÒµÓû§£¬¾ÀúÁ˶àÄêµÄÊг¡¿¼Ñé
Ö§³ÖË«»ú״̬Èȱ¸¹¦ÄÜ£¬Ö§³ÖÅäÖÃͬ²½ÓëIPSecVPNµÄ״̬±¸·Ý£¬Ö§³Ö
Active/ActiveºÍActive/PassiveÁ½ÖÖ¹¤×÷ģʽ£¬ÊµÏÖ¸ºÔØ·Öµ£ºÍÒµÎñ±¸·Ý
¼òµ¥Ò×ÓõÄÖÇÄܹÜÀí
¼òµ¥Ò×ÓõÄWeb UI¹ÜÀí ÊʺÏרҵÓû§µÄÈ«ÃüÁîÐйÜÀí Ö§³Ö»ùÓÚSNMPºÍTR-069ÐÒéµÄ¹ÜÀí
ͨ¹ýH3C SecCenter°²È«¹ÜÀíÖÐÐÄʵÏÖͳһ¹ÜÀí
ÖÐСÆóÒµInternet³ö¿Ú°²È«
H3C SecPath F100-M-GÖ§³ÖÍêÕûµÄ»ù´¡°²È«·À»¤ºÍÉî¶È°²È«·ÀÓù¹¦ÄÜ£¬ÎªÆóÒµÌṩרҵµÄ°²È«·À»¤£»F100-M-GÄܹ»Ö§³ÖÍêÕûµÄIPv6״̬·À»ðǽ£¬Âú×ãÂíÉϵ½À´µÄIPv6ʱ´úµÄ°²È«·À»¤ÐèÇó£»Í¬Ê±F100-M-G»¹ÄÚÖÃÁËÁ´Â·¸ºÔؾùºâ¡¢SSL VPNµÈ·á¸»ÌØÐÔ£¬Äܹ»Âú×㵱ǰ»¥ÁªÍø³ö¿Ú¶àISPÁ´Â·ºÍÒÆ¶¯°ì¹«µÄÒµÎñÐèÇó¡£
2¡¢
ÖÐÐÄÊý¾Ý½»»»»ú
H3C S5800PV2-EI ǧÕ×½»»»»ú
ǧÕ×½ÓÈë·½°¸
ÔÚÆóÒµÍøÂç»òÔ°ÇøÍøÂçÖУ¬S5800PV2-EIϵÁзḻÍêÉÆµÄ°²È«ÌØÐÔÄÜ×î´ó³Ì¶ÈµØ½µµÍ·Ç·¨Óû§ºÍ²¡¶¾ÈëÇÖ¶ÔÍøÂ簲ȫ´øÀ´µÄΣº¦£¬Í¬Ê±S5000PV2-EI¶ÔSNMPÍø¹ÜÌØÐÔµÄÖ§³ÖʹÆäÔÚÃæ¶Ô´óÖÐÐÍÍøÂçµÄͳһ¹ÜÀí·½ÃæÒ²ÄÜÓ¦¶ÔÓÎÈÐÓÐÓ࣬¿É¹ã·ºÊ¹ÓÃÔÚÆóÒµ¡¢Ñ§Ð£¡¢¾ÆµêµÈÍøÂç´î½¨¡£
3¡¢
½ÓÈë½»»»»ú
H3C S1600ϵÁа²È«ÖÇÄܽ»»»»ú ²úÆ·ÌØµã
È«ÏßËٵĶþ²ã½»»»£º
S1626£¯S1626-PWR£¯S1650½»»»»úÌṩËùÓж˿ڶþ²ãÏßËÙ½»»»ÄÜÁ¦£¬±£Ö¤ËùÓж˿ÚÎÞ×èÈûµÄ½øÐб¨ÎÄת·¢¡£ ÓÅÒìµÄ°²È«ÐÔÄÜ£º
Ö§³Ö802.1xÈÏÖ¤£¬°²È«×¨ÇøÌṩ¶àÖַḻµÄ°²È«¹¦ÄÜ£¬¿ÉÒÔʵÏÖIP+MAC+¶Ë¿Ú+VLANËÄÔªËØ°ó¶¨£¬²¢¿Éͨ¹ýDHCP-Snooping»òÕßÖÇÄܰó¶¨×Ô¶¯»ñÈ¡°ó¶¨ÁÐ±í£¬ÓÐЧ·ÀÓùARP¹¥»÷¡¢DOS¹¥»÷¼°È䳿¹¥»÷£¬²¢¿ÉÒÔ·½±ãµÄʵÏֽű¾ÅäÖÃÎļþµÄµ¼ÈëºÍµ¼³ö¡£
Ö§³Ö»ùÓÚMACµÄGuest VLAN£¬ÅäºÏ¶¯Ì¬VLANÏ·¢¹¦ÄܿɿØÖƽÓÈëͬһ¶Ë¿ÚµÄ²»Í¬Óû§·ÃÎʲ»Í¬µÄÍøÂç×ÊÔ´£¬ÔöÇ¿ÁËÍøÂçµÄ°²È«ÐÔºÍÒ×ÓÃÐÔ¡£ Ç¿´óµÄÁ´Â·À©Õ¹¼°±¸·ÝÄÜÁ¦£º
ÌṩLACP¡¢STP/RSTP¹¦ÄÜ£¬¿ÉÓÐЧʵÏÖÁ´Â·À©Õ¹¼°±¸·Ý¡£ ¼òµ¥·½±ãµÄ¹ÜÀí·½Ê½£º
¿ÉÒÔͨ¹ýWeb¿ÉÊÓ»¯µÄ½çÃæ£¬¶Ô½»»»»úµÄ¸÷ÖÖ¹¦ÄܽøÐмòµ¥·½±ãµÄ²Ù×÷£¬Í¬Ê±ÌṩConsole¿ÚºÍTelnetµÄÃüÁîÐÐÅäÖᣠ¶àÒµÎñÖ§³ÖÄÜÁ¦
Ö§³ÖPoE£¨Power over Ethernet£©¼¼Êõ£¬Í¨¹ýÒÔÌ«Íø¶ÔËùÁ¬½ÓµÄÉ豸£¨ÈçWireless AP¡¢IP Camera¡¢IP PhoneµÈ£©½øÐÐÔ¶³Ì¹©µç£¬´Ó¶øÊ¹µÃ²»±ØÔÚʹÓÃÏÖ³¡ÎªÉ豸²¿Êðµ¥¶ÀµÄµçԴϵͳ£¬Äܹ»¼«´óµØ¼õÉÙ²¿ÊðÖÕ¶ËÉ豸µÄ²¼Ïߺ͹ÜÀí³É±¾¡£
H3C S1600ϵÁа²È«ÖÇÄܽ»»»»ú¾ßÓзḻµÄ°²È«ÌØÐÔ£¬ÕâʹµÃÔÚÆóÒµÓ¦ÓÃÖпɷ½±ãµÄ×öµ½½ÓÈëÈÏÖ¤ºÍÊÚȨ·ÃÎÊ£¬·á¸»µÄ·À¹¥»÷ÌØÐÔÈÃÆóÒµÄÚ²¿µÄÍøÂç¸ü¼Ó½¡×³¡¢°²È«¡£
Ïà¹ØÍÆ¼ö£º