µÚÒ»·¶ÎÄÍø - רҵÎÄÕ·¶ÀýÎĵµ×ÊÁÏ·ÖÏíÆ½Ì¨

ÍøÂ簲ȫ¼¼Êõ¼°Ó¦ÓÃʵѵ±¨¸æ

À´Ô´£ºÓû§·ÖÏí ʱ¼ä£º2025/11/6 20:33:45 ±¾ÎÄÓÉloading ·ÖÏí ÏÂÔØÕâÆªÎĵµÊÖ»ú°æ
˵Ã÷£ºÎÄÕÂÄÚÈݽö¹©Ô¤ÀÀ£¬²¿·ÖÄÚÈÝ¿ÉÄܲ»È«£¬ÐèÒªÍêÕûÎĵµ»òÕßÐèÒª¸´ÖÆÄÚÈÝ£¬ÇëÏÂÔØwordºóʹÓá£ÏÂÔØwordÓÐÎÊÌâÇëÌí¼Ó΢ÐźÅ:xxxxxxx»òQQ£ºxxxxxx ´¦Àí£¨¾¡¿ÉÄܸøÄúÌṩÍêÕûÎĵµ£©£¬¸ÐлÄúµÄÖ§³ÖÓëÁ½⡣

Center(config)#ip dhcp pool vlan40

Center(dhcp-config)# network 172.16.40.0 255.255.255.0 Center(dhcp-config)# default-router 172.16.40.254 Center(dhcp-config)#dns-server 172.16.5.107

Center(config)#ip dhcp pool vlan50

Center(dhcp-config)# network 172.16.50.0 255.255.255.0 Center(dhcp-config)# default-router 172.16.50.254 Center(dhcp-config)# dns-server 172.16.5.107

Center(config)#ip dhcp pool vlan10_management------//vlan10,¹ÜÀíÔ±vlanÓò Center(dhcp-config)# network 172.16.10.0 255.255.255.0 Center(dhcp-config)# default-router 172.16.10.254 Center(dhcp-config)# dns-server 172.16.5.107

°²È«ÅäÖãº

°²È«²ßÂÔ1£º

ACL:£¨inner Router-f0/0 in£©

1.ÄÚÍø¿ÉÒÔ·ÃÎÊDMZÄڵķþÎñÆ÷£¨FTP,WEB,DNS¡£ 2.DMZÇøÓò²»ÄÜÖ÷¶¯·ÃÎÊÄÚÍø¡£

3.ÄÚÍø¿ÉÒÔping·þÎñÆ÷£¬·þÎñÆ÷²»ÄÜpingÄÚÍø¡£

Extended IP access list dmz-intranet

permit tcp 172.16.5.0 0.0.0.255 172.16.0.0 0.0.255.255 established deny tcp 172.16.5.0 0.0.0.255 172.16.0.0 0.0.255.255 deny icmp 172.16.5.0 0.0.0.255 172.16.0.0 0.0.255.255 echo permit ip any any

Inner_Router(config)#ip access-list extended dmz-intranet

Inner_Router(config-ext-nacl)#permit tcp 172.16.5.0 0.0.0.255 172.16.0.0 0.0.255.255 established Inner_Router(config-ext-nacl)#deny tcp 172.16.5.0 0.0.0.255 172.16.0.0 0.0.255.255 Inner_Router(config-ext-nacl)#deny icmp 172.16.5.0 0.0.0.255 172.16.0.0 0.0.255.255 echo Inner_Router(config-ext-nacl)#permit ip any any Ч¹û£º

10

°²È«²ßÂÔ2£º

ACL£ºInternet(ABR)--F0/1 OUT---Internet-dmz 1.ÄÚÍø¿ÉÒÔ·ÃÎÊÍâÍøµÄ·þÎñ--Web. 2.ÍâÍø¿ÉÒÔ·ÃÎÊDMZÇøÓòµÄ·þÎñ¡£ 3.DMZ²»ÄÜ·ÃÎÊÍâÍø

4.ÄÚÍø¿ÉÒÔpingͨÍâÍø£¬ÍâÍø²»ÄÜPingÄÚÍø

Extended IP access list internet

permit tcp 200.1.10.0 0.0.0.255 172.16.0.0 0.0.255.255 established deny tcp 200.1.10.0 0.0.0.255 172.16.0.0 0.0.255.255 deny icmp 200.1.10.0 0.0.0.255 172.16.0.0 0.0.255.255 echo permit ip any any

ip access-list extended Internet-dmz

permit tcp 172.16.0.0 0.0.255.255 any established deny tcp 172.16.0.0 0.0.255.255 any

deny icmp 172.16.0.0 0.0.255.255 any echo-reply permit ip any any

VPN_°²È«½ÓÈëÅäÖãº

¹«Ë¾×¤ÍâÈËÔ±µÄÖ÷»úÖ±½ÓÁ¬Í¨Internet£¬ÕâÖÖÇé¿öϱØÐëÔÚѧУµÄVPN·ÓÉÆ÷ÉϽøÐÐÅäÖ㬿ͻ§»úʹÓÃVPN¿Í»§¶ËÁ¬½Ó

ÔÚ¹«Ë¾VPN·ÓÉÆ÷ÉÏÅäÖÃEasy VPN£¬Easy VPNÊÇCisco¶ÀÓеÄÔ¶³Ì½ÓÈëVPN£¬ÅäÖùý³ÌÈçÏ£º

aaa new-model Æô¶¯AAAÈÏÖ¤

aaa authentication login vpn-a local aaa authorization network vpn-o local

username vpn password 0 vpn ½¨Á¢±¾µØÓû§ÃûÃÜÂë crypto isakmp enable

crypto isakmp policy 10 ½¨Á¢ipsec°²È«²ÎÊýÅäÖà hash md5

authentication pre-share group 2

ip local pool VPN-POOL 172.16.6.1 172.16.6.254 £¨½¨Á¢·ÖÅ䏸VPNÓû§µÄµØÖ·³Ø£© crypto isakmp client configuration group vpngroup £¨easyvpnµÄ×é¼°ÃÜÂëÅäÖÃ,vpngroup

11

Ϊ×éÃû£© key vpn

domain cisco.com pool VPN-POOL

crypto ipsec transform-set hw esp-3des esp-md5-hmac £¨Ipsec½×¶Î2ÅäÖã© crypto dynamic-map d-map 10 £¨¶¯Ì¬¼ÓÃÜͼ£© set transform-set hw

reverse-route £¨·´Ïò·ÓÉ×¢È룩

EasyvpnÓû§µÄÈÏÖ¤ÊÚȨÅäÖãºno ip domain-lookup crypto map hw-map client authentication list vpn-a crypto map hw-map isakmp authorization list vpn-o crypto map hw-map client configuration address respond crypto map hw-map 10 ipsec-isakmp dynamic d-map ×îºóÔÚ¶Ë¿ÚÉϰ󶨣º interface FastEthernet1/0 crypto map hw-map

ÅäÖÃÍê±ÏÖ®ºóÔÚ¹«Ë¾·Ö²¿ÈËÔ±µÄPCÉÏͨ¹ývpn¿Í»§¶Ë£¬×éÃûΪvpngroup£¬keyΪvpn£¬·þÎñÆ÷µØÖ·ÎªHuaWei.com_CenterµÄFa10µØÖ·£¬Óû§ÃûÃÜÂë¾ùΪvpn£¬¼´¿É¿´µ½Á¬½Ó³É¹¦£¬·Öµ½Ò»¸ö172.16.100.1~172.16.100.254µÄµØÖ·£¬Ö®ºó¾Í¿ÉÒÔÕý³£Ó빫˾ÄÚÖ÷»úͨÐÅÁË¡£

µÇ½ºó£º

µ½ÕâÀ¹«Ë¾ÍⲿµÄÈËÔ±ÔÚ·Ö¹«Ë¾¾Í¿ÉÒÔʹÓò¦ºÅVPNµÇ½µ½¹«Ë¾×ܲ¿£¬µÇ½ºó£¬¾Í¿ÉÒÔÍêÈ«ºÍ×ܹ«Ë¾ÄÚ²¿µÄ»úÆ÷ÏíÓй²Í¬µÄ×ÊÔ´ºÍ²ßÂÔ¡£ WEB·þÎñÆ÷£º

ÓòÃûΪ£ºwww.hw.com µØÖ·Îª£º172.16.5.100

12

Îå¡¢GREËíµÀÅäÖÃ

ÍØÆËͼ£º

ʵÑé²½Öè¼°ÒªÇó£º

1¡¢ÅäÖø÷̨·ÓÉÆ÷µÄIPµØÖ·£¬²¢ÇÒʹÓÃPingÃüÁîÈ·Èϸ÷·ÓÉÆ÷µÄÖ±Á¬¿ÚµÄ»¥Í¨¡£ 2¡¢ÔÚR1ºÍR3ÉÏÅäÖþ²Ì¬Â·ÓÉ¡£È·±£InternetÍøÂç¹Ç¸É¿ÉÒÔÏ໥ͨÐÅ¡£

ÔÚR1ÓëR3ÉÏÅäÖþ²Ì¬Ä¬ÈÏ·ÓÉ£¬²»½ö½öÊÇÓÃÓÚÄ£Äâ½ÓÈë·ÓÉÆ÷¡£Í¬Ê±»¹ÎªÁËÈ·±£ÔÚ´´½¨ËíµÀʱ£¬ËíµÀÔ´ÓëËíµÀÄ¿±êµÄIPµØÖ·Ï໥¿É¼û¡£ÒÔ±ãÓÚʵÏÖËíµÀ¡£ 3¡¢È·ÈÏR1Äܹ»PingͨR3·ÓÉÆ÷µÄ¹«Íø½Ó¿ÚIP¡£

4¡¢ÔÚR1»òR3·ÓÉÆ÷ÉÏPing·ÓÉÆ÷R3»òR1µÄ»Ø»·¿Ú¡£ 5¡¢ÔÚR1·ÓÉÆ÷ÉÏÅäÖÃGREËíµÀ¡£ 6¡¢ÔÚR2·ÓÉÆ÷ÉÏÅäÖÃGREËíµÀ¡£ 7¡¢ÔÚR1Éϲ鿴ËíµÀ½Ó¿ÚÐÅÏ¢¡£ 8¡¢²é¿´R1µÄ·ÓÉ±í¡£

9¡¢ÔÚR1ÉÏPING·ÓÉÆ÷R3µÄËíµÀ½Ó¿Ú¡£

10¡¢ÔÚR1ºÍR3·Ö±ðÅäÖÃÄ¿±êΪR1ºÍR3µÄ»Ø»·½Ó¿Ú£¬ÏÂÒ»ÌøÎªËíµÀ½Ó¿ÚµÄ·ÓÉ¡£

Áù¡¢°²È«²âÊÔ

°²È«Êý¾Ý¸ñʽ°üÉè¼ÆÓë·â×°

ICMP±¨ÎÄ£¬È»ºóʹÓõ÷ÖÆÄ£Ê½£¬²é¿´ÆäÔÚÍøÂçÖеķâ×°Çé¿ö¡£

Èçͼ£ºÎÒÃÇÀ´¹Û²ìÏÂÊý¾Ý°üµÄ¸ñʽ:

13

14

ËÑË÷¸ü¶à¹ØÓÚ£º ÍøÂ簲ȫ¼¼Êõ¼°Ó¦ÓÃʵѵ±¨¸æ µÄÎĵµ
ÍøÂ簲ȫ¼¼Êõ¼°Ó¦ÓÃʵѵ±¨¸æ.doc ½«±¾ÎĵÄWordÎĵµÏÂÔØµ½µçÄÔ£¬·½±ã¸´ÖÆ¡¢±à¼­¡¢ÊղغʹòÓ¡
±¾ÎÄÁ´½Ó£ºhttps://www.diyifanwen.net/c58g4i7802n1x2cx44ech_3.html£¨×ªÔØÇë×¢Ã÷ÎÄÕÂÀ´Ô´£©

Ïà¹ØÍÆ¼ö£º

ÈÈÃÅÍÆ¼ö
Copyright © 2012-2023 µÚÒ»·¶ÎÄÍø °æÈ¨ËùÓÐ ÃâÔðÉùÃ÷ | ÁªÏµÎÒÃÇ
ÉùÃ÷ :±¾ÍøÕ¾×ðÖØ²¢±£»¤ÖªÊ¶²úȨ£¬¸ù¾Ý¡¶ÐÅÏ¢ÍøÂç´«²¥È¨±£»¤ÌõÀý¡·£¬Èç¹ûÎÒÃÇ×ªÔØµÄ×÷Æ·ÇÖ·¸ÁËÄúµÄȨÀû,ÇëÔÚÒ»¸öÔÂÄÚ֪ͨÎÒÃÇ£¬ÎÒÃǻἰʱɾ³ý¡£
¿Í·þQQ£ºxxxxxx ÓÊÏ䣺xxxxxx@qq.com
ÓåICP±¸2023013149ºÅ
Top