配置接口IP地址,将接口加入安全区域并配置接口访问管理功能允许SNMP协议通过。 # 配置接口GE0/0/1的IP地址。
<sysname> system-view
[sysname] interface GigabitEthernet 0/0/1
[sysname-GigabitEthernet0/0/1] ip address 1.1.1.1 24
[sysname-GigabitEthernet0/0/1] quit
# 配置接口GE0/0/2的IP地址并配置接口访问管理。
[sysname] interface GigabitEthernet 0/0/2
[sysname-GigabitEthernet0/0/2] ip address 10.2.0.1 24
[sysname-GigabitEthernet0/0/2] service-manage snmp permit
[sysname-GigabitEthernet0/0/2] quit
# 配置接口GE0/0/3的IP地址。
[sysname] interface GigabitEthernet 0/0/3
[sysname-GigabitEthernet0/0/3] ip address 10.3.0.1 24
[sysname-GigabitEthernet0/0/3] quit
# 将接口GE0/0/1加入Untrust区域。
[sysname] firewall zone untrust
[sysname-zone-untrust] add interface GigabitEthernet 0/0/1
[sysname-zone-untrust] quit
# 将接口GE0/0/2加入DMZ区域。
[sysname] firewall zone dmz
[sysname-zone-dmz] add interface GigabitEthernet 0/0/2
[sysname-zone-dmz] quit
# 将接口GE0/0/3加入Trust区域。
[sysname] firewall zone trust
[sysname-zone-trust] add interface GigabitEthernet 0/0/3
[sysname-zone-trust] quit
配置安全策略。 # 在Trust和Untrust域间配置安全策略
[sysname-policy-security] rule name trust_untrust_outbound
[sysname-policy-security-trust_untrust_outbound] source-zone trust
[sysname-policy-security-trust_untrust_outbound] destination-zone untrust
[sysname-policy-security-trust_untrust_outbound] source-address 10.3.0.0 mask 255.255.255.0
[sysname-policy-security-trust_untrust_outbound] action permit
[sysname-policy-security-trust_untrust_outbound] quit
配置路由。 # 配置缺省路由到连接Internet的下一跳地址。
[sysname] ip route-static 0.0.0.0 0.0.0.0 1.1.1.2
# 配置黑洞路由,防止产生路由环路。
[sysname] ip route-static 1.1.1.10 32 NULL 0
[sysname] ip route-static 1.1.1.11 32 NULL 0
[sysname] ip route-static 1.1.1.12 32 NULL 0
配置FW的SNMP参数,并配置将FW产生的告警发送到eSight。
[sysname] snmp-agent sys-info version v3
[sysname] snmp-agent mib-view include mib2view iso
[sysname] snmp-agent group v3 v3group privacy
[sysname] snmp-agent usm-user v3 V3user authentication-mode sha
Please configure the authentication password (8-64)
Enter Password:
Confirm Password:
[sysname] snmp-agent usm-user v3 V3user privacy-mode aes128
Please configure the privacy password (8-64)
Enter Password:
Confirm Password:
[sysname] snmp-agent usm-user v3 V3user group v3group
[sysname] snmp-agent group v3 v3group privacy write-view mib2view notify-view mib2view
[sysname] snmp-agent target-host trap address udp-domain 10.2.0.10 params securityname V3user v3 privacy private-netmanager
[sysname] snmp-agent trap enable
Warning: All switches of SNMP trap/notification will be open. Continue? [Y/N]:y