freepeople性欧美熟妇, 色戒完整版无删减158分钟hd, 无码精品国产vα在线观看DVD, 丰满少妇伦精品无码专区在线观看,艾栗栗与纹身男宾馆3p50分钟,国产AV片在线观看,黑人与美女高潮,18岁女RAPPERDISSSUBS,国产手机在机看影片

正文內(nèi)容

juniper_srx防火墻簡(jiǎn)明配置手冊(cè)-文庫(kù)吧資料

2025-06-13 07:23本頁(yè)面
  

【正文】 JSRP是Juniper SRX的私有HA協(xié)議,對(duì)應(yīng)ScreenOS的NSRP雙機(jī)集群協(xié)議,支持A/P和A/A模式,JSRP對(duì)ScreenOS NSRP協(xié)議和JUNOS Cluster集群技術(shù)進(jìn)行了整合集成,熟悉NSRP協(xié)議有助于對(duì)JSRP協(xié)議的理解。自定義服務(wù)如果屬于FTP類應(yīng)用,需要將此自定義服務(wù)(非TCP 21端口)與FTP應(yīng)用進(jìn)行關(guān)聯(lián)。下面是圖中左側(cè)SRX基于路由方式Sitetosite VPN配置:set interfaces st0 unit 0 family inet address set security zones securityzone untrust interfaces set routingoptions static route 定義st0 tunnel接口地址/Zone及通過(guò)VPN通道到對(duì)端網(wǎng)絡(luò)路由set security ike policy ABC mode mainset security ike policy ABC proposalset standardset security ike policy ABC presharedkey asciitext juniper定義IKE Phase1 policy參數(shù),main mode,standard proposal及預(yù)共享密鑰方式set security ike gateway gw1 ikepolicy ABCset security ike gateway gw1 address set security ike gateway gw1 externalinterface ge0/0/定義IKE gaeway參數(shù),預(yù)共享密鑰認(rèn)證,出接口ge0/0/1(位于untrust zone)set security ipsec policy AAA proposalset standardset security ipsec vpn vpn1 bindinterface set security ipsec vpn vpn1 ike gateway gw1set security ipsec vpn vpn1 ike ipsecpolicy AAAset security ipsec vpn vpn1 establishtunnels immediately定義ipsec Phase 2 VPN參數(shù):standard proposal、調(diào)用Phase 1 gw1 ike網(wǎng)關(guān)。SRX中的加密/驗(yàn)證算法在命名上和ScreenOS存在一些區(qū)別,配置過(guò)程中建議選擇ike和ipsec的proposal為 standard模式,standard中包含SRX支持的全部加密/驗(yàn)證算法,只要對(duì)端設(shè)備支持其中任何一種即可。 Pool base Static NATNAT:set security nat static ruleset staticnat from zone untrustset security nat static ruleset staticnat rule rule1 match destinationaddress set security nat static ruleset staticnat rule rule1 then staticnat prefix Policy:set security policies fromzone trust tozone untrust policy 1 match sourceaddress anyset security policies fromzone trust tozone untrust policy 1 match destinationaddress set security policies fromzone trust tozone untrust policy 1 match application anyset security policies fromzone trust tozone untrust policy 1 then permitStatic NAT概念與ScreenOS MIP一致,屬于靜態(tài)雙向一對(duì)一NAT。Policy:set security policies fromzone trust tozone untrust policy 1 match sourceaddress anyset security policies fromzone trust tozone untrust policy 1 match destinationaddress set security policies fromzone trust tozone untrust policy 1 match application anyset security policies fromzone trust tozone untrust policy 1 then permit上述配置定義Policy策略,根據(jù)前面的NAT配置。 Pool base destination NATNAT:set security nat destination pool 111 address set security nat destination ruleset 1 from zone untrustset security nat destination ruleset 1 rule 111 match sourceaddress set security nat destination ruleset 1 rule 111 match destinationaddress set security nat destination ruleset 1 rule 111 then destinationnat pool 111,注意:定義的Dst Pool是內(nèi)網(wǎng)真實(shí)IP地址,而不是映射前的公網(wǎng)地址。配置proxyarp目的是讓返回包能夠送達(dá)SRX,如果Pool與出接口IP不在同一子網(wǎng)。 Pool based Source NAT    NAT:set security nat source pool pool1 address to set security nat source ruleset 1 from zone trustset security nat source ruleset 1 to zone untrustset security nat source ruleset 1 rule rule1 match sourceaddress set security nat source ruleset 1 rule rule1 then sourcenat pool pool1set security nat proxyarp interface ge0/0/2 address to 上述配置表示從trust方向(any)到untrust方向(any)訪問(wèn)時(shí)提供源地址轉(zhuǎn)換,源地址池為pool1( ),同時(shí)ge0/0/2接口為此pool IP提供ARP代理。下面是配置舉例及相關(guān)說(shuō)明: Interface based NATNAT:set security nat source ruleset 1 from zone trustset security nat source ruleset 1 to zone untrustset security nat source ruleset 1 rule rule1 match sourceaddress set security nat source ruleset 1 rule rule1 then sourcenat interface上述配置定義NAT源地址映射規(guī)則,從Trust Zone訪問(wèn)Untrust Zone的所有流量用Untrust Zone接口IP做源地址轉(zhuǎn)換。ScreenOS中基于Untrust zone接口的源地址轉(zhuǎn)換被保留下來(lái),但在SRX中不再是缺省模式(SRX中Trust Zone接口沒(méi)有NAT模式概念),需要手工配置。SRX NAT和Policy執(zhí)行先后順序?yàn)椋耗康牡刂忿D(zhuǎn)換-目的地址路由查找-執(zhí)行策略檢查-源地址轉(zhuǎn)換,結(jié)合這個(gè)執(zhí)行順序,在配置Policy時(shí)需注意:Policy中源地址應(yīng)是轉(zhuǎn)換前的源地址,而目的地址應(yīng)該是轉(zhuǎn)換后的目的地址,換句話說(shuō),Policy中的源和目的地址應(yīng)該是源和目的兩端的真實(shí)IP地址,這一點(diǎn)和Screen
點(diǎn)擊復(fù)制文檔內(nèi)容
物理相關(guān)推薦
文庫(kù)吧 www.dybbs8.com
備案圖鄂ICP備17016276號(hào)-1