防火墙安全策略作业
配ip
创建子接口
编写规则
web界面
命令行界面
1
、地址
创建地址集
[FW]ip address-set BG
创建地址内容
[FW-object-address-set-BG]address 192.168.1.0 mask 25
2
、时间段
创建时间段名称
[FW]time-range working-time
[FW-time-range-working-time]period-range 08:00:00 to 18:00:00 working-day
3
、创建安全策略
进入安全策略配置视图
[FW]security-policy
[FW-policy-security]rule name policy_1
描述信息
[FW-policy-security-rule-policy_1]description BG_to_OA
[FW-policy-security-rule-policy_1]destination-zone dmz
[FW-policy-security-rule-policy_1]source-address address-set BG
[FW-policy-security-rule-policy_1]destination-address address-set "OA Server"
[FW-policy-security-rule-policy_1]time-range working-time
动作
[FW-policy-security-rule-policy_1]action permit