H3C SecPath F100-E-G3 备忘

[H3C]display current-configuration
#
 version 7.1.064, Release 9333P26
#
 sysname H3C
#
 clock timezone Beijing add 08:00:00
 clock protocol ntp context 1
#
context Admin id 1
#
 irf mac-address persistent timer
 irf auto-update enable
 undo irf link-delay
 irf member 1 priority 1
#
 security-zone intra-zone default permit
#
 ip pool l2tp1 192.168.100.2 192.168.100.20
 ip pool l2tp1 gateway 192.168.100.1
#
 dns server 223.5.5.5
#
 password-recovery enable
#
vlan 1
#
object-group ip address ▒▒▒▒▒▒
 0 network subnet 10.0.0.0 255.0.0.0
#
object-group service 2222
 0 service tcp destination eq 2222
#
object-group service SSH▒˿▒
 0 service tcp destination eq 22
#
interface Virtual-Template1
 ppp authentication-mode chap domain system
 remote address pool l2tp1
 ip address 192.168.100.1 255.255.255.0
#
interface NULL0
#
interface GigabitEthernet1/0/0
 port link-mode route
 ip address 192.168.0.1 255.255.255.0
#
interface GigabitEthernet1/0/1
 port link-mode route
 ip address 112.28.8.131 255.255.255.0
 nat outbound 3000
 ipsec apply policy a
#
interface GigabitEthernet1/0/2
 port link-mode route
 ip address 10.0.0.1 255.255.255.240
#
interface GigabitEthernet1/0/3
 port link-mode route
#
interface GigabitEthernet1/0/4
 port link-mode route
#
interface GigabitEthernet1/0/5
 port link-mode route
#
interface GigabitEthernet1/0/6
 port link-mode route
#
interface GigabitEthernet1/0/7
 port link-mode route
#
interface GigabitEthernet1/0/8
 port link-mode route
#
interface GigabitEthernet1/0/9
 port link-mode route
#
interface GigabitEthernet1/0/10
 port link-mode route
#
interface GigabitEthernet1/0/11
 port link-mode route
#
interface GigabitEthernet1/0/12
 port link-mode route
#
interface GigabitEthernet1/0/13
 port link-mode route
#
interface GigabitEthernet1/0/14
 port link-mode route
#
interface GigabitEthernet1/0/15
 port link-mode route
#
interface GigabitEthernet1/0/16
 port link-mode route
#
interface GigabitEthernet1/0/17
 port link-mode route
#
interface GigabitEthernet1/0/18
 port link-mode route
#
interface GigabitEthernet1/0/19
 port link-mode route
#
interface GigabitEthernet1/0/20
 port link-mode route
#
interface GigabitEthernet1/0/21
 port link-mode route
#
interface GigabitEthernet1/0/22
 port link-mode route
#
interface GigabitEthernet1/0/23
 port link-mode route
#
security-zone name Local
#
security-zone name Trust
#
security-zone name DMZ
 import interface GigabitEthernet1/0/2
#
security-zone name Untrust
 import interface GigabitEthernet1/0/1
 import interface Virtual-Template1
#
security-zone name Management
 import interface GigabitEthernet1/0/0
#
 scheduler logfile size 16
#
line class aux
 user-role network-operator
#
line class console
 authentication-mode scheme
 user-role network-admin
#
line class usb
 user-role network-operator
#
line class vty
 user-role network-operator
#
line aux 0
 user-role network-admin
#
line con 0
 user-role network-admin
#
line vty 0 63
 authentication-mode scheme
 user-role network-admin
#
 ip route-static 0.0.0.0 0 GigabitEthernet1/0/1 112.28.8.1 description ▒▒▒▒ȱʡ·▒▒
 ip route-static 10.0.0.0 8 GigabitEthernet1/0/2 10.0.0.2 description ▒▒㽻▒▒▒ͷ▒▒▒▒▒▒
 ip route-static 192.168.10.0 24 GigabitEthernet1/0/2 10.0.0.2 description ▒▒▒▒▒▒MGMT
 ip route-static 192.168.128.0 24 GigabitEthernet1/0/2 10.0.0.2 description ▒洢▒▒▒▒▒▒MGMT
#
 ssh server enable
#
 ntp-service enable
 ntp-service source GigabitEthernet1/0/1
#
acl advanced 3000
 rule 0 deny udp destination-port eq 1701
 rule 5 permit ip
#
domain l2tp
 authorization-attribute ip-pool 10.1.1.1
 authentication login local
 authorization login local
 accounting login local
#
domain system
 authentication login local
 authorization login local
 accounting login local
 authentication lan-access local
 authorization lan-access local
 accounting lan-access local
 authentication ppp local
 authentication portal local
 authorization portal local
 accounting portal local
#
 domain default enable system
#
role name level-0
 description Predefined level-0 role
#
role name level-1
 description Predefined level-1 role
#
role name level-2
 description Predefined level-2 role
#
role name level-3
 description Predefined level-3 role
#
role name level-4
 description Predefined level-4 role
#
role name level-5
 description Predefined level-5 role
#
role name level-6
 description Predefined level-6 role
#
role name level-7
 description Predefined level-7 role
#
role name level-8
 description Predefined level-8 role
#
role name level-9
 description Predefined level-9 role
#
role name level-10
 description Predefined level-10 role
#
role name level-11
 description Predefined level-11 role
#
role name level-12
 description Predefined level-12 role
#
role name level-13
 description Predefined level-13 role
#
role name level-14
 description Predefined level-14 role
#
user-group system
 authorization-attribute vlan 1
#
local-user admin class manage
 password hash $h$6$S4MPElIqgJ19n/8E$kTSJFztCS/b+gD5UgoI3sCzEoIJ+1hZC2KnPrd3CtB+dMcftw2GD1Fhkb2J5fTqQXjkqiRlaxj5ww8GEPC/kFQ==
 service-type ssh terminal https
 authorization-attribute user-role level-3
 authorization-attribute user-role network-admin
 authorization-attribute user-role network-operator
#
local-user hs_vpn class network
 password cipher $c$3$wDlnybJhu/XFFoOYpDCnRA6or4CuaAEF5GXA+8A=
 access-limit 10
 service-type ppp
 authorization-attribute user-role network-operator
#
local-user tang class network
 password cipher $c$3$e/eCZepKOU8Y7TMJEENE+m+KMiVyyxk=
 service-type ppp
 authorization-attribute user-role network-operator
#
 session statistics enable
#
 ipsec logging packet enable
 ipsec logging negotiation enable
#
ipsec transform-set 1
 encapsulation-mode transport
 esp encryption-algorithm 3des-cbc
 esp authentication-algorithm md5
#
ipsec transform-set 2
 encapsulation-mode transport
 esp encryption-algorithm aes-cbc-128
 esp authentication-algorithm sha1
#
ipsec transform-set 3
 encapsulation-mode transport
 esp encryption-algorithm aes-cbc-256
 esp authentication-algorithm sha1
#
ipsec transform-set 4
 encapsulation-mode transport
 esp encryption-algorithm des-cbc
 esp authentication-algorithm sha1
#
ipsec transform-set 5
 encapsulation-mode transport
 esp encryption-algorithm 3des-cbc
 esp authentication-algorithm sha1
#
ipsec transform-set 6
 encapsulation-mode transport
 esp encryption-algorithm aes-cbc-192
 esp authentication-algorithm sha1
#
ipsec policy-template z 1
 transform-set 1 2 3 4 5 6
 ike-profile 1
#
ipsec policy a 10 isakmp template z
#
l2tp-group 1 mode lns
 allow l2tp virtual-template 1
 undo tunnel authentication
 tunnel name LNS
#
nat global-policy
 rule name ▒▒▒▒
  source-ip ▒▒▒▒▒▒
  action snat ip-address 112.28.8.131
  counting enable
 rule name APP1_SSH
  service 2222
  destination-ip host 112.28.8.131
  action dnat ip-address 10.10.10.7 local-port 22
#
 l2tp enable
#
 ike logging negotiation enable
#
ike profile 1
 keychain 1
 match remote identity address 0.0.0.0 0.0.0.0
 proposal 1 2 3 4 5 6
#
ike proposal 1
 encryption-algorithm aes-cbc-128
 dh group2
 authentication-algorithm md5
#
ike proposal 2
 encryption-algorithm 3des-cbc
 dh group2
 authentication-algorithm md5
#
ike proposal 3
 encryption-algorithm 3des-cbc
 dh group2
#
ike proposal 4
 encryption-algorithm aes-cbc-256
 dh group2
#
ike proposal 5
 dh group2
#
ike proposal 6
 encryption-algorithm aes-cbc-192
 dh group2
#
ike keychain 1
 pre-shared-key address 0.0.0.0 0.0.0.0 key cipher $c$3$qTVnYZ6BlQm+78JqzGBJ8LRlGla9DwBnQxy4
#
 ip https port 8443
 ip https enable
 webui log enable
#
 loadbalance isp file flash:/lbispinfo_v1.5.tp
#
sslvpn gateway 0
 ip address 0.0.0.0 port 8443
#
security-policy ip
 rule 4 name ▒▒▒▒ָ▒▒▒▒▒▒IP▒▒▒▒SSH
  action pass
  source-zone Untrust
  destination-zone DMZ
  source-ip-host 218.108.6.186
  destination-ip ▒▒▒▒▒▒
  service ssh
 rule 5 name ▒ܾ▒▒▒SSH▒▒▒▒▒▒
  source-zone Untrust
  destination-zone DMZ
  destination-ip ▒▒▒▒▒▒
  service ssh
 rule 2 name any
  action pass
#