这是一个配置笔记,所有的公网IP地址以 X.X.X.X 表示
AR28-31配置
<2831dxt>sys
System View: return to User View with Ctrl+Z.
[2831dxt]dis cu
#
sysname 2831dxt
#
cpu-usage cycle 1min
#
nat address-group 1 x.x.x.x x.x.x.x
#
vrrp ping-enable
#
radius scheme system
#
domain system
#
local-user ebinf
password simple xxxxx
service-type telnet
level 3
#
detect-group 10
detect-list 1 ip address x.x.x.x nexthop 10.250.16.5
timer loop 120
timer wait 3
retry 3
#
acl number 2000
rule 0 permit source 192.168.0.0 0.0.0.255
rule 1 permit source 192.168.1.0 0.0.0.255
rule 3 permit source 192.168.3.0 0.0.0.255
rule 4 permit source 192.168.2.225 0
rule 5 permit source 192.168.2.226 0
rule 6 permit source 192.168.2.227 0
rule 7 permit source 192.168.2.228 0
rule 8 permit source 192.168.2.229 0
rule 9 permit source 192.168.2.230 0
rule 10 permit source 192.168.2.231 0
rule 11 permit source 192.168.2.232 0
rule 12 permit source 192.168.2.233 0
rule 13 permit source 192.168.2.234 0
rule 14 permit source 192.168.5.0 0.0.0.255
#
acl number 3000
rule 210 deny ip source 123.125.59.16 0
rule 211 deny ip source 123.125.58.248 0
rule 212 deny ip source 123.125.44.242 0
rule 300 permit ip
#
interface Aux0
async mode flow
#
interface Ethernet0/0
ip address 10.250.16.6 255.255.255.252
firewall packet-filter 3000 inbound
firewall packet-filter 3000 outbound
nat outbound 2000 address-group 1
nat server protocol tcp global x.x.x.x 8080 inside 192.168.3.73 8080
nat server protocol tcp global x.x.x.x 5366 inside 192.168.3.73 5366
#
interface Ethernet0/1
ip address x.x.x.x 255.255.255.224
ip address x.x.x.x 255.255.255.252 sub
ip address 192.168.0.15 255.255.255.0 sub
vrrp vrid 1 virtual-ip 192.168.0.1
vrrp vrid 1 priority 110
vrrp vrid 1 preempt-mode timer delay 5
vrrp vrid 1 timer advertise 5
#
interface NULL0
#
info-center source IP channel 2
info-center source PPP channel 2
info-center loghost 192.168.0.249 facility local5
#
ip route-static 0.0.0.0 0.0.0.0 10.250.16.5 preference 60
ip route-static 0.0.0.0 0.0.0.0 x.x.x.x preference 60
ip route-static 192.168.0.0 255.255.255.0 192.168.0.254 preference 60
ip route-static 192.168.1.0 255.255.255.0 192.168.0.254 preference 60
ip route-static 192.168.2.0 255.255.255.0 192.168.0.254 preference 60
ip route-static 192.168.3.0 255.255.255.0 192.168.0.254 preference 60
#
snmp-agent
snmp-agent local-engineid 000007DB7F000001000055B4
snmp-agent community read sjwx001
snmp-agent sys-info version all
snmp-agent target-host trap address udp-domain 192.168.0.13 params securityname
sjwx001
#
user-interface con 0
user-interface aux 0
user-interface vty 0 4
authentication-mode scheme
#
return