当前位置:网站首页>华为防火墙-6
华为防火墙-6
2022-08-11 05:33:00 【macob】
防火墙A
interface Tunnel1
ip address 10.1.1.1 255.255.255.0
tunnel-protocol gre
source 1.2.3.4
destination 2.2.2.2
[FW_A] firewall zone dmz
[FW_A-zone-dmz] add interface Tunnel 1
rule name gre
service gre
action permit
#
ip route-static 10.100.0.0 24 Tunnel 1
防火墙B
interface Tunnel1
ip address 10.1.1.2 255.255.255.0
tunnel-protocol gre
source 2.2.2.2
destination 1.2.3.4
[FW_B] firewall zone dmz
[FW_B-zone-dmz] add interface Tunnel 1
rule name gre
service gre
action permit
#
ip route-static 10.10.0.0 24 Tunnel 1
ip route-static 10.20.0.0 24 Tunnel 1
有一点需要注意,使用OSPF动态路由方式时,如果GRE隧道对应的公网接口也使用OSPF发布路由,那我们就需要用一个新的OSPF进程来发布私网网段和Tunnel接口所在网段了,以免私网报文直接通过公网接口转发,而不是通过GRE隧道转
GRE关键字验证
[USG6000V1-Tunnel1]gre key 12345
隧道两端防火墙上设置的关键字必须相同。
GRE校验和验证
[USG6000V1-Tunnel1]gre checksum
GRE保活
[USG6000V1-Tunnel1]keepalive
根据session表细化安全策略
[FW_A] display firewall session table verbose
边栏推荐
- 无胁科技-TVD每日漏洞情报-2022-7-22
- pytorch下tensorboard可视化深坑
- CLUSTER DAY04 (Block Storage Use Cases, Distributed File Systems, Object Storage)
- C语言两百题(0基础持续更新)(1~5)
- Two hundred questions in C language (0 basic continuous update) (1~5)
- FusionCompute8.0.0实验(0)CNA及VRM安装(2280v2)
- 无胁科技-TVD每日漏洞情报-2022-7-31
- VMware workstation 16 安装与配置
- Threatless Technology-TVD Daily Vulnerability Intelligence-2022-8-1
- ETCD集群故障应急恢复-本地数据可用
猜你喜欢
Vulnhub靶机--Chronos
解决8080端口被占用问题
vi display line number in buildroot embedded file system
Basic use of Slurm
buildroot设置dhcp
Solve win10 installed portal v13 / v15 asked repeatedly to restart problem.
AUTOMATION DAY07( Ansible Vault 、 普通用户使用ansible)
内存调试工具Electric Fence
查看可执行文件依赖的库ldd
ETCD cluster fault emergency recovery - local data is available
随机推荐
Record a Makefile just written
记录一个刚写的Makefile
uboot代码解析1:根据目的找主线
Threatless Technology-TVD Daily Vulnerability Intelligence-2022-7-27
MoreFileRename批量文件改名工具
Windos10专业版开启远程桌面协助
C语言两百题(0基础持续更新)(1~5)
vi display line number in buildroot embedded file system
SECURITY DAY03(一键部署zabbix)
查看CPU和其他硬件温度的软件
buildroot setup dhcp
Threatless Technology-TVD Daily Vulnerability Intelligence-2022-7-28
Vulnhub靶机--DC8
TCP 三次握手、四次断开
Django QuerySet.order_by() SQL注入漏洞复现
文本三剑客——grep过滤
Numpy_备注
CLUSTER DAY03 (Ceph overview, the deployment of Ceph CLUSTER, Ceph block storage)
Apache Fink 文件上传漏洞复现及利用
AUTOMATION DAY06( Ansible进阶 、 Ansible Role)