科技行者

行者学院 转型私董会 科技行者专题报道 网红大战科技行者

知识库

知识库 安全导航

至顶网网络频道SmartHammerG503防火墙原理与配置(9)

SmartHammerG503防火墙原理与配置(9)

  • 扫一扫
    分享文章到微信

  • 扫一扫
    关注官方公众号
    至顶头条

这两天与电信联合切接一个网络工程对港湾防火墙多了些了解在这里写出来,希望对想了解港湾防火墙的朋友或许有帮助。

作者:整理自互联网 2007年11月25日

关键字: 华为 华为交换机 华为技术 华为路由器

  • 评论
  • 分享微博
  • 分享邮件

  error srcplace in mips64

  SmartHammer# dir flash0

  14921228 Sep 14 10:22 hsos.img

  32686k bytes total (9926k bytes free)

  SmartHammer# dir disk0:

  124922k bytes total (124922k bytes free)

  SmartHammer#

  SmartHammer# copy tftp://192.168.98.100/hsos.img disk0:(利用tftp将HSOS文件载入CF卡中)

  ...............

  14921228 bytes have received, we will move it to appropriate place!

  It maybe last a few minites,please waiting...

  [OK]

  SmartHammer#

  SmartHammer#

  SmartHammer# dir disk0:(查看一下CF卡中文件的内容和大小)

  14921228 Sep 14 12:26 hsos.img

  124922k bytes total (110350k bytes free)

  SmartHammer#

  SmartHammer#

  SmartHammer#

  SmartHammer# set boot system disk0:hsos.img(设置系统启动时加载的文件,disk0代表从CF卡上加载系统文件)

  SmartHammer# show system boot

  HSOS_IMAGE disk0:hsos.img

  HSOS_CONFIG “nvram”

  HSOS_OPTIONS “noconfig”

  SmartHammer#

  SmartHammer#

  SmartHammer#

  SmartHammer#

  SmartHammer#

  SmartHammer# reboot

  Are you sure to reboot the system? [Y/N](重新启动系统,看到不同的软件版本了吧!)

  System will reboot now!

  SmartHammer#

  BIOS version 1.1 and CPLD version 1.1 for SmartHammer G503

  Build Date: Sat Jul 15 18:51:38 HKT 2006

  Copyright (c) Harbour Networks Limited All rights reserved.

  eth2: Link speed: 1000BaseT FDX

  Loader:elf Filesys:fat Dev:disk0 File:hsos.img Optionsnull)

  Loading......

  Good. Loading finished!

  Closing network.

  Starting program .....

  SiByte BCM1250 B2 (SB1 rev 2)

  Board type: SiByte SmartHammer

  Password: ge0: Link is Down

  ge1: Link is Down

  ge2: Link is Down

  ge2: Link speed: 1000BaseT FDX

  Password:

  Harbour Networks Limited.

  version G503_1.3_0157(由原来的1.3.1_0051变成较老的版本1.3_0157)

  Build 0157 at Mon Nov 22 09:49:21 CST 2004.

  SmartHammer>

  SmartHammer>

  SmartHammer>

  SmartHammer>

  --------------------------------------------------------------------------------

  netstation

  2005-11-17, 01:19

  使CFE在引导系统软件时忽略配置文件。这样就连密码一起清楚了,以缺省配置进入后,用show startup-config再把原来的配置恢复了。

  进入CFE模块,用“ctrl + B” 进CFE模块

  harbour>setenv HSOS_OPTIONS “noconfig” 设置启动时不加载配置

  这样就会以出厂设置进入,然后注意在进入系统后,再把配置改回来,要不你做的配置虽然保存了,但还是不会在你启动时加载,用命令

  SmartHammer# set boot options config

  --------------------------------------------------------------------------------

  netstation

  2005-11-17, 01:25

  SmartHammer1# show runn

  Building configuration...

  Current configuration:

  hostname SmartHammer1

  line tty

  login

  !

  !

  no service password-encryption

  !

  password 8 ca6f986f681

  enable password 8 7dace19bafc8e4168dbeee58a0a6bd

  !

  no ip service inspect

  !

  ip-group eq

  !

  interface lo

  !

  interface ge0

  ip address 218.x.x.x/27

  ip security-level 80

  ip natinternet

  !

  interface ge1

  ip address 192.168.251.254/30

  ip security-level 100

  ip nat ftp

  !

  interface ge2

  !

  ip route 0.0.0.0/0 218.x.x.x

  ip route 192.168.0.0/16 192.168.251.253

  !

  http-filter

  !

  ip inspect max 500000

  ip inspect max 500000 tcp

  ip inspect max 100000 udp

  ip inspect maxincomplete high 20000 tcp

  ip inspect maxincomplete low 10000 tcp

  ip inspect one-minute high 20000 tcp

  ip inspect one-minute low 10000 tcp

  ip inspect max flow 100 src list 10

  !

  access-list 10 permit ip any any

  access-list firewallpermit tcp any any x.x.x.x telnet

  access-list firewall permit icmp any any

  access-list firewall permit tcp any any 192.168.251.254 telnet

  access-list mail permit icmp any any

  access-list mail permit tcp any any any ftp

  access-list mail permit tcp any any any pop3

  access-list mail permit tcp any any any smtp

  !

  ip access-group ge0 ge1 mail

  !

  block bittorrent timeout 65535 hours

  local ip access-group firewall

  !

  ip nat internet source static 192.168.1.3 218.x.x.x

  ip nat internet source list 10 interface

  !

  user admin secret ca6f986f681 admin

  !

  SmartHammer1# 

    • 评论
    • 分享微博
    • 分享邮件
    邮件订阅

    如果您非常迫切的想了解IT领域最新产品与技术信息,那么订阅至顶网技术邮件将是您的最佳途径之一。

    重磅专题
    往期文章
    最新文章