D-Link防火墙售后配置资料.ppt_第1页
D-Link防火墙售后配置资料.ppt_第2页
D-Link防火墙售后配置资料.ppt_第3页
D-Link防火墙售后配置资料.ppt_第4页
D-Link防火墙售后配置资料.ppt_第5页
已阅读5页,还剩245页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

DFL-800/1600/2500培训手册,Copyright2005.Allrightsreserved,Copyright2005.ByD-LinkHQTSDJoeLee,产品介绍Concept配置与管理应用示例故障排除,大纲,产品介绍Concept配置与管理应用示例故障处理,大纲,产品介绍防火墙型号,DFL-800,WAN1,WAN2,LAN,DMZ,Console,back,产品介绍防火墙型号,DFL-1600,WAN1,WAN2,LAN1,DMZ,Console,LAN3,LAN2,back,DFL-2500,产品介绍防火墙型号,WAN3,WAN4,Console,LAN3,LAN2,LAN1,DMZ,WAN1,WAN2,back,产品介绍,及forDFL-1600/2500Brandnewuser-friendly,noGUIconfusionissue.Neaterandmoreprofessionallookforfirewallproductline.mechanismwithD-Linkswitchespreventsthreatspreading.高级防火墙属性包含非常方便实施。,DFL-1600,DFL-2500,DFL-800,防火墙特性,透明模式,Zone-Defense,ID,GUI,高端口密度,千兆接口,LED,电源系统状态,Keypad,“Right”,“Left”,“N/A“及“Confirm“按键,系统信息流量监控告警监控配置显示,LCD显示,Auto-SensingCopperPortLAN、WAN及DMZ接口,Ethernet,Console,SerialConsolePortConcealedLook,产品介绍LED面板,SetupMode当防火墙开始通电时,按键盘5秒钟进入setup模式EntertheSetupMode使用Left或Right按键来进行选择1.StartFirewall:开始防火墙系统2.ResetFirewall:把防火墙复位到出厂配置.复位防火墙后,选择startfirewallAfter5seconds,iffirewalldoesntaccessSetupMode.itwillEntertoStatusModeautomatically,产品介绍LED面板,StatusModeModelname:显示设备型号.SystemStatus:显示系统工作状态.CPULoadandConnections:显示CPU利用率及当前会话数TotalBPSandPPS:当前每秒的流量统计DateandTime:显示当前设备的时间Uptime:设备正常运做的时间.Mem:系统内存利用率.IDSSigs:显示IDS特征库信息.WANDMZLAN:显示每个接口的IP地址CoreVersion:显示防火墙的软件版本.,产品介绍LED面板,产品介绍Concept配置与管理应用示例故障处理,大纲,INTERNET,IP:00,WANIP:6,ConceptPacketflow,所有数据进入防火墙,先根据VLAN信息检测(如果使用VLAN时).IDS规则主要过滤经过防火墙的特定数据.接下来检查IP规则和路由规则最后,这些数据需要检查ZoneDefense及TrafficShaping,ConceptPacketflow,进入的数据包,VLANpacket?,De-capsulate,Basicsanitychecks,IncludingverificationofIPheader,检测IDS特征,Drop,Fragment?,Yes,No,Yes,FoundmatchingConnection?,检查TCP/UDP包头信息,Forwardpacket,ApplyRules,Processfragment,Drop,Yes,failed,false,No,true,流量整形,ZD,ZD,OpenConnction,TrafficShaping,RouteIP,SAT_ApplyRulePack,TrafficShaping,DestIP=FW?,Allow/NAT/SAT,FwdFast/SAT,Drop,Drop,Yes,ConceptPacketflow,产品介绍Concept配置与管理应用示例故障处理,大纲,配置与管理默认接口属性配置(DFL-800),可以通过LAN的IP管理设备,能够PING通LAN的IP默认关闭DHCP,配置与管理默认接口属性定义(DFL-1600),LAN1canbemanagedandpingedThefirewalldisableDHCP,配置与管理默认接口属性定义(DFL-2500),LAN1canbemanagedandpingedThefirewalldisableDHCP,配置与管理,在PC上静态配置相应的IP登陆防火墙前,需要进行用户认证默认帐号:admin,Password:admin用户可以看到以下窗口部分;MenuBarTreeViewListMainWindow,back,树型列表,主菜单条,主窗口,配置与管理,System菜单选项,配置与管理,Object菜单选项,配置与管理,Rules菜单选项,配置与管理,Interfaces菜单选项,配置与管理,Routing菜单选项,配置与管理,IDS/IDP菜单选项,配置与管理,UserAuthentication菜单选项,配置与管理,TrafficShaping菜单选项,配置与管理,ZoneDefense菜单选项,配置与管理,配置的3个步骤:1.新建/修改object2.新建规则(IPrule,IDSrule,userauthenticationruleandPipesrule)3.修建/修改路由规则,配置与管理,配置的第一步骤1.新建/修改object防火墙中最重要的就是OBJECT(对象).Objects是防火墙中定义的网络基本元素.Itisalistofsymbolicnamesassociatedwithvarioustypesofaddresses,includingIPaddressesofhostandnetworkObjectitemsareheavilyusedthroughafirewallconfiguration;inroutingtables,rule-set,interfacedefinitions,VPNTunnelsamongothers,配置与管理,Hosts&NetworksconfigurationitemsaresymbolicnamesforIPnetworks,配置与管理ObjectsAddressBook,ALGsaredesignedtomanagespecificprotocolsExaminethepayloaddataandcarryoutappropriateactionsbasedondefinedrulesAppropriateApplicationLayerGatewaydefinitionisselectedinaServiceconfigurationitem.NetworktrafficthatmatchestheservicedefinitionwillthusbemanagedbytheselectedApplicationLayerGateway.,配置与管理ObjectsALG,AdefinitionofaspecificIPprotocolwithcorrespondingparameters.例如http服务,被定义为TCP协议,目标端口80.,配置与管理ObjectsServices,TheSchedule允许防火墙规则只在特定的时间内生效.Anyactivitiesoutsideofthescheduledtimeslotwillnotfollowtherulesandwillthereforelikelynotbepermittedtopassthroughthefirewall,配置与管理ObjectsSchedules,Acertificateisadigitalproofofidentity.Itlinksanidentitytoapublickeyinatrustworthymanner.Certificatescanbeusedtoauthenticateindividualusersorotherentities.Thesetypesofcertificatesarecommonlycalledend-entitycertificates.,配置与管理ObjectsCertificate,配置的第二步骤:2.新建规则TheRulesconfigurationsectionrepresentstheruleset,theheartofthefirewall.Therulesetistheprimaryfilterwhichisconfiguredtoallowordisallowcertaintypesofnetworktrafficthroughthefirewall.Therulesetalsoregulateshowaddresstranslationandbandwidthmanagement,trafficshaping,isappliedtotrafficflowingthroughthefirewall.,配置与管理,PacketsmatchingDropruleswillimmediatelybedropped.SuchpacketswillbeloggediflogginghasbeenenabledintheLogSettingspage,配置与管理IPRulesDrop,配置与管理IPRulesDrop,DROP规则,DROPPINGLOG,RejectworksinbasicallythesamewayasDrop.Inadditiontothis,thefirewallsendsanICMPUNREACHABLEmessagebacktothesenderor,iftherejectedpacketwasaTCPpacket,aTCPRSTmessage.,配置与管理IPRulesReject,配置与管理IPRulesReject,REJECTINGLOG,ICMPUnreachableTCPRST,REJECT规则,配置与管理IPRulesFwdFast,PacketsmatchingFwdFastrulesareallowedthroughimmediately.Firewalldoesnotrememberopenconnectionsanddoesnotstatefullyinspecttrafficpassedthroughit.Foronesinglepacket,itisindeedfasterthanfirsthavingtoopenastate-trackedconnectionandthenpassingthepackettoit.Butwhenseveralpacketspassoverthesameconnection,statetracking(Allow)isfaster,配置与管理IPRulesFwdFast,NoStatefullytrafficInspection(不记录打开的会话),如果数据是从不同源地址发出,FwdFast比Allow更快,INTERNET,如果数据是从同一源地址发出,Allow比FwdFast转发得更快,配置与管理IPRulesAllow,PacketsmatchingAllowrulesarepassedtothestatefulinspectionengine,whichwillrememberthataconnectionhasbeenopenedRulesforreturntrafficwillnotberequiredastrafficbelongingtoopenconnectionsisautomaticallydealtwithbeforeitreachestheruleset,配置与管理IPRulesAllow,Logging&StatefulInspection,INTERNET,配置与管理IPRulesSAT,NothinghappenswhenapacketmatchesaSATruleatthebeginningThefirewallwontrememberthatastaticaddresstranslationwillbeperformedatalaterstageandcontinuetolookforamatchingrulethatwillallowthepackettopass,配置与管理IPRulesSAT,FTPSERVER,23,00,WANIP:00,Thepublic_ipshouldbebindtotheWANoffirewallfirstredirect_addressisusedtoredirectincomingconnectionfrompublic_iptoprivate_ip,IwanttoFTPmyStarWarsEpisodeIIImovie,配置与管理IPRulesNAT,Therulesthatperformdynamicaddresstranslation,NAThidethesenderaddress.MostlyhidingallmachinesonaprotectednetworktoappeartotheoutsideworldasiftheyuseasingleIPaddress,配置与管理IPRulesNAT,INTERNET,IP:00,WANIP:6,配置第3步骤:3.新建/修改路由规则MainRoute:TheRoutesconfigurationsectiondescribesthefirewallsroutingtable.Firewallusesaslightlydifferentwayofdescribingroutescomparedtomostothersystems.Policy-BaseRoute:TherulesinthePBRrulesetcanspecifywhichroutingtabletouseintheforwardaswellasreturndirection(Selectroutingpriority),配置与管理,配置与管理MainRoutingTable,RoutingtellsthefirewallinwhichdirectionitshouldsendpacketsdestinedforagivenIPaddress,配置与管理PolicyBasedRouting,ConnecttotwoormoreISPs,andacceptinginboundconnectionsfromallofthem.ReturntrafficisroutedbackoutthroughtheISPthatdeliveredtheincomingrequest.Routecertainprotocolsthroughtransparentproxiessuchaswebcachesandanti-virusscanners,withoutaddinganotherpointoffailureforthenetworkasawhole.Createprovider-independentmetropolitanareanetworks,i.e.onewhereallusersshareacommonactivebackbone,butcanusedifferentISPs,subscribetodifferentstreamingmediaproviders,etc.,配置与管理PolicyBasedRouting,Intranet/24,Extranet/24,Internet,WAN1,WAN2,DMZ,产品介绍Concept配置与管理应用示例故障处理,大纲,Internet,G1,G6,G4,G5,G2,G7,G8,G3,G9,G10,应用示例Networktopologyforhands-on,AllWAN1portconnecttoswitch,back,mainswitch,应用示例Networktopologyforeverygroup,主交换机,groupswitch,ThethreepersonsinonegroupTheLAN1portconnectstogroupswitch,基本配置(WAN/LAN/DMZTransparentmode)配置负载均衡及路由冗余(use2WANs)配置ZonedefendPortmappingforserver(SATandserverloadbalance)用户认证配置流量整形配置VPN通道(PPTPL2TPandIPsec),应用示例,InternalLAN1IP:/24,InternalLAN2IP:/24,InternalLAN3IP:/24,WAN2(StaticIP),DMZ,DFL-1600,FTPServer,DFL-800,RemoteLANInternalLANIP:/24,WAN1IP:1/24,IPSecVPNTunnel,Handson:BasicConfigurationLoadSharingandRouteFailoverZonedefendPortmappingforserverUserAuthenticationTrafficshapingVPNtunnel,应用示例Accomplishedallscenariostopology,WAN1(DHCP),应用示例1BasicConfiguration,InternalLAN1IP:/24,InternalLAN2IP:/24,InternalLAN3IP:/24,WAN1PPPoEandDHCPStaticIP:0/24,InternalDMZIP:/24,Suggestion:ChangeIPaddressforLANandDMZinObjectConfiguretheruleVerifyroutingrule,InternalLAN1IP:/24,InternalLAN2IP:/24,InternalLAN3IP:/24,InternalDMZIP:/24,Suggestion:DFL-800onlyhasLANandDMZDFL-1600/2500hasLAN1,LAN2,LAN3,andDMZPayattentiontodefaultmanageablestatusConfirmconnectingportDFL-800DFL-1600DFL-2500BindasecondaryIPaddresstomatchthenewnetworkIPsegment.Afterconfiguration,usenewLANIPaddressfordefaultgatewayonNIC,应用示例1-1BasicConfiguration-VerifyIPaddressforLANandDMZNetworktopology,ObjectivesAccesstoLAN1IPaddresssuccessfully(Ping)ConfigurationoflogicBindasecondaryIPaddresstomatchthenewnetworkIPsegment.Afterconfiguration,usenewLANIPaddressfordefaultgatewayonNICVerifyobjectsofIPaddressandnetworkinaddressbookofObject,应用示例1-1BasicConfiguration-VerifyIPaddressforLANandDMZ,应用示例在PC网卡上绑定2个IP地址,1,2,3,应用示例在PC网卡上绑定2个IP地址,4,5,6,应用示例1-1BasicConfiguration-VerifyIPaddressforLANandDMZ,UsewebbrowsersuchasInternetExplorer6orFirefox1.0toconnecttoWebUI,ChangetheIPaddressinaddressbookofObjectClick“InterfaceAddresses”inObjectKeyinthecorrectIPaddressandnetwork,1,2,3,应用示例1-1BasicConfiguration-VerifyIPaddressforLANandDMZ,ChangetheIPaddressinaddressbookofObjectorEthernetofInterfaceKeyincorrectIPaddressandnetwork,1,2,3,应用示例1-1BasicConfiguration-VerifyIPaddressforLANandDMZ,Afterallconfiguration,Click“configuration”inmainbarClick“SaveandActive”,1,2,3,应用示例1-1BasicConfiguration-VerifyIPaddressforLANandDMZ,TestingResult,应用示例1-1BasicConfiguration-VerifyIPaddressforLANandDMZPingLANIPaddress,应用示例1-1BasicConfiguration-VerifyIPaddressforLANandDMZUsenewLANIPaddressfordefaultgatewayonNIC,1,2,3,应用示例1-1BasicConfiguration-VerifyIPaddressforLANandDMZUsenewLANIPaddressfordefaultgatewayonNIC,4,5,6,应用示例1-1BasicConfiguration-VerifyIPaddressforLANandDMZUsenewLANIPaddressfordefaultgatewayonNIC,7,8,应用示例1-1Exercise1-1-VerifyIPaddressforLANandDMZ,InternalLAN1,Goal:ChangeIPaddressforLANandDMZPingtheIPaddressofLAN1successfully,InternalLAN2,InternalLAN3,InternalDMZ,LAN1IP:Group1:/24Group2:/24.Group9:/24Group10:/24,InternalLAN1IP:0/24,WAN1IP:0/24,2/24,1/24,应用示例1-2BasicConfiguration-TransparentNetworktopology,ObjectivesTwocomputerspingtoeachothersuccessfullyConfigurationoflogicEnabletransparentmodeConfigureIPRulesandobjectsonfirewallBindasecondaryIPaddresstomatchthenewnetworkIPsegment.Afterconfiguration,usenewLANIPaddressfordefaultgatewayonNIC,应用示例1-2BasicConfiguration-Transparent,应用示例1-2BasicConfiguration-Transparent,CreatethecorrectgatewayobjectinaddressbookofObjectClick“addressbook”inObjectAddtheobjectforIP4Host/Network,1,2,3,4,5,6,7,ConfiguretheIPobjectinaddressbookofObjecttosameClick“addressbook”inObjectConfigureIPaddressofWAN1andLAN1,1,2,3,4,5,6,应用示例1-2BasicConfiguration-Transparent,7,EnabletransparentmodeforWAN1andLAN1Click“Ethernet”inInterfaceEnabletransparentinWAN1interfaceandaddtheobjectofgatewaytodefaultgateway,1,2,3,4,5,6,应用示例1-2BasicConfiguration-Transparent,7,EnabletransparentmodeforWAN1andLAN1Click“Ethernet”inInterfaceEnabletransparentinLAN1interface,1,2,3,4,5,6,应用示例1-2BasicConfiguration-Transparent,7,AddtheserviceruleinIPrules(WAN1toLAN1andLAN1toWAN1)Click“IPrules”inRulesChoosecorrectAction,Service,InterfaceandNetworkintherule,1,2,3,4,5,6,应用示例1-2BasicConfiguration-Transparent,7,CreatetheDHCPrelayforLAN1toWAN1Click“DHCPrelays”inDHCPsettingChoosecorrectAction,Service,InterfaceandNetworkintherule,1,2,3,4,5,6,应用示例1-2BasicConfiguration-Transparent,7,应用示例1-2BasicConfiguration-Transparent,Afterallconfiguration,Click“configuration”inmainbarClick“SaveandActive”,1,2,3,4,5,7,6,应用示例1-2BasicConfiguration-TransparentGetIPaddressfromDHCPserverandpingtogateway,TestingResult,应用示例1-2Exercise1-2-Transparent,InternalLAN1,WAN1,Goal:Thetwoworkstationscouldpingeachothersuccessfully,WAN1IPLAN1IPGroup1:/24/24Group2:/24/24.Group9:/24/24Group10:0/240/24WAN1-gateway:54,InternalLAN1IP:/24,WAN1(Static)IP:0/24WAN1-gatwayIP:54/24,应用示例1-3BasicConfiguration-WAN1-StaticIPNetworktopology,ObjectivesAccesstoInternetsuccessfully(Ping)ConfigurationoflogicBeforeconfigureWAN-staticIP,pleaseresettodefaultCreateanobjectforWAN1gatewaytoapplytotheinterfaceofWAN1ChoosecorrectAction,Service,InterfaceandNetworkintherule,应用示例1-3BasicConfiguration-WAN1-StaticIP,CreatethecorrectgatewayobjectinaddressbookofObjectClick“addressbook”inObjectAddtheobjectforIP4Host/NetworkVerifyIPaddressofwan1_ipandwan1net,应用示例1-3BasicConfiguration-WAN1-StaticIP,1,2,3,4,ApplythegatewayobjecttoWANInterfaceClick“Ethernet”inInterfaceAddthegatewayobjecttodefaultgateway,应用示例1-3BasicConfiguration-WAN1-StaticIP,1,2,3,4,CreatetheserviceruleinIPrulesClick“IPrules”inRulesChoosecorrectAction,Service,InterfaceandNetworkintherule,应用示例1-3BasicConfiguration-WAN1-StaticIP,1,2,3,4,应用示例1-3BasicConfiguration-WAN1-StaticIP,Afterallconfiguration,Click“configuration”inmainbarClick“SaveandActive”,1,2,3,4,TestingResult,应用示例1-3BasicConfiguration-WAN1-StaticIP,InternalLAN1GroupprivateIP,WAN1:GroupIP,Goal:AccesstoInternetsuccessfully(Ping),应用示例1-3Exercise1-3-WAN1-StaticIP,LAN1Group1:/24Group2:/24.Group9:/24Group10:/24,WAN1Group1:/24Group2:/24.Group9:/24Group10:0/24WAN1-Gateway:54,应用示例1-4BasicConfiguration-WAN1-PPPoENetworktopology,InternalLAN1IP:/24,WAN1PPPoE,ObjectivesAccesstoInternetsuccessfully(Ping)ConfigurationoflogicBeforeconfigurePPPoE,pleaseresettodefaultCreateaPPPoEtunneltoapplytotheIPruleChoosecorrectAction,Service,InterfaceandNetworkintherule,应用示例1-4BasicConfiguration-WAN1-PPPoE,CreatetheobjectofPPPoEruleinPPPoETunnelsofInterfaceClick“PPPoETunnels”inInterfaceApplycorrectPhysicalInterface,RemoteNetwork,UsernameandPasswordintheobject,应用示例1-4BasicConfiguration-WAN1-PPPoE,1,2,3,CreatetheIPruleClick“IPrules”inRulesChoosecorrectAction,Service,InterfaceandNetworkintherule,应用示例1-4BasicConfiguration-WAN1-PPPoE,1,2,3,应用示例1-4BasicConfiguration-WAN1-PPPoE,Afterallconfiguration,Click“configuration”inmainbarClick“SaveandActive”,1,2,3,TestingResult,应用示例1-4BasicConfiguration-WAN1-PPPoE,应用示例1-4Exercise1-4-WAN1-PPPoE,InternalLAN1IP:/24,WAN1PPPoE,Goal:AccesstoInternetsuccessfully(Ping),应用示例1-5BasicConfiguration-WAN1-DHCPNetworktopology,InternalLAN1IP:/24,WAN1PPPoE,ObjectivesAccesstoInternetsuccessfully(Ping)ConfigurationoflogicEnable“DHCPclient”inInterfaceCreatetheIPruleandchoosecorrectAction,Service,InterfaceandNetworkintherule,应用示例1-5BasicConfiguration-WAN1-DHCP,EnabletheDHCPclientinethernetofInterfaceClick“Ethernet”inInterfaceEnable“DHCPClient”,应用示例1-5BasicConfiguration-WAN1-DHCP,1,2,3,CreatetheserviceruleinIPrulesClick“IPrules”inRulesChoosecorrectAction,Service,InterfaceandNetworkintherule,应用示例1-5BasicConfiguration-WAN1-DHCP,1,2,3,应用示例1-5BasicConfiguration-WAN1-DHCP,Afterallconfiguration,Click“configuration”inmainbarClick“SaveandActive”,1,2,3,TestingResult,应用示例1-5BasicConfiguration-WAN1-DHCP,应用示例1-5Exercise1-5-WAN1-DHCP,InternalLAN1IP:/24,WAN1DHCP,Goal:AccesstoInternetsuccessfully(Ping),应用示例2-1RouteFailover,InternalLAN1IP:/16,InternalLAN2IP:/24,InternalLAN3IP:/24,WAN2(staticIP)IP:0/24WAN2-gatewayIP:54,WAN1DHCP,ObjectivesWAN1ismainline,WAN2isbackuplineUnplugWAN1cable,stillcouldaccesstoInternet(Ping)WhenWAN1restores,alltrafficaccesstoInternetbyWAN1ConfigurationoflogicApplyingroutingpolicybetweenDHCPandstaticIPinWANconnectionVerifyroutingruleinmainroutingtableCreatetheIPruleandchoosecorrectAction,Service,InterfaceandNetworkintherule,应用示例2-1RouteFailover,EnabletheDHCPclientinEthernetofInterfaceClick“Ethernet”inInterfaceDisable“Adddefaultrouteifdefaultgatewayisspecified”,1,2,3,4,5,6,7,应用示例2-1RouteFailover,8,CreatethecorrectgatewayobjectinaddressbookofObject(WAN2)Click“addressbook”inObjectAddtheobjectforIP4Host/NetworkVerifywan2_ipandwan2net,1,2,3,4,5,6,7,应用示例2-1RouteFailover,8,ApplythegatewayobjecttoWANInterfaceanddisable“adddefaultroute”Click“Ethernet”inInterfaceDisabledefaultrouteinInterface,1,2,3,4,5,6,7,应用示例2-1RouteFailover,8,CombineWAN1andWAN2totheobjectofWANClick“interfaceGroups”inInterfaceCreatetheobjectandchooseWAN1andWAN2,1,2,3,4,5,6,7,应用示例2-1RouteFailover,8,CreatetheIPruleforWANgroupClick“Rules”inIPRuleChoosecorrectAction,Service,InterfaceandNetworkintherule,1,2,3,4,5,6,7,应用示例2-1RouteFailover,8,CreatetheWAN1routingruleandenable“monitorthisroute”Click“MainRoutingTable”inRoutingCreatetheroutingruleforWAN1ChoosehigherMetricandenable“monitorthisroute”,1,2,3,4,5,6,7,应用示例2-1RouteFailover,8,CreatetheWAN2routingruleandenable“monitorthisroute”Click“MainRoutingTable”inRoutingCreatetheroutingruleforWAN2ChooselowerMetricandenable“monitorthisroute”,1,2,3,4,5,6,7,应用示例2-1RouteFailover,8,应用示例2-1RouteFailover,Afterallconfiguration,Click“configuration”inmainbarClick“SaveandActive”,1,2,3,4,5,6,7,8,应用示例2-1Exercise2-1-RouteFailover,InternalLAN1GroupIP,WAN2GroupIP(StaticIP),WAN1DHCP,Goal:WAN1ismainline,WAN2isbackuplineUnplugWAN1cable,stillcouldaccesstoInternet(Ping)WhenWAN1restores,alltrafficaccesstoInternetbyWAN1,WAN2LAN1Group1:/24/24Group2:/24/24.Group9:/24/24Group10:0/24/24WAN2-Gateway:54,应用示例2-2LoadSharingNetworktopology,InternalLAN1IP:/16,InternalLAN2IP:/24,InternalLAN3IP:/24,WAN1DHCP,WAN2(staticIP)IP:0/24WAN2-gatewayIP:54,ObjectivesThespecifictrafficandserviceaccesstoInternetbyWAN2UnplugWAN1cable,stillcouldaccesstoInternetWhenWAN2restores,thespecifictrafficandserviceaccess

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论