1 | set clock timezone 1
|
---|
2 | set vrouter trust-vr sharable
|
---|
3 | set vrouter "untrust-vr"
|
---|
4 | exit
|
---|
5 | set vrouter "trust-vr"
|
---|
6 | unset auto-route-export
|
---|
7 | set protocol ospf
|
---|
8 | set enable
|
---|
9 | set advertise-def-route metric 1 metric-type 1
|
---|
10 | set reject-default-route
|
---|
11 | exit
|
---|
12 | exit
|
---|
13 | set service "HTTP-PROXY" protocol tcp src-port 0-65535 dst-port 8080-8080
|
---|
14 | set auth-server "Local" id 0
|
---|
15 | set auth-server "Local" server-name "Local"
|
---|
16 | set auth default auth server "Local"
|
---|
17 | set auth radius accounting port 1646
|
---|
18 | set admin name "admin"
|
---|
19 | set admin password "nO1CGHrlLNQGcmMEDsjLaJOt8VPYtn"
|
---|
20 | set admin manager-ip 10.40.1.21 255.255.255.0
|
---|
21 | set admin auth timeout 10
|
---|
22 | set admin auth server "Local"
|
---|
23 | set admin format dos
|
---|
24 | set vip multi-port
|
---|
25 | set zone "Trust" vrouter "trust-vr"
|
---|
26 | set zone "Untrust" vrouter "trust-vr"
|
---|
27 | set zone "DMZ" vrouter "trust-vr"
|
---|
28 | set zone "VLAN" vrouter "trust-vr"
|
---|
29 | set zone "Untrust-Tun" vrouter "trust-vr"
|
---|
30 | set zone "Trust" tcp-rst
|
---|
31 | set zone "Untrust" block
|
---|
32 | unset zone "Untrust" tcp-rst
|
---|
33 | set zone "DMZ" tcp-rst
|
---|
34 | set zone "VLAN" block
|
---|
35 | unset zone "VLAN" tcp-rst
|
---|
36 | set zone "Untrust" screen tear-drop
|
---|
37 | set zone "Untrust" screen syn-flood
|
---|
38 | set zone "Untrust" screen ping-death
|
---|
39 | set zone "Untrust" screen ip-filter-src
|
---|
40 | set zone "Untrust" screen land
|
---|
41 | set zone "V1-Untrust" screen tear-drop
|
---|
42 | set zone "V1-Untrust" screen syn-flood
|
---|
43 | set zone "V1-Untrust" screen ping-death
|
---|
44 | set zone "V1-Untrust" screen ip-filter-src
|
---|
45 | set zone "V1-Untrust" screen land
|
---|
46 | set interface "ethernet0/0" zone "Null"
|
---|
47 | set interface "ethernet0/1" zone "Null"
|
---|
48 | set interface "bgroup0" zone "Null"
|
---|
49 | set interface "bgroup0.1" tag 340 zone "Untrust"
|
---|
50 | set interface "bgroup0.2" tag 2 zone "Untrust"
|
---|
51 | set interface "bgroup1.1" tag 441 zone "DMZ"
|
---|
52 | set interface "bgroup2" zone "Trust"
|
---|
53 | set interface "bgroup2.1" tag 442 zone "Trust"
|
---|
54 | set interface "bgroup3" zone "Trust"
|
---|
55 | set interface bgroup0 port ethernet0/0
|
---|
56 | set interface bgroup1 port ethernet0/1
|
---|
57 | set interface bgroup2 port ethernet0/2
|
---|
58 | unset interface vlan1 ip
|
---|
59 | set interface bgroup0.1 ip 10.30.0.6/30
|
---|
60 | set interface "bgroup0.1" ipv6 mode "router"
|
---|
61 | set interface "bgroup0.1" ipv6 ip 2001:db8:3:340::6/64
|
---|
62 | set interface "bgroup0.1" ipv6 enable
|
---|
63 | set interface bgroup0.1 route
|
---|
64 | set interface bgroup0.2 ip 10.40.130.254/24
|
---|
65 | set interface "bgroup0.2" ipv6 mode "router"
|
---|
66 | set interface bgroup0.2 route
|
---|
67 | set interface bgroup1.1 ip 10.40.2.1/24
|
---|
68 | set interface "bgroup1.1" ipv6 mode "router"
|
---|
69 | set interface "bgroup1.1" ipv6 ip 2001:db8:4:441::1/64
|
---|
70 | set interface "bgroup1.1" ipv6 enable
|
---|
71 | set interface bgroup1.1 route
|
---|
72 | set interface bgroup2.1 ip 10.40.30.2/30
|
---|
73 | set interface "bgroup2.1" ipv6 mode "router"
|
---|
74 | set interface "bgroup2.1" ipv6 ip 2001:db8:4:442::2/64
|
---|
75 | set interface "bgroup2.1" ipv6 enable
|
---|
76 | set interface bgroup2.1 nat
|
---|
77 | set interface "bgroup0.1" pmtu ipv4
|
---|
78 | unset interface vlan1 bypass-others-ipsec
|
---|
79 | unset interface vlan1 bypass-non-ip
|
---|
80 | unset interface bgroup0.1 ip manageable
|
---|
81 | set interface bgroup0.2 ip manageable
|
---|
82 | set interface bgroup1.1 ip manageable
|
---|
83 | set interface bgroup2.1 ip manageable
|
---|
84 | set interface bgroup0.1 manage ping
|
---|
85 | set interface bgroup0.1 manage ident-reset
|
---|
86 | set interface bgroup0.2 manage ping
|
---|
87 | set interface bgroup0.2 manage telnet
|
---|
88 | set interface bgroup0.2 manage web
|
---|
89 | unset interface bgroup2 manage ping
|
---|
90 | unset interface bgroup2 manage ssh
|
---|
91 | unset interface bgroup2 manage telnet
|
---|
92 | unset interface bgroup2 manage snmp
|
---|
93 | unset interface bgroup2 manage ssl
|
---|
94 | unset interface bgroup2 manage web
|
---|
95 | unset interface bgroup2.1 manage ssh
|
---|
96 | unset interface bgroup2.1 manage snmp
|
---|
97 | unset interface bgroup2.1 manage ssl
|
---|
98 | set interface bgroup0.1 ipv6 ra link-address
|
---|
99 | set interface bgroup0.2 ipv6 ra prefix 2001:db8:3:340::/64 autonomous onlink
|
---|
100 | set interface bgroup0.2 ipv6 ra link-address
|
---|
101 | set interface bgroup1.1 ipv6 ra prefix 2001:db8:4:441::/64 autonomous onlink
|
---|
102 | unset interface bgroup1.1 ipv6 ra link-address
|
---|
103 | set interface bgroup1.1 ipv6 ra transmit
|
---|
104 | set interface bgroup2.1 ipv6 ra prefix 2001:db8:4:441::/64 autonomous onlink
|
---|
105 | set interface bgroup2.1 ipv6 ra prefix 2001:db8:3:340::/64 autonomous onlink
|
---|
106 | set interface bgroup2.1 ipv6 ra link-address
|
---|
107 | set interface bgroup2.1 ipv6 ra other
|
---|
108 | set interface bgroup2.1 ipv6 ra managed
|
---|
109 | set interface bgroup2.1 ipv6 ra transmit
|
---|
110 | set interface bgroup0.1 ipv6 nd nud
|
---|
111 | set interface bgroup0.2 ipv6 nd nud
|
---|
112 | set interface bgroup1.1 ipv6 nd nud
|
---|
113 | set interface bgroup2.1 ipv6 nd nud
|
---|
114 | set interface bgroup0.2 dip interface-ip incoming
|
---|
115 | set interface bgroup1.1 dip interface-ip incoming
|
---|
116 | set interface "serial0/0" modem settings "USR" init "AT&F"
|
---|
117 | set interface "serial0/0" modem settings "USR" active
|
---|
118 | set interface "serial0/0" modem speed 115200
|
---|
119 | set interface "serial0/0" modem retry 3
|
---|
120 | set interface "serial0/0" modem interval 10
|
---|
121 | set interface "serial0/0" modem idle-time 10
|
---|
122 | set flow tcp-mss
|
---|
123 | unset flow no-tcp-seq-check
|
---|
124 | set flow tcp-syn-check
|
---|
125 | set hostname firewall1
|
---|
126 | set pki authority default scep mode "auto"
|
---|
127 | set pki x509 default cert-path partial
|
---|
128 | set ike respond-bad-spi 1
|
---|
129 | unset ike ikeid-enumeration
|
---|
130 | unset ipsec access-session enable
|
---|
131 | set ipsec access-session maximum 5000
|
---|
132 | set ipsec access-session upper-threshold 0
|
---|
133 | set ipsec access-session lower-threshold 0
|
---|
134 | set ipsec access-session dead-p2-sa-timeout 0
|
---|
135 | unset ipsec access-session log-error
|
---|
136 | unset ipsec access-session info-exch-connected
|
---|
137 | unset ipsec access-session use-error-log
|
---|
138 | set url protocol websense
|
---|
139 | exit
|
---|
140 | set policy id 1 from "Trust" to "Untrust" "Any-IPv4" "Any-IPv4" "ANY" permit
|
---|
141 | set policy id 1
|
---|
142 | exit
|
---|
143 | set policy id 2 from "Trust" to "DMZ" "Any-IPv4" "Any-IPv4" "ANY" permit
|
---|
144 | set policy id 2
|
---|
145 | exit
|
---|
146 | set policy id 3 from "Untrust" to "Trust" "Any-IPv4" "Any-IPv4" "ANY" deny
|
---|
147 | set policy id 3
|
---|
148 | exit
|
---|
149 | set policy id 4 from "Untrust" to "DMZ" "Any-IPv4" "Any-IPv4" "DNS" permit
|
---|
150 | set policy id 4
|
---|
151 | set service "HTTP"
|
---|
152 | set service "NTP"
|
---|
153 | set service "PING"
|
---|
154 | set service "SSH"
|
---|
155 | exit
|
---|
156 | set policy id 5 from "DMZ" to "Untrust" "Any-IPv4" "Any-IPv4" "DNS" permit
|
---|
157 | set policy id 5
|
---|
158 | set service "HTTP"
|
---|
159 | set service "HTTP-PROXY"
|
---|
160 | set service "NTP"
|
---|
161 | set service "PING"
|
---|
162 | exit
|
---|
163 | set policy id 6 from "DMZ" to "Trust" "Any-IPv4" "Any-IPv4" "DNS" permit
|
---|
164 | set policy id 6
|
---|
165 | set service "HTTP"
|
---|
166 | set service "NTP"
|
---|
167 | set service "PING"
|
---|
168 | exit
|
---|
169 | set policy id 7 from "Trust" to "DMZ" "Any-IPv6" "Any-IPv6" "ANY" permit
|
---|
170 | set policy id 7
|
---|
171 | exit
|
---|
172 | set policy id 8 from "Trust" to "Untrust" "Any-IPv6" "Any-IPv6" "ANY" permit
|
---|
173 | set policy id 8
|
---|
174 | exit
|
---|
175 | set policy id 9 from "Untrust" to "Trust" "Any-IPv6" "Any-IPv6" "ANY" deny
|
---|
176 | set policy id 9
|
---|
177 | exit
|
---|
178 | set policy id 10 from "Untrust" to "DMZ" "Any-IPv6" "Any-IPv6" "DNS" permit
|
---|
179 | set policy id 10
|
---|
180 | set service "HTTP"
|
---|
181 | set service "ICMP6-ANY"
|
---|
182 | set service "NTP"
|
---|
183 | exit
|
---|
184 | set policy id 11 from "DMZ" to "Untrust" "Any-IPv6" "Any-IPv6" "DNS" permit
|
---|
185 | set policy id 11
|
---|
186 | set service "HTTP"
|
---|
187 | set service "ICMP6-ANY"
|
---|
188 | set service "NTP"
|
---|
189 | exit
|
---|
190 | set policy id 12 from "DMZ" to "Trust" "Any-IPv6" "Any-IPv6" "DNS" permit
|
---|
191 | set policy id 12
|
---|
192 | set service "HTTP"
|
---|
193 | set service "ICMP6-ANY"
|
---|
194 | set service "NTP"
|
---|
195 | exit
|
---|
196 | set policy id 13 from "DMZ" to "Untrust" "Any-IPv4" "Any-IPv4" "ANY" permit
|
---|
197 | set policy id 13 disable
|
---|
198 | set policy id 13
|
---|
199 | exit
|
---|
200 | set monitor cpu 100
|
---|
201 | set nsmgmt bulkcli reboot-timeout 60
|
---|
202 | set ssh version v2
|
---|
203 | set config lock timeout 5
|
---|
204 | set ntp server "10.40.2.32"
|
---|
205 | set ntp server backup1 "0.0.0.0"
|
---|
206 | set ntp server backup2 "0.0.0.0"
|
---|
207 | set snmp community "public" Read-Only Trap-on traffic version v1
|
---|
208 | set snmp host "public" 10.40.1.0 255.255.255.0
|
---|
209 | set snmp name "firewall1"
|
---|
210 | unset snmp auth-trap enable
|
---|
211 | set snmp port listen 161
|
---|
212 | set snmp port trap 162
|
---|
213 | set vrouter "untrust-vr"
|
---|
214 | exit
|
---|
215 | set vrouter "trust-vr"
|
---|
216 | set router-id 10.30.0.6
|
---|
217 | set protocol bgp 65004
|
---|
218 | set enable
|
---|
219 | set neighbor 10.30.0.5 remote-as 65003
|
---|
220 | set neighbor 10.30.0.5 enable
|
---|
221 | set neighbor 10.30.0.5 send-community
|
---|
222 | set network 10.40.2.0/24 weight 1 no-check |
---|
223 |
set network 10.40.1.0/24 weight 1 no-check |
---|
224 |
exit
|
---|
225 | set access-list 1
|
---|
226 | set route-map name "DMZ"
|
---|
227 | unset add-default-route
|
---|
228 | set route 0.0.0.0/0 interface bgroup0.1 gateway 10.30.0.5 preference 20
|
---|
229 | set route 2001:db8:4:444::/64 interface bgroup2.1 gateway 2001:db8:4:442::1 preference 20
|
---|
230 | set route 2001:db8:4:445::/64 interface bgroup2.1 gateway 2001:db8:4:442::1 preference 20
|
---|
231 | set route ::/0 interface bgroup0.1 gateway 2001:db8:3:340::5 preference 20
|
---|
232 | set protocol bgp
|
---|
233 | set redistribute route-map "DMZ" protocol connected
|
---|
234 | exit
|
---|
235 | exit
|
---|
236 | set interface bgroup0.1 protocol ospf area 0.0.0.0
|
---|
237 | set interface bgroup0.1 protocol ospf passive
|
---|
238 | set interface bgroup0.1 protocol ospf enable
|
---|
239 | set interface bgroup0.1 protocol ospf cost 1
|
---|
240 | set interface bgroup2.1 protocol ospf area 0.0.0.0
|
---|
241 | set interface bgroup2.1 protocol ospf enable
|
---|
242 | set interface bgroup2.1 protocol ospf cost 1
|
---|
243 | set interface bgroup0.1 protocol bgp
|
---|
244 | set interface bgroup1.1 protocol bgp
|
---|
245 | set vrouter "untrust-vr"
|
---|
246 | exit
|
---|
247 | set vrouter "trust-vr"
|
---|
248 | exit
|
---|