发新话题
打印

[问题求助] 求助斑竹,关于juniper ssg5 的设置

求助斑竹,关于juniper ssg5 的设置

以下配置,是不是哪里设置错误,或者漏设了。 上不了网
set clock ntp
set clock timezone 8
set vrouter trust-vr sharable
set vrouter "untrust-vr"
exit
set vrouter "trust-vr"
unset auto-route-export
exit
set service "citrix" protocol tcp src-port 0-65535 dst-port 5678-5678
set auth-server "Local" id 0
set auth-server "Local" server-name "Local"
set auth default auth server "Local"
set auth radius accounting port 1646
set admin name "netscreen"
set admin password "nADjGMrJDMzFcwTMXsCDKNMt2vNgAn"
set admin user "2584" password "nL0pL/r0GLAPcc4HNszOdONtO/Ljrn" privilege "all"
set admin auth timeout 10
set admin auth server "Local"
set admin format dos
set zone "Trust" vrouter "trust-vr"
set zone "Untrust" vrouter "trust-vr"
set zone "DMZ" vrouter "trust-vr"
set zone "VLAN" vrouter "trust-vr"
set zone "Untrust-Tun" vrouter "trust-vr"
set zone "Trust" tcp-rst
set zone "Untrust" block
unset zone "Untrust" tcp-rst
set zone "DMZ" tcp-rst
set zone "VLAN" block
unset zone "VLAN" tcp-rst
set zone "Untrust" screen tear-drop
set zone "Untrust" screen syn-flood
set zone "Untrust" screen ping-death
set zone "Untrust" screen ip-filter-src
set zone "Untrust" screen land
set zone "V1-Untrust" screen tear-drop
set zone "V1-Untrust" screen syn-flood
set zone "V1-Untrust" screen ping-death
set zone "V1-Untrust" screen ip-filter-src
set zone "V1-Untrust" screen land
set interface "ethernet0/0" zone "Untrust"
set interface "ethernet0/1" zone "DMZ"
set interface "bgroup0" zone "Trust"
set interface "bgroup2" zone "Trust"
set interface bgroup0 port ethernet0/2
set interface bgroup0 port ethernet0/3
set interface bgroup0 port ethernet0/4
set interface bgroup0 port ethernet0/5
set interface bgroup0 port ethernet0/6
unset interface vlan1 ip
set interface ethernet0/0 ip 61.190.196.190/24
set interface ethernet0/0 route
set interface bgroup0 ip 192.168.110.254/24
set interface bgroup0 nat
unset interface vlan1 bypass-others-ipsec
unset interface vlan1 bypass-non-ip
set interface ethernet0/0 ip manageable
set interface bgroup0 ip manageable
set interface ethernet0/0 manage ping
set interface ethernet0/0 manage telnet
set interface ethernet0/0 manage ssl
set interface ethernet0/0 manage web
unset interface bgroup0 manage ssh
unset interface bgroup0 manage snmp
set interface ethernet0/0 dip interface-ip incoming
set interface bgroup0 dip interface-ip incoming
set interface "serial0/0" modem settings "USR" init "AT&F"
set interface "serial0/0" modem settings "USR" active
set interface "serial0/0" modem speed 115200
set interface "serial0/0" modem retry 3
set interface "serial0/0" modem interval 10
set interface "serial0/0" modem idle-time 10
set flow tcp-mss
unset flow no-tcp-seq-check
set flow tcp-syn-check
set hostname YIDE-F/W
set pki authority default scep mode "auto"
set pki x509 default cert-path partial
set dns host dns1 202.102.192.68 src-interface ethernet0/0
set dns host dns2 202.102.199.68 src-interface ethernet0/0
set dns host dns3 0.0.0.0
set dns host schedule 06:28
set group address "Trust" "web"
set group address "Trust" "web+msn"
set group service "help"
set ike respond-bad-spi 1
unset ike ikeid-enumeration
unset ike dos-protection
unset ipsec access-session enable
set ipsec access-session maximum 5000
set ipsec access-session upper-threshold 0
set ipsec access-session lower-threshold 0
set ipsec access-session dead-p2-sa-timeout 0
unset ipsec access-session log-error
unset ipsec access-session info-exch-connected
unset ipsec access-session use-error-log
set attack db sigpack base
set url protocol websense
exit
set policy id 3 name "any" from "Trust" to "Untrust"  "Any" "Any" "ANY" permit
set policy id 3
exit
set policy id 4 from "Untrust" to "Trust"  "Any" "Any" "ANY" permit
set policy id 4
exit
set nsmgmt bulkcli reboot-timeout 60
set ssh version v2
set config lock timeout 5
set ntp server "0.0.0.0"
set ntp server backup1 "0.0.0.0"
set ntp server backup2 "0.0.0.0"
set snmp port listen 161
set snmp port trap 162
set vrouter "untrust-vr"
exit
set vrouter "trust-vr"
unset add-default-route
exit
set vrouter "untrust-vr"
exit
set vrouter "trust-vr"
exit
  请指点,十万火急!!!!!!!!!!!!

TOP

怎么没有人支援呀

TOP

发新话题