大家好
我这里有一台NS5GT的设备,自从接上去以后就没有正常过.现象是:过个1个小时左右从外网接口(untrust)无法访问防火
墙了,就连PING也不能通,然后只要把外网接口(untrust)接口的网线拔下来,然后在接上去就正常了.如果不拔外网接口的网线的话就无法从外网接口进去. 里面也没有做什么
配置 这是什么原因啊????????????
只做了一个L2TP
VPN,然后做了几个映射.
以下就完整的配置
ns5gt-> get config
Total Config size 4498:
set clock timezone 7
set vrouter trust-vr sharable
set vrouter "untrust-vr"
exit
set vrouter "trust-vr"
unset auto-route-export
exit
set service "3389" protocol tcp src-port 0-65535 dst-port 3389-3389
set auth-server "Local" id 0
set auth-server "Local" server-name "Local"
set auth default auth server "Local"
set auth radius accounting port 1646
set admin name "netscreen"
set admin password "nKVUM2rwMUzPcrkG5sWIHdCtqkAibn"
set admin auth timeout 10
set admin auth server "Local"
set admin format dos
set zone "Trust" vrouter "trust-vr"
set zone "Untrust" vrouter "trust-vr"
set zone "VLAN" vrouter "trust-vr"
set zone "Untrust-Tun" vrouter "trust-vr"
set zone "Trust" tcp-rst
set zone "Untrust" block
unset zone "Untrust" tcp-rst
set zone "MGT" block
set zone "VLAN" block
unset zone "VLAN" tcp-rst
set zone "Untrust" screen tear-drop
set zone "Untrust" screen syn-flood
set zone "Untrust" screen ping-death
set zone "Untrust" screen ip-filter-src
set zone "Untrust" screen land
set zone "V1-Untrust" screen tear-drop
set zone "V1-Untrust" screen syn-flood
set zone "V1-Untrust" screen ping-death
set zone "V1-Untrust" screen ip-filter-src
set zone "V1-Untrust" screen land
set interface "trust" zone "Trust"
set interface "untrust" zone "Untrust"
unset interface vlan1 ip
set interface trust ip 192.168.0.1/24
set interface trust nat
set interface untrust ip x.x.x.x/24
set interface untrust route
unset interface vlan1 bypass-others-ipsec
unset interface vlan1 bypass-non-ip
set interface trust ip manageable
set interface untrust ip manageable
set interface untrust manage ping
set interface untrust manage ssh
set interface untrust manage telnet
set interface untrust manage snmp
set interface untrust manage ssl
set interface untrust manage web
set interface untrust vip untrust 21 "FTP" 192.168.0.2
set interface untrust vip untrust 3389 "3389" 192.168.0.2
set interface trust dhcp server service
set interface trust dhcp server auto
set interface trust dhcp server option gateway 192.168.0.1
set interface trust dhcp server option netmask 255.255.255.0
set interface trust dhcp server option dns1 61.153.224.8
set interface trust dhcp server ip 192.168.0.2 to 192.168.0.254
unset interface trust dhcp server config next-server-ip
set flow tcp-mss
unset flow no-tcp-seq-check
set flow tcp-syn-check
set pki authority default scep mode "auto"
set pki x509 default cert-path partial
set ippool "L2TP VPN" 10.10.10.2 10.10.10.254
set user "PHILIPS" uid 2
set user "PHILIPS" type ike l2tp
set user "PHILIPS" password "Uz/x0r61N8dyoss/3kCfegrBN1nYWoc2Kw=="
unset user "PHILIPS" type auth
set user "PHILIPS" "enable"
set user "winscom" uid 1
set user "winscom" ike-id fqdn "
www.winscom.com" share-limit 1
set user "winscom" type ike l2tp
set user "winscom" password "wz6ynN10NFYJZhs7DrCt2fQ0zEn1yjXYBA=="
unset user "winscom" type auth
set user "winscom" "enable"
set user-group "group01" id 1
set user-group "group01" user "PHILIPS"
set user-group "group01" user "winscom"
set ike respond-bad-spi 1
unset ike ikeid-enumeration
unset ike dos-protection
unset ipsec access-session enable
set ipsec access-session maximum 5000
set ipsec access-session upper-threshold 0
set ipsec access-session lower-threshold 0
set ipsec access-session dead-p2-sa-timeout 0
unset ipsec access-session log-error
unset ipsec access-session info-exch-connected
unset ipsec access-session use-error-log
set l2tp default dns1 220.189.127.106
set l2tp default ippool "L2TP VPN"
set l2tp "L2TP" id 1 outgoing-interface untrust keepalive 60
set l2tp "L2TP" remote-setting ippool "L2TP VPN"
set url protocol websense
exit
set policy id 2 from "Untrust" to "Trust" "Dial-Up VPN" "Any" "ANY" tunnel l2tp "L2TP" log
set policy id 2
exit
set policy id 5 from "Untrust" to "Trust" "Any" "VIP(untrust)" "FTP" permit log
set policy id 5
exit
set policy id 6 from "Untrust" to "Trust" "Any" "VIP(untrust)" "3389" permit log
set policy id 6
exit
set nsmgmt bulkcli reboot-timeout 60
set ssh version v2
set config lock timeout 5
set modem speed 115200
set modem retry 3
set modem interval 10
set modem idle-time 10
set snmp port listen 161
set snmp port trap 162
set vrouter "untrust-vr"
exit
set vrouter "trust-vr"
unset add-default-route
set route 0.0.0.0/0 interface untrust gateway x.x.x.x preference 20
exit
set vrouter "untrust-vr"
exit
set vrouter "trust-vr"
exit
ns5gt->