µÈ±£»¤ÒªÇójuniper·À»ðǽ°²È«ÅäÖüì²é±í-ÐÅÏ¢°²È«²âÆÀÖÐÐÄ ÏÂÔر¾ÎÄ

ÄÚÈÝ·¢²¼¸üÐÂʱ¼ä : 2025/3/28 22:41:08ÐÇÆÚÒ» ÏÂÃæÊÇÎÄÕµÄÈ«²¿ÄÚÈÝÇëÈÏÕæÔĶÁ¡£

ÐÅÏ¢°²È«µÈ¼¶±£»¤ÆÀ¹ÀÖÐÐÄ

ÐòºÅ Àà±ð ²âÆÀÏî ²âÆÀʵʩ Ô¤ÆÚ½á¹û ˵Ã÷ b)Ó¦Äܸù¾Ý»á»°×´Ì¬ÐÅϢΪÊý¾ÝÁ÷ÌṩÃ÷È·µÄÔÊÐí/¾Ü¾ø·ÃÎʵÄÄÜÁ¦£¬¿ØÖÆÁ£¶ÈΪ¶Ë¿Ú¼¶£» 1£©¼ì²é·ÃÎÊ¿ØÖƲßÂÔÁÐ±í£¬²é¿´ÊÇ·ñÅäÖÃÁËÃ÷È·µÄÔÊÐí/¾Ü¾øµÄ·ÃÎÊÄÜÁ¦£¬¿ØÖÆ¿ÅÁ£¶ÈΪ¶Ë¿Ú¼¶¡£ 1£©·À»ðǽ°²È«²ßÂԾ߱¸Ô´IPµØÖ·¡¢ÊäÈë¡°get config¡±ÃüÁӦ´æÔÚÈçÏÂÀàËÆÅäÖ㺠Ŀ±êIPµØÖ·¡¢ÔÊÐí/¾Ü¾øºÍÓ¦Ó÷þÎñset policy id 1 form Trust to Untrust any any ¶Ë¿ÚºÅ¡£ ftp permit ·Ã1 ÎÊ¿ØÖÆ c)Ó¦¶Ô½ø³öÍøÂçµÄÐÅÏ¢ÄÚÈݽøÐйýÂË£¬ÊµÏÖ¶ÔÓ¦ÓòãHTTP¡¢FTP¡¢1£©¼ì²é·À»ðǽ°²È«²ßÂÔÊÇ·ñ¶ÔÖØÒªÊý¾ÝÁ÷ÆôÓÃÓ¦ÓÃ1£©·À»ðǽ°²È«²ßÂÔÅäÖò¢ÆôÓÃÁËTELNET¡¢SMTP¡¢POP3µÈЭÒéÃüÁî²ãЭÒéÉî²ã¼ì²â¡£ Deep Inspection¡£ ¼¶µÄ¿ØÖÆ£» Éî¶È¼ì²â°üÀ¨http\\smtp\\pop3\\ftp,ÆôÓÃÉî¶È¼ì²âÓпÉÄÜ»áÓ°Ïì·À»ðǽµÄ´¦ÀíÐÔÄÜ¡£ d)Ó¦ÔڻỰ´¦ÓÚ·Ç»îÔ¾Ò»¶¨Ê±¼ä»ò»á»°½áÊøºóÖÕÖ¹ÍøÂçÁ¬½Ó£» 1£©·À»ðǽÄܹ»¸ù¾ÝÒµÎñÐèÒªÔÚûÓÐÊý1£©·Ã̸ϵͳ¹ÜÀíÔ±£¬ÊÇ·ñÔڻỰ´¦ÓÚ·Ç»îÔ¾Ò»¶¨Ê±¾Ý´«ÊäÒ»¶Îʱ¼äºóÖÕÖ¹ÍøÂç»á»°Á¬¼ä»ò»á»°½áÊøºóÖÕÖ¹ÍøÂçÁ¬½Ó£» ½Ó¡£ µÚ 1 Ò³ ¹² 7 Ò³

ÐÅÏ¢°²È«µÈ¼¶±£»¤ÆÀ¹ÀÖÐÐÄ

ÐòºÅ Àà±ð ²âÆÀÏî ²âÆÀʵʩ Ô¤ÆÚ½á¹û ˵Ã÷ e)Ó¦ÏÞÖÆÍøÂç×î´óÁ÷Á¿Êý¼°ÍøÂçÁ¬½ÓÊý£» 1£©·Ã̸ϵͳ¹ÜÀíÔ±²¢¼ì²é·À»ðǽÅäÖã¬ÊÇ·ñÏÞÖÆÍøÂç×î´óÁ÷Á¿Êý¼°ÍøÂçÁ¬½ÓÊý¡£ ÊäÈë¡°get config¡±ÃüÁӦ´æÔÚÈçÏÂÀàËÆÅäÖ㺠set zone dmz screen limit-session source-ip-based 1 set zone dmz screen limit-session source-ip-based set zone trust screen limit-session source-ip-based 80 1£©·À»ðǽÅäÖò¢ÆôÓûùÓÚÔ´IPµØÖ·set zone trust screen limit-session ºÍ»ùÓÚÄ¿±êIPµØÖ·µÄ¿¹¹¥»÷ÉèÖᣠsource-ip-based set zone untrust screen limit-session destination-ip-based 4000(ÒÀ¾ÝÒµÎñÐèÇóÉ趨´ËÖµ) set zone untrust screen limit-session destination-ip-based set flow aging low-watermark 70 set flow aging high-watermark 80 set flow aging early-ageout 4 N/A f) ÖØÒªÍø¶ÎÓ¦²ÉÈ¡¼¼ÊõÊֶηÀÖ¹µØÖ·ÆÛÆ­£» ¸Ã¹¦ÄÜÒ»°ãÓɽÓÈë½»»»»úʵÏÖ¡£ µÚ 2 Ò³ ¹² 7 Ò³

ÐÅÏ¢°²È«µÈ¼¶±£»¤ÆÀ¹ÀÖÐÐÄ

ÐòºÅ Àà±ð ²âÆÀÏî g) Ó¦°´Óû§ºÍϵͳ֮¼äµÄÔÊÐí·ÃÎʹæÔò£¬¾ö¶¨ÔÊÐí»ò¾Ü¾øÓû§¶ÔÊÜ¿Øϵͳ½øÐÐ×ÊÔ´·ÃÎÊ£¬¿ØÖÆÁ£¶ÈΪµ¥¸öÓû§£» h) Ó¦ÏÞÖƾßÓв¦ºÅ·ÃÎÊȨÏÞµÄÓû§ÊýÁ¿¡£ ²âÆÀʵʩ Ô¤ÆÚ½á¹û ˵Ã÷ N/A ¸ÃÉ豸ÎÞ²¦ºÅ¹¦ÄÜ¡£ N/A ¸ÃÉ豸ÎÞ²¦ºÅ¹¦ÄÜ¡£ °²2 È«Éó¼Æ a)Ó¦¶ÔÍøÂçϵͳÖеÄÍøÂçÉ豸ÔËÐÐ×´¿ö¡¢ÍøÂçÁ÷Á¿¡¢Óû§ÐÐΪµÈ½øÐÐÈÕÖ¾¼Ç¼£» 1)¼ì²é·À»ðǽÊÇ·ñ¿ªÆôÈÕÖ¾¹¦ÄÜ¡£ WebGUI·½Ê½: ½øÈë[reports]->[system log]->[event]Ñ¡Ôñʱ¼ä¼¶±ð½øÐвéѯ£¬[configuration]->[report settings]->[syslog]ÊÇ·ñÉèÖÃÈÕÖ¾·þÎñÆ÷¡£ 1£©·À»ðǽÉèÖÃÈÕÖ¾·þÎñÆ÷£¬²¢Ê¹ÓÃÃüÁʽ£º Syslog·½Ê½»òÕßSNMP·½Ê½½«ÈÕÖ¾·¢ÊäÈë¡°get config¡±ÃüÁӦ´æÔÚÈçÏÂÀàËÆÅäÖ㺠Ë͵½ÈÕÖ¾·þÎñÆ÷¡£ Set syslog config 1.1.1.1 port 1514 Set syslog config 1.1.1.1 log all Set syslog config 1.1.1.1 facilities local0 local0 Set syslog config 1.1.1.1 transport tcp µÚ 3 Ò³ ¹² 7 Ò³