当前位置:网站首页>HCIA-USG Security Policy
HCIA-USG Security Policy
2022-07-03 19:39:00 【fa_ nei_ kuang_ tu】
2022.2.14 What we should sober up is , Regret and failure are the normal state of life . It's no use trying , It's no use trying , It's useless to like it , I like it even if it's useless . This is also the greatest heroism !!!
Suggestions on security policy configuration
During business debugging , How to specify matching conditions accurately is the difficulty of configuring security policies . The matching condition is set too wide extensive , There are security risks ; The matching conditions are set too strictly , It may cause the message to fail to hit the strategy , Affect the business The normal operation . The general configuration idea is as follows :
1. The action of configuring the default security policy is to allow , Debug the business , Ensure the normal operation of the business .
2. Look at the conversation table , Configure the security policy with the information recorded in the session table as the matching condition .
3. Restore the configuration of the default security policy , Debug the business again , Verify the correctness of the security policy .
The action configuration of the default security policy is permit after , The firewall allows all messages to pass , There may be security risks , because After this commissioning , Be sure to restore the default security policy action to deny.
[USG6000V2]ip address-set deny8888 type object// The configuration name is deny8888 Address set for
[USG6000V2-object-address-set-deny8888]dis this
2022-02-14 20:28:44.810
#
ip address-set deny8888 type object
address 0 10.1.1.2 mask 32
address 1 10.2.1.2 mask 32
#
return
[USG6000V2]ip service-set server-deny type object// by Server Configure custom service set server-deny
[USG6000V2-object-service-set-server-deny]dis this
2022-02-14 20:33:05.760
#
ip service-set server-deny type object 131
service 0 protocol tcp destination-port 8888
#
return
[USG6000V2]time-range time-deny// The configuration name is time_deny Time period
[USG6000V2-time-range-time-deny]dis this
2022-02-14 20:35:03.750
#
time-range time-deny
period-range 08:00:00 to 17:00:00 daily
#
return
[USG6000V2]security-policy
[USG6000V2-policy-security]dis this
2022-02-14 20:36:06.500
#
security-policy
rule name deny8888
source-zone untrust
destination-zone dmz
source-address address-set deny8888
destination-address 10.2.0.10 mask 255.255.255.255
service server-deny
time-range time-deny
action deny
rule name deny6666
source-zone untrust
destination-zone dmz
source-address address-set deny8888
destination-address 10.2.0.11 mask 255.255.255.255
service server-deny
time-range time-deny
action deny
rule name permit-6666
source-zone untrust
destination-zone dmz
destination-address 10.2.0.11 mask 255.255.255.255
service server-deny
action permit
#
return
summary
Huawei USG Next generation firewall security policy :
By default :
Layer 2 multicast message 、 Broadcast message Not controlled by security policy --USG Second floor wall
OSPF、BGP、IP-link、BFD、DHCP、LDP etc. Unicast data Not controlled by security policy
Traffic between different security domains is rejected by default
By default , The traffic between interfaces within a security domain is directly connected , By default, the switch that controls the flow in the domain is not on
[USG6000V1]security-policy
[USG6000V1-policy-security]default packet-filter intrazone enable
// Control the switch of interface flow interworking in the domain , After turning on the switch , Intra domain interface traffic is controlled by security policy
firewall l2-multicast packet-filter enable command Configure layer 2 multicast messages Controlled by security policy
firewall packet-filter basic-protocol enable Command configuration is right BGP、OSPF、DHCP、LDP、BFD Unicast message is controlled by security policy
MA:Multi Access Multiple access
NBMA:Non-Broadcast MA Non broadcast multiple access
If the actual environment ,USG Firewall blocked .
1、 Let the strategy go first , All in
2、 There are other problems besides strategy , Strategic issues
Cisco router acts as HTTP The server :
HTTPServer1(config)#ip http server
HTTPServer1(config)#ip http port 8888
边栏推荐
- Difference between surface go1 and surface GO2 (non professional comparison)
- 2022-06-25 advanced network engineering (XI) IS-IS synchronization process of three tables (neighbor table, routing table, link state database table), LSP, cSNP, psnp, LSP
- Day_ 18 IO stream system
- Web Security (VII) specific process of authentication with session cookie scheme
- [free sharing] kotalog diary2022 plan electronic manual ledger
- During MySQL installation, the download interface is empty, and the components to be downloaded are not displayed. MySQL installer 8.0.28.0 download interface is empty solution
- Day11 - my page, user information acquisition, modification and channel interface
- Octopus online ecological chain tour Atocha protocol received near grant worth $50000
- Chapter 1: find the factorial n of n!
- Summary of composition materials for 2020 high-frequency examination center of educational resources
猜你喜欢
2022-06-25 网工进阶(十一)IS-IS-三大表(邻居表、路由表、链路状态数据库表)、LSP、CSNP、PSNP、LSP的同步过程
BOC protected tryptophan zinc porphyrin (Zn · TAPP Trp BOC) / copper porphyrin (Cu · TAPP Trp BOC) / cobalt porphyrin (cobalt · TAPP Trp BOC) / iron porphyrin (Fe · TAPP Trp BOC) / Qiyue supply
kubernetes集群搭建efk日志收集平台
The earliest record
Day18 - basis of interface testing
FPGA learning notes: vivado 2019.1 project creation
原生表格-滚动-合并功能
Valentine's Day - make an exclusive digital collection for your lover
第一章: 舍罕王失算
02 -- QT OpenGL drawing triangle
随机推荐
第一章:喝汽水,阶梯电费计算,阶梯电费计算函数,个人所税,求解平方根不等式,简化求解平方根不等式,求解调和级数不等式,解不等式:d<1+1/2-1/3+1/4+1/5-1/6+..士1/n
Chapter 2: find the classical solution of the maximum Convention and the least common multiple of a and B, find the conventional solution of the maximum Convention and the least common multiple of a a
Sentinel source code analysis part II - sentinel dashboard console startup and configuration
[water quality prediction] water quality prediction based on MATLAB Fuzzy Neural Network [including Matlab source code 1923]
2022-06-30 網工進階(十四)路由策略-匹配工具【ACL、IP-Prefix List】、策略工具【Filter-Policy】
[wallpaper] (commercially available) 70 wallpaper HD free
NFT without IPFs and completely on the chain?
Thesis study - 7 Very Deep Convolutional Networks for Large-Scale Image Recognition (3/3)
BOC protected phenylalanine zinc porphyrin (Zn · TAPP Phe BOC) / iron porphyrin (Fe · TAPP Phe BOC) / nickel porphyrin (Ni · TAPP Phe BOC) / manganese porphyrin (Mn · TAPP Phe BOC) Qiyue Keke
FPGA learning notes: vivado 2019.1 project creation
2022-06-25 advanced network engineering (XI) IS-IS synchronization process of three tables (neighbor table, routing table, link state database table), LSP, cSNP, psnp, LSP
2022 Xinjiang latest road transportation safety officer simulation examination questions and answers
I didn't cancel
BOC protected tryptophan porphyrin compound (TAPP Trp BOC) Pink Solid 162.8mg supply - Qiyue supply
第一章:求奇因数代数和,求同吗小数和s(d, n),简化同码小数和s(d, n),拓广同码小数和s(d, n)
Day11 - my page, user information acquisition, modification and channel interface
The most valuable thing
Chapitre 1: le roi de shehan a mal calculé
Floating source code comment (38) parallel job processor
Counting from the East and counting from the West will stimulate 100 billion industries. Only storage manufacturers who dare to bite the "hard bone" will have more opportunities