Title: Agenda(2??)
1???????? ????(2??)
2Agenda(2??)
3NetScreen(L2???)
NetScreen????????????????????
L2???(switch)????????????? ?????????????????????
???????? ?????????????????????? ??????????????
??(CLI)??????? web??????????????????????
CLI???????????????
4NetScreen(L2???)
??????(L2???) - 1
1. unset int trust ip (trust?ip????????)2.
unset int trust zone (trust?zone????????)3.
unset int untrust ip (untrust?ip????????)4.
unset int untrust zone (untrust?zone????????) 5.
set interface trust zone V1-Trust6. set
interface untrust zone V1-Untrust
???15?????????L2??????? ? ? L2??zone???
?????????????????? zone??????? Changed to
pure l2 mode ??? ????OK???
5NetScreen(L2???)
??????(L2???) - 2
Vlan1???IP???????
???????????
7. set int vlan1 ip xxx.xxx.xxx.xxx
xxx.xxx.xxx.xxx ? manage-ip???
Vlan?IP???????????????????????? -WEB??????
-ping???????? etc.
6NetScreen(L2???)
??????(L2???) - 3
?????IP???????
8. set admin manager-ip xxx.xxx.xxx.xxx ?
????????????????????????web??
?????????????????????????IP??????
????????????????????????
7NetScreen(????)
??????(L2???) - 4
LAN?????Trust??????????
Web???????????????????????????? ???????? set int
vlan1 ip xxx.xxx.xxx.xxx
8NetScreen(????)
??????(L2???) - 5
xxx.xxx.xxx.xxx (???????IP????)
????????" netscreen "
9?????????L2??
??????(L2???) - 6
? NetworkgtInterfaces ???
? Type?Layer2???????????
10NTP??(??????)
? ConfigurationgtDate/Time???
???9
???????
NTP????????????
11DNS??
? NetworkgtDNSgtHost ???
? FW????????
? ?????DNS??????
? ?????DNS??????
? ???????????? (Apply??????????????)
12DHCP???
? NetworkgtDHCP ???
? ??????Server? ??????????
? Edit?????
13DHCP???
DHCP?????
? DHCP??????
? ???????DHCP????????????
? ?Apply?????????
14DHCP???
DHCP?????
? NetworkgtDHCP ???
? DHCP???????????????????
15DHCP???
DHCP?????
?Edit?????????
16DHCP???
DHCP?????
? ???????IP??????????? ?????????? ??????????
? ?OK?????????
17???????
ServerA
10.0.0.200
V1-Untrust???
?To?
?From?
?????????????From? ???To??????? ??????????????????
????????????????????
?From?
?To?
V1-Trust???
UserA
10.0.0.100
V1-Untrust, V1-Trust??????????
18???????
? Policies ???
? ?????(From) ???? ????V1-Trust????
? ?????(To) ???? ????V1-Untrust????
? ?New?????????
???????????No entry available????????
19???????
? ????????????????????
? ???????????????????
? ??(Permit)??????(Block)???????
? ???????
? ???????????????
? ?OK?????????
20???????
??????????? V1-Trust?V1-Untrust,
V1-Untrust?V1-Trust ?????????????
From??To?ZONE??????????????
?????????????
21???????
?????? (HTTP,ftp,ping)etc ???????????
??????????permit,???????deny
??????
??
?????
???
??
??
??
??
??
???????????Any?Any deny ????Block????????????? ?
?????deny???? ???Permit????????????????????
22????(L2?????????)
ServerA
10.0.0.200
V1-Untrust???
Ping????
Netscreen
Manage-ip 10.0.0.1
V1-Trust???
UserA
10.0.0.100
V1-Untrust, V1-Trust??????????
23????(????)
V1-Untrust??? 10.0.0.0/24
V1-Trust??? 10.0.0.0/24
??????
ServerA
UserA
ping?????
ping???????
V1-Untrust, V1-Trust??????????
?????????????????????????