Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- firewall {
- all-ping enable
- broadcast-ping enable
- config-trap disable
- ipv6-receive-redirects disable
- ipv6-src-route disable
- ip-src-route enable
- log-martians enable
- name lan1-lan2 {
- rule 1 {
- action accept
- description LAN1-LAN2
- protocol all
- state {
- established enable
- new enable
- related enable
- }
- }
- }
- receive-redirects enable
- send-redirects enable
- source-validation disable
- syn-cookies enable
- twa-hazards-protection disable
- }
- interfaces {
- bridge br1 {
- address xxx.xxx.0.1/24
- aging 300
- description "Private switch"
- hello-time 2
- ip {
- enable-arp-accept
- ospf {
- network point-to-multipoint
- }
- }
- max-age 20
- priority 0
- stp false
- }
- bridge br2 {
- address xxx.xxx.101.1/24
- aging 300
- description "private switch"
- hello-time 2
- ip {
- enable-arp-accept
- ospf {
- network point-to-multipoint
- }
- }
- max-age 20
- priority 0
- stp false
- }
- bridge br3 {
- address xxx.xxx.2.1/24
- description "private switch"
- ip {
- enable-arp-accept
- ospf {
- network point-to-multipoint
- }
- }
- }
- bridge br4 {
- address xxx.xxx.3.1/24
- description "private switch"
- ip {
- enable-arp-accept
- ospf {
- network point-to-multipoint
- }
- }
- }
- bridge br5 {
- address xxx.xxx.4.1/24
- description "private switch"
- ip {
- enable-arp-accept
- ospf {
- network point-to-multipoint
- }
- }
- }
- ethernet eth0 {
- bridge-group {
- bridge br2
- }
- description private
- duplex auto
- hw-id XX:XX:XX:f8:3f:11
- smp-affinity auto
- speed auto
- }
- ethernet eth1 {
- bridge-group {
- bridge br1
- }
- description private
- duplex auto
- hw-id XX:XX:XX:f8:3f:12
- smp-affinity auto
- speed auto
- vif 1 {
- bridge-group {
- bridge br2
- }
- description "private VLAN 1"
- }
- vif 1002 {
- bridge-group {
- bridge br3
- }
- description "private VLAN 1002"
- }
- vif 1003 {
- bridge-group {
- bridge br4
- }
- description "private VLAN 1003"
- }
- vif 1004 {
- bridge-group {
- bridge br5
- }
- description "private VLAN 1004"
- }
- }
- ethernet eth2 {
- bridge-group {
- bridge br2
- }
- description private
- duplex auto
- hw-id XX:XX:XX:f8:3f:13
- smp-affinity auto
- speed auto
- }
- ethernet eth3 {
- bridge-group {
- bridge br2
- }
- description private
- duplex auto
- hw-id XX:XX:XX:f8:3f:14
- smp-affinity auto
- speed auto
- }
- ethernet eth4 {
- bridge-group {
- bridge br2
- }
- description private
- duplex auto
- hw-id XX:XX:XX:f8:3f:15
- smp-affinity auto
- speed auto
- }
- ethernet eth5 {
- description public
- duplex auto
- hw-id XX:XX:XX:f8:3f:16
- pppoe 0 {
- default-route auto
- mtu 1492
- name-server auto
- password xxxxxx
- user-id xxxxxx
- }
- smp-affinity auto
- speed auto
- }
- loopback lo {
- address xxx.xxx.0.1/8
- address ::1/128
- description local
- }
- }
- nat {
- source {
- rule 100 {
- description "TO PUBLIC"
- outbound-interface pppoe0
- source {
- address xxx.xxx.0.0/16
- }
- translation {
- address masquerade
- }
- }
- }
- }
- policy {
- route-map CONNECT {
- rule 10 {
- action permit
- match {
- interface lo
- }
- }
- }
- }
- protocols {
- ospf {
- area xxx.xxx.0.0 {
- network xxx.xxx.0.0/16
- }
- area xxx.xxx.0.1 {
- network xxx.xxx.0.0/24
- }
- area xxx.xxx.0.2 {
- network xxx.xxx.101.0/24
- }
- area xxx.xxx.0.3 {
- network xxx.xxx.2.0/24
- }
- area xxx.xxx.0.4 {
- network xxx.xxx.3.0/24
- }
- area xxx.xxx.0.5 {
- network xxx.xxx.4.0/24
- }
- default-information {
- originate {
- always
- metric 10
- metric-type 2
- }
- }
- log-adjacency-changes {
- }
- parameters {
- router-id xxx.xxx.0.0
- }
- redistribute {
- connected {
- metric-type 2
- route-map CONNECT
- }
- }
- }
- }
- service {
- dhcp-server {
- shared-network-name xxxxxx {
- subnet xxx.xxx.101.0/24 {
- default-router xxx.xxx.101.1
- dns-server xxx.xxx.101.1
- lease 86400
- range 0 {
- start xxx.xxx.101.2
- stop xxx.xxx.101.254
- }
- }
- }
- }
- dns {
- forwarding {
- cache-size 512
- listen-on br1
- listen-on br2
- name-server xxx.xxx.114.114
- name-server xxx.xxx.8.8
- }
- }
- snmp {
- community v3 {
- authorization ro
- }
- listen-address xxx.xxx.0.0 {
- port 161
- }
- }
- ssh {
- port 22
- }
- }
- system {
- config-management {
- commit-revisions 20
- }
- console {
- device ttyS0 {
- speed 9600
- }
- }
- host-name xxxxxx
- ip {
- arp {
- table-size 16384
- }
- }
- login {
- user xxxxxx {
- authentication {
- encrypted-password xxxxxx
- plaintext-password xxxxxx
- }
- level admin
- }
- }
- ntp {
- server xxxxx.tld {
- }
- server xxxxx.tld {
- }
- server xxxxx.tld {
- }
- }
- syslog {
- global {
- facility all {
- level notice
- }
- facility protocols {
- level debug
- }
- }
- }
- time-zone Asia/Shanghai
- }
- vpn {
- }
- zone-policy {
- zone lan1 {
- from lan2 {
- firewall {
- name lan1-lan2
- }
- }
- interface br1
- }
- zone lan2 {
- from lan1 {
- firewall {
- name lan1-lan2
- }
- }
- interface br2
- }
- zone lan3 {
- interface br3
- }
- zone lan4 {
- interface br4
- }
- zone lan5 {
- interface br5
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement