《防火墙与入侵检测技术》
一、实验目的
1.掌握防火墙的配置过程 2.掌握NAT的应用特点 3.掌握NAT的工作过程 4.掌握域内安全策略 5.掌握策略匹配机制
二、拓扑设计
data:image/s3,"s3://crabby-images/18ca1/18ca167c274cd9d92b7033ec3f515b5a343a1ece" alt="在这里插入图片描述"
三、实验设备
1.六台终端设备 2.两台交换机(型号:S5700、S3700) 3.一台防火墙(型号:USG5500)
四、实验要求
1.PC2不能访问server1 2.除了PC2无法server1,192.168.0.0/24网段可以访问server1 3.建立域内安全策略,使192.168.0.0/24网段无法与192.168.1.0/24网段进行通信 4.Untrust区计算机可以访问dmz区服务器 5.Trust区192.168.0.0/24网段可以访问的dmz区服务器,但192.168.1.0/24网段不能访问dmz区服务器 6.PC1访问PC3时进行地址转换,并分析转换过程
五、实验步骤及结果分析
一、配置pc、Server和Client data:image/s3,"s3://crabby-images/8d374/8d37467c3e0b9a9974afeacc5a10dae5c21629da" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/483f0/483f060ecb43e2162f37d164541b077bd4f20efc" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/0b9a0/0b9a047b3d3bb647bd61a456253ac8e408c3c5e2" alt="在这里插入图片描述"
data:image/s3,"s3://crabby-images/1841e/1841e6c66648b374ec1c706a4e2a36e409dc99ae" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/57b50/57b5040b6ded7dc538c98cae6a7230e55b952d4b" alt="在这里插入图片描述"
data:image/s3,"s3://crabby-images/d6232/d623245f901229af69ac3fae97878f8fa15ae2a3" alt="在这里插入图片描述"
配置防火墙端口 [SRG]interface GigabitEthernet 0/0/0 [SRG-GigabitEthernet0/0/0]ip address 192.168.0.254 24 [SRG-GigabitEthernet0/0/0]q [SRG]interface GigabitEthernet 0/0/1 [SRG-GigabitEthernet0/0/1]ip address 172.16.0.254 24 [SRG-GigabitEthernet0/0/1]q [SRG]interface GigabitEthernet 0/0/2 [SRG-GigabitEthernet0/0/2]ip address 192.168.1.254 24 [SRG-GigabitEthernet0/0/2]q [SRG]interface GigabitEthernet 0/0/3 [SRG-GigabitEthernet0/0/3]ip address 192.168.100.254 24 data:image/s3,"s3://crabby-images/ea637/ea6372e6edfa5db256cf437965d8b4d9aa7293be" alt="在这里插入图片描述"
二、 1、PC2不能访问server1 2、除了PC2无法server1,192.168.0.0/24网段可以访问server1
先把防火墙的各个端口加进对应的区域,G0/0/0和G0/0/2是在trust区的,G0/0/1是在untrust区的,G0/0/3是在dmz区内的
[SRG]firewall zone trust [SRG-zone-trust]add interface GigabitEthernet 0/0/0 [SRG-zone-trust]add interface GigabitEthernet 0/0/2 [SRG-zone-trust]q [SRG]firewall zone untrust [SRG-zone-untrust]add interface GigabitEthernet 0/0/1 [SRG-zone-untrust]q [SRG]firewall zone dmz [SRG-zone-dmz]add interface GigabitEthernet 0/0/3 data:image/s3,"s3://crabby-images/17abc/17abc4c064367aa94c142aa29e0264f6dc37d38e" alt="在这里插入图片描述"
配置安全策略,。先配置pc2不能访问Server1.拒绝pc2的ip地址访问,再放通192.168.0.0这个网段 [SRG]policy interzone trust untrust outbound [SRG-policy-interzone-trust-untrust-outbound]policy 1 [SRG-policy-interzone-trust-untrust-outbound-1]policy source 192.168.0.100 0 [SRG-policy-interzone-trust-untrust-outbound-1]action deny [SRG-policy-interzone-trust-untrust-outbound-1]q [SRG-policy-interzone-trust-untrust-outbound]policy 3 [SRG-policy-interzone-trust-untrust-outbound-3]policy source 192.168.0.0 mask 25 5.255.255.0 [SRG-policy-interzone-trust-untrust-outbound-3]action permit data:image/s3,"s3://crabby-images/138a9/138a93bfbc955d98afaa7331c9057c032a90760e" alt="在这里插入图片描述"
Ping命令验证实验结果 (1)pc2不能访问server1 data:image/s3,"s3://crabby-images/f55d6/f55d68351e8624a8eec65f7c7e5929c5f20b864a" alt="在这里插入图片描述"
(2)192.168.0.0/24网段可以访问server1 data:image/s3,"s3://crabby-images/e49a1/e49a1dc2c2c0939304fa947f785db384642b3bdb" alt="在这里插入图片描述"
三、 3、建立域内安全策略,使192.168.0.0/24网段无法与192.168.1.0/24网段进行通信 建立域内安全策略,使192.168.0.0/24网段不可以ping通192.168.1.0/24网段。 因为同一个区域内的是可以ping通的,要让ping不通,在trust区内建立安全策略,禁止192.168.0.0网段 [SRG]policy zone trust [SRG-policy-zone-trust]policy 4 [SRG-policy-zone-trust-4]action deny [SRG-policy-zone-trust-4]policy source 192.168.0.0 mask 255.255.255.0 data:image/s3,"s3://crabby-images/cfaf8/cfaf8e9e6ac88ec4e6c67888578fb82c4d2fdaad" alt="在这里插入图片描述"
实验结果验证: data:image/s3,"s3://crabby-images/2d080/2d080d077c5939c279abe357e5aa6c1be2d54cf8" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/1c3a2/1c3a2455e1f88eb28ff4ed27d62db1466591b1d5" alt="在这里插入图片描述"
四、Untrust区计算机可以访问dmz区服务器 开放untrust区到dmz区的通信 [SRG]firewall packet-filter default permit interzone dmz untrust direction inbound data:image/s3,"s3://crabby-images/b72f2/b72f24fb11bbfa2b1360d5c0cb84c9e1882e0f29" alt="在这里插入图片描述"
实验结果验证:
data:image/s3,"s3://crabby-images/3dfc0/3dfc0e97e8df6b247a368fb824f87a92c6586f64" alt="在这里插入图片描述" data:image/s3,"s3://crabby-images/d8955/d8955bf6b86043e403ff9d55852ee4aecf076a2a" alt="在这里插入图片描述"
五、 5、Trust区192.168.0.0/24网段可以访问的dmz区服务器,但192.168.1.0/24网段不能访问dmz区服务器 trust区192.168.0.0/24网段可以访问dmz区服务器,而192.168.1.0/24网段不能访问 先把trust区到dmz区放通,再配置策略 [SRG]firewall packet-filter default permit interzone trust dmz direction outbound [SRG]policy interzone trust dmz outbound [SRG-policy-interzone-trust-dmz-outbound]policy 6 [SRG-policy-interzone-trust-dmz-outbound-6]action permit [SRG-policy-interzone-trust-dmz-outbound-6]policy source 192.168.0.0 mask 255.255.255.0 [SRG-policy-interzone-trust-dmz-outbound-6]q [SRG-policy-interzone-trust-dmz-outbound]policy 7 [SRG-policy-interzone-trust-dmz-outbound-7]action deny [SRG-policy-interzone-trust-dmz-outbound-7]policy source 192.168.1.0 mask 255.255.255.0 data:image/s3,"s3://crabby-images/c6852/c68523b8e09efc53ff3b6e0ed165ba6c6794873f" alt="在这里插入图片描述"
实验结果验证: trust区192.168.0.0/24网段可以访问dmz区服务器 data:image/s3,"s3://crabby-images/7fd6d/7fd6d228e6fa26d1ac8d285ff5b79c4438cd101b" alt="在这里插入图片描述"
trust区192.168.1.0/24网段不可以访问dmz区服务器
data:image/s3,"s3://crabby-images/0cadb/0cadb62211659ff3f01804ef3bbeef0b31401a8d" alt="在这里插入图片描述"
六、PC1访问PC3时进行地址转换,并分析转换过程 [SRG]nat address-group 1 2.2.2.2 2.2.2.5 [SRG]nat-policy interzone trust untrust oubound [SRG-nat-policy-interzone-trust-untrust-outbound]policy 7 [SRG-nat-policy-interzone-trust-untrust-outbound-7]action source-nat [SRG-nat-policy-interzone-trust-untrust-outbound-7]policy destination 172.16.0.3 0.0.0.255 [SRG-nat-policy-interzone-trust-untrust-outbound-7]address-group 1 [SRG-nat-policy-interzone-trust-untrust-outbound-7]policy source 192.168.0.2 0.0.0.255 data:image/s3,"s3://crabby-images/87b96/87b96486ff622b9e23c179035edeb825029888c8" alt="在这里插入图片描述"
查看nat转换情况: data:image/s3,"s3://crabby-images/1acd0/1acd0377ae956d963b2bb15ae2cdb84b6b84ef9c" alt="在这里插入图片描述"
|