- 哪里可以下载说明书
我公司买了一个Quidway AR18-20路由器,说明书找不到了,要进行新的路由器配置该怎么办,有可以下载的说明书吗?
-
提问者: 游客 | 提问时间: 2007-05-13 14:34:32 | 回复(1)
我来回答
-
- 1.注:配置中<>为待命状态,[ ]为配置状态。
sys
[Quidway]int eth 1/0 //对内网进行配置
[Quidway-Ethernet1/0]ip add 192.168.1.1 24 //添加内网IP
[Quidway-Ethernet1/0]tcp mss 1024
[Quidway-Ethernet1/0]int eth 2/0 //对公网进行配置
[Quidway-Ethernet2/0]ip add (IP)xx.xx.xx.xx (掩码)xx.xx.xx.xx //添加公网IP及掩码
[Quidway-Ethernet2/0]tcp mss 1024
[Quidway-Ethernet2/0]qu
[Quidway]acl num 2000 //NAT 转换时ACL
[Quidway-acl-basic-2000]rule per sou 192.168.1.0 0.0.0.255
[Quidway-acl-basic-2000]rule deny sou any
[Quidway-acl-basic-2000]qu
[Quidway]acl num 3000 //防病毒ACL
下面是依次添加防火墙:会很累,建议复制吧:)
[Quidway-acl-adv-3000]rule deny udp sou any dest any destination-port eq tftp
[Quidway-acl-adv-3000]rule deny tcp sou any dest any destination-port eq 135
[Quidway-acl-adv-3000]rule deny udp sou any dest any destination-port eq 135
[Quidway-acl-adv-3000]rule deny udp sou any dest any destination-port eq netbios-ns
[Quidway-acl-adv-3000]rule deny udp sou any dest any destination-port eq netbios-dgm
[Quidway-acl-adv-3000]rule deny tcp sou any dest any destination-port eq 139
[Quidway-acl-adv-3000]rule deny udp sou any dest any destination-port eq netbios-ssn
[Quidway-acl-adv-3000]rule deny tcp sou any dest any destination-port eq 445
[Quidway-acl-adv-3000]rule deny udp sou any dest any destination-port eq 445
[Quidway-acl-adv-3000]rule deny tcp sou any dest any destination-port eq 539
[Quidway-acl-adv-3000]rule deny udp sou any dest any destination-port eq 539
[Quidway-acl-adv-3000]rule deny udp sou any dest any destination-port eq 593
[Quidway-acl-adv-3000]rule deny tcp sou any dest any destination-port eq 593
[Quidway-acl-adv-3000]rule deny udp sou any dest any destination-port eq 1434
[Quidway-acl-adv-3000]rule deny udp sou any dest any destination-port eq 1433
[Quidway-acl-adv-3000]rule deny tcp sou any dest any destination-port eq 4444
[Quidway-acl-adv-3000]rule deny tcp sou any dest any destination-port eq 9996
[Quidway-acl-adv-3000]rule deny tcp sou any dest any destination-port eq 5554
[Quidway-acl-adv-3000]rule deny udp sou any dest any destination-port eq 9996
[Quidway-acl-adv-3000]rule deny udp sou any dest any destination-port eq 5554
[Quidway-acl-adv-3000]rule deny tcp sou any dest any destination-port eq 137
[Quidway-acl-adv-3000]rule deny tcp sou any dest any destination-port eq 138
[Quidway-acl-adv-3000]rule deny tcp sou any dest any destination-port eq 1025
[Quidway-acl-adv-3000]rule deny udp sou any dest any destination-port eq 1025
[Quidway-acl-adv-3000]rule deny tcp sou any dest any destination-port eq 9995
[Quidway-acl-adv-3000]rule deny udp sou any dest any destination-port eq 9995
[Quidway-acl-adv-3000]rule deny tcp sou any dest any destination-port eq 1068
[Quidway-acl-adv-3000]rule deny udp sou any dest any destination-port eq 1068
[Quidway-acl-adv-3000]rule deny tcp sou any dest any destination-port eq 1023
[Quidway-acl-adv-3000]rule deny udp sou any dest any destination-port eq 1023
[Quidway-acl-adv-3000]qu
[Quidway]int eth 1/0
[Quidway-Ethernet1/0]fi pack 3000 in
[Quidway-Ethernet1/0]int eth 2/0
[Quidway-Ethernet2/0]nat out 2000
[Quidway-Ethernet1/0]qu
[Quidway]ip rou 0.0.0.0 0.0.0.0 192.168.1.1 //缺省路由
下面是添加路由用户及密码,其中添加了telnet访问,以便日后通过网络控制路由:
[Quidway]local-user admin password simple 123456
[Quidway]local-user admin service-type telnet
[Quidway]local-user admin level 3 //用户等级
[Quidway]qu
sa
The configuration will be written to the device.
Are you sure?[Y/N]y
Please input the file name(*.cfg)[flash:/config.cfg]:
Now saving current configuration to the device.
Saving configuration flash:/config.cfg. Please wait...
至此,基本配置完毕!
如果用户想增加ssh登陆的话。可以在下面状态配置:
[Quidway]rsa local-key-pair create //生成本地密匙对
[Quidway]user-interface vty 0 4 //进入vty视图
[Quidway-ui-vty0-4]authentication-modee scheme //设置scheme认证
[Quidway-ui-vty0-4]qu
[Quidway]local-user admin
[Quidway-user-admin]service-type ssh //设置服务类型为ssh
[Quidway-user-admin]level 3
[Quidway-user-admin]qu
[Quidway]ssh user admin authentication-type pssword //设置SSH用户验证方式为password
[Quidway]domain system
[Quidway-isp-system]scheme local //使用本地认证方案
[Quidway-isp-system]qu
[Quidway]qu
sa
如果用户想映射某台IP为192.168.1.123的A机为80端口,可以使用下列方法:
[quidway-ethernet2/0]nat server protocol global (公网IP) 80 inside 192.168.1.123 80
即可!
如果要删除某条配置,使用undo命令,后面跟配置就OK。
- 回答者: bjcxht 2007-05-16
- 1.注:配置中<>为待命状态,[ ]为配置状态。