Juniper SSG5(bgroupx介面詳解及刪除bgroupx自定義)
從console口登陸檢視介面,標紅部分預設從eth0/2-6都屬於Trust介面
ssg5-serial-> get interface
A - Active, I - Inactive, U -Up, D - Down, R - Ready
Interfaces in vsys Root:
Name IP Address Zone MAC VLAN State VSD
serial0/0 0.0.0.0/0 Null N/A - D -
eth0/0 0.0.0.0/0 Untrust b0a8.6e68.2bc0 - D -
eth0/1 0.0.0.0/0 DMZ b0a8.6e68.2bc5 - D -
bgroup0 192.168.1.1/24 Trust b0a8.6e68.2bcb - U -
eth0/2 N/A N/A N/A - D -
eth0/3 N/A N/A N/A - U -
eth0/4 N/A N/A N/A - D -
eth0/5 N/A N/A N/A - D -
eth0/6 N/A N/A N/A - D -
bgroup1 0.0.0.0/0 Null b0a8.6e68.2bcc - D -
bgroup2 0.0.0.0/0 Null b0a8.6e68.2bcd - D -
bgroup3 0.0.0.0/0 Null b0a8.6e68.2bce - D -
vlan1 0.0.0.0/0 VLAN b0a8.6e68.2bcf 1 D -
null 0.0.0.0/0 Null N/A - U 0
關於SSG5的介面(bgroupx相當於一個介面組,理解為vlan也可以,隨意;zone區段)
1、可以將一個或多個介面加入到bgroupx中,然後再將bgroupx加入到zone,最後給bgroupx設定IP地址(bgroupx下的所有介面都將屬於bgroupx的IP地址,相當於一個交換區域)
2、如果將介面加入到了bgroupx中那麼這個介面將不能配置IP地址等多種操作,你可以理解為這些介面變成了2層口;只要再次脫離bgroupx後,IP地址等多種操作又可以進行,你可以理解為這些介面變回了3層口。
3、如果物理介面處在某個zone下,那麼這個物理口將不能直接加入到bgroupx中,除非脫離當前zone。
將介面interface eth0/2 eht0/3加入到bgroup1中(SSG5不支援一次性新增多個埠)
ssg5-serial->set interface bgroup1 port eth0/2
ssg5-serial->set interface bgroup1 port eth0/3
刪除用unset (unset interface bgroup1 porteth0/3)
將bgroup1加入到trust中
ssg5-serial->set interface bgroup1 zone trust
刪除用unset (unset interface bgroup1 zonetrust)
新增一個zone
ssg5-serial->set zone name web
給bgroup1設定IP地址
要想給bgroup1設定IP地址,必須將bgroup1加入到一個zone中,否則將沒有設定IP地址的選項
ssg5-serial-> set interface bgroup1 zone web
設定bgroup1的IP地址
ssg5-serial-> set interface bgroup1 ip2.2.2.1/24
檢視剛才做的配置
ssg5-serial->get interface
Interfacesin vsys Root:
Name IP Address Zone MAC VLAN State VSD
serial0/0 0.0.0.0/0 Null N/A - D -
eth0/0 0.0.0.0/0 Untrust b0a8.6e68.2bc0 - D -
eth0/1 0.0.0.0/0 DMZ b0a8.6e68.2bc5 - D -
eth0/6 0.0.0.0/0 Null b0a8.6e68.2bca - D -
bgroup0 192.168.1.1/24 Trust b0a8.6e68.2bcb - D -
eth0/4 N/A N/A N/A - D -
eth0/5 N/A N/A N/A - D -
bgroup1 2.2.2.1/24 web b0a8.6e68.2bcc - U -
eth0/2 N/A N/A N/A - D -
eth0/3 N/A N/A N/A - U -
bgroup2 0.0.0.0/0 Null b0a8.6e68.2bcd - D -
bgroup3 0.0.0.0/0 Null b0a8.6e68.2bce - D -
vlan1 0.0.0.0/0 VLAN b0a8.6e68.2bcf 1 D -
null 0.0.0.0/0 Null N/A - U 0
檢視zone
ssg5-serial->get zon
------------------------------------------------------------------------
ID Name Type Attr VR Default-IF VSYS
0 Null Null Shared untrust-vr serial0/0 Root
1 Untrust Sec(L3) Sharedtrust-vr ethernet0/0 Root
2 Trust Sec(L3) trust-vr bgroup0 Root
3 DMZ Sec(L3) trust-vr ethernet0/1 Root
4 Self Func trust-vr self Root
5 MGT Func trust-vr null Root
6 HA Func trust-vr null Root
10 Global Sec(L3) trust-vr null Root
11 V1-Untrust Sec(L2) Sharedtrust-vr v1-untrust Root
12 V1-Trust Sec(L2) Sharedtrust-vr v1-trust Root
13 V1-DMZ Sec(L2) Sharedtrust-vr v1-dmz Root
14 VLAN Func Shared trust-vr vlan1 Root
15 V1-Null Sec(L2) Sharedtrust-vr l2v Root
16 Untrust-Tun Tun trust-vr hidden.1 Root
100 web Sec(L3) trust-vr bgroup1 Root
將SSG5的bgroup0的交換區域取消,全部介面改為3層口
SSG5預設介面規劃
ssg5-serial->get interface
Interfacesin vsys Root:
Name IP Address Zone MAC VLAN State VSD
serial0/0 0.0.0.0/0 Null N/A - D -
eth0/0 0.0.0.0/0 Untrust b0a8.6e68.2bc0 - D -
eth0/1 0.0.0.0/0 DMZ b0a8.6e68.2bc5 - D -
bgroup0 192.168.1.1/24 Trust b0a8.6e68.2bcb - U -
eth0/2 N/A N/A N/A - D -
eth0/3 N/A N/A N/A - U -
eth0/4 N/A N/A N/A - D -
eth0/5 N/A N/A N/A - D -
eth0/6 N/A N/A N/A - D -
bgroup1 0.0.0.0/0 Null b0a8.6e68.2bcc - D -
bgroup2 0.0.0.0/0 Null b0a8.6e68.2bcd - D -
bgroup3 0.0.0.0/0 Null b0a8.6e68.2bce - D -
vlan1 0.0.0.0/0 VLAN b0a8.6e68.2bcf 1 D -
null 0.0.0.0/0 Null N/A - U 0
SSG刪除bgroup0的預設
ssg5-serial->unset inter bgroup0 port ethernet0/2
ssg5-serial->unset inter bgroup0 port ethernet0/3
ssg5-serial->unset inter bgroup0 port ethernet0/4
ssg5-serial->unset inter bgroup0 port ethernet0/5
ssg5-serial->unset inter bgroup0 port ethernet0/6
ssg5-serial->unset inter bgroup0 ip
ssg5-serial->unset inter bgroup0 zone
ssg5-serial->get interface
A -Active, I - Inactive, U - Up, D - Down, R - Ready
Interfacesin vsys Root:
Name IP Address Zone MAC VLAN State VSD
serial0/0 0.0.0.0/0 Null N/A - D -
eth0/0 0.0.0.0/0 Untrust b0a8.6e68.2bc0 - D -
eth0/1 0.0.0.0/0 DMZ b0a8.6e68.2bc5 - D -
eth0/2 0.0.0.0/0 Null b0a8.6e68.2bc6 - D -
eth0/3 0.0.0.0/0 Null b0a8.6e68.2bc7 - U -
eth0/4 0.0.0.0/0 Null b0a8.6e68.2bc8 - D -
eth0/5 0.0.0.0/0 Null b0a8.6e68.2bc9 - D -
eth0/6 0.0.0.0/0 Null b0a8.6e68.2bca - D -
bgroup0 0.0.0.0/0 Null b0a8.6e68.2bcb - D -
bgroup1 0.0.0.0/0 Null b0a8.6e68.2bcc - D -
bgroup2 0.0.0.0/0 Null b0a8.6e68.2bcd - D -
bgroup3 0.0.0.0/0 Null b0a8.6e68.2bce - D -
vlan1 0.0.0.0/0 VLAN b0a8.6e68.2bcf 1 D -
null 0.0.0.0/0 Null N/A - U 0
ssg5-serial->
-----------------------------------------------------------------------------------------------------------------------------------------------
建立zone、設定IP地址及管理介面
建立zone
ssg5-serial->set interface eth0/0 zone dmz
ssg5-serial->set interface eth0/1 zone untrust
ssg5-serial->set interface eth0/2 zone trust
設定IP地址
ssg5-serial->set interface eth0/2 ip 192.168.1.1/24
設定管理介面
ssg5-serial->set interface eth0/2 manage web
注意:有些情況下SSG預設是將所有管理全部enable,我需要先執行unset interface eth0/2 manage,將所有管理關閉,在單獨放行需要的管理,如web
修改之後的SSG5
ssg5-serial->get interface
Interfacesin vsys Root:
Name IP Address Zone MAC VLAN State VSD
serial0/0 0.0.0.0/0 Null N/A - D -
eth0/0 0.0.0.0/0 DMZ b0a8.6e68.2bc0 - D -
eth0/1 0.0.0.0/0 Untrust b0a8.6e68.2bc5 - D -
eth0/2 192.168.1.1/24 Trust b0a8.6e68.2bc6 - U -
eth0/3 0.0.0.0/0 Null b0a8.6e68.2bc7 - D -
eth0/4 0.0.0.0/0 Null b0a8.6e68.2bc8 - D -
eth0/5 0.0.0.0/0 Null b0a8.6e68.2bc9 - D -
eth0/6 0.0.0.0/0 Null b0a8.6e68.2bca - D -
bgroup0 0.0.0.0/0 Null b0a8.6e68.2bcb - D -
bgroup1 0.0.0.0/0 Null b0a8.6e68.2bcc - D -
bgroup2 0.0.0.0/0 Null b0a8.6e68.2bcd - D -
bgroup3 0.0.0.0/0 Null b0a8.6e68.2bce - D -
vlan1 0.0.0.0/0 VLAN b0a8.6e68.2bcf 1 D -
null 0.0.0.0/0 Null N/A - U 0
修改介面模式(只有兩種,route/nat)
ssg5-serial->set interface eth0/2 route
ssg5-serial->set interface eth0/2 nat