-
UID:17777
-
- 注册时间2007-05-02
- 最后登录2025-05-15
- 在线时间18654小时
-
- 发帖788459
- 搜Ta的帖子
- 精华0
- 飞翔币211655
- 威望215717
- 飞扬币2627175
- 信誉值8
-
访问TA的空间加好友用道具
- 发帖
- 788459
- 飞翔币
- 211655
- 威望
- 215717
- 飞扬币
- 2627175
- 信誉值
- 8
|
【TL-FW6300】防火墙配置指南——三层路由网关实例设置
网络场景某公司使用<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">TL-FW6300搭建网络,防火墙连接互联网,并划分多个网段内部使用,网络拓扑结构如下图所示。需求分析安全需求n<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 需求<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">1:访客网络可以访问互联网,但是不能访问内部其他网络;n<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 需求<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">2:销售部可以访问内部服务器网络以及互联网,但是禁止访问常见的游戏、视频、炒股类网站和应用;n<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 需求<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">3:研发部、财务部、行政部可以访问内部服务器网络,但是不能访问互联网,仅允许访问公司外部官方网站<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">www.test.com;n<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 需求<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">4:出差员工可以通过互联网访问内网的<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">8080端口的<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">WEB服务器;n<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 需求<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">5:内部各个部门以及访客区域之间禁止互相访问;n<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 需求<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">6:管理接口仅用于管理防火墙自身。审计需求n<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 需求<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">1:对所有流经防火墙的数据进行审计,并记录到审计日志;n<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 需求<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">2:将防火墙的审计日志、系统日志、操作日志、流量日志、策略命中日志全部上传至安装了<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">TP-LINK安全审计系统的审计服务器。设置步骤1.<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 配置接口参数。点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“网络<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“接口设置<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,如下图所示。(<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">1)设置<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">GE1连接互联网本例中以设置静态<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP联网方式为例。按照运营商提供的联网参数进行填写即可。(<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">2)设置<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">GE2连接服务器区服务器区域网段是<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">172.16.0.0/24,配置如下图所示。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 连接方式:设置接口<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址的配置方式,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“静态<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> <span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址:设置接口的<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址,本例中为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“172.16.0.1”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 子网掩码:设置接口的子网掩码,本例中为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“255.255.255.0”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 网关地址:设置接口的网关地址,本例中不填。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 上行带宽:设置接口的上行带宽值,本例中保持默认。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 下行带宽:设置接口的下行带宽值,本例中保持默认。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> <span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">MTU:设置接口的<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">MTU值,本例中保持默认。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 首选<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">DNS服务器:设置接口的首选<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">DNS服务器<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址,本例中保持默认,不填写。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 备用<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">DNS服务器:设置接口的备用<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">DNS服务器<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址,本例中保持默认,不填写。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> <span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">MAC地址:设置接口的<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">MAC地址,本例中保持默认。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 备注:添加备注,方便后期维护,本例中为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“服务器<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">1.<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 设置完毕点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“确定<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,如下图所示。(<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">3)设置<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">GE3—GE7连接到其他内部各个区域的接口配置方法与服务器区类似,如下图所示。接口参数设置完毕。2.<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 设置NAPT配置各个网段通过<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">GE1进行<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">NAT联网。如下图所示。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 出接口:选择连接宽带的接口,本例中为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“GE1”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 源地址范围:设置为内部的网段,本例中为了简化设置,网段归纳为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“172.16.0.0/16”。3.<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 设置DHCP服务器为内网设备分配<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址。如下图所示。为每个网段添加一个<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">DHCP服务器,简化客户端配置。4.<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 设置安全区域为每个接口定义所属的安全区域。打开<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“网络<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“安全区域<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”菜单,如下图所示。将<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">GE3-GE7以及MGMT添加到<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">trust安全区域,点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">trust区域的编辑图标,如下图所示。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 备注:添加备注,本例中为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“内网<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 接口:选择属于<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">trust安全区域的接口,本例中包括<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“GE3-GE7以及MGMT”。点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“确定<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,添加完成,如下图所示。 相同设置方法将<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">GE1添加到<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">untrust安全区域,将<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">GE2添加到<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">dmz安全区域,添加完成,如下图所示。5.<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 设置对象参数<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">(1)<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 地址添加各个区域的<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址段。打开<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“对象<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“地址<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“地址<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”页面,点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“新增<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,如下图所示。 以服务器区<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址为例:l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 地址名称:自定义,本例中为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Servers”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> <span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP类型:本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP/Mask,设置<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址段<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“172.16.0.0/24”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 备注:添加备注<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“服务器区<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”按照上述方式依次添加防火墙内部各个区域的地址段,添加完毕如下图所示。添加地址组,打开<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“对象<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“地址<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“地址组<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”页面,点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“新增<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,如下图所示。 l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 组名称:自定义,本例中为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Servers”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 地址名称:选择已经定义的地址名称,本例中选择服务器地址段<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Servers”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 备注:添加备注方便后期维护,本例中为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“服务器<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址段<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。点击确定添加成功,如下图所示。按照此方式添加其他地址组,包括访客、销售部、研发部、财务部和行政部的地址组。另外单独添加一个包含研发部、财务部以及行政部的内网部门<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">Internal。添加完毕如下如所示。<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">(2)<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 时间段本例中无特定时间限制,所以使用默认的所有时间条目<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Any”即可,如下图所示。<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">(3)<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 服务设置外网可以访问的内部<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">WEB服务器服务条目,首先新增服务,打开<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“对象<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“服务<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“服务<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“新增<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,如下图所示。 l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 服务名称:自定义,本例为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“WEB_Server”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 协议类型:选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“TCP”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 源端口范围:本例中任意端口,即<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“0-65535”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 目的端口范围:本例中为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">8080,即<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“8080-8080”。<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">.l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 备注:自定义,本例中为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“内部<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">WEB服务器<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“确定<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,添加完毕。如下图所示。 接下来新增服务组,打开<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“对象<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“服务<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“服务组<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“新增<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,如下图所示。 l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 组名称:自定义,本例中为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“WEB_Server”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 服务类型:选择已定义的服务名称,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“WEB_Server”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 备注:添加备注,方便后期维护,本例中为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“内部<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">WEB服务器<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“确定<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,添加完成,如下图所示。<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">(4)<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 网站设置内部网络可以访问的公司官网网址,打开<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“对象<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“网站<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“网站组<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“新增<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,如下图所示。 l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 组名称:自定义,本例为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“公司官网<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 组成员:设置公司官网的网址,本例为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“www.test.com”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 备注:添加备注,方便后期维护,本例为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“公司官方网站<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“确定<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,新建完成,如下图所示。 <span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">(5)<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 应用定义销售部禁止访问的应用,打开<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“对象<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“应用<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“应用组<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“新增<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,如下图所示。 l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 名称:设置应用组名称,本例为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“entertainment”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 软件:选择需要控制的软件,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“游戏、视频、炒股<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”软件。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 备注:添加备注方便后期维护,本例中为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“游戏、视频、炒股<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“确定<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,添加完毕。如下图所示。<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">(6)<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 安全配置文件设置内网设备允许访问的公司官方网站的<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">URL过滤条目。打开<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“对象<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“安全配置文件<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“URL过滤<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“新增<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,如下图所示。 l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 名称:设置<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">URL过滤条目的名称,本例为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“official_WEB”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 策略类型:本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“仅允许访问下列的<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">URL”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 过滤方式:本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“网站分组<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 网站分组:选择已经添加的网站分组,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“公司官网<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 备注:添加备注,便于后期维护,本例中设置<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“允许访问公司官网<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“确定<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,添加完成,如下图所示。经过以上设置,设置安全策略所需的对象已经准备完毕。接下来进行安全策略的配置。6.<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 设置安全策略打开<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“策略<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“安全策略<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”页面,如下图所示。防火墙出厂默认已经存在一条禁止所有的安全策略。所以接下来需要根据之前定义的需求将需要允许的内容一一添加上去,分别是:n<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 需求<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">1:访客网络可以访问互联网,但是不能访问内部其他网络;n<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 需求<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">2:销售部可以访问内部服务器网络以及互联网,但是禁止访问常见的游戏、视频、炒股类网站和应用;n<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 需求<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">3:研发部、财务部、行政部可以访问内部服务器网络,但是不能访问互联网,仅允许访问公司外部官方网站<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">www.test.com;n<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 需求<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">4:出差员工可以通过互联网访问内网的<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">8080端口的<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">WEB服务器;n<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 需求<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">5:)内部各个部门以及访客区域之间禁止互相访问;n<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 需求<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">6:管理接口仅用于管理防火墙自身。<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">(1)<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 设置第<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">1条需求,点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“新增<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,如下图所示。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 规则名称:自定义,本例为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“GUEST_Internet”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 描述:自定义,本例为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“访客上网<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 源安全区域:选择访客网络所在区域,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“trust”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 目的安全区域:选择互联网所在区域,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“untrust”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 源地址:选择访客网络<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址范围,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“GUEST”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 目的地址:选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">Internet网络<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址范围,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Any”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 服务组:选择服务组,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Any”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 应用组:选择应用组,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Any”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 时间段:选择时间段,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Any”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 动作:选择命中规则后的处理动作,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“允许<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 内容安全:选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">URL过滤和文件过滤配置文件,本例中留空,不选择。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 记录策略命中日志:本例中不启用。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 状态:选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“启用<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 添加到指定位置(第几条):本例中无需设置。点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“确定<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,添加成功。如下图所示。<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">(2)<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 设置第<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">2条需求,点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“新增<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,如下图所示。相同方法设置销售部允许上互联网。设置销售部允许访问服务器网段。点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“新增<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,如下图所示。关键设置如下:l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 源安全区域:选择销售部网络所在区域,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“trust”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 目的安全区域:选择服务器所在区域,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“dmz”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 源地址:选择销售部<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址范围,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Sales”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 目的地址:选择服务器<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址范围,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Servers”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 设置完毕,点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“确定<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,添加完成。设置销售部禁止访问娱乐软件,点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“新增<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,如下图所示。关键设置如下:l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 源安全区域:选择销售部网络所在区域,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“trust”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 目的安全区域:选择互联网所在区域,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“untrust”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 源地址:选择销售部<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址范围,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Sales”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 目的地址:选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">Internet网络<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址范围,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“IPGROUP_ANY”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 添加到指定位置(第几条):该规则应当放在销售上网规则的前面,本例中设置为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“2”。设置完毕,点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“确定<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,添加完成。如下图所示。销售部规则添加完毕。<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">(3)<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 设置第<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">3条需求,研发部、财务部、行政部可以访问内部服务器网络,但是不能访问互联网,仅允许访问公司外部官方网站<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">www.test.com。<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">(4)<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 相同设置方法设置研发部、财务部、行政部可以访问内部服务器网络。如下图所示。设置研发部、财务部、行政部允许访问公司外部官方网站<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">www.test.com。点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“新增<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,如下图所示。 关键设置如下:l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 源安全区域:选择研发部、财务部、行政部网络所在区域,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“trust”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 目的安全区域:选择官方网站服务器所在区域,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“untrust”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 源地址:选择研发部、财务部、行政部<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址范围,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Internal”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 目的地址:选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">Internet网络<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址范围,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“IPGROUP_ANY”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> <span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">URL过滤:选择已设定的官方网站条目<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“official_WEB”。设置完毕,点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“确定<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,添加完成。如下图所示。出差员工可以通过互联网访问内网的<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">8080端口的<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">WEB服务器。点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“新增<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,如下图所示。关键设置如下:l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 源安全区域:选择互联网所在区域,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“untrust”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 目的安全区域:选择服务器所在区域,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“dmz”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 源地址:选择互联网<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址范围,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“IPGROUP_ANY”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 目的地址:选择服务器<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP地址范围,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Servers”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 服务组:选择已设定的内部<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">WEB服务器的服务组<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“WEB_Server”。设置完毕,点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“确定<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,添加完成。如下图所示。<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">(5)<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 第<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">5、<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">6条需求默认已经如此,无需专门设置。至此所有安全策略设置完毕。7.<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 设置审计策略设置审计需求一:对所有流经防火墙的数据进行审计,并记录到审计日志。以审计管理员身份登录防火墙,打开<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“对象<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“审计配置文件<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“新增<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,设置需要审计的<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">URL以及<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IM行为: l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 名称:设置审计配置文件的名称,本例为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“audit_all”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 描述:添加描述,便于后期维护,本例中设置为:<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“审计所有网站<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> <span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IM行为审计:通讯软件行为审计,目前仅支持记录<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">QQ上下线,本例中设置为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“启用<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> <span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">HTTP行为审计(<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">URL访问):设置需要审计的<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">URL,本例中设置为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“记录所有<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">URL”l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 网站组选择:仅记录指定<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">URL时,可选择要记录的<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">URL,本例中已设置为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“记录所有<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">URL”,故无需选择。点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“确定<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,添加完成,如下图所示。打开<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“策略<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“审计策略<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,如下图所示:可以看到系统默认有一条不审计的策略。下面我们根据审计需求设置审计策略,之前的需求为:对所有流经防火墙的数据进行审计。故设置如下图所示:l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 策略名称:可自定义,本例设置为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“audit_all_data”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 描述:添加描述,便于后期维护,本例设置为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“审计所有流量<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 源安全区域:选择源安全区域,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Any”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 目的安全区域:选择目的安全区域,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Any”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 源地址:选择源地址,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Any”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 目的地址:选择目的地址,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Any”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 服务组:选择服务组,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Any”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 应用组:选择应用组,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Any”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 时间段:选择时间段,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Any”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 动作:选择命中规则后的处理动作,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“审计<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 审计配置文件:选择审计配置文件,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“audit_all”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 添加到指定位置(第几条):本例中无需设置。点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“确定<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,添加成功。如下图所示。通过上述步骤,则完成了防火墙审计策略的设置。8.<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 对接审计服务器设置需求二:将防火墙的审计日志、系统日志、操作日志、流量日志、策略命中日志全部上传至安装了<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">TP-LINK安全审计系统的审计服务器。设置好审计策略后,可以登录防火墙查看审计信息,但防火墙自身存储能力有限,为了存储更多更久的审计信息,可以把审计信息上传到安装了<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">TP-LINK安全审计系统的服务器上。设置方法如下:以审计管理员身份登录防火墙,打开<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“系统<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“日志配置<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,做如下设置:l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 上传用户上网行为:本例中选择为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“启用<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 行为审计服务器地址:本例中设置为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“172.16.0.2”然而,仅通过上述设置无法实现防护墙与审计服务器的对接,还需要设置一条安全策略,允许防火墙去访问审计服务器,设置方法如下:以系统管理员身份登录防火墙,打开<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“对象<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“地址<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,增加审计服务器地址,设置如下图所示:l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 地址名称:本例中设置为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“audit_server_ip”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> <span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">IP类型:本例选择为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“IP/Mask”,设置为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“172.16.0.2 / 32”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 备注:本例设置为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“审计服务器地址<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。再新增地址组,将审计服务器地址添加到组,设置如下图所示:l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 组名称:本例设置为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“audit_server”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 地址名称:本例选择为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“audit_server_ip”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 备注:本例设置为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“审计服务器<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。打开<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“策略<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“安全策略<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“新增<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,设置一条安全策略,允许防火墙访问服务器,如下图所示:l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 规则名称:自定义,本例为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“allow_audit”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 描述:自定义,本例为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“允许防火墙访问审计服务器<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 源安全区域:选择防火墙所在区域,即设置为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“local”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 目的安全区域:选择审计服务器所在区域,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“dmz”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 源地址:由于安全区域已经选择为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“local”,故源地址可不选择,保持默认为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Any”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 目的地址:选择审计服务器的地址,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“audit_server”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 服务组:选择服务组,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Any”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 应用组:选择应用组,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Any”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 时间段:选择时间段,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“Any”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 动作:选择命中规则后的处理动作,本例中选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“允许<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 内容安全:选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">URL过滤和文件过滤配置文件,本例中留空,不选择。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 记录策略命中日志:本例中不启用。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 状态:选择<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“启用<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 添加到指定位置(第几条):本例中无需设置。点击<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“确定<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,添加成功。通过上述步骤,防火墙上的审计信息就可以上传至审计服务器,这就满足了审计需求一。而对于需求二:将防火墙的审计日志、系统日志、操作日志、流量日志、策略命中日志全部上传至安装了<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">TP-LINK安全审计系统的审计服务器。可以用系统管理员身份登录防火墙,打开<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“系统<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”——“日志<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”,做如下设置:l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 选择系统日志等级:是否选择要上传的系统日志的等级,本例中勾选,且选择为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“所有等级<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 选择系统日志模块类别:是否选择要上传的系统日志模块类别,本例中勾选,且选择为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“所有模块<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">”。l<span times="" new="" roman";"="" style="margin: 0px; padding: 0px; box-sizing: border-box;"> 发送日志:是否发送日志,本例中勾选,且设置服务器地址为<span lang="EN-US" arial",sans-serif;letter-spacing:1.0pt;"="" style="margin: 0px; padding: 0px; box-sizing: border-box;">“172.16.0.2”。
|