防火墙培训
议程
系统管理
路由模式
安全策略
地址翻译
应用层和网络层防攻击
NSRP高可用性
Debug
系统管理
系统组成
所有关键的系统功能都在内存中运行。
可以通过控制线和webu对防火墙的配置进行修改。
Tables
Buffers
Running
Config
ScreenOS
(active)
ScreenOS
Image
Saved
Config
Certs, etc.
RAM
Flash
Interf.
Interf.
Interf.
TFTP
@
PwrUp/
Reset
Aux.
Storage
WebUI
NetScreen
Aux.
Mgt.
Servers
DNS/
Syslog
Console
“Get”
“Set”
ns208-> get system
Product Name: NS208
Serial Number: 0043042002000034, Control Number: 00000000
Hardware Version: 0110(0)-(11), FPGA checksum: 00000000,
VLAN1 IP ()
Software Version: , Type: Firewall+VPN
Base Mac:
File Name: n200-LAS0z0ad, Checksum: 00000000
Date 04/15/2003 22:06:53, Daylight Saving Time enabled
work Time Protocol is Disabled
Up 2 hours 31 minutes 14 seconds Since 15 Apr 2003 19:35:39
Total Device Resets: 0
System in NAT/route mode.
Use interface IP, Config Port: 80
User Name: netscreen
Interface 1:
number 0, if_info 0, if_index 0, mode nat
link up, phy-link up/full-duplex
vsys Root, zone Trust, vr trust-vr
dhcp disabled
*ip mac
*manage ip , mac
--- more ---
显示状态信息- CLI
In the CLI, mands provide valuable status about operational conditions:
System serial number
Software version
Operating mode
Interface status
Interface address
Management addresses
Zone 和 Interface 的分配
A strict hierarchical linkage exists between zones and interfaces in Screen device
Zones are assigned to a virtual router
Interfaces are assigned to a security zone
An interface can only belong to one security zone
Individual configuration parameters are assigned to interfaces
IP addresses
Management services
Others
Int.
Zone
Zone
Virtual Router
VR
Zone
Int.
IP
Configuring Zones/Interfaces - WebUI
Network > Interfaces (edit)
保存配置
WebUI
Saves automatically when you click “Apply” or “OK”
Console displays save messages
CLI
mand
Writes to on-board flash configuration file
ns208> save
配置文件管理- CLI
只有根管理员才能进行这些操作
配置文件备份
配置文件恢复
Option 1:
防火墙售后培训中文 来自淘豆网www.taodocs.com转载请标明出处.