设为首页收藏本站language 语言切换
查看: 1504|回复: 0
收起左侧

[注意] 求助!!高手。。。

[复制链接]
发表于 2013-2-25 16:10:08 | 显示全部楼层 |阅读模式
分公司新上了一台H3C F100-C防火墙,公司为电话号拨号上网,拓扑:一台ADSL调制解调器连到F100的WAN口,F100的LAN1口下接一台傻瓜交换机,傻瓜交换下边接日常工作电脑。配置如下:问题:打网页一天比一天慢,用360测速显示下载速度300KB左右,请高手帮忙查找一下原因,谢谢。
Login authentication

Username:admin
Password:
<founder_nmg>sys
System View: return to User View with Ctrl+Z.
[founder_nmg]dis cur
[founder_nmg]dis current-configuration
#
sysname founder_nmg
#
firewall packet-filter enable
firewall packet-filter default permit
#
insulate
#
nat address-group 1 192.168.107.1 192.168.107.254
#
dialer-rule 1 ip permit
#
firewall statistic system enable
#
radius scheme system
server-type extended
#
domain system
#
local-user admin
password cipher .]@USE=B,53Q=^Q`MAF4<1!!
service-type telnet terminal
level 3
service-type ftp
#
ike proposal 1
#
ike dpd defaultdpd
#
ike peer founder_nm_peer
exchange-mode aggressive
pre-shared-key 1234567890
id-type name
remote-name fvx_beijing192
remote-address 123.127.240.200
nat traversal
dpd defaultdpd
#
ipsec card-proposal founder_nm_prop
use encrypt-card 1/0
transform ah-esp
undo esp authentication-algorithm
esp encryption-algorithm 3des
#
ipsec policy founder_nm_pol 1 isakmp
security acl 3000
pfs dh-group2
ike-peer founder_nm_peer
proposal founder_nm_prop
#
dhcp server ip-pool 0
network 192.168.107.0 mask 255.255.255.0
gateway-list 192.168.107.1
dns-list 202.99.224.68
expired day 8
#
acl number 2000
rule 0 permit source 192.168.107.0 0.0.0.255
#
acl number 3000
rule 0 permit ip source 192.168.107.0 0.0.0.255 destination 172.1
.255
acl number 3001
rule 0 permit ip source 192.168.107.0 0.0.0.255 destination 172.1
.255
#
interface Aux0
async mode flow
#
interface Dialer1
link-protocol ppp
ppp pap local-user xxxxxxxxxxxx password simple xxxxxx
ip address ppp-negotiate
dialer user 3
dialer-group 1
dialer bundle 3
nat outbound 2000
#
interface Ethernet0/0
ip address 192.168.0.1 255.255.255.0
#
interface Ethernet0/1
ip address 192.168.107.1 255.255.255.0
#
interface Ethernet0/2
#
interface Ethernet0/3
#
interface Ethernet0/4
pppoe-client dial-bundle-number 3
ip address dhcp-alloc
#
interface Encrypt1/0
#
interface NULL0
#
firewall zone local
set priority 100
#
firewall zone trust
add interface Ethernet0/0
add interface Ethernet0/1
add interface Ethernet0/4
add interface Dialer1
set priority 85
#
firewall zone untrust
set priority 5
#
firewall zone DMZ
set priority 50
#
firewall interzone local trust
#
firewall interzone local untrust
#
firewall interzone local DMZ
#
firewall interzone trust untrust
#
firewall interzone trust DMZ
#
firewall interzone DMZ untrust
#
FTP server enable
#
dhcp server forbidden-ip 192.168.107.1
dhcp server forbidden-ip 192.168.107.6
#
ip route-static 0.0.0.0 0.0.0.0 Dialer 1 preference 60
#
user-interface con 0
user-interface aux 0
user-interface vty 0 4
authentication-mode scheme
#
return
[founder_nmg]

您需要登录后才可以回帖 登录 | 论坛注册

本版积分规则

QQ|Archiver|手机版|小黑屋|sitemap|鸿鹄论坛 ( 京ICP备14027439号 )  

GMT+8, 2025-1-31 10:13 , Processed in 0.050462 second(s), 9 queries , Redis On.  

  Powered by Discuz!

  © 2001-2025 HH010.COM

快速回复 返回顶部 返回列表