4配置域间NAT策略和NAT Server 参考以前发布的内容
5 在Trust区域与DMZ区域的域间引用ACL3001进行长连接的配置。
[USG] firewall interzone trust dmz
[USG-interzone-trust-dmz] detect ftp
[USG-interzone-trust-dmz] long-link 3001 outbound
WARNING: Too large range of ACL maybe affect the performance of firewall, please use this command carefully!
Are you sure?[Y/N]Y
[USG-interzone-trust-dmz] quit
[USG] firewall interzone untrust dmz
[USG-interzone-dmz-untrust] detect ftp
[USG-interzone-dmz-untrust] quit
6配置长连接功能老化时间,使ACL3001中定义的流量按照该时间进行老化。然后调整FTP控制通道与FTP数据通道的老化时间。该配置对所有流量生效,所以不需要匹配ACL。其中ftp表示FTP控制通道,ftp-data表示FTP数据通道。
[USG] firewall long-link aging-time 24
[USG] firewall session aging-time service-set ftp 3600
[USG] firewall session aging-time service-set ftp-data 300
结果验证
1 通过命令display firewall long-link aging-time查看当前配置的长连接老化时间。
[USG] display firewall long-link aging-time
11:27:16 2011/09/16
Long-link aging-time is 24 hours
从屏显信息中可以看到,当前长连接的老化时间为24小时。
2通过命令display firewall session aging-time查看当前配置的FTP控制通道和数据通道的老化时间。
[USG] display firewall session aging-time
11:35:22 2011/09/16
Sequence Pre-defined VPN Timeout(s)
----------------------------------------------------------------------
1 http All 600
2 telnet All 600
3 ftp All 3600
4 ras All 600
5 dns All 120
6 rtsp All 600
7 ils All 600
8 hwcc All 120
9 smtp All 600
10 sip All 600
11 sqlnet All 600
12 netbios-name All 120
13 netbios-session All 120
14 netbios-data All 120
15 pptp All 600
16 qq All 120
17 stun All 600
18 msn-stun All 240
19 mgcp All 130
20 mms All 600
21 rpc All 600
22 h225 All 1200
23 h245 All 1200
24 icmp All 20
25 msn All 600
26 msn-audio All 240
27 msn-discard All 240
28 ftp-data All 300
29 rtsp-rtp All 120
30 rtsp-rtcp All 120
从屏显信息中可以看到,由于还没有进行报文的传输,故FTP控制通道的剩余老化时间为3600秒,FTP数据通道的剩余老化时间为300秒。