问题3(10分)以下是设备的部分配置,根据题意完成命令填空或者解释。
[DeviceA]interface ge 0/0/1
[DeviceA-GE0/0/1] ip address 1.1.1.1 24
[DeviceA-GE0/0/1] quit
[DeviceA] interface ge 0/0/2
[DeviceA-GE0/0/2] ip address 10.2.0.1 24
[DeviceA-GE0/0/2]quit
[DeviceA] firewall zone untrust
[DeviceA-zone-untrust] add interface ge 0/0/1
[DeviceA-zone-untrust] quit
[DeviceA]firewall zone (8)[DeviceA-zone-trust] add interface ge 0/0/2
[DeviceA-zone-trust] quit
# 配置允许用户访问内网资源。
[DeviceA-policy-security] rule name (9)
[DeviceA-policy-security-rule-policy_sslvpn_2] source-zone(10)
[DeviceA-policy-security-rule-policy_sslvpn_2]destination-zone trust
[DeviceA-policy-security-rule-policy_sslvpn_2]source-address (11)
[DeviceA-policy-security-rule-policy_sslvpn_2]destination-address 10.2.0.0 24
[DeviceA-policy-security-rule-policy_sslvpn_2] action (12)
[DeviceA-policy-security-rule-policy_sslvpn_2] quit
[DeviceA-policy-security] quit
[DeviceA] ucl-group name group1
[DeviceAlquit
[DeviceA] ip pool addr_pool
[DeviceA-ip-pool-addr_pool](13)0 172.16.1.1 172.16.1.100
[DeviceA-ip-pool-addr_pool] quit
创建SSLVPN虚拟网关,虚拟网关缺省情况下的认证方式为用户名+密码。
[DeviceA] virtual-gateway example 1
[DeviceA-virtual-gateway-example]service address interfacege 0/0/1 port (14)
# 创建角色staff,并关联ucl组和资源。
[DeviceA-virtual-gateway-example] role staff
[DeviceA-virtual-gateway-example-role-staff] group (15)
[DeviceA-virtual-gateway-example-role-staff] resource test
[DeviceA-virtual-gateway-example-role-staff] quit
[DeviceA-virtual-gateway-example] quit
# 配置本地接入用户的接入类型为sslvpn,用户名为abc,登录密码为Helloworld@135,绑定名称为“group1”的ucl组。
[DeviceA] aaa
[DeviceA-aaa](16) abc
[DeviceA-aaa-access-user-abc] passwordcipher Helloworld@123
[DeviceA-aaa-access-user-abc] service-type (17)
[DeviceA-aaa-access-user-abc] ucl-group group1
[DeviceA-aaa-access-user-abc]quit
[DeviceA-aaa] quit