问题2(13分):请将相关配置补充完整。
总部防火墙firewall1的部分配置如下
[FIREWALL1]interface(4)
[FIREWALL1-GigabitEthernet1/0/2]ip address (5)
[FIREWALL1-GiqabitEthernet1/0/2] quit
[FIREWALL1]interface GigabitEthernet 1/0/1
[FIREWALL1-GigabitEthernet1/0/1] ip address 202.1.3.1 24
[FIREWALL1-GigabitEthernet1/0/1] quit
# 配置接口加入相应的安全区域。
[FIREWALL1] firewall zone trust
[FIREWALL1-zone-trust] add interface (6)
[FIREWALL1-zone-trustl guit
[FIREWALL1](7)
[FIREWALL1-zone-untrust] add interface GigabitEthernet1/0/1
[FIREWALL1-zone-untrust] quit2.配置安全策略,允许私网指定网段进行报文交互:
# 配置Trust域与Untrust域的安全策略,允许封装前和解封后的报文能通过
[FIREWALL1](8)
[FIREWALL1-policy-security] rule name 1
[FIREWALL1-policy-security-rule-1]source-zone (9)
[FIREWALL1-policy-security-rule-1] destination-zone untrust
[FIREWALL1-policy-security-rule-1]source-address (10)
[FIREWALL1-policy-security-rule-1] destination-address192.168.200.0 24
[FIREWALL1-policy-security-rule-1] action (11)
[FIREWALL1-policy-security-rule-1] quit
....
# 配置Local域与Untrust域的安全策略,允许IKE协商报文能正常通过FIREWALL1。
[FIREWALL1-policy-security] rule name 3
[FIREWALL1-policy-security-rule-3] source-zone local
[FIREWALL1-policy-security-rule-3] destination-zone untrust
[FIREWALL1-policy-security-rule-3]source-address 202.1.3.132
[FIREWALL1-policy-security-rule-3] destination-address202.1.5.1 32
[FIREWALL1-policy-security-rule-3] action permit
[FIREWALL1-policy-security-rule-3] quit
:
3.配置IPSec隧道。
#配置访问控制列表,定义需要保护的数据流
[FIREWALL1](12)
[FIREWALL1-acl-adv-3000]rule permit (13)
[FIREWALL1-acl-adv-3000]quit
# 配置名称为tran1的IPSec安全提议。
[FIREWALL1] ipsec proposal tran1
[FIREWALL1-ipsec-proposal-tran1l encapsulation-mode (14)
[FIREWALL1-ipsec-proposal-tran1]transform esp
[FIREWALL1-ipsec-proposal-tran1] esp
authentication-algorithm sha2-256
[FIREWALL1-ipsec-proposal-tran1lesp encryption-algorithmaes
[FIREWALL1-ipsec-proposal-tran1] quit
#配置序号为10的IKE安全提议。
[FIREWALL1](15)
[FIREWALL1-ike-proposal-10] authentication-method
pre-share
[FIREWALL1-ike-proposal-10]authentication-algorithm
sha2-256
[FIREWALL1-ike-proposal-10] quit
# 配置IKE用户信息表。
[FIREWALL1l ike user-table 1
[FIREWALL1-ike-user-table-1] user id-type ip 202.1.5.1pre-shared-key Admin@gkys
[FIREWALL1-ike-user-table-1] quit
# 配置IKE Peer。
[FIREWALL1] ike peer b
[FIREWALL1-ike-peer-b]ike-proposal 10
[FIREWALL1-ike-peer-b]user-table 1
[FIREWALL1-ike-peer-b] quit
# 配置名称为map_temp序号为1的IPSec安全策略模板。
[FIR锾俜造WALL1]ipsec policy-template map_temp 1
[FIREWALL1-ipsec-policy-template-map_temp-1] security ac!3000
[FIREWALL1-ipsec-policy-template-map_temp-1] proposaltran1
[FIREWALL1-ipsec-policy-template-map temp-1] ike-peer b
[FIREWALL1-ipsec-policy-template-map temp-1]
reverse-route enable
[FIREWALL1-ipsec-policy-template-map_temp-1] quit
# 在IPSec安全策略map1中引用安全策略模板map_temp。
[FIREWAL磯伛L1]ipsec policy map1 10 isakmp templatemap temp
# 在接口GiqabitEthernet 1/0/1上应用安全策略map1。
[FIREWALL1]interface GigabitEthernet 1/0/1
[FIREWALL1-GigabitEthernet1/0/1] ipsec policy map1
[FIREWALL1-GigabitEthernet1/0/1] quit