﻿<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>防火墙应用技术 &#8211; 学术创新中心</title>
	<atom:link href="https://www.leexinghai.com/aic/category/gdgm/21221/fwat/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.leexinghai.com/aic</link>
	<description>Academic Innovation Center</description>
	<lastBuildDate>Mon, 29 Nov 2021 06:27:14 +0000</lastBuildDate>
	<language>zh-Hans</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.leexinghai.com/aic/wp-content/uploads/2025/08/cropped-徽标名称-32x32.jpg</url>
	<title>防火墙应用技术 &#8211; 学术创新中心</title>
	<link>https://www.leexinghai.com/aic</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>H11122-实训七firewalld地址转换技术</title>
		<link>https://www.leexinghai.com/aic/h11122-%e5%ae%9e%e8%ae%ad%e4%b8%83firewalld%e5%9c%b0%e5%9d%80%e8%bd%ac%e6%8d%a2%e6%8a%80%e6%9c%af/</link>
					<comments>https://www.leexinghai.com/aic/h11122-%e5%ae%9e%e8%ae%ad%e4%b8%83firewalld%e5%9c%b0%e5%9d%80%e8%bd%ac%e6%8d%a2%e6%8a%80%e6%9c%af/#respond</comments>
		
		<dc:creator><![CDATA[李星海]]></dc:creator>
		<pubDate>Mon, 29 Nov 2021 06:27:12 +0000</pubDate>
				<category><![CDATA[2021-2022-1课程资源分享]]></category>
		<category><![CDATA[防火墙应用技术]]></category>
		<guid isPermaLink="false">https://aic.leexinghai.com/?p=631</guid>

					<description><![CDATA[firewalld的IP伪装和端口转发实训 实验拓扑： firewalld中支持两种类型的nat： 1.ip伪 [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p><strong>firewalld</strong><strong>的IP伪装和端口转发实训</strong></p>



<p>实验拓扑：</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="187" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-73-1024x187.png" alt="" class="wp-image-632" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-73-1024x187.png 1024w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-73-300x55.png 300w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-73-768x140.png 768w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-73.png 1176w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p><strong>firewalld</strong><strong>中支持两种类型的nat：</strong></p>



<p><strong>1.ip</strong><strong>伪装</strong></p>



<p><strong>2.</strong><strong>端口转发</strong><strong></strong></p>



<p>1.修改内网主机的IP地址</p>



<figure class="wp-block-image size-full"><img decoding="async" width="865" height="585" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-74.png" alt="" class="wp-image-633" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-74.png 865w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-74-300x203.png 300w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-74-768x519.png 768w" sizes="(max-width: 865px) 100vw, 865px" /></figure>



<p>2.修改网关服务器两个网卡地址</p>



<figure class="wp-block-image size-full"><img decoding="async" width="865" height="518" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-75.png" alt="" class="wp-image-634" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-75.png 865w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-75-300x180.png 300w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-75-768x460.png 768w" sizes="(max-width: 865px) 100vw, 865px" /></figure>



<p>3.修改外网网卡地址信息</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="865" height="579" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-76.png" alt="" class="wp-image-635" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-76.png 865w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-76-300x201.png 300w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-76-768x514.png 768w" sizes="auto, (max-width: 865px) 100vw, 865px" /></figure>



<p>4.网关服务器开启路由转发功能&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="838" height="123" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-77.png" alt="" class="wp-image-636" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-77.png 838w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-77-300x44.png 300w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-77-768x113.png 768w" sizes="auto, (max-width: 838px) 100vw, 838px" /></figure>



<p>以上基本环境搭建好（步骤有些省略，参考iptables防火墙做snat关于源地址转换实训）</p>



<p>1.内网可以访问服务器连接内网网卡ens33</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="702" height="358" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-78.png" alt="" class="wp-image-637" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-78.png 702w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-78-300x153.png 300w" sizes="auto, (max-width: 702px) 100vw, 702px" /></figure>



<p>2.网关服务器都可以连接内外网</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="853" height="1024" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-79-853x1024.png" alt="" class="wp-image-638" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-79-853x1024.png 853w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-79-250x300.png 250w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-79-768x922.png 768w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-79.png 865w" sizes="auto, (max-width: 853px) 100vw, 853px" /></figure>



<p>3.外网可以访问网关服务器ens37网段</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="697" height="380" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-80.png" alt="" class="wp-image-639" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-80.png 697w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-80-300x164.png 300w" sizes="auto, (max-width: 697px) 100vw, 697px" /></figure>



<p><strong>实验一：端口转发</strong></p>



<p>1.网关服务器开启firewalld防火墙，在默认区域public中增加一条规则</p>



<p>（转发本机的456/tcp端口的流量到22/tcp端口）</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="865" height="722" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-81.png" alt="" class="wp-image-640" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-81.png 865w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-81-300x250.png 300w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-81-768x641.png 768w" sizes="auto, (max-width: 865px) 100vw, 865px" /></figure>



<p>2.外网测试</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="844" height="364" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-82.png" alt="" class="wp-image-641" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-82.png 844w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-82-300x129.png 300w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-82-768x331.png 768w" sizes="auto, (max-width: 844px) 100vw, 844px" /></figure>



<p>（登录成功，但是网关服务器并不想外网直接访问他的22号获取ssh服务，不公开默认ssh服务的22号端口可以增加服务器的安全性）</p>



<p>3.网关服务器firewalld移除ssh服务</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="865" height="994" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-83.png" alt="" class="wp-image-642" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-83.png 865w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-83-261x300.png 261w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-83-768x883.png 768w" sizes="auto, (max-width: 865px) 100vw, 865px" /></figure>



<p>4.再次测试</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="644" height="335" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-84.png" alt="" class="wp-image-643" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-84.png 644w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-84-300x156.png 300w" sizes="auto, (max-width: 644px) 100vw, 644px" /></figure>



<p>（外网不能直接通过默认的22号端口访问ssh服务，只能通过我在防火墙指定的456端口才能访问ssh服务）</p>



<p><strong>实验二：IP伪装</strong></p>



<p>1.清除实验一增加的规则，重新写入一条规则</p>



<p>（将本地的192.168.100.100：6666端口伪装成连接外网的192.168.200.200接口从而访问到192.168.200.10：22端口获取服务）</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="865" height="191" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-85.png" alt="" class="wp-image-644" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-85.png 865w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-85-300x66.png 300w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-85-768x170.png 768w" sizes="auto, (max-width: 865px) 100vw, 865px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="865" height="407" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-86.png" alt="" class="wp-image-645" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-86.png 865w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-86-300x141.png 300w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-86-768x361.png 768w" sizes="auto, (max-width: 865px) 100vw, 865px" /></figure>



<p>2.增加地址伪装功能</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="865" height="590" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-87.png" alt="" class="wp-image-646" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-87.png 865w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-87-300x205.png 300w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-87-768x524.png 768w" sizes="auto, (max-width: 865px) 100vw, 865px" /></figure>



<p>3.内网测试访问192.168.200.20 ssh服务</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="865" height="972" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-88.png" alt="" class="wp-image-647" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-88.png 865w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-88-267x300.png 267w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-88-768x863.png 768w" sizes="auto, (max-width: 865px) 100vw, 865px" /></figure>



<p>（内网主机192.168.100.10通过访问192.168.100.100：6666端口，触发网关服务器的防火墙ip伪装规则，伪装成连接外网接口的192.168.200.200地址再去访问192.168.200.20：22号端口访问到ssh服务）</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.leexinghai.com/aic/h11122-%e5%ae%9e%e8%ae%ad%e4%b8%83firewalld%e5%9c%b0%e5%9d%80%e8%bd%ac%e6%8d%a2%e6%8a%80%e6%9c%af/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>H11115-iptables防火墙实训3</title>
		<link>https://www.leexinghai.com/aic/h11115-iptables%e9%98%b2%e7%81%ab%e5%a2%99%e5%ae%9e%e8%ae%ad3/</link>
					<comments>https://www.leexinghai.com/aic/h11115-iptables%e9%98%b2%e7%81%ab%e5%a2%99%e5%ae%9e%e8%ae%ad3/#respond</comments>
		
		<dc:creator><![CDATA[李星海]]></dc:creator>
		<pubDate>Thu, 18 Nov 2021 11:53:58 +0000</pubDate>
				<category><![CDATA[2021-2022-1课程资源分享]]></category>
		<category><![CDATA[防火墙应用技术]]></category>
		<guid isPermaLink="false">https://aic.leexinghai.com/?p=506</guid>

					<description><![CDATA[1.1实验目的 &#160;&#160;&#160;&#160;&#160;&#160; 了解IPTABLE防 [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p><strong>1.1</strong><strong>实验目的</strong><strong></strong></p>



<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 了解IPTABLE防火墙的NAT转发原理</p>



<p><strong>1.2 </strong><strong>实验内容</strong><strong></strong></p>



<ol class="wp-block-list" type="1"><li>创建三台linux centos7服务器虚拟机<ol><li>前提：充当路由器网关这台linux7服务器已经安装iptables服务，安装完先关闭不然会影响实验结果（没有安装iptables服务的话，适配器默认vmware8 nat模式先下载好iptables服务），同时三台虚拟机要关闭centos7自带的firewalld服务，（关闭firewalld服务命令：systemctl stop firewalld）</li></ol></li><li>给网关路由器这台虚拟机多增加一块网卡</li></ol>



<p>为了更好区分内外网和路由器分别给三台虚拟机重命名，重新调试三台主机的网络适配器</p>



<p>内网Vmware 1（仅主机模式）</p>



<p>路由器连接内网的网卡 Vmware 1（仅主机模式）</p>



<p>路由器连接外网的网卡 Vmware 2（仅主机模式）</p>



<p>外网Vmware 2（仅主机模式）</p>



<p><strong>1.3 </strong><strong>实验步骤</strong>（实验内容截图及适当文字解析和结果分析）</p>



<p>本实验的【C7】虚拟机为路由器，其余的内外网主机以实际名称显示。</p>



<p>1.设置内网主机的ip为192.168.100.10，如图1所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="482" height="428" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image.png" alt="" class="wp-image-507" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image.png 482w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-300x266.png 300w" sizes="auto, (max-width: 482px) 100vw, 482px" /><figcaption>图1</figcaption></figure></div>



<p>2.路由器主机设置两个网卡地址分别为内网和外网，如图2、图3所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="470" height="390" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-1.png" alt="" class="wp-image-508" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-1.png 470w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-1-300x249.png 300w" sizes="auto, (max-width: 470px) 100vw, 470px" /><figcaption>图2</figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-2.png" alt="" class="wp-image-509" width="219" height="220" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-2.png 219w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-2-150x150.png 150w" sizes="auto, (max-width: 219px) 100vw, 219px" /><figcaption>图3</figcaption></figure></div>



<p>3.用路由器去ping内网主机，发现可以ping通，如图4所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="323" height="105" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-3.png" alt="" class="wp-image-510" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-3.png 323w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-3-300x98.png 300w" sizes="auto, (max-width: 323px) 100vw, 323px" /><figcaption>图4</figcaption></figure></div>



<p>4.用路由器去ping外网主机，发现可以ping通，如图5所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="317" height="84" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-4.png" alt="" class="wp-image-511" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-4.png 317w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-4-300x79.png 300w" sizes="auto, (max-width: 317px) 100vw, 317px" /><figcaption>图5</figcaption></figure></div>



<p>5.配置路由器路由转发功能，如图6所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="335" height="107" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-5.png" alt="" class="wp-image-512" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-5.png 335w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-5-300x96.png 300w" sizes="auto, (max-width: 335px) 100vw, 335px" /><figcaption>图6</figcaption></figure></div>



<p>6.内网主机增加网关信息，如图7所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="413" height="224" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-6.png" alt="" class="wp-image-513" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-6.png 413w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-6-300x163.png 300w" sizes="auto, (max-width: 413px) 100vw, 413px" /><figcaption>图7</figcaption></figure></div>



<p>7.外网主机增加网关信息，如图8所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="459" height="400" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-7.png" alt="" class="wp-image-514" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-7.png 459w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-7-300x261.png 300w" sizes="auto, (max-width: 459px) 100vw, 459px" /><figcaption>图8</figcaption></figure></div>



<p>8.尝试用内网主机ping外网主机，如图9所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="501" height="512" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-8.png" alt="" class="wp-image-515" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-8.png 501w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-8-294x300.png 294w" sizes="auto, (max-width: 501px) 100vw, 501px" /><figcaption>图9</figcaption></figure></div>



<p>9.外网主机ping内网主机，如图10所示。</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="525" height="496" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-9.png" alt="" class="wp-image-516" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-9.png 525w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-9-300x283.png 300w" sizes="auto, (max-width: 525px) 100vw, 525px" /><figcaption>图10</figcaption></figure>



<p>10.外网主机删除网关，如图11所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="398" height="313" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-10.png" alt="" class="wp-image-517" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-10.png 398w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-10-300x236.png 300w" sizes="auto, (max-width: 398px) 100vw, 398px" /><figcaption>图11</figcaption></figure></div>



<p>11.重启网络服务后，再次使用ping命令测试连通性，如图12所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="285" height="83" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-11.png" alt="" class="wp-image-518"/><figcaption>图12</figcaption></figure></div>



<p>12.增加防火墙规则，为数据包源地址是来自192.168.100.0网段的地址从ens37网卡流出，做动作是SNAT源地址转换，转换为公网出接口192.168.200.20。如图13所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="539" height="662" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-12.png" alt="" class="wp-image-519" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-12.png 539w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-12-244x300.png 244w" sizes="auto, (max-width: 539px) 100vw, 539px" /><figcaption>图13</figcaption></figure></div>



<p>13.使用ssh登录外网主机，发现可以成功登录，如图14所示。</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="435" height="782" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-13.png" alt="" class="wp-image-520" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-13.png 435w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-13-167x300.png 167w" sizes="auto, (max-width: 435px) 100vw, 435px" /><figcaption>图14</figcaption></figure>



<p>14.外网主机查看安全日志，发现有登录的行为，如图15所示。</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="540" height="354" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-14.png" alt="" class="wp-image-521" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-14.png 540w, https://www.leexinghai.com/aic/wp-content/uploads/2021/11/image-14-300x197.png 300w" sizes="auto, (max-width: 540px) 100vw, 540px" /><figcaption>图15</figcaption></figure>



<p><strong>2.1</strong><strong>实验结论</strong></p>



<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 通过实验，可以了解IPTABLE防火墙的NAT转发原理。完成相应的实践操作。</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.leexinghai.com/aic/h11115-iptables%e9%98%b2%e7%81%ab%e5%a2%99%e5%ae%9e%e8%ae%ad3/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>H11101-iptables 防火墙课堂小练习</title>
		<link>https://www.leexinghai.com/aic/h11101-iptables-%e9%98%b2%e7%81%ab%e5%a2%99%e8%af%be%e5%a0%82%e5%b0%8f%e7%bb%83%e4%b9%a0/</link>
					<comments>https://www.leexinghai.com/aic/h11101-iptables-%e9%98%b2%e7%81%ab%e5%a2%99%e8%af%be%e5%a0%82%e5%b0%8f%e7%bb%83%e4%b9%a0/#respond</comments>
		
		<dc:creator><![CDATA[李星海]]></dc:creator>
		<pubDate>Tue, 26 Oct 2021 08:55:32 +0000</pubDate>
				<category><![CDATA[2021-2022-1课程资源分享]]></category>
		<category><![CDATA[防火墙应用技术]]></category>
		<guid isPermaLink="false">https://aic.leexinghai.com/?p=472</guid>

					<description><![CDATA[CentOS7 默认的防火墙不是iptables, 而是firewalle. 1．先检查是否安装了iptabl [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p><a href="https://www.linuxidc.com/topicnews.aspx?tid=14">CentOS</a>7 默认的防火墙不是iptables, 而是firewalle.</p>



<div class="wp-block-group"><div class="wp-block-group__inner-container is-layout-flow wp-block-group-is-layout-flow">
<p>1．先检查是否安装了iptables<br> <code>[root@localhost ~]</code># service iptables status或者</p>



<pre class="wp-block-preformatted">[root@localhost ~]# rpm -qa|grep iptables</pre>



<pre class="wp-block-preformatted">iptables-services-1.4.21-35.el7.x86_64</pre>



<pre class="wp-block-preformatted">iptables-1.4.21-35.el7.x86_64</pre>



<p id="block-09cd3ca9-78fb-4437-9ab1-8e2181eb4b05">（显示iptables版本说明有安装，没有的话进行安装）</p>
</div></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="554" height="134" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-98.png" alt="" class="wp-image-473" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-98.png 554w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-98-300x73.png 300w" sizes="auto, (max-width: 554px) 100vw, 554px" /><figcaption>图1</figcaption></figure></div>



<p>2．安装iptables，图2显示已经完成了安装</p>



<p>[<code>root@localhost ~]# yum install -y iptables</code></p>



<div class="wp-block-image"><figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-99.png" alt="" class="wp-image-474" width="554" height="157" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-99.png 554w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-99-300x85.png 300w" sizes="auto, (max-width: 554px) 100vw, 554px" /><figcaption>图2</figcaption></figure></div>



<p>3．升级iptables，如图3所示。</p>



<pre class="wp-block-code"><code>&#91;root@localhost ~]yum update iptables </code></pre>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="554" height="157" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-100.png" alt="" class="wp-image-475" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-100.png 554w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-100-300x85.png 300w" sizes="auto, (max-width: 554px) 100vw, 554px" /><figcaption>图3</figcaption></figure></div>



<p>4．安装iptables-services，如图4所示。</p>



<pre class="wp-block-code"><code>&#91;root@localhost ~]yum install iptables-services</code></pre>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="554" height="248" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-101.png" alt="" class="wp-image-476" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-101.png 554w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-101-300x134.png 300w" sizes="auto, (max-width: 554px) 100vw, 554px" /><figcaption>图4</figcaption></figure></div>



<p>二，禁用/停止自带的firewalld服务</p>



<p>1.停止firewalld服务</p>



<pre class="wp-block-code"><code>&#91;root@localhost ~]systemctl stop firewalld</code></pre>



<p>2.禁用firewalld服务，结果如图5所示。</p>



<pre class="wp-block-code"><code>&#91;root@localhost ~]systemctl mask firewalld</code></pre>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="554" height="71" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-102.png" alt="" class="wp-image-477" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-102.png 554w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-102-300x38.png 300w" sizes="auto, (max-width: 554px) 100vw, 554px" /><figcaption>图5</figcaption></figure></div>



<ol class="wp-block-list" type="1"><li>查看filter表中的规则，说出filter存在几种链：存在三种链：INPUT FORWARD OUTPUT。如图6所示。</li></ol>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="504" height="191" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-103.png" alt="" class="wp-image-478" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-103.png 504w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-103-300x114.png 300w" sizes="auto, (max-width: 504px) 100vw, 504px" /><figcaption>图6</figcaption></figure></div>



<ul class="wp-block-list"><li>举一反三同时我们可以查看raw，mangles，nat表中的规则，如图7所示。</li></ul>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="554" height="385" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-104.png" alt="" class="wp-image-479" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-104.png 554w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-104-300x208.png 300w" sizes="auto, (max-width: 554px) 100vw, 554px" /><figcaption>图7</figcaption></figure></div>



<ul class="wp-block-list"><li>查看指定filter表中的output链的详细信息（注意链的大小写），了解每个字段的信息，如图8所示。</li></ul>



<div class="wp-block-image"><figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-105.png" alt="" class="wp-image-480" width="554" height="55" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-105.png 554w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-105-300x30.png 300w" sizes="auto, (max-width: 554px) 100vw, 554px" /><figcaption>图8</figcaption></figure></div>



<ul class="wp-block-list"><li>再次查看filter表中input链的详细信息和列出规则序列编号，不对地址进行名称解析，如图9所示。</li></ul>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="554" height="56" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-106.png" alt="" class="wp-image-481" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-106.png 554w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-106-300x30.png 300w" sizes="auto, (max-width: 554px) 100vw, 554px" /><figcaption>图9</figcaption></figure></div>



<ul class="wp-block-list"><li>再创建一台虚拟机来模拟另外一台主机，分别查看两台虚拟主机的ip地址，用ping测试两台虚拟主机的连通性，在对应表的相关链中在首部写一条规则来拒绝来自另外一台主机的所有报文访问,查看定义的规则生效了没有</li></ul>



<p>     5.1查看CENTOS的IP地址，如图10所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="554" height="373" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-107.png" alt="" class="wp-image-482" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-107.png 554w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-107-300x202.png 300w" sizes="auto, (max-width: 554px) 100vw, 554px" /><figcaption>图10</figcaption></figure></div>



<p>     5.2用另外一台虚拟机尝试使用ping命令进行连通性测试。发现可以正常连通 ，如图11所示。 </p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="554" height="558" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-108.png" alt="" class="wp-image-483" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-108.png 554w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-108-298x300.png 298w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-108-150x150.png 150w" sizes="auto, (max-width: 554px) 100vw, 554px" /><figcaption>图11</figcaption></figure></div>



<p>     5.3添加拒绝访问的防火墙规则，如图12所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-109.png" alt="" class="wp-image-484" width="554" height="75" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-109.png 554w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-109-300x41.png 300w" sizes="auto, (max-width: 554px) 100vw, 554px" /><figcaption>图12</figcaption></figure></div>



<p>     5.4再次使用ping命令进行连通性测试，发现已经不能进行连通， 如图13所示。 </p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="502" height="196" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-110.png" alt="" class="wp-image-485" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-110.png 502w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-110-300x117.png 300w" sizes="auto, (max-width: 502px) 100vw, 502px" /><figcaption>图13</figcaption></figure></div>
]]></content:encoded>
					
					<wfw:commentRss>https://www.leexinghai.com/aic/h11101-iptables-%e9%98%b2%e7%81%ab%e5%a2%99%e8%af%be%e5%a0%82%e5%b0%8f%e7%bb%83%e4%b9%a0/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>H11010-基于ENSP华为防火墙双机热备操作</title>
		<link>https://www.leexinghai.com/aic/h11010-%e5%9f%ba%e4%ba%8eensp%e5%8d%8e%e4%b8%ba%e9%98%b2%e7%81%ab%e5%a2%99%e5%8f%8c%e6%9c%ba%e7%83%ad%e5%a4%87%e6%93%8d%e4%bd%9c/</link>
					<comments>https://www.leexinghai.com/aic/h11010-%e5%9f%ba%e4%ba%8eensp%e5%8d%8e%e4%b8%ba%e9%98%b2%e7%81%ab%e5%a2%99%e5%8f%8c%e6%9c%ba%e7%83%ad%e5%a4%87%e6%93%8d%e4%bd%9c/#respond</comments>
		
		<dc:creator><![CDATA[李星海]]></dc:creator>
		<pubDate>Sat, 23 Oct 2021 07:05:58 +0000</pubDate>
				<category><![CDATA[2021-2022-1课程资源分享]]></category>
		<category><![CDATA[防火墙应用技术]]></category>
		<guid isPermaLink="false">https://aic.leexinghai.com/?p=426</guid>

					<description><![CDATA[1.1实验目的 &#160;&#160;&#160;&#160;&#160;&#160; 双机备份：FW直连部 [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p><strong>1.1</strong><strong>实验目的</strong><strong></strong></p>



<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 双机备份：FW直连部署，上下行连接二层设备的主备备份，组网要求：</p>



<p>1.企业的两台FW的业务都工作在三层，上下行分别连接三层交换机</p>



<p>2.上行交换机连接运营商的接入点，运营商为企业分配的IP地址为192.168.1.0/24</p>



<p>3.两台FW主备备份方式工作，正常情况下，流量通过主防火墙转发，当主防火墙发生故障时，流量通过备份防火墙转发，保证业务不中断</p>



<p><strong>1.2 </strong><strong>实验内容</strong><strong></strong></p>



<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 主备备份模式的双机热备，其中一台防火墙处于Active（活动）状态用于转发数据，另一台防火墙处于Standby（备份）状态不转发数据，两台防火墙通过心跳线同步信息，当处于Active状态防火墙发生故障时，处于Standby状态防火墙自动切换为Active状态，继续提供服务，以避免网络访问出现中断的情况。</p>



<p><strong>1.3 </strong><strong>实验步骤</strong>（实验内容截图及适当文字解析和结果分析）</p>



<p>&nbsp;&nbsp; （1）对防火墙进行基本网络配置，结构如图1所示。</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="437" height="271" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-63.png" alt="" class="wp-image-427" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-63.png 437w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-63-300x186.png 300w" sizes="auto, (max-width: 437px) 100vw, 437px" /><figcaption>图1</figcaption></figure>



<p>（2）配置信任的local区域和心跳接口dmz区域，区间的拓扑地址表可参见表1.</p>



<figure class="wp-block-table aligncenter"><table><tbody><tr><td>序号</td><td>设备名称</td><td>接口</td><td>IP地址/掩码</td><td>所属安全区域</td><td>所属vrrp备份组</td></tr><tr><td>1</td><td>FW1</td><td>G1/0/0</td><td>172.16.1.1/24</td><td>UNTRUST</td><td>主</td></tr><tr><td>2</td><td>G1/0/1</td><td>1.1.1.1/24</td><td>DMZ</td><td>&nbsp;</td></tr><tr><td>3</td><td>G1/0/2</td><td>10.10.10.1/24</td><td>TRUST</td><td>&nbsp;</td></tr><tr><td>4</td><td>路由器</td><td>G0/0/0</td><td>192.168.1.1/24</td><td>UNTRUST</td><td>&nbsp;</td></tr><tr><td>6</td><td>Fw2</td><td>G1/0/0</td><td>172.16.1.2/24</td><td>UNTRUST</td><td>备用</td></tr><tr><td>7</td><td>G1/0/1</td><td>1.1.1.2/24</td><td>DMZ</td><td>&nbsp;</td></tr><tr><td>8</td><td>G1/0/2</td><td>10.10.10.2/24</td><td>TRUST</td><td>&nbsp;</td></tr><tr><td>9</td><td>Pc1</td><td>E0/0/1</td><td>10.10.10.3/24</td><td>TRUST</td><td>&nbsp;</td></tr></tbody></table><figcaption>表1  IP地址规划表</figcaption></figure>



<p>（3）配置VRP组。</p>



<p>（4）在指定的心跳接口启用双机热备份功能。</p>



<p>（5）配置安全策略：只要双机热备的状态建立成功，仅配置Master，Backup设备可以不用配置，配置命令会自动切换。</p>



<p>（6）配置NAT策略，使内网用户可以访问Internet</p>



<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 6.1FW1的命令配置如图2-图6所示。</p>



<div class="wp-block-image"><figure class="alignleft size-full"><img loading="lazy" decoding="async" width="267" height="523" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-64.png" alt="" class="wp-image-428" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-64.png 267w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-64-153x300.png 153w" sizes="auto, (max-width: 267px) 100vw, 267px" /><figcaption>图2</figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="281" height="534" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-65.png" alt="" class="wp-image-429" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-65.png 281w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-65-158x300.png 158w" sizes="auto, (max-width: 281px) 100vw, 281px" /><figcaption>图3</figcaption></figure></div>



<div class="wp-block-image"><figure class="alignleft size-full"><img loading="lazy" decoding="async" width="294" height="503" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-66.png" alt="" class="wp-image-430" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-66.png 294w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-66-175x300.png 175w" sizes="auto, (max-width: 294px) 100vw, 294px" /><figcaption>图4</figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="233" height="502" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-67.png" alt="" class="wp-image-431" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-67.png 233w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-67-139x300.png 139w" sizes="auto, (max-width: 233px) 100vw, 233px" /><figcaption>图5</figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="406" height="519" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-68.png" alt="" class="wp-image-432" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-68.png 406w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-68-235x300.png 235w" sizes="auto, (max-width: 406px) 100vw, 406px" /><figcaption>图6</figcaption></figure></div>



<p>6.2 FW2的命令配置如图7-图11所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="404" height="851" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-69.png" alt="" class="wp-image-433" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-69.png 404w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-69-142x300.png 142w" sizes="auto, (max-width: 404px) 100vw, 404px" /><figcaption>图7</figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="554" height="736" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-70.png" alt="" class="wp-image-434" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-70.png 554w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-70-226x300.png 226w" sizes="auto, (max-width: 554px) 100vw, 554px" /><figcaption>图8</figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="492" height="697" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-71.png" alt="" class="wp-image-435" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-71.png 492w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-71-212x300.png 212w" sizes="auto, (max-width: 492px) 100vw, 492px" /><figcaption>图9</figcaption></figure></div>



<div class="wp-block-image"><figure class="alignleft size-full"><img loading="lazy" decoding="async" width="295" height="266" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-72.png" alt="" class="wp-image-436"/><figcaption>图10</figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="216" height="450" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-73.png" alt="" class="wp-image-437" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-73.png 216w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-73-144x300.png 144w" sizes="auto, (max-width: 216px) 100vw, 216px" /><figcaption>图11</figcaption></figure></div>



<p>6.3 R1的命令配置如图12所示。</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="387" height="372" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-74.png" alt="" class="wp-image-438" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-74.png 387w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-74-300x288.png 300w" sizes="auto, (max-width: 387px) 100vw, 387px" /><figcaption>图12</figcaption></figure>



<p>6.4查看双机备份状态，如图13，图14所示。</p>



<div class="wp-block-image"><figure class="alignleft size-full"><img loading="lazy" decoding="async" width="227" height="419" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-75.png" alt="" class="wp-image-439" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-75.png 227w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-75-163x300.png 163w" sizes="auto, (max-width: 227px) 100vw, 227px" /><figcaption>图13</figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="242" height="420" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-76.png" alt="" class="wp-image-440" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-76.png 242w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-76-173x300.png 173w" sizes="auto, (max-width: 242px) 100vw, 242px" /><figcaption>图14</figcaption></figure></div>



<p>（7）进行验证：先测试正常状态下的访问连接，然后将主备份防火墙一个接口关闭模拟线路发生故障，验证备份防火墙是否能进行转发，保持内网用户正常访问internet。</p>



<p>7.1使用GUI界面查看端口信息，如图15所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="554" height="470" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-77.png" alt="" class="wp-image-441" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-77.png 554w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-77-300x255.png 300w" sizes="auto, (max-width: 554px) 100vw, 554px" /><figcaption>图15</figcaption></figure></div>



<p>7.2观察热备份的web 界面，可见备份成功，如图16所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="603" height="482" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-78.png" alt="" class="wp-image-442" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-78.png 603w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-78-300x240.png 300w" sizes="auto, (max-width: 603px) 100vw, 603px" /><figcaption>图16</figcaption></figure></div>



<p>7.3使用ping命令验证通信情况 ,如图17所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="553" height="300" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-79.png" alt="" class="wp-image-443" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-79.png 553w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-79-300x163.png 300w" sizes="auto, (max-width: 553px) 100vw, 553px" /><figcaption>图17</figcaption></figure></div>



<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 7.4在FW1上观察防火墙会话表，可见通信成功。如图18所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="553" height="345" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-80.png" alt="" class="wp-image-444" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-80.png 553w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-80-300x187.png 300w" sizes="auto, (max-width: 553px) 100vw, 553px" /><figcaption>图18</figcaption></figure></div>



<p>7.5验证备份情况：尝试断开与主线的接口，如图19所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="481" height="306" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-81.png" alt="" class="wp-image-445" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-81.png 481w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-81-300x191.png 300w" sizes="auto, (max-width: 481px) 100vw, 481px" /><figcaption>图19</figcaption></figure></div>



<p>7.6对FW1显示hrp状态，如图20所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="497" height="142" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-82.png" alt="" class="wp-image-446" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-82.png 497w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-82-300x86.png 300w" sizes="auto, (max-width: 497px) 100vw, 497px" /><figcaption>图20</figcaption></figure></div>



<p>7.7对FW2显示hrp状态，如图21所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="554" height="145" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-83.png" alt="" class="wp-image-447" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-83.png 554w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-83-300x79.png 300w" sizes="auto, (max-width: 554px) 100vw, 554px" /><figcaption>图21</figcaption></figure></div>



<p>7.8使用ping命令再次对PC1与路由器通信情况进行验证，如图22所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="553" height="209" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-84.png" alt="" class="wp-image-448" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-84.png 553w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-84-300x113.png 300w" sizes="auto, (max-width: 553px) 100vw, 553px" /><figcaption>图22</figcaption></figure></div>



<p>7.9观察Fw2的防火墙会话状态表。如图23所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="554" height="311" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-85.png" alt="" class="wp-image-449" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-85.png 554w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-85-300x168.png 300w" sizes="auto, (max-width: 554px) 100vw, 554px" /><figcaption>图23</figcaption></figure></div>



<p>7.10观察华为防火墙的web界面，如图24所示。</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="545" height="341" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-86.png" alt="" class="wp-image-450" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-86.png 545w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-86-300x188.png 300w" sizes="auto, (max-width: 545px) 100vw, 545px" /><figcaption>图24</figcaption></figure></div>



<p><strong>2.1</strong><strong>实验结论</strong></p>



<p>两台防火墙使用主备备份方式工作。正常情况下，流量通过主防火墙转发，当主防火墙发生故障时，流量通过备份防火墙转发，保证业务不中断。</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.leexinghai.com/aic/h11010-%e5%9f%ba%e4%ba%8eensp%e5%8d%8e%e4%b8%ba%e9%98%b2%e7%81%ab%e5%a2%99%e5%8f%8c%e6%9c%ba%e7%83%ad%e5%a4%87%e6%93%8d%e4%bd%9c/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>H11011-华为防火墙安全策略配置</title>
		<link>https://www.leexinghai.com/aic/h11011-%e5%8d%8e%e4%b8%ba%e9%98%b2%e7%81%ab%e5%a2%99%e5%ae%89%e5%85%a8%e7%ad%96%e7%95%a5%e9%85%8d%e7%bd%ae/</link>
					<comments>https://www.leexinghai.com/aic/h11011-%e5%8d%8e%e4%b8%ba%e9%98%b2%e7%81%ab%e5%a2%99%e5%ae%89%e5%85%a8%e7%ad%96%e7%95%a5%e9%85%8d%e7%bd%ae/#respond</comments>
		
		<dc:creator><![CDATA[李星海]]></dc:creator>
		<pubDate>Sat, 23 Oct 2021 06:44:39 +0000</pubDate>
				<category><![CDATA[2021-2022-1课程资源分享]]></category>
		<category><![CDATA[防火墙应用技术]]></category>
		<guid isPermaLink="false">https://aic.leexinghai.com/?p=393</guid>

					<description><![CDATA[实验概述 公司有财务部，人事部，销售部三个部门统一规划为trust区域，还有部署服务器供內部和外网访问的dmz [&#8230;]]]></description>
										<content:encoded><![CDATA[
<ol class="wp-block-list" type="1"><li>实<strong>验概述</strong></li></ol>



<p>公司有财务部，人事部，销售部三个部门统一规划为trust区域，还有部署服务器供內部和外网访问的dmz区域，外网区域untrust区域</p>



<p><strong>2.</strong><strong>实验目的</strong><strong>：</strong><br>了解华为防火墙安全策略。<br>掌握华为防火墙安全策略的配置。</p>



<p><strong>3.</strong><strong>实验环境</strong></p>



<p>华为ensp模拟器</p>



<p><strong>4.</strong><strong>实验要求</strong></p>



<p>1.公司內部三个部门可以互相通信，同时财务部可以访问服务器获得服务，其他部门不能访问服务器区</p>



<p>2.外网可以访问服务器区获得服务</p>



<p>3.员工区域trust通过easy-ip模式的nat地址转换技术安全访问外网</p>



<p>4.服务器dmz区域它通过pat模式的nat地址转换技术来访问外网</p>



<h4 class="wp-block-heading">一．网络拓扑结构图</h4>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="619" height="305" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-41.png" alt="" class="wp-image-394" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-41.png 619w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-41-300x148.png 300w" sizes="auto, (max-width: 619px) 100vw, 619px" /><figcaption>图1</figcaption></figure>



<h4 class="wp-block-heading">二．IP地址规划</h4>



<p>根据网络拓扑图填写IP地址规划表如下表1：</p>



<figure class="wp-block-table aligncenter"><table><tbody><tr><td>序号</td><td>设备名称</td><td>接口</td><td>IP地址/掩码</td><td>所属安全区域</td><td>网关</td></tr><tr><td>1</td><td>防火墙</td><td>G1/0/1</td><td>192.168.7.2</td><td>TRUST</td><td>192.168.7.1</td></tr><tr><td>2</td><td>G1/0/2</td><td>192.168.8.254</td><td>DMZ</td><td>192.168.8.1</td></tr><tr><td>3</td><td>G1/0/0</td><td>8.8.8.254</td><td>UNTRUST</td><td>8.8.8.1</td></tr><tr><td>4</td><td>AR2</td><td>G0/0/1</td><td>192.168.5.2</td><td>TRUST</td><td>192.168.5.1</td></tr><tr><td>5</td><td>G0/0/0</td><td>192.168.6.1</td><td>TRUST</td><td>192.168.6.2</td></tr><tr><td>6</td><td>AR1</td><td>G0/0/1</td><td>192.168.6.2</td><td>TRUST</td><td>192.168.6.1</td></tr><tr><td>7</td><td>G0/0/2</td><td>192.168.3.2</td><td>TRUST</td><td>192.168.3.1</td></tr><tr><td>8</td><td>G0/0/0</td><td>192.168.7.1</td><td>TRUST</td><td>192.168.7.1</td></tr><tr><td>9</td><td>AR3</td><td>G0/0/0</td><td>8.8.8.1</td><td>UNTRUST</td><td>8.8.8.254</td></tr></tbody></table><figcaption>表1 IP地址规划表 </figcaption></figure>



<h4 class="wp-block-heading">三．VLAN规划表</h4>



<p>根据网络拓扑图填写Vlan规划表如下表2：</p>



<figure class="wp-block-table aligncenter"><table><tbody><tr><td>序号</td><td>设备名称</td><td>VLAN编号</td><td>IP地址</td><td>子网掩码</td></tr><tr><td>1</td><td>LSW2</td><td>Vlan10</td><td>192.168.1.2</td><td>255.255.255.0</td></tr><tr><td>2</td><td>LSW3</td><td>Vlan20</td><td>192.168.2.2</td><td>255.255.255.0</td></tr><tr><td>3</td><td>LSW1</td><td>Vlan30</td><td>192.168.3.1</td><td>255.255.255.0</td></tr><tr><td>4</td><td>LSW4</td><td>Vlan40</td><td>192.168.4.254</td><td>255.255.255.0</td></tr><tr><td>&nbsp;</td><td>LSW4</td><td>Vlan50</td><td>192.168.5.1</td><td>255.255.255.0</td></tr></tbody></table><figcaption>表2 Vlan规划表 </figcaption></figure>



<h4 class="wp-block-heading">三．各设备的相关命令截图</h4>



<p><strong>1.LSW2的配置命令如图2-3所示。</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="298" height="436" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-42.png" alt="" class="wp-image-395" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-42.png 298w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-42-205x300.png 205w" sizes="auto, (max-width: 298px) 100vw, 298px" /><figcaption>图2</figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="463" height="175" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-43.png" alt="" class="wp-image-396" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-43.png 463w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-43-300x113.png 300w" sizes="auto, (max-width: 463px) 100vw, 463px" /><figcaption>图3</figcaption></figure></div>



<p>2.<strong>LSW3 <strong>的配置命令如图4-5所示。</strong> </strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="350" height="520" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-44.png" alt="" class="wp-image-397" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-44.png 350w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-44-202x300.png 202w" sizes="auto, (max-width: 350px) 100vw, 350px" /><figcaption>图4</figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-45.png" alt="" class="wp-image-398" width="473" height="224" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-45.png 473w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-45-300x142.png 300w" sizes="auto, (max-width: 473px) 100vw, 473px" /><figcaption>图5</figcaption></figure></div>



<p>3.<strong>LSW4 <strong><strong>的配置命令如图6-8所示。</strong> </strong> </strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="341" height="561" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-46.png" alt="" class="wp-image-399" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-46.png 341w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-46-182x300.png 182w" sizes="auto, (max-width: 341px) 100vw, 341px" /><figcaption>图6</figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-47.png" alt="" class="wp-image-400" width="466" height="175" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-47.png 466w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-47-300x113.png 300w" sizes="auto, (max-width: 466px) 100vw, 466px" /><figcaption>图7</figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="439" height="100" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-48.png" alt="" class="wp-image-401" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-48.png 439w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-48-300x68.png 300w" sizes="auto, (max-width: 439px) 100vw, 439px" /><figcaption>图8</figcaption></figure></div>



<p>4<strong>.AR1<strong><strong><strong>的配置命令如图9所示，IP路由表如图10所示、OSPF区域如图11所示。</strong></strong></strong> </strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="435" height="448" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-49.png" alt="" class="wp-image-402" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-49.png 435w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-49-291x300.png 291w" sizes="auto, (max-width: 435px) 100vw, 435px" /><figcaption>图9</figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="431" height="386" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-50.png" alt="" class="wp-image-403" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-50.png 431w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-50-300x269.png 300w" sizes="auto, (max-width: 431px) 100vw, 431px" /><figcaption>图10</figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="328" height="160" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-51.png" alt="" class="wp-image-404" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-51.png 328w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-51-300x146.png 300w" sizes="auto, (max-width: 328px) 100vw, 328px" /><figcaption>图11</figcaption></figure></div>



<p>5.<strong>AR2<strong><strong><strong><strong><strong><strong><strong>的配置命令如图12所示，IP路由表如图13所示。</strong></strong></strong> </strong> </strong></strong></strong></strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-52.png" alt="" class="wp-image-405" width="404" height="480" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-52.png 404w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-52-253x300.png 253w" sizes="auto, (max-width: 404px) 100vw, 404px" /><figcaption>图12</figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="425" height="393" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-53.png" alt="" class="wp-image-406" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-53.png 425w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-53-300x277.png 300w" sizes="auto, (max-width: 425px) 100vw, 425px" /><figcaption>图13</figcaption></figure></div>



<p>6.<strong>AR3的<strong><strong><strong><strong>IP路由表如图14所示。</strong></strong></strong> </strong> </strong>配置方式同AR2</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="466" height="264" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-54.png" alt="" class="wp-image-407" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-54.png 466w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-54-300x170.png 300w" sizes="auto, (max-width: 466px) 100vw, 466px" /><figcaption>图14</figcaption></figure></div>



<h2 class="wp-block-heading">四．实训要求</h2>



<p><strong>公司内部三个部门可以相互通信，同时财务部可以访问服务器获得服务，其他不能访问服务器区</strong></p>



<p><strong>财务部（PC</strong><strong>）：192.168.1.1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </strong><strong>销售部IP</strong><strong>：192.168.4.1&nbsp;&nbsp; </strong><strong>人事部IP</strong><strong>：192.168.2.1</strong></p>



<p><strong>PC1可以Ping通另外两个部门</strong>（如图15所示）</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="372" height="407" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-55.png" alt="" class="wp-image-408" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-55.png 372w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-55-274x300.png 274w" sizes="auto, (max-width: 372px) 100vw, 372px" /><figcaption>图15</figcaption></figure></div>



<p><strong>PC2也可以Ping通另外另个部门</strong>（如图16所示）</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="397" height="481" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-56.png" alt="" class="wp-image-409" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-56.png 397w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-56-248x300.png 248w" sizes="auto, (max-width: 397px) 100vw, 397px" /><figcaption>图16</figcaption></figure></div>



<p><strong>（人事部）PC1（192.168.2.1）[如图17所示]、和（销售部）PC2（192.168.4.1）[如图18所示]都不能访问服务器区：</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="449" height="259" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-57.png" alt="" class="wp-image-410" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-57.png 449w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-57-300x173.png 300w" sizes="auto, (max-width: 449px) 100vw, 449px" /><figcaption>图17</figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="432" height="260" src="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-58.png" alt="" class="wp-image-411" srcset="https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-58.png 432w, https://www.leexinghai.com/aic/wp-content/uploads/2021/10/image-58-300x181.png 300w" sizes="auto, (max-width: 432px) 100vw, 432px" /><figcaption>图18</figcaption></figure></div>
]]></content:encoded>
					
					<wfw:commentRss>https://www.leexinghai.com/aic/h11011-%e5%8d%8e%e4%b8%ba%e9%98%b2%e7%81%ab%e5%a2%99%e5%ae%89%e5%85%a8%e7%ad%96%e7%95%a5%e9%85%8d%e7%bd%ae/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
