from-zone Lab to-zone Edu { policy edu-infra-ban { match { source-address any; destination-address [ Jwc JwcUtil ]; application any; } then { reject; log { session-init; session-close; } } } policy lab-to-edu { match { source-address any; destination-address any; application any; } then { permit; } } } from-zone DC to-zone Edu { policy dc-to-edu { match { source-address any; destination-address any; application any; } then { permit; } } } from-zone Lab to-zone DC { policy lab-to-dc { match { source-address any; destination-address any; application any; } then { permit; } } } from-zone Edu to-zone Lab { policy edu-to-lab { match { source-address any; destination-address any; application any; } then { permit; } } } from-zone DC to-zone Lab { policy dc-to-lab { match { source-address any; destination-address any; application any; } then { permit; } } } from-zone Edu to-zone DC { policy allow-management-access { match { source-address Lab-MGMT; destination-address any; application any; } then { permit; } } policy ban-remote-control { match { source-address any; destination-address any; application [ junos-ssh junos-telnet junos-icmp-all ]; } then { reject; log { session-init; session-close; } } } policy edu-to-dc { match { source-address any; destination-address any; application any; } then { permit; } } }
为 Zone-to-Zone 的流量制定规则。注意,这里的规则没有自反性。如 set
A->B,B->A 依然会被阻断。
地址段需要使用 address-book 配置。
Log Accounting
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19
set system syslog file messages any critical set system syslog file messages authorization info set system syslog file interactive-commands interactive-commands error set system syslog file traffic.log user info set system syslog file traffic.log match RT_FLOW_SESSION set system syslog file lab-deny.log user any set system syslog file lab-deny.log match edu-infra-ban set system syslog file traffic-screens any any set system syslog file traffic-screens match RT_SCREEN set system syslog file dc-deny.log user any set system syslog file dc-deny.log match ban-remote-control set system syslog file security-log.log any any set system syslog file security-log.log archive files 1 set system syslog file security-log.log structured-data set security log mode event set security policies from-zone Lab to-zone Edu policy edu-infra-ban then log session-init set security policies from-zone Lab to-zone Edu policy edu-infra-ban then log session-close set security policies from-zone Edu to-zone DC policy ban-remote-control then log session-init set security policies from-zone Edu to-zone DC policy ban-remote-control then log session-close