中小企业最简上线配置仅保留系统基础、SSH远程、内外网IP、NAT上网、默认路由、基础安全无多余花哨配置稳定零报错。1. 基础系统配置H3C system-view # 从用户视图进入系统视图[H3C] sysname Router # 修改设备主机名为Router[Router] undo info-center enable # 关闭终端日志弹窗避免配置刷屏[Router] clock timezone BJ add 8 # 配置设备时区为东八区北京时间2. Console本地密码[Router] user-interface console 0 # 进入Console本地控制台接口视图[Router-ui-console0] authentication-mode password # 开启Console密码认证模式[Router-ui-console0] set password simple Admin123 # 设置加密本地登录密码[Router-ui-console0] idle-timeout 3 # 配置3分钟无操作自动退出终端[Router-ui-console0] quit # 退出Console接口视图3. 标准SSH远程登录极简安全[Router] local-user admin # 创建加密管理员账号[Router-Gateway-luser-admin] password simple Admin123 #配置密码[Router] authorization-attribute level 3 # 配置账号最高3级操作权限[Router-Gateway-luser-admin] service-type ssh # SSH[Router-Gateway-luser-admin] quit # 退出[Router] ssh server enable # 全局开启SSH加密远程服务[Router] user-interface vty 0 15 # 进入0-15所有远程虚拟终端[Router-ui-vty0-15] authentication-mode scheme # 远程登录采用AAA账号认证[Router-ui-vty0-15] protocol inbound ssh # 仅允许SSH协议禁用Telnet明文[Router-ui-vty0-15] idle-timeout 5 # 远程终端5分钟无操作自动下线[Router-ui-vty0-15] quit # 退出VTY终端视图4.接口配置# 外网口上联运营商[Router] interface GigabitEthernet 0/0/0 # 进入外网千兆接口[Router-GigabitEthernet0/0/0] ip address 220.1.1.2 255.255.255.248 # 配置运营商分配公网IP及掩码[Router-GigabitEthernet0/0] description WAN_Internet # 描述[Router-GigabitEthernet0/0/0] undo shutdown # 启用外网接口[Router-GigabitEthernet0/0/0] quit # 退出外网接口视图# 内网口下联交换机[Router] interface GigabitEthernet 0/0/1 # 进入内网千兆接口[Router-GigabitEthernet0/0/1] ip address 192.168.1.1 255.255.255.0 # 配置内网网关IP及掩码[Router-Gateway-GigabitEthernet0/1] description LAN_Core # 描述[Router-GigabitEthernet0/0/1] undo shutdown # 启用内网接口[Router-GigabitEthernet0/0/1] quit # 退出内网接口视图5. 默认路由上网核心[Router] ip route-static 0.0.0.0 0.0.0.0 220.1.1.1 # 配置默认路由所有外网流量转发至运营商网关6. NAT[Router-Gateway] acl number 2000 # 建立ACL[Router-Gateway-acl-basic-2000] rule permit source 192.168.0.0 0.0.255.255 # 允许内网[Router-Gateway-acl-basic-2000] quit # 退出[Router-Gateway] interface GigabitEthernet 0/0 # 进入WAN口[Router-Gateway-GigabitEthernet0/0] nat outbound 2000 # 绑定NAT[Router-Gateway-GigabitEthernet0/0] quit # 退出7. 查看保存配置[Router] save # 保存配置断电重启不丢失Y # 确认保存配置
华三 路由器 极简核心配置
发布时间:2026/6/10 22:42:40
中小企业最简上线配置仅保留系统基础、SSH远程、内外网IP、NAT上网、默认路由、基础安全无多余花哨配置稳定零报错。1. 基础系统配置H3C system-view # 从用户视图进入系统视图[H3C] sysname Router # 修改设备主机名为Router[Router] undo info-center enable # 关闭终端日志弹窗避免配置刷屏[Router] clock timezone BJ add 8 # 配置设备时区为东八区北京时间2. Console本地密码[Router] user-interface console 0 # 进入Console本地控制台接口视图[Router-ui-console0] authentication-mode password # 开启Console密码认证模式[Router-ui-console0] set password simple Admin123 # 设置加密本地登录密码[Router-ui-console0] idle-timeout 3 # 配置3分钟无操作自动退出终端[Router-ui-console0] quit # 退出Console接口视图3. 标准SSH远程登录极简安全[Router] local-user admin # 创建加密管理员账号[Router-Gateway-luser-admin] password simple Admin123 #配置密码[Router] authorization-attribute level 3 # 配置账号最高3级操作权限[Router-Gateway-luser-admin] service-type ssh # SSH[Router-Gateway-luser-admin] quit # 退出[Router] ssh server enable # 全局开启SSH加密远程服务[Router] user-interface vty 0 15 # 进入0-15所有远程虚拟终端[Router-ui-vty0-15] authentication-mode scheme # 远程登录采用AAA账号认证[Router-ui-vty0-15] protocol inbound ssh # 仅允许SSH协议禁用Telnet明文[Router-ui-vty0-15] idle-timeout 5 # 远程终端5分钟无操作自动下线[Router-ui-vty0-15] quit # 退出VTY终端视图4.接口配置# 外网口上联运营商[Router] interface GigabitEthernet 0/0/0 # 进入外网千兆接口[Router-GigabitEthernet0/0/0] ip address 220.1.1.2 255.255.255.248 # 配置运营商分配公网IP及掩码[Router-GigabitEthernet0/0] description WAN_Internet # 描述[Router-GigabitEthernet0/0/0] undo shutdown # 启用外网接口[Router-GigabitEthernet0/0/0] quit # 退出外网接口视图# 内网口下联交换机[Router] interface GigabitEthernet 0/0/1 # 进入内网千兆接口[Router-GigabitEthernet0/0/1] ip address 192.168.1.1 255.255.255.0 # 配置内网网关IP及掩码[Router-Gateway-GigabitEthernet0/1] description LAN_Core # 描述[Router-GigabitEthernet0/0/1] undo shutdown # 启用内网接口[Router-GigabitEthernet0/0/1] quit # 退出内网接口视图5. 默认路由上网核心[Router] ip route-static 0.0.0.0 0.0.0.0 220.1.1.1 # 配置默认路由所有外网流量转发至运营商网关6. NAT[Router-Gateway] acl number 2000 # 建立ACL[Router-Gateway-acl-basic-2000] rule permit source 192.168.0.0 0.0.255.255 # 允许内网[Router-Gateway-acl-basic-2000] quit # 退出[Router-Gateway] interface GigabitEthernet 0/0 # 进入WAN口[Router-Gateway-GigabitEthernet0/0] nat outbound 2000 # 绑定NAT[Router-Gateway-GigabitEthernet0/0] quit # 退出7. 查看保存配置[Router] save # 保存配置断电重启不丢失Y # 确认保存配置