拓撲:服務器
基本配參照華爲防火牆USG基本配置(http://692344.blog.51cto.com/682344/1607629)app
下面只給出客戶端和服務器端配置:tcp
防火牆配置:ide
策略配置:測試
監控FTP配置(FTP是動態協議):blog
測試:ip
----------------------------------get
若是FTP使用特殊端口要配置以下:it
acl number 2001
rule 5 permit source 192.168.1.100 0io
port-mapping ftp port 2121 acl 2001
ip service-set newftp type object
service 0 protocol tcp description 2121
firewall interzone dmz untrust detect ftppolicy interzone dmz untrust inbound policy 0 action permit policy service service-set http policy service service-set newftp policy destination 192.168.1.100 0