安全模式配置
安全模式参数
- 启用安全模式(default):默认启用,确保设备在非内网和外网时使用默认的安全模式。
"security模式": { "enable": true, "enhance_encrypted": true, "firewall": true, "level": 0, "check_log": true, "check_loglog": true } - 提高加密:启用加密来保护数据,防止未经授权的访问。
"security模式": { "enable": true, "encrypt": true, "firewall": true, "level": 0, "check_log": true, "check_loglog": true } - 防火墙:配置防火墙规则,限制外部访问,允许内部设备访问。
"firewall": { "enable": true, "firewall": true, "level": 0, "rule": [ "eth", "eth1", "eth2", "eth3" ] } - 等级(level):设置防火墙的防火级,如、1、2等,控制访问权限。
"firewall": { "enable": true, "firewall": true, "level": 0, "rule": [ "eth", "eth1" ] }
防火墙配置
- 内网防火墙:仅限于内部网络,设备在内部网络内访问。
"web防火墙": { "enable": true, "firewall": true, "level": 0 } - 外网防火墙:仅限于外部网络,设备在外部网络内访问。
"web防火墙": { "enable": true, "firewall": true, "level": 0 } - 网络防火墙:仅限于网络段内的设备访问。
"web防火墙": { "enable": true, "firewall": true, "level": 0 }
网络防火墙配置
- 防火墙规则:限制设备访问的IP地址范围和端口。
"web防火墙": { "enable": true, "firewall": true, "level": 0, "rules": [ [ "eth", "eth1", "eth2", "eth3" ], [ "eth4", "eth5" ] ] }
WTFIS配置
WTFIS参数
- 启用WTFIS(enabled):启动WTFIS监控功能。
"wtfis": { "enabled": true } - WTFIS的防火墙(web防火墙):配置WTFIS的防火墙规则。
"wtfis": { "enabled": true, "firewall": true, "level": 0, "rules": [ [ "eth", "eth1" ], [ "eth2", "eth3" ] ] } - WTFIS的权限(web权限):配置WTFIS的权限规则。
"wtfis": { "enabled": true, "firewall": true, "level": 0, "rules": [ [ "eth/eth1", "eth2/eth3" ], [ "eth4/eth5" ] ] } - WTFIS的过滤规则(web_filter规则):配置WTFIS的过滤规则。
"wtfis": { "enabled": true, "firewall": true, "level": 0, "rules": [ [ "eth", "eth1" ], [ "eth2", "eth3" ], [ "eth4", "eth5" ] ] }
WTFIS日志配置
- 日志日志(logging日志):记录配置日志。
"logging": { "enabled": true, "logging": true, "log": "global.log" } - 日志日志日志(logging日志日志):记录日志日志。
"logging": { "enabled": true, "logging": true, "log": { "logging": true, "logging": true, "log": "logging.log" } }
IP树配置
IP树结构
- 树结构(tree structure):定义IP树的结构,通常使用树形结构表示各个IP地址范围。
"tree": { "name": "example", "children": [ { "name": "eth", "children": [ { "name": "eth", "children": [ { "name": "eth", "children": [ "eth" ] } ] }, { "name": "eth1" "children": [ { "name": "eth1" "children": [ "eth1" "eth11" ] } ] } ] } ] } - IP树的配置(tree配置):配置树结构,指定每个节点的IP地址范围。
"tree": { "name": "example", "children": [ { "name": "eth", "children": [ "eth", "eth1" ] }, { "name": "eth1", "children": [ "eth1", "eth11" ] } ] } - IP树的规则(tree规则):定义树结构的规则,确保每个子树的IP地址范围正确。
"tree": { "name": "example", "children": [ { "name": "eth", "children": [ "eth", "eth1" ] }, { "name": "eth1", "children": [ "eth1", "eth11" ] } ], "children": [ { "name": "eth", "children": [ "eth", "eth1" ] }, { "name": "eth1", "children": [ "eth1", "eth11" ] } ] }
IP列表配置
IP列表配置
- IP列表(list):直接配置设备的IP地址范围内的设备。
"list": { "name": "example", "ip_range": "eth/eth1" } - IP列表的配置(list配置):配置设备的IP地址范围。
"list": { "name": "example", "ip_range": "eth/eth1" } - IP列表的规则(list规则):限制设备的访问权限。
"list": { "name": "example", "ip_range": "eth/eth1", "level": 0 }
配置日志和日志日志
配置日志
- 日志日志(logging日志):记录配置日志,便于调试和分析。
"logging": { "enabled": true, "logging": true, "log": "global.log" } - 日志日志日志(logging日志日志日志):记录日志日志,便于进一步分析。
"logging": { "enabled": true, "logging": true, "log": { "logging": true, "logging": true, "log": "logging.log" } }
项目总结
通过以上配置文件,用户可以实现以下功能:
- **安全模式




