set system domain-name abc.cn set system domain-search abc.cn set system time-zone Asia/Shanghai set system name-server 8.8.8.8 set system ntp server 10.44.2.81 version 2 set system ntp source-address 10.44.2.243 set interfaces fxp0 unit 0 family inet address 192.168.1.1/24 set interfaces lo0 unit 0 family inet filter input protect-RE set interfaces lo0 unit 0 family inet address 10.44.2.243/32 set firewall family inet filter protect-RE term telnet-permit from source-address 10.44.2.80/28 set firewall family inet filter protect-RE term telnet-permit from source-address 192.168.1.0/24 set firewall family inet filter protect-RE term telnet-permit from protocol tcp set firewall family inet filter protect-RE term telnet-permit from port telnet set firewall family inet filter protect-RE term telnet-permit then accept set firewall family inet filter protect-RE term icmp from protocol icmp set firewall family inet filter protect-RE term icmp then accept set firewall family inet filter protect-RE term ospf from protocol ospf set firewall family inet filter protect-RE term ospf then accept set firewall family inet filter protect-RE term snmp from protocol udp set firewall family inet filter protect-RE term snmp from port snmp set firewall family inet filter protect-RE term snmp from port snmptrap set firewall family inet filter protect-RE term snmp then accept set firewall family inet filter protect-RE term http from source-address 10.44.2.80/28 set firewall family inet filter protect-RE term http from protocol tcp set firewall family inet filter protect-RE term http from port http set firewall family inet filter protect-RE term http then accept set firewall family inet filter protect-RE term syslog from protocol udp set firewall family inet filter protect-RE term syslog from port syslog set firewall family inet filter protect-RE term syslog then accept set firewall family inet filter protect-RE term ntp from source-port ntp set firewall family inet filter protect-RE term ntp then accept set firewall family inet filter protect-RE term other-limit then discard