华为路由器,自动断开会话的问题

有一批服务器,加了华为路由器后发现,所有ssh连接一段时间不操作以后,会自动断开服务器连接,重新连接又没有问题,检查了linux系统ssh设置没问题,直连交换机也没问题,关键就在于添加了路由器,并且有acl策略。路由器配置如下:
dis current-configuration
[V200R005C20SPC200]
#
sysname PS_530_RT
#
drop illegal-mac alarm
#
wlan ac-global carrier id other ac id 0
#
pki realm default
enrollment self-signed
#
acl name ControlForPS 3999

rule 100 permit ip source 12.32.4.210 0 destination 0.0.0.0 192.168.1.255
rule 101 permit ip source 12.32.4.211 0 destination 0.0.0.0 192.168.1.255
rule 102 permit ip source 12.32.4.212 0 destination 0.0.0.0 192.168.1.255
rule 103 permit ip source 12.32.4.213 0 destination 0.0.0.0 192.168.1.255
rule 104 permit ip source 12.32.4.214 0 destination 0.0.0.0 192.168.1.255
rule 105 permit ip source 12.32.4.215 0 destination 0.0.0.0 192.168.1.255
rule 106 permit ip source 12.32.4.216 0 destination 0.0.0.0 192.168.1.255
rule 107 permit ip source 12.32.4.217 0 destination 0.0.0.0 192.168.1.255
rule 108 permit ip source 12.32.4.218 0 destination 0.0.0.0 192.168.1.255
rule 109 permit ip source 12.32.4.219 0 destination 0.0.0.0 192.168.1.255
rule 110 permit ip destination 192.168.1.81 0
rule 111 permit ip source 12.32.3.165 0 destination 0.0.0.0 192.168.1.255
rule 112 permit ip source 0.0.0.0 192.168.2.255 destination 0.0.0.0 192.168.1.255
rule 115 permit ip source 12.32.4.223 0 destination 0.0.0.0 192.168.1.255
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default

domain default_admin

local-user admin password cipher %@%@MhDt-]77#%@%@
local-user admin privilege level 3
local-user admin service-type telnet terminal ssh ftp http
#
firewall zone Zone_530
priority 10
#
firewall zone Zone_PS
priority 1
#
firewall zone Local
priority 64
#
firewall interzone Zone_530 Zone_PS
firewall enable
packet-filter 3999 outbound
packet-filter default permit inbound

#
interface GigabitEthernet0/0/0
#
interface GigabitEthernet0/0/1
description 530_IP
ip address 12.32.3.5 255.255.254.0
nat static global 12.32.3.111 inside 192.168.1.81 netmask 255.255.255.255
zone Zone_530
#
interface GigabitEthernet0/0/2
description PS_To_530_GW
ip address 192.168.1.198 255.255.255.0
zone Zone_PS
#
interface Cellular0/0/0
#
interface Cellular0/0/1
#
interface NULL0
#
snmp-agent local-engineid 800007DB03105172F75064
#
http server enable
http secure-server enable

#
ip route-static 0.0.0.0 0.0.0.0 12.32.2.1
#
user-interface con 0
authentication-mode password
set authentication password cipher %@%@EGMUPR#_UG4ZU00NijS9,#WOlN$"1zG,@/\zq>.VX8dF#WR,%@%@
user-interface vty 0 4
authentication-mode password
user privilege level 3
set authentication password cipher %@%@/aN{2)KfHPPhF$J'=8qNc:DFqk`nClJd0*xkL567C"QG:DIc%@%@
idle-timeout 60 0
#
wlan ac
#
voice
#
diagnose
#
return

1个回答

Csdn user default icon
上传中...
上传图片
插入图片
抄袭、复制答案,以达到刷声望分或其他目的的行为,在CSDN问答是严格禁止的,一经发现立刻封号。是时候展现真正的技术了!