在两台防火墙之间做OSPF路由协议实现全网互通,红色区域是untrust,紫色和绿色区域是trust
进入防火墙:
F10901:int g1/0/0
ip address 192.168.10.254 24
undo info-center enable
security-zone name Trust
import int GigbitEthernet 1/0/0
quit
int g1/0/1
ip address 10.1.1.1 24
quit
security-zone untrust
import int GigbitEthernet 1/0/1
quit
ospf 1 router-id 192.168.10.254
area 1
network 192.168.10.0 0.0.0.255
quit
area 0
network 10.1.1.1 0.0.0.0
quit
quit
F10902:int GigabitEthernet 1/0/1
ip address 10.1.1.2 24
quit
security-zone name untrust
import int Gigabitethernet 1/0/1
quit
int g1/0/0
ip address 192.168.20.154 24
quit
security-zone name trust
import int GigabitEthernet 1/0/0
quit
ospf 1
如果不配置router-id会自动从防火墙上的两个接口上选择一个ip做router-id
area 0
network 10.1.1.2 0.0.0.0
quit
area 2
network 192.168.20.0 0.0.0.255
quit
quit
display ospf peer(查看是否能建立邻居关系)
发现两个防火墙建不了,因为要放行一个策略,使local区域可以访问untrust区域,untrust区域可以访问local区域
F10901:security-policy ip
rule name LtoU
source-zone local
destination-zone untrust
service ospf
action pass
quit
rule name UtoL
source-zone untrust
destination-zone local
service ospf
action pass
quit
quit
F10902:security-policy ip
rule name LtoU
security-zone local
destination-zone untrust
service ospf
action pass
quit
rule name UtoL
source-zone untrust
destination-zone local
aervice ospf
action pass
quit
quit
这样就建立了ospf邻居关系
查询ospf的routing:
此时pc5不能访问pc7
因为没有放行trust区域到untrust区域,同样也要放行untrust区域到trust区域,因为要回包
F10901:security-policy ip
rule name TtoU
source-zone trust
destination-zone untrust
source-ip-subnet 192.168.10.0 24
destination-ip-subnet 192.168.20.0 24
action pass
quit
rule name UtoT
source-zone untrust
destination-zone trust
source-ip-subnet 192.168.20.0 24
destination-ip subnet 192.168.10.0 24
action pass
F10902:security-policy ip
rule name TtoU
source-zone trust
destination-zone untrust
source-ip-subnet 192.168.20.0 24
destination-ip-subnet 192.168.10.0 24
action pass
quit
rule name UtoT
source-zone untrust
destination-zone trust
source-ip-subnet 192.168.10.0 24
destination-ip-subnet 192.168.20.0 24
action pass
quit
pc5可以ping通pc7了,pc7也可以回访
02-02
2438

01-27
773

12-03
3810

05-08
2947
