防火墙:安全策略使得OSPF邻接关系建立


在两台防火墙之间做OSPF路由协议实现全网互通,红色区域是untrust,紫色和绿色区域是trust
进入防火墙:
F10901:int g1/0/0
ip address 192.168.10.254 24
undo info-center enable
security-zone name Trust
import int GigbitEthernet 1/0/0
quit
int g1/0/1
ip address 10.1.1.1 24
quit
security-zone untrust
import int GigbitEthernet 1/0/1
quit
ospf 1 router-id 192.168.10.254
area 1
network 192.168.10.0 0.0.0.255
quit
area 0
network 10.1.1.1 0.0.0.0
quit
quit

F10902:int GigabitEthernet 1/0/1
ip address 10.1.1.2 24
quit
security-zone name untrust
import int Gigabitethernet 1/0/1
quit
int g1/0/0
ip address 192.168.20.154 24
quit
security-zone name trust
import int GigabitEthernet 1/0/0
quit
ospf 1
如果不配置router-id会自动从防火墙上的两个接口上选择一个ip做router-id
area 0
network 10.1.1.2 0.0.0.0
quit
area 2
network 192.168.20.0 0.0.0.255
quit
quit
display ospf peer(查看是否能建立邻居关系)
发现两个防火墙建不了,因为要放行一个策略,使local区域可以访问untrust区域,untrust区域可以访问local区域

F10901:security-policy ip
rule name LtoU
source-zone local
destination-zone untrust
service ospf
action pass
quit
rule name UtoL
source-zone untrust
destination-zone local
service ospf
action pass
quit
quit
F10902:security-policy ip
rule name LtoU
security-zone local
destination-zone untrust
service ospf
action pass
quit
rule name UtoL
source-zone untrust
destination-zone local
aervice ospf
action pass
quit
quit

这样就建立了ospf邻居关系
查询ospf的routing:

此时pc5不能访问pc7
因为没有放行trust区域到untrust区域,同样也要放行untrust区域到trust区域,因为要回包
F10901:security-policy ip
rule name TtoU
source-zone trust
destination-zone untrust
source-ip-subnet 192.168.10.0 24
destination-ip-subnet 192.168.20.0 24
action pass
quit
rule name UtoT
source-zone untrust
destination-zone trust
source-ip-subnet 192.168.20.0 24
destination-ip subnet 192.168.10.0 24
action pass
F10902:security-policy ip
rule name TtoU
source-zone trust
destination-zone untrust
source-ip-subnet 192.168.20.0 24
destination-ip-subnet 192.168.10.0 24
action pass
quit
rule name UtoT
source-zone untrust
destination-zone trust
source-ip-subnet 192.168.10.0 24
destination-ip-subnet 192.168.20.0 24
action pass
quit
pc5可以ping通pc7了,pc7也可以回访

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值