GRE 通用路由封装协议
IP协议号 47
FW1配置
#
interface GigabitEthernet1/0/0
undo shutdown
ip address 10.0.0.254 255.255.255.0
#
interface GigabitEthernet1/0/1
undo shutdown
ip address 1.1.1.1 255.255.255.0
service-manage ping permit
#
#
interface Tunnel1 //配置GRE隧道 tunnel 1
ip address 172.16.1.1 255.255.255.0 //添加隧道源地址
tunnel-protocol gre //隧道类型为GRE
source 1.1.1.1 //源接口地址
destination 2.2.2.2 //目的接口地址
#
firewall zone trust
add interface GigabitEthernet1/0/0 //将内网接口加入trust区域
#
firewall zone untrust //将外网和隧道接口加入untrust区域
add interface GigabitEthernet1/0/1
add interface Tunnel1
#
ip route-static 2.2.2.2 255.255.255.255 1.1.1.254 //指向防火墙2的路由
ip route-static 192.168.1.0 255.255.255.0 Tunnel1 //将目的地址为192.168.1.0 24位地址封装在tunnel隧道内
#
#
security-policy //实验环境下安全策略全放行
default action permit
#
R1配置(仅仅只有接口配置)
#
interface GigabitEthernet0/0/0
ip address 2.2.2.254 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 1.1.1.254 255.255.255.0
#
FW2配置
#
interface GigabitEthernet1/0/0
undo shutdown
ip address 192.168.1.254 255.255.255.0
#
interface GigabitEthernet1/0/1
undo shutdown
ip address 2.2.2.2 255.255.255.0
service-manage ping permit
#
#
interface Tunnel1 //配置GRE隧道 tunnel 1
ip address 172.16.1.2 255.255.255.0 //添加隧道源地址
tunnel-protocol gre //隧道类型为GRE
source 2.2.2.2 //源接口地址
destination 1.1.1.1 //目的接口地址
#
#
ip route-static 1.1.1.1 255.255.255.255 2.2.2.254 //指向防火墙1的路由
ip route-static 10.0.0.0 255.255.255.0 Tunnel1 //将目的地址为10.0.0.0 24位地址封装在tunnel隧道内
#
#
security-policy //实验环境下安全策略全放行
default action permit
#