综合实验
一、搭建拓扑图
二、实验步骤
1、基础配置








2、配置IP接口
[FW]interface GigabitEthernet 0/0/0
[FW-GigabitEthernet0/0/0]service-manage all permit
[FW]interface GigabitEthernet 1/0/0
[FW-GigabitEthernet1/0/0]ip address 192.168.1.254 255.255.255.0
[FW-GigabitEthernetl/0/0]interface GigabitEthernet 1/0/1
[FW-GigabitEthernet1/0/1]ip address 13.0.0.254 255.255.255.0
[FW-GigabitEthernetl/0/l]interface GigabitEthernet 1/0/2
[FW-GigabitEthernet1/0/2]ip address 12.0.0.254 255.255.255.0
[r1]interface GigabitEthernet 0/0/0
[r1-GigabitEthernet0/0/0]ip address 13.0.0.1 255.255.255.0
[r1-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r1-GigabitEthernet0/0/1]ip address 100.1.1.254 255.255.255.0
[r1-GigabitEthernet0/0/l]interface GigabitEthernet 0/0/2
[r1-GigabitEthernet0/0/2]ip address 110.1.1.254 255.255.255.0
[r2]interface GigabitEthernet 0/0/0
[r2-GigabitEthernet0/0/0]ip address 12.0.0.1 255.255.255.0
[r2-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r2-GigabitEthernet0/0/llip add 200.1.1.254 255.255.255.0
[r2-GigabitEthernet0/0/l]interface GigabitEthernet 0/0/2
[r2-GigabitEthernet0/0/2]ip add 210.1.1.254 255.255.255.0

3、创建安全区域


4、导入运营商地址

创建链路接口



5、配置真实DNS服务器

6、配置虚拟DNS服务器

7、启动透明代理功能

[FW]dns-transparent-policy
[FW1-policy-dns]dns transparent-proxy enable
[FW-policy-dns]dns server bind interface GigabitEthernet 1/0/1 preferred 100.1.1.1
[FW-policy-dns]dns server bind interface GigabitEthernet 1/0/2 preferred 200.1.1.1
8、安全策略配置

9、NAT配置

596

被折叠的 条评论
为什么被折叠?



