1.配置主机IP
2.配置防火墙IP
3.配置路由器IP
4.配置区域
5.配置安全策略
6.设置静态路由
例子:
PC9 ping通 PC10
PC9 ping通 3.3.3.3
R2 ping通 pc9
1.配置主机IP
2.配置防火墙IP
sys
sysname FW4
interface GigabitEthernet 1/0/0
ip address 1.1.1.254 24
interface GigabitEthernet 1/0/1
ip address 2.2.2.2 24
3.配置路由器IP
[R2]
sys
sysname R2
interface Ethernet 0/0/0
ip address 2.2.2.1 24
interface Ethernet 0/0/1
ip address 3.3.3.1 24
[R3]
sys
sysname R3
interface Ethernet 0/0/1
ip address 3.3.3.3 24
interface g 0/0/0
ip address 4.4.4.254 24
4.配置区域
firewall zone trust
add interface GigabitEthernet 1/0/0
firewall zone name isp
set priority 10
add interface GigabitEthernet 1/0/1
5.设置静态路由
【fw4】
ip route-static 4.4.4.0 24 2.2.2.1
ip route-static 3.3.3.0 24 2.2.2.1
【R2】
ip route-static 1.1.1.0 24 2.2.2.2
ip route-static 4.4.4.0 24 3.3.3.3
【R3】
ip route-static 1.1.1.0 24 3.3.3.1
6.配置安全策略
security-policy
rule name 1
source-zone trust
destination-zone isp
source-address 1.1.1.1 32
destination-address 4.4.4.4 32
service icmp
action permit
rule name 2
source-zone trust
destination-zone isp
source-address 1.1.1.1 32
destination-address 3.3.3.3 32
service icmp
action permit
rule name 3
source-zone isp
destination-zone trust
source-address 2.2.2.1 24
destination-address 1.1.1.1 32
service icmp
action permit