[FW1]firewall zone trust1
[FW1-zone-trust]add interface GigabitEthernet 1/0/0
[FW1]firewall zone name Untrust_1
[FW1-zone-Untrust_1]set priority 70
[FW1-zone-Untrust_1]add interface GigabitEthernet 1/0/1
[FW1]firewall zone name Untrust_2
[FW1-zone-Untrust_2]set priority 80
[FW1-zone-Untrust_2]add interface GigabitEthernet 1/0/2
(3)创建DNS服务器
[FW1]slb enable
[FW1]slb
[FW1-slb]
[FW1-slb]group 0 dns
[FW1-slb-group-0]rserver 0 rip 200.1.1.1 port 53
[FW1-slb-group-0]rserver 1 rip 100.1.1.1 port 53
[FW1]slb
[FW1-slb]vserver 0 dns
[FW1-slb-vserver-0]vip 10.10.10.10
[FW1-slb-vserver-0]group dns
(4)DNS服务器透明代理功能
[FW1-policy-dns]dns server bind interface GigabitEthernet 1/0/1 preferred 100.1.1.1
[FW1-policy-dns]dns server bind interface GigabitEthernet 1/0/2 preferred 200.1.1.1
[FW1-policy-dns]rule name dns_policy
[FW1-policy-dns-rule-dns_policy]source-address 192.168.1.0 24
[FW1-policy-dns-rule-dns_policy]enable
Info: The policy is enabled successfully.
[FW1-policy-dns-rule-dns_policy]action tpdns