内网互联地址10.10.34.1通过防火墙接入,通过200.1.1.X接入INTERNET,组网图如下
interface GigabitEthernet1/0/0
undo shutdown
ip address 10.10.34.1 255.255.255.252
service-manage ping permit /端口可以被PING通
#
interface GigabitEthernet1/0/1
undo shutdown
ip address 200.1.1.2 255.255.255.252
service-manage ping permit
接口加入安全组
firewall zone trust
set priority 85
add interface GigabitEthernet0/0/0
add interface GigabitEthernet1/0/0
#
firewall zone untrust
set priority 5
add interface GigabitEthernet1/0/1
配置安全策略
security-policy
rule name in_out
source-zone trust
destination-zone untrust
service icmp
action permit
rule name local_trust //本地能与trust和untrust区域相通
source-zone local
des