网络拓扑图和背景说明
要求:
1、中控室网段通过防火墙使用10M专线上网,不与办公网互通。
2、办公网网段通过防火墙使用100M专线上网,可以互通。
拓扑图
防火墙配置:
通过策略路由控制不同网段访问不同的外网出口。
<FW>dis cu
#
version 7.1.064, Alpha 7164
#
sysname FW
#
context Admin id 1
#
telnet server enable
#
irf mac-address persistent timer
irf auto-update enable
undo irf link-delay
irf member 1 priority 1
#
xbar load-single
password-recovery enable
lpu-type f-series
#
vlan 1
#
object-group ip address bangong
#
object-group ip address youxian
0 network subnet 192.168.1.0 255.255.255.0
10 network subnet 192.168.2.0 255.255.255.0
20 network subnet 192.168.3.0 255.255.255.0
#
policy-based-route bangong permit node 5
if-match acl 3000
apply next-hop 202.106.0.20
#
policy-based-route bangong permit node 10
if-match acl 3001
apply next-hop 202.106.2.2
#
interface NULL0
#
interface GigabitEthernet1/0/0
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/1
port link-mode route
combo enable copper
ip address 192.168.0.1 255.255.255.0
#
interface GigabitEthernet1/0/2
port link-mode route
combo enable copper
ip address 202.106.0.21 255.255.255.0
nat outbound 2000
#
interface GigabitEthernet1/0/3
port link-mode route
combo enable copper
ip address 202.106.2.3 255.255.255.0
nat outbound 2001
#
interface GigabitEthernet1/0/4
port link-mode route
combo enable copper
ip address 192.168.100.253 255.255.255.0
ip policy-based-route bangong
#
interface GigabitEthernet1/0/5
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/6
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/7
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/8
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/9
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/10
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/11
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/12
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/13
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/14
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/15
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/16
port link-mode route
combo enable copper
#
interface