防火墙3口与交换机31口互联
=====================================
防火墙侧配置
ip vpn-instance hongyu
interface GigabitEthernet1/0/3.111
vlan-type dot1q vid 111
ip binding vpn-instance hongyu
ip address 192.168.111.11 255.255.255.0
quit
security-zone name hongyu
import interface GigabitEthernet1/0/3.111
quit
security-policy ip
rule name hongyu_zone_local
action pass
vrf hongyu
source-zone hongyu
destination-zone Local
quit
rule name local_hongyu_zone
action pass
vrf hongyu source-zone Local
destination-zone hongyu
quit
=====================================
交换机侧配置
interface GigabitEthernet 1/0/31
port link-mode route
quit
ip vpn-instance hongyu quit
interface Ten-GigabitEthernet1/0/31.111
ip binding vpn-instance hongyu
ip address 192.168.111.10 255.255.255.0
quit
一样的配置HCL中F1060网络可通,物理F1010防火墙却不通.
防火墙上
ping -vpn-instance hongyu 192.168.111.10
交换机上
ping -vpn-instance hongyu 192.168.111.11
配置如上
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论