设备配置了ospf,看状态也是FULL,但是无法ping通。

<FW>display current-configuration
#
version 7.1.064, Alpha 7164
#
sysname FW
#
context Admin id 1
#
telnet server enable
#
irf mac-address persistent timer
irf auto-update enable
undo irf link-delay
irf member 1 priority 1
#
ospf 1 router-id 3.3.3.3
area 0.0.0.0
network 3.3.3.3 0.0.0.0
network 10.2.2.0 0.0.0.3
network 10.3.3.0 0.0.0.3
#
xbar load-single
password-recovery enable
lpu-type f-series
#
vlan 1
#
object-group service icmp
#
interface NULL0
#
interface LoopBack2
ip address 3.3.3.3 255.255.255.255
#
interface GigabitEthernet1/0/0
port link-mode route
combo enable copper
ip address 10.2.2.2 255.255.255.252
#
interface GigabitEthernet1/0/1
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/2
port link-mode route
combo enable copper
ip address 10.3.3.1 255.255.255.252
#
interface GigabitEthernet1/0/3
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/4
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/5
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/6
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/7
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/8
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/9
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/10
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/11
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/12
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/13
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/14
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/15
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/16
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/17
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/18
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/19
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/20
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/21
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/22
port link-mode route
combo enable copper
#
interface GigabitEthernet1/0/23
port link-mode route
combo enable copper
#
security-zone name Local
#
security-zone name Trust
import interface GigabitEthernet1/0/2
#
security-zone name DMZ
#
security-zone name Untrust
import interface GigabitEthernet1/0/0
#
security-zone name Management
import interface GigabitEthernet1/0/1
#
scheduler logfile size 16
#
line class aux
user-role network-operator
#
line class console
user-role network-admin
#
line class tty
user-role network-operator
#
line class vty
user-role network-operator
#
line aux 0
user-role network-admin
#
line con 0
user-role network-admin
#
line vty 0 4
authentication-mode scheme
user-role network-admin
#
line vty 5 63
user-role network-operator
#
domain system
#
aaa session-limit ftp 16
aaa session-limit telnet 16
aaa session-limit ssh 16
domain default enable system
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role
#
role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
user-group system
#
local-user admin class manage
password hash $h$6$UbIhNnPevyKUwfpm$LqR3+yg1IjNct39MkOR0H0iQXLkYB3jMqM4vbAeoXOhbabIIFnjJPEGR00YiYA1Sz4LiY3FmEdru2fOLMb1shQ==
service-type telnet terminal http https
authorization-attribute user-role level-3
authorization-attribute user-role network-admin
authorization-attribute user-role network-operator
#
ip http enable
ip https enable
#
security-policy ip
rule 0 name ospflocalin
action pass
source-zone untrust
destination-zone local
service ospf
rule 1 name ospflocalout
action pass
source-zone local
destination-zone untrust
service ospf
rule 2 name trust-untrust
action pass
source-zone trust
destination-zone untrust
source-ip-subnet 192.168.10.0 255.255.255.0
source-ip-subnet 192.168.20.0 255.255.255.0
destination-ip-subnet 0.0.0.0 0.0.0.0
rule 3 name untrust-trust
action pass
source-zone untrust
destination-zone trust
source-ip-subnet 0.0.0.0 0.0.0.0
destination-ip-subnet 192.168.10.0 255.255.255.0
destination-ip-subnet 192.168.20.0 255.255.255.0
rule 4 name trust-local-ospf
action pass
source-zone trust
destination-zone local
service ospf
rule 5 name local-trust-ospf
action pass
source-zone local
destination-zone trust
service ospf
rule 6 name local-untrust-icmp
action pass
source-zone local
destination-zone untrust
service icmp
rule 7 name untrust-local-icmp
action pass
source-zone untrust
destination-zone local
service icmp
#
return
<FW>
最佳答案
故障核心结论
OSPF 邻居能达到 FULL,代表路由层面互通、OSPF 报文放通;无法 ping 通跨域网段根源是:安全策略缺少 ICMP 放行规则,且 Trust、Untrust、Local 域之间无通用 ICMP 允许策略。
一、先梳理安全域划分
Untrust 域:G1/0/0,地址10.2.2.2,对接出口路由器 L1(2.2.2.2)
Trust 域:G1/0/2,地址10.3.3.1,对接核心交换机 L3(4.4.4.4)
Local 域:防火墙本机 LoopBack、接口 IP、设备自身
现有安全策略缺陷:
仅放行 OSPF、特定业务网段双向通行,但没有全局 ICMP 允许规则;
规则 2/3 仅放行192.168.10.0/24、192.168.20.0/24,你当前互联网段10.2.2.0/30、10.3.3.0/30不在此范围内;
跨域 ICMP 报文全部被默认拒绝,ping 不通。
二、分场景问题拆解
场景 1:FW ping 对端直连设备(出口 2.2.2.2 / 核心 4.4.4.4)
FW ping 2.2.2.2:源 ZOne=Local,目的 ZOne=Untrust
现有仅规则 6 放行 Local→Untrust ICMP,理论能通;
若不通,检查:
出口路由器回程路由是否存在10.2.2.0/30;
确认 FW 本地策略 6 生效。
FW ping 4.4.4.4:源 ZOne=Local,目的 ZOne=Trust
当前无任何 Local→Trust ICMP 放行规则,ICMP 报文直接丢弃,完全 ping 不通。
场景 2:PC 终端跨网段互访 / PC ping 出口
PC 网段不属于192.168.10/20,规则 2、3 匹配不到,流量被阻断;
直连互联网段10.2.2.0/30、10.3.3.0/30也不在现有允许子网内。
三、完整修复配置(直接复制粘贴)
1. 补齐各域之间 ICMP 互通策略
plaintext
system-view
security-policy ip
# 补充Local与Trust域ICMP(FW本机ping内网交换机)
rule 8 name local-trust-icmp
action pass
source-zone local
destination-zone trust
service icmp
rule 9 name trust-local-icmp
action pass
source-zone trust
destination-zone local
service icmp
# 补充Trust与Untrust全网段ICMP(内网ping外网、跨直连网段互通)
rule 10 name trust-untrust-icmp
action pass
source-zone trust
destination-zone untrust
service icmp
rule 11 name untrust-trust-icmp
action pass
source-zone untrust
destination-zone trust
service icmp
# 放开互联直连网段10.2.2.0/30、10.3.3.0/30双向通行(原有规则只放192.168段)
rule 12 name trust-untrust-all-subnet
action pass
source-zone trust
destination-zone untrust
rule 13 name untrust-trust-all-subnet
action pass
source-zone untrust
destination-zone trust
说明:规则 12/13 会放行 Trust/Untrust 之间所有 IP 流量,适合内网生产环境;若需要精细化,可替换为指定10.2.2.0/30、10.3.3.0/30子网。
2. 验证命令
plaintext
# 查看OSPF路由是否完整学习
display ip routing-table protocol ospf
# 查看安全策略命中计数,确认ICMP规则有hit
display security-policy ip statistics
# 测试连通性
ping 4.4.4.4
ping 2.2.2.2
四、补充排查点
确认接口全部加入对应安全域:
plaintext
display security-zone interface
G1/0/0 归属 Untrust、G1/0/2 归属 Trust,不能遗漏。
2. 检查对端设备路由:
出口路由器需要静态路由10.3.3.0 255.255.255.252 10.2.2.2;
核心交换机需要静态路由10.2.2.0 255.255.255.252 10.3.3.1。
3. 若仅能通路由、ping 不通,100% 是安全策略缺失 ICMP 规则,配置上面策略即可解决。
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论