配置文件如下
我想让10.32.217.221(接在GE6) 通过 192.168.101.1(接在GE3)这个路由器上互联网,哪里有问题啊
# version 7.1.070, Release 6113 # sysname H3C # irf mac-address persistent timer irf auto-update enable undo irf link-delay irf member 1 priority 1 # lldp global enable # password-recovery enable # vlan 1 # stp global enable # interface NULL0 # interface Vlan-interface1 ip address 192.168.101.252 255.255.255.0 # interface GigabitEthernet1/0/1 # interface GigabitEthernet1/0/2 # interface GigabitEthernet1/0/3 # interface GigabitEthernet1/0/4 # interface GigabitEthernet1/0/5 packet-filter 3000 inbound # interface GigabitEthernet1/0/6 packet-filter 3001 inbound # interface GigabitEthernet1/0/7 # interface GigabitEthernet1/0/8 # interface GigabitEthernet1/0/9 # interface GigabitEthernet1/0/10 # interface GigabitEthernet1/0/11 # interface GigabitEthernet1/0/12 # interface GigabitEthernet1/0/13 # interface GigabitEthernet1/0/14 # interface GigabitEthernet1/0/15 # interface GigabitEthernet1/0/16 # interface GigabitEthernet1/0/17 # interface GigabitEthernet1/0/18 # interface GigabitEthernet1/0/19 # interface GigabitEthernet1/0/20 # interface GigabitEthernet1/0/21 # interface GigabitEthernet1/0/22 # interface GigabitEthernet1/0/23 # interface GigabitEthernet1/0/24 # interface GigabitEthernet1/0/25 # interface GigabitEthernet1/0/26 # interface GigabitEthernet1/0/27 # interface GigabitEthernet1/0/28 # scheduler logfile size 16 # line class aux user-role network-admin # line class vty user-role network-operator # line aux 0 user-role network-admin # line vty 0 63 user-role network-operator # ip route-static 0.0.0.0 0 192.168.101.1 # acl advanced 3000 rule 1 permit ip source 10.32.217.220 0 destination 10.32.217.0 0.0.0.25 rule 20 deny ip # acl advanced 3001 rule 0 deny tcp source 10.32.217.221 0 destination 10.32.217.221 0 established rule 1 permit ip source 10.32.217.221 0 destination 10.32.217.221 0 rule 5 deny ip source 10.32.217.221 0 destination 10.32.217.0 0.0.0.255 rule 10 permit ip # acl advanced 3002 rule 5 deny ip source 10.32.217.221 0 destination 10.32.217.0 0.0.0.255 rule 10 permit ip # radius scheme system user-name-format without-domain # domain system # domain default enable system #
(0)
最佳答案
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论