防火墙作为最外层,在下面情况下,防火墙ping不通3层的地址
即防火墙192.168.0.1 ping 不通 三层192.168.0.2
将防火墙的5口改位二层口后可以正常使用
{
#
interface GigabitEthernet1/0/5
port link-mode bridge
port port link-type trunk
port trunk permit vlan all
#
vlan 10
interface Vlan-interface10
ip address 192.168.0.1 255.255.255.0
#
security-zone name Trust
import interface Vlan-interface10
}
这么配置是可以使用的嘛,外网口是3层模式,内网口是二层模式。
3层:
#
vlan 2 to 10
#
interface Vlan-interface vlan1
ip address 192.168.1.1 255.255.255.0
dhcp server ip-pool 1
network 192.168.1.0 mask 255.255.255.0
gateway-list 192.168.1.1
dns-list 192.168.1.20 192.168.1.19
#
interface Vlan-interface vlan10
ip address 192.168.0.2 255.255.255.0
#
interface GigabitEthernet1/0/23
port link-type trunk
port trunk permit vlan all
#
ip route-static 0.0.0.0 0.0.0.0 192.168.0.1
防火墙 :
#
object-group ip address 192.168.0.0
0 network subnet 192.168.0.0
255.255.255.0
#
object-group ip address 192.168.1.0
0 network subnet 192.168.1.0 255.255.255.0
#
interface GigabitEthernet1/0/5
port link-mode route
ip address 192.168.0.1 255.255.255.0
#
太多不一一列举,括号的object-policy ip 皆已创建
object-policy ip Any-Any(Local-Trust Local-Untrust Trust-Local Trust-Trust Trust-Untrust Untrust-Local Untrust-Trust)
rule 0 pass
#
security-zone name Trust
import interface GigabitEthernet1/0/5
#
security-zone name Untrust
import interface GigabitEthernet1/0/4
#
同上全部创建
zone-pair security source Any destination Any( Local-Trust Local-Untrust Trust-Local Trust-Trust Trust-Untrust Untrust-Local Untrust-Trust )
object-policy apply ip Any-Any
#
ip route-static 192.168.0.0 24 192.168.0.2
ip route-static 192.168.1.0 24 192.168.0.2
#
acl advanced 3000
rule 0 permit ip
(0)
最佳答案
您好,请知:
关于防火墙无法PING通,以下是排查要点,请参考:
1、由于端口的模式已变动,因此需要重新将端口加入到安全域内。
2、防火墙上涉及到的物理端口、int vlan等接口都要加入安全域,并放通安全策略或域间策略,尤其是到LOCAL域的策略。
(0)
不能在防火墙 interface GigabitEthernet1/0/5 port link-mode route ip address 192.168.0.1 255.255.255.0 3层 interface GigabitEthernet1/0/23 port link-type trunk port trunk permit vlan all 的情况下弄通嘛
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
不能在防火墙 interface GigabitEthernet1/0/5 port link-mode route ip address 192.168.0.1 255.255.255.0 3层 interface GigabitEthernet1/0/23 port link-type trunk port trunk permit vlan all 的情况下弄通嘛