华三模拟器内网设备可以ping通防火墙,防火墙可以ping通外网,做过nat,但是内网设备ping不通外网,接口也加进了相应的区域,是不是还少了什么没有配?
security-policy ip
rule 0 name Trust-Untrust
action pass
source-zone Trust
destination-zone Untrust
source-ip Trust rule 1 name Local-Trust
action pass
source-zone Local
destination-zone Trust
rule 2 name Local-Untrust
action pass
source-zone Local
destination-zone Untrust
rule 3 name Trust-Local
action pass
source-zone Trust
destination-zone Local
rule 4 name Untrust-Local
action pass source-zone Untrust
destination-zone Local
rule 5 name Untrust-Trust
action pass
source-zone Untrust
destination-zone Trust
security-zone name Local
#
security-zone name Trust
import interface GigabitEthernet1/0/1
import interface GigabitEthernet1/0/2
#
security-zone name DMZ
#
security-zone name Untrust
import interface GigabitEthernet1/0/0
#
security-zone name Management
acl advanced 3000
rule 0 permit ip
interface GigabitEthernet1/0/0
port link-mode route
combo enable copper
ip address dhcp-alloc
nat outbound 3000
设置列表
(0)
最佳答案
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
信息不全 rule 0 name Trust-Untrust action pass source-zone Trust destination-zone Untrust source-ip Trust //这个地址得包括转换前的地址