华三模拟器内网设备可以ping通防火墙,防火墙可以ping通外网,做过nat,但是内网设备ping不通外网,接口也加进了相应的区域,是不是还少了什么没有配?
security-policy ip
rule 0 name Trust-Untrust
action pass
source-zone Trust
destination-zone Untrust
source-ip Trust rule 1 name Local-Trust
action pass
source-zone Local
destination-zone Trust
rule 2 name Local-Untrust
action pass
source-zone Local
destination-zone Untrust
rule 3 name Trust-Local
action pass
source-zone Trust
destination-zone Local
rule 4 name Untrust-Local
action pass source-zone Untrust
destination-zone Local
rule 5 name Untrust-Trust
action pass
source-zone Untrust
destination-zone Trust
security-zone name Local
#
security-zone name Trust
import interface GigabitEthernet1/0/1
import interface GigabitEthernet1/0/2
#
security-zone name DMZ
#
security-zone name Untrust
import interface GigabitEthernet1/0/0
#
security-zone name Management
acl advanced 3000
rule 0 permit ip
interface GigabitEthernet1/0/0
port link-mode route
combo enable copper
ip address dhcp-alloc
nat outbound 3000
设置列表
对齐方式
(0)
加一条路由看看,以下是参考命令:
ip route-static 0.0.0.0 0.0.0.0 gi 1/0/0
(0)
不行
不行
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
允许所有了 上面有防火墙配置