目前做的SSLVPN是可以通内网,坐在防火墙F1090上但是进入内网后无法和互联网通信了,想做的效果是既能访问内网也可以访问互联网下面是配置,想问问是不是漏了哪一步?
interface SSLVPN-AC1 ip address 172.100.181.1 255.255.255.0
#
security-zone name SSLVPN import interface SSLVPN-AC1
#
sslvpn ip address-pool SSLPOOL-ZZ 172.100.182.66 172.100.182.70
#
sslvpn gateway SSLVPNGW ip address 172.100.110.14 port 4433 service enable
#
sslvpn context SSLVPN gateway SSLVPNGW
ip-tunnel interface SSLVPN-AC1
ip-tunnel address-pool SSLPOOL mask 255.255.255.0
ip-tunnel dns-server primary 223.6.6.6
ip-tunnel dns-server secondary 223.5.5.5
ip-route-list NEIWANG-ZZ
include 172.100.100.0 255.255.255.0
include 192.168.27.0 255.255.255.0
include 192.168.28.3 255.255.255.255
include 192.168.29.0 255.255.255.0
include 192.168.30.1 255.255.255.255
policy-group SSLVPNZIYUANGROUP-ZZ
filter ip-tunnel acl 3993
ip-tunnel access-route force-all
ip-tunnel access-route ip-route-list NEIWANG-ZZ
ip-tunnel address-pool SSLPOOL-ZZ mask 255.255.255.248
user manage-zzadmin
ip-tunnel bind address 172.100.182.65-172.100.182.70
service enable
#
# acl advanced 3993
rule 0 permit ip destination 192.168.29.0 0.0.0.255
rule 5 permit ip destination 192.168.27.0 0.0.0.255
rule 15 permit ip destination 192.168.28.3 0
rule 20 permit ip destination 192.168.30.1 0
#
security-policy ip
rule 6 name GuideSecPolicy
description 上网
action pass
disable
logging enable
counting enable
profile 6_IPv4
source-zone Trust
destination-zone Untrust
source-ip 172.100.200.*网段
source-ip 172.100.100.*网段
rule 7 name Any-To-Local
action pass
disable
logging enable
counting enable
profile 7_IPv4
destination-zone Local
rule 0 name Trust-Untrust
action pass
logging enable
counting enable
profile 0_IPv4
source-zone Trust
destination-zone Untrust
rule 1 name Untrust-Trust
action pass
logging enable
counting enable
profile 1_IPv4
source-zone Untrust
destination-zone Trust
rule 2 name Trust-Local
action pass
logging enable
counting enable
profile 2_IPv4
source-zone Trust
destination-zone Local
rule 3 name Lcoal-Trust
action pass
logging enable
counting enable
profile 3_IPv4
source-zone Local
destination-zone Trust
rule 4 name Lcoal-Untrust
action pass
logging enable
counting enable
profile 4_IPv4
source-zone Local
destination-zone Untrust
rule 5 name Untrust-Local 、
action pass
logging enable
counting enable
profile 5_IPv4
source-zone Untrust
destination-zone Local
service 4433
rule 8 name trust-trust
action pass disable
counting enable
profile 8_IPv4
source-zone Trust
destination-zone Trust
rule 10 name SSLVPN-Trust
action pass
counting enable
profile 10_IPv4
source-zone SSLVPN
destination-zone Trust #
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论