对齐方式
运营商分配127位前缀长度的点对点ipv6地址,防火墙ipv6默认路由已经开启,与运营商局端设备连接的untrust区端口也将运营商分配的地址配好,为什么在防火墙上ping对端运营商的ipv6地址ping不通,ICMPv6也都开启,防火墙是F1020
# ipv6 dns server 240E:51:C800:4::4
ipv6 dns server 240E:51:C800:4::8
# object-group ipv6 address TELECOM
security-zone Untrust
0 network host address ::
# object-group ipv6 address v6dmz
0 network subnet 240E:648:2::/64
# object-group service icmpv6
0 service icmpv6
# interface GigabitEthernet1/1/1
port link-mode route
packet-filter ipv6 2000 inbound
ipv6 address 240E:648:0:1::2/127
undo ipv6 nd ra halt
# object-policy ipv6 pass rule 0 pass
# security-zone name Local
# security-zone name Trust import interface GigabitEthernet1/1/3
# security-zone name DMZ import interface GigabitEthernet1/1/2
# security-zone name Untrust import interface GigabitEthernet1/1/1
# zone-pair security source DMZ destination DMZ packet-filter ipv6 2001
# zone-pair security source DMZ destination Local packet-filter ipv6 2001
# zone-pair security source DMZ destination Untrust packet-filter ipv6 2001
# zone-pair security source Local destination Any object-policy apply ipv6 pass
# zone-pair security source Local destination DMZ packet-filter ipv6 2001
# zone-pair security source Local destination Untrust packet-filter ipv6 2001
# zone-pair security source Trust destination Untrust object-policy apply ipv6 pass
# zone-pair security source Untrust destination DMZ packet-filter ipv6 2001
# zone-pair security source Untrust destination Local packet-filter ipv6 2001
# zone-pair security source Untrust destination Untrust packet-filter ipv6 2001
(1)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论