问题描述:
接口引入安全域后链路断开,安全策略昨晚业务及ospf都未恢复
组网及组网描述:
ip配置:
interface GigabitEthernet0/1
port link-mode route
combo enable copper
ip address 172.16.0.5 255.255.255.252
#
interface GigabitEthernet0/2
port link-mode route
combo enable copper
ip address 172.16.0.2 255.255.255.252
ospf配置:
ospf 1
area 0.0.0.0
network 172.16.0.0 0.0.0.3
network 172.16.0.4 0.0.0.3
安全策略配置:
security-zone name Trust
import interface GigabitEthernet0/2
security-zone name Untrust
import interface GigabitEthernet0/1
zone-pair security source Trust destination Untrust
packet-filter 3500
acl advanced 3500
rule 0 permit ip
rule 5 permit ospf
rule 10 permit icmp
rule 15 permit tcp
做完后链路状态:
Interface Physical Protocol IP Address Description
GE0/0 down down -- --
GE0/1 up up 172.16.0.5 --
GE0/2 up up 172.16.0.2 --
暂无评论