客户端ping 内网可以看到会话,ping外网全部timeout,在F100上看不到会话
但是同样的配置在MSR3610-X1上是没问题的,客户端访问内网外网都是通的,外网流量也确认是走了设备侧的。
F100的主要配置如下,请大神们帮忙看看,谢谢
#
version 7.1.064, Release 9510P12
#
sysname H3C
#
ip pool l2tp1 10.0.0.2 10.0.0.20
#
interface Virtual-Template1
ppp authentication-mode chap
remote address pool l2tp1
ppp account-statistics enable
ip address 10.0.0.1 255.255.255.0
#
interface NULL0
#
interface Vlan-interface1
#
interface GigabitEthernet1/0/1
port link-mode route
combo enable copper
tcp mss 1280
pppoe-client dial-bundle-number 1
#
interface GigabitEthernet1/0/4
port link-mode route
ip address 192.168.20.1 255.255.255.0
tcp mss 1280
#
object-policy ip Any-Any
rule 0 pass
#
object-policy ip Trust-Trust
rule 0 pass
#
object-policy ip Trust-Untrust
rule 0 pass
#
object-policy ip Untrust-Local
rule 0 pass
#
object-policy ip Untrust-Trust
rule 0 pass
#
object-policy ip pass
rule 0 pass
#
security-zone name Local
#
security-zone name Trust
import interface GigabitEthernet1/0/4
import interface GigabitEthernet1/0/5
import interface GigabitEthernet1/0/6
import interface GigabitEthernet1/0/7
import interface GigabitEthernet1/0/8
import interface GigabitEthernet1/0/9 vlan 1
import interface GigabitEthernet1/0/10 vlan 1
#
security-zone name DMZ
#
security-zone name Untrust
import interface Dialer1
import interface GigabitEthernet1/0/1
import interface GigabitEthernet1/0/11
import interface Virtual-Template1
import interface GigabitEthernet1/0/2 vlan 1
import interface GigabitEthernet1/0/3 vlan 1
#
security-zone name Management
import interface GigabitEthernet1/0/0
#
zone-pair security source Any destination Any
object-policy apply ip Any-Any
#
zone-pair security source Local destination Trust
object-policy apply ip pass
#
zone-pair security source Local destination Untrust
object-policy apply ip pass
#
zone-pair security source Trust destination Local
object-policy apply ip pass
#
zone-pair security source Trust destination Trust
object-policy apply ip Trust-Trust
#
zone-pair security source Trust destination Untrust
object-policy apply ip Trust-Untrust
#
zone-pair security source Untrust destination Local
object-policy apply ip Untrust-Local
#
zone-pair security source Untrust destination Trust
object-policy apply ip Untrust-Trust
#
domain system
#
l2tp-group 1 mode lns
allow l2tp virtual-template 1
undo tunnel authentication
tunnel name H3C-LNS
#
l2tp enable
#
return
(1)
你配置没贴完整啊
先创建
acl basic 2000
description NAT
rule 100 permit source 10.0.0. 0 0.0.0.255
然后在ppp拨号模版里面
nat outbound 2000
(0)
感谢指点,我在拨号里面有nat outbound 3888,其中有 rule permit ip
大佬你厉害啊,我加到trust果然行了。可是为什么呢? 我已经有any - any 的放行策略了呀
内外网接口是什么呢?看安全策略全放通优先考虑接口是不是忘记加安全域了,所有的接口需要加域逻辑接口
(0)
您好 内网 GigabitEthernet1/0/4 外网 GigabitEthernet1/0/1 绑定拨号 都加了安全域的
您好 内网 GigabitEthernet1/0/4 外网 GigabitEthernet1/0/1 绑定拨号 都加了安全域的
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
大佬你厉害啊,我加到trust果然行了。可是为什么呢? 我已经有any - any 的放行策略了呀