• 全部
  • 经验案例
  • 典型配置
  • 技术公告
  • FAQ
  • 漏洞说明
  • 全部
  • 全部
  • 大数据引擎
  • 知了引擎
产品线
搜索
取消
案例类型
发布者
是否解决
是否官方
时间
搜索引擎
匹配模式
高级搜索

防火墙直连路由器,路由器连外网,防火墙ping不通外网。

2023-02-09提问
  • 0关注
  • 0收藏,635浏览
粉丝:0人 关注:0人

问题描述:

路由器三层口连外网(用4GCPE模拟的),地址192.168.7.x

vlan1接口地址192.168.0.1,端口连防火墙,防火墙vlan1获取到192.168.0.2,ping不通192.168.7.x。

组网及组网描述:


最佳答案

粉丝:9人 关注:6人

接口加安全域了嘛,放通安全策略

我加入安全域提示The specified interface has been added to another security zone。防火墙连的接口在LAN域内

zhiliao_AoTbUP 发表时间:2023-02-09

已经添加到域了,把你的配置发出来看看

奔跑的小马 发表时间:2023-02-09

<H3C>dis security-zone Name: Local Members: None Name: Trust Members: None Name: DMZ Members: None Name: Untrust Members: None Name: Management Members: None Name: LAN Members: Vlan-interface1 GigabitEthernet1/0/0 in VLAN 1 GigabitEthernet1/0/2 in VLAN 1 GigabitEthernet1/0/3 in VLAN 1 GigabitEthernet1/0/4 in VLAN 1 GigabitEthernet1/0/5 in VLAN 1 GigabitEthernet1/0/6 in VLAN 1 GigabitEthernet1/0/7 in VLAN 1

zhiliao_AoTbUP 发表时间:2023-02-10

把你dis cu的配置方便发出来嘛

奔跑的小马 发表时间:2023-02-10

=~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2023.02.10 10:06:17 =~=~=~=~=~=~=~=~=~=~=~= gateway-list 192.168.0.1 [2023/02/10 10:06:17] ---- More ---- network 192.168.0.0 mask 255.255.255.0 [2023/02/10 10:06:17] ---- More ---- address range 192.168.0.2 192.168.0.254 [2023/02/10 10:06:17] ---- More ---- # [2023/02/10 10:06:18] ---- More ---- controller Cellular1/0/0 [2023/02/10 10:06:19] ---- More ---- # [2023/02/10 10:06:19] ---- More ---- controller Cellular1/0/1 [2023/02/10 10:06:19] ---- More ---- # [2023/02/10 10:06:19] ---- More ---- interface NULL0 [2023/02/10 10:06:20] ---- More ---- # [2023/02/10 10:06:21] ---- More ---- interface Vlan-interface1 [2023/02/10 10:06:21] ---- More ---- description LAN-interface [2023/02/10 10:06:21] ---- More ---- ip address dhcp-alloc [2023/02/10 10:06:21] ---- More ---- tcp mss 1280 [2023/02/10 10:06:21] ---- More ---- # [2023/02/10 10:06:21] ---- More ---- interface GigabitEthernet1/0/1 [2023/02/10 10:06:21] ---- More ---- port link-mode route [2023/02/10 10:06:21] ---- More ---- combo enable fiber [2023/02/10 10:06:21] ---- More ---- # [2023/02/10 10:06:21] ---- More ---- interface GigabitEthernet1/0/0 [2023/02/10 10:06:21] ---- More ---- port link-mode bridge [2023/02/10 10:06:21] ---- More ---- combo enable fiber [2023/02/10 10:06:21] ---- More ---- # [2023/02/10 10:06:21] ---- More ---- interface GigabitEthernet1/0/2 [2023/02/10 10:06:21] ---- More ---- port link-mode bridge [2023/02/10 10:06:21] ---- More ---- # [2023/02/10 10:06:21] ---- More ---- interface GigabitEthernet1/0/3 [2023/02/10 10:06:21] ---- More ---- port link-mode bridge [2023/02/10 10:06:21] ---- More ---- # [2023/02/10 10:06:21] ---- More ---- interface GigabitEthernet1/0/4 [2023/02/10 10:06:21] ---- More ---- port link-mode bridge [2023/02/10 10:06:21] ---- More ---- # [2023/02/10 10:06:21] ---- More ---- interface GigabitEthernet1/0/5 [2023/02/10 10:06:21] ---- More ---- port link-mode bridge [2023/02/10 10:06:22] ---- More ---- # [2023/02/10 10:06:22] ---- More ---- interface GigabitEthernet1/0/6 [2023/02/10 10:06:22] ---- More ---- port link-mode bridge [2023/02/10 10:06:22] ---- More ---- # [2023/02/10 10:06:22] ---- More ---- interface GigabitEthernet1/0/7 [2023/02/10 10:06:22] ---- More ---- port link-mode bridge [2023/02/10 10:06:23] ---- More ---- # [2023/02/10 10:06:23] ---- More ---- interface GigabitEthernet1/0/8 [2023/02/10 10:06:23] ---- More ---- port link-mode bridge [2023/02/10 10:06:23] ---- More ---- # [2023/02/10 10:06:23] ---- More ---- interface GigabitEthernet1/0/9 [2023/02/10 10:06:23] ---- More ---- port link-mode bridge [2023/02/10 10:06:23] ---- More ---- # [2023/02/10 10:06:24] ---- More ---- interface GigabitEthernet1/0/10 [2023/02/10 10:06:24] ---- More ---- port link-mode bridge [2023/02/10 10:06:24] ---- More ---- # [2023/02/10 10:06:24] ---- More ---- interface GigabitEthernet1/0/11 [2023/02/10 10:06:24] ---- More ---- port link-mode bridge [2023/02/10 10:06:24] ---- More ---- # [2023/02/10 10:06:25] ---- More ---- security-zone name Local [2023/02/10 10:06:25] ---- More ---- # [2023/02/10 10:06:25] ---- More ---- security-zone name Trust [2023/02/10 10:06:25] ---- More ---- # [2023/02/10 10:06:25] ---- More ---- security-zone name DMZ [2023/02/10 10:06:25] ---- More ---- # [2023/02/10 10:06:28] ---- More ---- security-zone name Untrust [2023/02/10 10:06:28] ---- More ---- # [2023/02/10 10:06:28] ---- More ---- security-zone name Management [2023/02/10 10:06:28] ---- More ---- # [2023/02/10 10:06:28] ---- More ---- security-zone name LAN [2023/02/10 10:06:28] ---- More ---- import interface Vlan-interface1 [2023/02/10 10:06:28] ---- More ---- import interface GigabitEthernet1/0/0 vlan 1 [2023/02/10 10:06:28] ---- More ---- import interface GigabitEthernet1/0/2 vlan 1 [2023/02/10 10:06:28] ---- More ---- import interface GigabitEthernet1/0/3 vlan 1 [2023/02/10 10:06:28] ---- More ---- import interface GigabitEthernet1/0/4 vlan 1 [2023/02/10 10:06:28] ---- More ---- import interface GigabitEthernet1/0/5 vlan 1 [2023/02/10 10:06:28] ---- More ---- import interface GigabitEthernet1/0/6 vlan 1 [2023/02/10 10:06:28] ---- More ---- import interface GigabitEthernet1/0/7 vlan 1 [2023/02/10 10:06:28] ---- More ---- # [2023/02/10 10:06:28] ---- More ---- scheduler logfile size 16 [2023/02/10 10:06:28] ---- More ---- # [2023/02/10 10:06:28] ---- More ---- line class aux [2023/02/10 10:06:28] ---- More ---- user-role network-operator [2023/02/10 10:06:28] ---- More ---- # [2023/02/10 10:06:28] ---- More ---- line class console [2023/02/10 10:06:28] ---- More ---- user-role network-admin [2023/02/10 10:06:28] ---- More ---- # [2023/02/10 10:06:28] ---- More ---- line class vty [2023/02/10 10:06:28] ---- More ---- user-role network-operator [2023/02/10 10:06:28] ---- More ---- # [2023/02/10 10:06:28] ---- More ---- line aux 0 [2023/02/10 10:06:28] ---- More ---- user-role network-admin [2023/02/10 10:06:28] ---- More ---- # [2023/02/10 10:06:28] ---- More ---- line con 0 [2023/02/10 10:06:28] ---- More ---- user-role network-admin [2023/02/10 10:06:29] ---- More ---- # [2023/02/10 10:06:29] ---- More ---- line vty 0 63 [2023/02/10 10:06:29] ---- More ---- authentication-mode scheme [2023/02/10 10:06:29] ---- More ---- user-role network-admin [2023/02/10 10:06:29] ---- More ---- # [2023/02/10 10:06:29] ---- More ---- performance-management [2023/02/10 10:06:29] ---- More ---- # [2023/02/10 10:06:29] ---- More ---- ssh server enable [2023/02/10 10:06:29] ---- More ---- # [2023/02/10 10:06:29] ---- More ---- arp ip-conflict log prompt [2023/02/10 10:06:29] ---- More ---- # [2023/02/10 10:06:29] ---- More ---- domain system [2023/02/10 10:06:29] ---- More ---- # [2023/02/10 10:06:29] ---- More ---- domain default enable system [2023/02/10 10:06:29] ---- More ---- # [2023/02/10 10:06:29] ---- More ---- role name level-0 [2023/02/10 10:06:29] ---- More ---- description Predefined level-0 role [2023/02/10 10:06:29] ---- More ---- # [2023/02/10 10:06:29] ---- More ---- role name level-1 [2023/02/10 10:06:29] ---- More ---- description Predefined level-1 role [2023/02/10 10:06:29] ---- More ---- # [2023/02/10 10:06:29] ---- More ---- role name level-2 [2023/02/10 10:06:29] ---- More ---- description Predefined level-2 role [2023/02/10 10:06:29] ---- More ---- # [2023/02/10 10:06:29] ---- More ---- role name level-3 [2023/02/10 10:06:29] ---- More ---- description Predefined level-3 role [2023/02/10 10:06:29] ---- More ---- # [2023/02/10 10:06:29] ---- More ---- role name level-4 [2023/02/10 10:06:29] ---- More ---- description Predefined level-4 role [2023/02/10 10:06:29] ---- More ---- # [2023/02/10 10:06:29] ---- More ---- role name level-5 [2023/02/10 10:06:29] ---- More ---- description Predefined level-5 role [2023/02/10 10:06:29] ---- More ---- # [2023/02/10 10:06:29] ---- More ---- role name level-6 [2023/02/10 10:06:30] ---- More ---- description Predefined level-6 role [2023/02/10 10:06:30] ---- More ---- # [2023/02/10 10:06:30] ---- More ---- role name level-7 [2023/02/10 10:06:30] ---- More ---- description Predefined level-7 role [2023/02/10 10:06:30] ---- More ---- # [2023/02/10 10:06:30] ---- More ---- role name level-8 [2023/02/10 10:06:30] ---- More ---- description Predefined level-8 role [2023/02/10 10:06:30] ---- More ---- # [2023/02/10 10:06:30] ---- More ---- role name level-9 [2023/02/10 10:06:30] ---- More ---- description Predefined level-9 role [2023/02/10 10:06:30] ---- More ---- # [2023/02/10 10:06:30] ---- More ---- role name level-10 [2023/02/10 10:06:30] ---- More ---- description Predefined level-10 role [2023/02/10 10:06:30] ---- More ---- # [2023/02/10 10:06:31] ---- More ---- role name level-11 [2023/02/10 10:06:31] ---- More ---- description Predefined level-11 role [2023/02/10 10:06:31] ---- More ---- # [2023/02/10 10:06:31] ---- More ---- role name level-12 [2023/02/10 10:06:31] ---- More ---- description Predefined level-12 role [2023/02/10 10:06:31] ---- More ---- # [2023/02/10 10:06:32] ---- More ---- role name level-13 [2023/02/10 10:06:32] ---- More ---- description Predefined level-13 role [2023/02/10 10:06:32] ---- More ---- # [2023/02/10 10:06:32] ---- More ---- role name level-14 [2023/02/10 10:06:32] ---- More ---- description Predefined level-14 role [2023/02/10 10:06:32] ---- More ---- # [2023/02/10 10:06:33] ---- More ---- user-group system [2023/02/10 10:06:33] ---- More ---- # [2023/02/10 10:06:33] ---- More ---- local-user admin class manage [2023/02/10 10:06:33] ---- More ---- password hash $h$6$CqeeSHnNReGazcKl$Zb5sFWr4CfITsDTascif1EbCxnG4XOpxkk5/inTedtnO4ikXxjUi0jK67f/c5JUQVlBWCIzjrp8pUbu6XEna3g== [2023/02/10 10:06:33] ---- More ---- service-type ssh telnet terminal http https [2023/02/10 10:06:34] ---- More ---- authorization-attribute user-role level-3 [2023/02/10 10:06:34] ---- More ---- authorization-attribute user-role network-admin [2023/02/10 10:06:34] ---- More ---- authorization-attribute user-role network-operator [2023/02/10 10:06:34] ---- More ---- # [2023/02/10 10:06:34] ---- More ---- ssl renegotiation disable [2023/02/10 10:06:35] ---- More ---- ssl version ssl3.0 disable [2023/02/10 10:06:35] ---- More ---- ssl version tls1.0 disable [2023/02/10 10:06:35] ---- More ---- undo ssl version tls1.1 disable [2023/02/10 10:06:35] ---- More ---- # [2023/02/10 10:06:35] ---- More ---- ipsec logging negotiation enable [2023/02/10 10:06:38] ---- More ---- # [2023/02/10 10:06:38] ---- More ---- ike logging negotiation enable [2023/02/10 10:06:38] ---- More ---- # [2023/02/10 10:06:38] ---- More ---- netconf soap http enable [2023/02/10 10:06:38] ---- More ---- # [2023/02/10 10:06:38] ---- More ---- ip http enable [2023/02/10 10:06:38] ---- More ---- ip https enable [2023/02/10 10:06:38] ---- More ---- # [2023/02/10 10:06:38] ---- More ---- loadbalance isp file flash:/lbispinfo_v1.5.tp [2023/02/10 10:06:38] ---- More ---- # [2023/02/10 10:06:38] ---- More ---- smartmc enable [2023/02/10 10:06:38] ---- More ---- smartmc password cipher $c$3$CoCblkYhfq9+JP6Gdep5DtGrs1ZbZqaBFJVeauQ= [2023/02/10 10:06:38] ---- More ---- # [2023/02/10 10:06:38] ---- More ---- security-policy ip [2023/02/10 10:06:38] ---- More ---- rule 0 name AUTONET_LOCAL2ANY_DONTMODIFY [2023/02/10 10:06:38] ---- More ---- action pass [2023/02/10 10:06:38] ---- More ---- source-zone local [2023/02/10 10:06:38] ---- More ---- rule 1 name AUTONET_LAN2LOCAL_DONTMODIFY [2023/02/10 10:06:38] ---- More ---- action pass [2023/02/10 10:06:38] ---- More ---- source-zone LAN [2023/02/10 10:06:38] ---- More ---- destination-zone local [2023/02/10 10:06:38] ---- More ---- rule 2 name AUTONET_LAN2LAN_DONTMODIFY [2023/02/10 10:06:38] ---- More ---- action pass [2023/02/10 10:06:38] ---- More ---- source-zone LAN [2023/02/10 10:06:38] ---- More ---- destination-zone LAN [2023/02/10 10:06:38] ---- More ---- # [2023/02/10 10:06:38] ---- More ---- cloud-management server domain secops.h3c.com [2023/02/10 10:06:38] ---- More ---- # [2023/02/10 10:06:38] ---- More ---- return [2023/02/10 10:06:38] ---- More ---- <H3C> [2023/02/10 10:06:38] <H3C> [2023/02/10 10:06:38] <H3C>

zhiliao_AoTbUP 发表时间:2023-02-10
2 个回答
粉丝:171人 关注:8人

检查路由,NAT,安全策略,安全域的配置

粉丝:154人 关注:1人

路由器配置NAT了吗

编辑答案

你正在编辑答案

如果你要对问题或其他回答进行点评或询问,请使用评论功能。

分享扩散:

提出建议

    +

亲~登录后才可以操作哦!

确定

亲~检测到您登陆的账号未在http://hclhub.h3c.com进行注册

注册后可访问此模块

跳转hclhub

你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作

举报

×

侵犯我的权益 >
对根叔社区有害的内容 >
辱骂、歧视、挑衅等(不友善)

侵犯我的权益

×

泄露了我的隐私 >
侵犯了我企业的权益 >
抄袭了我的内容 >
诽谤我 >
辱骂、歧视、挑衅等(不友善)
骚扰我

泄露了我的隐私

×

您好,当您发现根叔知了上有泄漏您隐私的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您认为哪些内容泄露了您的隐私?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)

侵犯了我企业的权益

×

您好,当您发现根叔知了上有关于您企业的造谣与诽谤、商业侵权等内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到 pub.zhiliao@h3c.com 邮箱,我们会在审核后尽快给您答复。
  • 1. 您举报的内容是什么?(请在邮件中列出您举报的内容和链接地址)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
  • 3. 是哪家企业?(营业执照,单位登记证明等证件)
  • 4. 您与该企业的关系是?(您是企业法人或被授权人,需提供企业委托授权书)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

抄袭了我的内容

×

原文链接或出处

诽谤我

×

您好,当您发现根叔知了上有诽谤您的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您举报的内容以及侵犯了您什么权益?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

对根叔社区有害的内容

×

垃圾广告信息
色情、暴力、血腥等违反法律法规的内容
政治敏感
不规范转载 >
辱骂、歧视、挑衅等(不友善)
骚扰我
诱导投票

不规范转载

×

举报说明