上图中
192.168.251.100可以ping通192.168.251.250
192.168.251.254可以ping通192.168.251.250
192.168.20.101ping不通192.168.251.250
192.168.20.101也可以ping通192.168.251.100、192.168.251.254
192.168.20段为vlan20
192.168.251段为管理vlan1000
为什么192.168.20段无法ping通防火墙的管理地址192.168.251.250
(0)
最佳答案
192.168.251.100可以ping通192.168.251.250
192.168.251.254可以ping通192.168.251.250
192.168.20.101ping不通192.168.251.250
192.168.20.101也可以ping通192.168.251.100、192.168.251.254
根据你的测试,同网段可以ping通墙,不同网段ping不通墙
1、考虑防火墙是否配置了正确的路由? 防火墙dis ip rout 看是否到20段的路由
防火墙配置路由的下一跳应该是交换机的地址:ip route-static 192.168.20.101 24 192.168.251.100
2、防火墙缺省是阻断的,需要放行相关策略才能ping通。(根据你上面回复的,策略已经放了)
(0)
检查下防火墙路由和策略问题
(0)
interface GigabitEthernet1/0/2 port link-mode route description GuideLan Interface ip address 192.168.251.250 255.255.255.0 manage http inbound manage http outbound manage https inbound manage https outbound manage netconf-http inbound manage netconf-https inbound manage netconf-ssh inbound manage ping inbound manage ping outbound manage snmp inbound manage ssh inbound manage ssh outbound manage telnet inbound manage telnet outbound undo dhcp select server # security-policy ip rule 1 name any action pass counting enable rule 0 name GuideSecPolicy action pass counting enable source-zone Trust destination-zone Untrust destination-zone DMZ
interface GigabitEthernet1/0/2 port link-mode route description GuideLan Interface ip address 192.168.251.250 255.255.255.0 manage http inbound manage http outbound manage https inbound manage https outbound manage netconf-http inbound manage netconf-https inbound manage netconf-ssh inbound manage ping inbound manage ping outbound manage snmp inbound manage ssh inbound manage ssh outbound manage telnet inbound manage telnet outbound undo dhcp select server # security-policy ip rule 1 name any action pass counting enable rule 0 name GuideSecPolicy action pass counting enable source-zone Trust destination-zone Untrust destination-zone DMZ
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明