源地址 10.248.68.0/24 属于TO_CMNET的vpn实例,目的地址10.248.89.0/24属于TO_BOSS的vpn实例。
ospf 1 vpn-instance TO_CMNET ospf 2 vpn-instance TO_BOSS
路由及安全策略具体如何配置,安全策略应该是只能选定一个vrf
(0)
vrf选入接口绑定的那个。
例如允许从TO_CMNET发起去TO_BOSS的访问,那么vrf选TO_CMNET。
至于路由怎么写,我看你用的是ospf,直接给你做个实验吧。
防火墙关键配置(有些配置可以调整,比如引入路由的时候绑定路由策略、引入直连路由等):
sysname F2
#
ip vpn-instance TO_BOSS
#
address-family ipv4
route-replicate from vpn-instance TO_CMNET protocol ospf 1 advertise
#
ip vpn-instance TO_CMNET
#
address-family ipv4
route-replicate from vpn-instance TO_BOSS protocol ospf 2 advertise
#
ospf 1 router-id 2.2.2.2 vpn-instance TO_CMNET
import-route ospf 2
area 0.0.0.0
network 0.0.0.0 255.255.255.255
#
ospf 2 router-id 2.2.2.2 vpn-instance TO_BOSS
import-route ospf 1
area 0.0.0.0
network 0.0.0.0 255.255.255.255
#
interface GigabitEthernet1/0/0
port link-mode route
combo enable copper
ip binding vpn-instance TO_CMNET
ip address 10.0.12.2 255.255.255.0
#
interface GigabitEthernet1/0/1
port link-mode route
combo enable copper
ip binding vpn-instance TO_BOSS
ip address 10.0.23.2 255.255.255.0
#
security-zone name A
import interface GigabitEthernet1/0/0
#
security-zone name B
import interface GigabitEthernet1/0/1
#
security-policy ip
rule 3 name ospf-TO_CMNET
action pass
vrf TO_CMNET
service ospf
rule 4 name ospf-TO_BOSS
action pass
vrf TO_BOSS
service ospf
rule 5 name test
action pass
vrf TO_CMNET
source-ip-subnet 10.248.68.0 255.255.255.0
destination-ip-subnet 10.248.89.0 255.255.255.0
#
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论