运营商专线进入到防火墙0口做与运营商级联配置了IP,2口与核心交换机互联配置了管理IP,网络中需要用到多个网段,配置完策略后我又配置了两条 acl advanced,结束后发现设备ping不通外网网关, 下面是我配置的命令
vlan 10
description GL-vlan
interface gigabitethernet 1/0/0
ip address 119.180.25.107 255.255.255.192
quit
interface GigabitEthernet 1/0/2
ip address 192.168.110.1 255.255.255.0
quit
ip route-static 0.0.0.0 0 119.180.25.65
ip route-static 192.168.0.0 16 192.168.110.2
ip route-static 170.16.0.0 16 192.168.110.2
security-zone name Untrust
import interface GigabitEthernet 1/0/0
quit
security-zone name Trust
import interface GigabitEthernet 1/0/2
quit
security-policy disable
object-policy ip pass
rule 0 pass
quit
zone-pair security source Trust destination Untrust
object-policy apply ip pass
packet-filter 3001
quit
zone-pair security source Trust destination Local
object-policy apply ip pass
quit
zone-pair security source Local destination Trust
object-policy apply ip pass
quit
zone-pair security source Local destination Untrust
object-policy apply ip pass
quit
security-policy ip
rule 10 name test
action pass
source-zone local
source-zone Trust
source-zone Untrust
destination-zone local
destination-zone Trust
[destination-zone Untrust
quit
acl advanced 3001
rule permit ip source 192.168.0.0 0.0.255.255
rule permit ip source 172.16.0.0 0.0.255.255
quit
nat address-group 0
address 119.180.25.107 mask 26
quit
acl basic 2000
rule permit source 192.168.0.0 0.0.255.255
rule permit source 172.16.0.0 0.0.255.255
quit
interface GigabitEthernet 1/0/0
nat outbound 2000 address-group 0
quit
好的 谢谢