现在防火墙自身ping,拨号都正常,但是电脑上不了网。以下是具体配置:
# version 5.20, Release 5142P02
# sysname H3C
# undo voice vlan mac-address 00e0-bb00-0000
# interzone policy default by-priority
# domain default enable system
# dns resolve
# telnet server enable
# port-security enable
# ip http port xxxx
# undo alg dns undo alg rtsp
undo alg h323 undo alg sip
undo alg sqlnet undo alg pptp
undo alg ils
undo alg nbt
undo alg msn
undo alg qq
undo alg tftp
undo alg sccp
undo alg gtp
# session synchronization enable
# password-recovery enable
# acl number 2000
rule 0 permit
# vlan 1
# domain system
access-limit disable
state active idle-cut disable
self-service-url disable
# pki domain default crl check disable
# dhcp server ip-pool 0
network 192.168.2.0 mask 255.255.255.0
gateway-list 192.168.2.2
dns-list xxxxxx
# dhcp server ip-pool 10
network 192.168.10.0 mask 255.255.255.0
gateway-list 192.168.10.10
dns-list 218.2.135.1 61.147.37.1
# user-group system
group-attribute allow-guest
# local-user admin
password cipher $c$3$IzvqVsD07tluutv1XuFxdXT5VDuqWck0
authorization-attribute level 3
service-type telnet
service-type web
# cwmp
undo cwmp enable
# interface Dialer20
nat outbound
link-protocol ppp
ppp chap user xxxxxx
ppp chap password cipher $c$3$X8nTDDeqOsHOcrIkVumSGtLgq7hyWn9DQg==
ppp pap local-userxxxxxx
password cipher $c$3$GkBny+zOjP746TQzVRStZWzZz+f2BvF7gw==
ppp ipcp dns request
ip address ppp-negotiate
dialer user pppoeclient
dialer-group 20
dialer bundle 20
# interface NULL0
# interface GigabitEthernet0/0
port link-mode route
ip address 192.168.2.2 255.255.255.0
# interface GigabitEthernet0/1
port link-mode route
ip address 192.168.10.10 255.255.255.0
# interface GigabitEthernet0/2
port link-mode route
ip address 192.168.1.1 255.255.255.0
undo dhcp select server global-pool
# interface GigabitEthernet0/3
port link-mode route
ip address 10.201.15.30 255.255.255.0
undo dhcp select server global-pool
# interface GigabitEthernet0/4
port link-mode route
pppoe-client dial-bundle-number 20
# vd Root id 1
# zone name Management id 0
priority 100
zone name Local id 1
priority 100
zone name Trust id 2
priority 85
import interface GigabitEthernet0/0
import interface GigabitEthernet0/1
import interface GigabitEthernet0/2
import interface GigabitEthernet0/3
zone name DMZ id 3
priority 50 zone name Untrust id 4
priority 5
import interface Dialer20
import interface GigabitEthernet0/4
switchto vd Root
zone name Management id 0
ip virtual-reassembly
zone name Local id 1
ip virtual-reassembly
zone name Trust id 2
ip virtual-reassembly
zone name DMZ id 3
ip virtual-reassembly
zone name Untrust id 4
ip virtual-reassembly
interzone source Trust destination Untrust
rule 0 permit source-ip any_address
destination-ip any_address
service any_service
rule enable
interzone source Untrust destination Trust
rule 0 permit
source-ip any_address
destination-ip any_address
service any_service
rule enable
# ip route-static 0.0.0.0 0.0.0.0 Dialer20
# dhcp server forbidden-ip 192.168.0.188
dhcp server forbidden-ip 192.168.10.10 192.168.10.100
dhcp server forbidden-ip 192.168.2.230 192.168.2.255
# dhcp enable
# dialer-rule 20 ip permit
# load xml-configuration
# load tr069-configuration
# user-interface con 0
user-interface vty 0 4
authentication-mode scheme
# return
(0)
最佳答案
进入interface Dialer 20 ,增加如下配置看看:
interface Dialer 20
mtu 1492
tcp mss 1200
保存后再测试下看看
(0)
改了,不行。还有其他数值不?以前工程师好像也提到过这两个值,默认就不行。
还是不行。
没问题,都可以ping通
在防火墙上ping的。
不通。
是的,不通。
dis ip int bri ,看看dialer 20口获取到ip地址了吗? 如果没获取到,拨号没成功,确定下用户名密码的正确性、重启猫,如果获取到地址了,在终端一次ping 下终端的网关、防火墙lan口地址、dialer口地址,看看结果
获取到地址的,也都能ping通。
[ZYNJ]display ip routing-table Routing Tables: Public Destinations : 7 Routes : 7 Destination/Mask Proto Pre Cost NextHop Interface 0.0.0.0/0 Static 60 0 114.221.71.83 Dia20 114.221.68.1/32 Direct 0 0 114.221.68.1 Dia20 114.221.71.83/32 Direct 0 0 127.0.0.1 InLoop0 127.0.0.0/8 Direct 0 0 127.0.0.1 InLoop0 127.0.0.1/32 Direct 0 0 127.0.0.1 InLoop0 192.168.2.0/24 Direct 0 0 192.168.2.3 GE0/0 192.168.2.3/32 Direct 0 0 127.0.0.1 InLoop0
请问是要看这个吗?
没问题,测过的。
ping 114.221.68.1 不通,拨号上网ping,是通的。
我仔细检查了配置,发现虽然我贴上来的配置是对的,但是通过web访问发现,实际配置和telnet登录看到的配置不一样,G0口被放在管理域,再次通过telnet登录,修改G0到Trust,终端就可以正常上网了。谢谢!
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
ping 114.221.68.1 不通,拨号上网ping,是通的。