有两根线插在ms830上 一根拨号 一根专线 专线插上后配置了一遍策略路由让专线只供192.168.10.224上网用 其他还走拨号上网
配置过后192.168.10.224 能上外网 192.168.10.XXXX上不了外网 192.168.10.XXXX能ping 通 专线的ip
哪个大神看看配置的哪里有问题
acl number 3010
rule 5 permit ip source 192.168.1.0 0.0.0.255
rule 10 permit ip source 192.168.2.0 0.0.0.255
rule 15 permit ip source 192.168.10.0 0.0.0.255
acl number 3011
rule 20 permit ip source 192.168.10.244 255.255.255.255
[H3C-acl-adv-3011]acl number 3012
[H3C-acl-adv-3012]rule 5 permit ip source 192.168.1.0 0.0.0.255
[H3C-acl-adv-3012]rule 10 permit ip source 192.168.2.0 0.0.0.255
[H3C-acl-adv-3012]rule 15 permit ip source 192.168.10.0 0.0.0.255
[H3C]policy-based-route aaa permit node .
[H3C-pbr-aaa-5]if-match acl 3012
[H3C-pbr-aaa-5]policy-based-route aaa permit node 10 .
[H3C-pbr-aaa-10]if-match acl 3011
[H3C-pbr-aaa-10]apply ip-address next-hop 192.168.10.224
[H3C-pbr-aaa-10]quit
[H3C]interface GigabitEthernet0/4
[H3C-GigabitEthernet0/4]ip address 123.149.207.94 255.255.255.0
[H3C-GigabitEthernet0/4]dhcp select relay
[H3C-GigabitEthernet0/4]dhcp relay server-select 1
[H3C-GigabitEthernet0/4]ip policy-based-route aaa
[H3C-GigabitEthernet0/4]quit
(0)
最佳答案
不太对劲啊,其实你这样就行:
acl number 3011
rule 20 permit ip source 192.168.10.244 0
[H3C-pbr-aaa-5]policy-based-route aaa permit node 10 .
[H3C-pbr-aaa-10]if-match acl 3011
[H3C-pbr-aaa-10]apply ip-address next-hop 123.149.207.X(网关地址,原来你这个地方写的不对,不应该是写10.224)
[H3C-pbr-aaa-10]quit
[H3C]interface GigabitEthernet0/4
[H3C-GigabitEthernet0/4]ip address 123.149.207.94 255.255.255.0
[H3C-GigabitEthernet0/4] nat out 3010
[H3C-GigabitEthernet0/4]ip policy-based-route aaa
[H3C-GigabitEthernet0/4]quit
然后写两条缺省路由,分别指向专线的下一跳和拨号的dialer口,
(0)
专线的下一跳和拨号的dialer口 这个怎么写
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
专线的下一跳和拨号的dialer口 这个怎么写