h3c防火墙 f1020 启动了某个端口,做了路由 也做了点nat转换,pc机查到对应端口可以上网,百度查ip是防火墙配置的ip。但是从外网ping防火墙上的ip地址,依旧无法平通。
简单说,能从内网往公网通信,但是无法从公网往内网通信。
求指导
(0)
最佳答案
访问一下,打印一下会话看看
display session table ipv4 dest 公网地址 verbose 看看
(0)
受累看看我下面的追评
安全策略没做吧
(0)
object-policy ip namage rule 0 pass # security-zone name Local # security-zone name Trust import interface GigabitEthernet1/0/6 # security-zone name DMZ # security-zone name Untrust import interface GigabitEthernet1/0/5 # security-zone name Management # zone-pair security source Local destination Any # zone-pair security source Trust destination Untrust object-policy apply ip namage # zone-pair security source Untrust destination Trust object-policy apply ip namage #
做了啊,我没法给你法图片啊。
上点配置
上配置
object-policy ip namage rule 0 pass # security-zone name Local # security-zone name Trust import interface GigabitEthernet1/0/6 # security-zone name DMZ # security-zone name Untrust import interface GigabitEthernet1/0/5 # security-zone name Management # zone-pair security source Local destination Any # zone-pair security source Trust destination Untrust object-policy apply ip namage # zone-pair security source Untrust destination Trust object-policy apply ip namage #
object-policy ip namage rule 0 pass # security-zone name Local # security-zone name Trust import interface GigabitEthernet1/0/6 # security-zone name DMZ # security-zone name Untrust import interface GigabitEthernet1/0/5 # security-zone name Management # zone-pair security source Local destination Any # zone-pair security source Trust destination Untrust object-policy apply ip namage # zone-pair security source Untrust destination Trust object-policy apply ip namage #
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
受累看看我下面的追评