F1000上连接口G0/1连接外网,加入UTRUST域,G0/2连接内网,配置了DHCP,加到trust域,配置了域间策略,trust到untrust,LOCAL到untrust都开放了,在超 级终端中,能ping通G0/1连接设备的ip192.168.62.253,但G0/2连接的PC不能ping通G0/1连接设备的IP192.168.62.254,只能ping通g0/1接口本身设置的IP.
zone name Management id 0
priority 100
import interface GigabitEthernet0/0
zone name Local id 1 priority 100
zone name Trust id 2
priority 85
import interface GigabitEthernet0/2
zone name DMZ id 3
priority 50
zone name Untrust id 4
priority 5 import
interface GigabitEthernet0/1
switchto vd Root
object network host manage-pc
host address 192.168.0.2
zone name Management id 0
undo ip virtual-reassembly
zone name Local id 1
ip virtual-reassembly
zone name Trust id 2
ip virtual-reassembly
zone name DMZ id 3
ip virtual-reassembly
zone name Untrust id 4
ip virtual-reassembly
interzone source Management destination Local rule 0 permit source-ip manage-pc destination-ip any_address service http rule enable rule 1 permit logging source-ip any_address destination-ip any_address service any_service rule enable
interzone source Local destination Trust rule 0 permit source-ip any_address destination-ip any_address service any_service rule enable
interzone source Local destination Untrust rule 0 permit source-ip any_address destination-ip any_address service any_service rule enable
interzone source Trust destination Local rule 0 permit source-ip any_address destination-ip any_address service any_service rule enable
interzone source Trust destination Untrust rule 0 permit source-ip any_address destination-ip any_address service any_service rule enable
interzone source Untrust destination Local rule 0 permit source-ip any_address destination-ip any_address service any_service rule enable
interzone source Untrust destination Trust rule 0 permit source-ip any_address destination-ip any_address service any_service rule enable
ip route-static 0.0.0.0 0.0.0.0 GigabitEthernet0/1 192.168.62.254 preference 1
(0)
最佳答案
display session table看一下会话收发包是否正常,debug aspf packet debug ip packet看一下报文
(0)
display session table会话收发包显示有TCP和UDP的包
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
display session table会话收发包显示有TCP和UDP的包