那位大侠帮我看下怎么上不了网:
有一台F100-M-G的防火墙,我做最基本的上网测试,发现无法连外网,配置如下:
#
version 5.20, Release 5142P02
#
sysname H3C
#
undo voice vlan mac-address 00e0-bb00-0000
#
domain default enable system
#
undo alg dns
undo alg rtsp
undo alg h323
undo alg sip
undo alg sqlnet
undo alg pptp
undo alg ils
undo alg nbt
undo alg msn
undo alg qq
undo alg tftp
undo alg sccp
undo alg gtp
#
session synchronization enable
#
password-recovery enable
#
acl number 3000
rule 0 permit ip
#
vlan 1
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
pki domain default
crl check disable
#
user-group system
group-attribute allow-guest
#
local-user admin
password cipher $c$3$IahP/n0Jk/yYxOYLc7HcmDPAbIaFow==
authorization-attribute level 3
service-type telnet
service-type web
#
interface NULL0
#
interface GigabitEthernet0/0
port link-mode route
ip address 192.168.11.1 255.255.255.0
#
interface GigabitEthernet0/1
port link-mode route
nat outbound 3000
ip address 192.168.10.212 255.255.255.0
#
interface GigabitEthernet0/2
port link-mode route
ip address 192.168.16.1 255.255.255.0
#
interface GigabitEthernet0/3
port link-mode route
#
interface GigabitEthernet0/4
port link-mode route
#
interface GigabitEthernet0/5
port link-mode route
#
vd Root id 1
#
zone name Management id 0
priority 100
import interface GigabitEthernet0/0
zone name Local id 1
priority 100
zone name Trust id 2
priority 85
import interface GigabitEthernet0/2
zone name DMZ id 3
priority 50
zone name Untrust id 4
priority 5
import interface GigabitEthernet0/1
switchto vd Root
object network host manage-pc
host address 192.168.11.2
zone name Management id 0
ip virtual-reassembly
zone name Local id 1
ip virtual-reassembly
zone name Trust id 2
ip virtual-reassembly
zone name DMZ id 3
ip virtual-reassembly
zone name Untrust id 4
ip virtual-reassembly
interzone source Management destination Local
rule 0 permit
source-ip manage-pc
destination-ip any_address
service http
rule enable
interzone source Local destination Trust
rule 0 permit
source-ip any_address
destination-ip any_address
service any_service
rule enable
interzone source Trust destination Untrust
rule 0 permit
source-ip any_address
destination-ip any_address
service any_service
rule enable
#
ip route-static 0.0.0.0 0.0.0.0 192.168.10.1
#
load xml-configuration
#
load tr069-configuration
#
user-interface con 0
user-interface vty 0 4
authentication-mode scheme
#
return
g0/1 外网接口
G0/2接电脑主机
G0/1接电脑都能上网,确定网线无问题。
(0)
最佳答案
ip route-static 0.0.0.0 0.0.0.0 192.168.10.1
这是G0/1 联外网的 IP地址网关 并做了NAT
这个还需要做回程路由吗?
(0)
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论