问题描述:
大概的配置是
int vlan 1
ip address 1.1.1.1 24
int g1/0/0
ip address 192.168.20.1 24
nat static enable
nat static outbound 1.1.1.2 192.168.20.2
nat static outbound 1.1.1.3 192.168.20.3
策略全开
security-zone name Trust
im int g1/0/0
security-zone name Untrust
im int vlan 1
zone-pair security source Local destination Untrust
packet-filter 3000
zone-pair security source Trust destination Local
packet-filter 3000
zone-pair security source Untrust destination Trust
packet-filter 3000
zone-pair security source trust destination Untrust
packet-filter 3000
acl ad 3000
ru 0 p ip
此时由local本身发起的访问并tracert 223.5.5.5 路由正常并且能正常访问(icmp通)
由win7 PC(IP:1.1.1.2 掩码24 手动路由cmd - route add 223.5.5.5/32 1.1.1.1)发起访问并tracert223.5.5.5 路由不正常不能正常访问(icmp不通)
之前一直是通的,就最近突然这样了。
组网及组网描述:
抓个包看看报文回FW了没,可能没回来。