赞
踩
目录
配置IP地址
- [FW1]int g1/0/0
- [FW1-GigabitEthernet1/0/0]ip address 10.1.14.1 24
- [FW1-GigabitEthernet1/0/0]int g1/0/1
- [FW1-GigabitEthernet1/0/1]ip address 10.1.15.1 24
- [FW1-GigabitEthernet1/0/1]int g1/0/6
- [FW1-GigabitEthernet1/0/6]ip address 10.1.66.1 24
- [FW2]int g1/0/0
- [FW2-GigabitEthernet1/0/0]ip address 10.1.14.2 24
- [FW2-GigabitEthernet1/0/1]int g1/0/1
- [FW2-GigabitEthernet1/0/1]ip address 10.1.15.2 24
- [FW2-GigabitEthernet1/0/1]int g1/0/6
- [FW2-GigabitEthernet1/0/6]ip address 10.1.66.2 24
划分区域
- [FW1]firewall zone trust
- [FW1-zone-trust]add interface GigabitEthernet 1/0/0
- [FW1]firewall zone untrust
- [FW1-zone-untrust]add interface GigabitEthernet 1/0/1
- [FW1]firewall zone name hrp
- [FW1-zone-hrp]set priority 30
- [FW1-zone-hrp]add interface GigabitEthernet 1/0/6
- [FW2]firewall zone trust
- [FW2-zone-trust]add interface GigabitEthernet 1/0/0
- [FW2]firewall zone untrust
- [FW2-zone-untrust]add interface GigabitEthernet 1/0/1
- [FW2]firewall zone name hrp
- [FW2-zone-hrp]set priority 30
- [FW2-zone-hrp]add interface GigabitEthernet 1/0/6
配置VRRP
- [FW1]interface GigabitEthernet 1/0/0
- [FW1-GigabitEthernet1/0/0]vrrp vrid 1 virtual-ip 10.1.14.254 active
- [FW1-GigabitEthernet1/0/0]interface GigabitEthernet 1/0/1
- [FW1-GigabitEthernet1/0/1]vrrp vrid 2 virtual-ip 10.1.15.254 active
- [FW2]interface GigabitEthernet 1/0/0
- [FW2-GigabitEthernet1/0/0]vrrp vrid 1 virtual-ip 10.1.14.254 standby
- [FW2-GigabitEthernet1/0/0]interface GigabitEthernet 1/0/1
- [FW2-GigabitEthernet1/0/1]vrrp vrid 2 virtual-ip 10.1.15.254 standby
配置心跳线
- [FW1]hrp interface GigabitEthernet 1/0/6 remote 10.1.66.2
- [FW1]hrp enable
- HRP_S[FW1]
- [FW2]hrp interface GigabitEthernet 1/0/6 remote 10.1.66.1
- [FW2]hrp enable
- HRP_S[FW2]
配置安全策略(在主防火墙上)
- HRP_M[FW1]security-policy (+B)
- HRP_M[FW1-policy-security]rule name test (+B)
- HRP_M[FW1-policy-security-rule-test]source-zone trust (+B)
- HRP_M[FW1-policy-security-rule-test]destination-zone untrust (+B)
- HRP_M[FW1-policy-security-rule-test]action permit (+B)
验证功能
VRRP协议验证
心跳线验证
连通性验证
学习记录 感谢观看
Copyright © 2003-2013 www.wpsshop.cn 版权所有,并保留所有权利。