[F]security-zone name trust 進入trust組
[F-security-zone-trust]import interface GigabitEthernet 1/0/1? ? ? 將接口加入trust組
[F]security-zone name untrust
[F-security-zone-untrust]import interface GigabitEthernet 1/0/2
[F]acl advanced 3000? ? ? ? ? ? ? ? ? ? ? 創(chuàng)建匹配組的ACL
[F-acl-ipv4-adv-3000]rule permit ip
[F]zone-pair security source trust destination untrust? ? ? ? ? ? 源組trust 到目的組untrust
[F-zone-pair-security-Management-Local]packet-filter 3000? ? ? ? ? ? 匹配ACL3000
[F]zone-pair security source untrust destination trust? ? ? ? ? ? 源組untrust 到目的組trust
[F-zone-pair-security-Local-Management]packet-filter 3000? ? ? ? ? ? 匹配ACL3000
NTP配置
[F]acl basic 2000
[F-acl-ipv4-basic-2000]rule 0 permit source 192.168.2.0 0.0.0.255? ? 定義內網匹配段
[F-acl-ipv4-basic-2000]rule 0 permit source 192.168.3.0 0.0.0.255? ?
[F]nat address-group 10? ? ? ? 創(chuàng)建NAT組
[F-address-group-10]address 192.168.1.10 192.168.1.25? ? ? ? ? ? 外網分配IP地址池源10到25
關聯
[F]int g1/0/3? ? 進入連接外部網絡的接口
[F-GigabitEthernet1/0/3]nat outbound 2000 address-group 10 no-pat? ? ? 抓取ACL2000內匹配的流量通過ANT审磁,地址池為10
[F]ip route-table 192.168.2.0 255.255.255.0 192.168.1.1
[F]ip route-table 192.168.3.0 255.255.255.0 192.168.1.1
[M1]ip route-table 0.0.0.0 0.0.0.0 192.168.1.2
如果想要防火墻的接口能被ping通(連通就可以配置路由協議與其他設備互動了)
security-zone name Trust
import interface GigabitEthernet1/0/0
import interface GigabitEthernet1/0/1
#
acl advanced 3000
rule 0 permit ip
#
zone-pair security source Local destination Trust
packet-filter 3000
zone-pair security source Trust destination Local
packet-filter 3000
#