实验拓扑
红圈里是备份组以及备份组的虚拟IP
注意事项:
1.两台防火墙的型号和版本必须一致
2.连接网络的接口编号要相同(两台防火墙相同编号接口连到同一个网络,如g1/0/0都连接到公网,g1/0/1都连接到了vlan10)
3.两台防火墙要连接心跳接口(传输防火墙配置、状态信息)
不要连接防火墙管理接口g0/0/0
实验内容
交换机
划分vlan,关闭stp
SW1
基本不用管,只关闭stp
<Huawei>undo ter mo
Info: Current terminal monitor is off.
[Huawei]sy sw1
[sw1]stp disable //不参与生成树计算也不转发BPDU报文
Warning: The global STP state will be changed. Continue? [Y/N]y
Info: This operation may take a few seconds. Please wait for a moment...done.
[sw1]int g User interface con0 is available
SW2
划分vlan。sw2上方共4个接口,vlan10、20各占两个,每个vlan都有连接fw1、fw2的线路。
<Huawei>undo ter mo
Info: Current terminal monitor is off.
<Huawei>sy
Enter system view, return user view with Ctrl+Z.
[Huawei]sy sw2
[sw2]vlan 10 //创建vlan10
[sw2-vlan10]vlan 20 //创建vlan20
[sw2-vlan20]q
[sw2]int g0/0/1
[sw2-GigabitEthernet0/0/1]p l a
[sw2-GigabitEthernet0/0/1]p d v 10
[sw2-GigabitEthernet0/0/1]
[sw2-GigabitEthernet0/0/1]int g0/0/2
[sw2-GigabitEthernet0/0/2]p l a
[sw2-GigabitEthernet0/0/2]p d v 10
[sw2-GigabitEthernet0/0/2]int g0/0/3
[sw2-GigabitEthernet0/0/3]p l a
[sw2-GigabitEthernet0/0/3]p d v 10
[sw2-GigabitEthernet0/0/3]
[sw2-GigabitEthernet0/0/3]
[sw2-GigabitEthernet0/0/3]q
[sw2]int g0/0/3
[sw2-GigabitEthernet0/0/3]int g0/0/4
[sw2-GigabitEthernet0/0/4]p l a
[sw2-GigabitEthernet0/0/4]p d v 20
[sw2-GigabitEthernet0/0/4]int g0/0/5
[sw2-GigabitEthernet0/0/5]p l a
[sw2-GigabitEthernet0/0/5]p d v 20
[sw2-GigabitEthernet0/0/5]int g0/0/6
[sw2-GigabitEthernet0/0/6]p l a
[sw2-GigabitEthernet0/0/6]p d v 20
[sw2-GigabitEthernet0/0/6]q
[sw2]dis th //查看该交换机信息
#
sysname sw2
#
vlan batch 10 20
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
return
[sw2]dis vlan
The total number of vlans is : 3
--------------------------------------------------------------------------------
U: Up; D: Down; TG: Tagged; UT: Untagged;
MP: Vlan-mapping; ST: Vlan-stacking;
#: ProtocolTransparent-vlan; *: Management-vlan;
--------------------------------------------------------------------------------
VID Type Ports
--------------------------------------------------------------------------------
1 common UT:GE0/0/7(D) GE0/0/8(D) GE0/0/9(D) GE0/0/10(D)
GE0/0/11(D) GE0/0/12(D) GE0/0/13(D) GE0/0/14(D)
GE0/0/15(D) GE0/0/16(D) GE0/0/17(D) GE0/0/18(D)
GE0/0/19(D) GE0/0/20(D) GE0/0/21(D) GE0/0/22(D)
GE0/0/23(D) GE0/0/24(D)
10 common UT:GE0/0/1(U) GE0/0/2(U) GE0/0/3(U) //划分到vlan10的接口
20 common UT:GE0/0/4(U) GE0/0/5(U) GE0/0/6(U) //划分到vlan20的接口
VID Status Property MAC-LRN Statistics Description
--------------------------------------------------------------------------------
1 enable default enable disable VLAN 0001
10 enable default enable disable VLAN 0010
20 enable default enable disable VLAN 0020
[sw2] User interface con0 is available
[sw2]stp dis
[sw2]stp disable //不参与生成树计算也不转发BPDU报文
Warning: The global STP state will be changed. Continue? [Y/N]y
Info: This operation may take a few seconds. Please wait for a moment...done.
[sw2]
(公网)路由R1
<Huawei>sy
Enter system view, return user view with Ctrl+Z.
[Huawei]sy r1
[r1]int g0/0/0
[r1-GigabitEthernet0/0/0]ip addr 202.1.1.100 24
[r1-GigabitEthernet0/0/0]
[r1-GigabitEthernet0/0/0]int loo0
[r1-LoopBack0]ip addr 100.1.1.1 32
[r1-LoopBack0]
[r1-LoopBack0]
防火墙
按步骤分别完成:
1.配置3个接口的IP
2.划分安全域
3.配置3个接口的VRRP虚拟IP
4.3个接口分别加入trust域、untrust域、dmz域
5.设置默认路由指向公网路由器
6.指定心跳接口
7.配置安全策略
8.配置nat策略
FW1和FW2配置大部分相同,在接口的虚拟IP设置上,FW1为主用,FW2为备用
FW1
<USG6000V1>undo ter mo
Info: Current terminal monitor is off.
<USG6000V1>sy
Enter system view, return user view with Ctrl+Z.
[USG6000V1]sy fw 1
[fw 1]sy fw 1
[fw 1]sy fw1
//设置接口g1/0/0
[fw1]int g1/0/0
[fw1-GigabitEthernet1/0/0]ip addr 10.1.12.1 24
[fw1-GigabitEthernet1/0/0]
[fw1-GigabitEthernet1/0/0]vrrp vrid 1 vir
[fw1-GigabitEthernet1/0/0]vrrp vrid 1 virtual-ip 202.1.1.1 24 active //设置备份组1
//active使其成为主用路由,防火墙使用双机热备技术,只能一个主用一个备用,不能设置优先级
[fw1-GigabitEthernet1/0/0]dis vrrp
2020-07-30 09:58:42.280
GigabitEthernet1/0/0 | Virtual Router 1
State : Backup //不是主用是因为没有划分安全域
Virtual IP : 202.1.1.1
Master IP : 0.0.0.0
PriorityRun : 100
PriorityConfig : 100
MasterPriority : 0
Preempt : YES Delay Time : 0 s
TimerRun : 60 s
TimerConfig : 60 s
Auth type : NONE
Virtual MAC : 0000-5e00-0101
Check TTL : YES
Config type : vgmp-vrrp
Backup-forward : disabled
Create time : 2020-07-30 09:56:39
Last change time : 2020-07-30 09:56:39
[fw1-GigabitEthernet1/0/0]q
[fw1]firewall zone untrust
[fw1-zone-untrust]add int g1/0/0 //接口g1/0/0连接公网,划入untrust域
[fw1-zone-untrust]q
[fw1]dis vrrp
2020-07-30 10:00:09.980
GigabitEthernet1/0/0 | Virtual Router 1
State : Master //划分完之后成为主用
Virtual IP : 202.1.1.1
Master IP