拓扑图
untrust区配置
对R1进行配置
[Huawei]sys ISP
[ISP]int g0/0/0
[ISP-GigabitEthernet0/0/0]ip add 100.1.1.2 24
[ISP-GigabitEthernet0/0/0]int g0/0/1
[ISP-GigabitEthernet0/0/1]ip add 200.1.1.1 24
server2上的配置
在接口列表里面给GE1/0/0接口配置IP,启动访问管理选ping
在防火墙GE1/0/0接口上写一条静态路由
配置trust区
先给交换机LSW1接口配置划分VLAN2和VLAN3
vlan2 g0/0/1接口
[Huawei]vlan 2
[Huawei-vlan2]
Mar 17 2023 19:08:52-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 4, th
e change loop count is 0, and the maximum number of records is 4095.q
[Huawei]int v
[Huawei]int Vlanif 2
[Huawei-Vlanif2]ip add 10.1.255.1 24
[Huawei-Vlanif2]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type access
vlan3 g0/0/2接口
[Huawei]vlan 3
[Huawei-vlan3]
Mar 17 2023 19:13:22-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 8, th
e change loop count is 0, and the maximum number of records is 4095.q
[Huawei]int v
[Huawei]int Vlanif 3
[Huawei-Vlanif3]ip add 10.1.3.1 24
[Huawei-Vlanif3]q
[Huawei]int g0/0/2
Mar 17 2023 19:14:12-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 9, th
e change loop count is 0, and the maximum number of records is 4095.
[Huawei-GigabitEthernet0/0/2]po
[Huawei-GigabitEthernet0/0/2]port l
[Huawei-GigabitEthernet0/0/2]port link-t
[Huawei-GigabitEthernet0/0/2]port link-type acc
[Huawei-GigabitEthernet0/0/2]port link-type access
[Huawei-GigabitEthernet0/0/2]po
[Huawei-GigabitEthernet0/0/2]port d
[Huawei-GigabitEthernet0/0/2]port de
Mar 17 2023 19:14:42-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 10, t
he change loop count is 0, and the maximum number of records is 4095.
[Huawei-GigabitEthernet0/0/2]port default v
[Huawei-GigabitEthernet0/0/2]port default vlan 3
[Huawei-GigabitEthernet0/0/2]
Mar 17 2023 19:14:47-08:00 Huawei %%01IFNET/4/IF_STATE(l)[0]:Interface Vlanif3 h
as turned into UP state.
Mar 17 2023 19:14:47-08:00 Huawei %%01IFNET/4/LINK_STATE(l)[1]:The line protocol
IP on the interface Vlanif3 has entered the UP state.
Mar 17 2023 19:14:52-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 11, t
he change loop count is 0, and the maximum number of records is 4095.
PC1上
防火墙上
写一条到达10.1.3.0/24网段的路由
接口聚合
交换机上
做接口汇聚
trust 到 dmz
给dmz区建立地址组
新建trust到dmz的策略
untrust 到指定dmz
给其中以个dmz区建立地址
新建untrust 到dmz的策略