华为防火墙智能选路

在这里插入图片描述

  1. 配置内网IP地址及区域
    [FW1-GigabitEthernet1/0/1]ip add 10.1.1.1 24
    [FW1]firewall zone trust
    [FW1-zone-trust]add interface GigabitEthernet 1/0/1
    [FW1-GigabitEthernet1/0/1]service-manage ping permit
    [FW2-GigabitEthernet1/0/1]ip add 10.1.1.2 24
    [FW2]firewall zone trust
    [FW2-zone-trust]add interface GigabitEthernet 1/0/1
    [FW2-GigabitEthernet1/0/1]service-manage ping permit
    在这里插入图片描述
    在这里插入图片描述

  2. 配置DMZ区域IP地址及区域
    [FW1-GigabitEthernet1/0/6]ip add 10.1.2.1 24
    [FW1]firewall zone dmz
    [FW1-zone-dmz]add interface GigabitEthernet 1/0/6
    [FW2-GigabitEthernet1/0/6]ip add 10.1.2.2 24
    [FW2]firewall zone dmz
    [FW2-zone-dmz]add interface GigabitEthernet 1/0/6

  3. 配置外网IP地址及其互通
    [FW1-GigabitEthernet1/0/2]ip add 20.1.1.1 24
    [FW1-GigabitEthernet1/0/2]service-manage ping permit
    [FW1-GigabitEthernet1/0/3]ip add 20.1.5.11 24
    [FW1-GigabitEthernet1/0/3]service-manage ping permit
    [FW1]firewall zone untrust
    [FW1-zone-untrust]add interface g1/0/2
    [FW1-zone-untrust]add interface g1/0/3
    [FW2-GigabitEthernet1/0/2]ip add 20.1.2.2 24
    [FW2-GigabitEthernet1/0/2]service-manage ping permit
    [FW2-GigabitEthernet1/0/3]ip add 20.1.4.22 24
    [FW2-GigabitEthernet1/0/3]service-manage ping permit
    [FW2]firewall zone untrust
    [FW2-zone-untrust]add interface GigabitEthernet1/0/2
    [FW2-zone-untrust]add interface GigabitEthernet1/0/3
    [AR1-GigabitEthernet0/0/0]ip add 20.1.1.2 24
    [AR1-GigabitEthernet0/0/2]ip add 20.1.4.23 24
    [AR1-GigabitEthernet0/0/1]ip add 20.1.3.6 24
    [AR2-GigabitEthernet0/0/0]ip add 20.1.2.3 24
    [AR2-GigabitEthernet0/0/2]ip add 20.1.5.12 24
    [AR2-GigabitEthernet0/0/1]ip add 20.1.3.7 24
    [FW1]ip route-static 0.0.0.0 0.0.0.0 20.1.1.2
    [FW1]ip route-static 0.0.0.0 0.0.0.0 20.1.5.12 preference 100
    [FW2]ip route-static 0.0.0.0 0.0.0.0 20.1.4.23
    [FW2]ip route-static 0.0.0.0 0.0.0.0 20.1.2.3 preference 100

  4. 配置域间安全策略
    [FW1]security-policy
    [FW1-policy-security]rule name sec_policy
    [FW1-policy-security-rule-sec_policy]source-zone trust
    [FW1-policy-security-rule-sec_policy]source-zone local
    [FW1-policy-security-rule-sec_policy]destination-zone untrust
    [FW1-policy-security-rule-sec_policy]action permit
    [FW2]security-policy
    [FW2-policy-security]rule name sec_policy
    [FW2-policy-security-rule-sec_policy]source-zone trust
    [FW2-policy-security-rule-sec_policy]source-zone local
    [FW2-policy-security-rule-sec_policy]destination-zone untrust
    [FW2-policy-security-rule-sec_policy]action permit

  5. 配置NAT功能
    (1)在FW1上配置nat地址池和可分配的地址,nat策略
    [FW1]nat address-group nat_isp1
    [FW1-address-group-nat_isp1]section 20.1.1.100 20.1.1.110
    [FW1]nat-policy
    [FW1-policy-nat]rule name source_isp1
    [FW1-policy-nat-rule-source_isp1]source-zone trust
    [FW1-policy-nat-rule-source_isp1]destination-zone untrust
    [FW1-policy-nat-rule-source_isp1]action source-nat address-group nat_isp1
    此时如果将PC1网关设为FW1的g1/0/1的地址,就可PING通20.1.1.0网段
    在这里插入图片描述

查看NAT转换
在这里插入图片描述

(2)在FW2上配置nat地址池和可分配的地址,nat策略
[FW2]nat address-group nat_isp1
[FW2-address-group-nat_isp1]section 20.1.4.100 20.1.4.110
[FW2]nat-policy
[FW2-policy-nat]rule name source_isp1
[FW2-policy-nat-rule-source_isp1]source-zone trust
[FW2-policy-nat-rule-source_isp1]destination-zone untrust
[FW2-policy-nat-rule-source_isp1]action source-nat address-group nat_isp1
在这里插入图片描述

  1. 配置健康检查功能
    [FW1]healthcheck enable
    [FW1]healthcheck name isp1_health
    [FW1-healthcheck-isp1_health]destination 20.1.1.2 interface g1/0/2 protocol icmp
    [FW1]healthcheck name isp2_health
    [FW1-healthcheck-isp2_health]destination 20.1.5.12 int g1/0/3 protocol icmp
    在这里插入图片描述

[FW2]healthcheck enable
[FW2]healthcheck name isp1_health
[FW2-healthcheck-isp1_health]destination 20.1.4.23 interface g1/0/3 protocol icmp
[FW2]healthcheck name isp2_health
[FW2-healthcheck-isp2_health]destination 20.1.2.3 interface g1/0/2 protocol icmp
在这里插入图片描述
在这里插入图片描述

  1. 配置接口带宽
    [FW1-GigabitEthernet1/0/2]healthcheck isp1_health
    [FW1-GigabitEthernet1/0/2]bandwidth ingress 50000 threshold 90
    [FW1-GigabitEthernet1/0/2]bandwidth egress 50000 threshold 90
    [FW1-GigabitEthernet1/0/3]healthcheck isp2_health
    [FW1-GigabitEthernet1/0/3]bandwidth egress 50000 threshold 90
    [FW1-GigabitEthernet1/0/3]bandwidth ingress 50000 threshold 90
    [FW2-GigabitEthernet1/0/2]healthcheck isp2_health
    [FW2-GigabitEthernet1/0/2]bandwidth ingress 50000 threshold 90
    [FW2-GigabitEthernet1/0/2]bandwidth egress 50000 threshold 90
    [FW2-GigabitEthernet1/0/3]healthcheck isp1_health
    [FW2-GigabitEthernet1/0/3]bandwidth ingress 50000 threshold 90
    [FW2-GigabitEthernet1/0/3]bandwidth egress 50000 threshold 90

  2. 配置双机热备
    [FW1-GigabitEthernet1/0/1]vrrp vrid 1 virtual-ip 10.1.1.254 active
    [FW1-GigabitEthernet1/0/1]vrrp virtual-mac enable
    [FW1]hrp enable
    [FW1]hrp interface GigabitEthernet 1/0/6 remote 10.1.2.2
    [FW2-GigabitEthernet1/0/1]vrrp vrid 1 virtual-ip 10.1.1.254 standby
    [FW2-GigabitEthernet1/0/1]vrrp virtual-mac enable
    [FW2]hrp enable
    [FW2]hrp interface g1/0/6 remote 10.1.2.1
    [AR1-GigabitEthernet0/0/1]vrrp vrid 1 virtual-ip 20.1.3.254
    [AR2-GigabitEthernet0/0/1]vrrp vrid 1 virtual-ip 20.1.3.254
    PC可以ping通服务器
    在这里插入图片描述

  3. 配置全局选路策略
    HRP_M[FW1]link-interface 0 name ISP1 (+B)
    HRP_M[FW1-linkif-0]interface GigabitEthernet 1/0/2 next-hop 20.1.1.2 (+B)
    HRP_M[FW1-linkif-0]healthcheck isp1_health (+B)
    HRP_M[FW1]link-interface 1 name ISP2 (+B)
    HRP_M[FW1-linkif-1]interface GigabitEthernet 1/0/3 next-hop 20.1.5.12 (+B)
    HRP_M[FW1-linkif-1]healthcheck isp2_health (+B)
    HRP_M[FW1]multi-linkif (+B)
    HRP_M[FW1-multi-linkif]mode priority-of-link-quality (+B)
    HRP_M[FW1-multi-linkif]priority-of-link-quality parameter loss (+B)
    HRP_M[FW1-multi-linkif]priority-of-link-quality protocol tcp-simple (+B)
    HRP_M[FW1-multi-linkif]add linkif ISP1 (+B)
    HRP_M[FW1-multi-linkif]add linkif ISP2 (+B)
    FW2上不用配置,会自动生成以上配置
    在这里插入图片描述

  • 0
    点赞
  • 9
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值