拓扑图:
目的:①要求trust可以ping通dmz、untrust,后者不能ping通trust。
②全网互通
①要求trust可以ping通dmz、untrust,后者不能ping通trust。
命令:
//路由配置
[SRG]inter g0/0/1
[SRG-GigabitEthernet0/0/1]ip add 192.168.1.1 24
[SRG]inter g0/0/2
[SRG-GigabitEthernet0/0/2]ip add 192.168.2.1 24
[SRG]inter g0/0/3
[SRG-GigabitEthernet0/0/3]ip add 192.168.3.1 24
//添加端口
[SRG]firewall zone trust
[SRG-zone-trust]add interface GigabitEthernet 0/0/1
[SRG]firewall zone untrust
[SRG-zone-untrust]add interface GigabitEthernet 0/0/2
[SRG]firewall zone dmz
[SRG-zone-dmz]add interface GigabitEthernet 0/0/3
//路由策略
[SRG]firewall packet-filter default permit interzone trust untrust direction outbound
Warning:Setting the default packet filtering to permit poses security risks. You are advi