H3C防火墙配置三层链路聚合互通

1.项目背景
某公司由于业务需要,需要将H3C防火墙和交换机做三层聚合,并配置网络互通。
2.网络拓扑

在这里插入图片描述
3.配置链路聚合组(交换机配置)
interface Route-Aggregation 22(创建三层虚拟聚合接口)
link-aggregation mode dynamic
ip add 192.168.1.2 24
4.配置交换机接口加入聚合组(交换机配置)
int GigabitEthernet 1/0/2
port link-mode route(将接口转换为三层接口)
port link-aggregation group 22(加入聚合组)
int GigabitEthernet 1/0/1
port link-mode route(将接口转换为三层接口)
port link-aggregation group 22(加入聚合组)
5.防火墙同配置以上配置(略)
配置防火墙聚合接口IP
interface Route-Aggregation 22(创建三层虚拟聚合接口)
link-aggregation mode dynamic
ip add 192.168.1.1 24
6.查看聚合状态,status为s为聚合成功
dis link-aggregation verbose
在这里插入图片描述
配置防火墙策略使交换机和防火墙可以直连ping通
配置防火墙直连互通策略

security-policy ip
rule 0 name trust-local
action pass
source-zone trust
destination-zone local
rule 1 name local-trust
action pass
source-zone local
destination-zone trust

配置将防火墙接口加入到trust区域
security-zone name Trust
import interface Route-Aggregation22
验证结果
在这里插入图片描述

  • 3
    点赞
  • 45
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
H3C三层链路聚合配置需要以下步骤: ```console [H3C]sys [H3C]vlan batch 10 //创建vlan10 [H3C]interface vlanif 10 //进入vlan10接口视图 [H3C-Vlanif10]ip address 10.1.1.1 24 //配置vlan10的IP地址 [H3C-Vlanif10]quit [H3C]interface GigabitEthernet 1/0/1 //进入GigabitEthernet 1/0/1接口视图 [H3C-GigabitEthernet1/0/1]port link-type trunk //配置端口为trunk模式 [H3C-GigabitEthernet1/0/1]port trunk allow-pass vlan 10 //允许vlan10通过 [H3C-GigabitEthernet1/0/1]quit [H3C]interface GigabitEthernet 1/0/2 //进入GigabitEthernet 1/0/2接口视图 [H3C-GigabitEthernet1/0/2]port link-type trunk //配置端口为trunk模式 [H3C-GigabitEthernet1/0/2]port trunk allow-pass vlan 10 //允许vlan10通过 [H3C-GigabitEthernet1/0/2]quit [H3C]interface Bridge-Aggregation 1 //进入聚合接口视图 [H3C-Bridge-Aggregation1]port link-type trunk //配置端口为trunk模式 [H3C-Bridge-Aggregation1]port trunk allow-pass vlan 10 //允许vlan10通过 [H3C-Bridge-Aggregation1]quit [H3C]interface Bridge-Aggregation 2 //进入聚合接口视图 [H3C-Bridge-Aggregation2]port link-type trunk //配置端口为trunk模式 [H3C-Bridge-Aggregation2]port trunk allow-pass vlan 10 //允许vlan10通过 [H3C-Bridge-Aggregation2]quit [H3C]interface Bridge-Aggregation 1 //进入聚合接口视图 [H3C-Bridge-Aggregation1]port link-aggregation group 1 //将GigabitEthernet 1/0/1加入聚合组1 [H3C-Bridge-Aggregation1]quit [H3C]interface Bridge-Aggregation 2 //进入聚合接口视图 [H3C-Bridge-Aggregation2]port link-aggregation group 1 //将GigabitEthernet 1/0/2加入聚合组1 [H3C-Bridge-Aggregation2]quit [H3C]interface Bridge-Aggregation 1 //进入聚合接口视图 [H3C-Bridge-Aggregation1]port link-type trunk //配置端口为trunk模式 [H3C-Bridge-Aggregation1]port trunk allow-pass vlan 10 //允许vlan10通过 [H3C-Bridge-Aggregation1]quit [H3C]interface Vlanif 10 //进入vlan10接口视图 [H3C-Vlanif10]ip address 10.1.1.1 24 //配置vlan10的IP地址 [H3C-Vlanif10]quit [H3C]interface Bridge-Aggregation 1 //进入聚合接口视图 [H3C-Bridge-Aggregation1]port link-type trunk //配置端口为trunk模式 [H3C-Bridge-Aggregation1]port trunk allow-pass vlan 10 //允许vlan10通过 [H3C-Bridge-Aggregation1]quit [H3C]interface Vlanif 10 //进入vlan10接口视图 [H3C-Vlanif10]ip address 10.1.1.1 24 //配置vlan10的IP地址 [H3C-Vlanif10]quit [H3C]interface Bridge-Aggregation 1 //进入聚合接口视图 [H3C-Bridge-Aggregation1]port link-type trunk //配置端口为trunk模式 [H3C-Bridge-Aggregation1]port trunk allow-pass vlan 10 //允许vlan10通过 [H3C-Bridge-Aggregation1]quit [H3C]interface Vlanif 10 //进入vlan10接口视图 [H3C-Vlanif10]ip address 10.1.1.1 24 //配置vlan10的IP地址 [H3C-Vlanif10]quit [H3C]interface Bridge-Aggregation 1 //进入聚合接口视图 [H3C-Bridge-Aggregation1]port link-type trunk //配置端口为trunk模式 [H3C-Bridge-Aggregation1]port trunk allow-pass vlan 10 //允许vlan10通过 [H3C-Bridge-Aggregation1]quit [H3C]interface Vlanif 10 //进入vlan10接口视图 [H3C-Vlanif10]ip address 10.1.1.1 24 //配置vlan10的IP地址 [H3C-Vlanif10]quit [H3C]interface Bridge-Aggregation 1 //进入聚合接口视图 [H3C-Bridge-Aggregation1]port link-type trunk //配置端口为trunk模式 [H3C-Bridge-Aggregation1]port trunk allow-pass vlan 10 //允许vlan10通过 [H3C-Bridge-Aggregation1]quit [H3C]interface Vlanif 10 //进入vlan10接口视图 [H3C-Vlanif10]ip address 10.1.1.1 24 //配置vlan10的IP地址 [H3C-Vlanif10]quit [H3C]interface Bridge-Aggregation 1 //进入聚合接口视图 [H3C-Bridge-Aggregation1]port link-type trunk //配置端口为trunk模式 [H3C-Bridge-Aggregation1]port trunk allow-pass vlan 10 //允许vlan10通过 [H3C-Bridge-Aggregation1]quit [H3C]interface Vlanif 10 //进入vlan10接口视图 [H3C-Vlanif10]ip address 10.1.1.1 24 //配置vlan10的IP地址 [H3C-Vlanif10]quit [H3C]interface Bridge-Aggregation 1 //进入聚合接口视图 [H3C-Bridge-Aggregation1]port link-type trunk //配置端口为trunk模式 [H3C-Bridge-Aggregation1]port trunk allow-pass vlan 10 //允许vlan10通过 [H3C-Bridge-Aggregation1]quit [H3C]interface Vlanif 10 //进入vlan10接口视图 [H3C-Vlanif10]ip address 10.1.1.1 24 //配置vlan10的IP地址 [H3C-Vlanif10]quit [H3C]interface Bridge-Aggregation 1 //进入聚合接口视图 [H3C-Bridge-Aggregation1]port link-type trunk //配置端口为trunk模式 [H3C-Bridge-Aggregation1]port trunk allow-pass vlan 10 //允许vlan10通过 [H3C-Bridge-Aggregation1]quit [H3C]interface Vlanif 10 //进入vlan10接口视图 [H3C-Vlanif10]ip address 10.1.1.1 24 //配置vlan10的IP地址 [H3C-Vlanif10]quit [H3C]interface Bridge-Aggregation 1 //进入聚合接口视图 [H3C-Bridge-Aggregation1]port link-type trunk //配置端口为trunk模式 [H3C-Bridge-Aggregation1]port trunk allow-pass vlan 10 //允许vlan10通过 [H3C-Bridge-Aggregation1]quit [H3C]interface Vlanif 10 //进入vlan10接口视图 [H3C-Vlanif10]ip address 10.1.1.1 24 //配置vlan10的IP地址 [H3C-Vlanif10]quit [H3C]interface Bridge-Aggregation 1 //进入聚合接口视图 [H3C-Bridge-Aggregation1]port link-type trunk //配置端口为trunk模式 [H3C-Bridge-Aggregation1]port trunk allow-pass vlan 10 //允许vlan10通过 [H3C-Bridge-Aggregation1]quit [H3C]interface Vlanif 10 //进入vlan10接口视图 [H3C-Vlanif10]ip address 10.1.1.1 24 //配置vlan10的IP地址 [H3C-Vlanif10]quit [H3C]interface Bridge-Aggregation 1 //进入聚合接口视图 [H3C-Bridge-Aggregation1]port link-type trunk //配置端口为trunk模式 [H3C-Bridge-Aggregation1]port trunk allow-pass vlan 10 //允许vlan10通过 [H3C-Bridge-Aggregation1]quit ```

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值