一、网络拓扑及设计思路
二、基础配置
(一)交换机配置
[S1]undo stp en
(二)路由器配置
如图所示配置相应的接口地址,此处省略
(三)防火墙配置
[FW1-policy-security]dis th
#
security-policy
rule name LOCAL_TO_ANY
source-zone local
action permit
rule name OUT_TO_DMZ
source-zone untrust
destination-zone dmz
destination-address 155.1.121.10 mask 255.255.255.255
service protocol tcp destination-port 80
action pe