一、配置思路
1.配置主机IP
2.配置防火墙IP
3.配置路由器IP
4.配置区域
5.配置安全策略
6.配置静态路由
例子:通过静态路由实现PC7ping通PC6
二、配置过程
1.配置主机IP
2.配置防火墙IP
sys
sysname FW2
interface GigabitEthernet 1/0/0
ip address 1.1.1.254 24
interface GigabitEthernet 1/0/1
ip address 2.2.2.2 24
3.配置路由器IP
sys
sysname R1
interface Ethernet 0/0/0
ip address 2.2.2.1 24
interface Ethernet 0/0/1
ip address 3.3.3.254 24
4.配置区域【FW2】
firewall zone trust
add interface GigabitEthernet 1/0/0
firewall zone untrust
add interface GigabitEthernet 1/0/1
5.配置安全策略
security-policy
rule name pc7_pc6
source-zone trust
destination-zone untrust
source-address 1.1.1.1 32
destination-address 3.3.3.3 32
service icmp
action permit
rule name pc7_pc6
source-zone untrust
destination-zone trust
source-address 3.3.3.3 32
destination-address 1.1.1.1 32
service icmp
action permit
6.设置静态路由
【FW2】ip route-static 3.3.3.0 24 2.2.2.1
【R1】ip route-static 1.1.1.0 24 2.2.2.2