模拟器实现WBE登录防火墙需要用防火墙的1/0/1口连接host的virtualBox虚拟网卡,同时电脑virtualBox网卡需要配置与防火墙在同网段。(注:防火墙1/0/1默认ip为192.168.0.1)
防火墙WBE登录配置
security-zone name Management
import interface GigabitEthernet 1/0/1
acl advanced 3000
rule 3 permit ip
zone-pair security source local destination management
packet-filter 3000
zone-pair security source management destination local
packet-filter 3000
此时即可用浏览器登录防火墙WBE界面
配置防火墙1/0/0口ip并划分到相应区域
配置路由
防火墙策略配置
配置trust到untrust的策略
R1配置
interface GigabitEthernet0/0
ip address 2.2.2.1 255.255.255.0
interface GigabitEthernet0/1
ip address 1.1.1.254 255.255.255.0
ip route-static 0.0.0.0 0 2.2.2.254
R2配置
interface GigabitEthernet0/0
ip address 3.3.3.1 255.255.255.0
interface GigabitEthernet0/1
ip address 4.4.4.254 255.255.255.0
ip route-static 0.0.0.0 0 3.3.3.254
PC配置省略
完成以上即可实现PC4与PC5的通信