拓扑结构
R2上的配置:
<Huawei>sys
[Huawei]sys R2
[R2]int G0/0/0
[R2-GigabitEthernet0/0/0]ip add 10.1.22.22 24
[R2-Ethernet0/0/0]ip add 10.1.6.254 24
[R2]ip route-static 0.0.0.0 0 10.1.22.2 #缺省静态路由,0.0.0.0包含所有IP
FW1上的配置:
<USG6000V1>sys
[USG6000V1]sys FW1
[FW1]int G1/0/0
[FW1-GigabitEthernet1/0/0]ip add 200.1.1.2 24
[FW1-GigabitEthernet1/0/0]int G1/0/1
[FW1-GigabitEthernet1/0/1]ip add 10.1.22.2 24
安全策略:
[FW1]ospf
[FW1-ospf-1]area 0
[FW1-ospf-1-area-0.0.0.0]network 200.1.1.0 0.0.0.255
[FW1]ip route-static 10.1.6.0 24 10.1.22.22
[FW1]security-policy
[FW1-policy-security]rule name t-un
[FW1-policy-security-rule-t-un]source-zone trust
[FW1-policy-security-rule-t-un]destination-zone untrust
[FW1-policy-security-rule-t-un]action permit
[FW1-policy-security]q
[FW1]nat address-group 1
[FW1-address-group-1]section 200.1.1.3
[FW1-address-group-1]q
防火墙源NAT
[FW1]nat-policy
[FW1-policy-nat]rule name nat1
[FW1-policy-nat-rule-nat1]source-zone trust
[FW1-policy-nat-rule-nat1]destination-zone untrust
[FW1-policy-nat-rule-nat1]source-address 10.1.6.6 32
[FW1-policy-nat-rule-nat1]action source-nat address-group 1
R1上的配置:
<Huawei>sys
[Huawei]sys R1
[R1]INT G0/0/0
[R1-GigabitEthernet0/0/0]IP address 200.1.1.1 24
[R1-GigabitEthernet0/0/0]INT G0/0/1
[R1-GigabitEthernet0/0/1]IP address 5.5.5.254 24
[R1-GigabitEthernet0/0/1]Q
[R1]OSPF
[R1-ospf-1]area 0
[R1-ospf-1-area-0.0.0.0]network 200.1.1.0 0.0.0.255
[R1-ospf-1-area-0.0.0.0]network 5.5.5.0 0.0.0.255
结果验证:
抓包抓R1