透明模式采用二层转发,无需路由及NAT,不改变网络结构。
配置Device
-
配置接口的工作模式
# 切换GigabitEthernet1/0/1和GigabitEthernet1/0/2的工作模式为二层。
<Device> system-view
[Device] interface range gigabitethernet 1/0/1 gigabitethernet 1/0/2
[Device-if-range] port link-mode bridge
[Device-if-range] quit
-
配置接口加入安全域
# 将GigabitEthernet1/0/1的VLAN1加入安全域Untrust,GigabitEthernet1/0/2的VLAN1加入安全域Trust。
[Device] security-zone name untrust
[Device-security-zone-Untrust] import interface gigabitethernet 1/0/1 vlan 1
[Device-security-zone-Untrust] quit
[Device] security-zone name trust
[Device-security-zone-Trust] import interface gigabitethernet 1/0/2 vlan 1
[Device-security-zone-Trust] quit
-
配置安全策略