目的:所有分区设备可以ping通网关(生产区,办公区)
PC2:
client1:
PC5:
client2:
总公司交换机7配置命令:
1.vlan batch 2 3
2.interface g0/0/1
3.port link-type access
4.port default vlan 2
5.int g0/0/2
6.port link-type access
7.port default vlan 3
8.int g0/0/3
9.port link-type trunk
10.port trunk allow-pass vlan 2 3
(vlan2为生产区 vlan3为办公区)
防火墙配置命令:
1.interface g0/0/0
2.service-manage all permit
配置DMZ区域server2和server3服务器:
service2:
service3:
修改安全策略生产区:
修改安全策略办公区:
测试ping:
pc2:
pc5: