1.配置需求
2.组网图
3.配置步骤
3.1配置连接路由器接口
[FW]int g1/0/0
[FW-GigabitEthernet1/0/0]port link-mode bridge #端口配置二层模式
[FW]security-zone name Untrust[FW-security-zone-Untrust]import int g1/0/0 vlan 1 to 4094 #端口加入到untrust域
3.2配置连接核心交换机接口
[FW]int g1/0/1
[FW-GigabitEthernet1/0/1]port link-mode bridge #端口配置二层模式
[FW]security-zone name Trust
[FW-security-zone-Trust]import int g1/0/1 vlan 1 to 4094 #端口加入到trust域
3.3配置连接核心交换机接口
[FW]object-policy ip trust-untrust #允许trust访问untrust的对象策略及规则
[FW-object-policy-ip-trust-untrust]rule pass
[FW]zone-pair security source trust destination untrust #放通源为trust,目的为untrust[FW-zone-pair-security-Trust-Untrust]object-policy apply ip trust-untrust