清除烦人的打印信息
undo info-center enable
查看完整的路由表
display ip routing-table
显示所有静态路由
display current-configuration | include ip route-static
配置静态路由
ip route-static 192.168.1.0 255.255.255.0 192.168.2.1
交换机查看接口vlan配置
display port vlan
查看所有接口的ip配置
display ip interface brief
交换机vlan配置
vlan batch 10 20
interface GigabitEthernet 0/0/1
port link-type access
port default vlan 10
interface GigabitEthernet 0/0/2
port link-type access
port default vlan 10
interface GigabitEthernet 0/0/0
port link-type trunk
port trunk allow-pass vlan 10 20
路由器vlan配置
interface GigabitEthernet 0/0/0.10
dot1q termination vid 10
ip address 192.168.1.1 255.255.255.0
arp broadcast enable
interface GigabitEthernet 0/0/0.20
dot1q termination vid 20
ip address 192.168.2.1 255.255.255.0
arp broadcast enable
路由器查看接口配置
display current-configuration interface
查看接口状态(包括 IP 地址、VLAN 信息等)
display ip interface brief
防火墙
配置信任区域
firewall zone trust
add int g0/0/1 (这里添加信任接口,内网接口)
配置非信任区域
firewall zone untrust
add int g0/0/0(添加非信任接口)
安全策略
policy interzone trust untrust outbound
policy 20
policy destination 192.168.10.0 0.0.0.255
policy destination 192.168.20.0 0.0.0.255
policy destination 192.168.30.0 0.0.0.255
policy destination192.168.40.0 0.0.0.255
action permit
启动ping服务
int g0/0/1
service-manage all permit
NAT
nat-policy interzone trust untrust outbound
policy 0
action source-nat
policy source 192.168.10.0 mask 24
policy source 192.168.20.0 mask 24
policy source 192.168.30.0 mask 24
policy source 192.168.40.0 mask 24
easy-ip GigabitEthernet 0/0/2
防火墙nat转发记录
[FW1]display firewall session table