一、实验拓扑![](https://img-blog.csdnimg.cn/8277162f9dcf4cc8ac6e479d1143dfb6.png)
二、实验目标
1、掌握华为防火墙的接口配置
2、路由配置
3、安全策略的添加
4、NAT策略的添加
三、实验步骤
1、内网主机通过防火墙进行源地址转换访问internet
2、将内网服务器得hhtp服务发布到外网,外网客户机可以通过防火墙得外网接口地址访问到
3、vlan10 主机只能访问server1得http,vlan20只能访问server1得ftp
四、实验配置
- LSW2配置命令
- <Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]vlan batch 10 20
Info: This operation may take a few seconds. Please wait for a moment...done.
[Huawei]int e0/0/01
[Huawei-Ethernet0/0/1]port link-t acc
[Huawei-Ethernet0/0/1]port def vlan 10
[Huawei-Ethernet0/0/1]int e0/0/2
[Huawei-Ethernet0/0/2]port link-t acc
[Huawei-Ethernet0/0/2]port def vlan 20
[Huawei-Ethernet0/0/2]int e0/0/3
[Huawei-Ethernet0/0/3]port link-t trunk
[Huawei-Ethernet0/0/3]port trunk allow-pass vlan 10 20
[Huawei-Ethernet0/0/3]
2、LSW1配置命令
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]vlan 10
[Huawei-vlan10]q
[Huawei]vlan 20
[Huawei-vlan20]int g0/0/1
[Huawei-GigabitEthernet0/0/1]port link-t trunk
[Huawei-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
[Huawei-GigabitEthernet0/0/1]q
[Huawei]vlan 50
[Huawei-vlan50]q
[Huawei]int g0/0/2
[Huawei-GigabitEthernet0/0/2]port link-t acc
[Huawei-GigabitEthernet0/0/2]port def vlan 50
[Huawei-GigabitEthernet0/0/2]q
[Huawei]int vlan 10
[Huawei-Vlanif10]ip add 192.168.10.254 24
[Huawei-Vlanif10]int vlan 20
[Huawei-Vlanif20]ip add 192.168.20.254 24
[Huawei-Vlanif20]int vlan 50
[Huawei-Vlanif50]ip add 10.10.10.1 24
[Huawei]ip route-static 0.0.0.0 0 10.10.10.2
3、防火墙配置