网络拓扑:
1、防火墙出口主备配置
防火墙接口划分安全区域:
[FW01]firewall zone trust
[FW01-zone-trust] add interface GigabitEthernet 1/0/0
[FW01]firewall zone untrust
[FW01-zone-untrust]add interface GigabitEthernet 1/0/1
[FW01-zone-untrust]add interface GigabitEthernet 1/0/2
防火墙接口设置IP地址:
[FW01]interface GigabitEthernet1/0/0
undo shutdown
ip address 10.1.11.1 255.255.255.0
service-manage ping permit
[FW01]interface GigabitEthernet1/0/1
undo shutdown
ip address 88.8.1.2 255.255.255.0
service-manage ping permit
[FW01]interface GigabitEthernet1/0/2
undo shutdown
ip address 99.9.1.2 255.255.255.0
service-manage ping permit
防火墙内部路由配置:
[Fw01]ip route-static 10.1.10.0 24 g 1/0/0 10.1.11.11
[Fw01]ip route-static 10.1.20.0 24 g 1/0/0 10.