步骤简写
sys
interface g0/0/0
ip address 192.168.9.254 24
firewall zone trust 同理untrust dmz
add interface g0/0/0
q
配置策略:
firewall packet-filter default permit interzone trust untrust direction outbound
firewall packet-filter default permit interzone trust dmz direction outbound
firewall packet-filter default permit interzone dmz untrust direction inbound
firewall packet-filter default permit interzone dmz untrust direction outbound
1.配置PC机IP地址
Tpc:
unpc:
dmzpc:
2.配置防火墙接口
3.定义trust,untrust,dmz区
4.定义安全策略
5.结果
①内网可以访问外网,外网不能访问内网
②内网可以访问服务器,服务器不能访问内网
③外网和服务器可以互相访问