以下为H3C V5防火墙透明墙命令行配置
安全域配置
对应相应接口加入安全域
zone name Management id 0
priority 100
import interface GigabitEthernet0/0
zone name Local id 1
priority 100
zone name Trust id 2
priority 85
import interface Vlan-interface4094
import interface Bridge-Aggregation10 vlan 4094
zone name DMZ id 3
priority 50
zone name Untrust id 4
priority 5
import interface Vlan-interface2
import interface Bridge-Aggregation20 vlan 1 to 4094
switchto vd Root
zone name Management id 0
ip virtual-reassembly
zone name Local id 1
ip virtual-reassembly
zone name Trust id 2
ip virtual-reassembly
zone name DMZ id 3
ip virtual-reassembly
zone name Untrust id 4
ip virtual-reassembly
域间策略配置
interzone source Management destination Local
rule 0 permit
source-ip any_address