注意:接口位置的接口都必须一样,(比方说上面俩口都是1/0/0)不然你的主防火墙坏了,备份的防火墙策略和主防火墙一致,备份过去不起会不起作用
1:配置接口ip(略)
2:设置区域
[fw1]firewall zone trust
[fw1-zone-trust]add interface GigabitEthernet 1/0/1
[fw1-zone-trust]q
[fw1]firewall zone untrust
[fw1-zone-untrust]add interface g1/0/0
[fw1-zone-untrust]q
[fw1]firewall zone dmz
[fw1-zone-dmz]add int g1/0/6
[fw1-zone-dmz]q
[fw2]firewall zone trust
[fw2-zone-trust]add int g1/0/1
[fw2-zone-trust]q
[fw2]firewall zone untrust
[fw2-zone-untrust]add int g1/0/0
[fw2-zone-untrust]q
[fw2]firewall zone d