1:配置ip地址(略)
2:防火墙接口加区域
[fw1]firewall zone trust
[fw1-zone-trust]add int g1/0/1
[fw1-zone-trust]q
[fw1]firewall zone untrust
[fw1-zone-untrust]add int g1/0/0
[fw1-zone-untrust]q
[fw2]firewall zone trust
[fw2-zone-trust]add int g1/0/1
[fw2-zone-trust]q
[fw2]firewall zone untrust
[fw2-zone-untrust]add int g1/0/0
[fw2-zone-untrust]q
3:配置防火墙路由
[fw1]ip route-static 2.2.2.2 24 1.1.1.254
[fw2]ip route-static 1.1.1.1 24 2.2.2.254
4:创建配置tunnel口
[fw1]interface Tunnel 1
[fw1-Tunnel1]tunnel-protocol gre
[fw1-Tunnel1]ip address 172.16.1.1 24
[fw1-Tunnel1]source 1.1.1.1 //源公网地址
[fw1-Tunnel1]destination 2.2.2.2