1. 背景介绍:
cline: 9.168.1.40
server:9.168.1.41
拓扑结构:
关键点就是让3口进来的client发往server的报文从5口发到IPS设备上,从server到client也是同样的流程,13口进来的发往client的报文从15口转出。
2. 交换机关键配置:
-
进入系统视图:
<H3C>system-view
System View: return to User View with Ctrl+Z.
-
分别创建vlan-interface 100 和 vlan -nterface 200:
[H3C] interface Vlan-interface 100
[H3C-Vlan-interface200] quit
[H3C] interface Vlan-interface 200
[H3C-Vlan-interface200] quit
vlan-interface一定要创建,否则会报“Please create the corresponding VLAN interface first.”的错误。
查看vlan-interface:
[H3C]display interface Vlan-interface
结果如下:
-
配置arp static:
[H3C]arp static 9.168.1.41 000f-e20f-0041 100 Ten-GigabitEthernet1/0/5
[H3C]arp static 9.168.1.40 000f-e20f-0040 200 Ten-GigabitEthernet1/0/15
查看arp static:
[H3C]display arp static
结果如下:
把IPS转发功能放开,试试两个地址是不是能ping通吧。