为何S5700交换机通过trunk直连防火墙USG5500,都互相无法ping通。
FW1:
#
interface Vlanif10
ip address 10.10.10.2 255.255.255.0
#
interface GigabitEthernet0/0/1
portswitch
port link-type trunk
port trunk permit vlan 10
#
firewall zone trust
set priority 85
add interface GigabitEthernet0/0/1
add interface GigabitEthernet0/0/2
add interface Vlanif10
#
firewall packet-filter default permit all
#
vlan batch 10
S1:
#
vlan 10
#
interface Vlanif10
ip address 10.10.10.1 255.255.255.0
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 10