juniper真实设备价格昂贵,所以我们用模拟器来模拟juniper路由器和juniper srx防火墙,拓扑很简单:
juniper router em0.0------------VM1----------------SRX ge0/0/0.0
(也就是说juniper router和srx的第一块网卡都桥接到VM1,这样就相当于juniper router与srx直连)
juniper router配置如下:
![1.PNG 091602949.png](https://s1.51cto.com/attachment/201309/091602949.png)
srx配置如下:
配置接口
![12.PNG 093307904.png](https://s1.51cto.com/attachment/201309/093307904.png)
配置静态路由
![3.PNG 093349479.png](https://s1.51cto.com/attachment/201309/093349479.png)
配置接口放行ping流量
![6.PNG 093443333.png](https://s1.51cto.com/attachment/201309/093443333.png)
测试:
![7.PNG 093736386.png](https://s1.51cto.com/attachment/201309/093736386.png)
转载于:https://blog.51cto.com/rujinfeng/1299087