我下面的配置那地方有问题? 我用e1/1连的路由器,ping防火墙ping不通?各位大神求教!
H3C]dis cu
#
sysname H3C
#
firewall packet-filter enable
firewall packet-filter default permit
#
insulate
#
firewall statistic system enable
#
radius scheme system
server-type extended
#
domain system
#
local-user admin
password cipher .]@USE=B,53Q=^Q`MAF4<1!!
service-type telnet
level 3
#
acl number 2000
rule 0 permit source 0.0.0.0 255.255.255.0
#
acl number 3000
rule 0 permit ip
#
interface Aux0
async mode flow
#
interface Ethernet0/0
#
interface Ethernet0/1
ip address 10.88.109.253 255.255.255.252
#
interface Ethernet0/2
#
interface Ethernet0/3
#
interface Ethernet1/0
#
interface Ethernet1/1
ip address 10.10.10.1 255.255.255.0
#
interface Ethernet1/2
#
interface NULL0
#
firewall zone local
set priority 100
#
firewall zone trust
add interface Ethernet1/1
set priority 85
#
firewall zone untrust
add interface Ethernet0/1
set priority 5
#
firewall zone DMZ
set priority 50
#
firewall interzone local trust
#
firewall interzone local untrust
#
firewall interzone local DMZ
#
firewall interzone trust untrust
#
firewall interzone trust DMZ
#
firewall interzone DMZ untrust
#
ip route-static 0.0.0.0 0.0.0.0 Ethernet 0/1 10.88.109.253 preference 60
ip route-static 10.88.109.0 255.255.255.128 10.10.10.2 preference 60
#
user-interface con 0
user-interface aux 0
user-interface vty 0 4
#
return
分享至: