HCL显示防火墙Web页面
[H3C]security-zone name management
[H3C-security-zone-Management]import interface GigabitEthernet 1/0/1
[H3C]acl advanced 3000
[H3C-acl-ipv4-adv-3000]rule permit ip
创建域间策略
Management到local策略:
[H3C]zone-pair security source management destination local
[H3C-zone-pair-security-Management-Local]packet-filter 3000
local到management策略:
[H3C]zone-pair security source local destination management
[H3C-zone-pair-security-Management-Local]packet-filter 3000
防火墙IRF
1、1号设备关键配置点如下:
[H3C]irf member 1 renumber 1 //将1号设备配置为IRF成员1
[H3C]int range GigabitEthernet 1/0/2 to GigabitEthernet 1/0/3
[H3C-if-range]shutdown
[H3C-if-range]quit
[H3C]irf-port 1/1 //将物理端口绑定到IRF端口
[H3C-irf-port1/1]port group interface GigabitEthernet 1/0/2
[H3C-irf-port1/1]port group interface GigabitEthernet 1/0/3
[H3C-irf-port1/1]quit
[H3C]int range GigabitEthernet 1/0/2 to GigabitEthernet 1/0/3
[H3C-if-range]undo shutdown
[H3C-if-range]quit
[H3C]irf-port-configuration active //激活IRF
[H3C]save //保存配置
2、2号设备关键配置点如下:
[H3C]irf member 1 renumber 2 //将2号设备配置为IRF成员2
[H3C]int range GigabitEthernet 1/0/2 to GigabitEthernet 1/0/3
[H3C-if-range]shutdown
[H3C-if-range]quit
[H3C]irf-port 1/2 //将物理端口绑定到IRF口
[H3C-irf-port1/2]port group interface GigabitEthernet 1/0/2
[H3C-irf-port1/2]port group interface GigabitEthernet 1/0/3
[H3C-irf-port1/2]quit
[H3C]int range GigabitEthernet 1/0/2 to GigabitEthernet 1/0/3
[H3C-if-range]undo shutdown
[H3C-if-range]quit
[H3C]irf-port-configuration active //激活IRF
[H3C]save //保存配置