拓扑
一、网络接口配置(web和命令行配置外网和内网接口)
system-view
interface GigabitEthernet 1/0/14
ip address 58.57.155.74 255.255.255.252
quit
interface GigabitEthernet 1/0/13
ip address 192.168.20.1 255.255.255.0
quit
二、添加静态路由
ip route-static 0.0.0.0 0 58.57.155.73
三、NAT地址转换
interface GigabitEthernet 1/0/14
nat outbound
quit
四、配置安全域及接口
security-zone name Untrust
import interface GigabitEthernet 1/0/14
quit
security-zone name trust
import interface GigabitEthernet 1/0/13
quit
五、配置域间策略
object-policy ip pass
rule 0 pass
quit
#创建Trust到Untrust域的域间策略调用pass策略
zone-pair security source Trust destination Untrust
object-policy Apply ip pass
quit
#创建Trust到Local域的域间策略调用pass策略。
zone-pair security source Trust destination Local
object-policy apply ip pass
quit
#创建Local到Trust域的域间策略调用pass策略。
zone-pair security source Local destination Trust
object-policy apply ip pass
quit