本次实验使用PC:1
服务器:2
client:1
交换机:1 为s3700
防火墙:1 为USG6000V beta版本 (使用该设备需要虚拟镜像)
1. 访问防火墙接口
当配置好了IP地址后发现访问不了防火墙的网关地址,这时候要在防火墙的接口中配置命令:
interface GigabitEthernet1/0/1
undo shutdown
ip address 192.168.1.254 255.255.255.0
service-manage ping permit //为允许接口ping
interface GigabitEthernet1/0/2
undo shutdown
ip address 59.39.77.1 255.255.255.0
service-manage ping permit
interface GigabitEthernet1/0/3
undo shutdown
ip address 172.16.1.254 255.255.255.0
service-manage ping permit
2.定义trust、untrust、dmz区
firewall zone trust//第一步
set priority 85