一、试验拓扑图
二、 基础配置,实现pc1和pc2互访拓扑图内任意ip地址
基础配置:
FW:
int gi1/0/0
ip address 192.168.137.1 24
service-manage all permit
int gi1/0/1
ip address 172.16.10.10 31
service-manage all permit
firewall zone name untrust
add int gi1/0/0
firewall zone name trust
add int gi1/0/1
sercurity-policy
default action permit #默认路由策略动作设置为允许
ip route-static 0.0.0.0 0.0.0.0 192.168.137.1
ip route-static 202.100.0.0 255.255.0.0 192.168.16.2
ip route-static 192.168.16.0 24 172.16.10.11
dns resolve #dns地址解析,不配置只能ping通ip地址,无法ping通域名
dns server 223.5.5.5
dns server 223.6.6.6
Router:
int gi0/0/0
ip address 172.16.10.11 31
int gi0/0/1
ip address 192.168.16.1 24
ip route-static 202.100.0.