拓撲圖:ide
交換機配置(LAV1):spa
vlan batch 10 20 100 //創建VLAN
interface GigabitEthernet0/0/1 //配置端口爲ACCESS與所屬VLAN
port link-type access
port default vlan 10blog
interface GigabitEthernet0/0/2
port link-type access
port default vlan 20ip
interface GigabitEthernet0/0/3
port link-type access
port default vlan 100get
interface GigabitEthernet0/0/23 //配置trunk與容許VLAN,華爲默認trunk不容許任何VLAN經過。
port link-type trunk
port trunk allow-pass vlan 10 20it
interface GigabitEthernet0/0/24
port link-type access
port default vlan 100io
AR1配置:class
interface GigabitEthernet0/0/0
ip address 202.1.1.1 255.255.255.0配置
ip route-static 0.0.0.0 0.0.0.0 202.1.1.254
AR2配置:route
interface GigabitEthernet0/0/0
ip address 192.168.1.1 255.255.255.0
ip route-static 0.0.0.0 0.0.0.0 192.168.1.254
AR3配置:
interface GigabitEthernet0/0/0
ip address 10.1.1.1 255.255.255.0
ip route-static 0.0.0.0 0.0.0.0 10.1.1.254
防火牆配置:
interface GigabitEthernet0/0/1.10
vlan-type dot1q 10
alias GigabitEthernet0/0/1.10
ip address 202.1.1.254 255.255.255.0
interface GigabitEthernet0/0/1.20
vlan-type dot1q 20
alias GigabitEthernet0/0/1.20
ip address 192.168.1.254 255.255.255.0
interface GigabitEthernet0/0/2 ip address 10.1.1.254 255.255.255.0#配置trust ZONE包含的端口firewall zone trust set priority 85 add interface GigabitEthernet0/0/0 add interface GigabitEthernet0/0/2#配置untrust ZONE包含的端口firewall zone untrust set priority 5 add interface GigabitEthernet0/0/1.10#配置DMZ ZONE包含的端口firewall zone dmz set priority 50 add interface GigabitEthernet0/0/1.20#配置策略policy interzone trust untrust outbound policy 0 action permit policy source 10.1.1.0 mask 255.255.255.0