[USG6000V1]int g1/0/0 [USG6000V1-GigabitEthernet1/0/0]ip ad 192.168.1.253 24 [USG6000V1]int g1/0/1 [USG6000V1-GigabitEthernet1/0/1]ip ad 202.196.1.253 24 [USG6000V1-GigabitEthernet1/0/1]int g1/0/2 [USG6000V1-GigabitEthernet1/0/2]ip ad 10.0.0.253 24 [USG6000V1-GigabitEthernet1/0/2]int g1/0/3 [USG6000V1-GigabitEthernet1/0/3]ip ad 10.0.12.1 24
FW2:
[USG6000V1]int g1/0/1 [USG6000V1-GigabitEthernet1/0/1]ip ad 192.168.1.252 24 [USG6000V1-GigabitEthernet1/0/1]int g1/0/0 [USG6000V1-GigabitEthernet1/0/0]ip ad 10.0.0.252 24 [USG6000V1-GigabitEthernet1/0/0]int g1/0/3 [USG6000V1-GigabitEthernet1/0/3]ip ad 10.0.12.2 24 [USG6000V1-GigabitEthernet1/0/3]int g1/0/2 [USG6000V1-GigabitEthernet1/0/2]ip ad 202.196.1.252 2
步骤二
根据拓扑,将接口划入对应的安全区域。 注意:两个防火墙之间的心跳接口要必须放进信任区域
FW1:
[USG6000V1]firewall zone trust [USG6000V1-zone-trust]add interface g1/0/0 [USG6000V1-zone-trust]ad interface g1/0/3 [USG6000V1-zone-trust]q [USG6000V1]firewall zone untrust [USG6000V1-zone-untrust]ad in g1/0/1 [USG6000V1-zone-untrust]q USG6000V1]firewall zone dmz [USG6000V1-zone-dmz]ad in g1/0/2