物理接口 邏輯接口 防火墻的Eth-trunk 優(yōu)點: 1) 本質(zhì)是要提高鏈路的帶寬 Eth-trunk模式分類: 1) 手工負載分擔模式(默認)注意:所有鏈路都要參與轉(zhuǎn)發(fā)
第一步:新建Eth-trunk及模式 interface Eth-Trunk1mode lacp-static ---------默認手工負載分擔 第二步:定義Eth-trunk類型
第三步:把接口加入Eth-trunk組 int XXXXeth-trunk 1 方法二
防火墻上面為三層Eth-trunk interface Eth-Trunk1 mode lacp-static 第二步:接口成員加入ETH-TRUNK
檢查Eth-Trunk的配置 <FW1>display eth-trunk 1 15:10:49 2019/06/02Eth-Trunk1's state information is: Local: LAG ID:1 WorkingMode: STATIC Preempt Delay: Disable Hash Arichmetic: According to IP System Priority: 32768 System ID: 2444-27ca-fbff Least active-linknumber: 1 Max active-linknumber: 8 Operate Status: up Number of Up Port in Trunk: 2----------------------------------------------------ActorPortName Status PortType PortPri PortNo PortKey PortState WeigthGigabitEthernet0/0/1 Selected 100M 32768 2 64 10111100 1 GigabitEthernet0/0/2 Selected 100M 32768 3 64 10111100 1 Partner:----------------------------------------------------ActorPortName SysPri SystemID PortPri PortNo PortKey PortState GigabitEthernet0/0/1 32768 384c-4f60-9d20 32768 1 289 10111100 GigabitEthernet0/0/2 32768 384c-4f60-9d20 32768 2 289 10111100 防火墻的子接口 物理接口的子接口
第二步:把子接口加ZONE firewall zone trust add interface GigabitEthernet1/0/1.10#firewall zone dmz add interface GigabitEthernet1/0/1.16 檢查:
第三步:測試防火墻直連通信 [FW1]display security-policy all 21:35:50 2019/09/05 Total:1 RULE ID RULE NAME STATE ACTION HITTED -------------------------------------------------------------------------------0 default enable deny 275 -------------------------------------------------------------------------------[FW1]security-policy default action permit ----------默認全開安全策略 測試各個直接通信
注意:
interface Eth-Trunk1 port link-type trunk port trunk allow-pass vlan 10 16 40 50 配置:
注意: firewall zone trust set priority 85 add interface Eth-Trunk1.10#firewall zone untrust set priority 5#firewall zone dmz set priority 50 add interface Eth-Trunk1.16 放行安全策略
防火墻的vlanif接口 ? 實驗演示防火墻上面的vlanif接口技術
vlan batch 20 30 第二步:把接口配置成為二層
第三步:創(chuàng)建VLANIF接口 interface Vlanif20 ip address 10.1.2.10 255.255.255.0 service-manage ping permit#interface Vlanif30 ip address 10.1.3.10 255.255.255.0 service-manage ping permit 第四步:接口劃入ZONE
第五步:測試檢查 security-policy rule name trust_trust source-zone trust destination-zone trust action permit |
|