
[USG6000V1]int g1/0/0 (连接外网)[USG6000V1-GigabitEthernet1/0/0]ip add 192.168.20.1 24[USG6000V1-GigabitEthernet1/0/0]vrrp vrid 1 virtual-ip 100.100.100.1 24 active(当前设备为Master角色(优先抢占)) [USG6000V1]int g1/0/2 (心跳线)[USG6000V1-GigabitEthernet1/0/2]ip add 10.0.1.1 30[USG6000V1]int g1/0/1 (连接内网)[USG6000V1-GigabitEthernet1/0/1]ip add 192.168.10.2 24[USG6000V1-GigabitEthernet1/0/1]vrrp vrid 2 virtual-ip 192.168.10.1 24 active (当前设备为Master)[USG6000V1]firewall zone untrust [USG6000V1-zone-untrust]add int g1/0/0[USG6000V1]firewall zone dmz [USG6000V1-zone-dmz]add int g1/0/2[USG6000V1]firewall zone trust [USG6000V1-zone-trust]add int g1/0/1[USG6000V1]security-policy[USG6000V1-policy-security]rule name l-d[USG6000V1-policy-security-rule-t-u]source-zone local[USG6000V1-policy-security-rule-t-u]destination-zone dmz[USG6000V1-policy-security-rule-t-u]action permit[USG6000V1]ip route-static 0.0.0.0 0 100.100.100.2[USG6000V1]hrp interface g1/0/2 remote 10.0.1.2 (指定HRP心跳线接口为 G1/0/2,对端设备IP为 10.0.1.2)[USG6000V1]hrp enable (启用HRP功能)
[USG6000V1]int g1/0/1[USG6000V1-GigabitEthernet1/0/1]ip add 192.168.10.3 24[USG6000V1-GigabitEthernet1/0/1]vrrp vrid 2 virtual-ip 192.168.10.1 standby [USG6000V1]int g1/0/0[USG6000V1-GigabitEthernet1/0/0]ip add 192.168.20.2 24[USG6000V1-GigabitEthernet1/0/0]vrrp vrid 1 virtual-ip 100.100.100.1 24 standby [USG6000V1]int g1/0/2[USG6000V1-GigabitEthernet1/0/2]ip add 10.0.1.2 30[USG6000V1]firewall zone trust [USG6000V1-zone-trust]add int g1/0/1[USG6000V1]firewall zone untrust [USG6000V1-zone-untrust]add int g1/0/0[USG6000V1]firewall zone dmz [USG6000V1-zone-dmz]add int g1/0/2[USG6000V1]security-policy[USG6000V1-policy-security]rule name l-d[USG6000V1-policy-security-rule-t-u]source-zone local[USG6000V1-policy-security-rule-t-u]destination-zone dmz[USG6000V1-policy-security-rule-t-u]action permit[USG6000V1]ip route-static 0.0.0.0 0 100.100.100.2[USG6000V1]hrp interface g1/0/2 remote 10.0.1.1 ((指定HRP心跳线接口为 G1/0/2,对端设备IP为 10.0.1.1))[USG6000V1]hrp enable(启用HRP功能)
HRP_M[USG6000V1]security-policy (+B)HRP_M[USG6000V1-policy-security]rule name t-u (+B)HRP_M[USG6000V1-policy-security-rule-t-u]source-zone trust (+B)HRP_M[USG6000V1-policy-security-rule-t-u]destination-zone untrust (+B)HRP_M[USG6000V1-policy-security-rule-t-u]action permit (+B)HRP_M[USG6000V1]nat address-group 1 (为什么要创建这个,因为是虚拟地址不能使用ensy ip 设置所以需要设置地址池)HRP_M[USG6000V1-address-group-1]section 0 100.100.100.1 100.100.100.1HRP_M[USG6000V1]nat-policy (+B)HRP_M[USG6000V1-policy-nat-rule-sw]source-zone trust (+B)HRP_M[USG6000V1-policy-nat-rule-sw]destination-zone untrust (+B)HRP_M[USG6000V1-policy-nat-rule-sw]action source-nat address-group 1 (将源IP替换为地址组1(即VRRP虚拟IP 100.100.100.1))





本文链接:https://www.jingber.cn/post/3838.html 转载需授权!

微信扫一扫,打赏作者吧~