F3726, F3211, F3174, R5135, R3816-HP Firewalls and UTM Devices Network Management Configuration Guide-6PW100
271
# Configure the link type of Ten-GigabitEthernet 2/0/1 as trunk. Assign the port to VLAN 102 and VLAN
103.
[Switch] interface ten-gigabitethernet 2/0/1
[Switch-Ten-GigabitEthernet2/0/1] port link-type trunk
[Switch-Ten-GigabitEthernet2/0/1] port trunk permit vlan 102 103
2. Configure the firewall module.
# Create VLAN 102 and VLAN 103.
<Firewall> system-view
[Firewall] vlan 102 to 103
# Configure the operating mode of Ten-GigabitEthernet 0/0 as Layer 2.
[Firewall] interface ten-gigabitethernet 0/0
[Firewall-Ten-GigabitEthernet0/0] port link-mode bridge
[Firewall-Ten-GigabitEthernet0/0] port link-type trunk
[Firewall-Ten-GigabitEthernet0/0] port trunk permit vlan 102 to 103
[Firewall-Ten-GigabitEthernet0/0] quit
# Create two VLAN interfaces for Ten-GigabitEthernet 0/0, VLAN-interface 102 and VLAN-interface
103.
[Firewall] interface vlan-interface 102
[Firewall-Vlan-interface102] ip address 102.0.0.3 24
[Firewall-Vlan-interface102] interface vlan-interface 103
[Firewall-Vlan-interface103] ip address 103.0.0.3 24
[Firewall-Vlan-interface103] quit
# Add Ten-GigabitEthernet 0/0 and VLAN-interface 102 to the security zone Trust.
[Firewall] zone name Trust
[Firewall-zone-Trust] import interface ten-gigabitethernet 0/0 vlan 102
[Firewall-zone-Trust] import interface vlan-interface 102
[Firewall-zone-Trust] quit
# Add Ten-GigabitEthernet 0/0 and VLAN-interface 103 to the security zone Untrust.
[Firewall] zone name Untrust
[Firewall-zone-Untrust] import interface ten-gigabitethernet 0/0 vlan 103
[Firewall-zone-Untrust] import interface vlan-interface 103