R3204P16-HP Load Balancing Module Typical Configuration Examples-6PW101
37
#
firewall interzone trust untrust
#
firewall interzone trust DMZ
#
firewall interzone DMZ untrust
#
ip route-static 11.0.0.0 255.0.0.0 6.0.0.2 preference 60
ip route-static 192.168.10.0 255.255.255.0 8.0.0.2 preference 60
Configurations on FW_2
Configuration procedures
1. Configure a packet filtering firewall policy.
[Sysname] firewall packet-filter enable
[Sysname] firewall packet-filter default permit
2. Configure IP addresses for interfaces.
[Sysname] interface Ethernet0/0
[Sysname-Ethernet0/0] ip address 7.0.0.1 255.0.0.0
[Sysname-Ethernet0/0] quit
[Sysname] interface Ethernet0/1
[Sysname-Ethernet0/1] ip address 9.0.0.1 255.0.0.0
[Sysname-Ethernet0/1] quit
3. Add the interfaces to security zones.
[Sysname] firewall zone trust
[Sysname-zone-trust] add interface Ethernet0/0
[Sysname-zone-trust] quit
[Sysname] firewall zone untrust
[Sysname-zone-untrust] add interface Ethernet0/1
[Sysname-zone-untrust] quit
4. Add static routes.
[Sysname] ip route-static 11.0.0.0 255.0.0.0 7.0.0.2
[Sysname] ip route-static 192.168.10.0 255.255.255.0 9.0.0.2
Configuration file
#
firewall packet-filter enable
firewall packet-filter default permit
#
interface Ethernet0/0
ip address 7.0.0.1 255.0.0.0
#
interface Ethernet0/1
ip address 9.0.0.1 255.0.0.0
#
firewall zone local
set priority 100
#