R3721-F3210-F3171-HP High-End Firewalls Network Management Configuration Guide-6PW101

Table Of Contents
44
NOTE:
In this configuration example, either Device A or Device B is the firewall.
Network requirements
As shown in Figure 30, Host A and Host C belong to Department A, and access the enterprise network
through different devices. Host B and Host D belong to Department B. They also access the enterprise
network through different devices.
To ensure communication security and avoid broadcast storms, VLANs are configured in the enterprise
network to isolate Layer 2 traffic of different departments. VLAN 100 is assigned to Department A, and
VLAN 200 is assigned to Department B.
Make sure that hosts within the same VLAN can communicate with each other. Host A can communicate
with Host C, and Host B can communicate with Host D.
Figure 30 Network diagram
Configuration procedure
1. Configure Device A:
# Create VLAN 100, and assign port GigabitEthernet 0/1 to VLAN 100.
<DeviceA> system-view
[DeviceA] vlan 100
[DeviceA-vlan100] port gigabitethernet 0/1
[DeviceA-vlan100] quit
# Create VLAN 200, and assign port GigabitEthernet 0/2 to VLAN 200.
[DeviceA] vlan 200
[DeviceA-vlan200] port gigabitethernet 0/2
[DeviceA-vlan200] quit
# Configure port GigabitEthernet 0/3 as a trunk port, and assign it to VLANs 100 and 200,
enabling GigabitEthernet 0/3 to forward traffic of VLANs 100 and 200 to Device B.
[DeviceA] interface gigabitethernet 0/3
[DeviceA-GigabitEthernet0/3] port link-type trunk
[DeviceA-GigabitEthernet0/3] port trunk permit vlan 100 200
Please wait... Done.
2. Configure Device B as you configure Device A.
3. Configure Host A and Host C to be on the same IP subnet. For example, 192.168.100.0/24.
Configure Host B and Host D to be on the same IP subnet. For example, 192.168.200.0/24.