本帖最后由 宅男女神 于 2016-11-18 21:41 编辑
- N% b2 m/ t% ~; m, i. r+ G$ f; g# w. y) r
华为模拟器做试验求助 为什么pc1还是可以通client2 附带配置+拓扑
$ [$ A6 L5 U1 k, d! X0 f
0 m- i6 @! ]0 K2 u$ A& W2 r$ V
acl number 3000 ! c% h' A+ O7 W, m9 u1 X
step 107 i- q U# H, A9 Z, j8 j! `
rule 10 deny ip source 172.16.1.0 0.0.0.255 destination 172.16.2.0 0.0.0.255 3 L7 H: U% M8 ^: J
#1 g4 U( K e+ c
aaa 9 U! _; o! N* }% d! y
authentication-scheme default) y2 B1 V6 f* [; ]$ v4 K& H8 ~
authorization-scheme default
4 l1 D7 d5 ^. m6 G' ?9 C: k accounting-scheme default; R" C- m3 a: K5 \" x# k3 P6 A
domain default
+ w8 r ^( i' H! ^8 D domain default_admin * Q) k' ~+ M1 Q3 z
local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$* X& `- l0 {( u1 R
local-user admin service-type http
5 X# X4 s" \3 W#
; x! W3 U k8 y2 O# Z3 t1 e( dfirewall zone HR' O: k6 x! W( c6 x4 R
priority 12
) N" t& c6 s5 q. F% t j$ Y, G#
! v( S% o8 c- sfirewall zone SALES+ k9 e5 b; e4 |0 E6 g% Q W) M$ R
priority 10
- C8 W" ~# |; A8 @# T5 j8 V#7 d9 L1 j$ G J) t, S" t# `
firewall zone IT4 {9 t9 E' o( w/ `. x+ ?) E/ e
priority 8% A& T4 B+ h! C& P; |+ s$ r
#9 k( i F, K. b! M
firewall zone trust
+ a4 @" ]5 P# _2 J priority 147 E7 Z4 b3 W* {) R( S, P$ e+ D
#
: j" | B7 g7 o! Ofirewall zone Local
9 U1 H @' u) X k priority 15
5 I5 e* N/ Q5 P, l# K$ I#
( z; n0 L9 p% W4 N& V! Z8 y$ i4 }firewall interzone HR SALES
) ^! F" ?! x5 n' ~( j! t firewall enable. }" u- Y) m }' G! Z6 H
packet-filter 3000 outbound
' C: i6 q! _ Z+ u' ]+ o. P6 J0 ]! m#
) U% E( y: u; `9 G9 j) C& xinterface GigabitEthernet0/0/09 `5 l) _# H' y" c7 X
ip address 172.16.1.1 255.255.255.0 : Y+ s# y5 H: B; E7 `# {$ h
zone HR
4 d8 x2 Y, O1 t& [- E9 a#- q" f( F. k6 r/ S
interface GigabitEthernet0/0/1+ A! L$ s: w( l
ip address 172.16.2.1 255.255.255.0 6 _3 @" ^/ b$ \" {. H0 I: H
zone SALES+ W& }5 D# [. H" A/ F6 A. p, R
#
1 Z e; A+ K. ?- T3 |, E' Ointerface GigabitEthernet0/0/2/ C' S- J4 E( }0 I9 N8 U W" y
ip address 172.16.3.1 255.255.255.0
' c- X0 a/ `/ }( h$ V zone IT
) c1 q0 @* N, H3 O$ j#0 W+ Y) @6 @8 p3 ?
interface GigabitEthernet4/0/0- N: X5 Q. S% R. G0 R
ip address 192.168.1.254 255.255.255.0
2 Z9 G% P* f/ @ zone trust) W$ g9 d& B6 [5 l x; q' c8 j
为什么pc1还是可以通client2
6 Y, f8 A+ }2 t! I- V( O
. P9 h) A7 `9 @" }* h
- U. P7 ~7 t1 u. ]& z9 [: W本问题来自群 22580975 ~. J7 d( s2 s. }8 j
|