IP配置
[r2]interface GigabitEthernet 0/0/0
[r2-GigabitEthernet0/0/0]ip address 13.0.0.3 24
[r2-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r2-GigabitEthernet0/0/1]ip address 100.1.1.254 24
[r2-GigabitEthernet0/0/1]interface GigabitEthernet 0/0/2
[r2-GigabitEthernet0/0/2]ip address 110.1.1.254 24
[r3]interface GigabitEthernet 0/0/0
[r3-GigabitEthernet0/0/0]ip address 12.0.0.2 24
[r3-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r3-GigabitEthernet0/0/1]ip address 210.1.1.254 24
[r3-GigabitEthernet0/0/1]interface GigabitEthernet 0/0/2
[r3-GigabitEthernet0/0/2]ip address 200.1.1.254 24
[FW]interface GigabitEthernet 0/0/0
[FW-GigabitEthernet0/0/0]service-manage all permit
[FW]interface GigabitEthernet 1/0/0
[FW-GigabitEthernet1/0/0]ip address 192.168.1.254 24
[FW-GigabitEthernet1/0/0]interface GigabitEthernet 1/0/1
[FW-GigabitEthernet1/0/1]ip address 13.0.0.1 24
[FW-GigabitEthernet1/0/1]interface GigabitEthernet 1/0/2
[FW-GigabitEthernet1/0/2]ip address 12.0.0.1 24
安全区域
[FW]firewall zone trust
[FW-zone-trust]add interface GigabitEthernet 1/0/0
[FW]firewall zone name untrust_1
[FW-zone-untrust_1]set priority 10
[FW-zone-untrust_1]add interface GigabitEthernet 1/0/1
[FW]firewall zone name untrust_2
[FW-zone-untrust_2]set priority 15
[FW-zone-untrust_2]add interface GigabitEthernet 1/0/2
真实dns
[FW]slb enable
[FW]slb
[FW-slb]group 0 dns
[FW-slb-group-0]metric roundrobin
[FW-slb-group-0]rserver 0 rip 100.1.1.1 port 53
[FW-slb-group-0]rserver 1 rip 200.1.1.1 port 53
虚拟dns
[FW]slb
[FW-slb]vserver 0 dns
[FW-slb-vserver-0]vip 10.10.10.10
[FW-slb-vserver-0]group dns
dns服务器透明代理
绑定要代理的服务器ip
透明代理策略
安全策略
nat策略
配置nat策略
配置安全策略
智能选路
IP-Link安全策略 功能
[FW-policy-security]rule name ip_link
[FW-policy-security-rule-ip_link]source-zone trust
[FW-policy-security-rule-ip_link]destination-zone untrust_1 untrust_2
[FW-policy-security-rule-ip_link]action permit
[FW]ip-link check enable
[FW]ip-link name p_1
[FW-iplink-p_1]destination 13.0.0.3 interface GigabitEthernet 1/0/1
[FW]ip-link name p_2
[FW-iplink-p_2]destination 12.0.0.2 interface GigabitEthernet 1/0/2
配置策略路由
链路带宽,过载保护机制
[FW]interface GigabitEthernet 1/0/1
[FW-GigabitEthernet1/0/1]bandwidth ingress 200000
[FW-GigabitEthernet1/0/1]bandwidth egress 200000
[FW-GigabitEthernet1/0/1]bandwidth ingress 200000 threshold 95
[FW-GigabitEthernet1/0/1]bandwidth egress 200000 threshold 95
[FW-GigabitEthernet1/0/1]gateway 13.0.0.3
[FW]interface GigabitEthernet 1/0/2
[FW-GigabitEthernet1/0/2]bandwidth ingress 100000 threshold 95
[FW-GigabitEthernet1/0/2]bandwidth egress 100000 threshold 95
[FW-GigabitEthernet1/0/2]gateway 12.0.0.2
全局选路策略