防火墙旁挂部署 - PBR方式
所有配置均基于HCL配置。基于PBR,不改变现有拓扑的方式进行防火墙旁挂的引流。
所有配置均基于HCL配置。
基于PBR,不改变现有拓扑的方式进行防火墙旁挂的引流。
拓扑图

描述
1、MSR36-20_1的Loopback0 口为1.1.1.1 用来模拟Internet。
2、整个网络采用OSPF动态路由协议来实现互联互通。
3、MSR36-20_5的Loopback 0 口5.5.5.5用来模拟局域内网。
4、S5820V2-54QS-GE_2为核心交换机。
5、两台F1060设备用来当做防火墙,一主一备。
6、防火墙旁挂网络,不中断现有的网络路由。
问题
1、在交换机新增两个vlan 100 200。
2、需要注意vlan 100 用来当做防火墙的Trust,vlan 200当做防火墙的Untrust。
3、交换机需要关闭快速转发功能。
4、所有设备开启ip unreachables enable、ip ttl-expires enable方便tracert查看现象。
配置
MSR36-20_5
接口IP配置 略
ospf 1 router-id 5.5.5.5
area 0.0.0.0
network 5.5.5.5 0.0.0.0
network 192.168.10.10 0.0.0.0
ip unreachables enable
ip ttl-expires enable
S5820V2-54QS-GE_2
ospf 1 router-id 2.2.2.2
area 0.0.0.0
network 2.2.2.2 0.0.0.0
network 192.168.10.254 0.0.0.0
network 192.168.100.254 0.0.0.0
area 0.0.0.1
network 12.1.1.2 0.0.0.0
network 192.168.200.254 0.0.0.0
#
ip unreachables enable
ip ttl-expires enable
undo ip fast-forwarding load-sharing
policy-based-route from_10 permit node 10
if-match acl 2000
apply next-hop 192.168.100.253
#
policy-based-route from_1 permit node 10
if-match acl 2001
apply next-hop 192.168.200.253
#
interface Bridge-Aggregation1
port link-type trunk
port trunk permit vlan 1 100 200
#
interface Bridge-Aggregation2
port link-type trunk
port trunk permit vlan 1 100 200
interface LoopBack0
description ospf-id
ip address 2.2.2.2 255.255.255.255
#
interface Vlan-interface10
description Trust
ip address 192.168.10.254 255.255.255.0
ip policy-based-route from_10
#
interface Vlan-interface12
description Internet
ip address 12.1.1.2 255.255.255.0
ip policy-based-route from_1
#
interface Vlan-interface100
ip address 192.168.100.254 255.255.255.0
#
interface Vlan-interface200
ip address 192.168.200.254 255.255.255.0
interface GigabitEthernet1/0/1
port link-mode bridge
port access vlan 12
combo enable fiber
#
interface GigabitEthernet1/0/2
port link-mode bridge
port access vlan 10
combo enable fiber
#
interface GigabitEthernet1/0/3
port link-mode bridge
port link-type trunk
port trunk permit vlan 1 100 200
combo enable fiber
port link-aggregation group 1
#
interface GigabitEthernet1/0/4
port link-mode bridge
port link-type trunk
port trunk permit vlan 1 100 200
combo enable fiber
port link-aggregation group 1
#
interface GigabitEthernet1/0/5
port link-mode bridge
port link-type trunk
port trunk permit vlan 1 100 200
combo enable fiber
port link-aggregation group 2
#
interface GigabitEthernet1/0/6
port link-mode bridge
port link-type trunk
port trunk permit vlan 1 100 200
combo enable fiber
port link-aggregation group 2
#
acl basic 2000
rule 0 permit source 192.168.10.0 0.0.0.255
rule 5 permit source 5.5.5.5 0
#
acl basic 2001
rule 0 permit source 1.1.1.1 0
MSR36-20_1
ospf 1 router-id 11.11.11.11
import-route direct route-policy DIRECT
area 0.0.0.1
network 11.11.11.11 0.0.0.0
network 12.1.1.1 0.0.0.0
#
ip unreachables enable
ip ttl-expires enable
#
route-policy DIRECT permit node 10
if-match ip address prefix-list DIRICT
#
ip prefix-list DIRICT index 10 permit 1.1.1.1 32
F1060
主备配置差不多,配置了remote-backup group后备用会同步配置(除接口配置、路由等)。
ospf 1 router-id 6.6.6.6
area 0.0.0.0
network 6.6.6.6 0.0.0.0
network 192.168.100.251 0.0.0.0
area 0.0.0.1
network 192.168.200.251 0.0.0.0
#
ip unreachables enable
ip ttl-expires enable
#
interface Bridge-Aggregation1
port link-type trunk
port trunk permit vlan 1 100 200
#
interface NULL0
#
interface LoopBack0
ip address 6.6.6.6 255.255.255.255
#
interface Vlan-interface100
ip address 192.168.100.251 255.255.255.0
vrrp vrid 1 virtual-ip 192.168.100.253 active
vrrp vrid 1 priority 110
vrrp vrid 1 preempt-mode delay 30
#
interface Vlan-interface200
ip address 192.168.200.251 255.255.255.0
vrrp vrid 1 virtual-ip 192.168.200.253 active
vrrp vrid 1 priority 110
vrrp vrid 1 preempt-mode delay 30
#
interface GigabitEthernet1/0/1
port link-mode route
combo enable copper
ip address 192.168.0.1 255.255.255.0
#
interface GigabitEthernet1/0/23
port link-mode route
combo enable copper
ip address 10.254.254.1 255.255.255.252
#
interface GigabitEthernet1/0/3
port link-mode bridge
port link-type trunk
port trunk permit vlan 1 100 200
combo enable copper
port link-aggregation group 1
#
interface GigabitEthernet1/0/4
port link-mode bridge
port link-type trunk
port trunk permit vlan 1 100 200
combo enable copper
port link-aggregation group 1
#
security-zone name Trust
import interface Vlan-interface100
#
security-zone name DMZ
import interface GigabitEthernet1/0/23
#
security-zone name Untrust
import interface Vlan-interface200
#
security-policy ip
rule 0 name OSPF
action pass
source-zone trust
source-zone untrust
source-zone Local
destination-zone trust
destination-zone untrust
destination-zone Local
service vrrp
service ospf
service ping
rule 1 name Internet
action pass
source-zone Trust
destination-zone Untrust
rule 2 name Untrust_Trust
action pass
source-zone Untrust
destination-zone Trust
service ping
#
remote-backup group
data-channel interface GigabitEthernet1/0/23
configuration sync-check interval 1
delay-time 1
adjust-cost ospf enable absolute 65535
local-ip 10.254.254.1
remote-ip 10.254.254.2
device-role primary
测试
MSR36-20_1

MSR36-20_5

更多推荐
所有评论(0)