源地址 10.248.68.0/24 屬於TO_CMNET的vpn實例,目的地址10.248.89.0/24屬於TO_BOSS的vpn實例。
ospf 1 vpn-instance TO_CMNET ospf 2 vpn-instance TO_BOSS
路由及安全策略具體如何配置,安全策略應該是隻能選定一個vrf
(0)
vrf選入接口綁定的那個。
例如允許從TO_CMNET發起去TO_BOSS的訪問,那麼vrf選TO_CMNET。
至於路由怎麼寫,我看你用的是ospf,直接給你做個實驗吧。
防火牆關鍵配置(有些配置可以調整,比如引入路由的時候綁定路由策略、引入直連路由等):
sysname F2
#
ip vpn-instance TO_BOSS
#
address-family ipv4
route-replicate from vpn-instance TO_CMNET protocol ospf 1 advertise
#
ip vpn-instance TO_CMNET
#
address-family ipv4
route-replicate from vpn-instance TO_BOSS protocol ospf 2 advertise
#
ospf 1 router-id 2.2.2.2 vpn-instance TO_CMNET
import-route ospf 2
area 0.0.0.0
network 0.0.0.0 255.255.255.255
#
ospf 2 router-id 2.2.2.2 vpn-instance TO_BOSS
import-route ospf 1
area 0.0.0.0
network 0.0.0.0 255.255.255.255
#
interface GigabitEthernet1/0/0
port link-mode route
combo enable copper
ip binding vpn-instance TO_CMNET
ip address 10.0.12.2 255.255.255.0
#
interface GigabitEthernet1/0/1
port link-mode route
combo enable copper
ip binding vpn-instance TO_BOSS
ip address 10.0.23.2 255.255.255.0
#
security-zone name A
import interface GigabitEthernet1/0/0
#
security-zone name B
import interface GigabitEthernet1/0/1
#
security-policy ip
rule 3 name ospf-TO_CMNET
action pass
vrf TO_CMNET
service ospf
rule 4 name ospf-TO_BOSS
action pass
vrf TO_BOSS
service ospf
rule 5 name test
action pass
vrf TO_CMNET
source-ip-subnet 10.248.68.0 255.255.255.0
destination-ip-subnet 10.248.89.0 255.255.255.0
#
(0)
親~登錄後才可以操作哦!
確定你的郵箱還未認證,請認證郵箱或綁定手機後進行當前操作
舉報
×
侵犯我的權益
×
侵犯了我企業的權益
×
抄襲了我的內容
×
原文鏈接或出處
誹謗我
×
對根叔社區有害的內容
×
不規範轉載
×
舉報說明
暫無評論