1、一、搭建本次实验的拓扑防火墙一台、路由器三台、交换机一台
2、二、配置设备的接口信息
3、三、划分本次实验需要的vlanquidwaysysname s1[s1vlan batch 11 to 13[s1interface gigabitethernet 0/0/1[s1-gigabitethernet0/0/1port link-type access[s1-gigabitethernet0/0/1port default vlan 11[s1-gigabitethernet0/0/1quit[s1interface gigabitethernet 0/0/2[s1-gigabitethernet0/0/2port link-type access[s1-gigabitethernet0/0/2port default vlan 12[s1-gigabitethernet0/0/2quit[s1interface gigabitethernet 0/0/3[s1-gigabitethernet0/0/3port link-type access[s1-gigabitethernet0/0/3port default vlan 13[s1-gigabitethernet0/0/3quit[s1interface gigabitethernet 0/0/21[s1-gigabitethernet0/0/21port link-type access[s1-gigabitethernet0/0/21port default vlan 11[s1-gigabitethernet0/0/21quit[s1interface gigabitethernet 0/0/22[s1-gigabitethernet0/0/22port link-type access[s1-gigabitethernet0/0/22port default vlan 12[s1-gigabitethernet0/0/22quit[s1interface gigabitethernet 0/0/23[s1-gigabitethernet0/0/23port link-type access[s1-gigabitethernet0/0/23port default vlan 13
4、四、配置静态路由信息[r1ip route-static 0.0.0.0 0 10.0.10.254[r2ip route-static 0.0.0.0 0 10.0.20.254[r3ip route-static 0.0.0.0 0 10.0.30.254[fwip route-static 10.0.1.0 24 10.0.10.1[fwip route-static 10.0.2.0 24 10.0.20.1[fwip route-static 10.0.3.0 24 10.0.30.1
5、五、配置防火墙的区域[fwfirewall zone dmz[fw-zone-dmzadd interface gigabitethernet 1/0/2[fw-zone-dmzquit[fwfirewall zone trust[fw-zone-trustadd interface gigabitethernet 1/0/1[fw-zone-trustundo add interface gigabitethernet 0/0/0[fw-zone-trustquit[fwfirewall zone untrust[fw-zone-untrustadd interface gigabitethernet 1/0/0[fw-zone-untrustquit
6、六、配置防火墙的安全策略[fwsecurity-policy[fw-policy-securityrule name policy_sec_1[fw-policy-security-rule-policy_sec_1source-zone trust[fw-policy-security-rule-policy_sec_1destination-zone untrust[fw-policy-security-rule-policy_sec_1action permit[fw-policy-security-rule-policy_sec_1quit[fw-policy-securityrule name policy_sec_2[fw-policy-security-rule-policy_sec_2source-zone trust[fw-policy-security-rule-policy_sec_2destination-zone dmz[fw-policy-security-rule-policy_sec_2action permit[fw-policy-security-rule-policy_sec_2quit[fw-policy-securityquit
7、七、验证防火墙各个区域间通信