配置安全策略。由于已经配置双机热备功能,所以安全策略只需在USG9000_A上配置,USG9000_B会自动备份相关配置。
# 配置安全策略允许内网用户访问外网,假设内网网段为202.10.0.0/16。
HRP_M[USG9000_A]
policy interzone trust untrust outboundHRP_M[USG9000_A-policy-interzone-trust-untrust-outbound]
policy 1HRP_M[USG9000_A-policy-interzone-trust-untrust-outbound-1]
policy source 202.10.0.0 mask 16HRP_M[USG9000_A-policy-interzone-trust-untrust-outbound-1]
action permitHRP_M[USG9000_A-policy-interzone-trust-untrust-outbound-1]
quitHRP_M[USG9000_A-policy-interzone-trust-untrust-outbound]
quit# 配置上下行业务接口所在安全区域与Local区域之间的域间安全策略,允许OSPF协议报文通过。
HRP_M[USG9000_A]
ip service-set ospf type objectHRP_M[USG9000_A-object-service-set-ospf]
service protocol 89HRP_M[USG9000_A-object-service-set-ospf]
quitHRP_M[USG9000_A]
policy interzone local untrust outboundHRP_M[USG9000_A-policy-interzone-local-untrust-outbound]
policy 1HRP_M[USG9000_A-policy-interzone-local-untrust-outbound-1]
policy service service-set ospfHRP_M[USG9000_A-policy-interzone-local-untrust-outbound-1]
action permitHRP_M[USG9000_A-policy-interzone-local-untrust-outbound-1]
quitHRP_M[USG9000_A-policy-interzone-local-untrust-outbound]
quitHRP_M[USG9000_A]
policy interzone local untrust inboundHRP_M[USG9000_A-policy-interzone-local-untrust-inbound]
policy 1HRP_M[USG9000_A-policy-interzone-local-untrust-inbound-1]
policy service service-set ospfHRP_M[USG9000_A-policy-interzone-local-untrust-inbound-1]
action permitHRP_M[USG9000_A-policy-interzone-local-untrust-inbound-1]
quitHRP_M[USG9000_A-policy-interzone-local-untrust-inbound]
quitHRP_M[USG9000_A]
policy interzone local trust outboundHRP_M[USG9000_A-policy-interzone-local-trust-outbound]
policy 1HRP_M[USG9000_A-policy-interzone-local-trust-outbound-1]
policy service service-set ospfHRP_M[USG9000_A-policy-interzone-local-trust-outbound-1]
action permitHRP_M[USG9000_A-policy-interzone-local-trust-outbound-1]
quitHRP_M[USG9000_A-policy-interzone-local-trust-outbound]
quitHRP_M[USG9000_A]
policy interzone local trust inboundHRP_M[USG9000_A-policy-interzone-local-trust-inbound]
policy 1HRP_M[USG9000_A-policy-interzone-local-trust-inbound-1]
policy service service-set ospfHRP_M[USG9000_A-policy-interzone-local-trust-inbound-1]
action permitHRP_M[USG9000_A-policy-interzone-local-trust-inbound-1]
quitHRP_M[USG9000_A-policy-interzone-local-trust-inbound]
quit