实验需求:
如图所示,PC1为公司内部网络设备,AR1为出口设备,在FW1和FW2上配置双机热备,当网络正常时PC1访问AR1路径为FW1-AR1,当FW1出现故障后,切换路径为FW2-AR1。
实现目的:
了解防火墙双机热备的配置
实验步骤:
1、配置ip地址
FW1:
interface GigabitEthernet1/0/1
ip address 10.1.100.1 255.255.255.0
interface GigabitEthernet1/0/0
ip address 100.1.1.1 255.255.255.0
interface GigabitEthernet1/0/2
ip address 12.1.1.1 255.255.255.0
FW2:
interface GigabitEthernet1/0/1
ip address 10.1.100.2 255.255.255.0
interface GigabitEthernet1/0/0
ip address 100.1.1.2 255.255.255.0
interface GigabitEthernet1/0/2
ip address 12.1.1.2 255.255.255.0
AR1:
interface GigabitEthernet0/0/0
ip address 100.1.1.3 255.255.255.0
interface LoopBack0
ip address 1.1.1.1 255.255.255.255
2、将接口加入安全区域
FW1:
firewall zone trust
add interface GigabitEthernet1/0/1
firewall zone untrust
add interface GigabitEthernet1/0/0
firewall zone dmz
add interface GigabitEth