1. 程式人生 > >3-華為防火墻:公共地址集、安全策略匹配順序

3-華為防火墻:公共地址集、安全策略匹配順序

-m -o cef water splay 優先 實驗 inter sort

一、實驗拓撲:
技術分享圖片
二、實驗要求:

三、命令部署:
1、手工調整策略之間的優先級:
[SRG-policy-interzone-trust-untrust-outbound]policy 0
[SRG-policy-interzone-trust-untrust-outbound]policy 1
[SRG-policy-interzone-trust-untrust-outbound]policy move 1 before 0
[SRG-policy-interzone-trust-untrust-outbound]display this
policy interzone trust untrust outbound

policy 1 //1排在了0前邊
policy 0
2、開啟自動排列:
[SRG-policy-interzone-trust-untrust-outbound]undo policy 0
[SRG-policy-interzone-trust-untrust-outbound]undo policy 1
[SRG-policy-interzone-trust-untrust-outbound]policy create-mode auto-sort enable
[SRG-policy-interzone-trust-untrust-outbound]policy 2
[SRG-policy-interzone-trust-untrust-outbound-2]policy 5
[SRG-policy-interzone-trust-untrust-outbound-5]policy 7
[SRG-policy-interzone-trust-untrust-outbound]display this
policy interzone trust untrust outbound
policy create-mode auto-sort enable
policy 2
policy 5
policy 7

3-華為防火墻:公共地址集、安全策略匹配順序