华为防火墙配置如下:
acl number 3001
rule 0 permit ip
rule 5 permit ip source 12.1.1.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
acl number 3002
rule 0 permit ip source 192.168.1.0 0.0.0.255 destination 12.1.1.0 0.0.0.255
#
firewall statistic system enable
#
firewall packet-filter default permit interzone local trust direction inbound
firewall packet-filter default permit interzone local trust direction outbound
firewall packet-filter default permit interzone local untrust direction inbound
firewall packet-filter default permit interzone local untrust direction outbound
firewall packet-filter default permit interzone local rc31 direction inbound
firewall packet-filter default permit interzone local rc31 direction outbound
firewall packet-filter default permit interzone local apg40extend direction inbound
firewall packet-filter default permit interzone local apg40extend direction outbound
firewall packet-filter default permit interzone local qi15 direction inbound
firewall packet-filter default permit interzone local qi15 direction outbound
#
interface GigabitEthernet0/0/0
ip address 192.168.1.1 255.255.255.0
#
interface GigabitEthernet0/0/3
ip address 12.1.1.1 255.255.255.0
#
firewall zone local
set priority 100
#
firewall zone trust
set priority 85
add interface GigabitEthernet0/0/0
#
firewall zone untrust
set priority 5
add interface GigabitEthernet0/0/3