sys firewall packet-filter default permit dialer-rule 1 ip permit /创建dialer-rule 1/ acl number 2001 /配置进行NAT的ACL/ rule 0 permit source any quit interface Dialer1 /创建int dialer 1/ link-protocol ppp ppp pap local-userhuawei password simple 123456 /用来认证的ADSL帐号和密码/ ip address ppp-negotiate /IP地址通过PPP协商获取/ dialer user mypppoe dialer-group 1 /引用dialer-rule 1/ dialer bundle 1 nat outbound 2001 /引用ACL 2001进行Easy IP NAT/ quit interface Ethernet1/0 ip address 192.168.1.1 255.255.255.0 quit interface Ethernet2/0 pppoe-client dial-bundle-number 1 /将e0/1绑定到dialer 1口,此口作为wan口/ quit firewall zone untrust add interface Ethernet2/0 add interface Dialer1 quit firewall zone trust add interface Ethernet1/0 quit ip route-static 0.0.0.0 0.0.0.0 Dialer 1 preference 60 /配置dialer 1作为默认路由出口/ save //保存配置 上述配置没有问题,结果还是不通,可能是ppoe拨号方式认证的问题,增加如下命令: interface Dialer1 ppp chap user 290122660 ppp chap password cipher 123456 ppp ipcp dns admit-any ppp ipcp dns request tcp mss 1024 配置后重启动OK |