
firewall zone hr
priority 12
#
firewall zone sales
priority 10
#
firewall zone it
priority 8
#
firewall zone trust
priority 14
#
firewall zone Local
priority 16
#
firewall interzone hr sales
firewall enable
#
interface Ethernet0/0/0
#
interface Ethernet0/0/1
#
interface Serial0/0/0
link-protocol ppp
#
interface Serial0/0/1
link-protocol ppp
#
interface Serial0/0/2
link-protocol ppp
#
interface Serial0/0/3
link-protocol ppp
#
interface GigabitEthernet0/0/0
ip address 172.16.1.254 255.255.255.0
zone hr
#
interface GigabitEthernet0/0/1
ip address 172.16.2.254 255.255.255.0
zone sales
#
interface GigabitEthernet0/0/2
ip address 172.16.3.254 255.255.255.0
zone it
#
interface GigabitEthernet0/0/3
ip address 192.168.1.254 255.255.255.0
zone trust 拓扑和配置如上,已经按照书里配置好了,可是sales区的172.16.2.1还是可以访问hr的172.16.1.1,请问问题出在哪里?
|