千家信息网

3-华为防火墙:公共地址集、安全策略匹配顺序

发表于:2025-02-01 作者:千家信息网编辑
千家信息网最后更新 2025年02月01日,一、实验拓扑:二、实验要求:三、命令部署:1、手工调整策略之间的优先级:[SRG-policy-interzone-trust-untrust-outbound]policy 0[SRG-policy
千家信息网最后更新 2025年02月01日3-华为防火墙:公共地址集、安全策略匹配顺序

一、实验拓扑:

二、实验要求:

三、命令部署:
1、手工调整策略之间的优先级:
[SRG-policy-interzone-trust-untrust-outbound]policy 0
[SRG-policy-interzone-trust-untrust-outbound]policy 1
[SRG-policy-interzone-trust-untrust-outbound]policy move 1 before 0
[SRG-policy-interzone-trust-untrust-outbound]display this
policy interzone trust untrust outbound
policy 1 //1排在了0前边
policy 0
2、开启自动排列:
[SRG-policy-interzone-trust-untrust-outbound]undo policy 0
[SRG-policy-interzone-trust-untrust-outbound]undo policy 1
[SRG-policy-interzone-trust-untrust-outbound]policy create-mode auto-sort enable
[SRG-policy-interzone-trust-untrust-outbound]policy 2
[SRG-policy-interzone-trust-untrust-outbound-2]policy 5
[SRG-policy-interzone-trust-untrust-outbound-5]policy 7
[SRG-policy-interzone-trust-untrust-outbound]display this
policy interzone trust untrust outbound
policy create-mode auto-sort enable
policy 2
policy 5
policy 7

0