组网拓扑图如下:
任务:
client1能够访问FTP服务器Server1
PC2能够ping通FTP服务器Server1
配置命令:
FW1
1、接口IP、VRRP(VRRP加VGMP管理组)、加域
interface g0/0/1.1
vlan dot1q 10
ip add 192.168.1.253 24
vrrp vrid 10 virtual-ip 192.168.1.254 24 master
#vrrp virtual-mac en
#Can not enable virtual-mac on subinterface!
interface g0/0/1.2
vlan dot1q 20
ip address 192.168.2.253 24
vrrp vrid 20 virtual-ip 192.168.2.254 24 master
interface g0/0/3
ip add 10.1.1.253 24
vrrp vrid 2 virtual-ip 10.1.1.254 24 master
vrrp virtual-mac en
interface g0/0/2
ip add 1.1.1.1 24
quit
firewall zone trust
add int g0/0/1.1
firewall zone untrust
add int g0/0/3
firewall zone dmz