拓朴图:
步骤:
1、交换机分配vlan,分配网关;PC分配IP
2、防火墙划分区域
firewall zone trust
add interface G1/0/0
dis zone
3、分配IP,分配服务
service-manage ping permit
4、做安全策略(先允许所有,再细分)
security-policy
rule name a2a
action permit
5、做vrrp(三组)
vrrp vrid 1 virtual-ip 10.10.10.1 active|standby
vrrp vrid 2 virtual-ip 10.10.20.1 active|standby
vrrp vrid 3 virtual-ip 200.200.200.1 active|standby
dis vrrp brief
6、开启心跳线(全局视图下做)
hrp interface G1/0/3 remode 1.1.1.2
hrp enable
dis hrp state