防火墙旁挂配置
1、核心交换机配置
acl number 2000 rule 5 permit source 10.1.1.2 0 # traffic classifier c1 operator or if-match acl 2000 # traffic behavior b1 redirect ip-nexthop 2.2.2.2 statistic enable # traffic policy tb1 match-order config classifier c1 behavior b1 # interface GigabitEthernet1/0/12 port link-type trunk port trunk allow-pass vlan 10 20 traffic-policy tb1 inbound
2、防火墙接口配置

3、防火墙鲁豫配置

4、防火墙策略配置
