防火墙旁挂配置

1、核心交换机配置

acl number 2000                           
 rule 5 permit source 10.1.1.2 0                 
#                                         
traffic classifier c1 operator or         
 if-match acl 2000                                               
#                                         
traffic behavior b1                       
 redirect ip-nexthop 2.2.2.2              
 statistic enable                                                
#                                                        
traffic policy tb1 match-order config     
 classifier c1 behavior b1       
#
interface GigabitEthernet1/0/12
 port link-type trunk
 port trunk allow-pass vlan 10 20
 traffic-policy tb1 inbound

2、防火墙接口配置

3、防火墙鲁豫配置

4、防火墙策略配置