单臂防火墙访问Internet
1.环回器与本机网卡共享
#配置命令
[FW1]
dhcp enable
vlan 1
dhcp server ip-pool 1
gateway-list 192.168.30.1
network 192.168.30.0 mask 255.255.255.0
dns-list 114.114.114.114
interface GigabitEthernet1/0/3
port link-mode route
combo enable copper
ip address 192.168.137.2 255.255.255.0
nat outbound
interface GigabitEthernet1/0/4
port link-mode route
combo enable copper
ip address 192.168.30.1 255.255.255.0
object-policy ip pass
rule 0 pass
security-zone name Trust
import interface GigabitEthernet1/0/4
security-zone name Untrust
import interface GigabitEthernet1/0/3
zone-pair security source Local destination Trust
object-policy apply ip pass
zone-pair security source Local destination Untrust
object-policy apply ip pass
zone-pair security source Trust destination Local
object-policy apply ip pass
zone-pair security source Trust destination Untrust
object-policy apply ip pass
ip route-static 0.0.0.0 0 192.168.137.1
ip http enable
ip https enable