今日喜提华为E1000E-N3防火墙一台,一接入网络的时候就掉坑里了,和一台交换机互联的时候,相互学习MAC地址都有问题,互ping就更加不行了。版本信息如下
<GDGZ-MA-DCN-DMZFW01-E1000N-XY12>disp version
2020-04-29 19:31:46.110
Huawei Versatile Routing Platform Software
VRP (R) Software, Version 5.160 (Eudemon1000E-N V500R002C00SPC600)
Copyright (C) 2013-2017 Huawei Technologies Co., Ltd
Eudemon1000E-N3 uptime is 0 week, 5 days, 8 hours, 31 minutes
IPS Signature Database Version :
IPS Engine Version : V200R002C30SPC082
AV Signature Database Version :
SA Signature Database Version : 2017060600
IP Reputation Database Version :
C&C Domain Name Database Version :
Location Database Version : 2015121515
SDRAM Memory Size : 8192 M bytes
Flash Memory Size : 16 M bytes
NVRAM Memory Size : 1024 K bytes
CF Card Memory Size : 2048 M bytes
RPU version information :
1. PCB Version : VER.A
2. CPLD Version : 105
3. BootROM Version : 170 Mar 23 2017 16:04:16
4. BootLoad Version : 170 Jun 15 2017 10:41:29
5. DiskIO Firware Version : 0x0
Slot 1 :
FIB version information :
1. PCB Version : VER.A
2. Board Type : FIBA
3. CPLD Version : 113
一番折腾之后,最后找到了原因,一个是把security-policy
从默认deny修改为默认permit,但作为一台防火墙,肯定还是要做一些策略控制的,所以可以根据需求,在security-policy下面配置策略。
<sysname> system-view
[sysname] security-policy
[sysname-policy-security] default action permit
Warning:Setting the default packet filtering to permit poses security risks.
You are advised to configure the security policy based on the actual data flows.
Are you sure you want to continue?[Y/N]y
在一个就是接口下面的service-manage,要么运行指定的应用,要么直接undo service-manage enable
interface GigabitEthernet0/0/0
undo shutdown
ip binding vpn-instance default
ip address 192.168.0.1 255.255.255.0
service-manage http permit
service-manage https permit
service-manage ping permit
service-manage ssh permit
service-manage snmp permit
service-manage telnet permit
service-manage netconf permit