< Home

Configuring Direct Communication Between Two Virtual Systems

Networking Requirements

As shown in Figure 1, the device is deployed between network A and network B. Virtual systems vsysa and vsysb function as network A's gateway and network B's gateway respectively to isolate and protect their respective network.

You need to configure direct communication between vsysa and vsysb so that networks A and B can communicate with each other.

Figure 1 Direct communication between two virtual systems

Configuration Roadmap

The configuration roadmap is as follows:
  1. Enable the virtual system function, create virtual systems vsysa and vsysb, and allocate resources to them.
  2. Configure interfaces for the public system, vsysa, and vsysb, and add the interfaces to security zones.
  3. Configure routes in the public system to divert traffic between networks A and B.
  4. Configure routes in vsysa and vsysb to divert traffic sent from the device to networks A and B.
  5. Configure security policies in vsysa and vsysb to permit the traffic between networks A and B.

Procedure

  1. Enable the virtual system function.

    <FW> system-view
    [FW] vsys enable

  2. Create virtual systems and allocate resources to them.

    # Create virtual system vsysa and allocate an interface to it.

    [FW] vsys name vsysa
    [FW-vsys-vsysa] assign interface GigabitEthernet 0/0/2
    [FW-vsys-vsysa] quit

    # Create virtual system vsysb and allocate an interface to it.

    [FW] vsys name vsysb
    [FW-vsys-vsysb] assign interface GigabitEthernet 0/0/1
    [FW-vsys-vsysb] quit

  3. Add the virtual interface Virtual-if0 to a security zone.

    [FW] firewall zone trust
    [FW-zone-trust] add interface Virtual-if 0
    [FW-zone-trust] quit

  4. Configure routes in the public system.

    # Configure a route from vsysa to vsysb to divert the forward traffic for network A to access network B to vsysb.

    [FW] ip route-static vpn-instance vsysa 10.3.1.0 255.255.255.0 vpn-instance vsysb

    # Configure a route from vsysb to vsysa to divert the forward traffic for network B to access network A to vsysa.

    [FW] ip route-static vpn-instance vsysb 10.3.0.0 255.255.255.0 vpn-instance vsysa

  5. Switch to the system view of vsysa.

    [FW] switch vsys vsysa
    <FW-vsysa> system-view

  6. Configure interfaces for vsysa and add the interfaces to security zones.

    [FW-vsysa] interface GigabitEthernet 0/0/2
    [FW-vsysa-GigabitEthernet0/0/2] ip address 10.3.0.1 24
    [FW-vsysa-GigabitEthernet0/0/2] quit
    [FW-vsysa] firewall zone trust
    [FW-vsysa-zone-trust] add interface GigabitEthernet 0/0/2
    [FW-vsysa-zone-trust] quit
    [FW-vsysa] firewall zone untrust
    [FW-vsysa-zone-untrust] add interface Virtual-if 1
    [FW-vsysa-zone-untrust] quit

  7. Configure a route in vsysa.

    Configure a route from vsysa to network A to divert the return traffic for network A to access network B or the forward traffic for network B to access network A to network A. 10.3.0.254 is the next-hop address of the route from vsysa to network A.

    [FW-vsysa] ip route-static 10.3.0.0 255.255.255.0 10.3.0.254

  8. Configure security policies in vsysa.

    # Configure a security policy for traffic from the Trust zone to the Untrust zone to permit traffic from network A to network B.

    [FW-vsysa] security-policy
    [FW-vsysa-policy-security] rule name vsysa_trust_to_untrust      
    [FW-vsysa-policy-security-rule-vsysa_trust_to_untrust] source-zone trust   
    [FW-vsysa-policy-security-rule-vsysa_trust_to_untrust] destination-zone untrust    
    [FW-vsysa-policy-security-rule-vsysa_trust_to_untrust] source-address 10.3.0.0 24
    [FW-vsysa-policy-security-rule-vsysa_trust_to_untrust] destination-address 10.3.1.0 24
    [FW-vsysa-policy-security-rule-vsysa_trust_to_untrust] action permit    
    [FW-vsysa-policy-security-rule-vsysa_trust_to_untrust] quit    

    # Configure a security policy for traffic from the Untrust zone to the Trust zone to permit traffic from network B to network A.

    [FW-vsysa-policy-security] rule name vsysa_untrust_to_trust      
    [FW-vsysa-policy-security-rule-vsysa_untrust_to_trust] source-zone untrust   
    [FW-vsysa-policy-security-rule-vsysa_untrust_to_trust] destination-zone trust
    [FW-vsysa-policy-security-rule-vsysa_untrust_to_trust] source-address 10.3.1.0 24   
    [FW-vsysa-policy-security-rule-vsysa_untrust_to_trust] destination-address 10.3.0.0 24
    [FW-vsysa-policy-security-rule-vsysa_untrust_to_trust] action permit    
    [FW-vsysa-policy-security-rule-vsysa_untrust_to_trust] quit    
    [FW-vsysa-policy-security] quit

  9. Switch to the system view of vsysb.

    [FW-vsysa] quit
    <FW-vsysa> quit  
    [FW] switch vsys vsysb
    <FW-vsysb> system-view

  10. Configure interfaces for vsysb and add the interfaces to security zones.

    [FW-vsysb] interface GigabitEthernet 0/0/1
    [FW-vsysb-GigabitEthernet0/0/1] ip address 10.3.1.1 24
    [FW-vsysb-GigabitEthernet0/0/1] quit
    [FW-vsysb] firewall zone trust
    [FW-vsysb-zone-trust] add interface GigabitEthernet 0/0/1
    [FW-vsysb-zone-trust] quit
    [FW-vsysb] firewall zone untrust
    [FW-vsysb-zone-untrust] add interface Virtual-if 2
    [FW-vsysb-zone-untrust] quit

  11. Configure a route in vsysb.

    Configure a route from vsysb to network B to divert the forward traffic for network A to access network B and the return traffic for network B to access network A to network B. 10.3.1.254 is the next-hop address of the route from vsysb to network B.

    [FW-vsysb] ip route-static 10.3.1.0 255.255.255.0 10.3.1.254

  12. Configure security policies in vsysb.

    # Configure a security policy for traffic from the Trust zone to the Untrust zone to permit traffic from network B to network A.

    [FW-vsysb] security-policy
    [FW-vsysb-policy-security] rule name vsysb_trust_to_untrust      
    [FW-vsysb-policy-security-rule-vsysb_trust_to_untrust] source-zone trust   
    [FW-vsysb-policy-security-rule-vsysb_trust_to_untrust] destination-zone untrust    
    [FW-vsysb-policy-security-rule-vsysb_trust_to_untrust] source-address 10.3.1.0 24
    [FW-vsysb-policy-security-rule-vsysb_trust_to_untrust] destination-address 10.3.0.0 24
    [FW-vsysb-policy-security-rule-vsysb_trust_to_untrust] action permit    
    [FW-vsysb-policy-security-rule-vsysb_trust_to_untrust] quit    

    # Configure a security policy for traffic from the Untrust zone to the Trust zone to permit traffic from network A to network B.

    [FW-vsysb-policy-security] rule name vsysb_untrust_to_trust      
    [FW-vsysb-policy-security-rule-vsysb_untrust_to_trust] source-zone untrust   
    [FW-vsysb-policy-security-rule-vsysb_untrust_to_trust] destination-zone trust
    [FW-vsysb-policy-security-rule-vsysb_untrust_to_trust] source-address 10.3.0.0 24   
    [FW-vsysb-policy-security-rule-vsysb_untrust_to_trust] destination-address 10.3.1.0 24
    [FW-vsysb-policy-security-rule-vsysb_untrust_to_trust] action permit    
    [FW-vsysb-policy-security-rule-vsysb_untrust_to_trust] quit    
    [FW-vsysb-policy-security] quit

Verifying the Configuration

  • A user on network A can access network B. In addition, the following sessions are created in vsysa and vsysb.

    10.3.1.3 is the IP address of the server on network B accessed by the user on network A. 10.3.0.2 is the IP address of the user host on network A.

    Sessions in vsysa:

    <FW> display firewall session table verbose vsys vsysa destination global 10.3.1.3
     Current Total Sessions : 1
     icmp  VPN: vsysa --> vsysb  ID: xxxxxxxxxxxxxxxxxxxxxx 
     Zone: trust --> untrust  TTL: xx:xx:xx  Left: xx:xx:xx 
     Recv Interface: GigabitEthernet 0/0/2
     Interface: Virtual-if1  NextHop: 0.0.0.0 
     <--packets: xxx bytes: xxx --> packets: xxx bytes: xxx 
     10.3.0.2:43999 --> 10.3.1.3:2048 PolicyName: vsysa_trust_to_untrust

    Sessions in vsysb:

    <FW> display firewall session table verbose vsys vsysb destination global 10.3.1.3 
     Current Total Sessions : 1
     icmp  VPN: vsysb --> vsysb  ID: xxxxxxxxxxxxxxxxxxxxxx 
     Zone: untrust --> trust  TTL: xx:xx:xx  Left: xx:xx:xx 
     Recv Interface: Virtual-if2
     Interface: GigabitEthernet 0/0/1  NextHop: 10.3.1.254  MAC: xxxx-xxxx-xxxx 
     <--packets: xxx bytes: xxx --> packets: xxx bytes: xxx 
     10.3.0.2:43999 --> 10.3.1.3:2048 PolicyName: vsysb_untrust_to_trust
  • A user on network B can access network A. In addition, the following sessions are created in vsysa and vsysb.

    10.3.0.3 is the IP address of the server on network A accessed by the user on network B. 10.3.1.2 is the IP address of the user host on network B.

    Sessions in vsysa:

    <FW> display firewall session table verbose vsys vsysa destination global 10.3.0.3 
     Current Total Sessions : 1
     icmp  VPN: vsysa --> vsysa  ID: xxxxxxxxxxxxxxxxxxxxxx 
     Zone: untrust --> trust  TTL: xx:xx:xx  Left: xx:xx:xx 
     Recv Interface: Virtual-if1  
     Interface: GigabitEthernet 0/0/2  NextHop: 10.3.0.254  MAC: xxxx-xxxx-xxxx 
     <--packets: xxx bytes: xxx --> packets: xxx bytes: xxx 
     10.3.1.2:43999 --> 10.3.0.3:2048 PolicyName: vsysa_untrust_to_trust

    Sessions in vsysb:

    <FW> display firewall session table verbose vsys vsysb destination global 10.3.0.3
     Current Total Sessions : 1
     icmp  VPN: vsysb --> vsysa  ID: xxxxxxxxxxxxxxxxxxxxxx 
     Zone: trust --> untrust  TTL: xx:xx:xx  Left: xx:xx:xx 
     Recv Interface: GigabitEthernet 0/0/1  
     Interface: Virtual-if2  NextHop: 0.0.0.0 
     <--packets: xxx bytes: xxx --> packets: xxx bytes: xxx 
     10.3.1.2:43999 --> 10.3.0.3:2048 PolicyName: vsysb_trust_to_untrust

Configuration Scripts

  • Public system (public)
    #
     sysname FW
    #
     vsys enable 
    #
    vsys name vsysa 1 
     assign interface GigabitEthernet0/0/2
    #
    vsys name vsysb 2 
     assign interface GigabitEthernet0/0/1
    # 
    interface Virtual-if 0  
     ip address 172.16.0.1 255.255.255.0       
    # 
    firewall zone trust 
     set priority 85  
     add interface Virtual-if0 
    #
     ip route-static vpn-instance vsysa 10.3.1.0 255.255.255.0 vpn-instance vsysb
     ip route-static vpn-instance vsysb 10.3.0.0 255.255.255.0 vpn-instance vsysa
    #
    return 
  • Virtual system (vsysa)
    #
    interface GigabitEthernet0/0/2
     ip address 10.3.0.1 255.255.255.0   
    # 
    interface Virtual-if 1  
     ip address 172.16.1.1 255.255.255.0       
    #
    firewall zone trust
     set priority 85  
     add interface GigabitEthernet0/0/2 
    #
    firewall zone untrust 
    set priority 5   
     add interface Virtual-if1      
    #
     ip route-static 10.3.0.0 255.255.255.0 10.3.0.254
    #
    security-policy   
     rule name vsysa_trust_to_untrust
      source-zone trust   
      destination-zone untrust    
      source-address 10.3.0.0 mask 255.255.255.0
      destination-address 10.3.1.0 mask 255.255.255.0
      action permit
     rule name vsysa_untrust_to_trust
      source-zone untrust   
      destination-zone trust
      source-address 10.3.1.0 mask 255.255.255.0
      destination-address 10.3.0.0 mask 255.255.255.0
      action permit     
    #
    return 
  • Virtual system (vsysb)
    #
    interface GigabitEthernet0/0/1
     ip address 10.3.1.1 255.255.255.0   
    # 
    interface Virtual-if 2  
     ip address 172.16.2.1 255.255.255.0       
    #
    firewall zone trust
     set priority 85  
     add interface GigabitEthernet0/0/1    
    #
    firewall zone untrust 
    set priority 5   
     add interface Virtual-if2      
    #
     ip route-static 10.3.1.0 255.255.255.0 10.3.1.254
    #
    security-policy   
     rule name vsysb_trust_to_untrust
      source-zone trust   
      destination-zone untrust    
      source-address 10.3.1.0 mask 255.255.255.0
      destination-address 10.3.0.0 mask 255.255.255.0
      action permit
     rule name vsysb_untrust_to_trust
      source-zone untrust   
      destination-zone trust
      source-address 10.3.0.0 mask 255.255.255.0 
      destination-address 10.3.1.0 mask 255.255.255.0
      action permit     
    #
    return 
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >