The FW uses virtual systems to manage departments separately, simplifying the configuration. This section describes how to implement communication between virtual systems.
As shown in Figure 1, a FW is deployed in area of the large campus network as the access gateway. The network of area A comprises the R&D and non-R&D departments, and the two departments have different network access permissions. Requirements are as follows:
Item |
Data |
Description |
|---|---|---|
vsysa |
|
- |
vsysb |
|
- |
Resource class |
|
- |

The configuration is similar to that of the R&D department except the following:
Configuration script of the public system
# sysname FW # vsys enable # resource-class r1 resource-item-limit session reserved-number 10000 maximum 50000 resource-item-limit policy reserved-number 300 resource-item-limit user reserved-number 300 resource-item-limit user-group reserved-number 10 resource-item-limit bandwidth 20 outbound # vsys name vsysa 1 assign resource-class r1 assign interface GigabitEthernet0/0/1 assign interface GigabitEthernet0/0/3 # vsys name vsysb 2 assign resource-class r1 assign interface GigabitEthernet0/0/2 assign interface GigabitEthernet0/0/4 # interface GigabitEthernet0/0/1 set public-interface # interface GigabitEthernet0/0/2 set public-interface # interface Virtual-if0 ip address 172.16.0.1 255.255.255.0 # firewall zone trust set priority 85 add interface Virtual-if0 # ip route-static vpn-instance vsysb 10.3.0.0 24 vpn-instance vsysa ip route-static vpn-instance vsysa 10.3.1.0 24 vpn-instance vsysb # return
Configuration script of vsysa
# interface GigabitEthernet0/0/1 ip address 10.1.1.8 255.255.255.0 # interface GigabitEthernet0/0/3 ip address 10.3.0.1 255.255.255.0 # interface Virtual-if1 ip address 172.16.1.1 255.255.255.0 # firewall zone trust set priority 85 add interface GigabitEthernet0/0/3 # firewall zone dmz set priority 50 add interface Virtual-if1 # firewall zone untrust set priority 5 add interface GigabitEthernet0/0/1 # ip address-set ipaddress1 type object address 0 range 10.3.0.2 10.3.0.10 # ip route-static 0.0.0.0 0.0.0.0 10.1.1.1 # security-policy rule name to_internet source-zone trust destination-zone untrust source-address address-set ipaddress1 action permit rule name to_vsysb source-zone trust destination-zone dmz source-address range 10.3.0.20 10.3.0.30 destination-address range 10.3.1.20 10.3.1.30 action permit rule name to_vsysa source-zone dmz destination-zone trust source-address range 10.3.1.20 10.3.1.30 destination-address range 10.3.0.20 10.3.0.30 action permit # nat-policy rule name nat1 source-zone trust egress-interface GigabitEthernet0/0/1 source-address address-set ipaddress1 action source-nat easy-ip # return
Configuration script of vsysb
# interface GigabitEthernet0/0/2 ip address 10.1.1.9 255.255.255.0 # interface GigabitEthernet0/0/4 ip address 10.3.1.1 255.255.255.0 # interface Virtual-if2 ip address 172.16.2.1 255.255.255.0 # firewall zone trust set priority 85 add interface GigabitEthernet0/0/4 # firewall zone dmz set priority 50 add interface Virtual-if2 # firewall zone untrust set priority 5 add interface GigabitEthernet0/0/2 # ip route-static 0.0.0.0 0.0.0.0 10.1.1.1 # security-policy rule name to_internet source-zone trust destination-zone untrust action permit rule name to_vsysa source-zone trust destination-zone dmz source-address range 10.3.1.20 10.3.1.30 destination-address range 10.3.0.20 10.3.0.30 action permit rule name to_vsysb source-zone dmz destination-zone trust source-address range 10.3.0.20 10.3.0.30 destination-address range 10.3.1.20 10.3.1.30 action permit # nat-policy rule name nat1 source-zone trust egress-interface GigabitEthernet0/0/2 action source-nat easy-ip # return