YilinChen 发表于 2020-4-14 14:49
备用防火墙上总得有回程路由吧
access-list 100 permit ip 10.99.202.0 255.255.255.0 any
route-map rm-test permit 10
match ip address 100
set ip next-hopc10.99.209.1===下一跳到备用防火墙的inside接口
核心去往主防火墙的接口
interface Port-channel1
no switchport
ip address 10.99.201.4 255.255.255.248
policy-route route-map rm-test
route inside 10.99.202.0 255.255.255.0 10.99.209.4 1---防火墙回程路由
能帮我看一下这样写是对的吗?谢谢