内 网 :
配置 GigabitEthernet 0/0/1 加入 Trust 区域
[USG5300] firewall zone trust
[USG5300-zone-untrust] add interface GigabitEthernet 0/0/1
外网:
配置 GigabitEthernet 0/0/2 加入 Untrust 区域
[USG5300] firewall zone untrust
[USG5300-zone-untrust] add interface GigabitEthernet 0/0/2
DMZ:
[USG5300] firewall zone dmz
[USG5300-zone-untrust] add interface GigabitEthernet 0/0/3
[USG5300-zone-untrust] quit
1.4.1 Trust 和 Untrust 域间:允许内网用户访问公网
policy 1 :允许源地址为 10.10.10.0/24 的网段的报文通过
[USG5300] policy interzone trust untrust outbound
[USG5300-policy-interzone-trust-untrust-outbound] policy 1
[USG5300-policy-interzone-trust-untrust-outbound-1] policy source