需求1:主机10.151.19.20/24访问外网把下一跳改为10.151.200.10再出去
(10.151.19.20/24访问外网,原来的下一跳是什么?)
需求2:主机10.151.19.20/24访问内网直接走原来的下一跳
(这个原来的下一跳,要保证内网可路由)
网段10.60.100.0/24和主机10.151.19.20/24之间互访直接转发
主机10.151.19.20 访问其他所有都跳转到10.151.200.10
——这个实现了。但可能内网访问有个限制,每增加一个内网网段,就要在前面再添加一个优先级高于5的条目
acl number 3002
rule 6 permit ip source 192.168.0.0 0.0.255.255 destination 10.151.19.20 0
rule 7 permit ip source 10.151.19.20 0 destination 192.168.0.0 0.0.255.255
acl number 3003
rule 8 permit ip source 172.16.0.0 0.15.255.255 destination 10.151.19.20 0
rule 9 permit ip source 10.151.19.20 0 destination 172.16.0.0 0.15.255.255
acl number 3004
rule 10 permit ip source 10.0.0.0 0.255.255.255 destination 10.151.19.20 0
rule 11 permit ip source 10.151.19.20 0 destination 10.0.0.0 0.255.255.255
acl number 3005
rule 5 permit ip source 10.151.19.20 0
traffic classifier c2 type or
if-match acl 3002
traffic classifier c3 type or
if-match acl 3003
traffic classifier c0 type or
if-match acl 3004
traffic classifier c1 type or
if-match acl 3005
trarric behavior b0
trarric behavior b1
redirect nexthop 10.151.200.10
traffic policy p1
classifier c2 behavior b0 precedence 1
classifier c3 behavior b0 precedence 1
classifier c0 behavior b0 precedence 1
classifier c1 behavior b1 precedence 5
感谢朋友做的总结。