一、实验拓扑:
3-华为防火墙:公共地址集、安全策略匹配顺序_第1张图片
二、实验要求:

三、命令部署:
1、手工调整策略之间的优先级:
[SRG-policy-interzone-trust-untrust-outbound]policy 0
[SRG-policy-interzone-trust-untrust-outbound]policy 1
[SRG-policy-interzone-trust-untrust-outbound]policy move 1 before 0
[SRG-policy-interzone-trust-untrust-outbound]display this
policy interzone trust untrust outbound
policy 1 //1排在了0前边
policy 0
2、开启自动排列:
[SRG-policy-interzone-trust-untrust-outbound]undo policy 0
[SRG-policy-interzone-trust-untrust-outbound]undo policy 1
[SRG-policy-interzone-trust-untrust-outbound]policy create-mode auto-sort enable
[SRG-policy-interzone-trust-untrust-outbound]policy 2
[SRG-policy-interzone-trust-untrust-outbound-2]policy 5
[SRG-policy-interzone-trust-untrust-outbound-5]policy 7
[SRG-policy-interzone-trust-untrust-outbound]display this
policy interzone trust untrust outbound
policy create-mode auto-sort enable
policy 2
policy 5
policy 7