Configuring virtual firewalls for the USG2000&5000 series

64

This section provides an example for configuring multiple virtual firewalls (or VPN instances) on the USG to provide relatively independent services to multiple small-scale private networks. These virtual firewalls share the hardware but have the data mutually isolated to guarantee respective independence and security.
For configuration details, search for "Example for Configuring Virtual Systems" in the product documentation.

Other related questions:
Whether USG2000&5000 series virtual firewalls support transparent mode
The virtual firewall supports transparent mode. You can bind virtual firewalls in transparent mode to VLANs one by one to isolate addresses on the same network segment.

Whether USG2000&5000&6000 series virtual firewalls support hot standby
Hot standby cannot be implemented between virtual firewalls.

Configuring an address set for the USG2000&5000 series
The USG2000&5000 series supports configuring an address set using the web UI or CLI. An address set can contain IP addresses, network segments, IP address ranges, and MAC addresses and be contained in another address set. Configuring an address set using the web UI: Choose Firewall > Address > Address Set and then click Create in Address Set List. Enter or select the address set name and description, reference the address or address set, configure the IP address, and click Apply. Configuring an address set using the CLI: 1. Run the ip address-set address-set-name [ type { object | group } | vpn-instance vpn-instance-name ] * command in the system view to create an address set and access its view. 2. Run the address [ id ] { ip-address { 0 | wildcard | mask { mask-address | mask-len } } | range start-ip-address end-ip-address | address-set address-set-name | mac-address } [ description description ] command to add a member to this address set. You can run this command repeatedly to add multiple members to this address set. 3. Run the description text command to configure the address set description.

USG2000&&5000 series equipment and competitors firewall docking configuration IPSEC,Is there a command to configure tunnel detection
Yes, configure DPD.

If you have more questions, you can seek help from following ways:
To iKnow To Live Chat
Scroll to top