# firewall statistic system enable
# interface GigabitEthernet0/0
# interface GigabitEthernet0/1
# interface GigabitEthernet0/2
# interface Secp3/0
# interface NULL0
# interface LoopBack0
# acl number 3000 match-order auto
rule 5 permit icmp
rule 10 permit ip source 202.116.*.* 0 destination 202.116.*.* 0
rule 15 permit ip source 202.116.*.* 0 destination 202.116.*.* 0
rule 20 deny ip destination 202.116.96.20 0
rule 25 permit ip
acl number 3001 match-order auto
rule 5 permit icmp
# firewall zone local
set priority 100
# firewall zone trust
set priority 85
add interface GigabitEthernet0/0
# firewall zone untrust
set priority 5
add interface GigabitEthernet0/1