参考までにCONFIGの一部を補足させていただきます。
【ZONE設定】
set zone "Trust" vrouter "trust-vr"
set zone "Untrust" vrouter "trust-vr"
set zone "DMZ" vrouter "trust-vr"
set zone "VLAN" vrouter "trust-vr"
set zone "Trust" tcp-rst
set zone "Untrust" block
unset zone "Untrust" tcp-rst
set zone "MGT" block
set zone "DMZ" tcp-rst
set zone "VLAN" block
set zone "VLAN" tcp-rst
set zone "Untrust" screen tear-drop
set zone "Untrust" screen syn-flood
set zone "Untrust" screen ping-death
set zone "Untrust" screen ip-filter-src
set zone "Untrust" screen land
set zone "V1-Untrust" screen tear-drop
set zone "V1-Untrust" screen syn-flood
set zone "V1-Untrust" screen ping-death
set zone "V1-Untrust" screen ip-filter-src
set zone "V1-Untrust" screen land
【I/F設定】
set interface "ethernet1" zone "Trust"
set interface "ethernet2" zone "DMZ"
set interface "ethernet3" zone "Untrust"
unset interface vlan1 ip
set interface ethernet1 ip 192.168.0.1/24
set interface ethernet1 nat
set interface ethernet2 ip 192.168.254.1/24
set interface ethernet2 nat
set interface ethernet3 ip ▲.▲.▲.▲/32
set interface ethernet3 route
unset interface vlan1 bypass-others-ipsec
unset interface vlan1 bypass-non-ip
【Policy設定】
set policy id 1 from "Trust" to "Untrust" "Any" "Any" "ANY" permit
set policy id 2 from "Untrust" to "Trust" "Any" "Any" "ANY" deny log count
set policy id 3 from "Trust" to "DMZ" "Any" "Any" "ANY" permit
set policy id 4 from "DMZ" to "Trust" "Any" "Any" "ANY" deny log count
set policy id 5 from "DMZ" to "Untrust" "Any" "Any" "ANY" permit
set policy id 7 from "Untrust" to "DMZ" "Any" "Any" "ANY" deny log count
set policy id 8 from "DMZ" to "Trust" "Any" "Any" "ANY" permit
set policy id 9 from "Untrust" to "DMZ" "Any" "Any" "ANY" permit
set policy id 10 from "Untrust" to "Trust" "Any" "Any" "ANY" permit
以上です。
お礼
早速の回答ありがとうございます。 eth2のRouteモードにしてみましたが、同様の結果になってしまいうまくいきませんでした・・・。
補足
参考までにCONFIGの一部を補足させていただきます。 【ZONE設定】 set zone "Trust" vrouter "trust-vr" set zone "Untrust" vrouter "trust-vr" set zone "DMZ" vrouter "trust-vr" set zone "VLAN" vrouter "trust-vr" set zone "Trust" tcp-rst set zone "Untrust" block unset zone "Untrust" tcp-rst set zone "MGT" block set zone "DMZ" tcp-rst set zone "VLAN" block set zone "VLAN" tcp-rst set zone "Untrust" screen tear-drop set zone "Untrust" screen syn-flood set zone "Untrust" screen ping-death set zone "Untrust" screen ip-filter-src set zone "Untrust" screen land set zone "V1-Untrust" screen tear-drop set zone "V1-Untrust" screen syn-flood set zone "V1-Untrust" screen ping-death set zone "V1-Untrust" screen ip-filter-src set zone "V1-Untrust" screen land 【I/F設定】 set interface "ethernet1" zone "Trust" set interface "ethernet2" zone "DMZ" set interface "ethernet3" zone "Untrust" unset interface vlan1 ip set interface ethernet1 ip 192.168.0.1/24 set interface ethernet1 nat set interface ethernet2 ip 192.168.254.1/24 set interface ethernet2 nat set interface ethernet3 ip ▲.▲.▲.▲/32 set interface ethernet3 route unset interface vlan1 bypass-others-ipsec unset interface vlan1 bypass-non-ip 【Policy設定】 set policy id 1 from "Trust" to "Untrust" "Any" "Any" "ANY" permit set policy id 2 from "Untrust" to "Trust" "Any" "Any" "ANY" deny log count set policy id 3 from "Trust" to "DMZ" "Any" "Any" "ANY" permit set policy id 4 from "DMZ" to "Trust" "Any" "Any" "ANY" deny log count set policy id 5 from "DMZ" to "Untrust" "Any" "Any" "ANY" permit set policy id 7 from "Untrust" to "DMZ" "Any" "Any" "ANY" deny log count set policy id 8 from "DMZ" to "Trust" "Any" "Any" "ANY" permit set policy id 9 from "Untrust" to "DMZ" "Any" "Any" "ANY" permit set policy id 10 from "Untrust" to "Trust" "Any" "Any" "ANY" permit 以上です。