AR1
[Huawei]sy AR12
[AR12]sy AR1
[AR1]int g0/0/0
[AR1-GigabitEthernet0/0/0]ip ad 192.168.1.254 24
[AR1-GigabitEthernet0/0/0]int g0/0/1
[AR1-GigabitEthernet0/0/1]ip ad 11.1.1.1 24
[AR1-GigabitEthernet0/0/1]ospf
[AR1-ospf-1]a 0
[AR1-ospf-1-area-0.0.0.0]net 192.168.1.0 0.0.0.255
[AR1-ospf-1-area-0.0.0.0]net 11.1.1.0 0.0.0.255
[AR1]ip route-static 0.0.0.0 0 11.1.1.2
[AR1]
[USG6000V1-policy-security-rule-1]action permit
[USG6000V1-policy-security-rule-1]q
[USG6000V1-policy-security]q
[USG6000V1]nat address-group zz
[USG6000V1-address-group-zz]s
[USG6000V1-address-group-zz]section 200.1.1.10 200.1.1.20
[USG6000V1-address-group-zz]q
[USG6000V1]nat-policy
[USG6000V1-policy-nat]rule name 1
[USG6000V1-policy-nat-rule-1]source-zone trust
[USG6000V1-policy-nat-rule-1]destination-zone untrust
[USG6000V1-policy-nat-rule-1]source-address 192.168.1.0 24
[USG6000V1-policy-nat-rule-1]action nat address-group zz
[USG6000V1-policy-nat-rule-1]q
[USG6000V1-policy-nat]q
[USG6000V1]ip route-static 0.0.0.0 0 200.1.1.1
[USG6000V1]security-policy
[USG6000V1-policy-security]rule name 2
[USG6000V1-policy-security-rule-2]source-zone trust
[USG6000V1-policy-security-rule-2]destination-zone untrust
[USG6000V1-policy-security-rule-2]action permit
[USG6000V1-policy-security-rule-2]q
[USG6000V1-policy-security]q
[USG6000V1]security-policy
[USG6000V1-policy-security]rule name 3
[USG6000V1-policy-security-rule-3]source-zone untrust
[USG6000V1-policy-security-rule-3]destination-zone dmz
[USG6000V1-policy-security-rule-3]action permit
[USG6000V1-policy-security-rule-3]q
[USG6000V1-policy-security]q
[USG6000V1]nat server huawei global 200.1.1.100 inside 10.1.1.1
AR2
[AR2]int g0/0/0
[AR2-GigabitEthernet0/0/0]ip ad 200.1.1.1 24
[AR2-GigabitEthernet0/0/0]int g0/0/1
[AR2-GigabitEthernet0/0/1]ip ad 202.1.1.254 24