1做条local到untrsut的策略就行了。policyinterzonelocaluntrustinbound(或者outbound)policy0actiondenypolicyserviceservice-settelnet2undotelnetserverenable(看下这个命令能用不)