设置列表
对齐方式
# sysname Quidway
# firewall packet-filter enable firewall packet-filter default permit
# nat static inside ip 192.168.0.11 global ip 172.10.10.31
nat static inside ip 192.168.0.12 global ip 172.10.10.32
# firewall statistic system enable
# radius scheme system server-type huawei
# domain system
# acl number 3000
rule 1 permit ip source 172.10.10.250 0 destination 192.168.0.11 0
rule 2 permit ip source 172.10.10.250 0 destination 192.168.0.12 0
rule 100 deny ip
# interface Aux0 async mode flow
# interface GigabitEthernet0/0 ip address 172.10.10.250 255.255.255.0 nat outbound static
# interface GigabitEthernet0/1 ip address 192.168.0.220 255.255.255.0 nat outbound 3000
# interface Encrypt2/0
# interface NULL0
# firewall zone local set priority 100
# firewall zone trust add interface GigabitEthernet0/1 set priority 85
# firewall zone untrust add interface GigabitEthernet0/0 set priority 5
# firewall zone DMZ set priority 50
# firewall interzone local trust
# firewall interzone local untrust
# firewall interzone local DMZ
# firewall interzone trust untrust
# firewall interzone trust DMZ
# firewall interzone DMZ untrust
# telnet source-interface GigabitEthernet0/0
# user-interface con 0 user-interface aux 0 user-interface vty 0 4 user privilege level 3 set authentication password simple 2wsxzaq1 #
内网设备:192.168.0.11,192.168.0.12
外网设备:172.10.10.250
防火墙内网接口:192.168.0.220
防火墙外网接口:172.10.10.220
内网设备:192.168.0.11 映射至外网 172.10.10.31
内网设备:192.168.0.11 映射至外网 172.10.10.32
需求是外网设备能172.10.10.250访问内网设备,获取数据。
目前现象是外网设备能ping 通内网设备的映射地址,也能telnet通端口,但获取不了数据。
(0)
最佳答案
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论