现场有一条平台专线接入到F1090防火墙,对端给了我们IP是172.1.1.2,网关是172.1.1.254,我们这边内网都是192.168开头,对端说不能相互写路由访问,只能是我们内网IP转换成172.1.1.2来访问他们指定的IP和端口,想问一下内网转换成外网改如何做呢?
(0)
IP和接口根据自己实际情况改写把
vlan 1
#
interface Vlan-interface1
ip address 192.168.30.1 255.255.255.0
#
interface GigabitEthernet1/0/2
port link-mode route
ip address 172.1.1.2 255.255.255.0
nat out
#
security-zone name Trust
import interface Vlan-interface1
import interface GigabitEthernet1/0/1 vlan 1 to 4094
#
security-zone name DMZ
#
security-zone name Untrust
import interface GigabitEthernet1/0/2
#
ip route-static 0.0.0.0 0 172.1.1.254
#
security-policy ip
rule 0 name u-t
action pass
logging enable
counting enable
profile 0_IPv4
source-zone Untrust
destination-zone Trust
rule 1 name t-u
action pass
logging enable
counting enable
profile 1_IPv4
source-zone Trust
destination-zone Untrust
rule 2 name t-l
action pass
source-zone Trust
destination-zone Local
rule 3 name l-t
action pass
source-zone Local
destination-zone Trust
rule 4 name u-l
action pass
logging enable
counting enable
source-zone Untrust
destination-zone Local
rule 5 name l-u
action pass
source-zone Local
destination-zone Untrust
rule 10 name t-t
action pass
disable
logging enable
counting enable
source-zone Trust
destination-zone Untrust
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
如何设置呢