[H3C-GigabitEthernet1/0/15]show version
H3C Comware Software, Version 7.1.070, Release 6312
Copyright (c) 2004-2020 New H3C Technologies Co., Ltd. All rights reserved.
H3C S6520-22SG-SI uptime is 0 weeks, 0 days, 0 hours, 6 minutes
Last reboot reason : User reboot
Boot image: flash:/S6520SGSI-cmw710-boot-r6312.bin
Boot image version: 7.1.070, Release 6312
Compiled Jan 10 2020 11:00:00
System image: flash:/S6520SGSI-cmw710-system-r6312.bin
System image version: 7.1.070, Release 6312
Compiled Jan 10 2020 11:00:00
Feature image(s) list:
flash:/S6520SGSI-cmw710-freeradius-r6312.bin, version: 7.1.070
Compiled Jan 10 2020 11:00:00
flash:/S6520SGSI-cmw710-escan-r6312.bin, version: 7.1.070
Compiled Jan 10 2020 11:00:00
1. 接口1/0/15连接外网:
[H3C-GigabitEthernet1/0/15]show interface GigabitEthernet 1/0/15
GigabitEthernet1/0/15
Current state: UP
Line protocol state: UP
Description: GigabitEthernet1/0/15 Interface
Bandwidth: 1000000 kbps
Maximum transmission unit: 1500
Allow jumbo frames to pass
Broadcast max-ratio: 100%
Multicast max-ratio: 100%
Unicast max-ratio: 100%
Internet address: 10.0.30.180/24 (primary)
IP packet frame type: Ethernet II, hardware address: 905d-7c5e-ce88
IPv6 packet frame type: Ethernet II, hardware address: 905d-7c5e-ce88
Media type is twisted pair
Port hardware type is 1000_BASE_T
Port priority: 0
1000Mbps-speed mode, full-duplex mode
Link speed type is autonegotiation, link duplex type is autonegotiation
Flow-control is not enabled
The Maximum Frame Length is 10000
Last link flapping: 0 hours 15 minutes 45 seconds
Last clearing of counters: Never
2.vlan 1连接内网网络192.168.1.0/24, 连接服务器IP: 192.168.1.100
[H3C]show interface Vlan-interface 1
Vlan-interface1
Current state: UP
Line protocol state: UP
Description: Vlan-interface1 Interface
Bandwidth: 10000000 kbps
Maximum transmission unit: 1500
Internet address: 192.168.1.1/24 (primary)
IP packet frame type: Ethernet II, hardware address: 905d-7c5e-ce6a
IPv6 packet frame type: Ethernet II, hardware address: 905d-7c5e-ce6a
Last clearing of counters: Never
[H3C]ping 192.168.1.100
Ping 192.168.1.100 (192.168.1.100): 56 data bytes, press CTRL+C to break
56 bytes from 192.168.1.100: icmp_seq=0 ttl=64 time=0.730 ms
56 bytes from 192.168.1.100: icmp_seq=1 ttl=64 time=0.552 ms
56 bytes from 192.168.1.100: icmp_seq=2 ttl=64 time=0.443 ms
56 bytes from 192.168.1.100: icmp_seq=3 ttl=64 time=0.506 ms
56 bytes from 192.168.1.100: icmp_seq=4 ttl=64 time=0.485 ms
3.配置了acl
[H3C]show acl 2000
Basic IPv4 ACL 2000, 1 rule,
ACL's step is 5, start ID is 0
rule 0 permit source 192.168.1.0 0.0.0.255
4.配置了nat outbound
[H3C-GigabitEthernet1/0/15]nat outbound 2000
[H3C-GigabitEthernet1/0/15]show nat all
NAT outbound information:
Totally 1 NAT outbound rules.
Interface: GigabitEthernet1/0/15
ACL: 2000 Address group: --- Port-preserved: N
NO-PAT: N Reversible: N
Service card: ---
Config status: Active
NAT logging:
Log enable : Disabled
Flow-begin : Disabled
Flow-end : Disabled
Flow-active : Disabled
Port-block-assign : Disabled
Port-block-withdraw : Disabled
Alarm : Disabled
NAT mapping behavior:
Mapping mode : Address and Port-Dependent
ACL : ---
Config status: Active
NAT ALG:
DNS : Enabled
FTP : Enabled
H323 : Enabled
ICMP-ERROR : Enabled
ILS : Enabled
MGCP : Enabled
NBT : Enabled
PPTP : Enabled
RTSP : Enabled
RSH : Enabled
SCCP : Enabled
SIP : Enabled
SQLNET : Enabled
TFTP : Enabled
XDMCP : Enabled
Static NAT load balancing: Disabled
nat不生效,服务器192.168.1.100上ping 10.0.50.111,收到的包还是192.168.1.100
192.168.1.100 > 10.0.50.111: ICMP echo request, id 9, seq 29389, length 64
10.0.50.111 > 192.168.1.100: ICMP echo reply, id 9, seq 29389, length 64
192.168.1.100 > 10.0.50.111: ICMP echo request, id 9, seq 29390, length 64
10.0.50.111 > 192.168.1.100: ICMP echo reply, id 9, seq 29390, length 64
192.168.1.100 > 10.0.50.111: ICMP echo request, id 9, seq 29391, length 64
10.0.50.111 > 192.168.1.100: ICMP echo reply, id 9, seq 29391, length 64
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论