如图,192.168.110.14通过路由器移动专线nat策略提供互联网服务,通过policy-based-route不同内网网端使用不同的路由器出口,现在192.168.110.14还需要访问政务网指定IP,求提供各解决思路。
路由器配置如下:
# version 7.1.064, Release 0615P15 # sysname H3C # clock timezone Beijing add 08:00:00 clock protocol none # dialer-group 1 rule ip permit dialer-group 2 rule ip permit # nat address-group 1 address 政务专线.1 政务专线.253 # dns proxy enable # password-recovery enable # vlan 1 # policy-based-route YIDONG permit node 5 if-match acl 3200 apply next-hop 联通专线.185 # policy-based-route YIDONG permit node 10 if-match acl 3301 # policy-based-route YIDONG permit node 15 if-match acl 3302 apply next-hop 专线.77 # policy-based-route YIDONG permit node 20 if-match acl 3300 apply next-hop 移动专线.1 # policy-based-route YIDONG permit node 25 if-match acl 3303 apply output-interface Dialer0 # policy-based-route YIDONG permit node 30 if-match acl 3305 apply next-hop 政务网专线.254 apply output-interface GigabitEthernet5/1 # controller Cellular0/0 # interface Dialer0 ppp chap password cipher 密码 ppp chap user 账号 ppp ipcp dns admit-any ppp ipcp dns request ppp pap local-user 账号 password cipher 密码 dialer bundle enable dialer-group 1 dialer timer idle 0 dialer timer autodial 5 ip address ppp-negotiate nat outbound # interface Virtual-Template0 # interface NULL0 # interface GigabitEthernet0/0 port link-mode route combo enable copper ip address 联通专线IP 255.255.255.248 ip last-hop hold packet-filter 3000 inbound packet-filter name WebTelnet2 inbound packet-filter name WebHttpHttps2 inbound packet-filter 3000 outbound nat outbound nat server protocol tcp global 联通专线IP 2222 inside 192.168.100.107 22 nat server protocol tcp global 联通专线IP 10022 inside 192.168.100.105 22 nat server protocol tcp global 联通专线IP 10080 inside 192.168.100.105 80 nat server protocol tcp global 联通专线IP 11521 inside 192.168.100.105 1521 nat server protocol tcp global 联通专线IP 13021 inside 192.168.100.105 13021 nat server protocol tcp global 联通专线IP 13022 inside 192.168.100.105 13022 nat server protocol tcp global 联通专线IP 13023 inside 192.168.100.105 13023 nat server protocol tcp global 联通专线IP 13024 inside 192.168.100.105 13024 nat server protocol tcp global 联通专线IP 19014 inside 192.168.100.105 9014 nat server protocol tcp global 联通专线IP 19015 inside 192.168.100.105 9015 nat server protocol tcp global 联通专线IP 23021 inside 192.168.100.107 23021 nat server protocol tcp global 联通专线IP 23022 inside 192.168.100.107 23022 nat server protocol tcp global 联通专线IP 23023 inside 192.168.100.107 23023 nat server protocol tcp global 联通专线IP 23024 inside 192.168.100.107 23024 nat server protocol udp global 联通专线IP 500 inside 192.168.98.1 500 nat server protocol udp global 联通专线IP 4500 inside 192.168.98.1 4500 attack-defense apply policy AtkInterface2 # interface GigabitEthernet0/1 port link-mode route description H7003 combo enable copper ip address 10.10.200.1 255.255.255.0 ip policy-based-route YIDONG # interface GigabitEthernet0/2 port link-mode route combo enable copper ip address 移动专线IP1 255.255.255.0 ip last-hop hold packet-filter 3000 inbound packet-filter name WebTelnet4 inbound packet-filter name WebHttpHttps4 inbound packet-filter 3000 outbound nat outbound nat server protocol tcp global 移动专线IP2 8001 inside 192.168.110.121 80 nat server protocol tcp global 移动专线IP2 8008 inside 192.168.110.121 8008 nat server protocol tcp global 移动专线IP3 5000 inside 192.168.223.9 5000 nat server protocol tcp global 移动专线IP3 5001 inside 192.168.223.9 5001 nat server protocol tcp global 移动专线IP4 80 inside 192.168.99.195 80 nat server protocol tcp global 移动专线IP4 443 inside 192.168.99.195 443 nat server protocol tcp global 移动专线IP4 3000 inside 192.168.99.195 3000 nat server protocol tcp global 移动专线IP4 3001 inside 192.168.99.195 3001 nat server protocol tcp global 移动专线IP4 5000 inside 192.168.99.195 5000 nat server protocol tcp global 移动专线IP4 5001 inside 192.168.99.195 5001 nat server protocol tcp global 移动专线IP4 6690 inside 192.168.99.195 6690 nat server protocol tcp global 移动专线IP4 55055 inside 192.168.99.195 55055 nat server protocol tcp global 移动专线IP4 55056 inside 192.168.99.195 55056 nat server protocol tcp global 移动专线IP5 8553 inside 192.168.110.144 8553 nat server protocol tcp global 移动专线IP5 8555 inside 192.168.110.144 8555 nat server protocol tcp global 移动专线IP5 9001 inside 192.168.110.144 9001 nat server protocol tcp global 移动专线IP5 9002 inside 192.168.110.144 9002 nat server protocol tcp global 移动专线IP5 9020 inside 192.168.110.142 9020 nat server protocol tcp global 移动专线IP5 9040 inside 192.168.110.142 9040 attack-defense apply policy AtkInterface4 # interface GigabitEthernet0/3 port link-mode route combo enable copper ip address 专线 255.255.255.252 packet-filter name WebTelnet5 inbound packet-filter name WebHttpHttps5 inbound nat outbound # interface GigabitEthernet0/4 port link-mode route description Multiple_Line pppoe-client dial-bundle-number 0 # interface GigabitEthernet0/5 port link-mode route packet-filter name WebTelnet7 inbound packet-filter name WebHttpHttps7 inbound # interface GigabitEthernet5/0 port link-mode route # interface GigabitEthernet5/1 port link-mode route description Multiple_Line ip address 政务专线 255.255.255.0 ip last-hop hold nat outbound 3305 address-group 1 no-pat # interface GigabitEthernet5/2 port link-mode route # interface GigabitEthernet5/3 port link-mode route # security-zone name Local # security-zone name Trust # security-zone name DMZ # security-zone name Untrust # security-zone name Management # scheduler logfile size 16 # line class tty user-role network-operator # line class vty user-role network-operator # line vty 5 63 authentication-mode scheme user-role network-operator # ip route-static 0.0.0.0 0 联通专线网关 ip route-static 0.0.0.0 0 移动专线网关 preference 80 ip route-static 0.0.0.0 0 Dialer0 preference 90 ip route-static 0.0.0.0 0 专线网关 preference 100 ip route-static 10.11.250.0 24 192.169.250.1 ip route-static 172.30.200.0 24 GigabitEthernet0/3 专线 ip route-static 192.168.0.0 24 10.10.200.2 ip route-static 192.168.1.0 24 10.10.200.2 ip route-static 192.168.2.0 24 192.169.250.1 ip route-static 192.168.3.0 24 10.10.200.2 ip route-static 192.168.4.0 24 10.10.200.2 ip route-static 192.168.5.0 24 10.10.200.2 ip route-static 192.168.6.0 24 10.10.200.2 ip route-static 192.168.7.0 24 10.10.200.2 ip route-static 192.168.8.0 24 10.10.200.2 ip route-static 192.168.9.0 24 10.10.200.2 ip route-static 192.168.10.0 24 10.10.200.2 ip route-static 192.168.11.0 24 10.10.200.2 ip route-static 192.168.12.0 24 10.10.200.2 ip route-static 192.168.98.0 24 10.10.200.2 ip route-static 192.168.99.0 24 10.10.200.2 ip route-static 192.168.100.0 24 10.10.200.2 ip route-static 192.168.101.0 24 10.10.200.2 ip route-static 192.168.110.0 24 10.10.200.2 ip route-static 192.168.200.0 24 10.10.200.2 ip route-static 192.168.201.0 24 10.10.200.2 ip route-static 192.168.202.0 24 10.10.200.2 ip route-static 192.168.203.0 24 10.10.200.2 ip route-static 192.168.204.0 24 10.10.200.2 ip route-static 192.168.205.0 24 10.10.200.2 ip route-static 192.168.206.0 24 10.10.200.2 ip route-static 192.168.207.0 24 10.10.200.2 ip route-static 192.168.208.0 24 10.10.200.2 ip route-static 192.168.209.0 24 10.10.200.2 ip route-static 192.168.210.0 24 10.10.200.2 ip route-static 192.168.211.0 24 10.10.200.2 ip route-static 192.168.212.0 24 10.10.200.2 ip route-static 192.168.215.0 24 10.10.200.2 ip route-static 192.168.216.0 24 10.10.200.2 ip route-static 192.168.217.0 24 10.10.200.2 ip route-static 192.168.218.0 24 10.10.200.2 ip route-static 192.168.222.0 24 10.10.200.2 ip route-static 192.168.223.0 24 10.10.200.2 ip route-static 192.168.227.0 24 10.10.200.2 # info-center loghost 10.10.200.10 facility local0 info-center source default loghost level debugging # ssh server enable ssh user 用户名 service-type all authentication-type password ssh server acl 3400 # telnet client source ip 10.10.200.1 # acl basic 2000 # acl advanced 3000 rule 5 deny tcp destination-port eq 135 rule 10 deny tcp destination-port eq 137 rule 15 deny tcp destination-port eq 139 rule 20 deny tcp destination-port eq 445 rule 25 deny udp destination-port eq 445 rule 30 deny udp destination-port eq 135 rule 35 deny udp destination-port eq netbios-ns rule 40 deny udp destination-port eq netbios-ssn rule 45 deny tcp destination-port eq 138 rule 50 deny ip destination 54.37.65.160 0 rule 51 deny ip destination 124.95.131.50 0 rule 55 permit ip # acl advanced 3005 # acl advanced 3200 rule 0 permit ip source 192.168.98.123 0 # acl advanced 3300 rule 125 permit ip source 192.168.110.120 0 rule 130 permit ip source 192.168.110.121 0 rule 135 permit ip source 192.168.110.144 0 rule 140 permit ip source 192.168.110.142 0 # acl advanced 3301 rule 0 permit ip source 192.168.201.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 5 permit ip source 192.168.202.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 10 permit ip source 192.168.203.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 15 permit ip source 192.168.204.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 20 permit ip source 192.168.205.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 25 permit ip source 192.168.206.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 30 permit ip source 192.168.207.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 35 permit ip source 192.168.208.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 40 permit ip source 192.168.209.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 45 permit ip source 192.168.210.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 50 permit ip source 192.168.211.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 55 permit ip source 192.168.212.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 60 permit ip source 192.168.213.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 65 permit ip source 192.168.214.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 70 permit ip source 192.168.215.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 75 permit ip source 192.168.216.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 80 permit ip source 192.168.217.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 85 permit ip source 192.168.218.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 90 permit ip source 192.168.219.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 95 permit ip source 192.168.220.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 100 permit ip source 192.168.221.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 105 permit ip source 192.168.222.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 110 permit ip source 192.168.223.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 115 permit ip source 192.168.99.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 120 permit ip source 192.168.201.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 125 permit ip source 192.168.202.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 130 permit ip source 192.168.203.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 135 permit ip source 192.168.204.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 140 permit ip source 192.168.205.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 145 permit ip source 192.168.206.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 150 permit ip source 192.168.207.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 155 permit ip source 192.168.208.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 160 permit ip source 192.168.209.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 165 permit ip source 192.168.210.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 170 permit ip source 192.168.211.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 175 permit ip source 192.168.212.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 180 permit ip source 192.168.213.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 185 permit ip source 192.168.214.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 190 permit ip source 192.168.215.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 195 permit ip source 192.168.216.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 200 permit ip source 192.168.217.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 205 permit ip source 192.168.218.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 210 permit ip source 192.168.219.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 215 permit ip source 192.168.220.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 220 permit ip source 192.168.221.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 225 permit ip source 192.168.222.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 230 permit ip source 192.168.223.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 235 permit ip source 192.168.99.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 rule 240 permit ip source 192.168.227.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 rule 245 permit ip source 192.168.227.0 0.0.0.255 destination 192.168.98.0 0.0.0.255 # acl advanced 3302 rule 0 permit ip source 192.168.201.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 5 permit ip source 192.168.202.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 10 permit ip source 192.168.203.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 15 permit ip source 192.168.204.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 20 permit ip source 192.168.205.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 25 permit ip source 192.168.206.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 30 permit ip source 192.168.207.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 35 permit ip source 192.168.208.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 40 permit ip source 192.168.209.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 45 permit ip source 192.168.210.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 50 permit ip source 192.168.211.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 55 permit ip source 192.168.212.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 60 permit ip source 192.168.213.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 65 permit ip source 192.168.214.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 70 permit ip source 192.168.215.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 75 permit ip source 192.168.216.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 80 permit ip source 192.168.217.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 85 permit ip source 192.168.218.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 90 permit ip source 192.168.219.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 95 permit ip source 192.168.220.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 100 permit ip source 192.168.221.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 105 permit ip source 192.168.222.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 110 permit ip source 192.168.223.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 115 permit ip source 192.168.99.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 120 permit ip source 192.168.227.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 rule 125 permit ip source 192.168.98.0 0.0.0.255 destination 172.30.200.0 0.0.0.255 # acl advanced 3303 rule 5 permit ip source 192.168.99.0 0.0.0.255 rule 10 permit ip source 192.168.201.0 0.0.0.255 rule 15 permit ip source 192.168.202.0 0.0.0.255 rule 20 permit ip source 192.168.203.0 0.0.0.255 rule 25 permit ip source 192.168.204.0 0.0.0.255 rule 30 permit ip source 192.168.205.0 0.0.0.255 rule 35 permit ip source 192.168.206.0 0.0.0.255 rule 45 permit ip source 192.168.208.0 0.0.0.255 rule 50 permit ip source 192.168.209.0 0.0.0.255 rule 55 permit ip source 192.168.210.0 0.0.0.255 rule 60 permit ip source 192.168.211.0 0.0.0.255 rule 65 permit ip source 192.168.212.0 0.0.0.255 rule 70 permit ip source 192.168.213.0 0.0.0.255 rule 75 permit ip source 192.168.214.0 0.0.0.255 rule 85 permit ip source 192.168.216.0 0.0.0.255 rule 90 permit ip source 192.168.217.0 0.0.0.255 rule 100 permit ip source 192.168.219.0 0.0.0.255 rule 105 permit ip source 192.168.220.0 0.0.0.255 rule 110 permit ip source 192.168.221.0 0.0.0.255 rule 115 permit ip source 192.168.222.0 0.0.0.255 rule 120 permit ip source 192.168.223.0 0.0.0.255 rule 125 permit ip source 192.168.227.0 0.0.0.255 rule 130 permit ip source 192.168.98.0 0.0.0.255 # acl advanced 3305 rule 5 permit ip source 192.168.218.0 0.0.0.255 rule 20 permit ip source 192.168.207.0 0.0.0.255 rule 25 permit ip source 192.168.215.0 0.0.0.255 rule 30 permit ip source 192.168.110.14 0 destination 需要访问的政务IP 0 # acl advanced 3400 rule 5 permit ip source 192.168.98.0 0.0.0.255 rule 10 permit ip source 192.168.99.0 0.0.0.255 rule 15 permit ip source 192.168.0.0 0.0.255.255 rule 100 deny ip # password-control enable undo password-control aging enable undo password-control history enable password-control length 6 password-control login-attempt 3 exceed lock-time 10 password-control update-interval 0 password-control login idle-time 0 password-control complexity user-name check # domain system # domain default enable system # role name level-0 description Predefined level-0 role # role name level-1 description Predefined level-1 role # role name level-2 description Predefined level-2 role # role name level-3 description Predefined level-3 role # role name level-4 description Predefined level-4 role # role name level-5 description Predefined level-5 role # role name level-6 description Predefined level-6 role # role name level-7 description Predefined level-7 role # role name level-8 description Predefined level-8 role # role name level-9 description Predefined level-9 role # role name level-10 description Predefined level-10 role # role name level-11 description Predefined level-11 role # role name level-12 description Predefined level-12 role # role name level-13 description Predefined level-13 role # role name level-14 description Predefined level-14 role # user-group system # ip http acl advanced 3400 ip http enable # wlan global-configuration # wlan ap-group default-group # return
(0)
最佳答案
源地址为192.168.110.14,访问政务网指定IP作为目的地址,创建acl规则,应用在策略路由中,下一跳指向政务网
看回答里是acl是3305,指向政务外网那个策略路由node 30不要 apply output-interface 会导致策略路由转发异常,
用户可以同时配置多个出接口(通过一次或多次配置本命令实现),起到主备或负载分担的作用。
指定出接口类型需配置为P2P接口,对于非P2P接口(广播类型的接口和NBMA类型的接口),比如以太网接口、Virtual-Template接口,由于有多个可能的下一跳,可能会造成报文转发不成功的现象。
(0)
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论