object-group ip address connlimitObjGrp_28292
0 network range 10.42.218.129 10.42.218.130
这段走NAT,其它走静态路由
version 7.1.064, Release 0809P27
#
sysname H3C
#
clock protocol ntp
#
security-zone intra-zone default permit
#
ip load-sharing mode per-flow src-ip global
#
dhcp enable
dhcp server always-broadcast
#
dns proxy enable
#
password-recovery enable
#
vlan 1
#
object-group ip address connlimitObjGrp_28292
0 network range 10.42.218.129 10.42.218.130
#
controller Cellular0/0
#
interface Dialer0
mtu 1492
#
interface NULL0
#
interface Vlan-interface1
description LAN-interface
ip address 10.42.218.254 255.255.255.0
tcp mss 1280
undo dhcp select server
#
interface GigabitEthernet0/0
port link-mode route
description Single_Line1
duplex full
speed 1000
ip address 10.42.250.153 255.255.255.252
dns server 10.42.128.120
dns server 202.96.107.27
tcp mss 1280
nat outbound
#
interface GigabitEthernet0/1
port link-mode route
#
interface GigabitEthernet0/2
port link-mode route
combo enable copper
#
interface GigabitEthernet0/3
port link-mode route
combo enable copper
#
interface GigabitEthernet0/4
port link-mode route
#
interface GigabitEthernet0/5
port link-mode route
#
interface GigabitEthernet2/0
port link-mode bridge
#
interface GigabitEthernet2/1
port link-mode bridge
#
interface GigabitEthernet2/2
port link-mode bridge
#
interface GigabitEthernet2/3
port link-mode bridge
#
security-zone name Local
#
security-zone name Trust
#
security-zone name DMZ
#
security-zone name Untrust
#
security-zone name Management
#
scheduler logfile size 16
#
line class console
user-role network-admin
#
line class tty
user-role network-operator
#
line class usb
user-role network-admin
#
line class vty
user-role network-operator
#
line con 0
user-role network-admin
#
line vty 0 63
authentication-mode scheme
user-role network-operator
#
ip route-static 0.0.0.0 0 GigabitEthernet0/0 10.42.250.154
#
ntp-service enable
ntp-service unicast-server ***.***
ntp-service unicast-server ***.***
ntp-service unicast-server ***.***
ntp-service unicast-server ***.***
ntp-service unicast-server ***.***
ntp-service unicast-server ***.***
ntp-service unicast-server ***.***
#
acl basic name connlimitAcl_28292_ip
rule 65534 permit source object-group connlimitObjGrp_28292
#
acl mac 4999
rule 5 permit
#
password-control enable
undo password-control aging enable
undo password-control history enable
password-control length 6
password-control login-attempt 3 exceed lock-time 10
password-control update-interval 0
password-control login idle-time 0
#
domain system
#
domain default enable system
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role
#
role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
user-group system
#
local-user admin class manage
service-type telnet http https
authorization-attribute user-role network-admin
#
connection-limit policy 32
limit 1 acl name connlimitAcl_28292_ip per-source amount 1000 999 description 断网
#
ip http enable
ip https enable
#
url-filter category custom severity 65535
#
cloud-management server domain oasis.h3c.com
#
return
MER8300,特定内网地址走接口NAT-其它内网地址走静态路由是否支持
(0)
最佳答案
您好,支持的,策略路由
(0)
interface GigabitEthernet0/0 port link-mode route description Single_Line1 duplex full speed 1000 ip address 10.42.250.153 255.255.255.252 dns server 10.42.128.120 dns server 202.96.107.27 tcp mss 1280 nat outbound 出接口下 nat outbound 还用写吗 web界面下操作感觉有点问题
interface GigabitEthernet0/0
port link-mode route
description Single_Line1
duplex full
speed 1000
ip address 10.42.250.153 255.255.255.252
dns server 10.42.128.120
dns server 202.96.107.27
tcp mss 1280
nat outbound
出接口下 nat outbound 还用写吗 web界面下操作感觉有点问题
(0)
需要的,正常走nat outbound,匹配策略路由的就走静态
需要的,正常走nat outbound,匹配策略路由的就走静态
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
interface GigabitEthernet0/0 port link-mode route description Single_Line1 duplex full speed 1000 ip address 10.42.250.153 255.255.255.252 dns server 10.42.128.120 dns server 202.96.107.27 tcp mss 1280 nat outbound 出接口下 nat outbound 还用写吗 web界面下操作感觉有点问题