设置列表
对齐方式
请教:配置了nat转换,但还是无法访问内部服务,通过192.168.1.21:11120无法访问
[H3C]dis cu
#
sysname H3C
#
firewall packet-filter enable firewall packet-filter default permit
#
insulate
#
firewall statistic system enable
#
radius scheme system server-type extended # domain system
#
acl number 2000 rule 0 permit source 0.0.0.0 0
#
interface Aux0 async mode flow
#
interface Ethernet0/0 ip address 10.10.10.216 255.255.255.0
#
interface Ethernet0/1
#
interface Ethernet0/2
#
interface Ethernet0/3
#
interface Ethernet1/0 ip address 192.168.1.21 255.255.255.0
firewall packet-filter 2000 outbound
nat server protocol tcp global 192.168.1.21 11120 inside 10.10.10.215 11120
#
interface Ethernet1/1
#
interface Ethernet1/2
#
interface NULL0
#
firewall zone local set priority 100
#
firewall zone trust add interface Ethernet0/0
set priority 85
#
firewall zone untrust add interface Ethernet1/0
set priority 5
#
firewall zone DMZ set priority 50
#
firewall interzone local trust
#
firewall interzone local untrust
#
firewall interzone local DMZ
#
firewall interzone trust untrust
#
firewall interzone trust DMZ
#
firewall interzone DMZ untrust
#
ip route-static 0.0.0.0 0.0.0.0 192.168.1.254 preference 60
#
user-interface con 0
user-interface aux 0
user-interface vty 0 4
#
return [H3C]
设置列表
(0)
最佳答案
策略放行一下
放行UNtrust 到Trust区域的策略
#创建Trust到Local域的域间策略调用pass策略。
[H3C]zone-pair security source untrust destination trust
[H3C-zone-pair-security-untrust-trust]object-policy apply ip pass
[H3C-zone-pair-security-untrust-trust]quit
#创建Local到Trust域的域间策略调用pass策略。
[H3C]zone-pair security source untrust destination Trust
[H3C-zone-pair-security-untrust-Trust]object-policy apply ip pass
[H3C-zone-pair-security-untrust-Trust]quit
(0)
隔行如隔山啊,求一条的命令呢。谢谢啦
谢谢你的帮助,可能是我这个设备太老了。命令不太一样,识别不到 [H3C]zone-pair security source untrust destination trust ^ % Unrecognized command found at '^' position. [H3C] [H3C]z? ^ % Unrecognized command found at '^' position. H3C SecPath F100-A 2008年的产品
谢谢你的帮助,可能是我这个设备太老了。命令不太一样,识别不到 [H3C]zone-pair security source untrust destination trust ^ % Unrecognized command found at '^' position. [H3C] [H3C]z? ^ % Unrecognized command found at '^' position. H3C SecPath F100-A 2008年的产品
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
可以WEB界面看下,复制的内容错位了,看不到你那个^是指在哪个命令下面的