现网环境是在互联网出口配置了端口映射互联网访问对一个的地址和端口可以访问,但是内网访问相同地址无法进行访问。
配置如下:
interface GigabitEthernet1/0/1 内网 |
port link-mode route |
ip address 192.168.20.2 255.255.255.0 |
nat outbound 3000 |
nat server protocol tcp global xx.xx.xx.xx 9001 inside 10.121.125.236 9001 rule ServerRule_6 |
nat server protocol tcp global xx.xx.xx.xx 9021 inside 10.121.125.233 9021 rule ServerRule_7 |
nat server protocol tcp global xx.xx.xx.xx 9031 inside 10.121.125.229 9031 rule ServerRule_8 |
nat server protocol tcp global xx.xx.xx.xx 10023 inside 192.168.210.2 23 rule ServerRule_9 |
nat server protocol tcp global xx.xx.xx.xx 60123 inside 192.168.210.2 8080 rule ServerRule_10 |
nat hairpin enable |
gateway 192.168.20.1 |
# |
interface GigabitEthernet1/0/2 内网 |
port link-mode route |
ip address 192.168.230.2 255.255.255.0 |
nat outbound 3000 |
nat server protocol tcp global xx.xx.xx.xx 9001 inside 10.121.125.236 9001 rule ServerRule_1 |
nat server protocol tcp global xx.xx.xx.xx 9021 inside 10.121.125.233 9021 rule ServerRule_2 |
nat server protocol tcp global xx.xx.xx.xx 9031 inside 10.121.125.229 9031 rule ServerRule_3 |
nat server protocol tcp global xx.xx.xx.xx 10023 inside 192.168.210.2 23 rule ServerRule_4 |
nat server protocol tcp global xx.xx.xx.xx 60123 inside 192.168.210.2 8080 rule ServerRule_5 |
nat hairpin enable |
gateway 192.168.230.1 |
# |
interface GigabitEthernet1/0/5 互联网出口 |
port link-mode route |
ip address xx.xx.xx.xx 255.255.255.252 |
nat outbound 3000 |
nat server protocol tcp global xx.xx.xx.xx 9001 inside 10.121.125.236 9001 rule ServerRule_1 |
nat server protocol tcp global xx.xx.xx.xx 9021 inside 10.121.125.233 9021 rule ServerRule_2 |
nat server protocol tcp global xx.xx.xx.xx 9031 inside 10.121.125.229 9031 rule ServerRule_3 |
nat server protocol tcp global xx.xx.xx.xx 10023 inside 192.168.210.2 23 rule ServerRule_4 |
nat server protocol tcp global xx.xx.xx.xx 60123 inside 192.168.210.2 8080 rule ServerRule_5 |
nat hairpin enable |
gateway 116.131.5.161 |
(0)
外网可以访问,但是内网通过公网地址访问不到
在内网口配置nat hairpin enable
(0)
已经在内网口配置了nat hairpin enable还是不可以访问
我看你的内网口上还有nat ,不太清除你的组网,正常操作在内网口nat hairpin 就行,你的不行估计是和内网口的nat server 有关系
大佬,有这方面的配置案例吗
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
大佬,有这方面的配置案例吗