acl basic 2030
rule 96 permit source 10.199.0.0 0.0.255.255
nat address-group 2
address 10.47.32.50 10.47.32.150
interface GigabitEthernet1/0/0 内部网口
port link-mode route
combo enable copper
ip address 10.199.33.65 255.255.255.248
nat hairpin enable
interface GigabitEthernet1/0/1 外部网口,natserver 及nat outbound配置
port link-mode route
combo enable copper
ip address 10.199.33.57 255.255.255.248
nat outbound 2030 address-group 2
nat server protocol icmp global 10.47.32.15 inside 10.199.6.20 rule 5
nat server protocol tcp global 10.47.32.15 22 inside 10.199.6.20 22 rule 7
#接口区域配置
security-zone name Trust
import interface GigabitEthernet1/0/0
attack-defense apply policy dns-guard
#
security-zone name Untrust
import interface GigabitEthernet1/0/1
###安全策略配置
security-policy ip
rule 0 name t-to-u
action pass
counting enable
source-zone Trust
destination-zone Untrust
rule 1 name u-to-t
action pass
counting enable
source-zone Untrust
destination-zone Trust
rule 2 name l-to-all
action pass
counting enable
source-zone Local
destination-zone Trust
destination-zone Untrust
rule 3 name t-u_to_local
action pass
counting enable
source-zone Trust
source-zone Untrust
destination-zone Local
是版本问题还是配置问题呢,外部用户可以直接ping 10.47.32.15以及ssh,
内网用户10.199.6.53无法ping通10.47.32.15,以及无法ssh 10.47.32.15
(0)
最佳答案
补上一条trust到trust的安全策略就好
(0)
大哥,牛逼啦,,谢谢
建议采纳一波
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
建议采纳一波