用的出接口 同一网段ip 映射不成功
#
nat static outbound 10.1.201.2 41.30.200.100
nat static outbound 10.1.201.3 41.30.200.90
#
password-recovery enable
#
vlan 1
#
object-group ip address 10.1.201.2---5
0 network host address 10.1.201.2
10 network host address 10.1.201.5
#
object-group ip address 10.1.201.3
0 network host address 10.1.201.3
interface GigabitEthernet1/0/0
port link-mode route
description GuideWan Interface
combo enable copper
ip address 41.30.200.100 255.255.255.0
nat outbound
nat server protocol tcp global 41.30.200.100 22 inside 10.1.201.2 22
nat server protocol tcp global 41.30.200.90 80 inside 10.1.201.3 80
nat static enable
#
interface GigabitEthernet1/0/1
port link-mode route
description GuideLan Interface
combo enable copper
ip address 10.1.67.30 255.255.255.240
undo dhcp select server
#
security-zone name Trust
import interface GigabitEthernet1/0/1
#
security-zone name DMZ
#
security-zone name Untrust
import interface GigabitEthernet1/0/0
#
#
Security-policy ip
rule 4 name ceshi1
action pass
disable
logging enable
counting enable
source-ip 10.1.201.2---5
rule 3 name ceshi
action pass
logging enable
counting enable
source-zone Untrust
destination-zone Trust
destination-ip 10.1.201.2---5
service all
rule 0 name GuideSecPolicy
action pass
source-zone Trust
source-zone Local
destination-zone Untrust
destination-zone DMZ
destination-zone Trust
destination-zone Local
rule 1 name 2
action pass
disable
logging enable
counting enable
source-zone Untrust
destination-zone Trust
source-ip 41.30.200.100
destination-ip 10.1.201.2---5
rule 2 name 445deny
action drop
disable
source-zone Untrust
destination-zone Trust
service smb
service 139
service 334
rule 5 name 3
action pass
counting enable
source-zone Untrust
destination-zone Trust
destination-ip 10.1.201.3
service http
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
22正常 目前是这个不生效 80端口 nat server protocol tcp global 41.30.200.90 80 inside 10.1.201.3 80
<H3C>dis nat static Static NAT mappings: Totally 2 outbound static NAT mappings. IP-to-IP: Local IP : 10.1.201.2 Global IP : 41.30.200.100 Config status: Active IP-to-IP: Local IP : 10.1.201.3 Global IP : 41.30.200.90 Config status: Active Interfaces enabled with static NAT: Totally 1 interfaces enabled with static NAT. Interface: GigabitEthernet1/0/0 Config status: Active
仔细看回答