以下是路由配置:
version 5.20, Release 3302
#
sysname Router
#
domain default enable system
#
dns server 211.138.106.7
#
telnet server enable
#
ip http enable
#
password-recovery enable
#
acl number 3000
rule 0 permit ip
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
user-group system
group-attribute allow-guest
#
local-user admin
password cipher $c$3$i+Ze7TNGXy27Lwaq2azYFxSYMbHdpkEW
authorization-attribute level 3
service-type terminal
service-type web
local-user h3cadmin
password cipher $c$3$J9e3KDZK6dBVl2mcyRHMhgzAW7BcsxRCRc8=
authorization-attribute level 3
service-type telnet
service-type web
#
interface NULL0
#
interface GigabitEthernet0/0/0
description to hulianwang
nat outbound 3000
ip address 111.53.48.126 255.255.255.240
#
interface GigabitEthernet0/0/1
description to FW
ip address 192.168.102.2 255.255.255.0
#
interface GigabitEthernet0/0/2
nat outbound 3000
nat server protocol tcp global 124.**.215.* 8080 inside 172.16.16.17 8080 映射地址
nat server protocol tcp global 124.**.215.* 9500 inside 172.16.16.17 9500 映射地址
ip address 124.**.215.* 255.255.255.240
#
interface GigabitEthernet0/0/3
#
interface M-GigabitEthernet0/0/0
#
nqa entry imclinktopologypleaseignore ping
type icmp-echo
destination ip 192.168.102.254
frequency 270000
#
ip route-static 0.0.0.0 0.0.0.0 111.53.48.113
ip route-static 0.0.0.0 0.0.0.0 124.165.215.1 preference 100
ip route-static 10.10.10.0 255.255.255.0 192.168.102.1
ip route-static 172.16.0.0 255.255.0.0 192.168.102.1
ip route-static 172.17.0.0 255.255.0.0 192.168.102.1
ip route-static 192.168.100.0 255.255.255.0 192.168.102.1
ip route-static 192.168.101.0 255.255.255.0 192.168.102.1
#
snmp-agent
snmp-agent local-engineid 800063A2035CDD70BDF014
snmp-agent community read public
snmp-agent community write private
snmp-agent sys-info version all
snmp-agent target-host trap address udp-domain 172.16.0.29 params securityname public v2c
snmp-agent target-host trap address udp-domain 172.16.16.16 params securityname public v2c
#
nqa schedule imclinktopologypleaseignore ping start-time now lifetime 630720000
#
load xml-configuration
#
user-interface con 0
user-interface aux 0
user-interface vty 0 4
authentication-mode scheme
#
return
<Router>
**************************************************************************************************************
以下为防火墙配置:
sysname FW
#
firewall packet-filter enable
firewall packet-filter default permit
#
firewall statistic system enable
#
radius scheme system
server-type extended
#
domain system
#
local-user h3cadmin
password simple jkga
service-type telnet
level 3
#
interface Aux0
async mode flow
#
interface GigabitEthernet0/0
ip address 192.168.101.2 255.255.255.0
#
interface GigabitEthernet0/1
#
interface GigabitEthernet1/0
#
interface GigabitEthernet1/1
ip address 192.168.102.1 255.255.255.0
#
interface Encrypt2/0
#
interface NULL0
#
firewall zone local
set priority 100
#
firewall zone trust
add interface GigabitEthernet0/0
set priority 85
#
firewall zone untrust
add interface GigabitEthernet1/1
set priority 5
#
firewall zone DMZ
set priority 50
#
firewall interzone local trust
#
firewall interzone local untrust
#
firewall interzone local DMZ
#
firewall interzone trust untrust
#
firewall interzone trust DMZ
#
firewall interzone DMZ untrust
#
hwping-agent enable
hwping imclinktopologypleaseignore ping
test-type icmp
destination-ip 192.168.102.254
frequency 270
#
ip route-static 0.0.0.0 0.0.0.0 192.168.102.2 preference 60
ip route-static 10.10.10.0 255.255.255.0 192.168.101.1 preference 60
ip route-static 172.16.0.0 255.255.0.0 192.168.101.1 preference 60
ip route-static 172.17.0.0 255.255.0.0 192.168.101.1 preference 60
ip route-static 192.168.100.0 255.255.255.0 192.168.101.1 preference 60
#
snmp-agent
snmp-agent local-engineid 000063A27F00000100001B58
snmp-agent community read public
snmp-agent community write private
snmp-agent sys-info version all
#
user-interface con 0
user-interface aux 0
user-interface vty 0 4
authentication-mode scheme
#
return
<FW>
路由器线路:
主网入口 GigabitEthernet0/0/2 124.**.215.*/255.255.255.240
去防火墙 GigabitEthernet0/0/1 192.168.102.2/255.255.255.0
防火墙线路 :
路由器来 GigabitEthernet1/1 192.168.102.1 255.255.255.0
去核心 GigabitEthernet0/0 192.168.101.2 255.255.255.0
(0)
最佳答案
这个是有啥问题啊?nat的配置看起来正常
(0)
地址映射不通 外网访问不到映射的地址 是不是防火墙也要进行设置
啥意思?是不通还是有啥问题?把问题现象描述的再详细一点吧
(0)
地址映射不通 外网访问不到映射的地址 是不是防火墙也要进行设置
地址映射不通 外网访问不到映射的地址 是不是防火墙也要进行设置
地址映射不通 外网访问不到映射的地址 是不是防火墙也要进行设置
(0)
防火墙没有做域间策略吧,你把防火墙跳过试试
可以在66上display nat session 看一下有没有相应会话。另外防火墙上如果有办法抓包或者debug,也可以看下报文有没有正常发送到防火墙上
防火墙没有做域间策略吧,你把防火墙跳过试试
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
地址映射不通 外网访问不到映射的地址 是不是防火墙也要进行设置