内部接口 interface vlanif 338 192.168.0.166/29
外部接口 interface g 1/0/1 120.120.120.120
对外服务主机 192.168.0.164
做nat: 外网访问:220.220.220.220:11111 --->120.120.120.120:22--->192.168.0.166:11111--->192.168.0.164:22
具体怎么操作?
(0)
最佳答案
interface GigabitEthernet1/0/1
port link-mode route
ip binding vpn-instance lyj
ip address 120.120.120.120 255.255.255.192
nat outbound
nat server global current-interface vpn-instance lyj inside 192.168.0.164 vpn-instance lyj reversible rule ServerRule_1 counting description fwq
nat static enable
interface Vlan-interface338
ip binding vpn-instance lyj
ip address 192.168.0.166 255.255.255.248
nat outbound
[H3C-GigabitEthernet1/0/1]ping -vpn-instance lyj 192.168.0.164
Ping 192.168.0.164 (192.168.0.164): 56 data bytes, press CTRL+C to break
56 bytes from 192.168.0.164: icmp_seq=0 ttl=64 time=0.943 ms
56 bytes from 192.168.0.164: icmp_seq=1 ttl=64 time=0.431 ms
56 bytes from 192.168.0.164: icmp_seq=2 ttl=64 time=0.366 ms
56 bytes from 192.168.0.164: icmp_seq=3 ttl=64 time=0.373 ms
56 bytes from 192.168.0.164: icmp_seq=4 ttl=64 time=0.411 ms
--- Ping statistics for 192.168.0.164 in VPN instance lyj ---
5 packet(s) transmitted, 5 packet(s) received, 0.0% packet loss
round-trip min/avg/max/std-dev = 0.366/0.505/0.943/0.220 ms
但外面ping就不通。
Initiator:
Source IP/port: xxx.xxx.xxx.xxx/98
Destination IP/port: 120.120.120.120/2048
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: lyj/-/-
Protocol: ICMP(1)
Inbound interface: GigabitEthernet1/0/1
Source security zone: Untrust
Responder:
Source IP/port: 192.168.0.164/72
Destination IP/port: 192.168.0.166/0
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: ICMP(1)
Inbound interface: Vlan-interface338
Source security zone: Trust
State: ICMP_REQUEST
Application: ICMP
Rule ID: 6
Rule name: Untrust_Trust_6_IPv4
Start time: 2025-07-20 21:29:49 TTL: 58s
Initiator->Responder: 442 packets 26520 bytes
Responder->Initiator: 0 packets 0 bytes
(0)
外网口nat server protocol tcp global 120.120.120.120 22 inside 192.168.0.164 22
内网口 nat outbound
(0)
不行啊。
不行啊。
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明