 
							
							
							[F1000] interface GigabitEthernet1/0/1  # WAN口,连接光猫
[F1000-GigabitEthernet1/0/1] ip address 61.148.35.90 255.255.255.252  # 运营商静态IP
[F1000-GigabitEthernet1/0/1] undo shutdown
[F1000-GigabitEthernet1/0/1] quit
[F1000-GigabitEthernet1/0/2] ip address 192.168.1.1 255.255.255.0  # 内网网关
[F1000-GigabitEthernet1/0/2] undo shutdown
[F1000-GigabitEthernet1/0/2] quit
[F1000-acl-basic-2000] rule 0 permit source 192.168.1.0 0.0.0.255  # 允许服务器所在网段
[F1000-acl-basic-2000] quit
[F1000-GigabitEthernet1/0/1] nat outbound 2000 address-group 1  # 内网流量出方向转换
[F1000-GigabitEthernet1/0/1] quit
[F1000-policy-security] rule name LAN_TO_WAN
[F1000-policy-security-rule-LAN_TO_WAN] source-zone trust  # 内网区域(默认LAN口属于trust)
[F1000-policy-security-rule-LAN_TO_WAN] destination-zone untrust  # 公网区域(默认WAN口属于untrust)
[F1000-policy-security-rule-LAN_TO_WAN] source-address 192.168.1.0 0.0.0.255
[F1000-policy-security-rule-LAN_TO_WAN] action permit  # 允许访问
[F1000-policy-security-rule-LAN_TO_WAN] quit
[F1000] nat server protocol tcp global 61.148.35.90 80 inside 192.168.1.100 80
# 配置允许公网访问服务器80端口的安全策略
[F1000-policy-security] rule name WAN_TO_SERVER
[F1000-policy-security-rule-WAN_TO_SERVER] source-zone untrust
[F1000-policy-security-rule-WAN_TO_SERVER] destination-zone trust
[F1000-policy-security-rule-WAN_TO_SERVER] destination-address 192.168.1.100 0.0.0.0
[F1000-policy-security-rule-WAN_TO_SERVER] destination-port eq 80
[F1000-policy-security-rule-WAN_TO_SERVER] action permit
[F1000-policy-security-rule-WAN_TO_SERVER] quit
[F1000-policy-security] quit
ping 8.8.8.8,确认 WAN 口连通。ping 192.168.1.1,确认内网连通。ping 8.8.8.8,确认 NAT 生效。telnet 61.148.35.90 80,确认端口映射生效。暂无评论
 
	 
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论