1.用户PC地址192.168.20.12/24,服务器地址192.168.20.11/24 2.用户PC可以访问服务内网口的48000端口 3.互联网用户可以访问183.234.247.226的48000端口 4.用户PC无法访问183.234.247.226的48000口。 路由器设备是H3C MSR36-40,版本是Version 7.1.064, Release 0821P13
1.用户PC和服务器接在核心交换机同一网段192.168.20.0/24 2.核心交换机三层口192.168.2.1/24与路由器内网口192.168.2.2/24互联 3.路由器外网口为G1/0/1 interface GigabitEthernet1/0/1 port link-mode route combo enable copper ip address 183.234.247.226 255.255.255.248 dns server 114.114.114.114 dns server 211.136.192.6 tcp mss 1280 ip last-hop hold nat outbound 2000 address-group 1 nat server protocol tcp global 183.234.247.226 48000 inside 192.168.20.11 48000 内网口G1/0/1 interface GigabitEthernet1/0/0 port link-mode route combo enable copper ip address 192.168.2.2 255.255.255.0 nat hairpin enable nat address-group 1 address 183.234.247.226 183.234.247.226
内网口G1/0/0开启nat hairpin enable了,不行。是不是跟版本有关系
内网口配置是这样的# interface GigabitEthernet1/0/0 port link-mode route combo enable copper ip address 192.168.2.2 255.255.255.0 nat hairpin enable #
内网接口下配置的nat取消
内网口配置是这样的# interface GigabitEthernet1/0/0 port link-mode route combo enable copper ip address 192.168.2.2 255.255.255.0 nat hairpin enable #
nat server,目标地址由 183.x.x.226 转换为 192.168.20.11。nat server 转换目标地址的同时,也转换源地址(SNAT),使服务器认为请求来自路由器,从而将回包发还给路由器。acl advanced 3000
rule 5 permit ip source 192.168.20.0 0.0.0.255 destination 192.168.20.0 0.0.0.255
quit
nat hairpin enable 的内网口,增加一条 nat outbound。interface GigabitEthernet1/0/0
# 原有配置保留
ip address 192.168.2.2 255.255.255.0
nat hairpin enable
# 新增配置:将回流流量的源地址伪装成路由器内网口 IP
nat outbound 3000
quit内网口G1/0/0配置如下: interface GigabitEthernet1/0/0 port link-mode route combo enable copper ip address 192.168.2.2 255.255.255.0 nat hairpin enable nat outbound 3000 # #ACL配置 acl number 2000 rule 10 permit source 192.168.0.0 0.0.255.255 # acl advanced 3000 rule 5 permit ip source 192.168.20.0 0.0.0.255 destination 192.168.20.0 0.0.0.255 # 做了以上配置,用户还是不能telnet到183.234.247.226 48000端口
内网口G1/0/0配置如下: interface GigabitEthernet1/0/0 port link-mode route combo enable copper ip address 192.168.2.2 255.255.255.0 nat hairpin enable nat outbound 3000 # #ACL配置 acl number 2000 rule 10 permit source 192.168.0.0 0.0.255.255 # acl advanced 3000 rule 5 permit ip source 192.168.20.0 0.0.0.255 destination 192.168.20.0 0.0.0.255 # 做了以上配置,用户还是不能telnet到183.234.247.226 48000端口
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明