外网电脑访问内部服务器。不能通过服务器映射访问内部服务器。
外部电脑使用的公网IP为118.113.134.3,UTM的外网的20003端口。
响应方的源地址是正确的内部服务器,但是目的地址为何是UTM的公网口地址?
导致TCP连接一直处于SYN状态。
interface GigabitEthernet0/4
port link-mode route
nat outbound 2000
nat server 4 protocol tcp global current-interface 20002 inside 192.168.1.49 www
ip address 125.69.150.155 255.255.255.0
tcp mss 1400
U200-CA为防火墙模式部署
此为域间策略,49地址的服务器处于office域。优先级仅次于local为90。
(0)
防火墙域间策略问题排查了吗?
然后看一下内网直接访问服务器这些都正常吗
(0)
内部使用是没问题的,问题是为何NAT做目的地址映射时将公网的源地址也修改了。
软件版本为5123P11
域间策略在截图里,应该是没问题的。有问题的话,不会有session表项吧。 <H3C>display session table source-ip 118.113.134.3 verbose Initiator: Source IP/Port : 118.113.134.3/6144 Dest IP/Port : 125.69.150.155/23 VPN-Instance/VLAN ID/VLL ID: Responder: Source IP/Port : 125.69.150.155/23 Dest IP/Port : 118.113.134.3/6144 VPN-Instance/VLAN ID/VLL ID: Pro: TCP(6) App: TELNET State: TCP-EST Start time: 2018-11-27 02:26:40 TTL: 3600s Root Zone(in): Untrust Zone(out): Local Received packet(s)(Init): 88 packet(s) 3624 byte(s) Received packet(s)(Reply): 75 packet(s) 3789 byte(s) Initiator: Source IP/Port : 118.113.134.3/7937 Dest IP/Port : 125.69.150.155/20003 VPN-Instance/VLAN ID/VLL ID: Responder: Source IP/Port : 192.168.1.4/80 Dest IP/Port : 125.69.150.155/4447 VPN-Instance/VLAN ID/VLL ID: Pro: TCP(6) App: unknown State: SYN Start time: 2018-11-27 02:27:09 TTL: 28s Root Zone(in): Untrust Zone(out): Untrust Received packet(s)(Init): 1 packet(s) 52 byte(s) Received packet(s)(Reply): 0 packet(s) 0 byte(s) Initiator: Source IP/Port : 118.113.134.3/8000 Dest IP/Port : 125.69.150.155/20003 VPN-Instance/VLAN ID/VLL ID: Responder: Source IP/Port : 192.168.1.4/80 Dest IP/Port : 125.69.150.155/4448 VPN-Instance/VLAN ID/VLL ID: Pro: TCP(6) App: unknown State: SYN Start time: 2018-11-27 02:27:09 TTL: 28s Root Zone(in): Untrust Zone(out): Untrust Received packet(s)(Init): 1 packet(s) 52 byte(s) Received packet(s)(Reply): 0 packet(s) 0 byte(s) Initiator: Source IP/Port : 118.113.134.3/8064 Dest IP/Port : 125.69.150.155/20003 VPN-Instance/VLAN ID/VLL ID: Responder: Source IP/Port : 192.168.1.4/80 Dest IP/Port : 125.69.150.155/4454 VPN-Instance/VLAN ID/VLL ID: Pro: TCP(6) App: unknown State: SYN Start time: 2018-11-27 02:27:09 TTL: 28s Root Zone(in): Untrust Zone(out): Untrust Received packet(s)(Init): 1 packet(s) 52 byte(s) Received packet(s)(Reply): 0 packet(s) 0 byte(s) Total find: 4 session里看到的和我截图里的一样的。
<H3C>display session table source-ip 118.113.134.3 verbose Initiator: Source IP/Port : 118.113.134.3/6144 Dest IP/Port : 125.69.150.155/23 VPN-Instance/VLAN ID/VLL ID: Responder: Source IP/Port : 125.69.150.155/23 Dest IP/Port : 118.113.134.3/6144 VPN-Instance/VLAN ID/VLL ID: Pro: TCP(6) App: TELNET State: TCP-EST Start time: 2018-11-27 02:26:40 TTL: 3600s Root Zone(in): Untrust Zone(out): Local Received packet(s)(Init): 88 packet(s) 3624 byte(s) Received packet(s)(Reply): 75 packet(s) 3789 byte(s) Initiator: Source IP/Port : 118.113.134.3/7937 Dest IP/Port : 125.69.150.155/20003 VPN-Instance/VLAN ID/VLL ID: Responder: Source IP/Port : 192.168.1.4/80 Dest IP/Port : 125.69.150.155/4447 VPN-Instance/VLAN ID/VLL ID: Pro: TCP(6) App: unknown State: SYN Start time: 2018-11-27 02:27:09 TTL: 28s Root Zone(in): Untrust Zone(out): Untrust Received packet(s)(Init): 1 packet(s) 52 byte(s) Received packet(s)(Reply): 0 packet(s) 0 byte(s) Initiator: Source IP/Port : 118.113.134.3/8000 Dest IP/Port : 125.69.150.155/20003 VPN-Instance/VLAN ID/VLL ID: Responder: Source IP/Port : 192.168.1.4/80 Dest IP/Port : 125.69.150.155/4448 VPN-Instance/VLAN ID/VLL ID: Pro: TCP(6) App: unknown State: SYN Start time: 2018-11-27 02:27:09 TTL: 28s Root Zone(in): Untrust Zone(out): Untrust Received packet(s)(Init): 1 packet(s) 52 byte(s) Received packet(s)(Reply): 0 packet(s) 0 byte(s) Initiator: Source IP/Port : 118.113.134.3/8064 Dest IP/Port : 125.69.150.155/20003 VPN-Instance/VLAN ID/VLL ID: Responder: Source IP/Port : 192.168.1.4/80 Dest IP/Port : 125.69.150.155/4454 VPN-Instance/VLAN ID/VLL ID: Pro: TCP(6) App: unknown State: SYN Start time: 2018-11-27 02:27:09 TTL: 28s Root Zone(in): Untrust Zone(out): Untrust Received packet(s)(Init): 1 packet(s) 52 byte(s) Received packet(s)(Reply): 0 packet(s) 0 byte(s) Total find: 4
域间全放通了,包括域内也放通了。。所有都any都any了,还是一样。。。
版本有点老,把版本升级到最新测试一下
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明