求这段配置的解释:这是防火墙发F1000-c-g的配置, GigabitEthernet0/11 是防火墙下联核心交换机的口,也是内网口,该接口上的 nat outbound 3001 是起到什么作用???
acl number 3001
rule 0 permit ip source 172.16.0.0 0.0.255.255 destination 10.10.10.1 0
rule 1 permit ip source 172.16.0.0 0.0.255.255 destination 172.16.255.1 0
public-key peer 172.16.255.1
public-key-code begin
30819F300D06092A864886F70D010101050003818D0030818902818100ECF2524711F1AF8B
A8F60F0E871E2EB9FB550E666D3A048FE11F5C56568C58D16BB24940B4528C8D6F79C7E9D3
F61D642FCC2E609509546429271F03ED1DE66AE0CD919B4347EC7DAD3DF249CC32252C5ABC
49977D7002520C825B69DBA70F7515EBACFA127B56D9E5D1C673B2FE1EEC0C9A7F9204200D
FDFBCFBD19A66028810203010001 public-key-code end
peer-public-key end
interface GigabitEthernet0/11
port link-mode route
nat outbound 3001
ip address 172.16.0.2 255.255.255.248
求这段配置的解释:这是核心交换机的配置, GigabitEthernet0/11 是核心交换机连接防火墙的上联口,上联口中的 nat outbound 3001 是起到什么作用???
acl number 3001
rule 0 permit ip source 172.16.0.0 0.0.255.255 destination 10.10.10.1 0
rule 1 permit ip source 172.16.0.0 0.0.255.255 destination 172.16.255.1 0
public-key peer 172.16.255.1
public-key-code begin
30819F300D06092A864886F70D010101050003818D0030818902818100ECF2524711F1AF8B
A8F60F0E871E2EB9FB550E666D3A048FE11F5C56568C58D16BB24940B4528C8D6F79C7E9D3
F61D642FCC2E609509546429271F03ED1DE66AE0CD919B4347EC7DAD3DF249CC32252C5ABC
49977D7002520C825B69DBA70F7515EBACFA127B56D9E5D1C673B2FE1EEC0C9A7F9204200D
FDFBCFBD19A66028810203010001 public-key-code end
peer-public-key end
interface GigabitEthernet0/11
port link-mode route
nat outbound 3001
ip address 172.16.0.2 255.255.255.248
(0)
最佳答案
满足acl 3001限定条件的流量在出接口0/11上做nat outbound转换源地址
(0)
主要GigabitEthernet0/11是防火墙下联核心交换机的内网口,不是公网出口,这条nat是将内网访问10.10.10.1的源地址为172.16的地址转为172.16.0.2嘛??
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
主要GigabitEthernet0/11是防火墙下联核心交换机的内网口,不是公网出口,这条nat是将内网访问10.10.10.1的源地址为172.16的地址转为172.16.0.2嘛??