路由器上内网做了两个网段
ip address 10.0.71.1 255.255.255.0
ip address 172.16.100.1 255.255.0.0 sub
现在映射了两个端口
nat server protocol tcp global 61.182.*.121 88 inside 172.16.10.1 88
nat server protocol tcp global 61.182.*.121 89 inside 172.16.10.1 89
在内网口做了连个策略
interface GigabitEthernet0/0
port link-mode route
nat server protocol tcp global 61.182.*.121 88 inside 172.16.10.1 88
nat server protocol tcp global 61.182.*.121 89 inside 172.16.10.1 89
现在内网下10.0.71.1段内访问61.182.*.121 88、61.182.*.* 89正常
但是172.16.100.1段先无法访问61.182.*.121 88、61.182.*.* 89。
请问如何设置,请详细一些,不太会设置。
运行[MSR-ShiJiaZhuangJiShi-GigabitEthernet0/1]nat out
Error: The NAT address-group conflicts with other NAT address-group!
具体配置如下:
interface GigabitEthernet0/0
port link-mode route
nat server protocol tcp global 61.182.*.12188 inside 172.16.10.1 88
nat server protocol tcp global 61.182.*.121 89 inside 172.16.10.1 89
ip address 10.0.71.1 255.255.255.0
ip address 172.16.100.1 255.255.0.0 sub
#
interface GigabitEthernet0/1
port link-mode route
nat outbound 3111 address-group 1
nat server protocol tcp global 61.182.*.122 4009 inside 10.0.71.222 4009
nat server protocol udp global 61.182.*.122 4009 inside 10.0.71.222 4009
nat server protocol tcp global 61.182.*.122 www inside 10.0.71.222 www
nat server protocol tcp global 61.182.*.122 443 inside 10.0.71.222 443
nat server protocol tcp global 61.182.*.123 any inside 172.16.150.150 any
nat server protocol udp global 61.182.*.123 any inside 172.16.150.150 any
nat server protocol tcp global 61.182.*.121 88 inside 172.16.10.1 88
nat server protocol tcp global 61.182.*.121 89 inside 172.16.10.1 89
nat server protocol tcp global 61.182.*.121 5222 inside 172.16.10.1 5222
nat server protocol tcp global 61.182.*.121 7070 inside 172.16.10.1 7070
nat server protocol tcp global 61.182.*.121 9090 inside 172.16.10.1 9090
ip address 61.182.*.121 255.255.255.128
ip address 61.182.*.122 255.255.255.128 sub
ipsec policy 1
(0)
最佳答案
acl 3111匹配的是什么?MSR3040默认支持nat hairpin功能,只要外网口的nat可以匹配上172.16段的源地址就可以
如果做不出来的话,就在内网口做一下nat outbound acl 3999,acl 3999只需要匹配172.16段的源地址就可以
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论