<ROU-MSR3610>dis cu
# version 7.1.049, Release 0106
# sysname ROU-MSR3610
# telnet server enable
# dns server 222.222.222.222
dns server 114.114.114.114
# password-recovery enable
# vlan 1
# policy-based-route aaa permit node 1
if-match acl 3000
apply next-hop 124.238.99.33
# policy-based-route aaa permit node 2
if-match acl 3333
apply next-hop 124.238.113.193
# controller Cellular0/0
# controller Cellular0/1
# interface Aux0
# interface NULL0
# interface GigabitEthernet0/0
port link-mode route
combo enable copper
ip address 124.238.99.38 255.255.255.240
nat outbound 3000
# interface GigabitEthernet0/1
port link-mode route
ip address 10.0.0.1 255.255.255.252
ip policy-based-route aaa
# interface GigabitEthernet0/2
port link-mode route
ip address 124.238.113.209 255.255.255.224
nat outbound 3333
nat server protocol tcp global current-interface 443 inside 172.16.6.253 443
nat server protocol tcp global current-interface 1521 inside 172.16.6.253 1521
nat server protocol tcp global current-interface 1526 inside 172.16.4.254 1526
nat server protocol tcp global current-interface 8027 inside 172.16.6.253 8027
nat server protocol tcp global current-interface 8028 inside 172.16.6.253 8028
nat server protocol tcp global current-interface 8029 inside 172.16.6.253 8029
nat server protocol tcp global current-interface 8030 inside 172.16.6.253 8030
nat server protocol tcp global current-interface 8031 inside 172.16.6.253 8031
nat server protocol tcp global current-interface 8032 inside 172.16.6.253 8032
nat server protocol tcp global current-interface 8033 inside 172.16.6.253 8033
nat server protocol tcp global current-interface 8088 inside 172.16.6.253 8088
#
scheduler logfile size 16
# line class aux user-role network-admin
# line class tty user-role network-operator
# line class vty user-role network-operator
# line aux 0 authentication-mode scheme user-role network-admin
# line vty 0 4 authentication-mode scheme user-role network-operator
# line vty 5 63 user-role network-operator
# ip route-static 0.0.0.0 0 124.238.99.33
ip route-static 0.0.0.0 0 124.238.113.193 preference 80
ip route-static 172.16.0.0 16 10.0.0.2
# acl number 3000
rule 0 permit ip source 172.16.0.0 0.0.0.255
rule 1 permit ip source 172.16.1.0 0.0.0.255
rule 2 permit ip source 172.16.2.0 0.0.0.255
rule 3 permit ip source 172.16.3.0 0.0.0.255
rule 4 permit ip source 172.16.4.0 0.0.0.255
# acl number 3333
rule 0 permit ip source 172.16.5.0 0.0.0.255
rule 1 permit ip source 172.16.6.0 0.0.0.255
# domain system
# aaa session-limit ftp 32
aaa session-limit telnet 32
aaa session-limit http 32
aaa session-limit ssh 32
aaa session-limit https 32
domain default enable system
# role name level-0
description Predefined level-0 role
# role name level-1
description Predefined level-1 role
# role name level-2
description Predefined level-2 role
# role name level-3
description Predefined level-3 role
# role name level-4
description Predefined level-4 role
# role name level-5
description Predefined level-5 role
# role name level-6
description Predefined level-6 role
# role name level-7
description Predefined level-7 role
# role name level-8
description Predefined level-8 role
# role name level-9
description Predefined level-9 role
# role name level-10
description Predefined level-10 role
# role name level-11
description Predefined level-11 role
# role name level-12
description Predefined level-12 role
# role name level-13
description Predefined level-13 role
# role name level-14
description Predefined level-14 role
# user-group system
acl3000走99.33外网 acl3333走113.209那个外网 那位大佬让我看看 配置还少一些什么东西。。
(0)
应该是不缺少什么了
(0)
可是他不行啊,acl3333还是能ping通99.33 和下边 1-6网段得IP地址都一会可以上网一会上不了网。。
别用模拟器测试呀,现场找找真机,模拟器总觉得有时候有问题
找400看看把,说不定有其他问题
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
400要收费。