华为防火墙配置NAT
来源:互联网 发布:php excel多级下拉版 编辑:程序博客网 时间:2024/05/16 03:27
interface GigabitEthernet0/0/0
alias GE0/MGMT
ip address 172.16.1.1 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 192.168.0.1 255.255.255.0
#
interface GigabitEthernet0/0/2
ip address 202.1.1.1 255.255.255.0
firewall zone local
set priority 100
#
firewall zone trust
set priority 85
add interface GigabitEthernet0/0/1
#
firewall zone untrust
set priority 5
add interface GigabitEthernet0/0/2
#
firewall zone dmz
set priority 50
add interface GigabitEthernet0/0/0
#
firewall interzone trust untrust
detect ftp
#
firewall interzone trust dmz
detect ftp
#
firewall interzone dmz untrust
detect ftp
ip route-static 0.0.0.0 0.0.0.0 202.1.1.2
nat address-group 1 192.168.0.10 192.168.0.20
nat address-group 2 192.168.0.30 192.168.0.40
nat server 0 zone untrust protocol tcp global 11.11.11.11 ftp inside 172.16.1.11 ftp
nat server 1 zone untrust protocol tcp global 11.11.11.12 www inside 172.16.1.12 www
nat server 2 zone trust protocol tcp global 11.11.11.11 ftp inside 172.16.1.11 ftp
nat server 3 zone trust protocol tcp global 11.11.11.12 www inside 172.16.1.12 www
nat server 4 protocol tcp global 11.11.11.6 www inside 192.168.0.6 www
nat server 5 protocol tcp global 11.11.11.6 ftp inside 192.168.0.6 ftp
#
policy interzone trust untrust inbound
policy 10
action permit
policy service service-set http
policy service service-set ftp
policy destination 192.168.0.6 0
#
policy interzone trust untrust outbound
policy 10
action permit
policy source 192.168.0.0 0.0.0.255
#
policy interzone trust dmz outbound
policy 10
action permit
policy service service-set ftp
policy source 192.168.0.0 0.0.0.255
policy destination 172.16.1.11 0
policy 20
action permit
policy service service-set http
policy source 192.168.0.0 0.0.0.255
policy destination 172.16.1.12 0
#
policy interzone dmz untrust inbound
policy 10
action permit
policy service service-set http
policy destination 172.16.1.12 0
policy 20
action permit
policy service service-set ftp
policy destination 172.16.1.11 0
#
nat-policy interzone trust untrust inbound
policy 10
action source-nat
policy destination 192.168.0.6 0
address-group 1
#
nat-policy interzone trust untrust outbound
policy 10
action source-nat
policy source 192.168.0.0 0.0.0.255
easy-ip GigabitEthernet0/0/2
nat-policy zone trust
policy 10
action source-nat
policy destination 192.168.0.6 0
address-group 2
- 华为防火墙配置NAT
- 华为防火墙NAT配置
- 华为USG防火墙 NAT配置
- 华为NAT配置
- 华为usg2220防火墙配置
- 华为防火墙安全策略配置
- 华为USG域内nat配置
- 华为路由器域内NAT配置
- 华为路由器-防火墙配置命令
- 华为路由器防火墙配置命令
- 华为防火墙地址转换配置
- 华为USG防火墙基本配置
- 华为USG防火墙区域配置
- 华为防火墙VPN-GRE配置
- 华为Eudemon1000防火墙-详细配置
- 9.4 iptables防火墙的NAT配置
- 高端防火墙NAT典型配置举例
- USG防火墙 配置域内NAT+NAT Server双出口
- python oj第一弹
- R语言:画q-q图
- uDig+Geoserver 发布shp
- 总结iframe高度自适应,自适应子页面高度
- Myeclipse背景颜色配置
- 华为防火墙配置NAT
- LeetCode 14. Longest Common Prefix
- 栈与堆
- ArrayList,LinkedList,Stack,Queue,PriorityQueue 基本概念
- Elasticsearch Date Histogram 时区问题
- 1042. 字符统计(20) PAT
- JAVA读取TXT文件 写入TXT文件
- 【剑指offer-解题系列(17)】树的子结构
- 3-Python-字典、元组、函数(上)