单臂路由(router-on-a-stick)是指在路由器的一个接口上通过配置子接口(或“逻辑接口”,并不存在真正物理接口)的方式,实现原来相互隔离的不同VLAN(虚拟局域网)之间的互联互通。(na)
实现服务器被外网访问,和单臂路由
FW1:
interface GigabitEthernet1/0/0.1
vlan-type dot1q 10 --允许pvid 10的通过,防火墙方式
ip address 192.168.1.254 255.255.255.0
service-manage ping permit
dhcp select interface
#
interface GigabitEthernet1/0/0.2
vlan-type dot1q 20
ip address 192.168.2.254 255.255.255.0
service-manage ping permit
dhcp select interface
#
interface GigabitEthernet1/0/1
undo shutdown
ip address 1.1.1.1 255.255.255.0
ip route-static 0.0.0.0 0.0.0.0 1.1.1.2 静态路由丢给外网路由1.1.1.2
security-policy
rule name internet ---允许内网访问外网
source-zone dmz
source-zone trust
destination-zone untrust
action permit
rule name to_pc2 ---允许vlan10 访问 vlan20
source-zone trust
destination-zone dmz
action permit
rule name visit_server ---允许外网访问服务器
source-zone untrust
destination-zone dmz
action permit
nat-policy
rule name internet ----做easyIP
source-zone dmz
source-zone trust
source-address 192.168.1.0 mask 255.255.255.0
source-address 192.168.2.0 mask 255.255.255.0
action source-nat easy-ip
nat server 0 protocol icmp global 1.1.1.10 inside 192.168.2.2 ---对服务器做nat
interface GigabitEthernet0/0/0
ip address 1.1.2.1 255.255.255.0
nat outbound 2000 ---nat访问
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/1.3
dot1q termination vid 30 ----允许vlan30通过,是路由方式
ip address 192.168.3.254 255.255.255.0
arp broadcast enable
dhcp select interface
#
interface GigabitEthernet0/0/1.4
dot1q termination vid 40
ip address 192.168.4.254 255.255.255.0
dhcp select interface
ip route-static 0.0.0.0 0.0.0.0 1.1.2.2
acl number 2000 ---为路由nat 做acl流量
rule 5 permit source 192.168.3.0 0.0.0.255
rule 10 permit source 192.168.4.0 0.0.0.255
外网访问服务器