netscreen 外网访问VIP配置

1、编辑interface

Network > Interfaces (List)


List per page      
 List  Interfaces  

 

 


 
NameIP/Netmask Zone TypeLinkConfigure
serial0.0.0.0/0NullUnuseddownEdit  
trust172.2.1.254/24TrustLayer3upEdit  
tunnel.1unnumberedUntrustTunnelreadyEdit  
untrust58.2.24.246/32UntrustLayer3upEdit  
vlan10.0.0.0/0VLANLayer3downEdit  
 

2、配置untrust

Network > Interfaces > Edit

 


Interface: untrust (IP/Netmask: 58.2.24.246/32)Back To Interface List  
 Properties:  Basic    MIP     DIP     VIP     Track IP     Track IP Options    

 

 

 


 
Interface Nameuntrust (mac 0010.db39.9051)
As member of loopback group
Zone Name

       Obtain IP using PPPoE Create new pppoe setting
    Status: Connected
       Static IP
IP Address / Netmask  /       Manageable
Manage IP (mac 0010.db39.9051)

Interface Mode NAT Route

        Service Options 
Management Services
 Web UI  Telnet  SSH
 SNMP  SSL 
Other Services
 Ping  Ident-reset   

WebAuth    IP 

Traffic Bandwidth  Kbps

         

 

 

3、创建VIP

Network > Interface > Edit > VIP/VIP Services

Interface: untrust (IP/Netmask: 58.2.24.246/32)Back To Interface List  
 Properties:  Basic     MIP     DIP     VIP    Track IP     Track IP Options      

 

 


 
VIPVIP Services
IP AddressConfigureVirtual PortService(Port)Server IPStatusConfigure
58.2.24.246Edit In use 9080was (9080)172.2.1.110...OKEdit Remove
 

 

 

这是已配置好的VIP,先增加一个VIP,再增加VIP Services,外网端口9080,映射服务端口为was(9080),映射内网主机为172.2.1.110

 

 

4、配置访问策略

 












































From Untrust To Global, total policy: 1
IDSourceDestinationServiceActionOptionsConfigureEnableMove
5AnyVIP::1ANYIndex: 3
Permit Edit Clone Remove Disable policy Move policy  Move policy
 

 

这是已配置好的访问策略policies,方向为Untrust 到Global

 

5、访问策略配置

 

Name (optional)
Source Address New Address /
Address Book Entry
Destination Address New Address /
Address Book Entry
Service
Application

Action  
Tunnel VPN
       Modify matching bidirectional VPN policy
 L2TP  
Logging

         
 

6、服务端口定制custom,即上面的VIP::1

Objects > Services > Custom

 


 
NameTransport Protocol and ParametersTimeout (min)Configure
wasTCP src port: 0-65535, dst port: 9080-9080default[30]Edit In Use
 

 

详细配置:

Service Name
Service Timeout
No.Transport protocolSource PortDestination PortICMP
LowHighLowHighTypeCode
1 none TCP UDP ICMP other
2 none TCP UDP ICMP other
3 none TCP UDP ICMP other
4 none TCP UDP ICMP other
5 none TCP UDP ICMP other
6 none TCP UDP ICMP other
7 none TCP UDP ICMP other
8 none TCP UDP ICMP other

 

 

 

 

 

 

 

 

 

 

 

 

 

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 1
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值