netscreen 外网访问VIP配置

1、编辑interface

Network > Interfaces (List)


List 5102050100 per page
List ALL(5)Layer2(0)Layer3(3)Loopback(0)Physical(3)Tunnel(1)Unused(1)VSI(0) Interfaces Loopback IFTunnel IFVSI IF


Name IP/Netmask Zone TypeLinkConfigure
serial0.0.0.0/0NullUnuseddown Edit
trust172.2.1.254/24TrustLayer3up Edit
tunnel.1unnumberedUntrustTunnelready Edit
untrust58.2.24.246/32UntrustLayer3up Edit
vlan10.0.0.0/0VLANLayer3down Edit

2、配置untrust

Network > Interfaces > Edit


Interface:untrust(IP/Netmask:58.2.24.246/32) Back To Interface List
Properties:Basic MIP DIP VIP Track IP Track IP Options


Interface Nameuntrust (mac 0010.db39.9051)
As member of loopback groupnone
Zone NameNullTrustUntrustMGTV1-TrustV1-UntrustVLAN

Obtain IP using PPPoE Noneuntrust Create new pppoe setting
Status:Connected
Static IP
IP Address / Netmask / Manageable
Manage IP (mac 0010.db39.9051)

Interface Mode NAT Route

Service Options
Management Services
Web UI Telnet SSH
SNMP SSL
Other Services
Ping Ident-reset

WebAuth IP

Traffic Bandwidth Kbps

3、创建VIP

Network > Interface > Edit > VIP/VIP Services

Interface:untrust(IP/Netmask:58.2.24.246/32) Back To Interface List
Properties:Basic MIP DIP VIP Track IP Track IP Options


VIPVIP Services
IP AddressConfigureVirtual PortService(Port)Server IPStatusConfigure
58.2.24.246 Edit In use 9080was (9080)172.2.1.110...OK Edit Remove

这是已配置好的VIP,先增加一个VIP,再增加VIP Services,外网端口9080,映射服务端口为was(9080),映射内网主机为172.2.1.110

4、配置访问策略

<!-- script language="javascript" src="acl.js" --><!-- /script -->












































From Untrust To Global, total policy: 1
IDSourceDestinationServiceActionOptionsConfigureEnableMove
5AnyVIP::1ANYIndex: 3 Permit Edit Clone Remove Disable policy Move policy Move policy

这是已配置好的访问策略policies,方向为Untrust 到Global

5、访问策略配置

Name (optional)
Source Address New Address /
Address Book Entry 172.25.1.110/9080AnyDial-Up VPNXM
Destination Address New Address /
Address Book Entry AnyDial-Up VPNVIP::1
Service wasANYAOLBGPDHCP-RelayDNSFINGERFTPFTP-GetFTP-PutGOPHERH.323HTTPHTTPSICMP Address MaskICMP-ANYICMP Dest UnreachableICMP Fragment NeededICMP Fragment ReassemblyICMP Host UnreachableICMP-INFOICMP Parameter ProblemICMP Port UnreachableICMP Protocol UnreachICMP RedirectICMP Redirect HostICMP Redirect TOS & HostICMP Redirect TOS & NetICMP Source QuenchICMP Source Route FailICMP Time ExceededICMP-TIMESTAMPIKEIMAPInternet Locator ServiceIRCL2TPLDAPMAILNetMeetingNFSNNTPNS GlobalNS Global PRONSMNTPOSPFPC-AnywherePINGPOP3PPTPReal MediaRIPRLOGINRSHSIPSNMPSQL*Net V1SQL*Net V2SSHSUN-RPCSYSLOGTALKTCP-ANYTELNETTFTPTRACEROUTEUDP-ANYUUCPVDO LiveWAISWINFRAMEX-WINDOWS
ApplicationNoneFTPRSHPORTMAPPERHTTPSMTPPOP3IMAPDNSTFTPH245Q931RASREALSIPSQLNETV2TALKVDOXINGIGNORE

Action PermitDenyTunnel
TunnelVPN None2XM
Modify matching bidirectional VPN policy
L2TP None
Logging

6、服务端口定制custom,即上面的VIP::1

Objects > Services > Custom


NameTransport Protocol and ParametersTimeout (min)Configure
wasTCP src port: 0-65535, dst port: 9080-9080default[30] Edit In Use

详细配置:

Service Name
Service Timeout Use protocol default
Never
Custom (minutes)
No.Transport protocolSource PortDestination PortICMP
LowHighLowHighTypeCode
1 none TCP UDP ICMP other
2 none TCP UDP ICMP other
3 none TCP UDP ICMP other
4 none TCP UDP ICMP other
5 none TCP UDP ICMP other
6 none TCP UDP ICMP other
7 none TCP UDP ICMP other
8 none TCP UDP ICMP other

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值