配置防火墙g0/0/2端口添加至trust域,g0/0/1端口添加至untrust域。配置trust域到untrust域规则,放行内部地址172.16.105.0/24网段。配置NAT规则,匹配内部地址172.16.105.0/24网段,使用g0/0/1端口的地址进行转换。
[SRG]firewall zone trust
[SRG-zone-trust]int g 0/0/2
[SRG-GigabitEthernet0/0/2]q
[SRG]firewall zone untrust
[SRG-zone-untrust]int g0/0/1
[SRG-GigabitEthernet0/0/1]q
[SRG]policy interzone trust untrust outbound
[SRG-policy-interzone-trust-untrust-outbound]policy 0
[SRG-policy-interzone-trust-untrust-outbound-0]action permit
[SRG-policy-interzone-trust-untrust-outbound-0]policy source 172.16.105.0 0.0.0.
255
[SRG-policy-interzone-trust-untrust-outbound-0]q
[SRG-policy-interzone-trust-untrust-outbound]q
[SRG]nat-policy interzone trust untrust outbound
[SRG-nat-policy-interzone-trust-untrust-outbound]policy 1
[SRG-nat-policy-interzone-trust-untrust-outbound-1]action source-nat
[SRG-nat-policy-interzone-trust-untrust-outbound-1]policy source172.16.105.0 0.2
55.255.255
[SRG-nat-policy-interzone-trust-untrust-outbound-1]easy-ip g 0/0/1