HUAWEI USG NAT OUTBOUND
ensp 1.2.00.350
USG5500
内网用户做NAT端口转换200.1.1.1访问互联
外网不能访问内网用户
内网:11.1.1.0/24
外网:200.1.1.0/24
外网不能访问内网用户
system-view
#配置防火墙的ip地址
interface g0/0/1
ip add 200.1.1.1 24
quit
interface g0/0/0
ip add 11.1.1.1 24
quit
#配置接口安全区域
firewall zone trust
add interface g0/0/0
quit
firewall zone untrust
add interface g0/0/1
quit
#配置域间包过滤策略
policy interzone trust untrust outbound
policy 0
action permit
policy source 11.1.1.0 mask 24
quit
quit
#配置NAT地址池
nat address-group 1 200.1.1.1 200.1.1.1
#配置NAT policy
nat-policy interzone trust untrust outbound
policy 1
action source-nat
policy destination any
address-group 1
policy source 11.1.1.0 0.0.0.255
quit
quit
查看防火墙NAT会话列表
[SRG]display firewall session table
18:45:42 2014/09/23
Current Total Sessions : 3
icmp VPN:public --> public 11.1.1.12:256[200.1.1.1:2053]-->200.1.1.2:2048
http VPN:public --> public 11.1.1.12:2063[200.1.1.1:2055]-->200.1.1.2:80
http VPN:public --> public 11.1.1.12:2064[200.1.1.1:2056]-->200.1.1.2:80
查看nat-policy配置
[SRG]dis nat-policy interzone trust untrust outbound
19:34:19 2014/09/23
nat-policy interzone trust untrust outbound
policy 1 (9 times matched)
action source-nat
policy service service-set ip
policy source 11.1.1.0 0.0.0.255
policy destination any
address-group 0