这两天搞路由器设置焦头烂额,总算有点儿眉目了,可是一个问题困扰着我。如下:
我只有一个公网IP地址(218.92.250.70),因为安装了路由器所有只好把它绑定到路由器上。可是我又想让外面的用户能通过 http://218.92.250.70 访问到我的WEB服务器,请教高手,他们提示我做端口重定向,这样可以透过路由器访问到内部的WEB服务器,成功了,请了许多网友访问,都能看到。可是我在局域网内部访问 http://218.92.250.70 时,却不能看到内容。这是什么原因?
我的路由器(CABLETRON Smart Switch Router 2000)现有设置(配置命令)如下:
1 : acl inside permit ip 192.168.21.0/24
2 : acl inside permit ip 192.168.22.0/24
3 : acl inside permit ip 192.168.23.0/24
4 : acl inside permit ip 192.168.31.0/24
5 : acl inside permit ip 192.168.32.0/24
6 : acl inside permit ip 192.168.33.0/24
7 : acl inside permit ip 192.168.42.0/24
8 : acl inside permit ip 192.168.1.0/24
9 : acl inside permit ip 192.168.88.0/24
10 : acl inside permit ip 192.168.66.0/24
19 : interface create ip isp address-netmask 218.92.250.70/30 port et.1.1
20 : interface create ip en1 address-netmask 192.168.21.1/24 vlan computer1
21 : interface create ip en2 address-netmask 192.168.22.1/24 vlan computer2
22 : interface create ip en3 address-netmask 192.168.23.1/24 vlan computer3
23 : interface create ip en4 address-netmask 192.168.31.1/24 vlan computer4
24 : interface create ip en5 address-netmask 192.168.32.1/24 vlan computer5
25 : interface create ip en6 address-netmask 192.168.33.1/24 vlan computer6
26 : interface create ip en7 address-netmask 192.168.42.1/24 vlan computer7
27 : interface create ip en8 address-netmask 192.168.1.1/24 vlan teacher
28 : interface create ip en9 address-netmask 192.168.88.88/24 vlan home
29 : interface create ip en10 address-netmask 192.168.66.66/24 vlan floor
30 : ip add route default gateway 218.92.250.69
31 : nat create dynamic local-acl-pool inside global-pool 218.92.250.70 enable-ip-overload
32 : nat create static protocol tcp global-ip 218.92.250.70 global-port 80 local-ip 192.168.88.1 local-port 80
33 : nat create static protocol tcp global-ip 218.92.250.70 global-port 21 local-ip 192.168.88.1 local-port 21
############
32、33两行就是我做的(WEB和FTP默认)端口重定向设置。
############
34 : nat set interface isp outside
35 : nat set interface en1 inside
36 : nat set interface en2 inside
37 : nat set interface en3 inside
38 : nat set interface en4 inside
39 : nat set interface en5 inside
40 : nat set interface en6 inside
41 : nat set interface en7 inside
42 : nat set interface en8 inside
43 : nat set interface en9 inside
44 : nat set interface en10 inside
……
49 : vlan add ports et.2.2 to computer1
50 : vlan add ports et.2.3 to computer2
51 : vlan add ports et.2.4 to computer3
52 : vlan add ports et.2.5 to computer4
53 : vlan add ports et.2.6 to computer5
54 : vlan add ports et.2.7 to computer6
55 : vlan add ports et.2.8 to computer7
56 : vlan add ports et.1.8 to teacher
57 : vlan add ports et.2.1 to teacher
58 : vlan add ports et.1.(2-5) to home
59 : vlan add ports et.1.(6-7) to floor
60 : vlan create computer1 port-based id 3
61 : vlan create computer2 port-based id 4
62 : vlan create computer3 port-based id 5
63 : vlan create computer4 port-based id 6
64 : vlan create computer5 port-based id 7
65 : vlan create computer6 port-based id 8
66 : vlan create computer7 port-based id 9
67 : vlan create teacher port-based id 10
68 : vlan create home port-based id 11
69 : vlan create floor port-based id 12
我是通过设定路由器的DHCP功能(上表未列出具体命令)得到的局域网IP地址192.168.1.12,即我在名为 “teacher“ 的VLAN中,按我的想象,他应该通过网关(192.168.1.1)访问218.92.250.70,HTTP访问时,当然也会访问默认端口(80),可是我为什么不成功?而外面的用户却能访问呢?路由究竟干什么的?网关又是干什么的?端口端口映射为什么对内部机器就不起作用了呢?~~~ 一头雾水~~
人打赏
0人 点赞
主帖获得的天涯分:0
举报 |
楼主
|
楼主发言:6次 发图:0张 | 添加到话题 |