NAPT配置方式
pc1:ip----192.168.1.100 255.255.255.0 192.168.1.1
pc2:ip ----100.1.1.10 255.255.255.0 100.1.1.1
)实验要求
PC1通过202.106.0.100地址与PC2实现通信!
2)案例实施
<R1>sys
[R1]undo info enable
[R1]int g0/0/0
[R1]ip add 202.106.0.2 24
[R1]undo sh
[R1]int g0/0/1
[R1]ip add 100.1.1.1 24
[R1]undo sh
[FW1]int g1/0/0
[FW1-GigabitEthernet1/0/0]ip add 192.168.1.1 24
[FW1-GigabitEthernet1/0/0]int g1/0/1
[FW1-GigabitEthernet1/0/1]ip add 202.106.0.1 24
[FW1-GigabitEthernet1/0/1]q
[FW1]ip route-static 0.0.0.0 0.0.0.0 202.106.0.2
//配置防火墙网络参数及路由
[FW1]firewall zone trust
[FW1-zone-trust]add int g1/0/0
[FW1-zone-trust]quit
[FW1]firewall zone untrust
[FW1-zone-untrust]add int g1/0/1
[FW1-zone-untrust]quit
[FW1]security-policy
[FW1-policy-security]rule name sec_2
[FW1-policy-security-rule-sec_2]source-zone trust
[FW1-policy-security-rule-sec_2]source-address 192.168.1.0 24
[FW1-policy-security-rule-sec_2]destination-zone untrust
[FW1-policy-security-rule-sec_2]action permit
[FW1-pol