华为防火墙源NAT/Easy_IP配置

实验物理拓扑:

 

实验配置:

FW1:

[FW1]
sysname FW1
#web-manager enable 
interface GigabitEthernet0/0/0   //web管理接口
 undo shutdown
 ip binding vpn-instance default
 ip address 172.16.1.2 255.255.255.0
 service-manage http permit
 service-manage https permit
 service-manage ping permit
 service-manage ssh permit
 service-manage snmp permit
 service-manage telnet permit
 service-manage netconf permit
#
interface GigabitEthernet1/0/0    //trust
 undo shutdown
 ip address 10.1.1.10 255.255.255.0
 service-manage ping permit
#
interface GigabitEthernet1/0/1   //untrust
 undo shutdown
 ip address 202.100.1.10 255.255.255.0
 service-manage ping permit
#
firewall zone trust
 set priority 85
 add interface GigabitEthernet0/0/0
 add interface GigabitEthernet1/0/0
#
firewall zone untrust
 set priority 5
 add interface GigabitEthernet1/0/1
#
nat address-group napt 0
 mode no-pat global
 section 0 202.100.1.100 202.100.1.110
#
 multi-interface
  mode proportion-of-weight
#
security-policy
 rule name trust_untrust
  source-zone trust
  destination-zone untrust
  source-address 10.1.1.0 24
  action permit
#
nat-policy
 rule name NAPT
  source-zone trust
  destination-zone untrust
  action nat address-group napt
#
return
[FW1] 


检查测试:

PC>ping 202.100.1.254

Ping 202.100.1.254: 32 data bytes, Press Ctrl_C to break
Request timeout!
From 202.100.1.254: bytes=32 seq=2 ttl=254 time=46 ms
From 202.100.1.254: bytes=32 seq=3 ttl=254 time=16 ms
From 202.100.1.254: bytes=32 seq=4 ttl=254 time=16 ms
From 202.100.1.254: bytes=32 seq=5 ttl=254 time=15 ms

--- 202.100.1.254 ping statistics ---
  5 packet(s) transmitted
  4 packet(s) received
  20.00% packet loss
  round-trip min/avg/max = 0/23/46 ms
[FW1]dis firewall session table 
 icmp  VPN: public --> public  10.1.1.1:27383[202.100.1.100:27383] --> 202.100.1
.254:2048
[FW1]

Easy_IP配置

检查测试:

PC>ping 202.100.1.254

Ping 202.100.1.254: 32 data bytes, Press Ctrl_C to break
From 202.100.1.254: bytes=32 seq=1 ttl=254 time<1 ms
From 202.100.1.254: bytes=32 seq=2 ttl=254 time=16 ms
From 202.100.1.254: bytes=32 seq=3 ttl=254 time<1 ms
From 202.100.1.254: bytes=32 seq=4 ttl=254 time=15 ms
From 202.100.1.254: bytes=32 seq=5 ttl=254 time=16 ms

--- 202.100.1.254 ping statistics ---
  5 packet(s) transmitted
  5 packet(s) received
  0.00% packet loss
  round-trip min/avg/max = 0/9/16 ms
[FW1]dis firewall session table 
 Current Total Sessions : 10
 icmp  VPN: public --> public  10.1.1.1:4345[202.100.1.10:2055] --> 202.100.1.25
4:2048
 tcp  VPN: default --> default  172.16.1.1:51477 --> 172.16.1.2:8443
 icmp  VPN: public --> public  10.1.1.1:4857[202.100.1.10:2057] --> 202.100.1.25
4:2048

  • 0
    点赞
  • 7
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值