紧接网络地址转换(1)
实验证明,pc1可以ping通pc2,但是pc2并不可以ping通pc1,以下步骤可以让pc2ping通pc1
步骤一:![](https://img-blog.csdnimg.cn/7ca1282325194a2db1d2feba6b5749f7.png)
[USG6000V1]nat server protocol icmp global 2.2.2.6 inside 192.168.1.10
[USG6000V1]dis firewall server-map
步骤二:
[USG6000V1-policy-security]rule name server_net
[USG6000V1-policy-security-rule-server_net]source-address 2.2.2.0 24
[USG6000V1-policy-security-rule-server_net]rule name server_net
[USG6000V1-policy-security-rule-server_net]source-zone untrust
[USG6000V1-policy-security-rule-server_net]destination-zone trust
[USG6000V1-policy-security-rule-server_net]action permit
[USG6000V1-policy-security-rule-server_net]q
[USG6000V1-policy-security]dis this