3.5 防火墙源NAT-Easy-IP
1.创建NAT策略绑定地址组 nat-policy rule name 192_168_1_0_nat source-zone trust destination-zone untrust source-address 192.168.1.0 mask 255.255.255.0 action source-nat easy-ip 2.内...
3.4 防火墙源NAT-Smart-NAT
1.创建公有地址组 nat address-group ag11 mode no-pat global route enable smart-nopat 120.1.1.104 section 0 120.1.1.101 120.1.1.103 2.创建NAT策略绑定地址组 nat-policy rule name 192_1...
3.3 防火墙源NAT-NAPT
1.创建地址组(端口转换) nat address-group ag11 mode pat route enable section 0 120.1.1.101 120.1.1.101 2.创建NAT策略绑定地址组 nat-policy rule name 192_168_1_0_nat source-zone tru...
3.2 防火墙源NAT-No-PAT
1.防火墙基本配置 #配置地址 interface GigabitEthernet1/0/0 ip address 192.168.1.254 255.255.255.0 service-manage all permit interface GigabitEthernet1/0/1 ip address 12.1.1.1 255.25...
第3章 防火墙NAT-3.1 路由器ACL与NAT
1.基于路由器的ACL 1)基本访问控制列表,匹配源地址 #定义acl匹配规则 acl number 2000 rule 10 deny source 192.168.1.1 0 #在接口进方向过滤acl interface GigabitEthernet0/0/1 traffic-fil...