pixfirewall(config)# sh run
interface Ethernet0
nameif inside
security-level 100
ip address 172.16.1.1 255.255.255.0
!
interface Ethernet1
nameif outside
security-level 0
ip address 192.168.1.1 255.255.255.0
!
interface Ethernet2
nameif dmz
security-level 50
ip address 10.10.1.1 255.255.255.0
!
access-list 1 extended permit ip any host 192.168.1.111
access-list 1 extended permit ip any host 192.168.1.10
global (outside) 1 192.168.1.111
nat (inside) 1 0.0.0.0 0.0.0.0
alias (inside) 1.1.10.1 192.168.1.10 255.255.255.255 ----发起去往外部网络接口的内部网络接口的名称。
用于替换外部IP地址的内部IP地址,这两个地址表示处于内部网络中的同一台主机。
一个要被内部IP地址替换的外部IP地址,这两个地址表示处于内部网络中的同一台主机
static (inside,outside) 192.168.1.10 1.1.10.1 netmask 255.255.255.255
access-group 1 in interface outside
route inside 1.1.0.0 255.255.0.0 172.16.1.2 1
route outside 2.2.2.0 255.255.255.0 192.168.1.2 1
route dmz 3.3.3.0 255.255.255.0 10.10.1.2 1
R1#sh run
interface Loopback0
ip address 1.1.1.1 255.255.255.0
!
interface Loopback2
ip address 1.1.10.1 255.255.255.0
!
interface FastEthernet0/0
ip address 172.16.1.2 255.255.255.0
duplex auto
speed auto
!
ip route 0.0.0.0 0.0.0.0 172.16.1.1
R2#sh run
interface Loopback0
ip address 2.2.2.2 255.255.255.0
!
interface FastEthernet0/0
ip address 192.168.1.2 255.255.255.0
duplex auto
speed auto
!
ip route 0.0.0.0 0.0.0.0 192.168.1.1
阅读(1041) | 评论(0) | 转发(0) |