分类: 系统运维
2008-05-08 13:20:30
公网地址:10.1.1.1
实现方式:PAT
PC上网要求:所有PC设备都可以上网。
服务器要求:使FTP/WWW/WWW8080/SMPT可以被公网上的PC访问。
PC上网NAT配置:
[Quidway] nat address-group 1 10.1.1.1 10.1.1.1
//指定外网地址池
[Quidway] acl number 2000
[Quidway-acl-basic-2000] rule permit source any
[Quidway-acl-basic-2000] quit
//与cisco acl规则相同,此处允许任意PC上网
[Quidway] interface Ethernet 0/0/0
[Quidway-Ethernet0/0/0] nat outbound 2000 address-group 1
//定义nat规则
服务器NAT配置:
[Quidway-Ethernet0/0/0] nat server protocol tcp global 10.1.1.1 ftp inside 192.168.1.200 ftp
//配置ftp服务器提供外网服务
[Quidway-Ethernet0/0/0] nat server protocol tcp global 10.1.1.1 www inside 192.168.1.201 www
//配置www服务器提供外网服务
[Quidway-Ethernet0/0/0] nat server protocol tcp global 10.1.1.1 8080 inside 192.168.1.202
//配置www服务器提供外网服务8080端口
[Quidway-Ethernet0/0/0] nat server protocol tcp global 10.1.1.1 smtp inside 192.168.1.203 smtp
//配置smpt服务器提供外网服务
[Quidway-Ethernet0/0/0]nat server protocol tcp global 10.1.1.1 ftp inside 192.168.1.203 ?
<0-65535> Port number of the server
CHARgen Character generator (19)
any Any protocol (0)
bgp Border Gateway Protocol (179)
cmd Remote commands (rcmd, 514)
daytime Daytime (13)
discard Discard (9)
domain Domain Name Service (53)
echo Echo (7)
exec Exec (rsh, 512)
finger Finger (79)
ftp File Transfer Protocol (21)
gopher Gopher (70)
hostname NIC hostname server (101)
irc Internet Relay Chat (194)
klogin Kerberos login (543)
kshell Kerberos shell (544)
login Login (rlogin, 513)
lpd Printer service (515)
nntp Network News Transport Protocol (119)
pop2 Post Office Protocol v2 (109)
pop3 Post Office Protocol v3 (110)
pptp Point-to-Point Tunneling Protocol (PPTP 1723)
smtp Simple Mail Transport Protocol (25)
sunrpc Sun Remote Procedure Call (111)
tacacs TAC Access Control System (49)
talk Talk (517)
telnet Telnet (23)
time Time (37)
uucp Unix-to-Unix Copy Program (540)
whois Nicname (43)
www World Wide Web (HTTP, 80)