华为eNSP防火墙 配置使用NAT
华为eNSP防火墙配置
1.配置NAPT源NAT转换

NAT地址池使用192.168.200.10和192.168.200.11两个互联网IP地址
[USG6000V1]nat address-group isp_ip
[USG6000V1-address-group-isp_ip]section 192.168.200.10 192.168.200.11 #配置互联网固定IP地址
[USG6000V1-address-group-isp_ip]mode pat #配置NAT模式为pat
配置允许访问的IP地址
[USG6000V1]ip address-set permit_ip type object #进入对象配置[USG6000V1-object-address-set-deny_ip]address 192.168.100.100 0 #配置单个IP地址
配置防火墙源NAT策略
[USG6000V1]nat-policy
[USG6000V1-policy-nat]rule name to_internet
[USG6000V1-policy-nat-rule-to_internet]destination-address any
[USG6000V1-policy-nat-rule-to_internet]source-address address-set permit_ip
[USG6000V1-policy-nat-rule-to_internet]source-zone trust
[USG6000V1-policy-nat-rule-to_internet]destination-zone untrust
[USG6000V1-policy-nat-rule-to_internet]action source-nat address-group isp_ip
2.配置No-PAT源NAT转换

NAT地址池使用192.168.200.10和192.168.200.11两个互联网IP地址
[USG6000V1]nat address-group isp_ip
[USG6000V1-address-group-isp_ip]section 192.168.200.10 192.168.200.11 #配置互联网固定IP地址
[USG6000V1-address-group-isp_ip]mode no-pat local #配置NAT模式为no-pat 配置允许访问的IP地址
[USG6000V1]ip address-set permit_ip type object #进入对象配置
配置NAT服务器映射
[USG6000V1-object-address-set-deny_ip]address 192.168.100.100 0 #配置单个IP地址
配置防火墙源NAT策略
[USG6000V1]nat-policy
[USG6000V1-policy-nat]rule name to_internet
[USG6000V1-policy-nat-rule-to_internet]destination-address any
[USG6000V1-policy-nat-rule-to_internet]source-address address-set permit_ip
[USG6000V1-policy-nat-rule-to_internet]source-zone trust
[USG6000V1-policy-nat-rule-to_internet]destination-zone untrust
[USG6000V1-policy-nat-rule-to_internet]action source-nat address-group isp_ip
3.配置NAT服务器映射

将接口添加到DMZ区域
[USG6000V1]firewall zone dmz
[USG6000V1-zone-dmz]add int g1/0/2
配置安全策略
[USG6000V1]security-policy
[USG6000V1-policy-security]rule name untrust_to_dmz
[USG6000V1-policy-security-rule-untrust_to_dmz]source-zone untrust
[USG6000V1-policy-security-rule-untrust_to_dmz]destination-zone dmz
[USG6000V1-policy-security-rule-untrust_to_dmz]destination-address 192.168.10.100 32
[USG6000V1-policy-security-rule-untrust_to_dmz]service http
[USG6000V1-policy-security-rule-untrust_to_dmz]action permit
配置NAT服务器映射
[USG6000V1]nat server Server1 protocol tcp global 192.168.200.1 5055 inside
192.168.10.100 80 #将192.168.10.100服务器的80端口映射到互联网IP地址192.168.200.1的5055端口
更多推荐
所有评论(0)