華為防火牆配置NAT
interface GigabitEthernet0/0/0
alias GE0/MGMT
ip address 172.16.1.1 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 192.168.0.1 255.255.255.0
#
interface GigabitEthernet0/0/2
ip address 202.1.1.1 255.255.255.0
firewall zone local
set priority 100
#
firewall zone trust
set priority 85
add interface GigabitEthernet0/0/1
#
firewall zone untrust
set priority 5
add interface GigabitEthernet0/0/2
#
firewall zone dmz
set priority 50
add interface GigabitEthernet0/0/0
#
firewall interzone trust untrust
detect ftp
#
firewall interzone trust dmz
detect ftp
#
firewall interzone dmz untrust
detect ftp
ip route-static 0.0.0.0 0.0.0.0 202.1.1.2
nat address-group 1 192.168.0.10 192.168.0.20
nat address-group 2 192.168.0.30 192.168.0.40
nat server 0 zone untrust protocol tcp global 11.11.11.11 ftp inside 172.16.1.11 ftp
nat server 1 zone untrust protocol tcp global 11.11.11.12 www inside 172.16.1.12 www
nat server 2 zone trust protocol tcp global 11.11.11.11 ftp inside 172.16.1.11 ftp
nat server 3 zone trust protocol tcp global 11.11.11.12 www inside 172.16.1.12 www
nat server 4 protocol tcp global 11.11.11.6 www inside 192.168.0.6 www
nat server 5 protocol tcp global 11.11.11.6 ftp inside 192.168.0.6 ftp
#
policy interzone trust untrust inbound
policy 10
action permit
policy service service-set http
policy service service-set ftp
policy destination 192.168.0.6 0
#
policy interzone trust untrust outbound
policy 10
action permit
policy source 192.168.0.0 0.0.0.255
#
policy interzone trust dmz outbound
policy 10
action permit
policy service service-set ftp
policy source 192.168.0.0 0.0.0.255
policy destination 172.16.1.11 0
policy 20
action permit
policy service service-set http
policy source 192.168.0.0 0.0.0.255
policy destination 172.16.1.12 0
#
policy interzone dmz untrust inbound
policy 10
action permit
policy service service-set http
policy destination 172.16.1.12 0
policy 20
action permit
policy service service-set ftp
policy destination 172.16.1.11 0
#
nat-policy interzone trust untrust inbound
policy 10
action source-nat
policy destination 192.168.0.6 0
address-group 1
#
nat-policy interzone trust untrust outbound
policy 10
action source-nat
policy source 192.168.0.0 0.0.0.255
easy-ip GigabitEthernet0/0/2
nat-policy zone trust
policy 10
action source-nat
policy destination 192.168.0.6 0
address-group 2