1. 程式人生 > >華為防火牆配置NAT

華為防火牆配置NAT



interface GigabitEthernet0/0/0
 alias GE0/MGMT
 ip address 172.16.1.1 255.255.255.0
#
interface GigabitEthernet0/0/1
 ip address 192.168.0.1 255.255.255.0
#
interface GigabitEthernet0/0/2
 ip address 202.1.1.1 255.255.255.0

firewall zone local
 set priority 100
#
firewall zone trust
 set priority 85
 add interface GigabitEthernet0/0/1
#
firewall zone untrust
 set priority 5
 add interface GigabitEthernet0/0/2
#
firewall zone dmz
 set priority 50
 add interface GigabitEthernet0/0/0
#
firewall interzone trust untrust
 detect ftp
#
firewall interzone trust dmz
 detect ftp
#
firewall interzone dmz untrust
 detect ftp

ip route-static 0.0.0.0 0.0.0.0 202.1.1.2

 nat address-group 1 192.168.0.10 192.168.0.20
 nat address-group 2 192.168.0.30 192.168.0.40
 nat server 0 zone untrust protocol tcp global 11.11.11.11 ftp inside 172.16.1.11 ftp
 nat server 1 zone untrust protocol tcp global 11.11.11.12 www inside 172.16.1.12 www
 nat server 2 zone trust protocol tcp global 11.11.11.11 ftp inside 172.16.1.11 ftp
 nat server 3 zone trust protocol tcp global 11.11.11.12 www inside 172.16.1.12 www
 nat server 4 protocol tcp global 11.11.11.6 www inside 192.168.0.6 www

nat server 5 protocol tcp global 11.11.11.6 ftp inside 192.168.0.6 ftp

#
policy interzone trust untrust inbound
 policy 10
  action permit
  policy service service-set http
  policy service service-set ftp
  policy destination 192.168.0.6 0
#
policy interzone trust untrust outbound
 policy 10
  action permit
  policy source 192.168.0.0 0.0.0.255
#
policy interzone trust dmz outbound
 policy 10
  action permit
  policy service service-set ftp
  policy source 192.168.0.0 0.0.0.255
  policy destination 172.16.1.11 0

 policy 20
  action permit
  policy service service-set http
  policy source 192.168.0.0 0.0.0.255
  policy destination 172.16.1.12 0
#
policy interzone dmz untrust inbound
 policy 10
  action permit
  policy service service-set http
  policy destination 172.16.1.12 0

 policy 20
  action permit
  policy service service-set ftp
  policy destination 172.16.1.11 0
#
nat-policy interzone trust untrust inbound
 policy 10
  action source-nat
  policy destination 192.168.0.6 0
  address-group 1
#
nat-policy interzone trust untrust outbound
 policy 10
  action source-nat
  policy source 192.168.0.0 0.0.0.255
  easy-ip GigabitEthernet0/0/2

nat-policy zone trust
 policy 10
  action source-nat
  policy destination 192.168.0.6 0
  address-group 2