2024年4月4日发(作者:业昆皓)
路由模式:
选择y
选择y
重启完成后,按下面配置操作
[H3C]ip rou 0.0.0.0 0 10.81.81.254
[H3C]acl nu 2000
[H3C-acl-2000]rule permit
[H3C-acl-2000]quit
[H3C]firewall packet-filter default permit
[H3C]firewall zone trust
[H3C-zone-trust]add int e1/0
[H3C-zone-trust]firewall zone untrust
[H3C-zone-untrust]add int e2/0
[H3C-zone-untrust]int e1/0
[H3C-Ethernet1/0]ip add 192.168.1.1 24
[H3C-Ethernet1/0]int e2/0
[H3C-Ethernet2/0]ip add 10.81.81.1 24
[H3C-Ethernet2/0]nat out 2000
[H3C-Ethernet2/0]sa
防火墙的LAN口下连的pc将地址设置为192.168.1.2-192.168.1.254范围的任意地
址,网关设置为192.168.1.1,dns设置为10.81.1.14即可
端口映射:
[H3C]int e2/0
[H3C-Ethernet2/0]nat server pro tcp global 10.81.81.101 www inside
192.168.1.2 www
[H3C-Ethernet2/0]sa
透明模式:
选择y
选择y
重启完成后,按下面配置操作
[H3C]firewall packet-filter default permit
[H3C] firewall mode transparent
[H3C] firewall unknown-mac flood
[H3C] firewall unknown-mac broadcast flood
[H3C]firewall zone trust
[H3C-zone-trust]add int e1/0
[H3C-zone-trust]firewall zone untrust
[H3C-zone-untrust]add int e2/0
[H3C-zone-untrust]int e1/0
[H3C]sa
2024年4月4日发(作者:业昆皓)
路由模式:
选择y
选择y
重启完成后,按下面配置操作
[H3C]ip rou 0.0.0.0 0 10.81.81.254
[H3C]acl nu 2000
[H3C-acl-2000]rule permit
[H3C-acl-2000]quit
[H3C]firewall packet-filter default permit
[H3C]firewall zone trust
[H3C-zone-trust]add int e1/0
[H3C-zone-trust]firewall zone untrust
[H3C-zone-untrust]add int e2/0
[H3C-zone-untrust]int e1/0
[H3C-Ethernet1/0]ip add 192.168.1.1 24
[H3C-Ethernet1/0]int e2/0
[H3C-Ethernet2/0]ip add 10.81.81.1 24
[H3C-Ethernet2/0]nat out 2000
[H3C-Ethernet2/0]sa
防火墙的LAN口下连的pc将地址设置为192.168.1.2-192.168.1.254范围的任意地
址,网关设置为192.168.1.1,dns设置为10.81.1.14即可
端口映射:
[H3C]int e2/0
[H3C-Ethernet2/0]nat server pro tcp global 10.81.81.101 www inside
192.168.1.2 www
[H3C-Ethernet2/0]sa
透明模式:
选择y
选择y
重启完成后,按下面配置操作
[H3C]firewall packet-filter default permit
[H3C] firewall mode transparent
[H3C] firewall unknown-mac flood
[H3C] firewall unknown-mac broadcast flood
[H3C]firewall zone trust
[H3C-zone-trust]add int e1/0
[H3C-zone-trust]firewall zone untrust
[H3C-zone-untrust]add int e2/0
[H3C-zone-untrust]int e1/0
[H3C]sa