华为防火墙地址转换
配置要求:
202.100.1.100 80、202.100.1.100 2121;(设置允许服务器访问外部,和不允许访问外部资源);
2、允许trust 访问Untrust区域资源,(使用AR2 telnet,pingAR1测试),使用基于源IP地址NO-pat,NAPt,
以及基于端口的地址转换easy-Ip
一、基本配置:
1、配置路由器
AR1
interface GigabitEthernet0/0/0
Ip address 202.100.1.1 24
quit
interface loopback 0
ip address 1.1.1.1 32
quit
ip route-static 0.0.0.0 0 202.100.1.10
配置telnet 用户名:huawei 密码:huawei123
user-interface vty 0 4
quit
aaa
quit
AR2
interface GigabitEthernet0/0/0
Ip address 192.168.1.1 24
quit
interface loopback 0
ip address 2.2.2.2 32
quit
ip route-static 0.0.0.0 0 192.168.1.10
2、配置ip及区域
FW1
interface GigabitEthernet0/0/0
quit
interface GigabitEthernet0/0/1
quit
interface GigabitEthernet0/0/2
quit
firewall zone trust
quit
firewall zone untrust
quit
firewall zone dmz
quit
firewall session link-state check ==启动会话链路状态检查
firewall packet-filter default deny all ==拒接所有流量
配置访问策略
(允许192.168.1.0/24 telnet 和ping Untrust区域 )
policy interzone trust untrust outbound
(允许untrust区域访问HTTP,和FTP服务器)
policy interzone dmz untrust inbound
启动FTP流量监控:
firewall interzone dmz untrust
client可以访问FTP
client可以访问HTTP
查看策略应用:
二、 配置地址转换;
1、trust到untrust地址转换
nat address-group 0 202.100.1.100 202.100.1.200 配置地址池
配置nat策略
nat-policy interzone trust untrust outbound
{
配置一对一地址转换
nat-policy interzone trust untrust outbound
转换为接口IP地址
nat-policy interzone trust untrust outbound
}
查看配置
{不允许服务器访问外部资源
}
配置查看[huaweiFW]display current-configuration
12:47:36 2015/02/05
#
stp region-configuration
#
interface GigabitEthernet0/0/0
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface NULL0
#
firewall zone local
#
firewall zone trust
#
firewall zone untrust
#
firewall zone dmz
#
firewall interzone dmz untrust
#
#
aaa
#
nqa-jitter tag-version 1
#
#
user-interface con 0
user-interface vty 0 4
#
#
right-manager server-group
#
#
#
#
#
#
#
#
#
#
#
#
policy interzone trust untrust outbound
#
policy interzone dmz untrust inbound
#
nat-policy interzone trust untrust outbound
#
return
[huaweiFW] :
发表评论