ASA防火墙如何配置成2个虚拟防火墙,做好有配置实例
发布网友
发布时间:2022-04-21 04:40
我来回答
共1个回答
热心网友
时间:2022-06-18 00:59
如果主机不用划VLAN做单臂路由
只需要运用到NAT知识点和端口映射知识点
配置很简单,如下。
(假设PC0、PC1是自动获取IP地址、服务器设置成192.168.1.2 255.255.255.0的静态C类IP)
Router>en
Router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Router4(config)#interface f0/1
Router4(config-if)#no shutdown
Router4(config-if)#ip address 100.100.100.1 255.255.255.0
Router4(config-if)#ip nat outside
Router4(config-if)#exit
Router4(config)#interface f0/0
Router4(config-if)#no shutdown
Router4(config-if)#ip nat inside
Router4(config-if)#exit
Router4(config)#ip dhcp pool 1
Router4(dhcp-config)#network 192.168.1.0 255.255.255.0
Router4(dhcp-config)#default-router 192.168.1.1
Router4(dhcp-config)#dns 202.103.24.68
Router4(dhcp-config)#exit
Router4(config)#ip dhcp ex 192.168.1.1
Router4(config)#access-list 1 permit 192.168.0.0 0.0.255.255
Router4(config)#ip nat inside source list 1 interface f0/1 overload
Router>en
Router#conf t
Router5(config)#inter f0/1
Router5(config-if)#no shutdown
Router5(config-if)#ip address 100.100.100.100 255.255.255.0
Router5(config-if)#ip nat outside
Router5(config-if)#exit
Router5(config)#interface f0/0
Router5(config-if)#no shutdown
Router5(config-if)#ip add 192.168.1.1 255.255.255.0
Router5(config-if)#ip nat inside
Router5(config-if)#exit
Router5(config)#ip nat
Router5(config)#access-list 1 permit 192.168.0.0 0.0.255.255
Router5(config)#ip nat inside source list 1 interface f0/1 overload
Router5(config)#ip nat inside source static tcp 192.168.1.2 80 100.100.100.100 80