
一、配置接口inside、outside
# D. A. C H" T: w m0 w" |interface g0/0
$ X& |+ G0 G+ Uspeed auto
! |% ~& p4 o( {2 fduplex auto3 y% _& k3 {! f, f* D% P3 d
nameif inside
4 P7 e" b, c/ f( }& b/ K/ {/ f7 pSecurity-level 100
$ ^* x9 D- r4 V* B9 S* }7 R) }) H4 vip address 192.168.8.1 255.255.0.0
+ N9 \8 m$ H* b( D4 W6 Y- R" Sno shut
( N/ {8 _7 P& a' j5 [+ b" k6 cexit7 J4 L( v7 |$ F( f* y' q. z5 p
interface g0/3
/ I' l* o# X* o6 {speed auto
7 x* r- c( { ?4 q4 j7 e* u2 Nduplex auto
+ J0 y: l* ]) \4 A) Z/ W" Snameif outside 5 |7 g0 P# a2 Q$ ?& c) @
Security-level 0
- N, c: `8 [" B: e# c S' Uip address 223.82.254.70 255.0.0.0
7 W2 |( X: K8 I" a3 ]8 u: sno shut
) k. G, P/ c0 Y: ^! J' R' `exit2 z) ~6 u" z* j. U* R
2 C2 t8 Q! q7 G二、添加外网路由8 h; r1 U* j- c* w
route outside 0 0 223.82.254.1
7 |' @" J+ k7 e$ h. w三、nat转换,使得内网可以上网8 S, V+ j/ R; z% i6 J+ r
nat-control9 S _9 x, B; q+ v
nat (inside) 1 192.168.0.0 255.255.0.0+ N- b) G* m" Y2 q
global (outside) 1 interface
! C8 ~% ~4 I' Q0 D% `$ W9 M1 o% C, Z1 W1 Q& Y
四、静态nat,对外网IP的访问转换到inside的服务器. v5 t8 T! B7 C. N' O6 L
static (inside,outside) 223.82.254.71 192.168.8.11 netmask 255.255.255.255 dns
# L! {: M% u7 m, \* U, Qaccess-list out_inside extended permit tcp any host 223.82.254.71 eq www
6 W [/ p+ _& j" F& k8 X7 v, q% Waccess-group out_inside in interface outside+ B; [3 @3 U( u# {& V; f6 |0 {) Z3 F) N
$ ?# b5 ?, q, }5 O2 B! {请问访问 http://223.82.254.71 是否可以通? 7 ~* X8 J0 X4 _$ {
|
评分
-
查看全部评分
|