欢迎光临
我们一直在努力

Juniper NetScreen 基于源NAT转换

1.NAT-Src with PAT Enabled

CLI:

set int eth2 zone trust

set int eth2 ip 10.1.1.1/24

set int eth2 nat

set int eth4 zone untrust

set int eth4 ip 1.1.1.1/24

set int eth4 route

set int eth4 dip 5 1.1.1.30 1.1.1.30

set policy from trust to untrust any any any nat src dip-id 5 permit log

2.NAT-Src with PAT Disabled

CLI:

set int eth2 zone trust

set int eth2 ip 10.1.1.1/24

set int eth2 nat

set int eth4 zone untrust

set int eth4 ip 1.1.1.1/24

set int eth4 route

set int eth4 dip 6 1.1.1.50 1.1.1.150 fix-port

set policy from trust to untrust any any any nat src dip-ip 6 permit log

3.NAT-Src with Address Shifting

CLI:

set int eth2 zone trust

set int eth2 ip 10.1.1.1/24

set int eth2 nat

set int eth4 zone untrust

set int eth4 ip 1.1.1.1/24

set int eth4 ip route

set int eth4 dip 10 shift-from 10.1.1.11 to 1.1.1.101 1.1.1.105

set address trust host1 10.1.1.11/32

set address trust host2 10.1.1.12/32

set address trust host3 10.1.1.13/32

set address trust host4 10.1.1.14/32

set address trust host5 10.1.1.15/32

set group address trust group1 add host1

set group address trust group1 add host2

set group address trust group1 add host3

set group address trust group1 add host4

set group address trust group1 add host5

set policy from trust to untrust group1 any any nat src dip-id 10 permit log

3.NAT-Src Without DIP

CLI :

set int eth2 zone trust

set int eth2 ip 10.1.1.1/24

set int eth2 nat

set int eth4 zone untrust

set int eth4 ip 1.1.1.1/24

set int eth4 route

set policy from trust to untrust any any any nat src  permit log

赞(0)
【声明】:本博客不参与任何交易,也非中介,仅记录个人感兴趣的主机测评结果和优惠活动,内容均不作直接、间接、法定、约定的保证。访问本博客请务必遵守有关互联网的相关法律、规定与规则。一旦您访问本博客,即表示您已经知晓并接受了此声明通告。