本文共 5235 字,大约阅读时间需要 17 分钟。
========================================================================================================================
-----------------------------------------内网地址端口发布到外网步骤-----------------------------------------------------set security address-book global address IMMQI_PRIVATE 172.22.201.20/32步骤一:创建 NAT pool
set security nat destination pool DP_TRUST_IMMQI_10089 address 172.22.201.20/32set security nat destination pool DP_TRUST_IMMQI_10089 address port 10089步骤二:创建 NAT Rule
set security nat destination rule-set DNAT_FROM_ISP1 rule ISP1_TCP10089_TO_IMMQI_10089 match destination-address-name WAN3001_241 -----119.145.16.241set security nat destination rule-set DNAT_FROM_ISP1 rule ISP1_TCP10089_TO_IMMQI_10089 match destination-port 10089set security nat destination rule-set DNAT_FROM_ISP1 rule ISP1_TCP10089_TO_IMMQI_10089 then destination-nat pool DP_TRUST_IMMQI_10089步骤三:创建放行端口及协议类型
set applications application tcp-10089 protocol tcpset applications application tcp-10089 destination-port 10089set applications application tcp-10090 protocol tcpset applications application tcp-10090 destination-port 10090步骤四:创建区域策略,并具体匹配源地址和目标地址端口
set security policies from-zone ISP1 to-zone trust policy P_IMMQI_80_9998 match source-address anyset security policies from-zone ISP1 to-zone trust policy P_IMMQI_80_9998 match destination-address IMMQI_PRIVATEset security policies from-zone ISP1 to-zone trust policy P_IMMQI_80_9998 match application tcp-80set security policies from-zone ISP1 to-zone trust policy P_IMMQI_80_9998 match application tcp-9998set security policies from-zone ISP1 to-zone trust policy P_IMMQI_80_9998 match application tcp-10089set security policies from-zone ISP1 to-zone trust policy P_IMMQI_80_9998 then permitset security policies from-zone ISP1 to-zone trust policy P_IMMQI_80_9998 then log session-initset security policies from-zone ISP1 to-zone trust policy P_IMMQI_80_9998 then log session-close步骤五:如果新建协议,则需要调整策略优先级
insert security policies from-zone Design to-zone trust policy RM-201_84-Cost-Lectra before policy DENY ----新增加策略需要检查是否需要修改策略优先级set security address-book global address QI_PRIVATE 172.22.201.19/32
正式环境
set security nat destination pool DP_TRUST_IQCSAP_10090 address 172.22.201.19/32
set security nat destination pool DP_TRUST_IQCSAP_10090 address port 10089ISP1电信线路
set security nat destination rule-set DNAT_FROM_ISP1 rule ISP1_TO_TRUST_IQCSAP_10090 match destination-address-name WAN3001_241
set security nat destination rule-set DNAT_FROM_ISP1 rule ISP1_TO_TRUST_IQCSAP_10090 match destination-port 10090set security nat destination rule-set DNAT_FROM_ISP1 rule ISP1_TO_TRUST_IQCSAP_10090 then destination-nat pool DP_TRUST_IQCSAP_10090set security policies from-zone ISP1 to-zone trust policy P_IQCSAP_10090 match source-address any
set security policies from-zone ISP1 to-zone trust policy P_IQCSAP_10090 match destination-address QI_PRIVATE set security policies from-zone ISP1 to-zone trust policy P_IQCSAP_10090 match application tcp-10089set security policies from-zone ISP1 to-zone trust policy P_IQCSAP_10090 then permitset security policies from-zone ISP1 to-zone trust policy P_IQCSAP_10090 then log session-initset security policies from-zone ISP1 to-zone trust policy P_IQCSAP_10090 then log session-closeset security policies from-zone ISP1 to-zone trust policy P_IQCSAP_10090 then countISP6 联通线路
set security nat destination rule-set DNAT_FROM_ISP6 rule ISP6_TO_TRUST_IQCSAP_10090 match destination-address-name WAN3006_165
set security nat destination rule-set DNAT_FROM_ISP6 rule ISP6_TO_TRUST_IQCSAP_10090 match destination-port 10090set security nat destination rule-set DNAT_FROM_ISP6 rule ISP6_TO_TRUST_IQCSAP_10090 then destination-nat pool DP_TRUST_IQCSAP_10090set security policies from-zone ISP6 to-zone trust policy P_IQCSAP_10090 match source-address any
set security policies from-zone ISP6 to-zone trust policy P_IQCSAP_10090 match destination-address QI_PRIVATEset security policies from-zone ISP6 to-zone trust policy P_IQCSAP_10090 match application tcp-10089set security policies from-zone ISP6 to-zone trust policy P_IQCSAP_10090 then permitset security policies from-zone ISP6 to-zone trust policy P_IQCSAP_10090 then log session-initset security policies from-zone ISP6 to-zone trust policy P_IQCSAP_10090 then log session-closeset security policies from-zone ISP6 to-zone trust policy P_IQCSAP_10090 then countinsert security policies from-zone ISP6 to-zone trust policy P_IQCSAP_10090 before policy DENY
验证
Session ID: 124271, Policy name: P_IQCSAP_10090/276, State: Backup, Timeout: 14396, Valid
In: 113.X.X.199/57104 --> X.X.X.165/10090;tcp, If: reth15.3006, Pkts: 0, Bytes: 0Out: 172.22.201.19/10089 --> 113.X.X.199/57104;tcp, If: reth3.500, Pkts: 0, Bytes: 0Total sessions: 1Session ID: 140801, Policy name: P_IQCSAP_10090/276, State: Active, Timeout: 1796, Valid
In: 113.X.X.199/57104 --> X.X.X.165/10090;tcp, If: reth15.3006, Pkts: 2, Bytes: 92Out: 172.22.201.19/10089 --> 113.X.X.199/57104;tcp, If: reth3.500, Pkts: 1, Bytes: 52Total sessions: 1转载于:https://blog.51cto.com/13637805/2334618