您的位置:首页 > 娱乐 > 八卦 > 企迪网_建一个外贸网站多少钱_软文模板app_湖南网络推广公司大全

企迪网_建一个外贸网站多少钱_软文模板app_湖南网络推广公司大全

2025/2/25 23:50:30 来源:https://blog.csdn.net/2302_76907945/article/details/145715575  浏览:    关键词:企迪网_建一个外贸网站多少钱_软文模板app_湖南网络推广公司大全
企迪网_建一个外贸网站多少钱_软文模板app_湖南网络推广公司大全

1,配置IP

[R1-GigabitEthernet0/0/2]ip add 210.1.1.254 24
[R1-GigabitEthernet0/0/1]ip add 200.1.1.254 24
[R1-GigabitEthernet0/0/0]ip add 12.0.0.254 24
[R2-GigabitEthernet0/0/1]ip add 100.1.1.254 24
[R2-GigabitEthernet0/0/2]ip add 110.1.1.254 24
[R2-GigabitEthernet0/0/0]ip add 13.0.0.254 24
[FW-GigabitEthernet1/0/1]ip add 13.0.0.1 24
[FW-GigabitEthernet1/0/2]ip add 12.0.0.1 24
[FW-GigabitEthernet1/0/0]ip add 192.168.1.254 24

Client1:

Client2:

电信DNS:

百度web1:

百度web2:

联通DNS:

2,配置安全策略

[FW]firewall zone name untrust1
[FW-zone-untrust1]add interface g1/0/1 
[FW]firewall zone trust 
[FW-zone-trust]add interface GigabitEthernet 1/0/0
[FW]firewall zone untrust1
[FW-zone-untrust1]set priority 10
[FW]firewall zone name untrust2
[FW-zone-untrust2]set priority 15
[FW-zone-untrust2]add interface g1/0/2
[FW]security-policy 
[FW-policy-security]rule name dns
[FW-policy-security-rule-dns]source-zone trust 
[FW-policy-security-rule-dns]destination-zone untrust1 untrust2
[FW-policy-security-rule-dns]source-address 192.168.1.0 mask 255.255.255.0
[FW-policy-security-rule-dns]action permit
[FW-policy-security]rule name web
[FW-policy-security-rule-web]source-zone trust
[FW-policy-security-rule-web]destination-zone untrust1 untrust2
[FW-policy-security-rule-web]source-address 192.168.1.0 mask 255.255.255.0
[FW-policy-security-rule-dns]action permit
[FW]nat address-group nat_1
[FW-address-group-nat_1]section 11.0.0.10 11.0.0.10
[FW-address-group-nat_1]mode pat
[FW-address-group-nat_1]route enable 
[FW]nat address-group nat_2
[FW-address-group-nat_2]section 12.0.0.10 12.0.0.10
[FW-address-group-nat_2]mode pat
[FW-address-group-nat_2]route enable
[FW]nat-policy
[FW-policy-nat]rule	
[FW-policy-nat]rule name policy_1
[FW-policy-nat-rule-policy_1]source-zone trust
[FW-policy-nat-rule-policy_1]d
[FW-policy-nat-rule-policy_1]destination-zone untrust1
[FW-policy-nat-rule-policy_1]source-address 192.168.1.0 24
[FW-policy-nat-rule-policy_1]action source-nat address-group nat_1
[FW-policy-nat]rule name policy_2
[FW-policy-nat-rule-policy_2]source-zone trust
[FW-policy-nat-rule-policy_2]de	
[FW-policy-nat-rule-policy_2]destination-zone untrust2
[FW-policy-nat-rule-policy_2]source-address 192.168.1.0 24
[FW-policy-nat-rule-policy_2]action source-nat address-group nat_2

3,配置链路接口

4,配置DNS服务器

   (1)真实DNS服务

[FW]slb enable 
[FW]slb
[FW-slb]group 0 dns
[FW-slb-group-0]rserver 0 rip 200.1.1.1 port 53

  (2)虚拟DNS服务

[FW]slb
[FW-slb]vserver 0 dns
[FW-slb-vserver-0]vip 11.11.11.11
[FW-slb-vserver-0]group dns

   (3)配置DNS透明代理

[FW]dns-transparent-policy
[FW-policy-dns]dns transparent-proxy enable 

策略路由

版权声明:

本网仅为发布的内容提供存储空间,不对发表、转载的内容提供任何形式的保证。凡本网注明“来源:XXX网络”的作品,均转载自其它媒体,著作权归作者所有,商业转载请联系作者获得授权,非商业转载请注明出处。

我们尊重并感谢每一位作者,均已注明文章来源和作者。如因作品内容、版权或其它问题,请及时与我们联系,联系邮箱:809451989@qq.com,投稿邮箱:809451989@qq.com