華爲USG防火牆NAT

拓撲:服務器

wKioL1TDGabSTYIzAAETLffhCNI579.jpg

基本配參照華爲防火牆USG基本配置(http://692344.blog.51cto.com/682344/1607629app

下面只給出客戶端和服務器端配置:tcp

wKiom1TDGVjRExsXAAFgoGJIYo8904.jpg

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

wKioL1TDGmHgqv53AAFmUj2gK50657.jpg

wKiom1TDGd_TC2LMAAF6Xe8f2pE273.jpg

wKioL1TDGrmwuU_OAAIP31UVTnA376.jpg

wKiom1TDGeDRgNZEAAEWawOOwU8427.jpg

防火牆配置:ide

  策略配置:測試

wKiom1TDGyLRjTs3AADTP5ZPNrw656.jpg

 

監控FTP配置(FTP是動態協議):blog

wKioL1TDHC_D3NulAAAyjAONtZA934.jpg

測試:ip

wKiom1TDG6Oi0FcuAAINyLZOwTc023.jpg

wKioL1TDHH3Aa6jtAAFI5CMxDTo564.jpg

 

 ----------------------------------get

若是FTP使用特殊端口要配置以下:it

acl number 2001
 rule 5 permit source 192.168.1.100 0io

port-mapping ftp port 2121 acl 2001

ip service-set newftp type object
 service 0 protocol tcp description 2121

firewall interzone dmz untrust detect ftppolicy interzone dmz untrust inbound policy 0  action permit  policy service service-set http  policy service service-set newftp  policy destination 192.168.1.100 0

相關文章
相關標籤/搜索