Easy IP is configured.
----End
5.3.5 Configuring an Internal Server
Deploying a server on the private network improves security of the server and prevents attacks
from the public network. Users on the private and public networks can access the server.
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
interface
interface-type
interface-number
The interface view is displayed.
Step 3
Run:
l
nat server
protocol
{
tcp
|
udp
}
global
{
global-address
|
current-interface
}
global-
port
inside
host-address
[
host-port
] [
vpn-instance
vpn-instance-name
] [
acl
acl-
number
] [
description
description
]
l
nat server
protocol
{
tcp
|
udp
}
global
interface
loopback
interface-number
global-
port
[
vpn-instance
vpn-instance-name
]
inside
host-address
[
host-port
] [
vpn-instance
vpn-instance-name
] [
acl
acl-number
] [
description
description
]
l
nat server
[
protocol
{
protocol-number
|
icmp
|
tcp
|
udp
} ]
global
global-address
inside
host-address
[
vpn-instance
vpn-instance-name
] [
acl
acl-number
] [
description
description
]
An internal server is configured.
Users on the public network can access the configured internal server. When a host on the public
network sends a connection request to the public address (
global-address
) of the internal server,
NAT translates the destination address of the request to a private address (
host-address
). The
AR150/200 then forwards the request the server.
NOTE
When configuring an internal server, ensure that
global-address
and
host-address
are different from
interface IP addresses and IP addresses in the user address pool.
----End
5.3.6 Configuring Static NAT
Static NAT maps a private address to a public address. Static NAT does not save public addresses
but shields the private network topology.
Procedure
Step 1
Run:
system-view
Huawei AR150&200 Series Enterprise Routers
Configuration Guide - IP Service
5 NAT Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
112