data:image/s3,"s3://crabby-images/be622/be622d5e96719d44b20091622f1ef505b7dd5019" alt="Huawei S Series Скачать руководство пользователя страница 52"
Configuring NAT Server and Multiple Egress Interfaces
Configure the egress router to allow external users to access intranet servers using
public IP addresses.
1
[Router]
interface GigabitEthernet 0/0/0
[Router-GigabitEthernet0/0/0]
nat server protocol tcp global current-
interface www inside 192.168.50.20 www
Warning:The port 80 is well-known port. If you continue it may cause
function failure.
Are you sure to continue?[Y/N]:y
[Router-GigabitEthernet0/0/0]
nat server protocol tcp global current-
interface ftp inside 192.168.50.10 ftp
[Router-GigabitEthernet0/0/0] quit
As services grow, the web server and FTP server on the intranet need to provide
services to both internal and external users who access the servers using public IP
addresses.
Enable NAT ALG for FTP on the egress router.
2
[Router]
nat alg ftp enable
Configure an ACL to allow intranet users to access intranet servers using public IP
addresses.
[Router]
acl 3333
[Router-acl-adv-3333]
rule permit ip source 192.168.10.0 0.0.0.255
destination 202.101.111.2 0.0.0.0
[Router-acl-adv-3333]
rule permit ip source 192.168.20.0 0.0.0.255
destination 202.101.111.2 0.0.0.0
[Router-acl-adv-3333]
quit
Configure a mapping table of internal servers on egress router interfaces connecting
to the intranet.
Configure NAT on egress router interfaces connecting to the intranet.
[Router]
interface GigabitEthernet 0/0/1
[Router-GigabitEthernet0/0/1]
nat outbound 3333
[Router]
interface GigabitEthernet 0/0/2
[Router-GigabitEthernet0/0/2]
nat outbound 3333
[Router-GigabitEthernet0/0/2]
quit
[Router]
interface GigabitEthernet 0/0/1
[Router-GigabitEthernet0/0/1]
nat server protocol tcp global interface
GigabitEthernet 0/0/0 www inside 192.168.50.20 www
[Router-GigabitEthernet0/0/1]
nat server protocol tcp global interface
GigabitEthernet 0/0/0 ftp inside 192.168.50.10 ftp
[Router-GigabitEthernet0/0/1]
quit
3
4
5
49
a. Configure NAT Server.