Appendix B: Network IP Topology
Non-NAT DMZ Configuration
Inter-Tel
®
5000 Installation Manual – Issue 2.4, May 2008
Page B-25
Non-NAT DMZ Configuration
The following illustrates a nonNAT DMZ configuration.
Single Node with ITP Endpoints
In this example you use the following commands set up the connection to the internal LAN. In
these commands, NAT is enabled and it uses
access-group e0in
for traffic coming in (to
the router) from the internal LAN.
interface Ethernet0/0
description Internal LAN
ip address 192.168.100.1 255.255.255.0
ip access-group e0in in
ip nat inside
ip inspect inspector in
!
•
The following section defines the access control list (the rules) for traffic coming from the
internal LAN into the router. As a general rule, this example allows just about anything to
go out from the trusted LAN.
! Access Control List e0in
!
ip access-list extended e0in
permit ip 192.168.100.0 0.0.0.255 any
deny ip any any
Internet
Internal Endpoint
Dynamic Private IP
`
Admin PC
Dynamic Private IP
External Endpoint
Dynamic Public IP
Inter-Tel CS-5x00
208.132.23.66
UC/SIP Server
208.132.23.67
Enterprise Conferencing
208.132.23.68
E0/0
192.168.100.1/24
E1/0
208.132.23.64/26
S0/0
208.13.17.33/30
Internal LAN
Non-NAT DMZ
Содержание Inter-Tel 5000
Страница 1: ...Inter Tel 5000 M I T E L Installation and Maintenance Manual ...
Страница 2: ......
Страница 3: ...Issue 2 4 May 2008 Inter Tel 5000 Installation and Maintenance Manual Part Number 580 8000 ...
Страница 4: ......
Страница 6: ......
Страница 20: ......
Страница 62: ......
Страница 366: ......
Страница 432: ......
Страница 467: ......
Страница 468: ...Part No 580 8000 Issue 2 4 May 2008 A691 9111A ...