设为首页收藏本站language 语言切换
查看: 2299|回复: 0
收起左侧

juniper SRX650

[复制链接]
发表于 2015-4-29 17:29:56 | 显示全部楼层 |阅读模式
小弟初次接觸SRX650,想請問NAT的設置
set security nat proxy-arp interface ge-0/0/0.0 address 1.1.1.100---將接口ge-0/0/0.0(接口ip1.1.1.100) 設為arp代理
set security nat destination pool dnat-pool-1 address 10.1.1.100/32----create一個名稱為dnat-pool-1的pool,pool內只有一個ip10.1.1.100/32
set security nat destination rule-set dst-nat from zone untrust-----這行不太懂??
set security nat destination rule-set dst-nat rule rule1 match destination-address 1.1.1.100/32 設置條件rule1,match des為1.1.1.100
set security nat destination rule-set dst-nat rule rule1 match destination-port 80 設置條件rule1,match des為1.1.1.100並使用80port
set security nat destination rule-set dst-nat rule rule1 then destination-nat pool dnat-pool-1----符合上述兩條件則將源為any des為1.1.1.100 nat為10.1.1.100
set security zones security-zone trust address-book address webserver 10.1.1.100---不懂?
set security zones security-zone trust address-book address-set servergroup address webserver ---不懂?
set security policies from-zone untrust to-zone trust policy static-nat match source-address any destination-address servergroup application junos-http---不懂?
set security policies from-zone untrust to-zone trust policy static-nat then permit---不懂?

想請大家幫我看一下,我解釋的內容是否正確,以及我不懂的地方能否幫解答
感謝!!!

您需要登录后才可以回帖 登录 | 论坛注册

本版积分规则

QQ|Archiver|手机版|小黑屋|sitemap|鸿鹄论坛 ( 京ICP备14027439号 )  

GMT+8, 2025-4-24 22:53 , Processed in 0.495355 second(s), 22 queries , Redis On.  

  Powered by Discuz!

  © 2001-2025 HH010.COM

快速回复 返回顶部 返回列表