|
现在公司内部有一台WEB服务器,端口号是8002;出口路由器是AR2200路由器,我配置了NAT server实现外网访问内部WEB服务器,配置如下:
sysname RZJY-Router
#
snmp-agent local-engineid 800007DB031047802A2761
snmp-agent
#
drop illegal-mac alarm
#
dns resolve
dns proxy enable
#
dhcp enable
#
acl number 2001
rule 5 permit source 172.16.1.0 0.0.0.255
rule 10 permit source 172.16.2.0 0.0.0.255
#
ip pool vlan1
gateway-list 172.16.1.1
network 172.16.1.0 mask 255.255.255.0
excluded-ip-address 172.16.1.2 172.16.1.10
dns-list 211.138.24.66 211.138.30.66
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user root password cipher %$%$:4~jNlEzfB8_n4/Nc<w=uh_V%$%$
local-user root privilege level 15
local-user root service-type http
local-user rzjy password cipher %$%$gquH34UBv2:U+,.sri#OQ#wn%$%$
local-user rzjy privilege level 15
local-user rzjy service-type telnet
local-user admin password cipher %$%$I6.ASV)hJET,p"Dn.YM%3aXO%$%$
local-user admin service-type http
#
firewall zone webtrust
priority 10
#
firewall zone webuntrust
priority 5
#
firewall interzone webtrust webuntrust
#
nat alg dns enable
#
interface GigabitEthernet0/0/0
ip address 172.16.2.254 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 172.16.1.1 255.255.255.0
dhcp select global
#
interface GigabitEthernet0/0/2
ip address 117.158.116.232 255.255.255.224
nat server protocol tcp global current-interface www inside 172.16.2.208 8002
nat outbound 2001
#
interface NULL0
#
ip route-static 0.0.0.0 0.0.0.0 117.158.116.225
#
user-interface con 0
authentication-mode password
set authentication password cipher %$%$VDT"W"n%CDpEQJN4}GcF,8/&.CP<V,#]M*:<m(LS%MP#.>50%$%$
user-interface vty 0 4
authentication-mode aaa
user-interface vty 16 20
#
voice
#
diagnose
#
return
我的外网接口是
interface GigabitEthernet0/0/2
ip address 117.158.116.232 255.255.255.224
只有一个IP地址,是否配置有问题,现在通过外网访问不到我公司内部服务器!请大神指点一下,谢谢了,着急等待中
|
|