GNS3里拓扑图
R2ping 200.100.10.100可以ping通,但是内网ESW1上ping 200.100.10.100就ping不通,做了NAT转换和ACL也没有用,是不是ESW1上默认路由配错了?还是没有指定防火墙inside路由的问题?
基本配置如下,
ASA防火墙基本配置 interface GigabitEthernet0 nameif inside security-level 100 ip address 172.16.1.1 255.255.255.0 ! interface GigabitEthernet1 nameif outside security-level 0 ip address 200.100.10.100 255.255.255.0 ! route outside 0.0.0.0 0.0.0.0 200.100.10.1 ! object network outside-pool range 200.100.10.101 200.100.10.105 object network inside-pool subnet 172.16.1.0 255.255.255.0 nat (inside,outside) dynamic outside-pool !
access-list 101 extended permit ip 172.16.1.0 255.255.255.0 any access-list 101 extended permit icmp any any access-group 101 in interface outside
路由器R2基本配置 interface FastEthernet1/0 ip address 200.100.10.1 255.255.255.0 duplex auto speed auto ! ESW1基本配置 interface FastEthernet0/0 ip address 172.16.1.2 255.255.255.0 duplex half ! ip route 0.0.0.0 0.0.0.0 f0/0
|