本帖最后由 yhao81 于 2018-4-15 14:37 编辑
接口配置, lo0加入trust,ge0/0/0加入untrust,不列出命令 set interfaces ge-0/0/0 unit 0 family inetaddress 203.0.113.63/24 set interfaces lo0 unit 0 family inet address 2.2.2.2/32 NAT source接口配置,从JUNIPER官网拷贝 set security nat source rule-set rs1 from zonetrust set security nat source rule-set rs1 to zoneuntrust set security nat source rule-set rs1 rule r1match source-address 0.0.0.0/0 set security nat source rule-set rs1 rule r1match destination-address 0.0.0.0/0 set security nat source rule-set rs1 rule r1then source-nat interface junos2 ping 202.1.103.1 可PING通 ping 202.1.103.1 source 2.2.2.2 带源ping不通!为什么? Show security flow session 显示没有转换成功!为什么? Session ID: 136, Policy name:self-traffic-policy/1, Timeout: 50, Valid In: 2.2.2.2/1--> 203.0.113.1/16905;icmp, If: .local..0, Pkts: 1, Bytes: 84 Out: 203.0.113.1/16905 --> 2.2.2.2/1;icmp,If: ge-0/0/0.0, Pkts: 0, Bytes: 0
|