91超碰碰碰碰久久久久久综合_超碰av人澡人澡人澡人澡人掠_国产黄大片在线观看画质优化_txt小说免费全本

溫馨提示×

溫馨提示×

您好,登錄后才能下訂單哦!

密碼登錄×
登錄注冊×
其他方式登錄
點擊 登錄注冊 即表示同意《億速云用戶服務條款》

juniper srx 240 cluster 內網服務器端口發布到外網配置實例

發布時間:2020-07-25 14:09:37 來源:網絡 閱讀:704 作者:ITint 欄目:安全技術

========================================================================================================================
-----------------------------------------內網地址端口發布到外網步驟-----------------------------------------------------
set security address-book global address IMMQI_PRIVATE 172.22.201.20/32

步驟一:創建 NAT pool
set security nat destination pool DP_TRUST_IMMQI_10089 address 172.22.201.20/32
set security nat destination pool DP_TRUST_IMMQI_10089 address port 10089

步驟二:創建 NAT Rule
set security nat destination rule-set DNAT_FROM_ISP1 rule ISP1_TCP10089_TO_IMMQI_10089 match destination-address-name WAN3001_241 -----119.145.16.241
set security nat destination rule-set DNAT_FROM_ISP1 rule ISP1_TCP10089_TO_IMMQI_10089 match destination-port 10089
set security nat destination rule-set DNAT_FROM_ISP1 rule ISP1_TCP10089_TO_IMMQI_10089 then destination-nat pool DP_TRUST_IMMQI_10089

步驟三:創建放行端口及協議類型
set applications application tcp-10089 protocol tcp
set applications application tcp-10089 destination-port 10089
set applications application tcp-10090 protocol tcp
set applications application tcp-10090 destination-port 10090

步驟四:創建區域策略,并具體匹配源地址和目標地址端口
set security policies from-zone ISP1 to-zone trust policy P_IMMQI_80_9998 match source-address any
set security policies from-zone ISP1 to-zone trust policy P_IMMQI_80_9998 match destination-address IMMQI_PRIVATE
set security policies from-zone ISP1 to-zone trust policy P_IMMQI_80_9998 match application tcp-80
set security policies from-zone ISP1 to-zone trust policy P_IMMQI_80_9998 match application tcp-9998
set security policies from-zone ISP1 to-zone trust policy P_IMMQI_80_9998 match application tcp-10089
set security policies from-zone ISP1 to-zone trust policy P_IMMQI_80_9998 then permit
set security policies from-zone ISP1 to-zone trust policy P_IMMQI_80_9998 then log session-init
set security policies from-zone ISP1 to-zone trust policy P_IMMQI_80_9998 then log session-close

步驟五:如果新建協議,則需要調整策略優先級
insert security policies from-zone Design to-zone trust policy RM-201_84-Cost-Lectra before policy DENY ----新增加策略需要檢查是否需要修改策略優先級


set security address-book global address QI_PRIVATE 172.22.201.19/32

正式環境

set security nat destination pool DP_TRUST_IQCSAP_10090 address 172.22.201.19/32
set security nat destination pool DP_TRUST_IQCSAP_10090 address port 10089

ISP1電信線路

set security nat destination rule-set DNAT_FROM_ISP1 rule ISP1_TO_TRUST_IQCSAP_10090 match destination-address-name WAN3001_241
set security nat destination rule-set DNAT_FROM_ISP1 rule ISP1_TO_TRUST_IQCSAP_10090 match destination-port 10090
set security nat destination rule-set DNAT_FROM_ISP1 rule ISP1_TO_TRUST_IQCSAP_10090 then destination-nat pool DP_TRUST_IQCSAP_10090

set security policies from-zone ISP1 to-zone trust policy P_IQCSAP_10090 match source-address any
set security policies from-zone ISP1 to-zone trust policy P_IQCSAP_10090 match destination-address QI_PRIVATE
set security policies from-zone ISP1 to-zone trust policy P_IQCSAP_10090 match application tcp-10089
set security policies from-zone ISP1 to-zone trust policy P_IQCSAP_10090 then permit
set security policies from-zone ISP1 to-zone trust policy P_IQCSAP_10090 then log session-init
set security policies from-zone ISP1 to-zone trust policy P_IQCSAP_10090 then log session-close
set security policies from-zone ISP1 to-zone trust policy P_IQCSAP_10090 then count

ISP6 聯通線路

set security nat destination rule-set DNAT_FROM_ISP6 rule ISP6_TO_TRUST_IQCSAP_10090 match destination-address-name WAN3006_165
set security nat destination rule-set DNAT_FROM_ISP6 rule ISP6_TO_TRUST_IQCSAP_10090 match destination-port 10090
set security nat destination rule-set DNAT_FROM_ISP6 rule ISP6_TO_TRUST_IQCSAP_10090 then destination-nat pool DP_TRUST_IQCSAP_10090

set security policies from-zone ISP6 to-zone trust policy P_IQCSAP_10090 match source-address any
set security policies from-zone ISP6 to-zone trust policy P_IQCSAP_10090 match destination-address QI_PRIVATE
set security policies from-zone ISP6 to-zone trust policy P_IQCSAP_10090 match application tcp-10089
set security policies from-zone ISP6 to-zone trust policy P_IQCSAP_10090 then permit
set security policies from-zone ISP6 to-zone trust policy P_IQCSAP_10090 then log session-init
set security policies from-zone ISP6 to-zone trust policy P_IQCSAP_10090 then log session-close
set security policies from-zone ISP6 to-zone trust policy P_IQCSAP_10090 then count

insert security policies from-zone ISP6 to-zone trust policy P_IQCSAP_10090 before policy DENY


驗證

{primary:node0}
owenli@cfw01a.cn1> show security flow session nat destination-port 10090
node0:

Session ID: 124271, Policy name: P_IQCSAP_10090/276, State: Backup, Timeout: 14396, Valid
In: 113.X.X.199/57104 --> X.X.X.165/10090;tcp, If: reth25.3006, Pkts: 0, Bytes: 0
Out: 172.22.201.19/10089 --> 113.X.X.199/57104;tcp, If: reth4.500, Pkts: 0, Bytes: 0
Total sessions: 1

node1:

Session ID: 140801, Policy name: P_IQCSAP_10090/276, State: Active, Timeout: 1796, Valid
In: 113.X.X.199/57104 --> X.X.X.165/10090;tcp, If: reth25.3006, Pkts: 2, Bytes: 92
Out: 172.22.201.19/10089 --> 113.X.X.199/57104;tcp, If: reth4.500, Pkts: 1, Bytes: 52
Total sessions: 1

向AI問一下細節

免責聲明:本站發布的內容(圖片、視頻和文字)以原創、轉載和分享為主,文章觀點不代表本網站立場,如果涉及侵權請聯系站長郵箱:is@yisu.com進行舉報,并提供相關證據,一經查實,將立刻刪除涉嫌侵權內容。

AI

达日县| 石阡县| 天峻县| 长垣县| 晋宁县| 纳雍县| 苍梧县| 宜昌市| 凤阳县| 吉木乃县| 腾冲县| 红安县| 宁晋县| 台北市| 启东市| 攀枝花市| 东丰县| 柳州市| 札达县| 文水县| 广汉市| 师宗县| 北辰区| 镇赉县| 离岛区| 出国| 嘉黎县| 城步| 开远市| 苍溪县| 禹城市| 金坛市| 长岭县| 门头沟区| 视频| 广宁县| 阜城县| 二连浩特市| 丰县| 江安县| 读书|