温馨提示×

温馨提示×

您好,登录后才能下订单哦!

密码登录×
登录注册×
其他方式登录
点击 登录注册 即表示同意《亿速云用户服务条款》

juniper SRX 地址映射

发布时间:2020-08-03 01:04:00 阅读:733 作者:z89177519 栏目:安全技术
开发者测试专用服务器限时活动,0元免费领,库存有限,领完即止! 点击查看>>

需求说明:公网122.93.43.X:16927 映射 内网 10.100.124.200:80

定义内网地址
set security nat destination pool srv200-80 address 10.100.124.200/32
定义内网端口号
set security nat destination pool srv200-80 address port 80
定义公网地址+端口
edit security nat destination
set rule-set untrust-trust-set rule un122-srv200-443 match source-address 0.0.0.0/0
set rule-set untrust-trust-set rule un122-srv200-443 match destination-address 122.93.43.X/32
set rule-set untrust-trust-set rule un122-srv200-443 match destination-port 16927 ##公网端口
set rule-set untrust-trust-set rule un122-srv200-443 match protocol tcp
set rule-set untrust-trust-set rule un122-srv200-443 then destination-nat pool srv200-80

定义内网协议+端口

set applications application tcp-80 protocol tcp
set applications application tcp-80 destination-port 80

定义内网地址

set security zones security-zone trust address-book address srv200 10.100.124.200

定义策略
edit security policies from-zone untrust to-zone trust
set policy utot-srv11-3389 match source-address any
set policy utot-srv11-3389 match destination-address srv200
set policy utot-srv11-3389 match application tcp-80 ###### 定义内网真实端口####
set policy utot-srv11-3389 match application junios-http
set policy utot-srv11-3389 then permit

亿速云「云服务器」,即开即用、新一代英特尔至强铂金CPU、三副本存储NVMe SSD云盘,价格低至29元/月。点击查看>>

向AI问一下细节

免责声明:本站发布的内容(图片、视频和文字)以原创、转载和分享为主,文章观点不代表本网站立场,如果涉及侵权请联系站长邮箱:is@yisu.com进行举报,并提供相关证据,一经查实,将立刻删除涉嫌侵权内容。

AI

开发者交流群×