- 论坛徽章:
- 0
|
IP 信息
outside : XXX.XXX.XXX.162 255.255.255.240 网关: xxx.xxx.xxx.161
inside: 192.168.0.1 255.255.255.0
要求将: xxx.xxx.xxx.163 静态NAT到LAN内的 192.168.0.2 上.
PC 192.168.0.2 所有都配置正确:
IP 192.168.0.2 255.255.255.0
网关 192.168.0.1
ping ASA的 inside 192.168.0.1 通信正常
192.168.0.2 其它PC可以ping通, 且www服务正常,LAN的其它PC可正常访问
故障情况是:
1. xxx.xxx.xxx.163 IP不能ping通
2. 访问xxx.xxx.xxx.163 www 服务不能静态映射到 192.168.0.2 www 上,造成www不可访问
以下是配置步骤
conf t
int e0/0
nameif outside
security-level 0
ip add xxx.xxx.xxx.162 255.255.255.240
no shutdown
int e0/1
nameif inside
security-level 100
ip add 192.168.0.1 255.255.255.0
no shutdown
route outside 0.0.0.0 0.0.0.0 xxx.xxx.xxx.161 # 配置默认路由
static (inside,outside) xxx.xxx.xxx.163 192.168.0.2 netmask 55.255.255.255 #配置静态NAT
access-list 101 permint icmp any any
access-list 101 extended permint tcp any host xxx.xxx.xxx.163 eq www #允许所有访问 xxx.xxx.xxx.163 的www
access-group 101 in interface outside #下发允许访问163的ACL
哪们兄弟,帮我看一下,哪里配置错了. |
|