- 论坛徽章:
- 0
|
PC1(10.20.36. -------(10.20.36.1)路由器(10.20.29.2)--------(10.20.29.1)ISG1000(61.1.1.2 )-----(61.1.1.1)CISCO路由器
(10.20.40.1)_|
PC2(10.20.40.10)________|
内网的默认路由指向ISG1000,现要求外网能够访问PC1提供的MIP(71.1.1.1)的公网服务
现象一 C2可以上网,转换出去的地址是61.1.1.2
现象二 C1可以上网,转换出去的地址是71.1.1.1,但是外网的地址Ping不通71.1.1.1
现象三:内网的所有机器只能ping通内网的路由器,Ping不通ISG1000
现象四:get log traffic policy 9 可以看到 PC1 Ping外网的时候的日志:
nsisg1000-> get log traffic policy 9
PID 9, from Trust to Untrust, src AAA-Self-Portal, dst Any, service ANY, action Permit
Total traffic entries matched under this policy = 2229
==================================================================================
Date Time Duration Source IP Port Destination IP Port Service
Reason Xlated Src IP Port Xlated Dst IP Port ID
==================================================================================
2002-07-05 07:13:15 0:00:04 10.20.36.8 25581 212.187.171.245 768 ICMP
Close - RESP 41.72.96.162 25581 212.187.171.245 768
2002-07-05 07:13:15 0:00:05 10.20.36.8 25325 212.187.171.245 768 ICMP
Close - RESP 41.72.96.162 25325 212.187.171.245 768
现象四:get log traffic policy 6 可以看到 PC1 Ping外网的时候的日志:
nsisg1000-> get log traffic policy 6
PID 6, from Trust to Untrust, src 10.20.40.0/21, dst Any, service ANY, action Permit
Total traffic entries matched under this policy = 30529
==================================================================================
Date Time Duration Source IP Port Destination IP Port Service
Reason Xlated Src IP Port Xlated Dst IP Port ID
==================================================================================
2002-07-05 07:13:49 0:01:06 10.20.40.120 58937 95.84.162.74 30459 UDP PORT 30459
Close - AGE OUT 61.1.1.2 23944 95.84.162.74 30459
2002-07-05 07:13:49 0:00:20 10.20.40.167 49263 74.53.106.178 80 HTTP
现象五:get log traffic policy 其他策略的时候就没有任何log
请问各位高手,我问题在哪里? |
|