求:CISCO 5520 简要配置(急)

来源:百度知道 编辑:UC知道 时间:2024/05/18 15:21:42
本人手中有一台CISCO5520的防火墙,我就想把它当一台路由器NAT来用,可是却不会怎么设置?

内网:192.168.1.0/24和172.20.20.0/24

外网XX.XX.XX.XX

求简要配置方法,最好有注解!

interface FastEthernet0/0
nameif outside
ip address xx.xx.xx.xx 255.255.255.xx 配置外网
interface FastEthernet0/1
nameif inside
ip address 192.168.1.0 255.255.255.0 配置内外
interface FastEthernet0/2
nameif inside
ip address 172.20.20.0 255.255.255.0 配置内外
exi
access-list 110 extended permit ip any any
access-list 110 extended permit icmp any any 配置访问策略
nat (inside) 1 0.0.0.0 0.0.0.0
global (outside) 1 interface 配置NAT
access-group 110 in interface inside 应用策略
route outside 0.0.0.0 0.0.0.0 xx.xx.xx.xx 配置路由

你改完外网地址往里面贴就好了。有什么问题给我留个言

global (outside) 1 interface
nat (inside) 1 access-list nat
access-list nat extended permit ip 192.168.1.0 255.255.255.0 any
access-list nat extended permit ip 172.20.20.0 255.255.255.0 any

outside 定义到外接口
inside 定义到内接口

enable
int gi 0/1(根据端口号)
nameif inside
ip address 192.168.1.1 255.2