Vyatta ÀÅŪNAT¤ÎÀßÄê
http://extstrg.asabiya.net/pukiwiki/index.php?Vyatta%20%C0%C5%C5%AANAT%A4%CE%C0%DF%C4%EAÌܼ¡
³µÍ× †
ÀÅŪNAT¤ÎÀßÄê»öÎã¡£
10.10.10.1 <-> 192.168.100.100¤Ø¤ÎÀÅŪNAT¤ò¹Ô¤¦¡£
¥Û¥¹¥È¤Î¼Â¥¢¥É¥ì¥¹¤Ï10.10.10.1¤Ç¤¢¤ê¡¢¥ë¡¼¥¿±Û¤·¤ÎÂй³¤Ë¤Ï¥ë¡¼¥¿¤¬»ý¤ÄVIP 192.168.100.100¤ÈÀÅŪNAT¤ò¤¹¤ë¹½À®¤È¤Ê¤ë¡£
ÀßÄê †
- eth1¤ËÀÅŪNATÍѤΥ¢¥É¥ì¥¹¡ÊVIP¡Ë¤òÀßÄê
configure set interfaces ethernet eth1 address 192.168.100.100/24
- eth0¦¤ÎDestination NAT¡Ê10.10.10.1 ¢ª 192.168.100.100¡Ë
set service nat rule 10 edit service nat rule 10 set inbound-interface eth0 set destination address 10.10.10.1/32 set inside-address address 192.168.100.100/32 set type destination commit exit
- eth0¦¤ÎSource NAT¡Ê192.168.100.100 ¢ª 10.10.10.1¡Ë
set service nat rule 20 edit service nat rule 20 set outbound-interface eth0 set source address 192.168.100.100/32 set outside-address address 10.10.10.1/32 set type source commit exit
- eth1¦¤ÎDestination NAT¡Ê10.10.10.1 ¢ª 192.168.100.100¡Ë
set service nat rule 11 edit service nat rule 11 set outbound-interface eth1 set source address 10.10.10.1/32 set outside-address address 192.168.100.100/32 set type source commit exit
- eth1¦¤ÎSource NAT¡Ê192.168.100.100 ¢ª 10.10.10.1¡Ë
set service nat rule 21 edit service nat rule 21 set inbound-interface eth1 set destination address 192.168.100.100/32 set inside-address address 10.10.10.1/32 set type destination commit exit
- ÀßÄê¤òÊݸ
save
Last-modified: 2012-07-13 (¶â) 19:15:20 (4569d)