Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Qiming Xingtian Qing Han Ma USG Firewall NAT backflow setting

Shulou Source: shulou.com Published: 2022-06-01 05:44:55 10月04日 Update

Configuration ideas:

In Topology 4, the WWW server is set up in the internal network, and internal and external users must access its external address 202.112.238.10 to access the server. In this case, the configuration of the external user remains the same, that is, when the external interface configures DNAT so that the external user accesses the external address of 202.112.238.10, it is translated to 192.168.100.10, while configuring the security policy that allows external users to access the internal network WWW server. The configuration of internal user access to 202.112.238.10 is slightly more complicated. First, configure DNAT on the inside interface so that when the internal user accesses the external address of 202.112.238.10, convert it to 192.168.100.10, and then configure a source NAT on the inside interface to translate the source address that matches 192.168.100.100 access to 192.168.100.10 to the inside interface address. Finally, configure a security policy from the inside interface to the inside interface to allow 192.168.100.100 access to 192.168.100.10.

The detailed configuration is as follows:

1. Destination address Translation any 202.112.238.10 Internal Network Interface http 192.168.100.10

2. Source address translation any 192.168.100.10 http private network interface IP

3. Security policy any 192.168.100.10 Internal network port allows internal network port

Tags: Configuration address interface user network port security server policy service complexity intranet at the same time ideas topology purpose network Qixing firewall Tianqing Qiming Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno MariaDB NVidia Linux Huawei Shulou Technology