The sixth of the top ten tasks of firewall configuration is the three-interface configuration of NAT
Task 6 for configuring firewalls
Three-interface configuration with NAT
Task topology figure 6.1
1. Basic port settings
Figure 6.2
two。 Set the Syslog information to be valid, which will provide diagnostic information and status to the firewall and send it to the buffer (figure 6.3)
3. Authorized internal hosts can use Telnet to access the firewall console. The maximum amount of time a session can be idle is 15 minutes. (figure 6.3)
Figure 6.3
4. Establish a global address pool for external and DMZ interfaces. Because there are only 10 external global IP addresses, add a global amount of PAT to handle the overflow. The global (dmz) command allows internal users to access the web server on the DMZ interface
5. Allows internal users to initiate connections on DMZ interfaces and external interfaces, and allows DMZ users to initiate connections on external interfaces
6. Allow any user on the external interface to access the Web server on the DMZ interface
7. Set the external default route connected to the access Internet router
Figure 6.7