- 1、本文档共6页,可阅读全部内容。
- 2、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。
- 3、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 4、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
查看更多
juniper防火墙 安装手册 2(Juniper Firewall installation manual 2)
juniper防火墙 安装手册 2(Juniper Firewall installation manual 2)
3, Juniper firewall several commonly used function configuration
Here the Juniper firewall about several commonly used functions mainly refers to the implementation of the strategy based on NAT, including: MIP, VIP and DIP, the main application of the three kinds of commonly used functions on the firewall protection server provides the external service.
3.1, MIP configuration
MIP is a one to one two-way address translation (translation) process. Typically, when you have a number of public IP addresses, and there are a number of foreign network service server (server using private IP address), in order to achieve Internet users access these servers, can be established between the public IP address and IP address of the server private one-to-one mapping to exit Internet firewall (MIP), and through the strategy to realize the access control service provided by the server.
Network topology diagram of MIP application:
Note: MIP is configured on the outer network port of the firewall (port of the Internet connection).
3.1.1 and configure MIP using the Web browser
Log into the firewall and deploy the firewall as a three tier mode (NAT or routing mode);
Define MIP:Network=Interface=ethernet2=MIP, configure and realize the address mapping of MIP. Mapped IP: public network IP address, Host IP: intranet server IP address
Defining policy: in POLICY, configure access control policies from outside to inside to allow access from external networks to internal network server applications.
3.1.2, configure MIP using command line
Configuring interface parameters
Set, interface, ethernet1, zone, trust
Set, interface, ethernet1, IP, /24
Set interface ethernet1 nat
Set, interface, ethernet2, zone, untrust
Set, interface, ethernet2, IP, /24
Defining MIP
Set, interface, ethernet2, MIP, , host, , netmask,, 55, vrouter, trust-vr
Definition strategy
Set, policy, from, untrust, to, trust, any, MIP (), HTTP, permit
Save
3.2, VIP configur
您可能关注的文档
- coreldraw题库(coreldraw题库).doc
- 图表统计在应用问题教学中的尝试(The attempt of chart statistics in the teaching of applied problems).doc
- 图解系列(Graphic series).doc
- 圆的面积---邱子珍(The area of the circle --- Qiu Zizhen).doc
- 土壤污染(soil pollution).doc
- 土建施工员应该知道的数据(The data that the builder should know).doc
- 土建管理(Civil Engineering Management).doc
- 土楼(Tulou).doc
- 土豆的营养价值(The nutritional value of potatoes).doc
- 圣典(Canon).doc
- 福莱特玻璃集团股份有限公司海外监管公告 - 福莱特玻璃集团股份有限公司2024年度环境、社会及管治报告.pdf
- 广哈通信:2024年度环境、社会及治理(ESG)报告.pdf
- 招商证券股份有限公司招商证券2024年度环境、社会及管治报告.pdf
- 宏信建设发展有限公司2024 可持续发展暨环境、社会及管治(ESG)报告.pdf
- 品创控股有限公司环境、社会及管治报告 2024.pdf
- 中信建投证券股份有限公司2024可持续发展暨环境、社会及管治报告.pdf
- 洛阳栾川钼业集团股份有限公司环境、社会及管治报告.pdf
- 361度国际有限公司二零二四年环境、社会及管治报告.pdf
- 中国神华能源股份有限公司2024年度环境、社会及管治报告.pdf
- 广西能源:2024年环境、社会及治理(ESG)报告.pdf
文档评论(0)