juniper SRX 地址映射

Posted

tags:

篇首语:本文由小常识网(cha138.com)小编为大家整理,主要介绍了juniper SRX 地址映射相关的知识,希望对你有一定的参考价值。

需求说明:公网127.90.43.122:16927 映射 内网 10.100.124.200:80

定义内网地址
set security nat destination pool srv200-80 address 10.100.124.200/32
定义内网端口号
set security nat destination pool srv200-80 address port 80
定义公网地址+端口
edit security nat destination
set rule-set untrust-trust-set rule un122-srv200-443 match source-address 0.0.0.0/0
set rule-set untrust-trust-set rule un122-srv200-443 match destination-address 127.90.43.122/32
set rule-set untrust-trust-set rule un122-srv200-443 match destination-port 16927 ##公网端口
set rule-set untrust-trust-set rule un122-srv200-443 match protocol tcp
set rule-set untrust-trust-set rule un122-srv200-443 then destination-nat pool srv200-80

定义内网协议+端口

set applications application tcp-80 protocol tcp
set applications application tcp-80 destination-port 80

定义内网地址

set security zones security-zone trust address-book address srv200 10.100.124.200

定义策略
edit security policies from-zone untrust to-zone trust
set policy utot-srv11-3389 match source-address any
set policy utot-srv11-3389 match destination-address srv200
set policy utot-srv11-3389 match application tcp-80 ###### 定义内网真实端口####
set policy utot-srv11-3389 match application junios-http
set policy utot-srv11-3389 then permit

以上是关于juniper SRX 地址映射的主要内容,如果未能解决你的问题,请参考以下文章

Juniper srx 240 端口映射\N个ISP出口 之 “浮动路由+指定资源走指定线路”

juniper srx550怎样配置端口映射功能

Juniper SRX240 端口映射配置

Juniper SRX240 建立Policy后,不能commit,怎麼解决?

juniper srx 240 cluster 内网服务器端口发布到外网配置实例

Juniper防火墙映射配置应用场景变异