欢迎来到天天文库
浏览记录
ID:17728762
大小:120.50 KB
页数:4页
时间:2018-09-05
《dnat负载均衡功能配置案例》由会员上传分享,免费在线阅读,更多相关内容在行业资料-天天文库。
1、DNAT负载均衡功能配置案例DNAT负载均衡功能配置案例(设置内网服务器对互联网提供服务)拓扑图如附件所示。需求说明:内网有三台http服务器(192.168.2.2/3/4)要对外提供服务,使用的外网口地址是192.168.0.2,需对外提供负载均衡的功能。后续准备还要增加邮件、ftp等服务器。同时,允许这些服务器能够方便在家休息时的网管人员能管理远程的服务器。具体配置如下:address"cluster1" range192.168.2.2192.168.2.4 host"192.168.2.2" host"192.168.2.3" host"192.168.2.4"exitse
2、rvice"rdp" tcpdst-port3389timeout1800exitinterfacevswitchif1 zone "trust" ipaddress192.168.2.1255.255.255.0 managessh manageping managehttp managehttpsexitinterfaceethernet0/1 zone "untrust" ipaddress192.168.0.21255.255.255.0 managessh manageping managehttpsexitipvroutertrust-vr ipro
3、ute0.0.0.0/0192.168.0.1exitpolicyfrom"trust"to"untrust" ruleid2 actionpermit src-addr"Any" dst-addr"Any" service"Any" exitexitpolicyfrom"untrust"to"trust" ruleid3 actionpermit src-addr"Any" dst-addr"Any" service"HTTP" service"FTP" service"POP3" service"PING" service"SMTP" service"rd
4、p" service"ICMP" exitpolicyfrom"l2-trust"to"l2-trust" ruleid4 actionpermit src-addr"Any" dst-addr"Any" service"Any" exitnatsnatruleid1from"cluster1"to"Any"eifethernet0/1trans-toaddress-book"192.168.0.20"modedynamicportstickyexitnatsnatruleid2from"Any"to"Any"eifethernet0/1trans-toeif-ipmoded
5、ynamicportstickyexitnatdnatruleid2from"Any" to"192.168.0.20"service"PING"trans-to"192.168.2.3"load-balancetrack-pingexitnatdnatruleid1from"Any" to"192.168.0.20"service"HTTP"trans-to"192.168.2.3"load-balancetrack-pingexitnatdnatruleid4from"Any" to"192.168.0.20"service"rdp"trans-to"192.168.2.3"loa
6、d-balancetrack-pingexitnatdnatruleid3from"Any" to"192.168.0.20"service"PING"trans-to"192.168.2.4"load-balancetrack-pingexitnatdnatruleid5from"Any" to"192.168.0.20"service"HTTP"trans-to"192.168.2.4"load-balancetrack-pingexitnatdnatruleid6from"Any" to"192.168.0.20"service"rdp"trans-to"192.168.2.4"
7、load-balancetrack-pingexitnatdnatruleid7from"Any" to"192.168.0.20"service"PING"trans-to"192.168.2.2"load-balancetrack-pingexitnatdnatruleid8from"Any" to"192.168.0.20"service"HTTP"trans-to"192.168.2.2"load
此文档下载收益归作者所有