1. 程式人生 > >juniper SRX 地址映射

juniper SRX 地址映射

ESS app perm The rul 端口號 nio tcp juniper

需求說明:公網127.90.43.122:16927 映射 內網 10.100.124.200:80

定義內網地址
set security nat destination pool srv200-80 address 10.100.124.200/32
定義內網端口號
set security nat destination pool srv200-80 address port 80
定義公網地址+端口
edit security nat destination
set rule-set untrust-trust-set rule un122-srv200-443 match source-address 0.0.0.0/0
set rule-set untrust-trust-set rule un122-srv200-443 match destination-address 127.90.43.122/32

set rule-set untrust-trust-set rule un122-srv200-443 match destination-port 16927 ##公網端口
set rule-set untrust-trust-set rule un122-srv200-443 match protocol tcp
set rule-set untrust-trust-set rule un122-srv200-443 then destination-nat pool srv200-80

定義內網協議+端口

set applications application tcp-80 protocol tcp
set applications application tcp-80 destination-port 80

定義內網地址

set security zones security-zone trust address-book address srv200 10.100.124.200

定義策略
edit security policies from-zone untrust to-zone trust
set policy utot-srv11-3389 match source-address any
set policy utot-srv11-3389 match destination-address srv200
set policy utot-srv11-3389 match application tcp-80 ###### 定義內網真實端口####

set policy utot-srv11-3389 match application junios-http
set policy utot-srv11-3389 then permit

juniper SRX 地址映射