netscreen防火墙
我这里的netscreen防火墙出了点问题,这是我与对端的连接
192.168.1.10(服务器IP)--->192.168.1.254(防火墙IP进)--->122.31.142.186(防火墙IP出)--->122.31.142.185(移动对端三层交换机IP)--->122.31.142.30(移动三层交机IP)--->122.31.142.20(对端路由器IP)---->122.31.247.126(对端路由器IP)--->122.31.247.76(对端服务器IP)
我在服务器上只能PING通192.168.1.10(服务器IP)--->192.168.1.254(防火墙IP进)
在防火墙上能PING通192.168.1.10(服务器IP)--->192.168.1.254(防火墙IP进)--->122.31.142.186(防火墙IP出)--->122.31.142.185(移动对端三层交换机IP)
我把出口端的网线拨下接入我的手提电脑(设出口端IP地址)能PING通122.31.142.186(防火墙IP出)--->122.31.142.185(移动对端三层交换机IP)--->122.31.142.30(移动三层交机IP)--->122.31.142.20(对端路由器IP)---->122.31.247.126(对端路由器IP)--->122.31.247.76(对端服务器IP)
现在我想192.168.1.10(服务器IP) 能PING通122.31.247.76(对端服务器IP)不只该怎么做(帮我写一下具体的操作参数配置)
下面是我现在的配置参数
get show conf
Total Config size 2342:
set clock timezone 0
set vrouter trust-vr sharable
unset vrouter "trust-vr" auto-route-export
set auth-server "Local" id 0
set auth-server "Local" server-name "Local"
set auth default auth server "Local"
set admin name "netscreen"
set admin password "nKVUM2rwMUzPcrkG5sWIHdCtqkAibn"
set admin auth timeout 10
set admin auth server "Local"
set admin format dos
set zone "Trust" vrouter "trust-vr"
set zone "Untrust" vrouter "trust-vr"
set zone "DMZ" vrouter "trust-vr"
set zone "VLAN" vrouter "trust-vr"
set zone "Trust" tcp-rst
set zone "Untrust" block
unset zone "Untrust" tcp-rst
set zone "MGT" block
set zone "DMZ" tcp-rst
set zone "VLAN" block
--- more ---
set zone "VLAN" tcp-rst
set zone "Untrust" screen tear-drop
set zone "Untrust" screen syn-flood
set zone "Untrust" screen ping-death
set zone "Untrust" screen ip-filter-src
set zone "Untrust" screen land
set zone "V1-Untrust" screen tear-drop
set zone "V1-Untrust" screen syn-flood
set zone "V1-Untrust" screen ping-death
set zone "V1-Untrust" screen ip-filter-src
set zone "V1-Untrust" screen land
set interface "ethernet1" zone "Trust"
set interface "ethernet2" zone "DMZ"
set interface "ethernet3" zone "Untrust"
unset interface vlan1 ip
set interface ethernet1 ip 192.168.1.254/24
set interface ethernet1 nat
set interface ethernet3 ip 122.31.142.186/30
set interface ethernet3 route
unset interface vlan1 bypass-others-ipsec
unset interface vlan1 bypass-non-ip
set interface ethernet1 ip manageable
--- more ---
set interface ethernet3 ip manageable
set interface "ethernet3" mip 122.31.231.129 host 192.168.1.10 netmask 255.255.255.255 vrouter "trust-vr"
set interface "ethernet3" mip 122.31.231.139 host 192.168.1.20 netmask 255.255.255.255 vrouter "trust-vr"
set hostname ns25
set ike respond-bad-spi 1
set pki authority default scep mode "auto"
set pki x509 default cert-path partial
set policy id 1 from "Untrust" to "Trust" "Any" "MIP(122.31.231.129)" "ANY" permit
set policy id 2 from "Untrust" to "Trust" "Any" "MIP(122.31.231.139)" "ANY" permit
set ssh version v2
set config lock timeout 5
set snmp port listen 161
set snmp port trap 162
set vrouter "untrust-vr"
exit
set vrouter "trust-vr"
unset add-default-route
set route 0.0.0.0/0 interface ethernet3 gateway 122.31.142.185
set route 0.0.0.0/0 vrouter "untrust-vr"
exit
ns25->
ns25->