紧急求助
netscreen25怎么配置了映射,在netscreen25上不能ping通映射地址呢?在netscreen25所连两端设备上却可以ping通映射地址.我看不出来配置有什么问题啊,那位高手给看看.万分感谢.
NS25->IP_WAN-> get system
Product Name: NS25
Serial Number: 0096092005000800, Control Number: 00000000
Hardware Version: 4010(0)-(00), FPGA checksum: 00000000, VLAN1 IP (0.0.0.0)
Software Version: 5.0.0r8.0, Type: Firewall+VPN
Base Mac: 0012.1ea0.8a10
File Name: ns50ns25.5.0.0r8.0, Checksum: f5e8bcce
NS25->IP_WAN->get config
Total Config size 6165:
set clock timezone 0
set vrouter trust-vr sharable
unset vrouter "trust-vr" auto-route-export
set service "desktop" protocol tcp src-port 0-65535 dst-port 3389-3389
set service "ORACLE" protocol tcp src-port 0-65535 dst-port 1521-1521
set service "SQL" protocol tcp src-port 0-65535 dst-port 1433-1433
set service "tcp135" protocol tcp src-port 0-65535 dst-port 135-135
set service "udp135" protocol udp src-port 0-65535 dst-port 135-135
set service "wap" protocol tcp src-port 0-65535 dst-port 8080-8080
set service "web" protocol tcp src-port 0-65535 dst-port 80-80
set auth-server "Local" id 0
set auth-server "Local" server-name "Local"
set auth default auth server "Local"
set admin name "netscreen"
set admin password "nKF9FZrzKFtIc0lEmsMHSOAtrFBGPn"
set admin auth timeout 10
set admin auth server "Local"
set admin format dos
set zone "Trust" vrouter "trust-vr"
set zone "Untrust" vrouter "trust-vr"
set zone "DMZ" vrouter "trust-vr"
--- more ---
set zone "VLAN" vrouter "trust-vr"
set zone "Trust" tcp-rst
set zone "Untrust" block
unset zone "Untrust" tcp-rst
set zone "MGT" block
set zone "DMZ" tcp-rst
set zone "VLAN" block
set zone "VLAN" tcp-rst
set zone "Untrust" screen tear-drop
set zone "Untrust" screen syn-flood
set zone "Untrust" screen ping-death
set zone "Untrust" screen ip-filter-src
set zone "Untrust" screen land
set zone "V1-Untrust" screen tear-drop
set zone "V1-Untrust" screen syn-flood
set zone "V1-Untrust" screen ping-death
set zone "V1-Untrust" screen ip-filter-src
set zone "V1-Untrust" screen land
set interface "ethernet1" zone "Trust"
set interface "ethernet2" zone "DMZ"
set interface "ethernet3" zone "Untrust"
set interface "ethernet4" zone "Trust"
--- more ---
unset interface vlan1 ip
set interface ethernet1 ip 192.168.1.1/30
set interface ethernet1 nat
set interface ethernet3 ip 218.139.136.122/29
set interface ethernet3 route
set interface ethernet4 ip 192.168.1.9/30
set interface ethernet4 nat
unset interface vlan1 bypass-others-ipsec
unset interface vlan1 bypass-non-ip
set interface ethernet1 ip manageable
set interface ethernet3 ip manageable
set interface ethernet4 ip manageable
unset interface ethernet1 manage ping
set interface ethernet3 manage ping
set interface "ethernet3" mip 218.139.136.123 host 192.168.2.10 netmask 255.255.255.255 vrouter "trust-vr"
set interface "ethernet3" mip 218.139.136.124 host 192.168.2.7 netmask 255.255.255.255 vrouter "trust-vr"
set interface "ethernet3" mip 218.139.136.125 host 192.168.2.6 netmask 255.255.255.255 vrouter "trust-vr"
set interface "ethernet3" mip 218.139.136.126 host 192.168.2.9 netmask 255.255.255.255 vrouter "trust-vr"
set interface "ethernet3" mip 218.139.136.122 host 192.168.1.2 netmask 255.255.255.255 vrouter "trust-vr"
set hostname NS25->IP_WAN
set ike respond-bad-spi 1
set pki authority default scep mode "auto"
--- more ---
set pki x509 default cert-path partial
set policy id 1 from "Trust" to "Untrust" "Any" "Any" "ANY" permit
set policy id 2 from "DMZ" to "Untrust" "Any" "Any" "ANY" permit
set policy id 3 from "Trust" to "DMZ" "Any" "Any" "ANY" permit
set policy id 4 from "Untrust" to "Trust" "Any" "Any" "ANY" permit
set policy id 7 from "Untrust" to "Trust" "Any" "MIP(218.139.136.124)" "PING" permit
set policy id 8 from "Untrust" to "Trust" "Any" "MIP(218.139.136.125)" "PING" permit
set policy id 9 from "Untrust" to "Trust" "Any" "MIP(218.139.136.126)" "PING" permit
set policy id 10 from "Untrust" to "Trust" "Any" "MIP(218.139.136.125)" "web" permit
set policy id 11 from "Untrust" to "Trust" "Any" "MIP(218.139.136.125)" "wap" permit
set policy id 13 from "Untrust" to "Trust" "Any" "MIP(218.139.136.124)" "desktop" permit
set policy id 14 from "Untrust" to "Trust" "Any" "MIP(218.139.136.125)" "desktop" permit
set policy id 15 from "Untrust" to "Trust" "Any" "MIP(218.139.136.126)" "desktop" permit
set policy id 17 from "Untrust" to "Trust" "Any" "MIP(218.139.136.124)" "tcp135" deny
set policy id 18 from "Untrust" to "Trust" "Any" "MIP(218.139.136.125)" "tcp135" deny
set policy id 19 from "Untrust" to "Trust" "Any" "MIP(218.139.136.126)" "tcp135" deny
set policy id 21 from "Untrust" to "Trust" "Any" "MIP(218.139.136.124)" "udp135" deny
set policy id 22 from "Untrust" to "Trust" "Any" "MIP(218.139.136.125)" "udp135" deny
set policy id 23 from "Untrust" to "Trust" "Any" "MIP(218.139.136.126)" "udp135" deny
set policy id 25 from "Untrust" to "Trust" "Any" "MIP(218.139.136.124)" "SQL" permit
set policy id 26 from "Untrust" to "Trust" "Any" "MIP(218.139.136.125)" "SQL" permit
set policy id 28 from "Untrust" to "Trust" "Any" "MIP(218.139.136.124)" "ORACLE" permit
--- more ---
set policy id 29 from "Untrust" to "Trust" "Any" "MIP(218.139.136.125)" "ORACLE" permit
set policy id 30 from "Untrust" to "Trust" "Any" "MIP(218.139.136.122)" "TELNET" permit
set policy id 6 from "Untrust" to "Trust" "Any" "MIP(218.139.136.123)" "PING" permit
set policy id 12 from "Untrust" to "Trust" "Any" "MIP(218.139.136.123)" "desktop" permit
set policy id 16 from "Untrust" to "Trust" "Any" "MIP(218.139.136.123)" "tcp135" deny
set policy id 20 from "Untrust" to "Trust" "Any" "MIP(218.139.136.123)" "udp135" deny
set policy id 24 from "Untrust" to "Trust" "Any" "MIP(218.139.136.123)" "SQL" permit
set policy id 27 from "Untrust" to "Trust" "Any" "MIP(218.139.136.123)" "ORACLE" permit
set ssh version v2
set config lock timeout 5
set snmp port listen 161
set snmp port trap 162
set vrouter "untrust-vr"
exit
set vrouter "trust-vr"
unset add-default-route
set route 192.168.2.0/24 interface ethernet1 gateway 192.168.1.2
set route 0.0.0.0/0 interface ethernet3 gateway 218.139.136.121
set route 192.168.3.0/24 interface ethernet4 gateway 192.168.1.10
set route 192.168.4.0/24 interface ethernet4 gateway 192.168.1.10
set route 192.168.5.0/24 interface ethernet4 gateway 192.168.1.10
set route 192.168.6.0/24 interface ethernet4 gateway 192.168.1.10
--- more ---
set route 192.168.7.0/24 interface ethernet4 gateway 192.168.1.10
set route 192.168.1.24/30 interface ethernet4 gateway 192.168.1.10