This section provides an example for configuring intranet users to access the public IP addresses of intranet servers.
An enterprise has deployed a FW as a security gateway on the intranet border. NAT Server is configured on the FW for the intranet web and File Transfer Protocol (FTP) servers to provide services for Internet users. PC D on the same network segment and security zone with the two servers. Source NAT is configured on the FW so that PC D can use a public address to access the two intranet servers.
Item |
Data |
Description |
|
|---|---|---|---|
GigabitEthernet 0/0/1 |
IP address: 1.1.1.1/24 Security zone: untrust |
1.1.1.1/24 is a public address provided by the ISP. |
|
GigabitEthernet 0/0/2 |
IP address: 10.2.0.1/24 Security zone: dmz |
Intranet servers use 10.2.0.1 as the default gateway address. |
|
Addresses in the source NAT address pool |
1.1.1.11 |
- |
|
Addresses in the destination NAT address pool |
10.2.0.7 to 10.2.0.8 |
- |
|
Routing information |
Default route |
Destination address: 0.0.0.0 Next hop address: 1.1.1.254 |
Configure a default route on the FW to direct intranet traffic to the ISP network. |

In Source Translation Address Pool List, click Add and configure a NAT address pool based on the following parameters.


In Destination Translation Address Pool List, click Add and configure a NAT address pool based on the following parameters.


In NAT Policy List, click Add and configure a NAT policy based on the following parameters.

When configuring Service, right-click the input box in the column where Service resides and choose from the shortcut menu.

Set a protocol number as follows:

Contact your ISP administrator to perform this step.
Configuration script for the FW:
# sysname FW # interface GigabitEthernet0/0/1 undo shutdown ip address 1.1.1.1 255.255.255.0 # interface GigabitEthernet0/0/2 undo shutdown ip address 10.2.0.1 255.255.255.0 # firewall zone untrust set priority 5 add interface GigabitEthernet0/0/1 # firewall zone dmz set priority 50 add interface GigabitEthernet0/0/2 detect ftp # firewall interzone dmz untrust detect ftp # ip route-static 0.0.0.0 0.0.0.0 1.1.1.254 ip route-static 1.1.10.10 255.255.255.255 NULL0 # nat address-group addressgroup1 0 mode pat route enable section 0 1.1.1.11 1.1.1.11 # destination-nat address-group addressgroup2 0 section 10.2.0.7 10.2.0.8 # security-policy rule name policy1 source-zone dmz destination-zone dmz destination-address 10.2.0.0 24 action permit # nat-policy rule name policy_nat1 source-zone dmz source-address 10.2.0.6 24 destination-address 1.1.10.10 32 service protocol tcp destination-port 3000 to 3001 action source-nat address-group addressgroup1 action destination-nat static port-to-address address-group addressgroup2 2000 # return