《分享》讓Cyberoam可以透過VPN Tunnel連結到遠端一整個網段 | |
同上述情境,若想讓Cyberoam本機能透過VPN Tunnel連到遠端一整個網段,而不是單單某一個IP,
那麼可將上述指令稍微修改,將host改為網段net。
cyberoam ipsec_route add net network/netmask tunnelname IPsec-TunnelName
set advanced-firewall cr-traffic-nat add destination network netmask netmask snatip Cyberom-Interface-IP
套用以上情境劇本,對應的指令如下。
cyberoam ipsec_route add net 172.16.16.0/255.255.255.0 tunnelname Test
set advanced-firewall cr-traffic-nat add destination 172.16.16.0 netmask 255.255.255.0 snatip 192.168.1.254
指令套用後,Cyberoam介面IP 192.168.1.254,就可以成功連結到172.16.16.0/24一段整個網段的IP。
♥順子老婆的網拍,請多關照∼
If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!
|