¡m¤À¨É¡n¦p¦ó«Ø¥ßloopback³W«h | |
¨Ï¥Î¹LCyberoamªºuser³£ª¾¹D¡A¦b«Ø¥ß¤@µ§Virtual IPªº³W«h«á¡A
Cyberom·|¦Û°Ê«Ø¥ß¤@µ§±a # ¸¹ªºloopback³W«h¡A
¥H´£¨Ñ¤º³¡client user³z¹L¥~³¡IP¨Ó³sµ²ªA°È¥D¾÷¡C
¦ý¤£ª¾¹DXG¬O¨S¾Ç¦n¡HÁÙ¬O¤°»ò¨ä¥¦¦]¯À¡H
³oÓloopback¦bXG¤¤¬O¨S¦³ªº¡I
Y¦³»Ýn¡AºÞ²zªÌ¥²»Ý¦Û¤v¤â°Ê«Ø¥ßªº¡I
§ÚÌ¥ý³z¹LCyberoam¡A¨Ã¥H¥H¤U±¡¹Ò¨Ó¬Ý¬Ý¤°»ò¬Oloopback³W«h¡C
- ¤º³¡192.168.1.101¥D¾÷mapping¤@Ó¥~³¡IP 123.123.123.2°µµêÀÀ¥D¾÷¡A¹ï¥~ªA°È¡C
- ·í¤º³¡LAN°Ï°ì¹q¸£192.168.1.7³sµ²µêÀÀ¥D¾÷ªº¥~³¡IP 123.123.123.2®É¡A
¦]¬°Cyberoam¤¤¤w«Ø¦³Virtual Host Mapping Table¡A¥¦ª¾¹DµêÀÀ¥D¾÷123.123.123.2¨ä¹ê´N¬OLANºÝ¥D¾÷192.168.1.101¡A
©Ò¥H¬y¶q¤£·|©¹WAN°e¡Aª½±µ©¹LANºÝ°eµ¹192.168.1.101¡C
- ¦ý¬O·íªA°È¥D¾÷192.168.1.101n¦^¶Ç°T®§®É¡A¥¦·|µo²{¨Ó·½ºÝIP 192.168.1.7¸ò¦Û¤v¬Û¦Pºô¬q¡A
©Ò¥H«Ê¥]¤£·|¸g¥ÑCyberoam¦^¶Ç¡A¦Ó¬Oª½±µ°eµ¹¦PÄÝLANªº192.168.1.7¡C
- µM¦Ó¹ïµo°_ºÝ192.168.1.7ªº¹q¸£¦Ó¨¥¡A§Ú©ú©ú¬On³s¨ì123.123.123.2³oÓ¥~³¡IP¡A
µ²ªG«o¬O¥Ñ¤º³¡IP 192.168.1.101²£¥Í¦^À³¡An¸ò§Úµo¥ÍÀǬNªºÃö«Y¡H
³o¤Ó¸Þ²§¤F§a¡H
©Ò¥Hµo°_ºÝ192.168.1.7©Úµ´¤F¨Ó¦Û192.168.1.101ªº¦^À³°T®§¡A
³y¦¨ªA°È³sµ²¥¢±Ñ...
¥ÑCyberoamªº¨¤«×¨Ó¬Ý¡A³o¬O¤@ºØ¤£¹ïºÙ¸ô¥Ñ¡A
¦b¹w³]±ø¥ó¤U¡A¤£¹ïºÙ¸ô¥Ñ¤]·|³QCyberoam«ÊÂê¡AµLªk§¹¦¨¥æ½Í¡C
- ¬°¤F¸Ñ¨M¦¹°ÝÃD¡ACyberoam·|¦b«Ø¥ßVirtual IP«á¡A¦Û°Ê«Ø¥ß¤@µ§±a # ¸¹loopback³W«h¡A
±N¨Ó·½ºÝ±j¨î°µ¤F¨Ó·½ºÝÂà§}(NAT)¬Fµ¦¡C
- ¦bCyberoam°µ¤FNAT«á¡AªA°È¥D¾÷¬Ý¨ìªº¨Ó·½ºÝIP·|Åܦ¨Cyberomªº¤¶±IP¡A
·íµMsyncªº°T®§¡A¤]´N·|¥á¦^Cyberoam¡A¦A¥á¦^clientºÝ¡A§¹¦¨Âù¦V°T®§ªº¶Ç¹F¡C
- ¤£¹L¦bNAT«á¡AªA°È¥D¾÷¬Ý¨ìªºClientºÝ³s½u¡A¥þ³¡³£²Î¤@³QÂনCyberoamªº¤¶±IP¡A
µLªk½T¤Áªº¤À¿ì¥X¨Ó·½ºÝ¡A³o¬Oloopback³W«h¤Uªº¤@ӰƧ@¥Î¡C
n¹Àª½³sserverªº¤º³¡IP¡An¹À³z¹Lloopback³W«h³sµ²¥~³¡IP¡A¥u¯à¨â¿ï¤@¡A¨S¦³¨ä¥¦¸Ñªk...
¦bÁA¸Ñ¤Floopback³W«hªº¨ÓÀs¥h¯ß«á¡A§Ų́Ӭݬݦp¦ó¦bXG¤W°µ¥Xloopback³W«h¡C
¥Ñ©ó¬O¸òVirtual IP¦³Ãö¡A©Ò¥H³oloopback³W«h´N¸òVirtual IP¤@¼Ë¡A¤]¬O³z¹LBusiness Application Rule¤¤ªº¡§Non-HTTP Based Policy¡¨¼Òª©¨Ó«Ø¥ß¡C
¦Ó¥B¨âªÌ¤§¶¡´X¥G¤@¼Ò¼Ò¤@¼Ë¼Ë¡I
Virtual IPªº³]©w¡A½Ð°Ñ¦Ò³o¤@½g¡÷ Virtual IP³]©w
¦b´X¥G¤@¼Ò¤@¼Ëªºpolicy¤¤¡A³]©wloopback³W«hn¯S§Oª`·N¥H¤U´XÂI¡C
- ¦bHosted Server³oӰ϶ôùتºSource Zone¡A§ÚÌn¥ÑWAN§ï¦¨ANY¡A
²¦³º±qLAN¨ìLAN»P±qLAN¨ìDMZ³£¤@¼Ë·|»Ýnloopback³W«hªº¥[«ù¡A
¤£»Ýn§âSource Zone«]¦bLAN©Î¬ODMZ¡A¿ïANY³Ì¦n¡I
¨º±z¬O§_·|°Ý¡A³o¼Ë¤£´N³sWANªº³s¤J¤]¤@¨Ö¨ü¼vÅT¤F¡H
¼K¡ã§ÚÌ·|¦b²Ä¥|ÂI¡ApolicyªºÀu¥ý¶¶§Ç°µ¤@¨Ç½Õ¾ã¡A
ÅýWANªº³s¤J¨«Virtual IP policy¡A¦Ó¨ä¥¦Zone«h¨«loopback policy¡C
- ±µµÛ¦bRoutingªº³¡¤À¡A¤@©wn±Ò¥Î¡A³o¼Ë¤~¯à°µ¨Ó·½ºÝÂà§}«á¡A¦A³s¨ìªA°È¥D¾÷¡C
¦ÓÂà¥XªºIP¡A¥Î¹w³]ªºMASQ§Y¥i¡C
- ¦Ó¦bReflexiveªº³¡¤À¡A½Ð¤£n±Ò¥Î¡I
¶¶¤l·|¦b¤U¤@½g¸ò¤j®a°µÓ´ú¸Õ¤ÀªR¡C
- §¹¦¨«á¡A§Ú̻ݤâ°Ê§âloopback policy½Õ¾ã¨ìVirtual IPªºpolicy¤§¤U¡C
³o¼Ë¤@¼Ë¡A¥ÑWAN¨ÓªºIP¡A±N¨«²Ä¤W¤@±øVirtual IPªºpolicy¡A¤£°µNATÂà´«¡F
¦Ó¥ÑLAN©ÎDMA¨ÓªºIP¡A±N¨«¤U¤@±øloopbackªºpolicy¡A¶i¦æNATÂà´«¡C
¬J¤£¼vÅT§Y¦³ªºVirtual IP policy¡A¤S§¹¬üªº¸Ñ¨M¤F¤º³¡IPµLªk¥H¥~³¡IP³sµ²ªA°È¥D¾÷ªº°ÝÃD¡C
¤£¹L´N¹³¤@¶}©lloopbackªº³B²zÅ޿褤©Òz¡ANAT«áªºIP·|¬OMASQªºIP¡A
ªA°È¥D¾÷±NµLªkÃѧO¥X¨Ó·½ºÝªº¯u¥¿IP¡I
³o¬O¨Ï¥Î¤Wªº¤@Ó¨î¡C
Loopback³W«h³]©w¨ì¦¹§¹¦¨¡ã
°Ñ¦Ò¸ê®Æ
How do you create a loopback/hairpin NAT to an Interface IP?
****2018/8/17¸É¥R»¡©ú*****
¤Wzªº³]©w¦³¨Ç¦a¤è»Ýn½Õ¾ã¡A
Y¥Ø¼Ð¥D¾÷¦bDMZ¡A«hDMZ to WANªº³¡¤À¡A½T¹ê¦³¥²nÂàNAT¡A«Ø¥ßloopback³W«h¡F
¦ý¹ï¦bLANªºuser¦Ó¨¥¡ALAN to WANªº³¡¤À´N¨S¦³loopbackªº°ÝÃD¡A¤£»ÝnÂàNAT¡C
©Ò¥Hloopback³W«h¤¤ªº¨Ó·½zone¡A¥un¿ï¾Ü¥Ø¼Ð¥D¾÷©Ò¦bªºzone§Y¥i¡A¨Ã¤£»Ýn³]©w¬°ANY¡C
¥Ñ shunze ¦b 2018-08-17, 09:27 ³Ì«áקï.
♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã
If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!
|