Shunze ¾Ç¶é >¸ê°T³]³Æ±M°Ï >Sophos XG > ¡m¤À¨É¡n¦p¦ó«Ø¥ßloopback³W«h «¢Åo¡AÁÙ¨S¦³µù¥U©ÎªÌµn¤J¡C½Ð§A[µù¥U|µn¤J]
« ¤W¤@½g¥DÃD ¤U¤@½g¥DÃD » Åã¥Ü¦¨¦C¦L¼Ò¦¡ | ¼W¥[¨ì§Úªº³Ì·R
µoªí·s¥DÃD µoªí¦^ÂÐ
§@ªÌ
¥DÃD
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2380

shunze Â÷½u
¡m¤À¨É¡n¦p¦ó«Ø¥ßloopback³W«h¤Þ¥Î¦^ÂÐ ½s¿è/§R°£¤å³¹ ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¨Ï¥Î¹LCyberoamªºuser³£ª¾¹D¡A¦b«Ø¥ß¤@µ§Virtual IPªº³W«h«á¡A
Cyberom·|¦Û°Ê«Ø¥ß¤@µ§±a # ¸¹ªºloopback³W«h¡A
¥H´£¨Ñ¤º³¡client user³z¹L¥~³¡IP¨Ó³sµ²ªA°È¥D¾÷¡C

¦ý¤£ª¾¹DXG¬O¨S¾Ç¦n¡HÁÙ¬O¤°»ò¨ä¥¦¦]¯À¡H
³o­Óloopback¦bXG¤¤¬O¨S¦³ªº¡I
­Y¦³»Ý­n¡AºÞ²zªÌ¥²»Ý¦Û¤v¤â°Ê«Ø¥ßªº¡I


§Ú­Ì¥ý³z¹LCyberoam¡A¨Ã¥H¥H¤U±¡¹Ò¨Ó¬Ý¬Ý¤°»ò¬Oloopback³W«h¡C

  1. ¤º³¡192.168.1.101¥D¾÷mapping¤@­Ó¥~³¡IP 123.123.123.2°µµêÀÀ¥D¾÷¡A¹ï¥~ªA°È¡C



  2. ·í¤º³¡LAN°Ï°ì¹q¸£192.168.1.7³sµ²µêÀÀ¥D¾÷ªº¥~³¡IP 123.123.123.2®É¡A
    ¦]¬°Cyberoam¤¤¤w«Ø¦³Virtual Host Mapping Table¡A¥¦ª¾¹DµêÀÀ¥D¾÷123.123.123.2¨ä¹ê´N¬OLANºÝ¥D¾÷192.168.1.101¡A
    ©Ò¥H¬y¶q¤£·|©¹WAN°e¡Aª½±µ©¹LANºÝ°eµ¹192.168.1.101¡C



  3. ¦ý¬O·íªA°È¥D¾÷192.168.1.101­n¦^¶Ç°T®§®É¡A¥¦·|µo²{¨Ó·½ºÝIP 192.168.1.7¸ò¦Û¤v¬Û¦Pºô¬q¡A
    ©Ò¥H«Ê¥]¤£·|¸g¥ÑCyberoam¦^¶Ç¡A¦Ó¬Oª½±µ°eµ¹¦PÄÝLANªº192.168.1.7¡C



  4. µM¦Ó¹ïµo°_ºÝ192.168.1.7ªº¹q¸£¦Ó¨¥¡A§Ú©ú©ú¬O­n³s¨ì123.123.123.2³o­Ó¥~³¡IP¡A
    µ²ªG«o¬O¥Ñ¤º³¡IP 192.168.1.101²£¥Í¦^À³¡A­n¸ò§Úµo¥ÍÀǬNªºÃö«Y¡H
    ³o¤Ó¸Þ²§¤F§a¡H

    ©Ò¥Hµo°_ºÝ192.168.1.7©Úµ´¤F¨Ó¦Û192.168.1.101ªº¦^À³°T®§¡A
    ³y¦¨ªA°È³sµ²¥¢±Ñ...

    ¥ÑCyberoamªº¨¤«×¨Ó¬Ý¡A³o¬O¤@ºØ¤£¹ïºÙ¸ô¥Ñ¡A
    ¦b¹w³]±ø¥ó¤U¡A¤£¹ïºÙ¸ô¥Ñ¤]·|³QCyberoam«ÊÂê¡AµLªk§¹¦¨¥æ½Í¡C

  5. ¬°¤F¸Ñ¨M¦¹°ÝÃD¡ACyberoam·|¦b«Ø¥ßVirtual IP«á¡A¦Û°Ê«Ø¥ß¤@µ§±a # ¸¹loopback³W«h¡A
    ±N¨Ó·½ºÝ±j¨î°µ¤F¨Ó·½ºÝÂà§}(NAT)¬Fµ¦¡C



  6. ¦bCyberoam°µ¤FNAT«á¡AªA°È¥D¾÷¬Ý¨ìªº¨Ó·½ºÝIP·|Åܦ¨Cyberomªº¤¶­±IP¡A



    ·íµMsyncªº°T®§¡A¤]´N·|¥á¦^Cyberoam¡A¦A¥á¦^clientºÝ¡A§¹¦¨Âù¦V°T®§ªº¶Ç¹F¡C



  7. ¤£¹L¦bNAT«á¡AªA°È¥D¾÷¬Ý¨ìªºClientºÝ³s½u¡A¥þ³¡³£²Î¤@³QÂনCyberoamªº¤¶­±IP¡A
    µLªk½T¤Áªº¤À¿ì¥X¨Ó·½ºÝ¡A³o¬Oloopback³W«h¤Uªº¤@­Ó°Æ§@¥Î¡C

    ­n¹Àª½³sserverªº¤º³¡IP¡A­n¹À³z¹Lloopback³W«h³sµ²¥~³¡IP¡A¥u¯à¨â¿ï¤@¡A¨S¦³¨ä¥¦¸Ñªk...



¦bÁA¸Ñ¤Floopback³W«hªº¨ÓÀs¥h¯ß«á¡A§Ú­Ì¨Ó¬Ý¬Ý¦p¦ó¦bXG¤W°µ¥Xloopback³W«h¡C

¥Ñ©ó¬O¸òVirtual IP¦³Ãö¡A©Ò¥H³oloopback³W«h´N¸òVirtual IP¤@¼Ë¡A¤]¬O³z¹LBusiness Application Rule¤¤ªº¡§Non-HTTP Based Policy¡¨¼Òª©¨Ó«Ø¥ß¡C
¦Ó¥B¨âªÌ¤§¶¡´X¥G¤@¼Ò¼Ò¤@¼Ë¼Ë¡I

Virtual IPªº³]©w¡A½Ð°Ñ¦Ò³o¤@½g¡÷ Virtual IP³]©w

¦b´X¥G¤@¼Ò¤@¼Ëªºpolicy¤¤¡A³]©wloopback³W«h­n¯S§Oª`·N¥H¤U´XÂI¡C
  1. ¦bHosted Server³o­Ó°Ï¶ôùتºSource Zone¡A§Ú­Ì­n¥ÑWAN§ï¦¨ANY¡A
    ²¦³º±qLAN¨ìLAN»P±qLAN¨ìDMZ³£¤@¼Ë·|»Ý­nloopback³W«hªº¥[«ù¡A
    ¤£»Ý­n§âSource Zone«]­­¦bLAN©Î¬ODMZ¡A¿ïANY³Ì¦n¡I



    ¨º±z¬O§_·|°Ý¡A³o¼Ë¤£´N³sWANªº³s¤J¤]¤@¨Ö¨ü¼vÅT¤F¡H

    ¼K¡ã§Ú­Ì·|¦b²Ä¥|ÂI¡ApolicyªºÀu¥ý¶¶§Ç°µ¤@¨Ç½Õ¾ã¡A
    ÅýWANªº³s¤J¨«Virtual IP policy¡A¦Ó¨ä¥¦Zone«h¨«loopback policy¡C

  2. ±µµÛ¦bRoutingªº³¡¤À¡A¤@©w­n±Ò¥Î¡A³o¼Ë¤~¯à°µ¨Ó·½ºÝÂà§}«á¡A¦A³s¨ìªA°È¥D¾÷¡C
    ¦ÓÂà¥XªºIP¡A¥Î¹w³]ªºMASQ§Y¥i¡C



  3. ¦Ó¦bReflexiveªº³¡¤À¡A½Ð¤£­n±Ò¥Î¡I
    ¶¶¤l·|¦b¤U¤@½g¸ò¤j®a°µ­Ó´ú¸Õ¤ÀªR¡C



  4. §¹¦¨«á¡A§Ú­Ì»Ý¤â°Ê§âloopback policy½Õ¾ã¨ìVirtual IPªºpolicy¤§¤U¡C



    ³o¼Ë¤@¼Ë¡A¥ÑWAN¨ÓªºIP¡A±N¨«²Ä¤W¤@±øVirtual IPªºpolicy¡A¤£°µNATÂà´«¡F
    ¦Ó¥ÑLAN©ÎDMA¨ÓªºIP¡A±N¨«¤U¤@±øloopbackªºpolicy¡A¶i¦æNATÂà´«¡C

    ¬J¤£¼vÅT§Y¦³ªºVirtual IP policy¡A¤S§¹¬üªº¸Ñ¨M¤F¤º³¡IPµLªk¥H¥~³¡IP³sµ²ªA°È¥D¾÷ªº°ÝÃD¡C


¤£¹L´N¹³¤@¶}©lloopbackªº³B²zÅ޿褤©Ò­z¡ANAT«áªºIP·|¬OMASQªºIP¡A
ªA°È¥D¾÷±NµLªkÃѧO¥X¨Ó·½ºÝªº¯u¥¿IP¡I
³o¬O¨Ï¥Î¤Wªº¤@­Ó­­¨î¡C

Loopback³W«h³]©w¨ì¦¹§¹¦¨¡ã


°Ñ¦Ò¸ê®Æ
How do you create a loopback/hairpin NAT to an Interface IP?


****2018/8/17¸É¥R»¡©ú*****
¤W­zªº³]©w¦³¨Ç¦a¤è»Ý­n½Õ¾ã¡A
­Y¥Ø¼Ð¥D¾÷¦bDMZ¡A«hDMZ to WANªº³¡¤À¡A½T¹ê¦³¥²­nÂàNAT¡A«Ø¥ßloopback³W«h¡F
¦ý¹ï¦bLANªºuser¦Ó¨¥¡ALAN to WANªº³¡¤À´N¨S¦³loopbackªº°ÝÃD¡A¤£»Ý­nÂàNAT¡C

©Ò¥Hloopback³W«h¤¤ªº¨Ó·½zone¡A¥u­n¿ï¾Ü¥Ø¼Ð¥D¾÷©Ò¦bªºzone§Y¥i¡A¨Ã¤£»Ý­n³]©w¬°ANY¡C

¥Ñ shunze ¦b 2018-08-17, 09:27 ³Ì«á­×§ï.



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2016-09-05, 18:10 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2380

shunze Â÷½u
¡m¤À¨É¡nReflexive rule on/off¤Þ¥Î¦^ÂÐ ½s¿è/§R°£¤å³¹ ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

Ãö©óreflexive ruleªº±Ò¥Î»P§_¡A
¥Ñ©óloopback³W«h¬O¬°¤F­n¸Ñ¨MVirtual IP¥H¥~³¡IP´£¨Ñ¤º³¡user³sµ²©Ò²£¥Í¡A¨âªÌ±K¤£¥i¤À¡C
©Ò¥H¶¶¤l®³¤FVirtual IP»Ploopback¨âºØ³W«hªºreflexive on/off¥|ºØ²Õ¦X°µ¤F¥æ¤e´ú¸Õ¡Aµ²ªG¦p¤U¡C


VIPªA°È¡A¬O«üVirtual IP´£¨Ñ¥~³¡/¤º³¡ªº³sµ²ªºªA°Èª¬ºA¡F
¤º³¡³s¥~¡A¬O«ü¤º³¡userªº³s¥~¯à¤O¡F
³sXG¤º³¡IP¡A¬O«ü¤º³¡user³sµ²XG¨¾¤õÀðªºLANºÝIP¡F
³sXG¥~³¡IP¡A¬O«ü¤º³¡user³sµ²XG¨¾¤õÀðªºWANºÝIP¡C



¥Ñ´ú¸Õµ²ªG¥i¥Hµo²{¡A
·íloopback³W«h±Ò¥Î¤Freflexive¥\¯à«á¡A©Î¦h©Î¤Ö³£·|¹ï¤º³¡userªº³sµ²¯à¤O²£¥Í¤F¼vÅT¡C

¦]¦¹¦b«Ø³Ðloopback³W«h®É¡A½Ð¤£­n±Ò¥Îreflexive¥\¯à¡I



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2016-09-08, 12:11 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
  « ¤W¤@½g¥DÃD ¤U¤@½g¥DÃD »
µoªí·s¥DÃD µoªí¦^ÂÐ
¸õ¨ì:

Powered by: Burning Board 1.1.1 2001 WoltLab GbR