Shunze ¾Ç¶é >¸ê°T³]³Æ±M°Ï >Sophos XG > ¡m¤À¨É¡nVirtual IP³]©w «¢Åo¡AÁÙ¨S¦³µù¥U©ÎªÌµn¤J¡C½Ð§A[µù¥U|µn¤J]
« ¤W¤@½g¥DÃD ¤U¤@½g¥DÃD » Åã¥Ü¦¨¦C¦L¼Ò¦¡ | ¼W¥[¨ì§Úªº³Ì·R
µoªí·s¥DÃD µoªí¦^ÂÐ
§@ªÌ
¥DÃD
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2380

shunze Â÷½u
¡m¤À¨É¡nVirtual IP³]©w¤Þ¥Î¦^ÂÐ ½s¿è/§R°£¤å³¹ ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¦bCyberoamùØ¡A­n¬M®g¤@­Ó¥~³¡¥i¥ÎIP¨ì¤º³¡¨p¦³¥D¾÷IP¬O«Ü®e©öªº¡A
¦ý¦bXG¤¤¡A³o³¡¤À´NÅܱo½ÆÂø¨Ç¡A
¥H¤U§Ú­Ì´N¨Ó¬Ý¬Ý¦p¦óMapping¤@­Ó¥~³¡¹êÅéIP 211.75.130.142¨ì¤º³¡¨p¦³IP 192.168.30.101¡C


­º¥ý¡A§Ú­Ì¥²»Ý¦bWAN port¤W¡A¸j©w¤@­ÓISPµ¹ªº¹êÅéIP°µ¬°Alias¡A³o¸òCyberoam¬O¤@¼Ëªº¡C








Wan¤¶­±¤WªºAlias IP«Ø¦n«á¡A±µµÛ´N­n³z¹LBusiness Application Rule¨Ó«Ø¥ß¤@±ø¬M®g³W«h¡A
§â¥~³¡IPÂà¨ì¤º³¡¨p¦³IP¡C



¦bApplication Template¤W¡A½Ð¿ï¥Î¡§Non-HTTP Based Policy¡¨¼Òª©¨Ó«Ø¥ß¥~¹ï¤ºªºIP¬M®g¡C



¦Ó¦bSource°Ï¶ô¡A§Ú­Ì­n³]©w­þ¨ÇIP¹L¨Óªº«Ê¥]¡A­n¶i¦æ¥~¹ï¤ºªºÂà¾É¡A
¦pªG¨S¦³¯S§O­­¨î¨Ó·½IP¡A¥i¥H¿ï¥ÎAny¡C




±µµÛ­«ÂI¨Ó¤F¡A¦bHosted Server³o­Ó°Ï¶ô¡A¬O­n³]©w¤¶­±¤Wªº­þ­ÓIP­n°µÂà¾É¡A
¥Ñ©ó§Ú­Ì¬O­n§âWAN¤¶­±¤WªºAlias IPÂà¨ì¤º³¡¨p¦³IP¡A
©Ò¥H³oùتºSource Zone´N¿ï¾ÜWAN¡AµM«á§âHosted Address¿ï¨ì²Ä¤@¨BÆJ©Ò«Ø¥ßªºWAN¤WªºAlias IP¡C




¥~³¡¨Ó·½ºÝ³]¦n¤F¡A±µµÛ´N­n³]©w­nÂà¨ì¤º³¡­þ¤@¥x¥D¾÷¥h¡H
¦bProtected Application Server³o¡AProtect Zone­n¿ï¤º³¡¯u¥¿¥D¾÷©Ò¦bªº°Ï°ì¡A¥H¶¶¤lªº½d¨Ò¨Ó»¡¬OLAN³o­ÓZone¡A
¦ÓServer IP«h¬O192.168.30.101¡C




¥~¹ï¤ºªºÂà¾É³]©w­n¶µ½T©w«á¡A±µµÛ´N¬O¤@¨Ç³]©w¤Wªº¨ä¥¦²Ó¶µ¡A
¨Ò¦p¥~¹ï¤ºPortªºÂà¾É¡C

¨ú®ø±Ò¥ÎForward all ports¡A¨º§Ú­Ì´N¥i¥H¦Û¦æ©w¸q¡A¥~³¡­þ¨Çport­nÂà´«¨ì¹ê»ÚªA°ÈªºPort¤W¡C
³o¹ïISP·~ªÌ´£¨Ñµ¹§Ú­Ì¥i¥Îªº¹êÅéIP¦³­­®É¡A«D¥Î¦n¥Î¡I



·íµM¡A­Y§Ú­Ì¹êÅéIP¼Æ¬Û¦P¥R¨¬¡A
¥i¥H¤@­Ó¥~³¡IP§¹¾ã¹ïÀ³¨ì¤@­Ó¤º³¡IP®É¡A§Ú­Ì´N¥i¥H±Ò¥ÎForward all ports¡C
³o¼Ë´N¬O¤@¹ï¤@ªº§¹¾ã¹ïÀ³¡A¥~¹ï¤ºªºport§¹¥þ³z³q¡C



¦ÓRoutingªº³¡¤À¡A¥i¥H¿ï¾Ü¬O§_­n±N¨Ó¦Û¥~¬Éªº«Ê¥]¡A°µ¨Ó·½ºÝÂà§}¡A
Âন¤¶­±IP«á¡A¦A³s¨ì¤º³¡ªA°Èªº¯u¹ê¥D¾÷¡C



¤@¯ë¨Ó»¡³o¶µ¥Ø¬O¤£»Ý­n±Ò¥Îªº¡A¦]¬°±Ò¥Î«á¡A«áºÝªA°È¥D¾÷¬Ý¨ìªº¨Ó·½IP·|¤@¼Ë¡A¥þ³¡³£¬OÂà§}«áªº¤¶­±IP¡A
µLªk¤À¿ë¥X¨Ó·½ºÝIPªº¤£¦P¡C

¨º¦ó®É¤~·|¥Î¨ì¦¹¨Ó·½ºÝÂà§}ªº¥\¯à¡H
³o­Ó¹À¡A¦bloopback³W«hªº³]©w¤¤´N·|¬Ý¨ì¦¹¥\¯àªºÀ³¥Î¡C


¥t¥~¡A¦b¤U¤èÁÙ¦³¤@­ÓCreate Reflexive Ruleªº¿ï¶µ¥i¥H±Ò¥Î¡C
²z½×¤W¦b±Ò¥Î«á¡A¸Ó¤º³¡ªA°È¥D¾÷¥~³s®É¡A´N·|¦Û°ÊÂà´«¬°WAN¤WªºAlias IP¦A³s¥~¡A
¦Ó¤£¬O¥H¹w³]ªºMASQ¹ï¥~¦^À³¡A³o¦bmail³q°T®ÉÁÙº¡­«­nªº¡A
±Ò¥Î¦¹¶µ¥Øªº¥Î·N¬O½T«O¤º³¡¥D¾÷¨Ó¦^¶Ç»¼®É¡A·|¥H¬Û¦PIP¶i¦æ¦^À³¡C



¦ý³o­Ó¥\¯à¦³­ì¼t¤£Ä@·N©Ó»{ªºbug¡A¶¶¤l·|¦b¤U¤@½g¸ò¤j®a°Q½×¡C
©Ò¥H¦b«Ø¥ßVirtual IP³W«h®É¡A½Ð°È¥²¤£­n±Ò¥Îreflexive³o­Ó¶µ¥Ø¡I


¥H¤W«Ø¥ß¨BÆJ§¹¦¨«á¡A§Ú­Ì´N¥i¥H¦b´y­z¤¤²M·¡ªº¬Ý¨ì¡A
³o³W«h¬O§â¥~³¡IP 211.75.130.142ªº¥ô¦óªA°ÈÂà¾É¨ì¤º³¡IP 192.168.30.101³o¥xServer¥h¡A
§¹¦¨§Ú­Ì¥~³¡¹êÅéIP¬M®g¨ì¤º³¡µêÀÀIPªº»Ý¨D¡ã



Virtual IPªº³W«h«Ø¥ß¨ì¦¹§¹¦¨¡A
ÁöµM¤ñCyberoam½ÆÂø³\¦h¡A¦ýÀ´±o¨ä²Ó¶µ¥\¯à·N¸q«á¡A¦h³]­Ó´X¦¸«á¡AÀ³¸Ó¤]´N²ßºD¤F¡ã



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2016-09-05, 16:37 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2380

shunze Â÷½u
¡m¤À¨É¡n¤â°Ê¦Û¦æ«Ø¥ßReflexive Rule¤Þ¥Î¦^ÂÐ ½s¿è/§R°£¤å³¹ ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¦b¤W¤@½g Virtual IP³]©w ¤¤¦³´£¨ì¡Areflexive¥\¯à¦³­Ó­ì¼t¤£Ä@·N©Ó¿Õªºbug¡C

³o­Óbugªº²£¥Í¡A¬O¦]¬°¦bXG¤¤±Ò¥Îreflexive¥\¯à«á¡A
XG¥u·|«Ø¥ß¤@­Ó¤Ï¦V³W«hµ¹¸ÓªA°È¥D¾÷³s¥~¨Ï¥Î¡C

­ì¼tDavid¦^ÂЦp¤U¡A

Shunze¡A

¦bBusiness Application Rule¤¤ªºReflexive Rule¿ï¶µªº·N¸q¡A¬O¨t²Î·|¦Û°Ê«Ø¥ß¥t¤@±ø¬Û¦P±ø¥óªº³W«h¡A¦ý¬O±N¨Ó·½©M¥ØªºÄæ¦ìªº­È¹ï½Õ¡C
¦]¦¹¡A©Ò¥H¦³ªº³]©w¤¤¡A¤]·|¥]§t¨ìNATªº³]©w¡C
°²¦p±z¦b³]©wBusiness Application Rule®É¡A¨S¦³±NNAT¿ï¶µ±Ò¥Î¡C
¨t²Î¦Û°Ê«Ø¥ßªº³W«h¡A¦ÛµM¤]¤£·|±Ò¥ÎNAT¡A¤]´N·|³y¦¨³s½u¨ìºô»Úºô¸ô¥¢±Ñªºª¬ªp¡C

¦]¦¹¡A«Øij¥i¥H¦Û¦æ«Ø¥ßNetwork Rule¨Ó°µ¬°¹ï¥~³s½uªº³W«h¡A³o¼Ë·|¤ñ¸û¦X²z¡C

¨ä·N¬°
­ì¥»¥~¹ï¤ºªºVirtual IP³W«h¤¤¥¼¥[NAT¡A©Ò¥Hreflexive«áªº¤º¹ï¥~¡A¤]¤£·|¥[NAT¡C

¦Ó¦ì¦b¤º³¡ªºªA°È¥D¾÷¨äIP¬O¨p¦³IP¡A
½Ð°Ý¦U¦ì¡A­Y¤£°µNAT¡A¨p¦³IP¦³¿ìªkª½±µ³s¥~¶Ü¡H
µª®×·íµM¬O§_©wªº¡C

¦Ó³o­ÓXG¦Û«Øªºreflexive³W«h¤£¶È¬Ý¤£¨ì¡A¤]¤£´£¨Ñ­×§ï¡F
©Ò¥H³o­ÓXG¦Û±aªºreflexive³W«h®Ú¥»´N¬O­ÓÂû¦Ø¡C

¥¦°ß¤@¾A¥Îªº±¡¹Ò¬O¡A·í¥~¹ï¤ºªºVirtual IP³W«h¤¤¡A¦³±Ò¥Î¨Ó·½ºÝÂà§}(NAT)®É¡Areflexive¥\¯à¤~¯à¥¿±`¹B§@¡F
¦ý¤@¥¹®M¥ÎNAT«á¡A«áºÝªA°È¥D¾÷¤]µL±qÃѧO¥~¬É³X«Èªº­Ó§OIP¡I¡H
©Ò¥H±Ò¥ÎNAT«á¡Areflexive¤~¯à¥¿±`¹B§@®Ú¥»´N¬OÂû¦Ø¡I



©ê«è§¹¤F¡A±µµÛ¨Ó¬Ý¬Ý¦p¦ó¥¿±`ªº«Ø¥ß¤@­ÓReflexive Rule¡H

¨ä¹ê«Ü²³æ¡A´N¬O¤â°Ê«Ø¤@±ø¤º¹ï¥~ªºNetwork Policy¡A¨Ã«ü©wMASQ­nÂà¨ìAlias IP¡A
µM«á²¾¨ìVirtual IP policy¤§«e¡AÅý¥¦¤ñVirtual IPªº³W«h´£¦­¥Í®Ä¡C









³o¼Ë¤£¬O¦³ÂI³Â·Ð¶Ü¡H

¨S¿ù¡Areflexive rule¦bCyberoam¬O¥¿½Tªº¡A¦Ó¥B¤]¥i¥H­×§ïªº¡C

¦ý¬JµM¥Î¤FXG¡A­±¹ï³o¼Ëªºbug¡A­ì¼t¿ï¾ÜµLµø¥¦¡H¨º§Ú­Ì¥u¯à±µ¨ü¥¦¡B©ñ¤U¥¦¡F
©ñ±ó©ÎµLµø³o­Ó¥\¯à¡AµM«á¨Ä¨Äªº¦Û¦æ¤â°Ê«Ø¥ßreflexive³W«h...



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2016-09-09, 11:18 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
  « ¤W¤@½g¥DÃD ¤U¤@½g¥DÃD »
µoªí·s¥DÃD µoªí¦^ÂÐ
¸õ¨ì:

Powered by: Burning Board 1.1.1 2001 WoltLab GbR