多谢楼主
先谢谢楼主了,可否帮忙看下我这个配制
我这是一家有200台机器的网吧,用的是锐捷的NBR1000E,10M光纤
配制如下,麻烦您帮我看看有什么问题..
access-list 3199 deny tcp any any eq 135
access-list 3199 deny tcp any any eq 445
access-list 3199 deny tcp any eq 135 any
access-list 3199 deny udp any any eq 135
access-list 3199 deny udp any eq 135 any
access-list 3199 deny tcp any any eq 136
access-list 3199 deny udp any any eq 136
access-list 3199 deny tcp any any eq 137
access-list 3199 deny tcp any any eq 138
access-list 3199 deny tcp any any eq 256
access-list 3199 deny tcp any eq 445 any
access-list 3199 deny udp any any eq 445
access-list 3199 deny tcp any any eq 593
access-list 3199 deny tcp any any eq 768
access-list 3199 deny tcp any any eq 1025
access-list 3199 deny tcp any any eq 1068
access-list 3199 deny tcp any any eq 1080
access-list 3199 deny tcp any any eq 1081
access-list 3199 deny tcp any any eq 1433
access-list 3199 deny tcp any eq 1433 any
access-list 3199 deny udp any any eq 1433
access-list 3199 deny tcp any any eq 1434
access-list 3199 deny udp any any eq 1434
access-list 3199 deny tcp any any eq 4444
access-list 3199 deny tcp any eq 4444 any
access-list 3199 deny udp any any eq 4444
access-list 3199 deny tcp any any eq 5554
access-list 3199 deny tcp any any eq 5800
access-list 3199 deny tcp any any eq 5900
access-list 3199 deny tcp any any eq 6667
access-list 3199 deny tcp any any eq 9995
access-list 3199 deny tcp any any eq 9996
access-list 3199 deny tcp any any eq 29851
access-list 3199 deny tcp any eq 29851 any
access-list 3199 deny udp any any eq 29851
access-list 3199 deny tcp any any eq 34385
access-list 3199 deny tcp any any eq www
access-list 3199 permit ip any any
access-list 101 deny tcp any any eq 135
access-list 101 deny tcp any any eq 445
access-list 101 deny tcp any eq 135 any
access-list 101 deny udp any any eq 135
access-list 101 deny udp any eq 135 any
access-list 101 deny tcp any any eq 136
access-list 101 deny udp any any eq 136
access-list 101 deny tcp any any eq 137
access-list 101 deny tcp any any eq 138
access-list 101 deny tcp any any eq 256
access-list 101 deny tcp any eq 445 any
access-list 101 deny udp any any eq 445
access-list 101 deny tcp any any eq 593
access-list 101 deny tcp any any eq 768
access-list 101 deny tcp any any eq 1025
access-list 101 deny tcp any any eq 1068
access-list 101 deny tcp any any eq 1080
access-list 101 deny tcp any any eq 1081
access-list 101 deny tcp any any eq 1433
access-list 101 deny tcp any eq 1433 any
access-list 101 deny udp any any eq 1433
access-list 101 deny tcp any any eq 1434
access-list 101 deny udp any any eq 1434
access-list 101 deny tcp any any eq 4444
access-list 101 deny tcp any eq 4444 any
access-list 101 deny udp any any eq 4444
access-list 101 deny tcp any any eq 5554
access-list 101 deny tcp any any eq 5800
access-list 101 deny tcp any any eq 5900
access-list 101 deny tcp any any eq 6667
access-list 101 deny tcp any any eq 9995
access-list 101 deny tcp any any eq 9996
access-list 101 deny tcp any any eq 29851
access-list 101 deny tcp any eq 29851 any
access-list 101 deny udp any any eq 29851
access-list 101 deny tcp any any eq 34385
access-list 101 permit ip 124.192.95.0 0.0.0.255 any
access-list 101 deny ip any any
access-list 102 permit ip any host 172.30.23.146
access-list 102 permit ip any host 124.192.95.1
!
service timestamps debug datetime
service timestamps log datetime
no service password-encryption
!
!
!
!
interface FastEthernet 0/0
ip nat inside
ip access-group 101 in
ip address 124.192.95.1 255.255.255.0
arp gratuitous-send interval 1
!
interface FastEthernet 1/0
ip nat outside
ip access-group 3199 in
ip address 172.30.23.146 255.255.255.252
rate-limit input access-group 102 64000 3000 3000 conform-action transmit exce
ed-action drop
duplex auto
speed auto
!
interface FastEthernet 1/1
duplex auto
speed auto
shutdown
!
interface Null 0
!
!
ip nat pool nbr_setup_build_pool prefix-length 24
address 172.30.23.146 172.30.23.146 match interface FastEthernet 1/0
!
ip nat translation per-user 0.0.0.0 200
ip nat translation rate-limit iprange 124.192.95.250 124.192.95.250 inbound 2000
outbound 2000
ip nat translation rate-limit iprange 124.192.95.251 124.192.95.251 inbound 400
outbound 2000
ip nat translation rate-limit iprange 124.192.95.2 124.192.95.199 inbound 300 ou
tbound 800