1.将左半部划分为内部区域,右半部划分为外部区域
2.进行IP规划和配置
[r1-GigabitEthernet0/0/0]ip address 192.168.1.1 24
[r1-GigabitEthernet0/0/1]ip address 12.1.1.1 24
[r2-GigabitEthernet0/0/0]ip address 12.1.1.2 24
[r2-GigabitEthernet0/0/1]ip address 1.1.1.1 24
(如图所示,P2为192.168.1.3 /24 ,Server1为192.168.1.4 /24 ,Server2为192.168.1.5 /24 ,Client1为1.1.1.2 /24, DNS为1.1.1.3 /24)
进行ACL配置
[r1]acl 2000
[r1-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[r1]int g 0/0/1
[r1-GigabitEthernet0/0/1]nat outbound 2000
[r1]ip route-static 0.0.0.0 0 12.1.1.2
[r1-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 8888 inside 192.168.1.5 80
[r1-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 80 inside 192.168.1.4 80
Warning:The port 80 is well-known port. If you continue it may cause function failure.
Are you sure to continue?[Y/N]:y
配置对应客户端
DNS
HTTP
最后使用平版客户端进行搜索