示例:在 MX-SPC3 服务卡上配置 DNS ALG 应用程序
此示例说明如何将转换类型配置为 basic-nat-pt。您必须配置 DNS ALG 应用程序、NAT 池和规则、带有服务接口的服务集。
要求
此示例使用以下硬件和软件组件:
- MX240、MX480 和 MX960 以及 MX-SPC3
- Junos OS 21.1R1 版
配置
要在 MX-SPC3 服务卡上配置 DNS ALG 应用程序,请执行以下任务:
-
设置应用程序。
[edit] user@host# set application application-name application-protocol protocol-name
-
配置服务集。
[edit] user@host# set services service-set ss1 syslog mode event
user@host# set services service-set ss1 syslog mode event
-
3. 使用 NAT 规则配置服务集。
[edit] user@host# set services service-set ss1 nat-rule-sets src_nat_rule_set1
user@host# set services service-set ss1 nat-rule-sets dst_nat_rule_set1
user@host# set services service-set ss1 interface-service service-interface vms-2/0/0.0
-
指定 NAT 池和规则信息。
[edit] user@host# set services nat source pool source_pool1 address 100.0.0.0/24
user@host# set services nat source rule-set src_nat_rule_set1 rule source_nat_rule1 match source-address 2000::/64
user@host# set services nat source rule-set src_nat_rule_set1 rule source_nat_rule1 match destination-address 0.0.0.0/0
user@host# set services nat source rule-set src_nat_rule_set1 rule source_nat_rule1 match application dns_alg
user@host# set services nat source rule-set src_nat_rule_set1 rule source_nat_rule1 then source-nat pool source_pool1
user@host# set services nat source rule-set src_nat_rule_set1 rule source_nat_rule1 then syslog
user@host# set services nat source rule-set src_nat_rule_set1 match-direction input
user@host# set services nat destination rule-set dst_nat_rule_set1 rule dst_nat_rule1 match source-address 2000::/64
user@host# set services nat destination rule-set dst_nat_rule_set1 rule dst_nat_rule1 match destination-address 6000::/96
user@host# set services nat destination rule-set dst_nat_rule_set1 rule dst_nat_rule1 match application dns_alg
user@host# set services nat destination rule-set dst_nat_rule_set1 rule dst_nat_rule1 then destination-nat destination-prefix 6000::/96
user@host# set services nat destination rule-set dst_nat_rule_set1 rule dst_nat_rule1 then syslog
user@host# set services nat destination rule-set dst_nat_rule_set1 match-direction input
-
配置接口。
[edit] user@host# set interfaces vms-2/0/0 unit 0 family inet
user@host# set interfaces vms-2/0/0 unit 0 family inet6
结果
[edit] user@host# show services service-set ss1 { syslog { mode event; local-category all; } nat-rule-sets src_nat_rule_set1; nat-rule-sets dst_nat_rule_set1; interface-service { service-interface vms-2/0/0.0; } } nat { source { pool source_pool1 { address { 100.0.0.0/24; } } rule-set src_nat_rule_set1 { rule source_nat_rule1 { match { source-address 2000::/64; destination-address 0.0.0.0/0; application dns_alg; } then { source-nat { pool { source_pool1; } } syslog; } } match-direction input; } } destination { rule-set dst_nat_rule_set1 { rule dst_nat_rule1 { match { source-address 2000::/64; destination-address 6000::/96; application dns_alg } then { destination-nat { destination-prefix 6000::/96; } syslog; } } match-direction input; } } }