interface Ethernet0/0
nameif outside
security-level 0
ip address 116.228.1.? 255.255.255.X
interface Ethernet0/1
nameif inside
security-level 100
ip address 192.168.9.1 255.255.255.0
!
interface Ethernet0/2
shutdown
no nameif
no security-level
no ip address
!
access-list nat-only extended permit ip 192.168.9.0 255.255.255.0 any
access-list out-from extended permit ip any any
pager lines 24
logging asdm informational
mtu outside 1500
mtu inside 1500
mtu management 1500
no asdm history enable
arp timeout 14400
nat-control
global (outside) 1 interface
nat (inside) 1 access-list nat-only
nat (inside) 1 192.168.9.0 255.255.255.0
access-group out-from in interface outside
配置路由
route outside 0.0.0.0 0.0.0.0 网关IP
配置NAT
nat (inside) 1 0.0.0.0 0.0.0.0
global (outside) 1 interface
要做NAT,你内部的私有IP是不会在公网被转发的。
你需要NAT和Policy