asa 5510 端口映射问题
asa双ISP,外网访问没问题,现在电信端口上做端口映射,感觉应该配置都没问题,可还是不行,各位大侠帮我分析一下。下面是关键配置
interface Ethernet0/0
description to chinanet
nameif outside
security-level 0
ip address 60.191.*.* 255.255.255.240
interface Ethernet0/1
description to chinacnc
nameif wt
security-level 0
ip address 221.12.*.* 255.255.255.248
interface Ethernet0/2
nameif inside
security-level 100
ip address 192.168.1.1 255.255.255.0
access-list 110 extended permit ip any any
access-list 110 extended permit icmp any any
access-list 110 extended permit tcp any any
access-list 110 extended permit tcp any host 192.168.1.87 eq ftp
access-list 111 extended permit ip any any
global (outside) 1 interface
global (wt) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0
static (inside,outside) tcp 60.191.*.* ftp 192.168.1.87 ftp netmask 255.255.255.255
access-group 110 in interface outside
access-group 111 in interface wt
route outside 0.0.0.0 0.0.0.0 60.191.*.* 1
route wt 0.0.0.0 0.0.0.0 221.12.*.* 254