5. ืชื—ื™ืœืช ื”ืขื‘ื•ื“ื” ืฉืœ Fortinet v6.0. NAT

5. ืชื—ื™ืœืช ื”ืขื‘ื•ื“ื” ืฉืœ Fortinet v6.0. NAT

ื‘ืจื›ื•ืช! ื‘ืจื•ื›ื™ื ื”ื‘ืื™ื ืœืฉื™ืขื•ืจ ื”ื—ืžื™ืฉื™ ืฉืœ ื”ืงื•ืจืก ืคื•ืจื˜ื™ื ื˜ ืชื—ื™ืœืช ื”ืขื‘ื•ื“ื”. ืขืœ ืฉื™ืขื•ืจ ืื—ืจื•ืŸ ื”ื‘ื ื• ื›ื™ืฆื“ ืคื•ืขืœืช ืžื“ื™ื ื™ื•ืช ื”ืื‘ื˜ื—ื”. ืขื›ืฉื™ื• ื”ื’ื™ืข ื”ื–ืžืŸ ืœืฉื—ืจืจ ืžืฉืชืžืฉื™ื ืžืงื•ืžื™ื™ื ืœืื™ื ื˜ืจื ื˜. ืœืฉื ื›ืš, ื‘ืฉื™ืขื•ืจ ื–ื” ื ื‘ื—ืŸ ืืช ืคืขื•ืœืช ืžื ื’ื ื•ืŸ ื”-NAT.
ื‘ื ื•ืกืฃ ืœืฉื—ืจื•ืจ ืžืฉืชืžืฉื™ื ืœืื™ื ื˜ืจื ื˜, ื ื‘ื—ืŸ ื’ื ืฉื™ื˜ื” ืœืคืจืกื•ื ืฉื™ืจื•ืชื™ื ืคื ื™ืžื™ื™ื. ืžืชื—ืช ืœื’ื–ืจื” ื™ืฉื ื” ืชื™ืื•ืจื™ื” ืงืฆืจื” ืžื”ืกืจื˜ื•ืŸ, ื›ืžื• ื’ื ืฉื™ืขื•ืจ ื”ื•ื•ื™ื“ืื• ืขืฆืžื•.
ื˜ื›ื ื•ืœื•ื’ื™ื™ืช NAT (ืชืจื’ื•ื ื›ืชื•ื‘ื•ืช ืจืฉืช) ื”ื™ื ืžื ื’ื ื•ืŸ ืœื”ืžืจืช ื›ืชื•ื‘ื•ืช IP ืฉืœ ืžื ื•ืช ืจืฉืช. ื‘ืžื•ื ื—ื™ื ืฉืœ Fortinet, NAT ืžื—ื•ืœืง ืœืฉื ื™ ืกื•ื’ื™ื: ืžืงื•ืจ NAT ื•-Destination NAT.

ื”ืฉืžื•ืช ืžื“ื‘ืจื™ื ื‘ืขื“ ืขืฆืžื - ื‘ืฉื™ืžื•ืฉ ื‘ืžืงื•ืจ NAT ื›ืชื•ื‘ืช ื”ืžืงื•ืจ ืžืฉืชื ื”, ื‘ืฉื™ืžื•ืฉ ื‘-Destination NAT ืžืฉืชื ื” ื›ืชื•ื‘ืช ื”ื™ืขื“.

ื‘ื ื•ืกืฃ, ืงื™ื™ืžื•ืช ื’ื ืžืกืคืจ ืืคืฉืจื•ื™ื•ืช ืœื”ื’ื“ืจืช NAT - Firewall Policy NAT ื•-Central NAT.

5. ืชื—ื™ืœืช ื”ืขื‘ื•ื“ื” ืฉืœ Fortinet v6.0. NAT

ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืืคืฉืจื•ืช ื”ืจืืฉื•ื ื”, ื™ืฉ ืœื”ื’ื“ื™ืจ ืžืงื•ืจ ื•ื™ืขื“ NAT ืขื‘ื•ืจ ื›ืœ ืžื“ื™ื ื™ื•ืช ืื‘ื˜ื—ื”. ื‘ืžืงืจื” ื–ื”, ืžืงื•ืจ NAT ืžืฉืชืžืฉ ื‘ื›ืชื•ื‘ืช ื”-IP ืฉืœ ื”ืžืžืฉืง ื”ื™ื•ืฆื ืื• ื‘ืžืื’ืจ IP ืžื•ื’ื“ืจ ืžืจืืฉ. Destination NAT ืžืฉืชืžืฉ ื‘ืื•ื‘ื™ื™ืงื˜ ืžื•ื’ื“ืจ ืžืจืืฉ (ืžื” ืฉื ืงืจื VIP - Virtual IP) ื›ื›ืชื•ื‘ืช ื”ื™ืขื“.

ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-Central NAT, ืชืฆื•ืจืช ื”-NAT ืฉืœ ื”ืžืงื•ืจ ื•ื”ื™ืขื“ ืžืชื‘ืฆืขืช ืขื‘ื•ืจ ื›ืœ ื”ืžื›ืฉื™ืจ (ืื• ื”ืชื—ื•ื ื”ื•ื•ื™ืจื˜ื•ืืœื™) ื‘ื‘ืช ืื—ืช. ื‘ืžืงืจื” ื–ื”, ื”ื’ื“ืจื•ืช NAT ื—ืœื•ืช ืขืœ ื›ืœ ื”ืžื“ื™ื ื™ื•ืช, ื‘ื”ืชืื ืœื›ืœืœื™ ื”ืžืงื•ืจ NAT ื•ื”-Destination NAT.

ื›ืœืœื™ ืžืงื•ืจ NAT ืžื•ื’ื“ืจื™ื ื‘ืžื“ื™ื ื™ื•ืช ื”-Source NAT ื”ืžืจื›ื–ื™ืช. ื™ืขื“ NAT ืžื•ื’ื“ืจ ืžืชืคืจื™ื˜ DNAT ื‘ืืžืฆืขื•ืช ื›ืชื•ื‘ื•ืช IP.

ื‘ืฉื™ืขื•ืจ ื–ื” ื ืฉืงื•ืœ ืจืง Firewall Policy NAT - ื›ืคื™ ืฉืžืจืื” ื‘ืคื•ืขืœ, ืืคืฉืจื•ืช ืชืฆื•ืจื” ื–ื• ื ืคื•ืฆื” ื”ืจื‘ื” ื™ื•ืชืจ ืžืืฉืจ Central NAT.

ื›ืคื™ ืฉื›ื‘ืจ ืืžืจืชื™, ื‘ืขืช ื”ื’ื“ืจืช Firewall Policy Source NAT, ื™ืฉื ืŸ ืฉืชื™ ืืคืฉืจื•ื™ื•ืช ืชืฆื•ืจื”: ื”ื—ืœืคืช ื›ืชื•ื‘ืช ื”-IP ื‘ื›ืชื•ื‘ืช ืฉืœ ื”ืžืžืฉืง ื”ื™ื•ืฆื, ืื• ื‘ื›ืชื•ื‘ืช IP ืžืžืื’ืจ ื›ืชื•ื‘ื•ืช IP ืžื•ื’ื“ืจ ืžืจืืฉ. ื–ื” ื ืจืื” ืžืฉื”ื• ื›ืžื• ื–ื” ืฉืžื•ืฆื’ ื‘ืื™ื•ืจ ืœืžื˜ื”. ืœืื—ืจ ืžื›ืŸ, ืื“ื‘ืจ ื‘ืงืฆืจื” ืขืœ ื‘ืจื™ื›ื•ืช ืืคืฉืจื™ื•ืช, ืืš ื‘ืคื•ืขืœ ื ืฉืงื•ืœ ืจืง ืืช ื”ืื•ืคืฆื™ื” ืขื ื›ืชื•ื‘ืช ื”ืžืžืฉืง ื”ื™ื•ืฆื โ€“ ื‘ืคืจื™ืกื” ืฉืœื ื•, ืื™ื ื ื• ืฆืจื™ื›ื™ื ื‘ืจื™ื›ื•ืช ื›ืชื•ื‘ื•ืช IP.

5. ืชื—ื™ืœืช ื”ืขื‘ื•ื“ื” ืฉืœ Fortinet v6.0. NAT

ืžืื’ืจ IP ืžื’ื“ื™ืจ ื›ืชื•ื‘ืช IP ืื—ืช ืื• ื™ื•ืชืจ ืฉืชืฉืžืฉ ื›ื›ืชื•ื‘ืช ื”ืžืงื•ืจ ื‘ืžื”ืœืš ื”ืคื’ื™ืฉื”. ื›ืชื•ื‘ื•ืช IP ืืœื• ื™ืฉืžืฉื• ื‘ืžืงื•ื ื›ืชื•ื‘ืช ื”-IP ืฉืœ ืžืžืฉืง ื”ื™ื•ืฆื FortiGate.

ื™ืฉื ื 4 ืกื•ื’ื™ื ืฉืœ ื‘ืจื™ื›ื•ืช IP ืฉื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ื‘-FortiGate:

  • ืœื”ืขืžื™ืก ื™ื•ืชืจ ืžื“ื™
  • ืื—ื“ ืœืื—ื“
  • ื˜ื•ื•ื— ื ืžืœ ืงื‘ื•ืข
  • ื”ืงืฆืืช ื‘ืœื•ืง ื™ืฆื™ืื”

ืขื•ืžืก ื™ืชืจ ื”ื•ื ืžืื’ืจ ื”-IP ื”ืจืืฉื™. ื–ื” ืžืžื™ืจ ื›ืชื•ื‘ื•ืช IP ื‘ืืžืฆืขื•ืช ืกื›ื™ืžืช ืจื‘ื™ื ืœืื—ื“ ืื• ืจื‘ื™ื ืœืจื‘ื™ื. ื ืขืฉื” ืฉื™ืžื•ืฉ ื’ื ื‘ืชืจื’ื•ื ืคื•ืจื˜ื™ื. ืฉืงื•ืœ ืืช ื”ืžืขื’ืœ ื”ืžื•ืฆื’ ื‘ืื™ื•ืจ ืœืžื˜ื”. ื™ืฉ ืœื ื• ื—ื‘ื™ืœื” ืขื ืฉื“ื•ืช ืžืงื•ืจ ื•ื™ืขื“ ืžื•ื’ื“ืจื™ื. ืื ื”ื•ื ืžื’ื™ืข ืชื—ืช ืžื“ื™ื ื™ื•ืช ื—ื•ืžืช ืืฉ ื”ืžืืคืฉืจืช ืœื—ื‘ื™ืœื” ื–ื• ืœื’ืฉืช ืœืจืฉืช ื”ื—ื™ืฆื•ื ื™ืช, ื›ืœืœ NAT ืžื•ื—ืœ ืขืœื™ื”. ื›ืชื•ืฆืื” ืžื›ืš, ื‘ื—ื‘ื™ืœื” ื–ื• ืฉื“ื” ื”ืžืงื•ืจ ืžื•ื—ืœืฃ ื‘ืื—ืช ืžื›ืชื•ื‘ื•ืช ื”-IP ืฉืฆื•ื™ื ื• ื‘ืžืื’ืจ ื”-IP.

5. ืชื—ื™ืœืช ื”ืขื‘ื•ื“ื” ืฉืœ Fortinet v6.0. NAT

ืžืื’ืจ ืื—ื“ ืœืื—ื“ ืžื’ื“ื™ืจ ื’ื ื›ืชื•ื‘ื•ืช IP ื—ื™ืฆื•ื ื™ื•ืช ืจื‘ื•ืช. ื›ืืฉืจ ืžื ื” ื ื•ืคืœืช ืชื—ืช ืžื“ื™ื ื™ื•ืช ื—ื•ืžืช ืืฉ ื›ืืฉืจ ื›ืœืœ ื”-NAT ืžื•ืคืขืœ, ื›ืชื•ื‘ืช ื”-IP ื‘ืฉื“ื” ื”ืžืงื•ืจ ืžืฉืชื ื” ืœืื—ืช ืžื”ื›ืชื•ื‘ื•ืช ื”ืฉื™ื™ื›ื•ืช ืœืžืื’ืจ ื–ื”. ื”ื”ื—ืœืคื” ืคื•ืขืœืช ื‘ื”ืชืื ืœื›ืœืœ "ื ื›ื ืก ืจืืฉื•ืŸ, ื™ื•ืฆื ืจืืฉื•ืŸ". ื›ื“ื™ ืœื”ื‘ื”ื™ืจ ืืช ื–ื”, ื‘ื•ืื• ื ืกืชื›ืœ ืขืœ ื“ื•ื’ืžื”.

ืžื—ืฉื‘ ื‘ืจืฉืช ื”ืžืงื•ืžื™ืช ืขื ื›ืชื•ื‘ืช IP 192.168.1.25 ืฉื•ืœื— ืžื ื” ืœืจืฉืช ื”ื—ื™ืฆื•ื ื™ืช. ื–ื” ื ื•ืคืœ ืชื—ืช ื›ืœืœ NAT, ื•ื”ืฉื“ื” Source ืžืฉืชื ื” ืœื›ืชื•ื‘ืช ื”-IP ื”ืจืืฉื•ื ื” ืžื”ืžืื’ืจ, ื‘ืžืงืจื” ืฉืœื ื• ื–ื” 83.235.123.5. ืจืื•ื™ ืœืฆื™ื™ืŸ ื›ื™ ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืžืื’ืจ IP ื–ื”, ืœื ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืชืจื’ื•ื ืคื•ืจื˜ื™ื. ืื ืœืื—ืจ ืžื›ืŸ ืžื—ืฉื‘ ืžืื•ืชื” ืจืฉืช ืžืงื•ืžื™ืช, ืขื ื›ืชื•ื‘ืช ืฉืœ, ืœืžืฉืœ, 192.168.1.35, ืฉื•ืœื— ื—ื‘ื™ืœื” ืœืจืฉืช ื—ื™ืฆื•ื ื™ืช ื•ื’ื ื ื•ืคืœ ืชื—ืช ื›ืœืœ NAT ื–ื”, ื›ืชื•ื‘ืช ื”-IP ื‘ืฉื“ื” ื”ืžืงื•ืจ ืฉืœ ืžื ื” ื–ื• ืชืฉืชื ื” ืœ- 83.235.123.6. ืื ืœื ื™ื™ืฉืืจื• ื›ืชื•ื‘ื•ืช ื ื•ืกืคื•ืช ื‘ืžืื’ืจ, ื”ื—ื™ื‘ื•ืจื™ื ื”ื‘ืื™ื ื™ื™ื“ื—ื•. ื›ืœื•ืžืจ, ื‘ืžืงืจื” ื–ื”, 4 ืžื—ืฉื‘ื™ื ื™ื›ื•ืœื™ื ืœื™ืคื•ืœ ืชื—ืช ื›ืœืœ ื”-NAT ืฉืœื ื• ื‘ื•-ื–ืžื ื™ืช.

5. ืชื—ื™ืœืช ื”ืขื‘ื•ื“ื” ืฉืœ Fortinet v6.0. NAT

Fixed Port Range ืžื—ื‘ืจ ื‘ื™ืŸ ื˜ื•ื•ื—ื™ื ืคื ื™ืžื™ื™ื ื•ื—ื™ืฆื•ื ื™ื™ื ืฉืœ ื›ืชื•ื‘ื•ืช IP. ืชืจื’ื•ื ืคื•ืจื˜ ืžื•ืฉื‘ืช ื’ื ื”ื•ื. ื–ื” ืžืืคืฉืจ ืœืš ืœืฉื™ื™ืš ืœืฆืžื™ืชื•ืช ืืช ื”ื”ืชื—ืœื” ืื• ื”ืกื•ืฃ ืฉืœ ืžืื’ืจ ื›ืชื•ื‘ื•ืช IP ืคื ื™ืžื™ื•ืช ืขื ื”ื”ืชื—ืœื” ืื• ื”ืกื•ืฃ ืฉืœ ืžืื’ืจ ื›ืชื•ื‘ื•ืช IP ื—ื™ืฆื•ื ื™ื•ืช. ื‘ื“ื•ื’ืžื” ืœืžื˜ื”, ืžืื’ืจ ื”ื›ืชื•ื‘ื•ืช ื”ืคื ื™ืžื™ 192.168.1.25 - 192.168.1.28 ืžืžื•ืคื” ืœืžืื’ืจ ื”ื›ืชื•ื‘ื•ืช ื”ื—ื™ืฆื•ื ื™ 83.235.123.5 - 83.235.125.8.

5. ืชื—ื™ืœืช ื”ืขื‘ื•ื“ื” ืฉืœ Fortinet v6.0. NAT

ื”ืงืฆืืช ื‘ืœื•ืง ื™ืฆื™ืื•ืช - ืžืื’ืจ IP ื–ื” ืžืฉืžืฉ ืœื”ืงืฆืืช ื‘ืœื•ืง ื™ืฆื™ืื•ืช ืขื‘ื•ืจ ืžืฉืชืžืฉื™ ืžืื’ืจ IP. ื‘ื ื•ืกืฃ ืœืžืื’ืจ ื”-IP ืขืฆืžื•, ื™ืฉ ืœืฆื™ื™ืŸ ื›ืืŸ ื’ื ืฉื ื™ ืคืจืžื˜ืจื™ื - ื’ื•ื“ืœ ื”ื‘ืœื•ืง ื•ืžืกืคืจ ื”ื‘ืœื•ืงื™ื ืฉื”ื•ืงืฆื• ืœื›ืœ ืžืฉืชืžืฉ.

5. ืชื—ื™ืœืช ื”ืขื‘ื•ื“ื” ืฉืœ Fortinet v6.0. NAT

ืขื›ืฉื™ื• ื‘ื•ืื• ื ืกืชื›ืœ ืขืœ ื˜ื›ื ื•ืœื•ื’ื™ื™ืช Destination NAT. ื”ื•ื ืžื‘ื•ืกืก ืขืœ ื›ืชื•ื‘ื•ืช IP ื•ื™ืจื˜ื•ืืœื™ื•ืช (VIP). ืขื‘ื•ืจ ืžื ื•ืช ืฉื ื•ืคืœื•ืช ืชื—ืช ื›ืœืœื™ Destination NAT, ื›ืชื•ื‘ืช ื”-IP ื‘ืฉื“ื” Destination ืžืฉืชื ื”: ื‘ื“ืจืš ื›ืœืœ ื›ืชื•ื‘ืช ื”ืื™ื ื˜ืจื ื˜ ื”ืฆื™ื‘ื•ืจื™ืช ืžืฉืชื ื” ืœื›ืชื•ื‘ืช ื”ืคืจื˜ื™ืช ืฉืœ ื”ืฉืจืช. ื›ืชื•ื‘ื•ืช IP ื•ื™ืจื˜ื•ืืœื™ื•ืช ืžืฉืžืฉื•ืช ื‘ืžื“ื™ื ื™ื•ืช ื—ื•ืžืช ืืฉ ื‘ืชื•ืจ ื”ืฉื“ื” 'ื™ืขื“'.

ื”ืกื•ื’ ื”ืกื˜ื ื“ืจื˜ื™ ืฉืœ ื›ืชื•ื‘ื•ืช IP ื•ื™ืจื˜ื•ืืœื™ื•ืช ื”ื•ื Static NAT. ืžื“ื•ื‘ืจ ื‘ื”ืชื›ืชื‘ื•ืช ืื—ื“ ืขืœ ืื—ื“ ื‘ื™ืŸ ื›ืชื•ื‘ื•ืช ื—ื™ืฆื•ื ื™ื•ืช ื•ืคื ื™ืžื™ื•ืช.

ื‘ืžืงื•ื NAT ืกื˜ื˜ื™, ื ื™ืชืŸ ืœื”ื’ื‘ื™ืœ ื›ืชื•ื‘ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ืขืœ ื™ื“ื™ ื”ืขื‘ืจืช ื™ืฆื™ืื•ืช ืกืคืฆื™ืคื™ื•ืช. ืœื“ื•ื’ืžื”, ืฉื™ื™ืš ื—ื™ื‘ื•ืจื™ื ืœื›ืชื•ื‘ืช ื—ื™ืฆื•ื ื™ืช ื‘ื™ืฆื™ืื” 8080 ืœื—ื™ื‘ื•ืจ ืœื›ืชื•ื‘ืช IP ืคื ื™ืžื™ืช ื‘ื™ืฆื™ืื” 80.

ื‘ื“ื•ื’ืžื” ืœืžื˜ื”, ืžื—ืฉื‘ ืขื ื”ื›ืชื•ื‘ืช 172.17.10.25 ืžื ืกื” ืœื’ืฉืช ืœื›ืชื•ื‘ืช 83.235.123.20 ื‘ื™ืฆื™ืื” 80. ื—ื™ื‘ื•ืจ ื–ื” ื ื•ืคืœ ืชื—ืช ื›ืœืœ ื”-DNAT, ื›ืš ืฉื›ืชื•ื‘ืช ื”-IP ืฉืœ ื”ื™ืขื“ ืžืฉืชื ื” ืœ-10.10.10.10.

5. ืชื—ื™ืœืช ื”ืขื‘ื•ื“ื” ืฉืœ Fortinet v6.0. NAT

ื”ืกืจื˜ื•ืŸ ื“ืŸ ื‘ืชื™ืื•ืจื™ื” ื•ืžืกืคืง ื’ื ื“ื•ื’ืžืื•ืช ืžืขืฉื™ื•ืช ืœื”ื’ื“ืจืช NAT ืฉืœ ืžืงื•ืจ ื•ื™ืขื“.


ื‘ืฉื™ืขื•ืจื™ื ื”ื‘ืื™ื ื ืขื‘ื•ืจ ืœื”ื‘ื˜ื—ืช ื‘ื˜ื™ื—ื•ืช ื”ืžืฉืชืžืฉ ื‘ืื™ื ื˜ืจื ื˜. ื‘ืื•ืคืŸ ืกืคืฆื™ืคื™, ื”ืฉื™ืขื•ืจ ื”ื‘ื ื™ื“ื•ืŸ ื‘ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืœ ืกื™ื ื•ืŸ ืื™ื ื˜ืจื ื˜ ื•ื‘ืงืจืช ื™ื™ืฉื•ืžื™ื. ื›ื“ื™ ืœื ืœืคืกืคืก, ืขืงื‘ื• ืื—ืจ ื”ืขื“ื›ื•ื ื™ื ื‘ืขืจื•ืฆื™ื ื”ื‘ืื™ื:

YouTube
ืงื”ื™ืœืช Vkontakte
ื™ืื ื“ืงืก ื–ืŸ
ื”ืืชืจ ืฉืœื ื•
ืขืจื•ืฅ ื˜ืœื’ืจื

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”