HQ(config)#ip nat inside source list NAT_LIST pool XYZCORP HQ(config)#int se 0/0/1 HQ(config-if)#ip nat inside
HQ(config)#int se 0/0/0.41 point-to-point HQ(config-if)#ip nat inside
HQ(config)#int se 0/0/0.42 point-to-point HQ(config-if)#ip nat inside
HQ(config)#int se 0/0/0.43 point-to-point HQ(config-if)#ip nat inside
HQ(config)#ip route 0.0.0.0 0.0.0.0 se0/1/0 // 到ISP的默认路由 HQ(config)#ip route 10.4.5.0 255.255.255.0 se 0/0/1 //到NewB的默认路由 HQ(config)#router eigrp 100
HQ(config-router)#network 10.0.0.0 HQ(config-router)#no auto-summary
HQ(config-router)#passive-interface default
HQ(config-router)#no passive-interface se0/0/0.41 HQ(config-router)#no passive-interface se0/0/0.42
HQ(config-router)#no passive-interface se0/0/0.43 或passive-interface se0/1/0 HQ(config-router)#no passive-interface fa 0/1 或passive-interface se0/0/1 HQ(config)#ip access-list extended FIREWALL
HQ(config-ext-nacl)#permit tcp any host 10.0.1.2 eq 80 HQ(config-ext-nacl)#permit tcp 209.165.201.0 0.0.0.3 any HQ(config-ext-nacl)#permit tcp 209.165.201.136 0.0.0.3 any HQ(config-ext-nacl)#permit tcp 209.165.201.132 0.0.0.3 any HQ(config-ext-nacl)#permit tcp 209.165.201.128 0.0.0.3 any HQ(config-ext-nacl)#permit icmp 209.165.201.0 0.0.0.3 any echo HQ(config-ext-nacl)#permit icmp 209.165.201.136 0.0.0.3 any echo HQ(config-ext-nacl)#permit icmp 209.165.201.132 0.0.0.3 any echo HQ(config-ext-nacl)#permit icmp 209.165.201.128 0.0.0.3 any echo HQ(config-ext-nacl)#exit HQ(config)#int se 0/1/0
HQ(config-if)#ip access-group FIREWALL in HQ(config-if)#exit