需求说明:公网122.93.43.X:16927 映射 内网 10.100.124.200:80

定义内网地址 set security nat destination pool srv200-80 address 10.100.124.200/32 定义内网端口号 set security nat destination pool srv200-80 address port 80 定义公网地址+端口 edit security nat destination set rule-set untrust-trust-set rule un122-srv200-443 match source-address 0.0.0.0/0 set rule-set untrust-trust-set rule un122-srv200-443 match destination-address 122.93.43.X/32 set rule-set untrust-trust-set rule un122-srv200-443 match destination-port 16927 ##公网端口 set rule-set untrust-trust-set rule un122-srv200-443 match protocol tcp set rule-set untrust-trust-set rule un122-srv200-443 then destination-nat pool srv200-80

定义内网协议+端口

set applications application tcp-80 protocol tcp set applications application tcp-80 destination-port 80

定义内网地址

set security zones security-zone trust address-book address srv200 10.100.124.200

定义策略 edit security policies from-zone untrust to-zone trust set policy utot-srv11-3389 match source-address any set policy utot-srv11-3389 match destination-address srv200 set policy utot-srv11-3389 match application tcp-80 ###### 定义内网真实端口#### set policy utot-srv11-3389 match application junios-http set policy utot-srv11-3389 then permit