R1 u t m Info:Current terminal monitor is off. sys Enter system view,return user view with Ctrl+Z. [Huawei]sys r1 [r1]intg0/0/0 [r1-GigabitEthernet0/0/0]ip add 192.168.1.1 24 [r1-GigabitEthernet0/0/0]undo shutdown Info:Interface GigabitEthernet0/0/0 is not shutdown. [r1-GigabitEthernet0/0/0]q [r1]intg0/0/1 [r1-GigabitEthernet0/0/1]ip add 202.10.100.1 24 [r1-GigabitEthernet0/0/1]undo shutdown Info:Interface GigabitEthernet0/0/1 is not shutdown. [r1-GigabitEthernet0/0/1]q#nat 分组(映射的外网IP范围) [r1]nat address-group 1 200.10.100.10 200.10.100.20 #ACL访问控制 [r1]ac1 2000 #PS:ac1 (2000-2999):只能匹配源ip地址 [r1-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255 [r1-acl-basic-2000]q [r1]intg0/0/1 [r1-GigabitEthernet0/0/1]nat outbound 2000 address-group 1 [r1-GigabitEthernet0/0/1]display nat outbound
小结:
映射出去的地址池(范围段)
ACL规则,允许哪些主机出去
需要确定在哪个网络接口(路由接口)应用这个规则
判断是出口方向还是进口方向
Easyip(多个内网地址对一个接口)
sys Enter system view, return user view with Ctrl+Z. [Huawei]sys r1[r1]int g0/0/0 [r1-GigabitEthernet0/0/0]ip add 192.168.1.1 24 [r1-GigabitEthernet0/0/0]undo shutdown Info: Interface GigabitEthernet0/0/0 is not shutdown. [r1-GigabitEthernet0/0/0]int g0/0/1 [r1-GigabitEthernet0/0/1]ip add 202.10.100.1 24 [r1-GigabitEthernet0/0/1]undo shutdown Info: Interface GigabitEthernet0/0/1 is not shutdown. [r1-GigabitEthernet0/0/1]q[r1]acl 2000 [r1-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255 ##定义规则 [r1-acl-basic-2000]q [r1]int g0/0/1 [r1-GigabitEthernet0/0/1]nat outbound 2000 ## 指向出去位置 [r1-GigabitEthernet0/0/1]display nat outbound NAT Outbound Information:--------------------------------------------------------------------------Interface Acl Address-group/IP/Interface Type--------------------------------------------------------------------------GigabitEthernet0/0/1 2000 202.10.100.1 easyip --------------------------------------------------------------------------Total : 1
静态PAT(一对一,但是外网口IP和服务映射网内网服务器的IP和服务)
R1 u t m Info: Current terminal monitor is off. sys Enter system view, return user view with Ctrl+Z. [Huawei]sysname r1[r1]int g0/0/0 [r1-GigabitEthernet0/0/0]ip add 192.168.1.1 24 [r1-GigabitEthernet0/0/0]undo shutdown Info: Interface GigabitEthernet0/0/0 is not shutdown. [r1-GigabitEthernet0/0/0]int g0/0/1 [r1-GigabitEthernet0/0/1]ip add 200.10.100.1 24 [r1-GigabitEthernet0/0/1]undo shutdown Info: Interface GigabitEthernet0/0/1 is not shutdown. [r1-GigabitEthernet0/0/1]q [r1]ip route-static 0.0.0.0 0 200.10.100.2##配置一个静态路由(因为跨网段了) [r1]int g0/0/1 [r1-GigabitEthernet0/0/1]at server protocol tcp global 200.10.100.254 21 inside 200.10.100.2 21 ###映射一个服务 TCP协议 在全局模块中 [r1-GigabitEthernet0/0/1]display nat serverNat Server Information:Interface : GigabitEthernet0/0/1Global IP/Port : 200.10.100.254/21(ftp) Inside IP/Port : 200.10.100.2/21(ftp)Protocol : 6(tcp) VPN instance-name : ---- Acl number : ----Description : ----Total : 1 [ar1-GigabitEthernet0/0/1] [r1-GigabitEthernet0/0/1]q [r1]nat alg all enable #FTP服务默认数据端口没有开启,需要手动去开:R2 [ISP]int g0/0/0 [ISP-GigabitEthernet0/0/0]ip add 202.10.100.3 24 Info: Interface GigabitEthernet0/0/0 is not shutdown. [ISP-GigabitEthernet0/0/0]q [ISP]ip route-static 15.0.0.10 32 202.10.100.1AR1 ftp 200.10.100.254 Connected to 200.10.100.254 220 FtpServerTry FtpD for free Uger(200.10.100.254:(none): 331 Password required for Enter password: 230 User logged in progeedls ##查看当前目录下的文件
小结: NAT 是对内网IP/PORT 转换为外网IP/PORT 的一种映射的技术 NAT 的作用: ① 节省ipv4地址(跨2个网络环境的IP就可以借助于NAT的技术来支持重复IP) ② 安全性(让外网网络设备无法直接获取内网的IP/PORT) ③ 灵活性
NAT 常用的方式:
① EasyIP ——》EIP : 一组内网地址映射为一个外网接口IP 场景:常规企业的公网IP 例如www.baidu.com 域名对应的IP ② 静态NAT ③ 静态PAT ④ 动态NAT-PAT 2 - 4 主要用于公司内部进行划分 NAT 配置: 两种方式:一种在系统视图模式配置 一种在接口模式中配置