NAT及其配置

一.配置静态NAT

NAT及其配置

1.给PC1,PC2,配置ip地址
NAT及其配置

2.给R1,R2配置接口IP

[r2]interface GigabitEthernet 0/0/0
[r2-GigabitEthernet0/0/1]ip address 192.168.1.254 24
[r2-GigabitEthernet0/0/1]quit
[r2]interface GigabitEthernet 0/0/1
[r2-GigabitEthernet0/0/1]ip address 201.10.10.1 24

[r2]interface GigabitEthernet 0/0/1
[r2-GigabitEthernet0/0/1]ip address 201.10.10.2 24

3.在R1上配置静态NAT

[r1-GigabitEthernet0/0/1]nat static global 202.10.10.4 inside 192.168.1.1
[r1-GigabitEthernet0/0/1]nat static global 202.10.10.4 inside 192.168.1.2

4.查看配置结果
NAT及其配置

二.配置动态NAT

[r1]nat address-group 1 202.10.10.1 220.10.10.200

[r1]acl
[r1]acl 2000
[r1-acl-basic-2000]rule 5 permit source 192.168.1.0 0.0.0.255
[r1-acl-basic-2000]quit

[r1]interface g0/0/1
[r1-GigabitEthernet0/0/1]nat outbound 2000 address-group 1 no-pat

验证配置
<r1>display nat address-group 1

配置动态NAT
第一步定义公网地址范围
第二步定义私网地址范围
第三步在公网接口将公网地址池和私网地址池关联在一起

三.easyIP的配置
[r1]acl
[r1]acl 2000
[r1-acl-basic-2000]rule 5 permit source 192.168.1.0 0.0.0.255
[r1-acl-basic-2000]quit

[r1]interface g0/0/1
[r1-GigabitEthernet0/0/1]nat outbound 2000

工作方式和NAPT一样,转换后的公网IP为路由器出口的公网IP

四.NAPT的配置
1.配置NAPT

[r1]nat address-group 1 202.10.10.1 220.10.10.1

[r1]acl
[r1]acl 2000
[r1-acl-basic-2000]rule 5 permit source 192.168.1.0 0.0.0.255
[r1-acl-basic-2000]quit

[r1]interface g0/0/1
[r1-GigabitEthernet0/0/1]nat outbound 2000 address-group 1

NAPT的配置方式和动态NAT类似,只是在最后调用公网和私网地址池时
不加no-pat参数即可

猜你喜欢

转载自blog.51cto.com/13212728/2517529