1 实验说明
利用 NAT 实现内网与公网的通信。
2 实验
命令设置:
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]int g 0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 192.168.1.254 255.255.255.0
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int g 0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 64.1.1.254 255.255.255.0
[Huawei-GigabitEthernet0/0/1]q
<Huawei>dis ip routing-table
Route Flags: R - relay, D - download to fib
------------------------------------------------------------------------------
Routing Tables: Public
Destinations : 10 Routes : 10
Destination/Mask Proto Pre Cost Flags NextHop Interface
64.1.1.0/24 Direct 0 0 D 64.1.1.254 GigabitEthernet
0/0/1
64.1.1.254/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/1
64.1.1.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/1
127.0.0.0/8 Direct 0 0 D 127.0.0.1 InLoopBack0
127.0.0.1/32 Direct 0 0 D 127.0.0.1 InLoopBack0
127.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
192.168.1.0/24 Direct 0 0 D 192.168.1.254 GigabitEthernet
0/0/0
192.168.1.254/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/0
192.168.1.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/0
255.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
[Huawei]acl name intranet basic
[Huawei-acl-basic-intranet]rule permit source 192.168.1.0 0.255.255.255
[Huawei-acl-basic-intranet]dis acl all
Total quantity of nonempty ACL number is 1
Basic ACL intranet 2999, 1 rule
Acl's step is 5
rule 5 permit source 192.0.0.0 0.255.255.255
[Huawei-acl-basic-intranet]q
[Huawei]nat ?
address-group IP address-group of NAT
alg Application level gateway
dns-map DNS mapping
filter-mode NAT filter mode
link-down Link down reset session function
mapping-mode NAT mapping mode
overlap-address Overlap address pool to temp address pool map
static Specify static NAT
[Huawei]nat address-group 1 64.1.1.250 64.1.1.253
[Huawei]int g 0/0/1
[Huawei-GigabitEthernet0/0/1]nat outbound 2999 address-group 1
[Huawei-GigabitEthernet0/0/1]q