NAT实验报告

实验要求:

实验预览图:

实验分析:

1、仅对私网设备进行OSPF配置,公网仅对test设备配置缺省路由,和配置R3端口IP

2、对私网配置OSPF,R2对公网的端口IP不宣发,同时对R2配置缺省路由,指向公网,再在R2配置缺省路由下发,对telnet、test配置缺省路由

3、4:先对私网和公网分开配置,使用NAT将私网与公网进行联系起来

5、在R3的端口上配置ACL,使得test-可以登入telnet server;而test-2不可以

6、在R2的0/0/0口配置ACL,使pc1可以访问test-1;test-2不可以

7、分别在R1、R2开启DHCP协议,对pc1、pc2进行IP分配

实验过程:

配置IP:

telnet:

[telnet server]interface GigabitEthernet 0/0/0

[telnet server-GigabitEthernet0/0/0]ip address 192.168.1.2 24

r1:
对0/0/0口:

[r1]interface GigabitEthernet 0/0/0

[r1-GigabitEthernet0/0/0]ip address 192.168.1.1 24

对0/0/1口:

[r1]interface GigabitEthernet 0/0/1

[r1-GigabitEthernet0/0/1]ip address 192.168.12.1 24

检查配置:

[r1]display ip interface brief

Interface IP Address/Mask Physical Protocol

GigabitEthernet0/0/0 192.168.1.1/24 up up

GigabitEthernet0/0/1 192.168.12.1/24 up up

GigabitEthernet0/0/2 unassigned down down

NULL0 unassigned up up(s)

r2:
对0/0/0口:

[r2]interface GigabitEthernet 0/0/0

[r2-GigabitEthernet0/0/0]ip address 192.168.12.2 24

对0/0/1口:

[r2]interface GigabitEthernet 0/0/1

[r2-GigabitEthernet0/0/1]ip address 192.168.2.1 24

对0/0/2口:

[r2]interface GigabitEthernet 0/0/2

[r2-GigabitEthernet0/0/2]ip address 23.0.0.1 24

检查配置:

[r2]display ip interface brief

Interface IP Address/Mask Physical Protocol

GigabitEthernet0/0/0 192.168.12.2/24 up up

GigabitEthernet0/0/1 192.168.2.1/24 up up

GigabitEthernet0/0/2 23.0.0.1/24 up up

NULL0 unassigned up up(s)

r3:
对0/0/0口:

[r3]interface GigabitEthernet 0/0/0

[r3-GigabitEthernet0/0/0]ip address 34.0.0.1 24

对0/0/1口:

[r3]interface GigabitEthernet 0/0/1

[r3-GigabitEthernet0/0/1]ip address 23.0.0.2 24

检查配置:

[r3]display ip interface brief

Interface IP Address/Mask Physical Protocol

GigabitEthernet0/0/0 34.0.0.1/24 up up

GigabitEthernet0/0/1 23.0.0.2/24 up up

GigabitEthernet0/0/2 unassigned down down

NULL0 unassigned up up(s)

test-1:
对0/0/0口:

[test1]interface GigabitEthernet 0/0/0

[test1-GigabitEthernet0/0/0]ip address 34.0.0.2 24

检查配置:

[test1]display ip interface brief

Interface IP Address/Mask Physical Protocol

GigabitEthernet0/0/0 34.0.0.2/24 up up

GigabitEthernet0/0/1 unassigned down down

GigabitEthernet0/0/2 unassigned down down

NULL0 unassigned up up(s)

test-2:
对0/0/0口:

[test2]interface GigabitEthernet 0/0/0

[test2-GigabitEthernet0/0/0]ip address 34.0.0.3 24

检查配置:

[test2]display ip interface brief

Interface IP Address/Mask Physical Protocol

GigabitEthernet0/0/0 34.0.0.3/24 up up

GigabitEthernet0/0/1 unassigned down down

GigabitEthernet0/0/2 unassigned down down

NULL0 unassigned up up(s)

IP配置完成图:

配置DHCP协议

r1:

[r1]dhcp enable

[r1]ip pool aa

[r1-ip-pool-aa]network 192.168.1.0 mask 24

[r1-ip-pool-aa]gateway-list 192.168.1.1

[r1-ip-pool-aa]dns-list 8.8.8.8

[r1]interface GigabitEthernet 0/0/0

[r1-GigabitEthernet0/0/0]dhcp select global

 在pc1开启DHCP服务:

测试:

r2:

[r2]dhcp enable

[r2]ip pool aa

[r2-ip-pool-aa]network 192.168.2.0 mask 24

[r2-ip-pool-aa]gateway-list 192.168.2.1

[r2-ip-pool-aa]dns-list 8.8.8.8

[r2]interface GigabitEthernet 0/0/1

[r2-GigabitEthernet0/0/1]dhcp select global

在pc2开启DHCP服务:

测试:

全网可达:

r1:

[r1]ospf 1

[r1-ospf-1]area 0

[r1-ospf-1-area-0.0.0.0]network 192.168.1.1 0.0.0.0

[r1-ospf-1-area-0.0.0.0]network 192.168.12.1 0.0.0.0

r2:

[r2]ospf 1

[r2-ospf-1]area 0

[r2-ospf-1-area-0.0.0.0]network 192.168.12.2 0.0.0.0

[r2-ospf-1-area-0.0.0.0]network 192.168.2.1 0.0.0.0

[r2]ip route-static 0.0.0.0 0 23.0.0.2

[r2]ospf 1

[r2-ospf-1]default-route-advertise

[r2]acl 2000

[r2-acl-basic-2000]rule permit source 192.168.0.0 0.0.255.255

[r2]interface GigabitEthernet 0/0/2

[r2-GigabitEthernet0/0/2]nat outbound 2000

telnet:

[telnet server]ip route-static 0.0.0.0 0 192.168.1.1

test-1:

[test1]ip route-static 0.0.0.0 0 34.0.0.1

test-2:

[test2]ip route-static 0.0.0.0 0 34.0.0.1

开启telnet服务:

telnet端:

[telnet server]user-interface vty 0 4

[telnet server-ui-vty0-4]authentication-mode aaa

[telnet server-aaa]local-user huawei password cipher 123456

[telnet server-aaa]local-user huawei privilege level 15

[telnet server-aaa]local-user huawei service-type telnet

r2开启telnet服务映射:

[r2]interface GigabitEthernet 0/0/2

[r2-GigabitEthernet0/0/2]nat server protocol tcp global current-interface telne t inside 192.168.1.2 telnet

Are you sure to continue?[Y/N]:y

测试映射是否成功:
test-1:

test-2:

配置test设备权限:

在r3的0/0/0口配置ACL:

[r3]acl 3000

[r3-acl-adv-3000]rule permit tcp source 34.0.0.2 0 destination 23.0.0.1 0 destin ation-port eq 23

[r3-acl-adv-3000]rule deny tcp source 34.0.0.3 0 destination 23.0.0.1 0 destinat ion-port eq 23

[r3]interface GigabitEthernet 0/0/0

[r3-GigabitEthernet0/0/0]traffic-filter inbound acl 3000

在r2的0/0/0口配置ACL:

[r2]acl 3100

[r2-acl-adv-3100]rule deny ip source 192.168.1.254 0 destination 34.0.0.3 0

[r2-acl-adv-3100]rule permit ip source 192.168.1.254 0 destination 34.0.0.2 0

[r2]interface GigabitEthernet 0/0/0

[r2-GigabitEthernet0/0/0]traffic-filter inbound acl 3100

进行测试:

要求1、3、4:

r1:

r2:

r3:

要求2:

r1:

r2:

r3:

要求5:

test-1:

test-2:

要求6:

pc1—>:

pc2—>:

要求7:

pc1:

pc2:

评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

Rinleren

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值