目录
1.NAT
NAT主要用于实现从内网上外网
工作原理
当内网的数据包经过路由器,会将源地址转换成公网地址
当公网的数据包经过路由器时,NAT会将目的的地址转换成内网地址
2.NAT种类
1.静态NAT
公网地址和私网地址一一对应
若pc1和pc2要访问外网
<Huawei>u t m //关闭通知
Info: Current terminal monitor is off.
<Huawei>sys //进入系统视图
Enter system view, return user view with Ctrl+Z.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 192.168.1.254 24
[Huawei-GigabitEthernet0/0/0]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 200.1.1.1 24 //配置接口IP
[Huawei-GigabitEthernet0/0/1]
[Huawei-GigabitEthernet0/0/1]
[Huawei-GigabitEthernet0/0/1]
[Huawei-GigabitEthernet0/0/1]
[Huawei-GigabitEthernet0/0/1]q
[Huawei]nat
[Huawei]nat st
[Huawei]nat static en
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]nat st
[Huawei-GigabitEthernet0/0/1]nat static en
[Huawei-GigabitEthernet0/0/1]nat static enable //进入接口开启nat
[Huawei-GigabitEthernet0/0/1]nat s
[Huawei-GigabitEthernet0/0/1]nat stat
[Huawei-GigabitEthernet0/0/1]nat static gl
[Huawei-GigabitEthernet0/0/1]nat static global 200.1.1.100 in
[Huawei-GigabitEthernet0/0/1]nat static global 200.1.1.100 inside 192.168.1.1 //配置pc1公网地址与私网地址一一对应
[Huawei-GigabitEthernet0/0/1]nat st
[Huawei-GigabitEthernet0/0/1]nat static gl
[Huawei-GigabitEthernet0/0/1]nat static global 200.1.1.101 in
[Huawei-GigabitEthernet0/0/1]nat static global 200.1.1.101 inside 192.168.1.2 //配置pc2公网地址与私网地址一一对应
[Huawei-GigabitEthernet0/0/1]
[Huawei-GigabitEthernet0/0/1]
[Huawei-GigabitEthernet0/0/1]
用pc1ping外网
2.动态NAT
动态的将私网地址和公网地址一一对应
操作:进入AR1设置
<Huawei>u t m //关闭通知
Info: Current terminal monitor is off.
<Huawei>sys //进入系统视图
Enter system view, return user view with Ctrl+Z.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 192.168.1.254 24
[Huawei-GigabitEthernet0/0/0]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 200.1.1.1 24
[Huawei-GigabitEthernet0/0/1]q //配置两个接口ip地址,并退出
[Huawei]nat ad
[Huawei]nat address-group 1 200.1.1.10 200.1.1.15 //建立地址池
[Huawei]acl 2000 //新建表格
[Huawei-acl-basic-2000]ru
[Huawei-acl-basic-2000]rule 5 per
[Huawei-acl-basic-2000]rule 5 permit so
[Huawei-acl-basic-2000]rule 5 permit source 192.168.1.0 0.0.0.255
[Huawei-acl-basic-2000]q //制定规制5,允许192.168.1.0/24所有网段通过
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]nat ou
[Huawei-GigabitEthernet0/0/1]nat outbound 2000 ad
[Huawei-GigabitEthernet0/0/1]nat outbound 2000 address-group 1 no
[Huawei-GigabitEthernet0/0/1]nat outbound 2000 address-group 1 no-pat
[Huawei-GigabitEthernet0/0/1]q //进入接口添加规制并退出
[Huawei]
用pc2ping外网可以正常通讯
3.NAPT
一个公网对应多个私网地址
进入AR1配置
<Huawei>sys /// 进入系统视图
Enter system view, return user view with Ctrl+Z.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 192.168.1.254 24
[Huawei-GigabitEthernet0/0/0]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 200.1.1.1 24 //进入两个接口并配置接口IP地址
[Huawei-GigabitEthernet0/0/1]nat sse
[Huawei-GigabitEthernet0/0/1]nat se
[Huawei-GigabitEthernet0/0/1]nat server pr
[Huawei-GigabitEthernet0/0/1]nat server protocol tcp gl
[Huawei-GigabitEthernet0/0/1]nat server protocol tcp global cu
[Huawei-GigabitEthernet0/0/1]nat server protocol tcp global current-interface ww
w in
[Huawei-GigabitEthernet0/0/1]nat server protocol tcp global current-interface ww
w inside 192.168.1.100 www //进入g0/0/1端口,将私网地址的www端口映射到公网地址www的端口上
Warning:The port 80 is well-known port. If you continue it may cause function fa
ilure.
Are you sure to continue?[Y/N]:y //选择yes
[Huawei-GigabitEthernet0/0/1]nat st
[Huawei-GigabitEthernet0/0/1]nat static en
[Huawei-GigabitEthernet0/0/1]nat static enable //打开NAT
[Huawei-GigabitEthernet0/0/1]q
[Huawei]ip rou
[Huawei]ip route
[Huawei]ip route-static 202.1.1.0 24 200.1.1.2 //配置目的地址,以及下一跳地址
进入Server1任意选择一个文件根目录,并点击启用
点击进入家庭用户,ping地址200.1.1.1,能获取到刚刚设置的文件就是实验成功
4.EASY-IP
将所有的私网地址映射成路由器当前接口的公网地址
进入企业出口路由器配置
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 192.168.1.254 24
[Huawei-GigabitEthernet0/0/0]int g/0/0/1
[Huawei-GigabitEthernet0/0/0]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 200.1.1.1 24 //进入接口配置IP
[Huawei-GigabitEthernet0/0/1]q
[Huawei]acl 2000 //新建表格
[Huawei-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255 //建立规制 允许192.168.1.1/24所有网段通过
[Huawei-acl-basic-2000]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]nat ou
[Huawei-GigabitEthernet0/0/1]nat outbound 2000 //进入接口应用规制
[Huawei-GigabitEthernet0/0/1]q
[Huawei]ip route-static 202.1.1.0 24 200.1.1.2 //设置目标地址和下一跳地址
进入pc1ping家庭用户,能通
最后抓包看一下,自动将私网地址映射成公网地址