RT2配置ipv4 nat,实现AC1 ipv4产品部门用RT2外网接口ipv4地址访问Internet。RT2配置nat64,实现AC1 ipv6产品部门用RT2外网接口ipv4地址访问Internet,ipv4地址转ipv6地址前缀为64:ff9b::/96。
Ipv4 nat:
ip access-list standard nat4
permit 10.17.110.0 255.255.255.0 sequence 10
!
ip nat inside source list nat4 interface GigaEthernet0/3
interface GigaEthernet0/3
ip nat outside
interface GigaEthernet0/1
ip nat inside
nat64:IPV6主动访问IPV4
ipv6 access-list nat64
permit ipv6 2001:10:17:110::/64 any sequence 10
!
ipv6 access-list v
permit ipv6 2001:10:17:110::/64 64:FF9B::/96 sequence 10
! \\别问我为什么还要设置这个acl,问就是必须要做
ipv6 nat v6v4 source list nat64 interface GigaEthernet0/3
ipv6 nat prefix 64:FF9B::/96 v4-mapped v \\设置nat转换前缀动态转换后面一定加上v4参数再加 v访问控制列表
interface GigaEthernet0/1
ipv6 nat
interface GigaEthernet0/3
ipv6 nat \\出接口和入接口都需要开启ipv6 nat
防火墙
防火墙NAT64配置