1.为什么需要NAT?
IPV4地址紧缺
2.什么是NAT?(Network address translate)
私有地址空间
A:10.0.0.0-10.255.255.255
B:172.16.0.0-172.31.255.255
C:192.168.0.0-192.168.255.255
3.NAT的三种类型
1)静态NAT(内网——外网,一对一,并没有解决IP地址不足的问题)
定义静态映射
定义inside/outside
配置格式:Router(config)#ip nat inside source static local-ip global-ip
Router(config-if)#ip nat inside
Router(config-if)#ip nat outside
eg:
ip nat inside source static 192.168.1.1 202.101.100.1
interface s1/0
ip nat outside
interface f0/0
ip nat inside
show ip nat translations ----查看nat条目
2.动态NAT(内网——外网,虽然有过地址池,但还是一对一的关系,并没有解决IP地址不足的问题)
配置格式:(1)定义地址池——Router(config)#ip nat pool name start-ip(起始地址) end-ip(终止地址)
{network network | prefix-length prefix-length}
(2)定义允许那些做nat转换的内网地址Router(config)#access-list access-list-number permit source [source-wildcard]
(3)将ACL和地址池关联起来Router(config)#ip nat inside source list access-list-number pool name
eg:
ip nat pool nat1 202.101.100.1 202.101.100.10 netmask 255.255.255.0
access-list 1 permit 192.168.1.0 0.0.0.255
ip nat inside source list 1 pool nat1
interface s1/0
ip nat outside
interface f0/0
ip nat inside
3.端口复用(PAT解决IP地址不足的问题)
配置格式:Router(config-if)#access-list access-list-number permit source source-wildcard
Router(config-if)#ip nat inside source list access-list-number interface interface (出接口) overload
Router#show ip nat translations
eg:
interface f0/0
ip nat inside
interface serial1/0
ip nat outside
ip nat inside source list 1 interface serial1/0 overload
ip route 0.0.0.0 0.0.0.0 serial0
access-list 1 permit 192.168.1.0 0.0.0.255
通过上图要求进行模拟实验
这里最主要的就在网关设备上对入接口与出接口进行配置
interface FastEthernet0/0
ip address 192.168.1.254 255.255.255.0
ip nat inside
duplex auto
speed auto
!
interface Serial2/0
ip address 202.101.100.1 255.255.255.224
ip nat outside
clock rate 2000000
ip nat inside source list 1 interface Serial2/0 overload——出接口方向配置端口复用
ip nat inside source static tcp 192.168.1.100 23 202.101.100.3 9090
ip classless
ip route 0.0.0.0 0.0.0.0 202.101.100.30 ——配置默认路由
!
ip flow-export version 9
!
!
access-list 1 permit 192.168.1.0 0.0.0.255 ——入接口允许所有1.0网段通过
!
模拟internet外网接口配置
interface Serial2/0
ip address 202.101.100.30 255.255.255.224
!
interface Serial2/0
ip address 202.101.100.30 255.255.255.224
!