CE Router是做静态NAT的地方; 静态NAT可以建立1v1的固定的公私网IP地址映射,这样可以保证重要主机使用固定的公网IP地址访问外网,而且可以同时双向通信,but 在实战中很少使用。
CE配置:
int g0/0
ip address 192.168.1.1 255.255.255.0
ip nat inside
no shut
int s0/3/0
ip address 222.0.1.1 255.255.255.0
ip nat outside
no shut
ip nat inside source static 192.168.1.2 222.0.1.3
ip route 222.0.2.0 255.255.255.0 222.0.1.2
PE配置:
int g0/0
ip address 222.0.2.1 255.255.255.0
no shut
interface Serial0/3/0
ip address 222.0.1.2 255.255.255.0
no shut
ip route 192.168.1.0 255.255.255.0 222.0.1.1
实验结果:
在PE上开启 debug ip icmp:
server ping 222.0.1.2(PE) 和 PC1 ping 222.0.1.2(PE) 的结果分别如下:
PE#debug ip icmp
ICMP packet debugging is on
PE#
ICMP: echo reply sent, src 222.0.1.2, dst 222.0.1.3
ICMP: echo reply sent, src 222.0.1.2, dst 222.0.1.3
ICMP: echo reply sent, src 222.0.1.2, dst 222.0.1.3
ICMP: echo reply sent, src 222.0.1.2, dst 222.0.1.3
ICMP: echo reply sent, src 222.0.1.2, dst 192.168.1.3
ICMP: echo reply sent, src 222.0.1.2, dst 192.168.1.3
ICMP: echo reply sent, src 222.0.1.2, dst 192.168.1.3
ICMP: echo reply sent, src 222.0.1.2, dst 192.168.1.3