要求:PC1能ping通Server1
基本配置
PC1
ISP
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname ISP
[ISP]int g0/0/1
[ISP-GigabitEthernet0/0/1]ip address 192.168.10.254 24
[ISP-GigabitEthernet0/0/1]q
[ISP]int g0/0/2
[ISP-GigabitEthernet0/0/2]ip address 10.1.1.2 24
Server1
静态NAT:大概就就是私网地址与公网地址一对一转换
在路由器ISP基础配置上增加一条命令(私网地址映射成公网地址)
[ISP-GigabitEthernet0/0/2]nat static global 10.1.1.100 inside 192.168.10.1
PC1 ping Server1
查看转换表
Easy-ip:单向转换的,配置时候不需要创建公网地址池
[ISP]acl 3001
[ISP-acl-adv-3001]rule permit ip source 192.168.10.1 0 destination 10.1.1.1 0
[ISP-acl-adv-3001]q
[ISP]int g0/0/2
[ISP-GigabitEthernet0/0/2]nat outbound 3001
ping 服务器
在ISP路由器查看转换表
动态nat:将内部网络的私有IP地址转换为公用I地址(地址池)时 ,IP地址对是不确定的,是随机的。
[ISP]nat address-group 1 10.1.1.100 10.1.1.105
[ISP]acl 3002
[ISP-acl-adv-3002]r
[ISP-acl-adv-3002]rule permit ip source 192.168.10.1 0 destination 10.1.1.1 0
[ISP-acl-adv-3002]q
[ISP]int g0/0/2
[ISP-GigabitEthernet0/0/2]nat outbound 3002 address-group 1 no-pat
[ISP-GigabitEthernet0/0/2]q
PC1 ping Server1
查看转换表
nat server:只能访问主机80端口
[ISP-GigabitEthernet0/0/2]nat server protocol tcp global 10.1.1.100 80 inside 19
2.168.10.1 80