NAT配置
一、静态NAT配置
实验目的:
使用静态配置方法实现私网地址与公网地址的一对一映射
实现内部设备访问外网
实验拓扑:
(1)在边界路由器AR1上配置如下:
sys
Enter system view, return user view with Ctrl+Z.
[Huawei]un in en //关闭提示符
Info: Information center is disabled.
[Huawei]sysname AR1 //重命名路由器
[AR1]int g0/0/0
[AR1-GigabitEthernet0/0/0]ip add 192.168.1.254 24 //配置IP地址
[AR1-GigabitEthernet0/0/0]int g0/0/1
[AR1-GigabitEthernet0/0/1]ip add 100.1.1.1 24
[AR1]ip route-static 0.0.0.0 0.0.0.0 100.1.1.2 //设置静态路由
[AR1-GigabitEthernet0/0/1]nat static global 100.1.1.3 inside 192.168.1.1
//配置静态路由映射
(2)在外网路由器AR2上配置如下:
sys
Enter system view, return user view with Ctrl+Z.
[Huawei]un in en
Info: Information center is disabled.
[Huawei]sysname AR2
[AR2]int g0/0/0
[AR2-GigabitEthernet0/0/0]ip add 100.1.1.2 24
[AR2]ip route-static 192.168.1.0 255.255.255.0 100.1.1.1
(3)在内网PC上配置相关IP地址与网关;
(4)在边界路由器上查看静态路由映射如下:
(5)验证NAT配置结果。
注:ping -a 源地址 目标地址
测试源地址到目标地址连通性
二、动态NAT配置
使用动态配置方法,实现私网地址与公网地址的多对多映射
实现内部设备访问外网
实验拓扑:
(1)边界路由器AR1配置如下:
sys
Enter system view, return user view with Ctrl+Z.
[Huawei]un in en
Info: Information center is disabled.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 192.168.1.254 24
[Huawei-GigabitEthernet0/0/0]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 122.1.2.1 24
[Huawei]ip route-static 0.0.0.0 0.0.0.0 122.1.2.2 //配置静态路由
[Huawei]acl 2000 //创建ACL
[Huawei-acl-basic-2000]rule 5 permit source 192.168.1.0 0.0.0.255
//配置ACL规则
[Huawei-acl-basic-2000]q
[Huawei]nat address-group 1 122.1.2.3 122.1.2.7
//配置公网地址转换池
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]nat outbound 2000 address-group 1 no-pat
//将ACL规则、地址池配置应用在接口上
(2)外网路由器AR2配置如下:
sys
Enter system view, return user view with Ctrl+Z.
[Huawei]un in en
Info: Information center is disabled.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 122.1.2.2 24
[Huawei]ip route-static 192.168.1.0 255.255.255.0 122.1.2.1
(3)在内网PC上配置对应IP地址和网关
(4)配置验证