华为eNSP:华为静态NAT,动态NAT配置实列

拓扑图实验拓扑以及IP地址分配如下

在这里插入图片描述

静态NAT(服务器地址转换)

  • 静态NAT实现了私有地址和公有地址的一对一转换,一个公网地址对应一个私网地址

动态NAT

  • 动态NAT基于地址池来实现私有地址和公有地址的转换,转换是随机的

代码展示

交换机的代码

<Huawei>system-view 
[Huawei]sysname SW1
[SW1]vlan batch  10 20 30 40                                       ##创建VLAN
[SW1]interface  GigabitEthernet 0/0/1                              ##进入线路
[SW1-GigabitEthernet0/0/1]port link-type access                    ##定义他为access端口
[SW1-GigabitEthernet0/0/1]port default vlan 10                     ##打标签
[SW1]interface  GigabitEthernet 0/0/2
[SW1-GigabitEthernet0/0/2]port link-type access
[SW1-GigabitEthernet0/0/2]port default vlan 20
[SW1]interface  GigabitEthernet 0/0/3
[SW1-GigabitEthernet0/0/3]port link-type access
[SW1-GigabitEthernet0/0/3]port default vlan 30
[SW1]interface  GigabitEthernet 0/0/4
[SW1-GigabitEthernet0/0/4]port link-type access
[SW1-GigabitEthernet0/0/4]port default vlan 20
[SW1]interface  GigabitEthernet 0/0/5
[SW1-GigabitEthernet0/0/5]port link-type access
[SW1-GigabitEthernet0/0/5]port default vlan 40
[SW1]interface  GigabitEthernet 0/0/6
[SW1-GigabitEthernet0/0/6]port link-type access
[SW1-GigabitEthernet0/0/6]port default vlan 10
[SW1]interface  Vlanif 10                                          ##进入VLAN
[SW1-Vlanif10]ip address 192.168.10.1 24                           ##设置ip地址
[SW1]interface  Vlanif 20
[SW1-Vlanif10]ip address 192.168.20.1 24
[SW1]interface  Vlanif 30
[SW1-Vlanif10]ip address 192.168.30.1 24
[SW1]interface  Vlanif 40
[SW1-Vlanif10]ip address 11.0.0.2 24
[SW1]ip route-static 0.0.0.0 0.0.0.0 11.0.0.1                      ##设置静态路由

路由器R1的代码

<Huawei>system-view 
[Huawei]sysname R1
[R1]]interface GigabitEthernet 0/0/0                               ##进入线路
[R1-GigabitEthernet0/0/0]ip add 11.0.0.1 24                        ##设置ip地址
[R1]]interface GigabitEthernet 0/0/0 
[R1-GigabitEthernet0/0/1]ip add 12.0.0.1 24
[R1]ip route-static 192.168.10.0 24 11.0.0.2                       ##设置静态路由
[R1]ip route-static 192.168.20.0 24 11.0.0.2 
[R1]ip route-static 192.168.30.0 24 11.0.0.2 
[R1]ip route-static 0.0.0.0 0.0.0.0 12.0.0.2
[R1]nat static global 8.8.8.8 inside 192.168.10.10                 ##静态nat设置
[R1]]interface g 0/0/1                                       
[R1-GigabitEthernet0/0/1]nat static enable                         ##开通nat服务
[R1]nat address-group 1 212.0.0.100 212.0.0.200                    ##设置外网ip群
[R1]acl 2000                                                       ##设置内网ip池名为2000
[R1-acl-basic-2000]rule permit  source  192.168.20.0 0.0.0.255     ##设置地址池范围
[R1-acl-basic-2000]rule permit source  11.0.0.0 0.0.0.255
[R1-acl-basic-2000]int g 0/0/1
[R1-GigabitEthernet0/0/1]nat outbound 2000 address-group 1 no-pat  ##将内网地址池2000里面的ip转换成外网地址群里面address-group 1
[R1-acl-adv-3000]rule permit ip source 192.168.30.0 0.0.0.255
[R1]int g 0/0/1
[R1-GigabitEthernet0/0/1]nat outbound  3000
[R1]int g 0/0/1
[R1-GigabitEthernet0/0/1]nat server protocol tcp global 9.9.9.9 www inside 192.168.10.100 www

路由器R2的代码

<Huawei>system-view 
[Huawei]sysname R2
[R2]interface GigabitEthernet 0/0/0
[R2-GigabitEthernet0/0/0]ip add 12.0.0.2 24
[R2]interface loo 0
[R2-LoopBack0]ip add 114.114.114.114 32
[R2]ip route-static 8.8.8.8 32 12.0.0.1
[R2]ip route-static 212.0.0.0 24 12.0.0.1
[R2]interface g 0/0/1
[R2-GigabitEthernet0/0/1]ip add 13.0.0.1 24
[R2]ip route-static 9.9.9.9 24 12.0.0.1

配置展示

交换机配置

SW1交换机一配置
vlan batch 10 20 30 40
interface Vlanif10
 ip address 192.168.10.1 255.255.255.0
interface Vlanif20
 ip address 192.168.20.1 255.255.255.0
interface Vlanif30
 ip address 192.168.30.1 255.255.255.0
interface Vlanif40
 ip address 11.0.0.2 255.255.255.0
interface MEth0/0/1
interface GigabitEthernet0/0/1
 port link-type access
 port default vlan 10
interface GigabitEthernet0/0/2
 port link-type access
 port default vlan 20
interface GigabitEthernet0/0/3
 port link-type access
 port default vlan 30
interface GigabitEthernet0/0/4
 port link-type access
 port default vlan 20
interface GigabitEthernet0/0/5
 port link-type access
 port default vlan 40
interface GigabitEthernet0/0/6
 port link-type access
 port default vlan 10
ip route-static 0.0.0.0 0.0.0.0 11.0.0.1

路由器R1配置

acl number 2000  
 rule 5 permit source 192.168.20.0 0.0.0.255 
 rule 10 permit source 11.0.0.0 0.0.0.255 
acl number 3000  
 rule 5 permit ip source 192.168.30.0 0.0.0.255 
 nat address-group 1 212.0.0.100 212.0.0.200
 nat static global 8.8.8.8 inside 192.168.10.10 netmask 255.255.255.255
interface GigabitEthernet0/0/0
 ip address 11.0.0.1 255.255.255.0 
interface GigabitEthernet0/0/1
 ip address 12.0.0.1 255.255.255.0 
 nat server protocol tcp global 9.9.9.9 www inside 192.168.10.100 www
 nat outbound 2000 address-group 1 no-pat
 nat outbound 3000
 nat static enable
ip route-static 0.0.0.0 0.0.0.0 12.0.0.2
ip route-static 192.168.10.0 255.255.255.0 11.0.0.2
ip route-static 192.168.20.0 255.255.255.0 11.0.0.2
ip route-static 192.168.30.0 255.255.255.0 11.0.0.2

路由器R2配置

interface GigabitEthernet0/0/0
 ip address 12.0.0.2 255.255.255.0 
interface GigabitEthernet0/0/1
 ip address 13.0.0.1 255.255.255.0 
ip address 114.114.114.114 255.255.255.255 
ip route-static 8.8.8.8 255.255.255.255 12.0.0.1
ip route-static 9.9.9.9 255.255.255.255 12.0.0.1
ip route-static 212.0.0.0 255.255.255.0 12.0.0.1
  • 23
    点赞
  • 148
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 6
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 6
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

阿辉爱学习

奥利给你的打赏就是我的动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值