拓扑图实验拓扑以及IP地址分配如下
静态NAT(服务器地址转换)
- 静态NAT实现了私有地址和公有地址的一对一转换,一个公网地址对应一个私网地址
动态NAT
- 动态NAT基于地址池来实现私有地址和公有地址的转换,转换是随机的
代码展示
交换机的代码
<Huawei>system-view
[Huawei]sysname SW1
[SW1]vlan batch 10 20 30 40
[SW1]interface GigabitEthernet 0/0/1
[SW1-GigabitEthernet0/0/1]port link-type access
[SW1-GigabitEthernet0/0/1]port default vlan 10
[SW1]interface GigabitEthernet 0/0/2
[SW1-GigabitEthernet0/0/2]port link-type access
[SW1-GigabitEthernet0/0/2]port default vlan 20
[SW1]interface GigabitEthernet 0/0/3
[SW1-GigabitEthernet0/0/3]port link-type access
[SW1-GigabitEthernet0/0/3]port default vlan 30
[SW1]interface GigabitEthernet 0/0/4
[SW1-GigabitEthernet0/0/4]port link-type access
[SW1-GigabitEthernet0/0/4]port default vlan 20
[SW1]interface GigabitEthernet 0/0/5
[SW1-GigabitEthernet0/0/5]port link-type access
[SW1-GigabitEthernet0/0/5]port default vlan 40
[SW1]interface GigabitEthernet 0/0/6
[SW1-GigabitEthernet0/0/6]port link-type access
[SW1-GigabitEthernet0/0/6]port default vlan 10
[SW1]interface Vlanif 10
[SW1-Vlanif10]ip address 192.168.10.1 24
[SW1]interface Vlanif 20
[SW1-Vlanif10]ip address 192.168.20.1 24
[SW1]interface Vlanif 30
[SW1-Vlanif10]ip address 192.168.30.1 24
[SW1]interface Vlanif 40
[SW1-Vlanif10]ip address 11.0.0.2 24
[SW1]ip route-static 0.0.0.0 0.0.0.0 11.0.0.1
路由器R1的代码
<Huawei>system-view
[Huawei]sysname R1
[R1]]interface GigabitEthernet 0/0/0
[R1-GigabitEthernet0/0/0]ip add 11.0.0.1 24
[R1]]interface GigabitEthernet 0/0/0
[R1-GigabitEthernet0/0/1]ip add 12.0.0.1 24
[R1]ip route-static 192.168.10.0 24 11.0.0.2
[R1]ip route-static 192.168.20.0 24 11.0.0.2
[R1]ip route-static 192.168.30.0 24 11.0.0.2
[R1]ip route-static 0.0.0.0 0.0.0.0 12.0.0.2
[R1]nat static global 8.8.8.8 inside 192.168.10.10
[R1]]interface g 0/0/1
[R1-GigabitEthernet0/0/1]nat static enable
[R1]nat address-group 1 212.0.0.100 212.0.0.200
[R1]acl 2000
[R1-acl-basic-2000]rule permit source 192.168.20.0 0.0.0.255
[R1-acl-basic-2000]rule permit source 11.0.0.0 0.0.0.255
[R1-acl-basic-2000]int g 0/0/1
[R1-GigabitEthernet0/0/1]nat outbound 2000 address-group 1 no-pat
[R1-acl-adv-3000]rule permit ip source 192.168.30.0 0.0.0.255
[R1]int g 0/0/1
[R1-GigabitEthernet0/0/1]nat outbound 3000
[R1]int g 0/0/1
[R1-GigabitEthernet0/0/1]nat server protocol tcp global 9.9.9.9 www inside 192.168.10.100 www
路由器R2的代码
<Huawei>system-view
[Huawei]sysname R2
[R2]interface GigabitEthernet 0/0/0
[R2-GigabitEthernet0/0/0]ip add 12.0.0.2 24
[R2]interface loo 0
[R2-LoopBack0]ip add 114.114.114.114 32
[R2]ip route-static 8.8.8.8 32 12.0.0.1
[R2]ip route-static 212.0.0.0 24 12.0.0.1
[R2]interface g 0/0/1
[R2-GigabitEthernet0/0/1]ip add 13.0.0.1 24
[R2]ip route-static 9.9.9.9 24 12.0.0.1
配置展示
交换机配置
SW1交换机一配置
vlan batch 10 20 30 40
interface Vlanif10
ip address 192.168.10.1 255.255.255.0
interface Vlanif20
ip address 192.168.20.1 255.255.255.0
interface Vlanif30
ip address 192.168.30.1 255.255.255.0
interface Vlanif40
ip address 11.0.0.2 255.255.255.0
interface MEth0/0/1
interface GigabitEthernet0/0/1
port link-type access
port default vlan 10
interface GigabitEthernet0/0/2
port link-type access
port default vlan 20
interface GigabitEthernet0/0/3
port link-type access
port default vlan 30
interface GigabitEthernet0/0/4
port link-type access
port default vlan 20
interface GigabitEthernet0/0/5
port link-type access
port default vlan 40
interface GigabitEthernet0/0/6
port link-type access
port default vlan 10
ip route-static 0.0.0.0 0.0.0.0 11.0.0.1
路由器R1配置
acl number 2000
rule 5 permit source 192.168.20.0 0.0.0.255
rule 10 permit source 11.0.0.0 0.0.0.255
acl number 3000
rule 5 permit ip source 192.168.30.0 0.0.0.255
nat address-group 1 212.0.0.100 212.0.0.200
nat static global 8.8.8.8 inside 192.168.10.10 netmask 255.255.255.255
interface GigabitEthernet0/0/0
ip address 11.0.0.1 255.255.255.0
interface GigabitEthernet0/0/1
ip address 12.0.0.1 255.255.255.0
nat server protocol tcp global 9.9.9.9 www inside 192.168.10.100 www
nat outbound 2000 address-group 1 no-pat
nat outbound 3000
nat static enable
ip route-static 0.0.0.0 0.0.0.0 12.0.0.2
ip route-static 192.168.10.0 255.255.255.0 11.0.0.2
ip route-static 192.168.20.0 255.255.255.0 11.0.0.2
ip route-static 192.168.30.0 255.255.255.0 11.0.0.2
路由器R2配置
interface GigabitEthernet0/0/0
ip address 12.0.0.2 255.255.255.0
interface GigabitEthernet0/0/1
ip address 13.0.0.1 255.255.255.0
ip address 114.114.114.114 255.255.255.255
ip route-static 8.8.8.8 255.255.255.255 12.0.0.1
ip route-static 9.9.9.9 255.255.255.255 12.0.0.1
ip route-static 212.0.0.0 255.255.255.0 12.0.0.1