Ͳ ²Ҳ
(NAT) IP- , . , IP- , ' IP- , . , ' , IP - . NAT IP- . IP - IP - , NAT , .
IP- : 10..., 192.168.., 172.16.. - 172.32...
.1
4 :
1. (Full Cone)
2. (Restricted Cone)
3. (Port Restricted Cone)
4. (Symmetric)
NAT IP- . .
NAT . ³ , NAT 䳺 ( , 1-3 ), , . NAT , 1024.
(192.168.0.2:2210) (1.1.1.2:8801). - 192.168.0.2:2210 1.1.1.2:8801. - , 1.1.1.2:8801 192.168.0.2:2210
.2.
(192.168.0.2:2210) (1.1.1.2:8801). - 192.168.0.2:2210 1.1.1.2:8801. - , 1.1.1.2:8801 192.168.0.2:2210 , 192.168.0.2:2210 .
.3.
(192.168.0.2:2210) (1.1.1.2:8801). - 192.168.0.2:2210 1.1.1.2:8801. (1.1.1.30:1234) 192.168.0.2:2210 1.1.1.2:8801 192.168.0.2:2210 1.1.1.30:1234
|
|
.4.
NAT
IP : IP : :. ³, : , -. : , .
.5 NAT
inside outside , .
.
, , inside, , , . . , outside - . , . - , - . , outside - .
, outside , , NAT. (, ), inside source NAT, destination. .
' inside - . , , . , , outside NAT. , . , - . , , permit any, , .
loopback - , inside outside,
1. inside source dynamic NAT
, (. 6). .
.6. -
:
1. , . access - list (ACL), .
(config) # access - list 100 permit ip 10.0.0.0 0.255.255.255 any
ACL deny. , . ACL , .
2. , . :
(config) # ip nat pool NAME_OF_POOL 11.1.1.10 11.1.1.20 netmask 255.255.255.0
, .
3. .
(config) # interface fa 0 / 0
|
|
(config - if) # ip nat inside
(config) # interface fa 0 / 1
(config - if) # ip nat outside
4. :
ip nat inside source list 100 pool NAME_OF_POOL
10.1.1.1 11.1.1.2 :
Router#sh ip nat translations
Pro Inside global Inside local Outside local Outside global
tcp 11.1.1.10:55209 10.0.1.1:55209 11.1.1.2:23 11.1.1.2:23
2 inside source dynamic NAT with overload
Overloading - . , NAT PAT (Port Address Translation). PAT , .
NAT 㳿 :
1. 1-3 .
2.
ip nat inside source list 100 pool NAME_OF_POOL overload
:
Router #sh ip nat translations
Pro Inside global Inside local Outside local Outside global
tcp 11.1.1.11:21545 10.0.1.1:21545 11.1.1.2:23 11.1.1.2:23
tcp 11.1.1.11:49000 10.0.2.1:49000 11.1.1.2:23 11.1.1.2:23
3 Static NAT
Static NAT - NAT, IP , .
,
. 7.
, 10.11.11.10 192.168.56.10.
:
1.
(config)#interface fastEthernet 0/0
R1(config-if)#ip nat inside
R1(config-if)#exit
R1(config)#
R1(config)#interface fastEthernet 0/1
R1(config-if)#ip nat outside
R1(config-if)#exit
R1(config)#
2. access - list
R1(config)#access-list 1 permit 192.168.56.0 0.0.0.255
3.
R1(config)#ip nat inside source static 192.168.56.10 10.11.11.10
(), , :
R1 (config) # ip nat inside source static tcp 192.168.56.10 22 10.11.11.10 2222
10.11.11.10 tcp 2222 ' 22- tcp 192.168.56.10
4 .
, , .8.
. 8.
:
1. 2514
(config)#interface fastEthernet 0/0
(config-if) #ip address 172.16.88.1 255.255.255.0
(config)# interface Serial0
(config-if) #ip address 172.16.191.254 255.255.255.252
(config) # ip route 0.0.0.0 0.0.0.0 172.16.191.253!-- 2514X.
2. 2514
(config)#interface Serial0
(config-if)#ip address 171.68.192.202 255.255.255.0
(config-if)#ip nat inside
(config)#interface Serial1
(config-if)#ip address 172.16.191.253 255.255.255.252
(config-if) #ip nat outside
(config)#ip nat pool Net171 171.68.16.10 171.68.16.254 netmask 255.255.255.0
(config)# ip nat outside source list 1 pool Net171
(config)# ip route 172.16.88.0 255.255.255.0 172.16.191.254
(config)# ip route 171.68.1.0 255.255.255.0 171.68.192.201
(config)# ip route 171.68.16.0 255.255.255.0 172.16.191.254
access-list 1 permit 172.16.88.0 0.0.0.255
3.
(config)#interface fastEthernet 0/0
(config-if) #ip address 171.68.1.1 255.255.255.0
(config)# interface Serial0
(config-if) #ip address 171.68.192.201 255.255.255.0
(config) # ip route 0.0.0.0 0.0.0.0 171.68.192.202!-- 2514X.
|
|
3. ί
1. 㳺, .
( 31 ) ' , . 172.16.10.1 172.16.10.63.
2. , ' , .
3. 㳺, , .
, , ..
4. ².
:
1.
2. .
3. , .
˳:
1. . Cisco, - 2005, 317 .
2. , . Cisco, - 298
isco
㳿
7(8).05090201
.., . . , .
.. , . . , .