1. .
2. .
3. . 1, 2.
4. , 1.
5. , 2.
6. Packet Tracer .
7. , .
8. . .
9. .
1. 2, 3 ,
/ | |||
router 1 | E0 | ||
router 1 | S0 | ||
router 1 | E1 | ||
router 1 | E1 | ||
router 2 | E0 | ||
router 2 | E0 | ||
router 2 | S0 | ||
router 2 | S0 | ||
router 2 | E1 | ||
router 2 | E1 |
2.
router1# show access-list
router1# show running-config
3. .
4. 6 4 v ,
Router1 | Router2 | |
Fa0/0 | 1.v.3.1/24 | 1.v.1.129/25 |
Fa0/1 | 1.v.1.1/25 | |
Serial0 | 1.v.2.1/24 | 1.v.2.2/24 |
Hostname | IP ethernet | |
PC1 | 1.v.3.2 255.255.255.0 | 1.v.3.1 |
PC2 | 1.v.1.130 255.255.255.128 | 1.v.1.129 |
PC3 | 1.v.1.131 255.255.255.128 | 1.v.1.129 |
PC4 | 1.v.1.2 255.255.255.128 | 1.v.1.1 |
PC5 | 1.v.1.3 255.255.255.128 | 1.v.1.1 |
, 6 .
.
.
1. , .
2. , .
3. .txt , .
4. .txt , 1 .
5. , 3 .
6. .txt , 4 .
7. , .
10. NAT
Network address translation (NAT - ) IP . NAT IP , . , IP . IP IP (intranet), . NAT .
|
|
Class A: 10.0.0.0-10.255.255.255
Class B: 172.16.0.0-172.16.255.255
Class C: 192.168.1-192.168.255.255
NAT IP IP . NAT intranet, , .
NAT . . NAT , .
Cisco NAT intranet , :
(inside) . , . .
(outside). , - . .
. IP, .
. IP, Intranet. .
(inside local). , , .
(inside global). , , .
(outside local). , - , .
(outside global). , - , .
C , (Outside Local) (outside global).
NAT . NAT ( ) . , . : , (overload). NAT IOS _ - _. . , , .
NAT ip nat inside | outside. , interface. NAT. NAT, . , ACL , . ACL NAT .
|
|
, , PAT (Port Address Translation - ). PAT . PAT TCP UDP .
NAT X. Yi Pi G p. . NAT Yi Pi X:Pinew, Pinew . (Yi:Pi, X: Pinew, G:p) NAT . X, Pinew. : G:p. X, Pinew, G, p NAT (Yi:Pi, X: Pinew, G:p) X Yi, Pinew Pi. Yi Pi. Pinew .
NAT . Yi, , NAT . , .
.
1. .
10.1
L1 | G1 | G2 | |
Ethern | 10.10.1.2 255.255.255.0 | 10.10.1.1 255.255.255.0 | |
Serial | 175.10.1.1 255.255.255.0 | 175.10.1.2 255.255.255.0 |
OSPF G1
G1(config)# router ospf 1
G1(config- router)# network 10.10.1.0 0.0.0.255 area 0
G1(config- router)# network 175.10.1.0 0.0.0.255 area 0
L1
L1 (config)# router ospf 1
L1 (config- router)# network 10.10.1.0 0.0.0.255 area 0
G2
G2 (config)# router ospf 1
G2(config- router)# network 175.10.1.0 0.0.0.255 area 0
G2 G2
G2 (config)# line vty 0 4
G2 (config-line)# login
G2 (config-line)# password G2
ping. Telnet- L1 (10.10.1.2) G2
L1# telnet 175.10.1.2
Password: G2
G2> show users
:ctrl+shift+6 x. disconnect L1 G2.
NAT/PAT G1. : , ( ). , Ethernet 10.10.1.0/24 intranet, G1, 175.10.1.0/24 .
1.1 G1 NAT Ethernet- L1 10.10.1.2 169.10.1.2, :
G1(config)#ip nat inside source static 10.10.1.2 169.10.1.2
fastEthernet0/0
G1(config)#interface fa0/0
G1(config-if)# ip nat inside
serial2/0
G1(config-if)#interface s2/0
G1(config-if#ip nat outside
|
|
G1# show ip nat translations
, Telnet- L1 G2. Telnet G2 show users. IP- 169.10.1.2.
L1# telnet 175.10.1.2
Password: G2
G2> show users
169.10.1.2 Serial2/0 G1
175.10.1.1
G1(config)# no ip nat inside source static 10.10.1.2 169.10.1.2
G1(config)# ip nat inside source static 10.10.1.2 175.10.1.1
L1# telnet 175.10.1.2
Password: G2
G2> show users
1.2. G1 NAT-
G1(config)# no ip nat inside source static 10.10.1.2 175.10.1.1
NAT Ethernet- L1. : 169.10.1.50 - 169.10.1.100. pool1
G1(config)# ip nat pool pool1 169.10.1.50 169.10.1.100 netmask 255.255.255.0
NAT 1 pool1
G1(config)# ip nat inside source list 1 pool pool1
1 ,
G1(config)# access-list 1 permit 10.10.1.0 0.0.0.255
^Z
G1# Show access-list
show running-config , G1 .
, Telnet- L1 G2. Telnet G2 show users. IP- 169.10.1.50.
L1# telnet 175.10.1.2
Password: G2
G2> show users
NAT 169.10.1.50.
show ip nat translations G1.
1.3 G1 NAT- ( ) Ethernet- L1 (10.10.1.2) serial2/0 (175.10.1.1) G1.
G1(config)# no ip nat pool pool1 169.10.1.50 169.10.1.100 netmask 255.255.255.0
G1(config)# no nat inside source list 1 pool pool1
G1(config)# ip nat inside source list 1 interface s2/0 overload
show running-config , G1 .
, Telnet- L1 G2. G2, show users. IP- 175.10.1.1.
L1# telnet 175.10.1.2
Password: G2
G2> show users
NAT- G1.
G1#show ip nat translations
2. . L1, L2, G1 G2 -805, LG G 1605.
10.2
. 255.255.255.0
L1 | L2 | LG | G | G1 | G2 | |
Eth0 | 10.1.1.2 | 10.1.1.1 | 1.1.2.1 | 1.1.2.2 | ||
Eth1 | 10.1.2.2 | 10.1.2.1 | 1.1.3.1 | 1.1.3.2 | ||
serial | 1.1.1.1 | 1.1.1.2 |
OSPF
LG(config)# router ospf 1
LG(config-router)# network 1.1.1.0 0.0.0.255 area 10
LG(config-router)# network 10.1.1.0 0.0.0.255 area 10
LG(config-router)# network 10.1.2.0 0.0.0.255 area 10
G(config)# router ospf 1
G(config-router)# network 1.1.1.0 0.0.0.255 area 10
G(config-router)# network 1.1.2.0 0.0.0.255 area 10
G(config-router)# network 1.1.3.0 0.0.0.255 area 10
|
|
L1(config)# router ospf 1
L1(config-router)# network 10.1.1.0 0.0.0.255 area 10
L2(config)# router ospf 1
L2(config-router)# network 10.1.2.0 0.0.0.255 area 10
G1(config)# router ospf 1
G1(config-router)# network 1.1.2.0 0.0.0.255 area 10
G2(config)# router ospf 1
G2(config-router)# network 1.1.3.0 0.0.0.255 area 10
G1 G2:
G1(config)# line vty 0 4
G1(config-line)# login
G1(config-line)# password G1
G2(config)# line vty 0 4
G2(config-line)# login
G2(config-line)# password G2
: L1 G1, L1 G2, L2 G1, L2 G2.
disconnect 1. 8 . : L1, L2, G1 G2.
show session.
LG 10.1.1.0/24 10.1.2.0/24 , 1.1.1.0/24
LG(config)# interface s2/0
LG(config-if)# ip nat outside
LG(config-if)# interface fa0/0
LG(config-if)# ip nat inside
LG(config-if)# interface fa1/0
LG(config-if)# ip nat inside
Ethernet
LG(config)# access-list 2 permit 10.1.0.0 0.0.255.255
PAT 1.1.1.1 Serial2/0
LG(config)# ip nat inside source list 2 interface s2/0 overload
: L1 G1
L1# telnet 1.1.2.2
Password: G1
G1> show users
, Ctrl-shift-6 x.
L1 G2
L1# telnet 1.1.3.2
Password: G2
G2> show users
, Ctrl-shift-6 x.
L2. L2 G1
L2# telnet 1.1.2.2
Password: G1
G1> sh us
, Ctrl-shift-6 x.
L2 G2
L2# telnet 1.1.2.2
Password: G2
G2> sh us
G1 G2 . - 1.1.1.1 Serial2/0.
LG.
LG# show ip nat tr
telnet
L1# telnet 1.1.2.2
L1# telnet 1.1.3.2
L2# telnet 1.1.2.2
L2# telnet 1.1.3.2
1.1.1.1 Serial2/0.
1. NAT.
2. IP NAT?
3. ?
4. ?
5. ?
6. ?
7. ?
8. ?
9. ?
10. ?
11. ?
12. .
13. PAT.
14. , NAT, ?